Plan the settings work beyond GNOME parity
Parity is done except for Color, which the platform blocks. This is the other direction: what a settings application should own on a machine whose owner runs the servers. Every item was checked against this machine before being written down, including the one that was dropped -- a VPN page, because the WireGuard tunnel lives on the router and neither wg nor tailscale is installed here, so it would have had nothing to drive. Claude-Session: https://claude.ai/code/session_01BRvzt4H8XXLPVH5MyYdk9L
This commit is contained in:
@@ -0,0 +1,216 @@
|
||||
# Settings beyond GNOME
|
||||
|
||||
Written 2026-08-19, after the last GNOME panel worth owning was taken.
|
||||
|
||||
The goal has changed. Up to now the target was parity: make GNOME Settings
|
||||
unnecessary. That is done except for Color, which is blocked by the platform
|
||||
rather than by effort. What follows is the other direction — the things a
|
||||
settings application should own on *this* machine, which neither macOS nor
|
||||
Windows can offer because neither assumes you run your own infrastructure.
|
||||
|
||||
Everything below was checked against this machine before it was written. Where
|
||||
something is not possible, it says so and why.
|
||||
|
||||
---
|
||||
|
||||
## What is already true
|
||||
|
||||
| | |
|
||||
|---|---|
|
||||
| `dnf5`, `dnf`, `flatpak` | present; **2 flatpak updates pending** at time of writing |
|
||||
| `firewalld`, `nmcli` | present |
|
||||
| `podman` | 22 images, 5.31 GB reclaimable |
|
||||
| `gamemoded`, `mangohud` | present; Steam library is 1.2 TB |
|
||||
| Nextcloud client | installed and running |
|
||||
| `rustdesk` | installed |
|
||||
| Self-hosted services | cloud, git, home, agentchat all answering over HTTPS |
|
||||
| `wg`, `tailscale` | **absent** — the WireGuard tunnel lives on the router, not here |
|
||||
|
||||
That last row matters: a VPN page on this machine would have nothing to drive.
|
||||
Skipped for that reason, not forgotten.
|
||||
|
||||
---
|
||||
|
||||
## Batch 1 — Keeping the machine current
|
||||
|
||||
The clearest "this OS is unfinished" gap. Both macOS and Windows put this front
|
||||
and centre; here you update in a terminal.
|
||||
|
||||
### 1.1 Software Update
|
||||
|
||||
- Pending updates by source (dnf and flatpak, counted separately because they
|
||||
fail separately), download size, and which are security fixes.
|
||||
- Whether a kernel update means a reboot, stated plainly rather than implied.
|
||||
- When it last checked, and a switch for automatic updates (`dnf-automatic`).
|
||||
- Update history, and what `dnf history undo` can and cannot reverse.
|
||||
|
||||
**Mechanism.** `dnf5` has machine-readable output; `flatpak remote-ls --updates`
|
||||
is already scriptable. Applying updates needs root, so pkexec, prompting through
|
||||
the agent that is already running.
|
||||
|
||||
**Deliberately excluded.** Automatic *unattended* installation of anything but
|
||||
security updates. A machine that reboots itself into a new kernel while you are
|
||||
mid-sentence is not a feature.
|
||||
|
||||
### 1.2 Snapshot before updating
|
||||
|
||||
The reason to do updates first. Snapper is wired up as of yesterday, so an
|
||||
update can take a restore point before it touches anything — with the snapshot
|
||||
named after the transaction, so the Snapshots page shows *"before 47 package
|
||||
updates"* rather than a timestamp.
|
||||
|
||||
Neither macOS nor Windows does this cleanly. It is the single most distinctive
|
||||
thing on this list and it is nearly free now.
|
||||
|
||||
**Done when** the machine can be brought fully current from Settings, and going
|
||||
back is one click on a page that already exists.
|
||||
|
||||
---
|
||||
|
||||
## Batch 2 — Your infrastructure
|
||||
|
||||
The part no shipped operating system has, because no shipped operating system
|
||||
assumes the user runs the servers.
|
||||
|
||||
### 2.1 Services
|
||||
|
||||
A page listing your self-hosted services with reachability, TLS certificate
|
||||
expiry, and version where the service exposes one.
|
||||
|
||||
**Mechanism.** Endpoints stored as a preference (so the list is yours, not
|
||||
hardcoded); an HTTP HEAD per endpoint and an `openssl s_client` for expiry.
|
||||
|
||||
**Deliberately a status view, not management.** Settings will not administer a
|
||||
VPS. "Is my stuff up, and does anything expire soon" is the question worth
|
||||
answering here; anything more belongs in the service's own admin surface.
|
||||
|
||||
**Watch for.** Certificate expiry is the row that earns this page. It is also
|
||||
the one that must never report a false green — a check that fails should say
|
||||
"could not check", never "fine".
|
||||
|
||||
### 2.2 Nextcloud
|
||||
|
||||
The iCloud Drive equivalent, and the reason this list exists rather than a
|
||||
OneDrive page. Sync state, which folders, quota, conflicts, pause and resume.
|
||||
|
||||
**Mechanism.** The desktop client is running; its configuration is readable and
|
||||
`nextcloudcmd` exists. **Risk to check first:** the client's status surface may
|
||||
be too thin to drive a page honestly. If it is, this becomes a smaller card —
|
||||
"syncing / paused / N conflicts" and a button to open the client — rather than
|
||||
a pretend management panel.
