#version=DEVEL
# Keyboard layouts
keyboard 'us'
#Root password
rootpw --lock
# System language
lang en_US.UTF-8
# Shutdown after installation
shutdown
user --groups=wheel --name=liveuser --gecos="Live User"
# System timezone
timezone Asia/Shanghai --isUtc
# Network information
network  --bootproto=dhcp --device=link --activate
repo --name="koji" --baseurl=https://build.opencloudos.tech/kojifiles/repos/dist-oc9-desktop-build/latest/$basearch/
repo --name="OC9EPOL" --baseurl=https://mirrors.opencloudos.tech/epol/9/Everything/x86_64/os/
# Use network installation
url --url="https://build.opencloudos.tech/kojifiles/repos/dist-oc9-desktop-build/latest/$basearch/"
# Firewall configuration
firewall --enabled
firstboot --disable
# SELinux configuration
selinux --enforcing

# System services
services --disabled="sshd" --enabled="NetworkManager,gdm"
# System bootloader configuration
bootloader --location=none
reqpart
# Partition clearing information
clearpart --all --initlabel
# Disk partitioning information
part / --fstype="ext4" --size=10240

%post --logfile=/root/oc-live-compose-30-live-session.log --erroronfail
set -eux
export LC_ALL=C.UTF-8 LANG=C.UTF-8

LIVE_USER="liveuser"

# ---- 账户：kickstart user 若未生效，这里补建 ----
if ! id "${LIVE_USER}" >/dev/null 2>&1; then
  # %post 默认 PATH 往往不含 /usr/sbin
  /usr/sbin/useradd -m -G wheel -c "Live User" "${LIVE_USER}"
fi
/usr/bin/passwd -d "${LIVE_USER}" >/dev/null || true

# ---- 免密 sudo（仅 Live；安装后由清理钩子删除）----
mkdir -p /etc/sudoers.d
cat > /etc/sudoers.d/99-opencloudos-live-user <<EOF
${LIVE_USER} ALL=(ALL) NOPASSWD: ALL
EOF
chmod 0440 /etc/sudoers.d/99-opencloudos-live-user

# ---- GDM：自动登录 liveuser，关闭 Live 上的首启向导 ----
mkdir -p /etc/gdm
cat > /etc/gdm/custom.conf <<EOF
[daemon]
AutomaticLoginEnable=True
AutomaticLogin=${LIVE_USER}
InitialSetupEnable=false
EOF

# ---- 服务策略（不用 systemctl，避免 chroot 里拖住宿主 /sys 挂载）----
mkdir -p /etc/systemd/system
ln -sfn /usr/lib/systemd/system/graphical.target /etc/systemd/system/default.target
rm -f /etc/systemd/system/multi-user.target.wants/sshd.service \
      /etc/systemd/system/sshd.service \
      /etc/systemd/system/sshd-keygen.target \
      /etc/systemd/system/multi-user.target.wants/sshd-keygen.target \
      2>/dev/null || true

# Live 会话中文与 IBus 收尾见本模块末尾；compose 期各 %post 一律
# 显式 LC_ALL=C.UTF-8，避免 Anaconda 42 对 chroot 命令输出做严格 UTF-8 解码时失败。

# ---- 对齐官方 livesys（若已装 livesys-scripts）----
if [[ -f /etc/sysconfig/livesys ]]; then
  sed -i 's/^livesys_session=.*/livesys_session="gnome"/' /etc/sysconfig/livesys || true
fi
if [[ -f /usr/lib/systemd/system/livesys.service ]]; then
  mkdir -p /etc/systemd/system/multi-user.target.wants
  ln -sfn /usr/lib/systemd/system/livesys.service \
    /etc/systemd/system/multi-user.target.wants/livesys.service
fi
if [[ -f /usr/lib/systemd/system/livesys-late.service ]]; then
  mkdir -p /etc/systemd/system/multi-user.target.wants
  ln -sfn /usr/lib/systemd/system/livesys-late.service \
    /etc/systemd/system/multi-user.target.wants/livesys-late.service
fi
# Live：/tmp 用 tmpfs（对齐 dist-oc9-webui 产品 kickstart）
if [[ -f /usr/lib/systemd/system/tmp.mount ]]; then
  mkdir -p /etc/systemd/system/local-fs.target.wants
  ln -sfn /usr/lib/systemd/system/tmp.mount \
    /etc/systemd/system/local-fs.target.wants/tmp.mount
fi
# Live overlay 上少写 /var/tmp（产品 Live / Fedora live 常见做法）
if ! grep -qE '^[[:space:]]*vartmp[[:space:]]+/var/tmp' /etc/fstab 2>/dev/null; then
  printf 'vartmp   /var/tmp    tmpfs   defaults   0  0\n' >> /etc/fstab
fi

