The installation script had a critical bug where it created the config directory in the script runner's home directory instead of the target user's home directory. This caused "permission denied" errors when the systemd service tried to run as the target user. Changes: - Fixed CONFIG_DIR to use $TARGET_HOME instead of $HOME - Updated config path replacements to use $TARGET_HOME - Added ownership change after config creation when running as different user - Created fix_talkkonnect_permissions.sh script to repair existing installations - Added comprehensive TALKKONNECT_SETUP.md with troubleshooting guide This fixes the "open /home/user/.config/talkkonnect/talkkonnect.xml: permission denied" error.
7.1 KiB
TalkKonnect Mumble Client Setup Guide
This guide will help you set up TalkKonnect as a headless Mumble client on your kiosk.
The Permission Issue (FIXED)
The original installation script had a bug where it created the configuration directory in the script runner's home directory instead of the target user's home directory. This caused a "permission denied" error when the service tried to run.
The fix has been applied to talkkonnect_complete_install.sh
Quick Fix for Existing Installations
If you already ran the installation and got the permission error, run this:
sudo ./fix_talkkonnect_permissions.sh
This will:
- Move the config to the correct user's home directory
- Fix all file permissions and ownership
- Verify your systemd service configuration
Fresh Installation
For a new installation, simply run:
./talkkonnect_complete_install.sh
When prompted, enter the username that should run talkkonnect (e.g., user or kiosk).
The script will now:
- Install all dependencies
- Build talkkonnect with the correct Opus library fixes
- Create the config in the TARGET user's home directory (FIXED)
- Set proper ownership and permissions (FIXED)
- Set up the systemd service to run as the target user
Configuration
After installation, edit the configuration file:
# If you're the target user:
nano ~/.config/talkkonnect/talkkonnect.xml
# If talkkonnect runs as a different user (e.g., 'user'):
sudo nano /home/user/.config/talkkonnect/talkkonnect.xml
Required Settings
Update these fields in the XML:
<serverandport>your.mumble.server:64738</serverandport>
<username>your_username</username>
<password>your_password</password>
<channel>Root</channel>
Self-Signed Certificates
If your Mumble server uses a self-signed certificate, set:
<insecure>true</insecure>
Voice Activation vs PTT
Voice Activation (Default):
<voiceactivity enabled="true">
<settings threshold="0.3" holdtimems="1000" holdtimeoutms="2000"/>
</voiceactivity>
<ptt enabled="false"/>
Push-to-Talk with USB Keyboard:
<voiceactivity enabled="false"/>
<ptt enabled="true">
<usbkeyboard enabled="true" device="/dev/input/event0" keycode="KEY_F13"/>
</ptt>
To find your USB keyboard device:
sudo evtest
Testing
Manual Test
Before enabling the service, test manually:
# If running as yourself:
/usr/local/bin/talkkonnect -config ~/.config/talkkonnect/talkkonnect.xml
# If running as a different user (e.g., 'user'):
sudo -u user /usr/local/bin/talkkonnect -config /home/user/.config/talkkonnect/talkkonnect.xml
You should see:
- Connection to Mumble server
- Join the specified channel
- No permission errors
Common Errors
"permission denied" on config file:
- Run
./fix_talkkonnect_permissions.sh - OR manually:
sudo chown -R user:user /home/user/.config/talkkonnect
"unable to unmute" errors:
- This is usually non-fatal; audio may still work
- Check:
amixer scontrols
Connection refused:
- Check your
<serverandport>setting - Verify firewall allows outbound connections on port 64738
Certificate errors:
- Set
<insecure>true</insecure>for self-signed certs
Systemd Service (if available)
If your system uses systemd:
# Enable and start
sudo systemctl enable talkkonnect
sudo systemctl start talkkonnect
# Check status
sudo systemctl status talkkonnect
# View logs
journalctl -u talkkonnect -f
Docker/Non-Systemd Environments
If you're running in Docker or without systemd, run talkkonnect directly:
# Create a simple start script
cat > ~/start-talkkonnect.sh << 'EOF'
#!/bin/bash
/usr/local/bin/talkkonnect -config ~/.config/talkkonnect/talkkonnect.xml
EOF
chmod +x ~/start-talkkonnect.sh
# Run it
./start-talkkonnect.sh
Or run in the background:
nohup /usr/local/bin/talkkonnect -config ~/.config/talkkonnect/talkkonnect.xml > ~/talkkonnect.log 2>&1 &
Audio Configuration
ALSA (Direct)
Best for single-application use:
<input>
<settings enabled="true" device="hw:0,0" samplerate="48000" channels="1"/>
</input>
<output>
<settings enabled="true" device="hw:0,0" samplerate="48000" channels="1"/>
</output>
PulseAudio/PipeWire
Best for multi-application use:
<input>
<settings enabled="true" device="default" samplerate="48000" channels="1"/>
</input>
<output>
<settings enabled="true" device="default" samplerate="48000" channels="1"/>
</output>
List available devices:
aplay -L # List output devices
arecord -L # List input devices
Programmatic Channel Switching
TalkKonnect can join a specific channel on connect by setting:
<channel>Your/Channel/Path</channel>
Use / to separate nested channels:
Root- joins root channelGeneral- joins General channelGeneral/Support- joins Support subchannel under General
To switch channels at runtime, TalkKonnect has an API you can enable:
<api enabled="true">
<listenport>8011</listenport>
</api>
Then use HTTP requests to control it:
# Switch channel
curl http://localhost:8011/api/channel?channel=General/Support
Troubleshooting
View Logs
# Config file log
cat ~/.config/talkkonnect/talkkonnect.log
# Systemd logs (if applicable)
journalctl -u talkkonnect -f
# Manual run (shows errors directly)
/usr/local/bin/talkkonnect -config ~/.config/talkkonnect/talkkonnect.xml
Common Issues
-
No audio input/output:
- Check
aplay -landarecord -l - Verify user is in
audiogroup:groups - Test audio:
speaker-testorarecord -d 5 test.wav && aplay test.wav
- Check
-
Can't access /dev/input devices (for PTT):
- Verify user is in
inputgroup:groups - May need to log out and back in after adding to group
- Verify user is in
-
Connection drops frequently:
- Check network stability
- Increase keepalive timeouts in config
- Check server logs
-
Permissions errors:
- Run
./fix_talkkonnect_permissions.sh - Verify config directory ownership:
ls -la ~/.config/talkkonnect
- Run
Files and Locations
- Binary:
/usr/local/bin/talkkonnect - Config:
~/.config/talkkonnect/talkkonnect.xml - Logs:
~/.config/talkkonnect/talkkonnect.log - Service:
/etc/systemd/system/talkkonnect.service(if using systemd) - Source:
~/talkkonnect
Security Notes
- Config file contains your Mumble password in plain text
- Protect it:
chmod 600 ~/.config/talkkonnect/talkkonnect.xml - Consider using certificate-based authentication instead of passwords
- For production, use proper systemd hardening options
Next Steps
- ✅ Fix permissions (if needed):
./fix_talkkonnect_permissions.sh - ✅ Edit config:
nano ~/.config/talkkonnect/talkkonnect.xml - ✅ Test manually first
- ✅ Enable systemd service (if applicable)
- ✅ Configure audio ducking for multi-app environments (optional)
- ✅ Set up API for programmatic control (optional)
References
- TalkKonnect GitHub
- Mumble Protocol
- Config file path:
~/.config/talkkonnect/talkkonnect.xml