Let a machine say what it is for, and give Firefox its face back
Phase 4: the optional application categories, and the Firefox chrome. Everything Panama installed until now was what every machine gets, which meant a work laptop acquired emulators and a desktop that wanted Steam had to be told about it by hand. The interview now offers the categories in setup/packages/extras/ as a checklist -- gaming, creative, communication, virtualization -- and nothing is preselected, because a default here installs applications nobody chose on a machine whose owner answered a question they thought was about something else. A category is one file, and a category mixes both package managers because the applications do: Steam is in RPM Fusion, Slack publishes only a flatpak. So a bare line is a dnf package and a flatpak: line is a Flathub ID, and one file holds the whole answer rather than splitting each category across two. The menu is read from the directory rather than written down, so adding a category is adding a file. Every name in all four was resolved against the actual repositories before being written down, and the contract re-resolves them -- the point of admitting applications one at a time is that they stay installable, and a typo here fails on somebody else's machine, not this one. Firefox is declared, and its chrome is Edge-Frfox, vendored into config/firefox. sunhat carried that theme with no license and no attribution; it is MIT, and now it says so and says whose it is. It is the only piece of Panama's configuration that does not go to a path this repository chooses. Firefox owns the profile directory, names it with a random salt, and does not create one until the browser has been run -- so link-dotfiles finds or creates a profile and links both halves into it. Both, or neither works: chrome/ is the CSS and user.js sets the preference that makes Firefox read chrome/ at all, without which the theme is a directory of dead files. Two assumptions there were wrong, and the contract exists for both. Firefox has moved to the XDG directories -- the profile root is ~/.config/mozilla/firefox on this build, not ~/.mozilla/firefox, and writing to the wrong one themes nothing and says nothing about it. And -CreateProfile turns out to be non-interactive, so a fresh machine gets the theme on the first install rather than the second. The contract runs link-dotfiles for real against a throwaway home with no profile in it and looks at what came out; it was checked by pointing the search at the legacy path only and watching it fail. Also: the enrolment/enrollment spellings from the last commit are corrected. This repository is US-spelled everywhere else -- color 1131 times against colour never -- and consistency in prose is worth as much as it is in code. Claude-Session: https://claude.ai/code/session_01NvgBuSWB5sE43yWmg21ozj
This commit is contained in:
@@ -4,7 +4,7 @@
|
||||
#
|
||||
# This stage cannot be verified the way the rest of Panama is. It installs a
|
||||
# proprietary driver, rewrites kernel arguments and queues a Secure Boot
|
||||
# enrolment, and the machine it was written on is an AMD desktop with no NVIDIA
|
||||
# enrollment, and the machine it was written on is an AMD desktop with no NVIDIA
|
||||
# card in it. Running it to see what happens is not available.
|
||||
#
|
||||
# So every privileged command it can reach is stood in on PATH, and the contract
|
||||
@@ -132,19 +132,19 @@ hash='$6$notarealsalt$notarealhashvalue'
|
||||
mok="$(run_stage PANAMA_MOK_HASH="$hash" PANAMA_MOK_CERT="$cert")"
|
||||
|
||||
called "$mok" 'mokutil --import' \
|
||||
|| note 'a recorded MOK hash does not queue an enrolment'
|
||||
|| note 'a recorded MOK hash does not queue an enrollment'
|
||||
called "$mok" -- '--hash-file' \
|
||||
|| note 'the enrolment does not pass a hash file, so mokutil would prompt for a password'
|
||||
|| note 'the enrollment does not pass a hash file, so mokutil would prompt for a password'
|
||||
if grep -qF -- "$hash" <<<"$mok"; then
|
||||
note 'the MOK hash is passed on a command line where any process can read it'
|
||||
fi
|
||||
|
||||
# No certificate means akmods never generated a key. Requesting enrolment of a
|
||||
# No certificate means akmods never generated a key. Requesting enrollment of a
|
||||
# key that does not exist is worse than skipping: it queues a prompt at the next
|
||||
# boot for nothing.
|
||||
without_cert="$(run_stage PANAMA_MOK_HASH="$hash" PANAMA_MOK_CERT="$work/absent.der")"
|
||||
if called "$without_cert" 'mokutil --import'; then
|
||||
note 'enrolment is requested even with no akmods certificate to enrol'
|
||||
note 'enrollment is requested even with no akmods certificate to enroll'
|
||||
fi
|
||||
|
||||
# ── 4. Removal is honest about what it removes ───────────────────────────────
|
||||
|
||||
Reference in New Issue
Block a user