# ---- Live 会话中文：在所有 compose 期 chroot 命令结束前不写 locale.conf，
# 避免 Anaconda/lmc 对 chroot 命令输出做严格 UTF-8 解码时失败（模块编号
# 31/34/35 在本模块之后，故放在这里仍安全——它们不再执行本地化命令）。
printf 'LANG=zh_CN.UTF-8\n' > /etc/locale.conf

# 统一 GTK、Qt 与 XIM 客户端的 IBus 发现方式。不设 dconf input-sources：
# Live 安装器对 ibus 输入源不兼容，正式系统由 post/31-epol-input-method 的
# 安装后 hook 配置。
mkdir -p /etc/environment.d
cat > /etc/environment.d/90-ibus.conf <<'EOF'
GTK_IM_MODULE=ibus
QT_IM_MODULE=ibus
XMODIFIERS=@im=ibus
EOF

# Live 镜像去掉固定 machine-id，首启再生成。compose 阶段已不再跑
# opencloudos-gnome-desktop-profile（桌面整合走 RPM，profile 改为首登
# autostart 执行），因此在此处清空是安全的。
rm -f /etc/machine-id
touch /etc/machine-id
rm -f /var/lib/dbus/machine-id
ln -sf /etc/machine-id /var/lib/dbus/machine-id

# 不改动 D-Bus provider：跟随发行版默认（OpenCloudOS 多为 dbus-broker）
%end

%post --logfile=/root/oc-live-compose-31-gnome-extensions.log --erroronfail
set -eux
export LC_ALL=C.UTF-8 LANG=C.UTF-8

JP_UUID="just-perfection-desktop@just-perfection"
[[ -f "/usr/share/gnome-shell/extensions/${JP_UUID}/metadata.json" ]] || {
  echo "ERROR: gnome-shell-extension-just-perfection was not installed" >&2
  exit 1
}

if [[ -d "/usr/share/gnome-shell/extensions/${JP_UUID}/schemas" ]]; then
  /usr/bin/glib-compile-schemas \
    "/usr/share/gnome-shell/extensions/${JP_UUID}/schemas"
fi

mkdir -p /etc/dconf/profile /etc/dconf/db/local.d

cat > /etc/dconf/profile/user <<'EOF'
user-db:user
system-db:local
EOF

cat > /etc/dconf/db/local.d/00-gnome-extensions <<'EOF'
[org/gnome/shell]
enabled-extensions=['dash-to-panel@jderose9.github.com', 'arcmenu@arcmenu.com', 'appindicatorsupport@rgcjonas.gmail.com', 'drive-menu@gnome-shell-extensions.gcampax.github.com', 'blur-my-shell@aunetx', 'just-perfection-desktop@just-perfection', 'gtk4-ding@smedius.gitlab.com', 'clipboard-indicator@tudmotu.com']
welcome-dialog-last-shown-version='9999'

[org/gnome/shell/extensions/just-perfection]
startup-status=0
EOF

if [[ -x /usr/bin/dconf ]]; then
  /usr/bin/dconf update
else
  echo "ERROR: dconf was not found in the image" >&2
  exit 1
fi

echo "GNOME extensions installed from RPM packages and enabled"
%end

%post --logfile=/root/oc-live-compose-31-epol-input-method.log --erroronfail
set -eux
export LC_ALL=C.UTF-8 LANG=C.UTF-8

