Bare Openbox rendered only a blank slate root — usable but not the
desktop wanted. Make the X11/NVENC capture path render a full GNOME
session by default, with Openbox available via HEADLESS_DESKTOP=openbox
for minimal/low-power hosts.
- files/headless-desktop-gnome.service: full Ubuntu GNOME session forced
onto the X11 path (XDG_SESSION_TYPE=x11, no dbus-run-session so it
shares the systemd user bus). Renamed the Openbox unit to
headless-desktop-openbox.service.
- lib/headless.sh: HEADLESS_DESKTOP (default gnome) selects the unit
template + the packages to install (gnome-session/gnome-shell vs
openbox/xsetroot).
- install.sh: step message + usage document HEADLESS_DESKTOP.
- status.sh: the :0 desktop check now reports which desktop is running
(reads _NET_WM_NAME off the supporting-wm-check window, e.g.
"GNOME Shell").
- docs: TROUBLESHOOTING §13 + FOLLOWUPS P3 updated for the GNOME default
and the openbox toggle.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
A Moonlight client connecting to the x11-backend host got a black screen
even though pairing, NVENC, and input injection all worked: the headless
Xorg on :0 had no window manager rendering on it, so capture=x11 grabbed
an empty black root window. (The wlr/kms backends don't hit this — their
capture source renders for itself.)
This was a hand-built path with nothing in the repo to reproduce the
desktop piece. Now:
- files/headless-desktop.service: Openbox session on :0, bound to
xorg-headless.service, enabled via default.target for lingering boots,
with a best-effort xsetroot so the desktop is visibly non-black.
- lib/headless.sh: capture_backend_is_x11 + install_headless_desktop
(idempotent; pulls openbox/xsetroot via the distro dispatch).
- install.sh: installs the desktop unit when capture=x11 is detected.
- status.sh: x11 branch now FAILs if no window manager is on :0 instead
of only checking the X server answers — the gap that hid this failure.
- docs: TROUBLESHOOTING §13 black-screen lesson; FOLLOWUPS P3 updated.
Part of the P3 x11-backend work; --backend flag, config.sh x11 variant,
and xorg-headless templates remain outstanding.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adds a parallel install path for Debian/Ubuntu hosts alongside the existing
Arch/Omarchy/Hyprland one. The Arch path is untouched at runtime; everything
new is gated on $DISTRO and (for headless) $COMPOSITOR.
Highlights:
- lib/distro.sh: detect_distro + pkg_install/pkg_remove/ca_anchor_path/
ca_update_trust dispatch helpers
- lib/packages.sh: Ubuntu sunshine install pulls LizardByte's official .deb
from GitHub releases (override via SUNSHINE_DEB_URL/SUNSHINE_DEB_VERSION);
GPU encoder packages branch per $DISTRO:$GPU_VENDOR
- bin/sunshine-stream-{do,undo,prestart}-sway.sh + files/sway-headless.*:
swaymsg-based headless capture path for hosts without Hyprland. sway runs
under a systemd-user unit that sunshine.service depends on via drop-in.
- lib/preflight.sh: clearer NVIDIA driver guidance on Ubuntu (we don't install
the driver - too many branch/kernel/Secure-Boot variants); sway-aware
headless preflight
- lib/certs.sh + lib/verify.sh + uninstall.sh: distro-aware CA trust anchor
(Arch: /etc/ca-certificates/trust-source/anchors + update-ca-trust;
Debian: /usr/local/share/ca-certificates + update-ca-certificates)
Verified on Ubuntu 24.04: ./install.sh --doctor --headless loads cleanly,
distro/GPU/compositor detection report the right values, all pre-install
failures correspond to the actual missing pieces.
This bundles every fix we made debugging the first real install plus a
comprehensive troubleshooting reference. Working tree is now PII-safe for
public distribution: hostname-based default mode is driven by a HEADLESS_HOSTS
env var instead of a hardcoded literal; docs use placeholders for hostnames
and LAN IPs.
Self-healing headless management
- bin/sunshine-prestart.sh (new): runs as systemd ExecStartPre. Resolves the
Hyprland instance signature from XDG_RUNTIME_DIR/hypr when systemd-user env
didn't propagate it. Reduces to exactly one headless output by keeping the
lowest-numbered HEADLESS-N and removing the rest. Rewrites the managed
sunshine.conf's output_name line to match the surviving name — Hyprland's
HEADLESS-N counter is monotonic and ignores the optional name argument to
'output create headless', so without active sync output_name drifts off
HEADLESS-1 after the first restart cycle.
- bin/sunshine-stream-do.sh: dropped the hardcoded MON=HEADLESS-1. Now
discovers whatever HEADLESS-* exists via jq. Resize and workspace migration
target the actual output.
- bin/sunshine-stream-undo.sh: reads the headless name from a state file the
do-script wrote, with discovery fallback. Stops removing the output between
sessions — the create/destroy race caused fatal startup encoder errors on
the next Sunshine restart.
- files/headless-prestart.conf, files/sunshine.service: ExecStartPre now
points at the new prestart script.
- lib/headless.sh: install_headless_hooks now installs all three scripts.
