Merge quattro into the Chromium first-run EULA branch
Quattro stopped making the Chromium managed-policy directory world-writable while this branch was open, and the block it deleted from the theme install leaf sat directly above the comment this branch rewrites, so the two edits landed in one hunk. The resolution keeps the hardening — the policy directory is set up through install/config/browser-policy.sh now — along with the first-run seed and the comment that names both things the seed does.
This commit is contained in:
@@ -1,4 +1,5 @@
|
||||
run_logged "$OMARCHY_INSTALL/config/theme-system.sh"
|
||||
run_logged "$OMARCHY_INSTALL/config/browser-policy.sh"
|
||||
run_logged "$OMARCHY_INSTALL/config/increase-lockout-limit.sh"
|
||||
run_logged "$OMARCHY_INSTALL/config/lockscreen-pam.sh"
|
||||
run_logged "$OMARCHY_INSTALL/config/fix-powerprofilesctl-shebang.sh"
|
||||
|
||||
@@ -0,0 +1,2 @@
|
||||
source "$OMARCHY_PATH/install/helpers/browser-policy.sh"
|
||||
browser_policy_setup_dir /etc/chromium/policies/managed
|
||||
@@ -6,10 +6,6 @@ ln -snf /usr/share/icons/Adwaita/symbolic/actions/go-next-symbolic.svg \
|
||||
/usr/share/icons/Yaru/scalable/actions/go-next-symbolic.svg
|
||||
gtk-update-icon-cache /usr/share/icons/Yaru &>/dev/null || true
|
||||
|
||||
# Chromium policy directory for theme
|
||||
mkdir -p /etc/chromium/policies/managed
|
||||
chmod a+rw /etc/chromium/policies/managed
|
||||
|
||||
# Seed Chromium's first run: follow system appearance ("device") instead of dark,
|
||||
# and skip the terms-of-service dialog Chromium 151 turned on by default.
|
||||
mkdir -p /usr/lib/chromium
|
||||
|
||||
@@ -25,6 +25,10 @@ run_logged "$OMARCHY_INSTALL/hardware/intel/fred.sh"
|
||||
run_logged "$OMARCHY_INSTALL/hardware/intel/fix-wifi7-eht.sh"
|
||||
run_logged "$OMARCHY_INSTALL/hardware/intel/sof-firmware.sh"
|
||||
|
||||
# Rebuilds the boot image, so it has to follow the Panther Lake kernel swap
|
||||
# above rather than sit with the other Dell leaf at the top of this file.
|
||||
run_logged "$OMARCHY_INSTALL/hardware/dell-xps13-sidecar-amps.sh"
|
||||
|
||||
run_logged "$OMARCHY_INSTALL/hardware/asus/fix-asus-ptl-display-backlight.sh"
|
||||
run_logged "$OMARCHY_INSTALL/hardware/asus/fix-asus-ptl-b9406-display.sh"
|
||||
run_logged "$OMARCHY_INSTALL/hardware/asus/fix-asus-ptl-b9406-touchpad.sh"
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
# Enable the temporary sidecar amplifier workaround on the exact Dell XPS 13 model that needs it.
|
||||
#
|
||||
# Pacman registers a package even when its post_install scriptlet fails, so the
|
||||
# apply command runs explicitly here: a failed cleanup or boot-image rebuild has
|
||||
# to reach the caller rather than hide behind a successfully registered package.
|
||||
|
||||
if omarchy-hw-dell-xps13-sidecar-amps; then
|
||||
omarchy-pkg-add dell-xps13-sidecar-amps &&
|
||||
sudo dell-xps13-sidecar-amps-apply
|
||||
fi
|
||||
@@ -0,0 +1,7 @@
|
||||
as_root() {
|
||||
if (( EUID == 0 )); then
|
||||
"$@"
|
||||
else
|
||||
sudo "$@"