# 确保 Live 镜像里没有残留的 ibus 默认输入源配置。
rm -f /etc/dconf/db/local.d/02-epol-input-method
if [[ -x /usr/bin/dconf ]]; then
  /usr/bin/dconf update
fi

mkdir -p /usr/share/anaconda/post-scripts
HOOK=/usr/share/anaconda/post-scripts/zz-opencloudos-epol-input-method.ks
{
  echo '%post --log=/root/opencloudos-epol-input-method.log --erroronfail'
  cat <<'HOOKBODY'
mkdir -p /etc/dconf/db/local.d
cat > /etc/dconf/db/local.d/02-epol-input-method <<'EOF'
[org/gnome/desktop/input-sources]
sources=[('xkb', 'us'), ('ibus', 'libpinyin')]
EOF

if [ -x /usr/bin/dconf ]; then
  /usr/bin/dconf update
fi

rm -f /usr/share/anaconda/post-scripts/zz-opencloudos-epol-input-method.ks
HOOKBODY
  printf '%s\n' '%end'
} > "${HOOK}"
%end

%post --logfile=/root/oc-live-compose-34-orchis-oc-gtk-theme.log --erroronfail
set -eux
export LC_ALL=C.UTF-8 LANG=C.UTF-8

THEME_NAME="Orchis-OC"
DST_THEME="/usr/share/themes/${THEME_NAME}"
LIVE_USER="liveuser"

[[ -s "${DST_THEME}/gtk-3.0/gtk.css" && -s "${DST_THEME}/gtk-4.0/gtk.css" ]] || {
  echo "ERROR: orchis-oc-gtk-theme was not installed: ${DST_THEME}" >&2
  exit 1
}

mkdir -p /etc/dconf/db/local.d
cat > /etc/dconf/db/local.d/01-orchis-oc-gtk-theme <<'EOF'
[org/gnome/desktop/interface]
gtk-theme='Orchis-OC'
EOF

if [[ -x /usr/bin/dconf ]]; then
  /usr/bin/dconf update
fi

link_gtk4() {
  local home="$1"
  local cfg="${home}/.config/gtk-4.0"
  mkdir -p "$cfg"
  ln -sfn "/usr/share/themes/${THEME_NAME}/gtk-4.0/gtk.css" "${cfg}/gtk.css"
  ln -sfn "/usr/share/themes/${THEME_NAME}/gtk-4.0/gtk-dark.css" "${cfg}/gtk-dark.css"
  ln -sfn "/usr/share/themes/${THEME_NAME}/gtk-4.0/assets" "${cfg}/assets"
}

link_gtk4 /etc/skel
if id -u "${LIVE_USER}" >/dev/null 2>&1; then
  link_gtk4 "/home/${LIVE_USER}"
  chown -R "${LIVE_USER}:${LIVE_USER}" "/home/${LIVE_USER}/.config" 2>/dev/null || true
fi

if command -v restorecon >/dev/null 2>&1; then
  restorecon -RF "$DST_THEME" /etc/dconf || true
fi

echo "Orchis-OC theme configured from orchis-oc-gtk-theme RPM"
%end

%post --logfile=/root/oc-live-compose-35-desktop-integration.log --erroronfail
set -eux
export LC_ALL=C.UTF-8 LANG=C.UTF-8

UUID="opencloudos-desktop-integration@opencloudos.org"
EXT_DIR="/usr/share/gnome-shell/extensions/${UUID}"

# ---- 断言：扩展与 profile 工具必须由 RPM 提供 ----
[[ -f "${EXT_DIR}/metadata.json" ]] || {
  echo "ERROR: desktop integration extension is not installed" >&2
  exit 1
}
[[ -x /usr/bin/opencloudos-gnome-desktop-profile ]] || {
  echo "ERROR: opencloudos-gnome-desktop-profile is not installed" >&2
  exit 1
}

# ---- dconf 基础设施与系统默认值（0.1.0 缺，0.1.1 RPM 自带同名文件）----
mkdir -p /etc/dconf/profile /etc/dconf/db/local.d
if [[ ! -f /etc/dconf/profile/user ]]; then
  printf 'user-db:user\nsystem-db:local\n' > /etc/dconf/profile/user
elif ! grep -qx 'system-db:local' /etc/dconf/profile/user; then
  printf '\nsystem-db:local\n' >> /etc/dconf/profile/user
fi

if [[ ! -f /etc/dconf/db/local.d/00-opencloudos-gnome-desktop-integration ]]; then
  cat > /etc/dconf/db/local.d/00-opencloudos-gnome-desktop-integration <<'EOF'
[org/gnome/shell]
enabled-extensions=['dash-to-panel@jderose9.github.com', 'arcmenu@arcmenu.com', 'appindicatorsupport@rgcjonas.gmail.com', 'drive-menu@gnome-shell-extensions.gcampax.github.com', 'blur-my-shell@aunetx', 'just-perfection-desktop@just-perfection', 'gtk4-ding@smedius.gitlab.com', 'clipboard-indicator@tudmotu.com', 'opencloudos-desktop-integration@opencloudos.org']

