Skip to content

[FEAT] Add option to disable all window control buttons #186

Description

@alandooz

Is this a new feature request?

  • I have searched the existing issues

Wanted change

Add an option to disable all window control buttons (minimize/iconify, maximize/restore, and close), rather than only the close button.

Currently HARDEN_OPENBOX=true sets DISABLE_CLOSE_BUTTON=true, which removes only the close button.

It would be useful to have these two:

  • add a new environment variable such as DISABLE_WINDOW_BUTTONS=true, which removes minimize, maximize/restore, and close;
  • extend the existing hardening behavior so HARDEN_OPENBOX=true removes all three window control buttons.

Ideally this should behave consistently on both Openbox/Xorg and labwc/Wayland.

Reason for change

When using Selkies containers as a locked-down application interface, removing only the close button still allows users to minimize or change the maximized state of the application.

For hardened/single-application deployments, users should not be able to manipulate the application window through any of the standard title-bar controls.

Removing all three controls would make HARDEN_OPENBOX more complete and would prevent users from minimizing, restoring/unmaximizing, or closing the application from the title bar while still keeping the window decoration/title bar itself.

Proposed code change

A possible implementation would be to introduce DISABLE_WINDOW_BUTTONS.

For Openbox, the current close-button handling:

if [[ "${DISABLE_CLOSE_BUTTON,,}" == "true" ]]; then
  echo "[ls.io-init] Disabling close button"
  sed -i '/<titleLayout>/s/C//' "$SYS_RC_XML"
fi

could be extended with something like:

if [[ "${DISABLE_WINDOW_BUTTONS,,}" == "true" ]]; then
  echo "[ls.io-init] Disabling window buttons"
  sed -i '/<titleLayout>/s/[IMC]//g' "$SYS_RC_XML"
fi

where I, M, and C correspond to iconify/minimize, maximize, and close.

For labwc/Wayland, the default titlebar layout is:

<layout>icon:iconify,max,close</layout>

so the same option could remove iconify, max, and close, while retaining the application icon/titlebar.

HARDEN_OPENBOX=true could then set:

export DISABLE_WINDOW_BUTTONS="true"

instead of, or in addition to, DISABLE_CLOSE_BUTTON="true".

Keeping DISABLE_CLOSE_BUTTON separately may be preferable for backwards compatibility and for users who only want to hide Close.

Activity

  1. github-actions commented on Aug 22, 2026

    @github-actions

    Thanks for opening your first issue here! Be sure to follow the relevant issue templates, or risk having this issue marked as invalid.

  2. junkerderprovinz commented on Sep 3, 2026

    @junkerderprovinz
    Contributor

    Your [IMC] sed is exactly right for the openbox side, so most of this is wiring your own sketch into the right files. Two details matter in practice.

    On openbox, /etc/xdg/openbox/rc.xml is not always the file that counts: with HARDEN_OPENBOX=true the init copies the system rc.xml to /config/.config/openbox/rc.xml and locks it, and openbox-session prefers that user copy. On Wayland the labwc layout token is max, as your issue text already says, and with hardening on the init has usually stripped close from that line before any custom script sees it, so a literal replacement of the default string quietly misses too.

    Until something lands in the image, a /custom-cont-init.d script covers it per container (it runs after the image's own config init, before the desktop starts):

    #!/bin/bash
    # /custom-cont-init.d/90-no-window-buttons (mounted executable)
    for f in /etc/xdg/openbox/rc.xml /config/.config/openbox/rc.xml; do
      [ -f "$f" ] && sed -i '/<titleLayout>/s/[IMC]//g' "$f"
    done
    if [ -f /config/.config/labwc/rc.xml ]; then
      # anchor on the tag: the image init may already have stripped "close"
      sed -i "s|<layout>[^<]*</layout>|<layout>icon:</layout>|" /config/.config/labwc/rc.xml
    fi

    A DISABLE_WINDOW_BUTTONS=true inside init-selkies-config would be the same substitutions next to the existing DISABLE_CLOSE_BUTTON blocks. On your second bullet, I would keep it a separate variable rather than folding it into HARDEN_OPENBOX, since changing what that removes would alter existing deployments that rely on minimize staying available. Happy to send it as a small PR if the maintainers want it.

  3. thelamer commented on Oct 3, 2026

    @thelamer
    Member

    This is in all bases now.

  4. moved this from Issues to Done in Issue & PR Trackeron Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions