Skip to main content

max / alloy

Swap the browser to Helium and delete the Firefox estate Helium (helium-browser-bin 0.14.9.1, from Terra, already enabled for satty) replaces Firefox as the browser in the image, and the five files of Firefox theming and preference seeding go with it: the enterprise policy, mozilla.cfg, the autoconfig pointer, profiles.ini, and about two hundred lines of userChrome.css. Nothing replaces them. No Helium policy file, no pref seed, no chrome CSS. That is the point rather than an omission. Alloy stopped theming and preconfiguring applications, so an app now earns a recommendation by not needing configuration, and Alloy's own Firefox config had been stating which app that was for months: its header read "Alloy Firefox chrome: Helium-style ultra-compact horizontal". Two hundred lines of CSS and fifty preferences were emulating a browser that is packaged. Dropping the fifty prefs would be indefensible on a browser with bad defaults; it is affordable here because Helium already blocks ads, trackers, cookie banners and third-party cookies, ships no analytics, and makes no network request on first launch. The monoculture argument in STACK.md, which rejected Blink as the default, is recorded as overridden rather than deleted. It did not become wrong. It lost to the theming rule: the previous answer was "ship Gecko and fix it", and the fixing is what stopped. Firefox is one Containerfile line away for anyone who wants Gecko, and would ship unconfigured too. Reasoning in wiki alloy-packaging-policy, work in GoingsOn alloy 4e91cc42. Ruled out on the way: a Helium Flatpak (upstream refuses to make one, holding that Chromium cannot be packaged as a Flatpak without breaking its internal sandbox, so every Flatpak of it is an unofficial repackaging, which is worse provenance than Terra's -bin for the most attack-exposed program on the box), and compiling ungoogled-chromium (Helium is built on it; compiling costs hours and roughly 100 GB for a subset of what the prebuilt package provides). The rest is the stale-reference sweep the deletions force, which is the same class of defect this repo keeps finding: config that is correct about something absent. The Noto coverage fonts stay and their justification is rewritten, since it argued from shipping Firefox specifically. Eight other files named Firefox in comments, docs or a test path and no longer do. The sway idle-inhibit rule now matches ^(helium|firefox), on the strength of StartupWMClass=helium read out of the built image; that has not been confirmed against a running window and the comment says so. Verified by a full build: helium-browser-bin installed, firefox absent, /usr/lib64/firefox, /etc/firefox and /etc/skel/.mozilla all gone, and skelgen's four render guards still passing with the userChrome template removed. What the portal does with Helium's light and dark is still unobserved. The deleted mozilla.cfg set ui.systemUsesDarkTheme = 0, so Alloy was fighting that path deliberately and it has never been seen working. STACK.md lists it as an accepted cost rather than claiming it works, and GoingsOn alloy 02f873f0 carries the verification for a real session on fw12.
Co-Authored-By
Claude Opus 5 (1M context) <noreply@anthropic.com>
Author: Max Johnson <me@maxj.phd> · 2026-07-30 21:55 UTC
Signed with PGP, not checked
Commit: fd869fb3e184ffdabf6e5fdf518ea52161984847
Parent: 31812f7
18 files changed, +75 insertions, -435 deletions
M Containerfile +22 -17
@@ -135,7 +135,7 @@
135 135 # Two renders per themed template now, the plain one and a `.night` sibling. The
136 136 # sibling is written next to its target, which is not where it belongs: left
137 137 # there, every new user gets a ~/.config/mako/config.night and a
138 - # userChrome.css.night inside their Firefox profile. No program picks those up —
138 + # config.night beside every other themed file. No program picks those up —
139 139 # helix scans for *.toml, sway reads `config` — so the failure is clutter rather
140 140 # than breakage, which is exactly the kind that ships. Hence the relocation
141 141 # below, and the assertion that it left nothing behind.
@@ -327,9 +327,9 @@
327 327 # Sources noted per group. Anything absent from both Fedora main and
328 328 # Terra is downloaded directly (Nerd Fonts, in the layer above). The
329 329 # `flatpak` client is installed as the `sandboxed` level of the isolation
330 - # dial, which is also how users pull ungoogled-chromium and other
331 - # on-demand apps from Flathub post-install; no Flatpaks are provisioned
332 - # at build or first-boot time.
330 + # dial, which is also how users pull on-demand apps from Flathub
331 + # post-install; no Flatpaks are provisioned at build or first-boot
332 + # time.