[org/gnome/shell/extensions/just-perfection]
startup-status=0
EOF
fi

# ---- 每用户首登 autostart（0.1.0 缺，0.1.1 RPM 自带同名文件）----
if [[ ! -f /etc/xdg/autostart/opencloudos-desktop-profile-once.desktop ]]; then
  cat > /etc/xdg/autostart/opencloudos-desktop-profile-once.desktop <<'EOF'
[Desktop Entry]
Type=Application
Name=OpenCloudOS Desktop Profile
Comment=Enable the OpenCloudOS desktop extensions and apply defaults
Exec=sh -c '/usr/bin/opencloudos-gnome-desktop-profile --enable-only || exit 0; stamp="$HOME/.config/opencloudos-gnome-desktop-profile.stamp"; [ -f "$stamp" ] && exit 0; /usr/bin/opencloudos-gnome-desktop-profile || exit 0; mkdir -p "$HOME/.config" && touch "$stamp"'
OnlyShowIn=GNOME;
X-GNOME-Autostart-enabled=true
EOF
fi

if [[ -x /usr/bin/dconf ]]; then
  /usr/bin/dconf update
fi

echo "OpenCloudOS GNOME desktop integration verified (RPM + profile wiring)"
%end

%post --logfile=/root/oc-live-compose-32-live-installer.log --erroronfail
set -eux
export LC_ALL=C.UTF-8 LANG=C.UTF-8

LIVE_USER="liveuser"
LIVEINST=""
for candidate in /usr/bin/liveinst /usr/sbin/liveinst; do
  if [[ -x "$candidate" ]]; then
    LIVEINST="$candidate"
    break
  fi
done

# --ignoremissing 是 pykickstart 的全局开关；源中缺少 anaconda-live 时，
# 在 compose 阶段失败，避免产出没有“安装到硬盘”的 Live ISO。
if [[ -z "$LIVEINST" ]]; then
  echo "ERROR: liveinst is missing; anaconda-live was not installed" >&2
  echo "确认软件源提供 anaconda-live（提供 /usr/bin/liveinst）" >&2
  exit 1
fi

mkdir -p /etc/anaconda/profile.d /etc/anaconda/conf.d \
  /etc/xdg/autostart /home/"${LIVE_USER}"/Desktop

# ---- Anaconda UI：Live 安装只暴露存储等必要 spoke ----
cat > /etc/anaconda/profile.d/opencloudos-live-desktop.conf <<'EOF'
# OpenCloudOS Live Desktop 安装器配置
# 语言/键盘/网络/时间在 Live 会话已有默认；用户账户留给安装后首启向导。

[Profile]
profile_id = opencloudos-live-desktop
base_profile = opencloudos

[User Interface]
hidden_spokes =
    NetworkSpoke
    PasswordSpoke
    UserSpoke
    DatetimeSpoke
    KeyboardSpoke
    LangsupportSpoke
    SourceSpoke
    SoftwareSelectionSpoke
    SubscriptionSpoke

hidden_webui_pages =
    anaconda-screen-accounts
EOF

# Anaconda 42 会在 profile 之后加载 conf.d；这里全局隐藏账户页，
# 因此从发行版自带的“安装到硬盘”入口启动时同样生效。
cat > /etc/anaconda/conf.d/99-opencloudos-live-desktop.conf <<'EOF'
[User Interface]
hidden_webui_pages =
    anaconda-screen-accounts
EOF

# 保留上游名称、图标和 desktop 文件，只给它追加 Live profile 参数。
LIVEINST_DESKTOP=/usr/share/applications/liveinst.desktop
[[ -f "$LIVEINST_DESKTOP" ]] || {
  echo "ERROR: liveinst desktop launcher is missing: $LIVEINST_DESKTOP" >&2
  exit 1
}
sed -i -E "s|^Exec=.*|Exec=${LIVEINST} --profile opencloudos-live-desktop|" \
  "$LIVEINST_DESKTOP"

