Let a machine say what it is for, and give Firefox its face back

Phase 4: the optional application categories, and the Firefox chrome.

Everything Panama installed until now was what every machine gets, which meant a
work laptop acquired emulators and a desktop that wanted Steam had to be told
about it by hand. The interview now offers the categories in
setup/packages/extras/ as a checklist -- gaming, creative, communication,
virtualization -- and nothing is preselected, because a default here installs
applications nobody chose on a machine whose owner answered a question they
thought was about something else.

A category is one file, and a category mixes both package managers because the
applications do: Steam is in RPM Fusion, Slack publishes only a flatpak. So a
bare line is a dnf package and a flatpak: line is a Flathub ID, and one file
holds the whole answer rather than splitting each category across two. The menu
is read from the directory rather than written down, so adding a category is
adding a file. Every name in all four was resolved against the actual
repositories before being written down, and the contract re-resolves them --
the point of admitting applications one at a time is that they stay installable,
and a typo here fails on somebody else's machine, not this one.

Firefox is declared, and its chrome is Edge-Frfox, vendored into config/firefox.
sunhat carried that theme with no license and no attribution; it is MIT, and now
it says so and says whose it is.

It is the only piece of Panama's configuration that does not go to a path this
repository chooses. Firefox owns the profile directory, names it with a random
salt, and does not create one until the browser has been run -- so link-dotfiles
finds or creates a profile and links both halves into it. Both, or neither works:
chrome/ is the CSS and user.js sets the preference that makes Firefox read chrome/
at all, without which the theme is a directory of dead files.

Two assumptions there were wrong, and the contract exists for both. Firefox has
moved to the XDG directories -- the profile root is ~/.config/mozilla/firefox on
this build, not ~/.mozilla/firefox, and writing to the wrong one themes nothing
and says nothing about it. And -CreateProfile turns out to be non-interactive, so
a fresh machine gets the theme on the first install rather than the second. The
contract runs link-dotfiles for real against a throwaway home with no profile in
it and looks at what came out; it was checked by pointing the search at the
legacy path only and watching it fail.

Also: the enrolment/enrollment spellings from the last commit are corrected. This
repository is US-spelled everywhere else -- color 1131 times against colour never
-- and consistency in prose is worth as much as it is in code.

Claude-Session: https://claude.ai/code/session_01NvgBuSWB5sE43yWmg21ozj
This commit is contained in:
Gabriel Brown
2026-08-20 21:24:15 -04:00
parent b319d1a5e1
commit 88497826ec
168 changed files with 6293 additions and 32 deletions
+6 -6
View File
@@ -4,7 +4,7 @@
# NVIDIA driver, the machine owner key that lets it load under Secure Boot,
# Fedora's preinstalled extras, and firmware.
#
# Runs last. MOK enrolment arms a prompt consumed at the next boot and firmware
# Runs last. MOK enrollment arms a prompt consumed at the next boot and firmware
# updates can ask for a reboot, so neither belongs in front of the package work
# or the dotfiles -- a machine that reboots out of this stage has already been
# fully configured.
@@ -66,7 +66,7 @@ fi
# ── Secure Boot ──────────────────────────────────────────────────────────────
#
# akmods signs the modules it builds with a key it generates on installation.
# Under Secure Boot that key means nothing until it is enrolled, and enrolment
# Under Secure Boot that key means nothing until it is enrolled, and enrollment
# is deliberately a thing only somebody at the physical machine can complete:
# the request is queued here, and the next boot shows a blue screen asking for
# the password before it will trust the key.
@@ -83,7 +83,7 @@ if [[ -n "$mok_hash" ]]; then
cert="${PANAMA_MOK_CERT:-/etc/pki/akmods/certs/public_key.der}"
if [[ ! -r "$cert" ]]; then
warn "No akmods certificate at $cert, so there is no key to enrol"
warn "No akmods certificate at $cert, so there is no key to enroll"
elif mokutil --test-key "$cert" 2>/dev/null | grep -q 'already enrolled'; then
log "The akmods key is already enrolled"
else
@@ -91,10 +91,10 @@ if [[ -n "$mok_hash" ]]; then
chmod 600 "$hash_file"
printf '%s\n' "$mok_hash" >"$hash_file"
if sudo mokutil --import "$cert" --hash-file "$hash_file"; then
log "Key enrolment requested"
log "At the next boot, choose 'Enrol MOK' and enter the password you gave the installer"
log "Key enrollment requested"
log "At the next boot, choose 'Enroll MOK' and enter the password you gave the installer"
else
warn "Key enrolment failed; the NVIDIA module will not load until it is enrolled"
warn "Key enrollment failed; the NVIDIA module will not load until it is enrolled"
fi
rm -f "$hash_file"
fi