citrix-workspace: find the privileged FUSE helper

Redirect Citrix's /usr/bin/fusermount3 calls to the NixOS security
wrapper when it is executable. Preserve the original path on other
systems and document programs.fuse.enable for FUSE-based file transfer.
This commit is contained in:
Austin Horstman
2026-09-17 23:00:49 -05:00
parent 53c42c5840
commit 6a105ae81e
2 changed files with 22 additions and 3 deletions

View File

@@ -16,6 +16,16 @@ To enable it on NixOS:
}
```
For FUSE-based file transfer, enable the privileged helper on NixOS:
```nix
{
programs.fuse.enable = true;
}
```
The package uses `/run/wrappers/bin/fusermount3` when it is available.
## Citrix Self-service {#sec-citrix-selfservice}
The [self-service](https://support.citrix.com/article/CTX200337) is an application for managing Citrix desktops and applications. Please note that this feature only works with at least `citrix_workspace_20_06_0` and later versions.

View File

@@ -263,6 +263,15 @@ stdenv.mkDerivation (finalAttrs: {
]
);
runtimeSetup = ''
export NIX_REDIRECTS="/usr/share/zoneinfo=${tzdata}/share/zoneinfo:/etc/zoneinfo=${tzdata}/share/zoneinfo:/etc/timezone=$ICAROOT/timezone"
# Citrix invokes the FHS helper path; NixOS supplies the privileged wrapper here.
if [ -x /run/wrappers/bin/fusermount3 ]; then
NIX_REDIRECTS="$NIX_REDIRECTS:/usr/bin/fusermount3=/run/wrappers/bin/fusermount3"
fi
'';
# Only the ICA engine needs the top-level client directory on the library
# path. Leaving it enabled for UI helpers exposes Citrix's session-only
# libproxy.so to the embedded web stack, which then fails to resolve CGP
@@ -277,7 +286,7 @@ stdenv.mkDerivation (finalAttrs: {
''--prefix GST_PLUGIN_SYSTEM_PATH_1_0 : "$ICAInstDir/gst-plugins:${gstPluginPath}"''
''--prefix LD_LIBRARY_PATH : "${ldLibraryPath program}"''
''--set LD_PRELOAD "${libredirect}/lib/libredirect.so ${lib.getLib pcsclite}/lib/libpcsclite.so"''
''--set NIX_REDIRECTS "/usr/share/zoneinfo=${tzdata}/share/zoneinfo:/etc/zoneinfo=${tzdata}/share/zoneinfo:/etc/timezone=$ICAInstDir/timezone"''
"--run ${lib.escapeShellArg runtimeSetup}"
]
++ lib.optionals (isWfica program) [
# wfica is an X11 client (it runs under XWayland). On a Wayland
@@ -291,7 +300,7 @@ stdenv.mkDerivation (finalAttrs: {
);
wrap = program: ''
wrapProgram $out/opt/citrix-icaclient/${program} \
wrapProgramShell $out/opt/citrix-icaclient/${program} \
${wrapperArgs program}
'';
@@ -301,7 +310,7 @@ stdenv.mkDerivation (finalAttrs: {
'';
makeBinWrapper = program: wrapperName: ''
makeWrapper $out/opt/citrix-icaclient/${program} $out/bin/${wrapperName} \
makeShellWrapper $out/opt/citrix-icaclient/${program} $out/bin/${wrapperName} \
${wrapperArgs program}
'';