333 333 # =====================================================================
334 334 RUN dnf install -y \
335 335 # Compositor and Wayland session (Fedora main)
@@ -460,16 +460,23 @@
460 460 adw-gtk3-theme \
461 461 # Screenshot capture + region-select (sway has no built-in grab)
462 462 grim slurp \
463 - # Browser (Gecko default; ungoogled-chromium is opt-in Flatpak per docs/STACK.md)
464 - firefox \
463 + # Browser (docs/STACK.md#browser). Helium is ungoogled-chromium with
464 + # the defaults Alloy used to hand-build in fifty Firefox prefs and a
465 + # policy file, so it ships here with no configuration at all: no
466 + # policy, no pref seed, no chrome CSS. That is the whole reason it is
467 + # the default. Terra packages it; upstream ships no Flatpak, and the
468 + # unofficial repackagings are worse provenance than this for the most
469 + # attack-exposed program on the box.
470 + helium-browser-bin \
465 471 # Script coverage for the browser. Until now the image carried
466 472 # google-noto-sans-vf (Latin, Greek, Cyrillic) and nothing else, so
467 - # Firefox rendered every CJK, Arabic, Hebrew, Indic and Thai page as
468 - # rows of missing glyphs. Shipping a browser as the default and then
469 - # not carrying the fonts a large share of the web is written in is the
470 - # same defect class as the emoji alias that named a font the image
471 - # never installed: the config was fine, the coverage was absent, and
472 - # nothing said so.
473 + # the browser rendered every CJK, Arabic, Hebrew, Indic and Thai page
474 + # as rows of missing glyphs. Shipping a browser as the default and
475 + # then not carrying the fonts a large share of the web is written in
476 + # is the same defect class as the emoji alias that named a font the
477 + # image never installed: the config was fine, the coverage was
478 + # absent, and nothing said so. The fonts outlive any one browser
479 + # pick, so this line does not move when the pick does.
473 480 #
474 481 # These are Fedora's own coverage metapackages rather than a hand-
475 482 # picked list, because the failure mode of hand-picking is a script
@@ -492,7 +499,7 @@
492 499 # dial (docs/STACK.md#containers). The user picks a level, not a
493 500 # tool. podman is the runtime and is what `workspace` calls
494 501 # directly; distrobox wraps it for `host`; flatpak is `sandboxed`,
495 - # and is also the install path for ungoogled-chromium.
502 + # and is the install path for everything Alloy does not bake in.
496 503 podman \
497 504 flatpak \
498 505 # Secrets (docs/STACK.md#secrets). Two different jobs, and only the
@@ -789,10 +796,8 @@
789 796
790 797 # =====================================================================
791 798 # Config tree — the etc/ and usr/ trees in the repo map 1:1 into
792 - # the image. Per-user defaults live under etc/skel/.config/ and
793 - # etc/skel/.mozilla/ (Firefox first-launch profile seed); system-
794 - # wide config under etc/; Firefox autoconfig + mozilla.cfg under
795 - # usr/lib64/firefox/. See docs/IMAGE.md for the layout.
799 + # the image. Per-user defaults live under etc/skel/.config/;
800 + # system-wide config under etc/. See docs/IMAGE.md for the layout.
796 801 #
797 802 # Two sources, in this order. The repo tree is everything whose content is
798 803 # fixed; the rendered tree is everything that carries a color, which is not in
M docs/CONSOLE.md +1 -1
@@ -50,7 +50,7 @@
50 50 matching render of every themed config out of the image: `/etc/skel` for `day`,
51 51 `/usr/share/alloy/skel-night` for `night`. `usr/bin/alloy-session` runs it before
52 52 exec'ing sway, and greetd's `--cmd` points at that wrapper, so a theme chosen in
53 - the console reaches sway, mako, Firefox and the rest at the next login. A file
53 + the console reaches sway, mako, shop and the rest at the next login. A file
54 54 whose contents match neither render is one the user edited, and it is kept and
55 55 named rather than replaced; `--force` is the only way past that, and it leaves a
56 56 `.alloy-bak`.
M docs/IMAGE.md +2 -2
@@ -90,13 +90,13 @@
90 90 2. **Third-party repos:** Tailscale, any COPRs Alloy depends on for packages not in Fedora main.