# 不依赖 liveinst-setup 的首登时机，compose 时即投放到 Live 桌面。
install -m 0755 "$LIVEINST_DESKTOP" \
  "/home/${LIVE_USER}/Desktop/liveinst.desktop"
chown "${LIVE_USER}:${LIVE_USER}" "/home/${LIVE_USER}/Desktop/liveinst.desktop"

cat > /etc/xdg/autostart/opencloudos-liveinst-trust.desktop <<'EOF'
[Desktop Entry]
Type=Application
Name=Trust OpenCloudOS Live Installer Launcher
Exec=sh -c 'gio set "$HOME/Desktop/liveinst.desktop" metadata::trusted true 2>/dev/null || true'
OnlyShowIn=GNOME;
NoDisplay=true
X-GNOME-Autostart-enabled=true
EOF
%end

%post --logfile=/root/oc-live-compose-36-desktop-shortcuts.log --erroronfail
set -eux

LIVE_USER="liveuser"
LIVE_DESKTOP="/home/${LIVE_USER}/Desktop"
SKEL_DESKTOP="/etc/skel/Desktop"
mkdir -p "$LIVE_DESKTOP" "$SKEL_DESKTOP"

for launcher in \
  firefox.desktop \
  ungoogled-chromium.desktop \
  softcenter.desktop
do
  source="/usr/share/applications/${launcher}"
  [[ -f "$source" ]] || continue
  install -m 0755 "$source" "$LIVE_DESKTOP/$launcher"
  install -m 0755 "$source" "$SKEL_DESKTOP/$launcher"
  chown "${LIVE_USER}:${LIVE_USER}" "$LIVE_DESKTOP/$launcher"
done

# GNOME/DING 仅信任带 metadata::trusted 标记的桌面启动器。该 autostart
# 保留到硬盘系统，使从 /etc/skel 继承启动器的新用户也会被自动信任。
mkdir -p /etc/xdg/autostart
cat > /etc/xdg/autostart/opencloudos-desktop-shortcuts-trust.desktop <<'EOF'
[Desktop Entry]
Type=Application
Name=Trust OpenCloudOS Desktop Shortcuts
Exec=sh -c 'for f in "$HOME"/Desktop/firefox.desktop "$HOME"/Desktop/ungoogled-chromium.desktop "$HOME"/Desktop/softcenter.desktop; do [ -f "$f" ] && gio set "$f" metadata::trusted true 2>/dev/null || true; done'
OnlyShowIn=GNOME;
NoDisplay=true
X-GNOME-Autostart-enabled=true
EOF
%end

%post --logfile=/root/oc-live-compose-33-cleanup-hook.log --erroronfail
set -eux
export LC_ALL=C.UTF-8 LANG=C.UTF-8

CLEANUP=/usr/local/sbin/opencloudos-installed-system-cleanup
SERVICE=/etc/systemd/system/opencloudos-installed-system-cleanup.service

mkdir -p /usr/local/sbin /usr/share/anaconda/post-scripts \
  /etc/systemd/system/multi-user.target.wants

# ---- 唯一清理实现：安装期钩子和首次硬盘启动服务共用，避免两份逻辑漂移 ----
cat > "${CLEANUP}" <<'CLEANUPEOF'
#!/usr/bin/env bash
set -u

LIVE_USER="liveuser"
SERVICE_NAME="opencloudos-installed-system-cleanup.service"
CLEANUP_PATH="/usr/local/sbin/opencloudos-installed-system-cleanup"
FIRST_BOOT=0

is_live_boot() {
  [[ -e /run/initramfs/live ]] && return 0

  if grep -Eq '(^|[[:space:]])(rd\.live\.image(=([^[:space:]]*)?)?|root=live:)' \
      /proc/cmdline 2>/dev/null; then
    return 0
  fi

  local root_source
  root_source="$(findmnt -n -o SOURCE / 2>/dev/null || true)"
  [[ "${root_source}" == /dev/mapper/live-* ]] && return 0

  return 1
}

case "${1:-}" in
  --check-installed)
    # systemd ExecCondition：Live 环境返回 1（跳过），硬盘系统返回 0（执行）。
    is_live_boot && exit 1
    exit 0
    ;;
  --installed)
    # Anaconda 的目标系统 %post 已经在 chroot 中，明确绕过 Live 启动判断。
    ;;
  --installed-first-boot)
    # 只有真实硬盘启动才允许调用 systemctl，避免安装期 chroot 误连 Live systemd。
    FIRST_BOOT=1
    ;;
  *)
    echo "Usage: ${0} --check-installed | --installed | --installed-first-boot" >&2
    exit 2
    ;;
esac

mkdir -p /var/log
exec >>/var/log/opencloudos-installed-system-cleanup.log 2>&1
set -x
echo "Removing temporary Live configuration from the installed system"