|
||||
fi
|
||||
}
|
||||
@@ -0,0 +1,168 @@
|
||||
# Chromium-family machine policy is mandatory for every profile. Directories
|
||||
# stay 0755 root:root; omarchy-theme-set-browser-policy is the privileged
|
||||
# write for color.json.
|
||||
|
||||
source "$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)/as-root.sh"
|
||||
|
||||
BROWSER_POLICY_MANAGED_DIRS=(
|
||||
/etc/chromium/policies/managed
|
||||
/etc/opt/chrome/policies/managed
|
||||
/etc/opt/edge/policies/managed
|
||||
/etc/brave/policies/managed
|
||||
)
|
||||
|
||||
# Ancestors of the managed dirs, shortest first. A writable or attacker-owned
|
||||
# parent can rename the leaf aside; install -d follows a planted symlink.
|
||||
BROWSER_POLICY_PARENT_DIRS=(
|
||||
/etc/chromium
|
||||
/etc/chromium/policies
|
||||
/etc/opt/chrome
|
||||
/etc/opt/chrome/policies
|
||||
/etc/opt/edge
|
||||
/etc/opt/edge/policies
|
||||
/etc/brave
|
||||
/etc/brave/policies
|
||||
)
|
||||
|
||||
BROWSER_POLICY_FIREFOX_DIRS=(
|
||||
/usr/lib/firefox/distribution
|
||||
/opt/zen-browser/distribution
|
||||
)
|
||||
|
||||
BROWSER_POLICY_DEFAULT_COLOR="#1c2027"
|
||||
|
||||
browser_policy_purge_dir() {
|
||||
local dir=$1
|
||||
|
||||
as_root find "$dir" -mindepth 1 -maxdepth 1 ! -user root -exec rm -rf -- {} +
|
||||
}
|
||||
|
||||
browser_policy_parent_hardened() {
|
||||
local dir=$1
|
||||
|
||||
[[ -d $dir && ! -L $dir ]] || return 1
|
||||
[[ $(stat -c '%a' "$dir") == "755" ]] || return 1
|
||||
[[ $(stat -c '%U' "$dir") == "root" ]] || return 1
|
||||
}
|
||||
|
||||
browser_policy_dir_hardened() {
|
||||
browser_policy_parent_hardened "$1"
|
||||
}
|
||||
|
||||
browser_policy_parents_hardened() {
|
||||
local dir=$1
|
||||
local parent
|
||||
|
||||
for parent in "${BROWSER_POLICY_PARENT_DIRS[@]}"; do
|
||||
[[ $dir == "$parent"/* ]] || continue
|
||||
[[ -e $parent || -L $parent ]] || continue
|
||||
browser_policy_parent_hardened "$parent" || return 1
|
||||
done
|
||||
}
|
||||
|
||||
browser_policy_setup_parent() {
|
||||
local dir=$1
|
||||
|
||||
if [[ -L $dir || ( -e $dir && ! -d $dir ) ]]; then
|
||||
as_root rm -rf -- "$dir"
|
||||
fi
|
||||
as_root install -d -m 0755 -o root -g root "$dir"
|
||||
}
|
||||
|
||||
browser_policy_setup_parents_for() {
|
||||
local dir=$1
|
||||
local parent
|
||||
|
||||
for parent in "${BROWSER_POLICY_PARENT_DIRS[@]}"; do
|
||||
[[ $dir == "$parent"/* ]] || continue
|
||||
browser_policy_setup_parent "$parent"
|
||||
done
|
||||
}
|
||||
|
||||
browser_policy_setup_dir() {
|
||||
local dir=$1
|
||||
|
||||
browser_policy_setup_parents_for "$dir"
|
||||
browser_policy_setup_parent "$dir"
|
||||
browser_policy_purge_dir "$dir"