91 91 3. **Package additions:** the full Alloy stack from [STACK.md](STACK.md): compositor, bar, launcher, notifications, terminal, editor, shell, viewers, utilities, continuity daemons, fonts, themes.
92 92 4. **Package removals:** stock Silverblue desktop pieces Alloy replaces (gnome-shell, gdm; the latter gated on the greeter pick).
93 - 5. **Config tree:** the tree at `etc/skel/.config/*` and `etc/skel/.mozilla/*` (new-user defaults, including the Firefox first-launch profile seed), `etc/*` (system-wide, including `etc/firefox/policies/policies.json`), `usr/lib64/firefox/*` (Firefox autoconfig + `mozilla.cfg` default prefs), and `usr/share/polkit-1/rules.d/*` (which system settings the console may change without a prompt) in the repo maps 1:1 into the image. The polkit rule is asserted at build time against the actions the image actually defines, since a grant naming a renamed action is inert and silent about it.
93 + 5. **Config tree:** the tree at `etc/skel/.config/*` (new-user defaults), `etc/*` (system-wide), and `usr/*`, including `usr/share/polkit-1/rules.d/*` (which system settings the console may change without a prompt) in the repo maps 1:1 into the image. The polkit rule is asserted at build time against the actions the image actually defines, since a grant naming a renamed action is inert and silent about it.
94 94 6. **Rendered tree:** everything in the image that carries a color is not in the repo as a finished file. `templates/` holds it with the palette left as tokens, and `skelgen` renders it against the two Akari themes into a second tree that mirrors `/` the same way the config tree does. Themed skeleton files render twice: the light one lands at `etc/skel/<rel>`, the dark one at `usr/share/alloy/skel-night/<rel>`, and `alloy theme apply` copies whichever the user's mode file names into `$HOME` at login. The build asserts the two trees are a bijection and that they do not overlap the repo's own `etc/skel`, because a themed file that quietly loses its dark render leaves a light sway border on a dark desktop and nothing else.
95 95 7. **Systemd presets:** which services are enabled by default (syncthing off by default, gammastep off until enrolled, alloy-hinged conditionally on FW12, etc.).
96 96 8. **Branding:** os-release, plymouth splash.
97 97 9. **Validation:** `bootc container lint` runs at build.
98 98
99 - The base browser (Firefox) ships as an RPM baked into the image: one code path, no first-boot delay, and enterprise policies (`/etc/firefox/policies/policies.json`) take effect immediately. The `flatpak` client is included so users can pull ungoogled-chromium and other Flathub-only apps on demand post-install; no Flatpaks are provisioned at build or first-boot time.
99 + The browser ships as an RPM baked into the image: one code path, no first-boot delay, and no first-run network dependency. Alloy ships no configuration for it at all, which is why it is the browser Alloy ships (see [STACK.md](STACK.md#browser)). The `flatpak` client is included so users can pull Flathub-only apps on demand post-install; no Flatpaks are provisioned at build or first-boot time.
100 100
101 101 ## Update cadence
102 102
M docs/STACK.md +19 -22
@@ -48,7 +48,7 @@
48 48
49 49 **`alloy-menu`: fzf over desktop entries, run in rio.** Bound `Mod+D`. A shell script in `usr/bin/`, about forty lines, that reads `.desktop` files from the system, user and Flatpak paths, pipes names through fzf, and hands the chosen `Exec` line to `swaymsg exec` so the app outlives the terminal that launched it.
50 50
51 - The split with `Mod+Return` is the design. Typing a command is what a shell is for, and a shell is one keystroke away, so the launcher does not list every binary on `PATH`: doing that buries Firefox under coreutils. It lists the graphical apps that have a name, an icon and a binary nobody remembers. Two keys, two jobs.
51 + The split with `Mod+Return` is the design. Typing a command is what a shell is for, and a shell is one keystroke away, so the launcher does not list every binary on `PATH`: doing that buries the browser under coreutils. It lists the graphical apps that have a name, an icon and a binary nobody remembers. Two keys, two jobs.
52 52
53 53 This replaces "none by default". That line read as terminal-first discipline and worked as one until `Mod+Return` broke, at which point a session with no launcher had no way to open a terminal and no way to edit the file that would have fixed it. A launcher is the second door.