# ---- 先阻止 livesys/GDM 使用 Live 配置 ----
# 首次硬盘启动时，livesys 的 start job 可能已经随 multi-user.target 排队；
# stop 会取消该 job，runtime mask 则防止本次启动中被其他单元再次拉起。
if (( FIRST_BOOT )); then
  systemctl stop livesys.service livesys-late.service 2>/dev/null || true
  systemctl mask --runtime livesys.service livesys-late.service 2>/dev/null || true
fi
rm -f /etc/systemd/system/multi-user.target.wants/livesys.service
rm -f /etc/systemd/system/multi-user.target.wants/livesys-late.service
rm -f /etc/systemd/system/livesys.service
rm -f /etc/systemd/system/livesys-late.service
rm -f /etc/sysconfig/livesys

mkdir -p /etc/gdm
cat > /etc/gdm/custom.conf <<'GDMEOF'
[daemon]
InitialSetupEnable=true
GDMEOF

# ---- 删除 Live 专用用户与提权配置 ----
if id "${LIVE_USER}" >/dev/null 2>&1; then
  userdel -r "${LIVE_USER}" 2>/dev/null || userdel "${LIVE_USER}" 2>/dev/null || true
fi
rm -rf -- "/home/${LIVE_USER}"
rm -f "/var/lib/AccountsService/users/${LIVE_USER}"
rm -f /etc/sudoers.d/99-opencloudos-live-user

# ---- 删除自定义与发行版自带的安装入口 ----
rm -f /usr/local/bin/opencloudos-liveinst
rm -f /usr/share/applications/opencloudos-liveinst.desktop
rm -f /etc/xdg/autostart/opencloudos-liveinst-trust.desktop
rm -f /etc/anaconda/profile.d/opencloudos-live-desktop.conf
rm -f /etc/anaconda/conf.d/99-opencloudos-live-desktop.conf
rm -f /home/*/Desktop/opencloudos-liveinst.desktop 2>/dev/null || true
rm -f /home/*/Desktop/liveinst.desktop 2>/dev/null || true
rm -f /tmp/opencloudos-liveinst.log

# Live 专用 /var/tmp tmpfs 不要带到装机系统。
sed -i '/^[[:space:]]*vartmp[[:space:]]\+\/var\/tmp[[:space:]]/d' \
  /etc/fstab 2>/dev/null || true

passwd -l root 2>/dev/null || true
rm -f /etc/skel/.config/gnome-initial-setup-done
find /home -name gnome-initial-setup-done -delete 2>/dev/null || true

# ---- 移除仅 Live 需要的安装器 / Live 启动包 ----
if command -v dnf >/dev/null 2>&1; then
  # anaconda-webui depends on Firefox. Only remove the named Live packages;
  # dependency autoremove would otherwise delete Firefox from the installed desktop.
  dnf -y --setopt=clean_requirements_on_remove=False remove \
    anaconda anaconda-core anaconda-gui anaconda-tui anaconda-widgets \
    anaconda-live anaconda-webui anaconda-install-env-deps livesys-scripts \
    dracut-live dracut-squash gnome-tour || true
fi

# 即使 RPM 事务受依赖关系阻止，也不要在应用菜单里留下安装入口。
rm -f /usr/bin/liveinst /usr/sbin/liveinst
rm -f /usr/share/applications/liveinst.desktop
rm -f /etc/xdg/autostart/liveinst-setup.desktop
rm -f /usr/libexec/liveinst-setup.sh
rm -f /usr/share/polkit-1/actions/org.fedoraproject.pkexec.liveinst.policy

ln -sfn /usr/lib/systemd/system/graphical.target /etc/systemd/system/default.target

