Jump to content

Chromium/zh: Difference between revisions

From Official NixOS Wiki
Ardenet (talk | contribs)
Created page with "== 使用 libc 内存分配器 =="
Tags: Mobile edit Mobile web edit
Ardenet (talk | contribs)
Created page with "* $homepageLocation 选项允许您设置主页打开的网站。 * $extensions 允许您通过一个简单的扩展程序 ID 列表直接在浏览器中下载扩展程序。该列表可以从 [$1 Chrome 网上应用商店] 获取,通过打开扩展程序页面并复制 URL 的最后一部分。 ** 然而,示例中还有另一个组件,即扩展程序的下载源。 ** 列表中提供的 URL 是 Google 用于管理、检查和更新扩展程序的链接。 **..."
Line 10: Line 10:
== 更新浏览器政策 ==
== 更新浏览器政策 ==


<div lang="en" dir="ltr" class="mw-content-ltr">
Chromium 中,可以通过 {{Ic|chrome://policy}} 访问政策设置。用户可以使用这些设置更改影响企业政策的各种功能,例如
In Chromium, policy settings are accessible via {{Ic|chrome://policy}}. They allow the user to change enterprise policies affecting things like
</div>


<div lang="en" dir="ltr" class="mw-content-ltr">
* 安装浏览器时自动创建 Web 应用
* Creating webapps when the browser is installed
* 自动查找并下载浏览器扩展程序
* Finding and downloading browser extensions automatically
* 设备离线时启用或禁用恐龙游戏
* Enabling or disabling the dinosaur game when the device is offline
* 禁用浏览器扩展程序截屏功能
* Disable screenshots to be taken with browser extensions
* 阻止浏览器进行所有下载(如果您出于某种原因需要这样做)
* Block all downloads from the browser (if you want to do that for some reason)
* 以及更多!
* and more!
</div>


<div lang="en" dir="ltr" class="mw-content-ltr">
<div lang="en" dir="ltr" class="mw-content-ltr">
Line 30: Line 26:
=== 原生支持的政策 ===
=== 原生支持的政策 ===


<div lang="en" dir="ltr" class="mw-content-ltr">
NixOS 默认提供了一些可以直接启用的政策,下面给出一个简单的示例来理解这些政策的实现方式。
By default NixOS provides a few policies that can be enabled directly, a simple example is given below to understand how these are implemented
</div>


<syntaxhighlight lang="nixos" line="1">  programs.chromium = {
<syntaxhighlight lang="nixos" line="1">  programs.chromium = {
Line 53: Line 47:
   };</syntaxhighlight>
   };</syntaxhighlight>


<div lang="en" dir="ltr" class="mw-content-ltr">
* {{Ic|homepageLocation}} 选项允许您设置主页打开的网站。
* {{Ic|homepageLocation}} option allows you to set the site that the homepage will open on
 
* {{Ic|extensions}} allows for the download of extensions directly in the browser through a simple list of the extension ID's that can be obtained from the [https://chromewebstore.google.com/ Chrome Web Store] by opening an extension page and copying the last part of the URL
* {{Ic|extensions}} 允许您通过一个简单的扩展程序 ID 列表直接在浏览器中下载扩展程序。该列表可以从 [https://chromewebstore.google.com/ Chrome 网上应用商店] 获取,通过打开扩展程序页面并复制 URL 的最后一部分。
** In the example however there is another component, the download source from which the extensions will be downloaded
 
** The URL provided in the list is the link that is used by google for managing, checking and updating extensions
** 然而,示例中还有另一个组件,即扩展程序的下载源。
** So the method of just placing the extension ID can work like this: {{Ic|"fnpbehpgglbfnpimkachnpnecjncndgm"}}
 
** But just in case that method does not automatically function the second method is shown above, where you place {{Ic|;}} and then the URL {{Ic|https //clients2.google.com/service/update2/crx}} to explicitly tell NixOS where to install the extension from
** 列表中提供的 URL 是 Google 用于管理、检查和更新扩展程序的链接。
* There are many more options that are natively supported and you can learn about them through {{Ic|man configuration.nix}}
 