|
||||
}
|
||||
|
||||
# Themes are user-installed. Accept only three 0-255 components.
|
||||
browser_policy_theme_hex() {
|
||||
local theme_rgb=$1
|
||||
|
||||
if [[ $theme_rgb =~ ^[[:space:]]*([0-9]{1,3})[[:space:]]*,[[:space:]]*([0-9]{1,3})[[:space:]]*,[[:space:]]*([0-9]{1,3})[[:space:]]*$ ]] &&
|
||||
(( 10#${BASH_REMATCH[1]} < 256 && 10#${BASH_REMATCH[2]} < 256 && 10#${BASH_REMATCH[3]} < 256 )); then
|
||||
printf '#%02x%02x%02x' "$((10#${BASH_REMATCH[1]}))" "$((10#${BASH_REMATCH[2]}))" "$((10#${BASH_REMATCH[3]}))"
|
||||
return
|
||||
fi
|
||||
|
||||
printf '%s' "$BROWSER_POLICY_DEFAULT_COLOR"
|
||||
}
|
||||
|
||||
browser_policy_install_color() {
|
||||
local policy_dir=$1
|
||||
local hex=$2
|
||||
local dest=$policy_dir/color.json
|
||||
local tmp
|
||||
|
||||
[[ -d $policy_dir && ! -L $policy_dir ]] || return 0
|
||||
[[ $hex =~ ^#[0-9a-f]{6}$ ]] || return 1
|
||||
|
||||
tmp=$(mktemp) || return 1
|
||||
printf '{"BrowserThemeColor": "%s", "BrowserColorScheme": "device"}\n' "$hex" >"$tmp"
|
||||
|
||||
if [[ -L $dest || -d $dest ]]; then
|
||||
if ! rm -rf -- "$dest" 2>/dev/null; then
|
||||
rm -f "$tmp"
|
||||
return 1
|
||||
fi
|
||||
fi
|
||||
|
||||
if install -m 0644 -T "$tmp" "$dest" 2>/dev/null; then
|
||||
rm -f "$tmp"
|
||||
return 0
|
||||
fi
|
||||
|
||||
rm -f "$tmp"
|
||||
return 1
|
||||
}
|
||||
|
||||
browser_policy_firefox_policy_file_ok() {
|
||||
local file=$1
|
||||
local mode
|
||||
local group_write
|
||||
local other_write
|
||||
|
||||
[[ -f $file && ! -L $file ]] || return 1
|
||||
[[ $(stat -c '%U' "$file") == "root" ]] || return 1
|
||||
mode=$(stat -c '%a' "$file")
|
||||
group_write=$((8#${mode: -2:1}))
|
||||
other_write=$((8#${mode: -1}))
|
||||
(( (group_write & 2) == 0 && (other_write & 2) == 0 ))
|
||||
}
|
||||
|
||||
browser_policy_firefox_hardened() {
|
||||
local dir=$1
|
||||
|
||||
[[ -d $dir && ! -L $dir ]] || return 1
|
||||
[[ $(stat -c '%a' "$dir") == "755" ]] || return 1
|
||||
[[ $(stat -c '%U' "$dir") == "root" ]] || return 1
|
||||
browser_policy_firefox_policy_file_ok "$dir/policies.json"
|
||||
}
|
||||
|
||||
browser_policy_install_firefox_policies() {
|
||||
local distribution_dir=$1
|
||||
local policies=${2:-$OMARCHY_PATH/default/firefox/policies.json}
|
||||
|
||||
as_root install -m 644 -o root -g root -T "$policies" "$distribution_dir/policies.json"
|
||||
}
|
||||
|
||||
browser_policy_setup_firefox_distribution() {
|
||||
local distribution_dir=$1
|
||||
local policies=${2:-$OMARCHY_PATH/default/firefox/policies.json}
|
||||
|
||||
browser_policy_setup_parent "$distribution_dir"
|
||||
browser_policy_purge_dir "$distribution_dir"
|
||||