54 54
@@ -74,11 +74,11 @@
74 74
75 75 ## File manager
76 76
77 - **yazi** (Rust, async, plugin system, sixel/kitty/iTerm image preview). TUI-only, no GUI fallback shipped; the pivot's TUI-first line applies here the same way it applied to Rnote. Firefox and other GUI apps that need file dialogs go through xdg-desktop-portal, not a bundled file manager, so the daily case is covered.
77 + **yazi** (Rust, async, plugin system, sixel/kitty/iTerm image preview). TUI-only, no GUI fallback shipped; the pivot's TUI-first line applies here the same way it applied to Rnote. The browser and other GUI apps that need file dialogs go through xdg-desktop-portal, not a bundled file manager, so the daily case is covered.
78 78
79 79 No custom egui file manager planned. Scope is too large (file ops, permissions, drag-drop, thumbnails, archives, mounts, trash, search, batch ops, associations) for a marquee-app slot, and the pivot moved off graphical authored surfaces anyway.
80 80
81 - Rejected: broot (Rust TUI, useful as a complement but a different model), nautilus / dolphin (not Rust), cosmic-files (was the pre-pivot GUI fallback; dropped along with the rest of the graphical stack). Users who want a graphical file manager install one themselves with `flatpak install flathub com.system76.CosmicFiles` (or thunar, nautilus), the same posture as ungoogled-chromium.
81 + Rejected: broot (Rust TUI, useful as a complement but a different model), nautilus / dolphin (not Rust), cosmic-files (was the pre-pivot GUI fallback; dropped along with the rest of the graphical stack). Users who want a graphical file manager install one themselves with `flatpak install flathub com.system76.CosmicFiles` (or thunar, nautilus): Flathub is where ad-hoc applications come from, and Alloy provisions none of them.
82 82
83 83 ## Text editor
84 84
@@ -137,32 +137,29 @@
137 137
138 138 ## Browser
139 139
140 - **Firefox (upstream) baked in as the default; ungoogled-chromium available as an opt-in Flatpak.** Alloy's identity work happens at the engine level, not the fork level, so upstream Firefox is the right base: no ESR lag, no fork-specific patch drift, the most-tested Gecko build shipping. Alloy owns the visual and behavioral layer via four files, each landing at the path Firefox actually reads:
140 + **Helium baked into the image as the default, unconfigured.** Helium is ungoogled-chromium with the behavior Alloy used to hand-build on top of Firefox already set upstream: ads, trackers, cookie banners and third-party cookies blocked by default, fingerprinting tampered with, no analytics, and no network request at all on first launch. Alloy ships no policy file, no preference seed, no chrome CSS and no extension pin for it. Shipping nothing is the reason it is the default, not an omission next to it. The packaging rules this follows are in the wiki note `alloy-packaging-policy`; the short form is that an app earns a recommendation by not needing configuration, which is the same test that picked helix over a configured vim.
141 141
142 - - [`etc/firefox/policies/policies.json`](../etc/firefox/policies/policies.json): enterprise policy. Pins **uBlock Origin** as a force-installed, update-locked extension. Disables telemetry, Pocket, studies, sponsored tiles, new-tab feed, formfill, and password saving at the policy layer (higher-precedence than user prefs).
143 - - [`usr/lib64/firefox/mozilla.cfg`](../usr/lib64/firefox/mozilla.cfg): system-wide default prefs, loaded via Firefox autoconfig. Configures compact UI density, blank new tab, DuckDuckGo suggestions off, quiet scroll, and enables `toolkit.legacyUserProfileCustomizations.stylesheets` so `userChrome.css` gets read. Every entry uses `defaultPref()` so users can still override in `about:config`.
144 - - [`usr/lib64/firefox/defaults/pref/autoconfig.js`](../usr/lib64/firefox/defaults/pref/autoconfig.js): one-line pointer telling Firefox to load `mozilla.cfg` at startup.
145 - - [`etc/skel/.mozilla/firefox/profiles.ini`](../etc/skel/.mozilla/firefox/profiles.ini) + [`etc/skel/.mozilla/firefox/alloy.default/chrome/userChrome.css`](../templates/etc/skel/.mozilla/firefox/alloy.default/chrome/userChrome.css.in): first-launch profile seed. `profiles.ini` names a fixed-path profile (`alloy.default/`) so the pre-seeded `chrome/userChrome.css` (Helium-style ultra-compact horizontal, Alloy light-mode tokens from [TOKENS.md](TOKENS.md)) lands under it. Firefox opens the seeded profile on first launch instead of generating a random-suffix one.
