Profile: editors¶
VS Code and VSCodium, opt-in, each behind its publisher's apt repository
Stage: post-1.0
Who it is for¶
Someone who wants VS Code or VSCodium on a machine whose archive does not carry it, and accepts a publisher's apt repository to get it.
At a glance¶
| Stage | post-1.0 |
| Units | 2 |
| Disk | about 400 MB per editor |
| Hardware | None. |
| Consent | a typed key fingerprint per repository, only where the target's archive lacks the unit: codium, code |
| Install | hammunition install editors |
What it installs¶
Two builds of the same editor. codium is the telemetry-free community build of VS Code's open-source tree, and it is what Parrot ships in its own archive; code is Microsoft's branded build with its marketplace and telemetry. Each manifest declares its publisher's apt repository and the fingerprint of the key that signs it; the engine adds the repository only when the target's archive offers no candidate of its own (D-022), and only after you have affirmed that key by fingerprint (D-040).
Disk footprint: Around 400 MB per editor after the package unpacks; roughly 800 MB with both. Each repository's metadata adds a few megabytes under /var/lib/apt/lists/ and a refresh on every apt update from then on.
Why these belong together¶
They are alternatives to each other, and neither belongs in workstation. A serial console, git and lsusb come from every target's own archive; an editor from a publisher's repository does not, and under D-039 a member the archive cannot supply is deferred while the rest of the profile installs. Keeping both editors here means an operator who wants the bench tooling never sees a repository disclosure they did not ask for, and one who wants an editor sees exactly the one for the build they picked.
Packages (2)¶
What it deliberately excludes¶
Every other editor. Vim, Emacs, nano, Kate, gedit and their relatives are in every target's archive already and need no manifest, no repository and no consent gate; the only reason these two are catalogued at all is that they are the ones AHRL and 73Linux users ask for and the ones that need a third-party repository to get. Extensions, settings sync and the marketplace are the editor's business, not the catalog's. Installing both is supported but pointless: they coexist without conflict and there is no reason to hold both unless you are comparing them.
Install it¶
Read the plan first. It changes nothing and prints every package, build, file and system change, and every consent gate you will meet:
Then do it. The engine asks for your sudo password once, near the start,
and shows the same plan again before it asks you to confirm:
A member your machine cannot take is deferred by name and the rest installs (D-039); the plan lists each under Will NOT happen, with the reason and the command that fixes it. Installation explains how to read every part of the plan.
Third-party apt repositories. codium, code can need a publisher's apt repository on a target whose own archive lacks the package (D-040). The plan then prints the repository, the two files it would write and the key's fingerprint, and asks you to type that fingerprint into HAMMUNITION_ACCEPT_APT_REPO_<NAME>. --yes and a value of 1 are refused.
What you configure by hand afterward¶
Affirm the repository before installing. The plan names the environment variable and the fingerprint it must equal, and prints both the file it will write under /etc/apt/sources.list.d/ and the keyring under /etc/apt/keyrings/ that Signed-By will point at. Check the fingerprint against the publisher's own page before exporting it — that check is the whole point of the gate, and the engine cannot do it for you. On Parrot, codium comes from the distribution and no repository is added; code is Microsoft's everywhere. hammunition uninstall <unit> removes the package and, where this engine wrote them, both repository files, then refreshes apt.
Your first ten minutes¶
- Pick one:
codiumis the telemetry-free community build,codeis Microsoft's. They coexist, but there is rarely a reason to hold both. - Read the plan:
hammunition install codium --dry-run(orcode). On Parrot,codiumcomes from the distribution and the plan adds no repository. Elsewhere the plan names the repository, the files it will write and the fingerprint you must type. - Check that fingerprint against the publisher's own page. That check is the whole point of the gate and only you can do it.
- Install, setting the variable the plan printed to the fingerprint itself, never to
1: for exampleHAMMUNITION_ACCEPT_APT_REPO_<NAME>=<fingerprint> hammunition install codium.--yescannot answer this gate. - To remove it:
hammunition uninstall codium. It removes the package and both repository files this engine wrote, and refreshes apt.
Take it off again¶
This removes what Hammunition itself installed and nothing else. It does not remove dependencies apt pulled in, group memberships or configuration files it wrote; the plan says so and the transaction log records them (D-004).