browser_policy_install_firefox_policies "$distribution_dir" "$policies"
|
||||
}
|
||||
@@ -19,7 +19,7 @@ cliamp
|
||||
cups
|
||||
cups-browsed
|
||||
cups-filters
|
||||
cups-pdf
|
||||
cups-pk-helper
|
||||
ddcutil
|
||||
docker
|
||||
docker-buildx
|
||||
|
||||
@@ -61,6 +61,7 @@ linux-firmware-marvell
|
||||
|
||||
# Dell laptop support packages
|
||||
dell-xps-touchpad-haptics
|
||||
dell-xps13-sidecar-amps
|
||||
|
||||
# Speaker tunings (LV2 limiter every tuning ends in)
|
||||
lsp-plugins-lv2
|
||||
|
||||
@@ -3,11 +3,13 @@
|
||||
cp -f "$OMARCHY_PATH/default/pacman/pacman-${OMARCHY_MIRROR:-stable}.conf" /etc/pacman.conf
|
||||
cp -f "$OMARCHY_PATH/default/pacman/mirrorlist-${OMARCHY_MIRROR:-stable}" /etc/pacman.d/mirrorlist
|
||||
|
||||
# omarchy-settings skips this override until cups-browsed is actually present
|
||||
# to avoid pacman creating cups-browsed.conf.pacnew during ISO package install.
|
||||
if [[ -f $OMARCHY_PATH/etc-overrides/cups-cups-browsed.conf && -d /etc/cups ]]; then
|
||||
# omarchy-settings skips these overrides until CUPS is actually present to
|
||||
# avoid pacman creating .pacnew files during ISO package installation.
|
||||
if [[ -f $OMARCHY_PATH/etc-overrides/cups-cups-browsed.conf && -f /etc/cups/cups-files.conf ]]; then
|
||||
systemd-sysusers /etc/sysusers.d/omarchy-cups-browsed.conf
|
||||
cp -f "$OMARCHY_PATH/etc-overrides/cups-cups-browsed.conf" /etc/cups/cups-browsed.conf
|
||||
rm -f /etc/cups/cups-browsed.conf.pacnew
|
||||
install -m 0640 -o root -g cups "$OMARCHY_PATH/etc-overrides/cups-cups-files.conf" /etc/cups/cups-files.conf
|
||||
rm -f /etc/cups/cups-browsed.conf.pacnew /etc/cups/cups-files.conf.pacnew
|
||||
fi
|
||||
|
||||
source "$OMARCHY_INSTALL/hardware/pacman.sh"
|
||||
|
||||
@@ -79,7 +79,7 @@ Turkish|trq
|
||||
Ukrainian|ua'
|
||||
|
||||
OMARCHY_USERNAME_PATTERN='^[a-z_][a-z0-9_-]*[$]?$'
|
||||
OMARCHY_RESERVED_USERNAMES='^(root|bin|daemon|mail|ftp|http|nobody|dbus|systemd-coredump|systemd-network|systemd-oom|systemd-journal-remote|systemd-resolve|systemd-timesync|tss|uuidd|alpm|git|avahi|cups|lp|_talkd|polkitd|rtkit|qemu|brltty|gluster|rpc|libvirt-qemu|pcscd|nvidia-persistenced|sddm)$'
|
||||
OMARCHY_RESERVED_USERNAMES='^(root|bin|daemon|mail|ftp|http|nobody|dbus|systemd-coredump|systemd-network|systemd-oom|systemd-journal-remote|systemd-resolve|systemd-timesync|tss|uuidd|alpm|git|avahi|cups|cups-browsed|lp|_talkd|polkitd|rtkit|qemu|brltty|gluster|rpc|libvirt-qemu|pcscd|nvidia-persistenced|sddm)$'
|
||||
OMARCHY_HOSTNAME_PATTERN='^[A-Za-z0-9]([A-Za-z0-9-]{0,61}[A-Za-z0-9])?$'
|
||||
OMARCHY_HOSTNAME_DEFAULT='omarchy'
|
||||
|
||||
|
||||
Reference in New Issue
Block a user