142 + The package is `helium-browser-bin` from Terra, the repo Alloy already enables for satty.
146 143
147 - Runs all modern sites (uBlock Origin blocks ads, never JS). Horizontal tabs only, per firm preference.
144 + **What Alloy used to ship here, and no longer does.** Five files went with this change: an enterprise policy pinning uBlock Origin and disabling telemetry, Pocket, studies, sponsored tiles and password saving; a `mozilla.cfg` of around fifty default prefs; the autoconfig pointer that loaded it; a `profiles.ini` naming a fixed-path profile; and roughly two hundred lines of `userChrome.css`. That CSS described its own purpose in its header as "Helium-style ultra-compact horizontal". It was emulating a browser that is packaged, so the emulation had no reason to exist. The fifty prefs were not only cosmetic, and dropping them on a browser with bad defaults would be indefensible. It is affordable here because the recommended browser already behaves that way.
148 145
149 - **Ungoogled-chromium** is offered as the second-engine escape valve for the rare site that only renders correctly under Blink, and for users who prefer Chromium ergonomics without Google telemetry. Not baked into the ISO. Install path:
146 + **This is a non-endorsement, not a pick.** Alloy is not claiming Blink is the better engine, and the monoculture argument that previously rejected Chromium as the default is recorded as overridden rather than withdrawn. Reinforcing one engine's dominance is a real cost and Alloy is paying it. What it lost to is the theming rule: the previous answer was "ship Gecko and fix it", and Alloy no longer fixes browsers. **Firefox remains one line in the Containerfile** for anyone who wants Gecko, which is what a builder-not-artifact distribution means by a choice, and it would ship with no Alloy configuration on it either.
150 147
151 - ```
152 - flatpak install flathub io.github.ungoogled_software.ungoogled_chromium
153 - ```
154 -
155 - No Alloy config is shipped for it. The point is a working Chromium engine on demand, not a second identity surface.
148 + **What still reaches the browser** is system appearance, through the portal and the toolkit rather than through per-app files: `org.freedesktop.appearance` `color-scheme` for light and dark, the GTK theme for system dialogs, the cursor theme, and the font stack including the Noto coverage packages. That is the whole of it. Anything past what a well-behaved app reads from the system is now the user's to set in the browser's own settings.
156 149
157 150 Accepted costs:
158 - - **userChrome.css drifts** across Firefox major versions. Alloy owns the theme; re-verify after each Firefox major release. Bounded work (a few selectors per bump).
159 - - **uBlock Origin pinning** is Alloy's enterprise policy, so Firefox will refuse to let the user disable or uninstall it via the extensions UI. Users who need to disable it can edit `/etc/firefox/policies/policies.json` themselves; Alloy documents the location.
151 + - **The day/night switch reaching the browser is unverified.** The deleted `mozilla.cfg` set `ui.systemUsesDarkTheme = 0`, so Alloy was deliberately fighting the portal and the portal path has never been observed working here. If it turns out not to drive Helium, that is recorded as a defect in the appearance propagation and fixed there. Per-app chrome CSS does not come back for it.
152 + - **No blocker is pinned.** Helium's blocking is a browser feature rather than a forced extension, which also means a user who disables it has disabled it, with nothing in the image arguing.
153 + - **`-bin` provenance.** Terra repackages an upstream binary rather than building from source, and this is the most attack-exposed program in the image. It is still better provenance than the alternatives: Helium has no official Flatpak and upstream refuses to make one, holding that Chromium cannot be packaged as a Flatpak without breaking its internal sandbox, so every Flatpak of it is an unofficial community repackaging.
154 + - **Updates come with the image.** A browser inside the image moves when the image is rebuilt rather than on its own channel. `alloy update` shows what is booted, what is staged, and how to roll back; reporting how far behind the image's packages have fallen, with the browser called out rather than buried in a bulk count, is filed work and not yet shipped.
160 155
161 156 Rejected:
162 - - **Floorp.** Was the previous pick. Rough edges in daily use, ESR-based cadence lags Firefox security patches, fork-specific patches add drift Alloy doesn't own. Upstream Firefox with policies + userChrome.css captures the actual value (visual and behavioral configurability) at less cost.
