Let a machine say what it is for, and give Firefox its face back
Phase 4: the optional application categories, and the Firefox chrome. Everything Panama installed until now was what every machine gets, which meant a work laptop acquired emulators and a desktop that wanted Steam had to be told about it by hand. The interview now offers the categories in setup/packages/extras/ as a checklist -- gaming, creative, communication, virtualization -- and nothing is preselected, because a default here installs applications nobody chose on a machine whose owner answered a question they thought was about something else. A category is one file, and a category mixes both package managers because the applications do: Steam is in RPM Fusion, Slack publishes only a flatpak. So a bare line is a dnf package and a flatpak: line is a Flathub ID, and one file holds the whole answer rather than splitting each category across two. The menu is read from the directory rather than written down, so adding a category is adding a file. Every name in all four was resolved against the actual repositories before being written down, and the contract re-resolves them -- the point of admitting applications one at a time is that they stay installable, and a typo here fails on somebody else's machine, not this one. Firefox is declared, and its chrome is Edge-Frfox, vendored into config/firefox. sunhat carried that theme with no license and no attribution; it is MIT, and now it says so and says whose it is. It is the only piece of Panama's configuration that does not go to a path this repository chooses. Firefox owns the profile directory, names it with a random salt, and does not create one until the browser has been run -- so link-dotfiles finds or creates a profile and links both halves into it. Both, or neither works: chrome/ is the CSS and user.js sets the preference that makes Firefox read chrome/ at all, without which the theme is a directory of dead files. Two assumptions there were wrong, and the contract exists for both. Firefox has moved to the XDG directories -- the profile root is ~/.config/mozilla/firefox on this build, not ~/.mozilla/firefox, and writing to the wrong one themes nothing and says nothing about it. And -CreateProfile turns out to be non-interactive, so a fresh machine gets the theme on the first install rather than the second. The contract runs link-dotfiles for real against a throwaway home with no profile in it and looks at what came out; it was checked by pointing the search at the legacy path only and watching it fail. Also: the enrolment/enrollment spellings from the last commit are corrected. This repository is US-spelled everywhere else -- color 1131 times against colour never -- and consistency in prose is worth as much as it is in code. Claude-Session: https://claude.ai/code/session_01NvgBuSWB5sE43yWmg21ozj
This commit is contained in:
+36
-9
@@ -15,9 +15,8 @@
|
||||
# somebody else could clone. Re-answering a handful of questions costs less than
|
||||
# maintaining an answers file that drifts out of date.
|
||||
#
|
||||
# This asks only what a stage in this repository actually consumes. The extras
|
||||
# checklist arrives with the stage that acts on it; a prompt whose answer nothing
|
||||
# reads is a control that lies.
|
||||
# This asks only what a stage in this repository actually consumes. A prompt
|
||||
# whose answer nothing reads is a control that lies.
|
||||
#
|
||||
# The hardware questions name what was found rather than asking a person to
|
||||
# recite their own machine, and they are not asked at all on a machine they
|
||||
@@ -109,16 +108,16 @@ if [[ -n "$nvidia_card" ]]; then
|
||||
# Only asked where it does something. On a machine with Secure Boot off,
|
||||
# akmods' signature is never checked and enrolling a key is ceremony.
|
||||
if mokutil --sb-state 2>/dev/null | grep -qi 'secureboot enabled'; then
|
||||
printf 'Secure Boot is on, so the driver must be signed with a key you enrol.\n'
|
||||
printf 'Secure Boot is on, so the driver must be signed with a key you enroll.\n'
|
||||
printf 'The next boot will ask for this password on a blue screen.\n'
|
||||
if yes_no "Enrol a machine owner key?"; then
|
||||
if yes_no "Enroll a machine owner key?"; then
|
||||
# Hashed here and only the hash recorded. The password never
|
||||
# reaches the answers file, the environment, or a command line
|
||||
# -- mokutil takes a hash file precisely so it does not have to.
|
||||
while :; do
|
||||
first="$(gum input --password --header "MOK password")"
|
||||
if [[ -z "$first" ]]; then
|
||||
printf 'No password given; skipping enrolment.\n'
|
||||
printf 'No password given; skipping enrollment.\n'
|
||||
break
|
||||
fi
|
||||
second="$(gum input --password --header "MOK password again")"
|
||||
@@ -160,6 +159,33 @@ if command -v fwupdmgr >/dev/null 2>&1; then
|
||||
fi
|
||||
record PANAMA_FIRMWARE "$firmware"
|
||||
|
||||
# ── Applications ─────────────────────────────────────────────────────────────
|
||||
#
|
||||
# Everything else in this repository is what every Panama machine gets. This is
|
||||
# the one question about what this machine is for: a work laptop should not
|
||||
# acquire emulators and a desktop should not skip Steam.
|
||||
#
|
||||
# The categories are read from the directory rather than listed here, so adding
|
||||
# one is adding a file. Nothing is preselected -- a default here would install
|
||||
# applications nobody chose, on a machine whose owner answered a question they
|
||||
# thought was about something else.
|
||||
|
||||
heading "Applications"
|
||||
|
||||
extras_dir="$(dirname "${BASH_SOURCE[0]}")/../packages/extras"
|
||||
extras=""
|
||||
if [[ -d "$extras_dir" ]]; then
|
||||
mapfile -t categories < <(for file in "$extras_dir"/*; do
|
||||
[[ -f "$file" ]] && basename "$file"
|
||||
done)
|
||||
if (( ${#categories[@]} > 0 )); then
|
||||
printf 'Optional application categories. Space to select, enter to accept.\n'
|
||||
extras="$(gum choose --no-limit --header "Extras" "${categories[@]}" | tr '\n' ' ')"
|
||||
extras="${extras% }"
|
||||
fi
|
||||
fi
|
||||
record PANAMA_EXTRAS "$extras"
|
||||
|
||||
# ── Confirm ──────────────────────────────────────────────────────────────────
|
||||
#
|
||||
# The last chance to catch a typo before twenty minutes of package work that
|
||||
@@ -176,9 +202,10 @@ gum style --border rounded --padding "0 1" "$(
|
||||
printf 'GitHub %s\n' "$([[ "$gh_login" == yes ]] && echo "sign in" || echo "no change")"
|
||||
printf 'SSH key %s\n' "$([[ "$ssh_key" == yes ]] && echo "generate" || echo "no change")"
|
||||
printf 'NVIDIA %s\n' "$([[ "$nvidia" == yes ]] && echo "install driver" || echo "no")"
|
||||
printf 'Secure Boot %s\n' "$([[ -n "$mok_hash" ]] && echo "enrol a key" || echo "no change")"
|
||||
printf 'Extras %s\n' "$([[ "$debloat" == yes ]] && echo "remove ${installed[*]}" || echo "keep")"
|
||||
printf 'Firmware %s' "$([[ "$firmware" == yes ]] && echo "update" || echo "no")"
|
||||
printf 'Secure Boot %s\n' "$([[ -n "$mok_hash" ]] && echo "enroll a key" || echo "no change")"
|
||||
printf 'Fedora apps %s\n' "$([[ "$debloat" == yes ]] && echo "remove ${installed[*]}" || echo "keep")"
|
||||
printf 'Firmware %s\n' "$([[ "$firmware" == yes ]] && echo "update" || echo "no")"
|
||||
printf 'Extras %s' "${extras:-none}"
|
||||
)"
|
||||
|
||||
if ! gum confirm --default=true "Install with these answers?"; then
|
||||
|
||||
Reference in New Issue
Block a user