OpenScreen
OpenScreen is an open-source desktop screen recorder and video editor with built-in cursor telemetry, auto-zoom, local Whisper captions, and GPU compositing.
Host Availability
OpenScreen is defined in modules/tools/openscreen.nix and enabled exclusively on the workstation host titan (modules/hosts/titan.nix):
programs.openscreen.enable = true;
It is disabled by default across all other hosts in modules/hosts/_common.nix.
GPU Acceleration on Linux
The Encoder Ladder
OpenScreen's Linux pipeline uses an automatic capability ladder for recording and MP4 export:
- VAAPI (
h264_vaapi): Hardware acceleration via VA-API. - Vulkan (
h264_vulkan): Hardware acceleration via Vulkan video encode queues. - Software (
libopenh264): CPU software encoding fallback.
Titan (AMD GPU) vs Laptop (ixo without discrete GPU)
- On
titan: Titan is equipped with an AMD Radeon GPU running Mesa drivers withhardware.graphics.enable = true;. The driver exposes VA-API hardware encoding (radeonsi_drv_video.so), and uservorburgeris a member of therendergroup with access to/dev/dri/renderD128. OpenScreen automatically selectsh264_vaapifor both real-time capture and MP4 export. - On a host without a GPU (e.g.
ixo): OpenScreen dynamically probes encoder capabilities at launch. If no hardware encoder is found or initialisation fails, it transparently falls back tolibopenh264(software encoding) without crashing or requiring distinct host configuration. - Overriding the Encoder:
To force a specific backend or verify selection:
OPENSCREEN_LINUX_ENCODER=vaapi openscreen # or force software encoding: OPENSCREEN_LINUX_ENCODER=software openscreen
Mouse Click Telemetry & Security
Why Click Capture Needs Special Permissions on Wayland
Wayland intentionally isolates input events between windows for security. The Wayland ScreenCast portal provides cursor position, but does not stream button presses. To draw click animations and ripple effects, OpenScreen reads left mouse button presses (BTN_LEFT) from the Linux kernel evdev interface (/dev/input/event*).
The Security Hazard of the input Group
Upstream documentation suggests adding the user to the input group:
sudo usermod -aG input $USER
Adding your user to the input group grants every process running under your user account (browsers, shell scripts, third-party dependencies, IDE extensions) permission to read every device node in /dev/input/, including all keyboards. This introduces a persistent keylogger vulnerability.
Threat Profile Comparison
| Capability | Default Wayland | With Mouse udev uaccess |
With Scoped setgid Binary | With sudo usermod -aG input |
|---|---|---|---|---|
| Keystrokes / Passwords | π Blocked | π Blocked | β οΈ Exposes attack surface (helper has group input) |
π¨ Exposed to all user apps |
| Global Mouse Clicks | π Blocked | β οΈ Readable by user apps | π Blocked (only helper reads it) | β οΈ Readable by user apps |
| Relative Mouse Motion | π Blocked | β οΈ Readable by user apps | π Blocked (only helper reads it) | β οΈ Readable by user apps |
| Synthetic Click Injection | π Blocked | π Blocked | π Blocked | π Blocked |
| Device Grab / Freeze | π Blocked | β οΈ Possible via ioctl |
π Blocked | β οΈ Possible via ioctl |
Architectural Decision: udev vs. setgid Wrapper
When securing click capture, two technical routes exist:
- Targeted udev
uaccess(Recommended): Dynamically grant the active desktop seat user access strictly to mouse character devices (ENV{ID_INPUT_KEYBOARD}!="1"). - Scoped setgid Wrapper: Create a setgid wrapper binary (
owner = "root",group = "input", mode2750) so only the helper binary acquires groupinput.
Why the udev Route is Recommended
We recommend and implement the targeted udev approach as a closed architectural choice:
- Zero Privileged Binaries: The setgid approach introduces a setgid binary on disk. Even though setgid does not elevate UID to root, it grants the helper executable permission to read all
inputdevicesβincluding physical keyboards. If that helper binary ever has a memory safety bug or vulnerability, it could be leveraged to snoop on keyboards. - Kernel-Level Keyboard Exclusion: The udev approach enforces hardware device isolation at the kernel level (
ENV{ID_INPUT_KEYBOARD}!="1"). Even if userspace is compromised, the kernel refuses to open keyboard event character devices. - Native Desktop Integration: It leverages standard
systemd-logindseat management, matching how cameras, audio devices, and GPUs are exposed to desktop sessions.
Enabling Click Capture Safely
OpenScreen works completely out of the box without click capture (default). If click animations are desired, enable the safe udev rule via:
programs.openscreen.captureMouseClicks = true;
This deploys:
KERNEL=="event*", SUBSYSTEM=="input", ENV{ID_INPUT_MOUSE}=="1", ENV{ID_INPUT_KEYBOARD}!="1", TAG+="uaccess"
Systemd's logind assigns dynamic POSIX ACLs (setfacl) on mouse devices for the active desktop seat session while leaving keyboards strictly protected.