From 8a90e3e34f639eb38be5a1f6b3402a166f51efc1 Mon Sep 17 00:00:00 2001 From: saphid <4596216+saphid@users.noreply.github.com> Date: Sat, 26 Sep 2026 14:22:58 +1000 Subject: [PATCH] Don't let the screenshot copy inherit stdin either Co-Authored-By: Claude Opus 5.5 (1M context) --- scripts/chromium-xr.sh | 6 ++++++ ui/server.py | 2 +- 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/scripts/chromium-xr.sh b/scripts/chromium-xr.sh index ccfab0a..2fb8e2d 100755 --- a/scripts/chromium-xr.sh +++ b/scripts/chromium-xr.sh @@ -39,11 +39,17 @@ case "${1:-}" in # need to be open. The app starts in $HOME, so the profile path is relative. # Without --no-first-run and --password-store=basic, startup can stop at a # first-run or keyring prompt before DevTools comes up. + # --disable-seccomp-filter-sandbox: under the XR seccomp policy, SteamVR's + # client reads /proc/self/status through the file broker, gets the + # broker's pid, and SteamVR binds the app to the wrong process, so + # xrCreateInstance fails. The namespace sandbox stays on, but seccomp is + # off for every process, so keep this profile for VR sites. exec "$here/panel-on-frame.sh" --name chromium-xr -- '~/chromium-xr/chrome' \ --user-data-dir=.config/chromium-xr \ --enable-features=OpenXR \ --ozone-platform=x11 \ --no-first-run --no-default-browser-check --password-store=basic \ + --disable-seccomp-filter-sandbox \ --remote-debugging-port="$DEVTOOLS_PORT" \ "${2:-https://immersive-web.github.io/webxr-samples/}" ;; diff --git a/ui/server.py b/ui/server.py index a70f234..5415c51 100755 --- a/ui/server.py +++ b/ui/server.py @@ -249,7 +249,7 @@ def save_shots(body): try: try: r = subprocess.run(["scp", "-p", *SSH[1:], *(f"{FRAME}:{p}" for p in todo), str(incoming)], - capture_output=True, text=True, timeout=300) + capture_output=True, stdin=subprocess.DEVNULL, text=True, timeout=300) except subprocess.TimeoutExpired: raise Failure("Copying screenshots timed out") if r.returncode != 0: