Expand description
What this machine offers a window, and what an engine has to be told before it opens one.
A desktop harness draws on the person’s own screen, so unlike every other container QCode starts, its container needs something of the machine: the compositor’s socket and, where there is one, the graphics card. This module is the whole of what QCode looks at outside the container, and it is deliberately small — the rule it keeps is that the container is given the one socket file and nothing beside it.
Why not the runtime folder itself: that folder also holds the engine’s own socket, the session bus, the sound server and the keyring. A container that could reach the engine’s socket could start any container it liked on the machine, with any mount. So the container gets a private runtime folder of its own with a single file bind-mounted into it. The price is that a compositor restart changes the socket and cuts an open window off; reopening the tab is the way back, and the tab says so.
Modules§
- callback
- The way back of a sign-in: the page opens in the person’s own browser, and the answer the browser is sent back with is carried to the application inside its container.
- login
- Signing a window in once, in the profile wizard, and giving that login to every workspace.
- seccomp
- The seccomp profile a window’s container runs under on docker, and how it reaches the engine.
- signin
- Signing in from a window: how the page the application wants opened reaches QCode, and the window of last resort it can be shown in inside the container.
Structs§
- Display
- What this machine offers a window.
Enums§
- NoDisplay
- Why this machine cannot show a window.
Constants§
- GRAPHICS_
DEVICE - The graphics device a container is given when the machine has one.
- RUNTIME_
DIR - Where a window’s runtime folder is inside its container.
- RUNTIME_
MODE - The permissions that runtime folder is made with. A compositor library warns and some applications refuse when the folder is open to more than its owner.
- SHM_
SIZE - How much shared memory a window’s container gets.
- WINDOW_
GRACE - How long a window is given to close by itself before it is killed, in seconds.
Functions§
- current
- What this machine offers a window, read from the variables of this process.
- display
- What this machine offers a window, read from the session
qcodewas started in. - run_
command - The command that opens a window:
oncerun as the containername, given the one socket ofdisplay, a runtime folder of its own, the graphics device when there is one, the shared memory a browser engine needs, and the program QCode’s own opener as its browser; and, for the engine that needs one, the seccomp profile atseccomp.