From 2567db01dfe3df6bb67a2692280541ace93a8a2c Mon Sep 17 00:00:00 2001 From: roboomp Date: Fri, 7 Aug 2026 12:43:37 +0000 Subject: [PATCH] fix(computer): removed orphaned wayland remote-desktop token Pre-#7884 builds wrote a world-readable RemoteDesktop restore token under $XDG_STATE_HOME/omp/remote-desktop-token during read-only calls, and nothing on the fixed tree reads, rewrites, or removes it. WaylandBackend::new now unlinks it best-effort on construction so the stale credential does not survive the upgrade. Fixes #7884 --- .../src/desktop/linux/wayland/mod.rs | 3 ++ .../src/desktop/linux/wayland/portal.rs | 52 ++++++++++++++++--- packages/natives/CHANGELOG.md | 1 + 3 files changed, 50 insertions(+), 6 deletions(-) diff --git a/crates/pi-natives/src/desktop/linux/wayland/mod.rs b/crates/pi-natives/src/desktop/linux/wayland/mod.rs index 80d403fb4..d11adde54 100644 --- a/crates/pi-natives/src/desktop/linux/wayland/mod.rs +++ b/crates/pi-natives/src/desktop/linux/wayland/mod.rs @@ -31,6 +31,9 @@ pub struct WaylandBackend { impl WaylandBackend { pub fn new(display: DisplaySelector) -> Self { + // Remove the world-readable RemoteDesktop restore token that pre-#7884 + // builds wrote during read-only calls; nothing reads it anymore (#7884). + portal::remove_orphaned_remote_desktop_token(); let (ax, ax_error) = match AtSpiAx::new() { Ok(ax) => (Some(ax), None), Err(err) => (None, Some(err)), diff --git a/crates/pi-natives/src/desktop/linux/wayland/portal.rs b/crates/pi-natives/src/desktop/linux/wayland/portal.rs index 62e3bdb0b..ec67669f5 100644 --- a/crates/pi-natives/src/desktop/linux/wayland/portal.rs +++ b/crates/pi-natives/src/desktop/linux/wayland/portal.rs @@ -1,6 +1,8 @@ -use std::sync::LazyLock; -#[cfg(feature = "wayland-pipewire")] -use std::{fs, path::PathBuf}; +use std::{ + fs, + path::{Path, PathBuf}, + sync::LazyLock, +}; use tokio::runtime::{Builder, Runtime}; @@ -26,12 +28,36 @@ pub(super) fn portal_runtime() -> CoreResult<&'static Runtime> { .map_err(|err| DesktopError::internal(format!("xdg-desktop-portal runtime: {err}"))) } -#[cfg(feature = "wayland-pipewire")] -fn token_path(name: &str) -> Option { +/// File name of the RemoteDesktop restore token that pre-#7884 builds wrote +/// (world-readable) during read-only `computer` calls. Nothing reads it after +/// #7884 dropped the restore-token path. +const ORPHANED_REMOTE_DESKTOP_TOKEN: &str = "remote-desktop-token"; + +/// Resolves the `omp` state directory (`$XDG_STATE_HOME/omp` or +/// `~/.local/state/omp`) that holds portal tokens. +fn omp_state_dir() -> Option { let base = std::env::var_os("XDG_STATE_HOME") .map(PathBuf::from) .or_else(|| std::env::var_os("HOME").map(|home| PathBuf::from(home).join(".local/state")))?; - Some(base.join("omp").join(name)) + Some(base.join("omp")) +} + +fn remove_token_in(dir: &Path) { + let _ = fs::remove_file(dir.join(ORPHANED_REMOTE_DESKTOP_TOKEN)); +} + +/// Best-effort removal of the orphaned RemoteDesktop restore token left behind +/// by pre-#7884 builds. Runs on Wayland backend construction; a missing file +/// is success, so it is safe to call on every session. +pub(super) fn remove_orphaned_remote_desktop_token() { + if let Some(dir) = omp_state_dir() { + remove_token_in(&dir); + } +} + +#[cfg(feature = "wayland-pipewire")] +fn token_path(name: &str) -> Option { + Some(omp_state_dir()?.join(name)) } #[cfg(feature = "wayland-pipewire")] @@ -71,4 +97,18 @@ mod tests { "portal_runtime must hand back one long-lived runtime, not a fresh per-call instance" ); } + + /// The orphaned RemoteDesktop token written by pre-#7884 builds must be + /// removed, and a second removal on the now-missing file must stay a no-op. + #[test] + fn removes_orphaned_remote_desktop_token() { + let dir = std::env::temp_dir().join(format!("omp-token-test-{}", std::process::id())); + fs::create_dir_all(&dir).expect("create token test dir"); + let token = dir.join(ORPHANED_REMOTE_DESKTOP_TOKEN); + fs::write(&token, "cafef00d").expect("plant orphaned token"); + remove_token_in(&dir); + assert!(!token.exists(), "orphaned token must be removed"); + remove_token_in(&dir); + let _ = fs::remove_dir_all(&dir); + } } diff --git a/packages/natives/CHANGELOG.md b/packages/natives/CHANGELOG.md index c05d942a3..9e9ae9073 100644 --- a/packages/natives/CHANGELOG.md +++ b/packages/natives/CHANGELOG.md @@ -6,6 +6,7 @@ - Fixed read-only Wayland `computer` calls acquiring persistent keyboard and pointer control; RemoteDesktop input permission is now requested only on first input, is not persisted, and closes with the desktop session ([#7884](https://github.com/can1357/oh-my-pi/issues/7884)). - Fixed Wayland `libei` input initialization poisoning PipeWire screen capture: both paths now share one long-lived Tokio runtime so `ashpd`'s process-global D-Bus connection is never orphaned by a dropped runtime ([#7886](https://github.com/can1357/oh-my-pi/issues/7886)). +- Removed the orphaned world-readable RemoteDesktop restore token that pre-fix builds wrote under `$XDG_STATE_HOME/omp/remote-desktop-token` during read-only calls; the Wayland backend now unlinks it on startup ([#7884](https://github.com/can1357/oh-my-pi/issues/7884)). ## [17.2.10] - 2026-08-06