|
||||
|
||||
### 2.3 RustDesk
|
||||
|
||||
The peer to the RDP controls already built. ID, whether unattended access is on,
|
||||
and — the part that matters to you — whether it is pointed at your own relay or
|
||||
the public one.
|
||||
|
||||
**Mechanism.** `rustdesk --get-id`, plus its config. Credentials follow the same
|
||||
rule as everywhere else: never through Panama, never on a command line.
|
||||
|
||||
---
|
||||
|
||||
## Batch 3 — Machine control
|
||||
|
||||
### 3.1 Firewall
|
||||
|
||||
You expose services, so this is worth owning. Zones, what is open, and which
|
||||
zone a connection is in.
|
||||
|
||||
**Mechanism.** `firewall-cmd`, which is fully scriptable, plus polkit for
|
||||
changes.
|
||||
|
||||
**Deliberately excluded.** Rich rules and direct rules. They are a syntax, not a
|
||||
setting, and a settings page that half-supports a syntax is a trap.
|
||||
|
||||
**This one is security-sensitive**: every change must state what it exposes,
|
||||
and closing a port someone is currently connected over should say so first.
|
||||
|
||||
### 3.2 Containers
|
||||
|
||||
podman is here and Storage already found 5.31 GB of reclaimable images. Running
|
||||
containers, images, disk, logs, start and stop.
|
||||
|
||||
**Deliberately excluded.** Building images and editing compose files. That is a
|
||||
development tool, not a setting.
|
||||
|
||||
### 3.3 Gaming
|
||||
|
||||
You have `gamemoded`, `mangohud`, and a terabyte of Steam. Windows has Game
|
||||
Mode; macOS added one.
|
||||
|
||||
Gamemode status and which process triggered it; the MangoHud overlay and preset;
|
||||
how it pairs with the power profile Settings already controls; Proton versions;
|
||||
where the library lives.
|
||||
|
||||
**Watch for.** This is the page most likely to become a dumping ground. It
|
||||
should own the handful of things that are actually settings and link out for the
|
||||
rest.
|
||||
|
||||
---
|
||||
|
||||
## Batch 4 — The developer surface
|
||||
|
||||
### 4.1 SSH and keys
|
||||
|
||||
Keys, agent state, known hosts, per-host configuration. Neither macOS nor
|
||||
Windows does this well, and this machine has a pile of `ksshaskpass` entries in
|
||||
the keyring already.
|
||||
|
||||
**Rules carried from the keyring work.** A private key is never read, never
|
||||
displayed, and never leaves its file. The page manages *which* keys exist and
|
||||
what they are for.
|
||||
|
||||
### 4.2 Settings that follow you
|
||||
|
||||
`SettingsBackup` already exists. Nextcloud as transport would make Panama
|
||||
settings arrive on another machine.
|
||||
|
||||
**Watch for.** Machine-specific values — monitor layout, device names — must not
|
||||
follow. A sync that carries a display arrangement to a laptop with one screen is
|
||||
worse than no sync.
|
||||
|
||||
---
|
||||
|
||||
## Cross-cutting, and worth more than any single page
|
||||
|
||||
**Make snapshots ambient.** Now that they exist, anything risky can offer to
|
||||
take one first: updates, restoring defaults, firewall changes. This is the
|
||||
thread that makes a settings application feel *safe* rather than merely capable,
|
||||
and it is cheap everywhere it applies.
|
||||
|
||||
**Make findings actionable.** Storage reports 86 GB in the trash and 5.31 GB of
|
||||
reclaimable images, then leaves you to deal with it. The offer belongs next to
|
||||
the finding — carefully, since these are the destructive ones.
|
||||
|
||||
---
|
||||
|
||||
## Principles this plan inherits
|
||||
|
||||
Every one of these was learned the hard way in the work before it.
|
||||
|
||||
- **No switch that lies.** If the mechanism cannot act — Color's missing
|
||||
devices, snapper's overridden rollback, a driver we cannot choose — the page
|
||||
says so instead of offering a control that changes nothing.
|
||||
- **A write is not done until it is read back.** The failure that made "some
|
||||
things in the settings app don't work" true was a refresh that silently no-oped
|
||||
after a successful write.
|
||||
- **Guards read the object, not a binding over it.** A derived property is stale
|
||||
inside the handler that changes it.
|
||||
- **A test must be seen to fail.** "Something returned an error" is not evidence
|
||||
that your own code refused it; assert the reason.
|
||||
- **Check what exists before writing a file.** Two components were overwritten in
|
||||
one session by not looking first.
|
||||
|
||||
---
|
||||
|
||||
## Order, and why
|
||||
|
||||
Batch 1 first: it is the biggest gap, it is self-contained, and the snapshot
|
||||
pairing makes it distinctive rather than a copy of someone else's panel.
|
||||
|
||||
Batch 2 second: Services is read-only, which makes it low-risk and high-value,
|
||||
and it is the page that makes this feel like *your* operating system.
|
||||
|
||||
Batch 3 and 4 in either order. Firewall is the most valuable of the remainder
|
||||
and also the one that most deserves care.
|
||||
Reference in New Issue
Block a user