* But as shown above there is also an {{Ic|extraOpts}} option and that is used for policies that are not supported for direct setup, such as the policy to install web-apps
** 因此,只需放置扩展程序 ID 的方法即可工作,如下所示:{{Ic|"fnpbehpgglbfnpimkachnpnecjncndgm"}}
</div>
 
** 但以防该方法无法自动生效,上面显示了第二种方法,您需要放置 {{Ic|;}},然后放置 URL {{Ic|https //clients2.google.com/service/update2/crx}},以明确告诉 NixOS 从哪里安装扩展程序。
 
* 还有许多其他原生支持的选项,您可以通过 {{Ic|man configuration.nix}} 了解它们。
 
* 但如上所示,还有一个 {{Ic|extraOpts}} 选项,用于不支持直接设置的政策,例如安装网络应用程序的政策。


<span id="Non-natively_Supported_Policies"></span>
<span id="Non-natively_Supported_Policies"></span>
Line 159: Line 158:
== 使用 libc 内存分配器 ==
== 使用 libc 内存分配器 ==


<div lang="en" dir="ltr" class="mw-content-ltr">
当使用诸如 scudo 之类的其他系统级内存分配器时,Chromium 可能无法正常工作。要在 Chromium 上使用 libc,需要以下 firejail 封装:
Chromium may not work when an alternative system-wide memory allocator like scudo is used. To use libc on Chromium, the following firejail wrap is required:
</div>


<syntaxhighlight lang="nix">
<syntaxhighlight lang="nix">

Revision as of 16:03, 31 May 2026

安裝

NixOS

添加 chromiumsystemPackages

更新瀏覽器政策

在 Chromium 中,可以通過 chrome://policy 訪問政策設置。用戶可以使用這些設置更改影響企業政策的各種功能,例如

  • 安裝瀏覽器時自動創建 Web 應用
  • 自動查找並下載瀏覽器擴展程序
  • 設備離線時啟用或禁用恐龍遊戲
  • 禁用瀏覽器擴展程序截屏功能
  • 阻止瀏覽器進行所有下載(如果您出於某種原因需要這樣做)
  • 以及更多!

A full list of policies can be found at Chrome Enterprise Policy List & Management.

原生支持的政策

NixOS 默認提供了一些可以直接啟用的政策,下面給出一個簡單的示例來理解這些政策的實現方式。

  programs.chromium = {
    enable = true;
    homepageLocation = "https://www.startpage.com/";
    extensions = [
      "eimadpbcbfnmbkopoojfekhnkhdbieeh;https://clients2.google.com/service/update2/crx" # dark reader
      "aapbdbdomjkkjkaonfhkkikfgjllcleb;https://clients2.google.com/service/update2/crx" # google translate
    ];
    extraOpts = {
      "WebAppInstallForceList" = [
        {
          "custom_name" = "Youtube";
          "create_desktop_shortcut" = false;
          "default_launch_container" = "window";
          "url" = "https://youtube.com";
        }
      ];
    };
  };
  • homepageLocation 選項允許您設置主頁打開的網站。
  • extensions 允許您通過一個簡單的擴展程序 ID 列表直接在瀏覽器中下載擴展程序。該列表可以從 Chrome 網上應用商店 獲取,通過打開擴展程序頁面並複製 URL 的最後一部分。
    • 然而,示例中還有另一個組件,即擴展程序的下載源。
    • 列表中提供的 URL 是 Google 用於管理、檢查和更新擴展程序的鏈接。
    • 因此,只需放置擴展程序 ID 的方法即可工作,如下所示:"fnpbehpgglbfnpimkachnpnecjncndgm"
    • 但以防該方法無法自動生效,上面顯示了第二種方法,您需要放置 ;,然後放置 URL https //clients2.google.com/service/update2/crx,以明確告訴 NixOS 從哪裡安裝擴展程序。
  • 還有許多其他原生支持的選項,您可以通過 man configuration.nix 了解它們。
  • 但如上所示,還有一個 extraOpts 選項,用於不支持直接設置的政策,例如安裝網絡應用程序的政策。

非原生支持的政策

There are hundreds of policies in Chromium based browsers, and not all have direct methods to set them. The extraOpts option allows for the declaration of all the other policies.