# ---- 成功走到末尾后自删除；若中途被杀，下次启动仍可重试 ----
rm -f "/etc/systemd/system/multi-user.target.wants/${SERVICE_NAME}"
rm -f "/etc/systemd/system/${SERVICE_NAME}"
rm -f /usr/share/anaconda/post-scripts/opencloudos-live-cleanup.ks
rm -f /usr/share/anaconda/post-scripts/zz-opencloudos-live-cleanup.ks
rm -f "${CLEANUP_PATH}"
if (( FIRST_BOOT )); then
  systemctl daemon-reload 2>/dev/null || true
fi
echo "Live configuration cleanup completed"
CLEANUPEOF
chmod 0755 "${CLEANUP}"

# ---- 首次从硬盘启动的兜底服务：必须早于 livesys 和显示管理器 ----
cat > "${SERVICE}" <<EOF
[Unit]
Description=Remove OpenCloudOS Live session configuration after installation
After=local-fs.target
Before=livesys.service livesys-late.service display-manager.service gdm.service

[Service]
Type=oneshot
ExecCondition=${CLEANUP} --check-installed
ExecStart=${CLEANUP} --installed-first-boot

[Install]
WantedBy=multi-user.target
EOF

ln -sfn "${SERVICE}" \
  /etc/systemd/system/multi-user.target.wants/opencloudos-installed-system-cleanup.service

# ---- Anaconda 安装期快速路径；zz 前缀确保在内置 post-scripts 之后执行 ----
rm -f /usr/share/anaconda/post-scripts/opencloudos-live-cleanup.ks
HOOK=/usr/share/anaconda/post-scripts/zz-opencloudos-live-cleanup.ks
{
  echo '%post --log=/root/opencloudos-live-cleanup.log --erroronfail'
  cat <<'HOOKBODY'
if [ -x /usr/local/sbin/opencloudos-installed-system-cleanup ]; then
  /usr/local/sbin/opencloudos-installed-system-cleanup --installed
fi
HOOKBODY
  printf '%s\n' '%end'
} > "${HOOK}"
%end

