Environment variables¶
These variables change how Dangerzone behaves. Most of them exist for development and testing. None of them is needed for normal use.
DANGERZONE_DEV- Set to
1to run Dangerzone from a source tree. Resources are looked up undershare/in the checkout instead of the installed locations, and development-only behaviour is enabled (such as the hidden--unsafe-dummy-conversionCLI flag andQUBES_CONVERSION). All the build from source guides set it. DANGERZONE_BYPASS_SIG_CHECKS- Only honoured together with
DANGERZONE_DEV=1. Set to1to skip the Cosign signature verification of the sandbox image. Meant for testing a locally built, unsigned image stored inshare/container.tar. See Use a local container image. DANGERZONE_INSECURE_CONVERTER_PATH- Qubes OS development only. Path to a checkout of the
dangerzone-imagerepository (itssrcdirectory). The server-side conversion code is sent to the disposable qube through thedz.ConvertDevRPC call on each conversion, so changes are picked up without rebuilding the RPM. See Build from source on Qubes OS. QUBES_CONVERSION- Qubes OS development only, and only honored together with
DANGERZONE_DEV=1. Set to1to convert documents in disposable qubes instead of containers when running from source inside a qube. Installed Qubes builds detect this on their own. SIGSTORE_REKOR_PUBLIC_KEY- Path to a Rekor public key that replaces the one bundled in
share/rekor.pub, used to verify the transparency log entries of the sandbox image signatures. Only needed if Sigstore rotates its key before a Dangerzone release ships the new one. See Configure the verification material.
Variables set by Dangerzone¶
Dangerzone also sets a few variables for the processes it starts. They are listed here so that they are not a surprise:
OMP_NUM_THREADS,OMP_THREAD_LIMIT- Limit the threads used by Tesseract during OCR.
QT_MAC_WANTS_LAYER- Set on macOS for the Qt graphical toolkit.
IS_WORKER_PROCESS- Marks the OCR worker processes spawned by the application.