New install_headless_prestart_dropin resolves the actual systemd unit name
(sunshine.service vs app-dev.lizardbyte.app.Sunshine.service) and lands the
drop-in under <unit>.service.d/.
Firewall detection
- lib/firewall.sh: _ufw_active now uses 'systemctl is-active ufw.service'
instead of 'ufw status'. The latter requires root to read /etc/ufw state,
so the unprivileged probe returned false and we silently skipped opening
Sunshine's ports on hosts where ufw was actively dropping packets.
Service unit fallbacks
- lib/service.sh: ensure_sunshine_unit_present looks for sunshine.service in
every systemd-user path first; falls back to the reverse-DNS AUR-source
unit name; last resort drops a repo-provided fallback unit. systemctl
reset-failed before each restart so a previous start-limit-hit doesn't
immediately reject the new attempt.
Preflight
- lib/preflight.sh: new preflight_headless step that, only when STREAM_MODE
is headless, surfaces missing hyprctl / jq / Hyprland reachability before
install proceeds.
Public-safe defaults
- install.sh: streaming-mode default is now driven by HEADLESS_HOSTS env var
(comma-separated, case-insensitive). Unset by default — every host gets
mirror mode unless its hostname is listed or --headless is passed
explicitly. Past versions hardcoded a specific hostname.
- README.md: replaced JARVIS-specific examples with HEADLESS_HOSTS prose.
Docs
- docs/TROUBLESHOOTING.md (new): comprehensive failure-mode reference. Every
issue hit during the first end-to-end install, in order, with symptom →
cause → fix → permanent prevention. Plus a "Custom keybinding to escape
Moonlight" section and an outstanding-followups punch list (1Password
black-rectangle workarounds, hypridle inhibit during stream, busiest-
workspace auto-switch, jarvis.lan DNS, 1Password SSH agent timeouts).
Two streams of fixes shipped together.
Headless persistence (root cause of "Fatal: Unable to find display or
encoder during startup")
- bin/sunshine-stream-undo.sh: stop removing HEADLESS-1 on disconnect.
Create-on-connect / destroy-on-disconnect raced with Sunshine's startup
encoder probe and made every restart fail with a fatal-but-misleading
warning. The output now lives across stream sessions; sunshine-stream-
do.sh just resizes it per client.
- files/headless-prestart.conf: systemd-user drop-in that runs
'hyprctl output create headless' (non-fatal) before Sunshine starts, so
HEADLESS-1 exists before the encoder probe.
- lib/headless.sh: install_headless_prestart_dropin resolves the actual
unit name (sunshine.service or app-dev.lizardbyte.app.Sunshine.service)
and lands the drop-in under ~/.config/systemd/user/<unit>.d/.
- lib/service.sh: enable_sunshine_service calls install_headless_prestart_
dropin when STREAM_MODE=headless. Placed after ensure_sunshine_unit_
present so the unit name is settled when the drop-in is written.
- install.sh: comment noting the drop-in install is deferred to the
service-enable step.
Web UI lockdown + tunnel-friendly certs
- lib/config.sh: emits origin_web_ui_allowed = pc. Sunshine rejects web UI
requests from anywhere other than localhost regardless of bind address.
Streaming/pairing (47989) stays LAN-accessible. Inline comment documents
the SSH tunnel recipe.
- lib/certs.sh: add DNS:localhost and IP:127.0.0.1 to host cert SANs so
the tunneled https://localhost:47990 URL doesn't trigger a hostname
mismatch. Idempotency check now requires those SANs too.
Misc.
- files/sunshine.service: fallback unit also gains the prestart ExecStartPre.
- lib/service.sh: ensure_sunshine_unit_present aliases the reverse-DNS
Sunshine unit as sunshine.service when sunshine-bin's short-name unit
isn't installed.
Headless mode (new) — for KVM-attached hosts streaming to disconnected clients
- --headless / --mirror flags; default headless on hostname JARVIS, mirror elsewhere
- New lib/headless.sh installs prep-cmd hooks to ~/.local/share/omarchy-moonlight/bin
- bin/sunshine-stream-do.sh creates/resizes a Hyprland HEADLESS-1 output to the
connecting client's resolution and migrates the active workspace onto it
- bin/sunshine-stream-undo.sh tears down the headless output on disconnect and
returns the workspace to a non-headless monitor when one is available
- lib/config.sh writes capture=wlr, output_name=HEADLESS-1, and the JSON
global_prep_cmd entry referencing the installed hook paths
- lib/preflight.sh adds a preflight_headless step that checks hyprctl, jq, and
a running Hyprland session (warn-only, install can proceed)
- lib/verify.sh adds checks for the hook scripts and the wlr/global_prep_cmd
config lines
Mac client
- client/install-macos.sh: Darwin guard, Homebrew presence check, brew cask
install of Moonlight, idempotent
- client/README.md: per-platform install (macOS / Android / iOS / Apple TV /
Linux + Steam Deck) and the five-step first-pair walkthrough
Other
- jq added to the helper install set in lib/packages.sh (hooks parse Hyprland
JSON output)
- README.md rewritten to cover both modes, the new flags, the tuned defaults
per mode + per vendor, the headless internals, and the client pointer