%packages --ignoremissing
ModemManager
NetworkManager
NetworkManager-adsl
NetworkManager-bluetooth
NetworkManager-tui
NetworkManager-wifi
abattis-cantarell-fonts
acl
adobe-source-code-pro-fonts
alsa-firmware
alsa-sof-firmware
alsa-tools-firmware
amd-gpu-firmware
amd-ucode-firmware
anaconda
anaconda-core
anaconda-gui
anaconda-install-env-deps
anaconda-live
anaconda-tui
anaconda-webui
appstore-backend
appstore-frontend
at
at-spi2-atk
at-spi2-core
atheros-firmware
attr
audit
authselect
avahi
baobab
basesystem
bash
bash-completion
bc
blktrace
bluez
bluez-cups
bluez-hid2hci
bluez-libs
bluez-obexd
bolt
bpftool
brcmfmac-firmware
bzip2
cheese
chrony
cirrus-audio-firmware
coreutils
cpio
cronie
crontabs
crypto-policies
crypto-policies-scripts
cryptsetup
curl
cyrus-sasl-plain
dbus
dbus-x11
dconf
dejavu-fonts
device-mapper
dnf
dnf-plugins-core
dos2unix
dosfstools
dracut-config-rescue
dracut-live
dracut-squash
dvb-firmware
e2fsprogs
ed
efibootmgr
eog
ethtool
evince
file
filesystem
firefox
firewalld
flatpak
fprintd
fprintd-pam
gdm
gedit
glib-networking
glibc
glibc-all-langpacks
glibc-langpack-zh
glx-utils
gnome-backgrounds
gnome-bluetooth
gnome-bluetooth-libs
gnome-calculator
gnome-characters
gnome-classic-session
gnome-color-manager
gnome-control-center
gnome-disk-utility
gnome-font-viewer
gnome-initial-setup
gnome-logs
gnome-remote-desktop
gnome-screenshot
gnome-session-wayland-session
gnome-session-xsession
gnome-settings-daemon
gnome-shell
gnome-shell-extension-appindicator
gnome-shell-extension-arcmenu
gnome-shell-extension-blur-my-shell
gnome-shell-extension-clipboard-indicator
gnome-shell-extension-dash-to-panel
gnome-shell-extension-drive-menu
gnome-shell-extension-gtk4-ding
gnome-shell-extension-just-perfection
gnome-system-monitor
gnome-terminal
gnome-terminal-nautilus
gnome-user-docs
gnupg2
google-noto-emoji-color-fonts
google-noto-sans-cjk-sc-fonts
google-noto-sans-cjk-tc-fonts
google-noto-sans-cjk-ttc-fonts
google-noto-sans-gurmukhi-fonts
google-noto-sans-mono-cjk-sc-fonts
google-noto-sans-sinhala-vf-fonts
google-noto-serif-cjk-sc-fonts
google-noto-serif-cjk-tc-fonts
google-noto-serif-cjk-ttc-fonts
grub2
grub2-efi-x64
grub2-efi-x64-cdboot
grub2-pc-modules
grub2-tools
grub2-tools-extra
grub2-tools-minimal
grubby
gvfs-fuse
gvfs-goa
gvfs-gphoto2
gvfs-mtp
gvfs-smb
hostname
ibus-libpinyin
iio-sensor-proxy
initscripts
initscripts-rename-device
intel-audio-firmware
intel-gpu-firmware
intel-vsc-firmware
iproute
iproute-tc
iprutils
iptstate
iputils
irqbalance
iw
iwlegacy-firmware
iwlwifi-dvm-firmware
iwlwifi-mld-firmware
iwlwifi-mvm-firmware
jomolhari-fonts
julietaula-montserrat-fonts
kbd
kernel
kernel-tools
kexec-tools
khmer-os-system-fonts
kmod-kvdo
kpartx
kpatch
kpatch-dnf
ledmon
less
libblockdev-dm
libblockdev-lvm
libblockdev-mpath
libblockdev-nvdimm
libcanberra-gtk3
liberation-mono-fonts
liberation-sans-fonts
liberation-serif-fonts
libertas-firmware
libinput
librsvg2
libsane-hpaio
libstoragemgmt
libsysfs
libwacom
libwacom-data
linux-firmware
linux-firmware-whence
livesys-scripts
logrotate
lohit-assamese-fonts
lohit-bengali-fonts
lohit-devanagari-fonts
lohit-gujarati-fonts
lohit-kannada-fonts
lohit-odia-fonts
lohit-tamil-fonts
lohit-telugu-fonts
lshw
lsof
lsscsi
lvm2
mailcap
man-db
man-pages
mcelog
mdadm
mesa-dri-drivers
microcode_ctl
mlocate
mt7xxx-firmware
mtr
nano
nautilus
ncurses
net-tools
netronome-firmware
nmap-ncat
nvidia-gpu-firmware
nvme-cli
nxpwireless-firmware
opencloudos-gnome-desktop-integration
opencloudos-release
openssh-clients
openssh-server
orca
orchis-oc-gtk-theme
p11-kit
paktype-naskh-basic-fonts
parted
passwd
pciutils
plymouth
plymouth-system-theme
policycoreutils
polkit
power-profiles-daemon
procps-ng
psacct
pt-sans-fonts
pulseaudio-module-bluetooth
python3-libselinux
qcom-accel-firmware
qcom-firmware
qcom-wwan-firmware
qed-firmware
quota
realmd
realtek-firmware
rfkill
rootfiles
rpm
rpm-plugin-audit
rsync
rsyslog
rsyslog-gnutls
rsyslog-gssapi
sane-backends-drivers-scanners
selinux-policy-targeted
setup
sg3_utils
sg3_utils-libs
shadow-utils
shim
shim-x64
sil-abyssinica-fonts
sil-nuosu-fonts
sil-padauk-fonts
smartmontools
smc-meera-fonts
sos
sssd
sssd-common
sssd-kcm
stix-fonts
strace
sudo
sushi
symlinks
syslinux
systemd
systemd-udev
tar
tcpdump
teamd
thermald
time
tiwilink-firmware
totem
tracker
tracker-miners
tree
tuned
ungoogled-chromium
unzip
upower
usbutils
util-linux
util-linux-user
vdo
vim-enhanced
vim-minimal
virt-what
wget
which
wireless-regdb
words
wpa_supplicant
xdg-desktop-portal
xdg-desktop-portal-gnome
xdg-desktop-portal-gtk
xdg-user-dirs-gtk
xfsdump
xfsprogs
xorg-x11-drv-evdev
xorg-x11-drv-fbdev
xorg-x11-drv-libinput
xorg-x11-drv-vmware
xorg-x11-drv-wacom
xorg-x11-server-Xorg
xorg-x11-xauth
xorg-x11-xinit
xorg-x11-xinit-session
yelp-tools
yum
zip

%end
