Follow-up to #171 (Linux AppImage packaging, phase 0 of #168).
The one-time install helper works and is verified, but the root step can be friendlier and smaller:
- pkexec front-end. Desktop users should be able to run
pkexec ./deckd-install-system-integration.sh ./deckd-<version>-x86_64.AppImage
and get the native polkit password dialog instead of a terminal sudo. The helper must resolve the target user from PKEXEC_UID as well as SUDO_USER, and print the rerun/uninstall command matching how it was invoked. Keep sudo documented for headless/SSH.
- uaccess-first. The shipped udev rule already has
TAG+="uaccess", so on logind desktops the active seat user gets an ACL on /dev/uinput — the input group add (and its "log out and back in") is unnecessary for the autostart-at-login case. Make the group opt-in (--add-group) for linger/headless setups and reword the install output.
- Maybe: when
/dev/uinput can't be opened, surface a one-time-setup notice (client banner or log line) with the exact command — an on-demand prompt like balenaEtcher, as a notice rather than a blocker.
Verification: re-run the sandboxed install→uninstall lifecycle (pre-existing group/extension/icon preserved) plus the live-session focus/injection checks; confirm the pkexec path on a real desktop.
Follow-up to #171 (Linux AppImage packaging, phase 0 of #168).
The one-time install helper works and is verified, but the root step can be friendlier and smaller:
pkexec ./deckd-install-system-integration.sh ./deckd-<version>-x86_64.AppImageand get the native polkit password dialog instead of a terminal
sudo. The helper must resolve the target user fromPKEXEC_UIDas well asSUDO_USER, and print the rerun/uninstall command matching how it was invoked. Keepsudodocumented for headless/SSH.TAG+="uaccess", so on logind desktops the active seat user gets an ACL on/dev/uinput— theinputgroup add (and its "log out and back in") is unnecessary for the autostart-at-login case. Make the group opt-in (--add-group) for linger/headless setups and reword the install output./dev/uinputcan't be opened, surface a one-time-setup notice (client banner or log line) with the exact command — an on-demand prompt like balenaEtcher, as a notice rather than a blocker.Verification: re-run the sandboxed install→uninstall lifecycle (pre-existing group/extension/icon preserved) plus the live-session focus/injection checks; confirm the pkexec path on a real desktop.