There is no single place to find all Chromium policies, but these are some places to look;

  • Commonly used policies are present and documented within man configuration.nix under programs.chromium.
  • You can navigate to chrome://policy and enable "Show policies with no value set" to see all available keys. Clicking a policy name opens its specific definition and usage details.
  • The most up to date policies for Chromium are available in the source code.

視頻播放加速

請確保系統已正確設置 視頻播放加速。檢查 chrome://gpu 以查看 Chromium 是否已啟用硬件加速。

如果視頻播放加速不起作用,請檢查 chrome://flags 中的相關標誌,或使用 CLI 啟用它們:

❄︎ /etc/nixos/configuration.nix
{
  environment.systemPackages = with pkgs; [
    (chromium.override {
      commandLineArgs = [
        "--enable-features=AcceleratedVideoEncoder"
        "--ignore-gpu-blocklist"
        "--enable-zero-copy"
      ];
    })
  ];
}

在某些情況下,chrome://gpu 將顯示「視頻解碼(Video Decode)」已啟用,但「視頻加速信息(Video Acceleration Information)」為空,此時 chrome://media-internals 使用的是 FFmpeg 視頻解碼器(軟件解碼)。如果出現這種情況,請嘗試啟用以下功能:

❄︎ /etc/nixos/configuration.nix
{
  environment.systemPackages = with pkgs; [
    (chromium.override {
      commandLineArgs = [
        "--enable-features=AcceleratedVideoEncoder,VaapiOnNvidiaGPUs,VaapiIgnoreDriverChecks,Vulkan,DefaultANGLEVulkan,VulkanFromANGLE"
        "--enable-features=VaapiIgnoreDriverChecks,VaapiVideoDecoder,PlatformHEVCDecoderSupport"
        "--enable-features=UseMultiPlaneFormatForHardwareVideo"
        "--ignore-gpu-blocklist"
        "--enable-zero-copy"
      ];
    })
  ];
}

啟用原生 Wayland 支持

您可以通過將 `NIXOS_OZONE_WL` 環境變量設置為 `1`,在所有基於 Chromium 的應用程序和大多數 Electron 應用程序中啟用原生 Wayland 支持。

啟用 DRM(Widevine 支持)

默認情況下,chromium 不支持播放受 DRM 保護的媒體。但是,可以通過構建時標誌來包含來自 Nixpkgs 的專有 Widevine blob:

❄︎ /etc/nixos/configuration.nix
{
  environment.systemPackages = with pkgs; [
    (chromium.override { enableWideVine = true; })
  ];
}

Flatpak 中的 KeePassXC 支持

要在 Flatpak 環境下運行 KeePassXC 和基於 Chromium 的瀏覽器時啟用瀏覽器集成,請配置以下文件系統訪問權限:

# NativeMessagingHost directory (browser-specific)
# Brave Browser
xdg-config/BraveSoftware/Brave-Browser/NativeMessagingHosts:ro
# Chromium
xdg-config/chromium/NativeMessagingHosts:ro
# Google Chrome
xdg-config/google-chrome/NativeMessagingHosts:ro

# KeePassXC server socket and Nix store
xdg-run/app/org.keepassxc.KeePassXC/org.keepassxc.KeePassXC.BrowserServer
/nix/store:ro

使用 libc 內存分配器

當使用諸如 scudo 之類的其他系統級內存分配器時,Chromium 可能無法正常工作。要在 Chromium 上使用 libc,需要以下 firejail 封裝:

programs.firejail = {
  enable = true;
  wrappedBinaries = {
    chromium = {
      executable = "${pkgs.chromium}/bin/chromium-browser";
      profile = "${pkgs.firejail}/etc/firejail/chromium-browser.profile";
      extraArgs = [
        "--blacklist=/etc/ld-nix.so.preload"
      ];
    };
  };
};