Files
DeeJanuz--frametop/session/remote-desktop.sh
T
DeeJanuzandClaude Opus 5.5 1f19732aaf Add Frametop Remote Access, a settings app for the VNC view
A GTK 4 / libadwaita app (remote/ft-remote-settings, on the host's own
Python like the gaze probe): remote access on and off (REMOTE, applied at
once when the desktop allows it), the tailnet name and address to connect
to, and the VNC password shown, copied, or replaced. The password stays
random and made on the Frame, in ~/.config/frametop-remote; none is in
the code.

session/remote-ctl.sh starts, stops, and reports remote access; the
session uses it and leaves a remote-capable marker, since KWin allows the
capture only in a desktop that started with REMOTE=1. The password
between krdp and the VNC bridge (local only, but on krdp's command line)
is now new at every start. The installer adds the app to the menu.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 15:55:49 -06:00

35 lines
1.6 KiB
Bash
Executable File

#!/bin/bash
# Runs on the Frame host. Internal capture server for remote access: KRdp's
# krdpserver (from the dev container) talks to the nested KWin directly
# (--plasma, no desktop portal) and serves it over RDP on 127.0.0.1 only.
# Nothing outside the Frame can reach it. vnc-bridge.sh connects to it and
# re-serves the desktop over VNC. Started by frametop-session.sh when REMOTE=1.
set -eu
runtime=${1:?usage: remote-desktop.sh <nested XDG_RUNTIME_DIR>}
# 3389 is taken by SteamOS's own xrdp (a separate X11 session, not the VR desktop).
port=${RDP_PORT:-3390}
creds=$HOME/.config/frametop-remote
mkdir -p -m 0700 "$creds"
# The password between krdp and vnc-bridge.sh (both on this host), new at every start: krdp
# takes it only on its command line, which other local users can read while it runs.
(umask 077; head -c 24 /dev/urandom | base64 | tr -d '/+=' | cut -c1-20 > "$creds/password")
if [ ! -s "$creds/cert.pem" ]; then
(umask 077; openssl req -x509 -newkey rsa:2048 -nodes -days 3650 -subj /CN=steam-frame \
-keyout "$creds/key.pem" -out "$creds/cert.pem" 2>/dev/null)
fi
# Wait for the nested KWin to come up.
for _ in $(seq 60); do
[ -S "$runtime/wayland-0" ] && break
sleep 1
done
# podman needs the real runtime dir. The nested one is passed only to krdpserver.
export XDG_RUNTIME_DIR=/run/user/$(id -u)
exec ~/.local/bin/distrobox enter dev -- env XDG_RUNTIME_DIR="$runtime" WAYLAND_DISPLAY=wayland-0 QT_QPA_PLATFORM=wayland \
krdpserver --plasma --address 127.0.0.1 --port "$port" \
-u steamos -p "$(cat "$creds/password")" \
--certificate "$creds/cert.pem" --certificate-key "$creds/key.pem"