163 - - **LibreWolf.** Ships uBlock Origin preinstalled (a real win), but its hardening (`resistFingerprinting`, letterboxing, cookie clears on close, WebGL off) breaks modern sites. Un-hardening it to pass Alloy's "runs all modern sites" bar erases the reason to choose it over Firefox.
157 + - **Firefox as the default.** Was the previous pick, and upstream Gecko remains the right Gecko. It loses on rule 3 alone: keeping it as the default meant keeping the five files, and every one of them was Alloy configuring an application.
158 + - **Ungoogled-chromium.** Helium is built on it, so these were never two options, and it is packaged for neither Fedora nor Terra. Compiling it in the image costs hours of build time and roughly 100 GB of scratch space for a subset of what the prebuilt package already provides.
159 + - **Helium as a Flatpak.** See the provenance note above.
160 + - **LibreWolf.** Ships uBlock Origin preinstalled, but its hardening (`resistFingerprinting`, letterboxing, cookie clears on close, WebGL off) breaks modern sites. Un-hardening it to pass the "runs all modern sites" bar erases the reason to choose it.
164 161 - **Zen Browser.** Gecko-based and design-forward, but its identity centers vertical tabs and sidebar-forward layout. Revisit only if Zen ships a first-class horizontal mode as a supported configuration.
165 - - **Chromium as default, Brave, Vivaldi, Arc, Helium.** Alloy doesn't reinforce browser-engine monoculture. Ungoogled-chromium covers the "I need Blink" case without making it the default.
162 + - **Brave, Vivaldi, Arc.** Each arrives with a business model attached to the browser, which is the class of default Alloy is least willing to hand a user.
166 163
167 164 ## Containers
168 165
@@ -349,7 +346,7 @@
349 346
350 347 ### Media keys: **playerctl**
351 348
352 - C, MPRIS client. CLI. No config; sway binds media keys directly to `exec playerctl play-pause` and similar. Handles Spotify, mpv, Firefox, and any MPRIS-compliant source.
349 + C, MPRIS client. CLI. No config; sway binds media keys directly to `exec playerctl play-pause` and similar. Handles Spotify, mpv, the browser, and any MPRIS-compliant source.
353 350
354 351 Rejected: playerctld (still a playerctl variant), no serious alternative.
355 352
@@ -379,7 +376,7 @@
379 376
380 377 Config at [`templates/etc/skel/.config/gtk-3.0/`](../templates/etc/skel/.config/gtk-3.0/) and [`templates/etc/skel/.config/gtk-4.0/`](../templates/etc/skel/.config/gtk-4.0/) with matching `gtk.css` and `settings.ini` per version.
381 378
382 - **What this covers:** any GTK 3 or GTK 4 app that consumes libadwaita's named tokens: swayosd (GTK-rendered overlays), Firefox's system dialogs, xdg-desktop-portal-gtk dialogs, etc.
379 + **What this covers:** any GTK 3 or GTK 4 app that consumes libadwaita's named tokens: swayosd (GTK-rendered overlays), the portal file dialogs a browser opens, xdg-desktop-portal-gtk dialogs, etc.
383 380
384 381 **What this doesn't cover:**
385 382 - Legacy GTK 3 apps with their own token sets (rare; most have migrated).
@@ -274,16 +274,16 @@
274 274 license = "MIT"
275 275 url = "https://github.com/Byron/dua-cli"
276 276
277 - [[section.project]]
278 - name = "Firefox"
279 - license = "MPL-2.0"
280 - url = "https://mozilla.org/firefox"
281 -
282 277 [[section.project]]
283 278 name = "Git"
284 279 license = "GPL-2.0-only"
285 280 url = "https://git-scm.com"
286 281
282 + [[section.project]]
283 + name = "Helium"
284 + license = "GPL-3.0-only AND BSD-3-Clause"
285 + url = "https://helium.computer"
286 +
287 287 [[section.project]]
288 288 name = "jq"
289 289 license = "MIT"
@@ -9,7 +9,7 @@
9 9 # shell, which is one keystroke away. This exists for the other case -- the
10 10 # graphical apps that have a .desktop file and an icon and a name nobody
11 11 # remembers the binary for. So it lists desktop entries and nothing else;
12 - # adding every binary on PATH would bury Firefox under coreutils.
12 + # adding every binary on PATH would bury the browser under coreutils.
13 13 #
14 14 # Launched apps are handed to sway rather than run as children of this script,
15 15 # so the terminal hosting the picker can close immediately and the app is not