e1a04d2d704ff1df0b688649536464b48c719fe7
222
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
e1a04d2d70 |
Write the eight accents down once
They were written down five times: ThemeProfileModel.js for QML, looks.lua for the compositor, and again in panama-theme-apps and panama-lock. The GNOME accent-name mapping was a sixth list. Adding a ninth accent meant editing all of them, and the file most likely to be missed was the lock screen, which fails silently -- the machine locks in last season's colour and nothing says why. panama-theme-apps admitted it in a comment: "there is no shared source between QML and a shell script". config/palette.json is that source now. looks.lua reads it through a new prefs.readJson, which uses the same never-raise parser the settings store uses, so an unreadable palette costs the accent colours and never the compositor config. The two shell generators read it through scripts/panama-palette, which also carries the hex-to-rgb conversion hyprlock needs and the GNOME member lookup. QML keeps its table, because a .js module imported into QML cannot read a file. That is still a copy, so the palette contract compares the two value by value -- every accent, every field -- and fails on any disagreement. Verified by planting a wrong hex and watching it name the exact field. The adwaita contract used to check the shell's own copy of the GNOME mapping. It now checks that the shell resolves through the palette, and fails if that copy ever grows back. |
||
|
|
202b5b89ac |
Write the manual for the person using the desktop
docs/ is engineering artifacts -- design specs, plans, an upstream ledger -- and none of it is written for the person who has to live here. Five chapters that are: coming from another desktop, the keyboard, windows and workspaces, when something breaks, and making it yours. Rendered inside Settings rather than opened in a browser, so a chapter that says "the Displays page reverts after fifteen seconds" is one click from the Displays page. Qt's markdown renderer does the work; one chapter per Text, because Text has an implicit texture size limit and a document long enough to hit it goes blank rather than complaining. The chapters live beside the shell in manual/ rather than at the repository root, which departs from the plan. The reason is the path: the shell finds them through Quickshell.shellDir, which is correct wherever the repository is, whereas walking upward out of the shell directory is only correct by accident. The contract fails that pattern if it comes back. The contract also pins the set both ways -- every chapter listed exists, every chapter that exists is listed -- because a renamed file shows an error card where a chapter should be, which reads as a broken manual rather than as a moved file. |
||
|
|
9202697734 |
Introduce the desktop to somebody who has just met it
Thirty settings pages is the opposite of the usual problem: a person arriving from GNOME, macOS or Windows cannot tell which few things matter. This is those few, once, on the first start. Not a tour. Nobody reads a tour, and a multi-step wizard on a desktop somebody just installed is one more thing between them and using it. One card, five keys, and a way out. The chords come from the live keymap rather than being written here, so a machine whose owner has already rebound something teaches what they actually have. A welcome screen is the one surface read by somebody with no way to tell it is wrong, which is exactly why it must not be. Two deliberate departures from how every other surface behaves. It does not close on a click outside, because a stray click in the first thirty seconds would throw away the only explanation on offer. And dismissing by any route marks it seen, Escape included, because a desktop that reintroduces itself every login has failed to take no for an answer. It stays reachable from the launcher afterwards, since the moment somebody wants it again is exactly when a one-shot has thrown it away. Also teaches the keymap to spell punctuation: slash, period, comma and the rest were rendering as their raw keysym names, so the welcome screen offered "Super + slash" and the cheatsheet agreed with it. |
||
|
|
9fbbdd902b |
Answer "what can I press" in one keypress
The Shortcuts settings page answers "how do I change this", which is worth opening a window for. This answers the other question, the one you have with your hands already on the keyboard, so it is an overlay on SUPER + / and the same key closes it. It reads Keybinds.grouped() rather than a written-down list, so a shortcut rebound in Settings shows its new chord here with nothing kept in sync. A cheatsheet that lies is worse than none: it gets consulted exactly when somebody does not already know. Three columns, balanced by how many shortcuts each category holds. The first attempt used a Flow, which wraps into as many columns as it likes and made 120 binds across six uneven categories unreadable; it also sized the card from a child that filled it, which is a circular binding and produced a card taller than the display with its contents running off the bottom. Both were found by looking at it rather than by a test, which is the argument for looking at it. Fixes a real bug on the way past: luaChord and formatChord appended the key unconditionally, so the window switcher's modifier-only release bind became "SUPER + " with a dangling separator. That matched neither the chord keybinds.lua binds nor the one an override is keyed by, so that bind could never be rebound and had no category -- it was sitting in a seventh group of its own, which is how it was noticed. |
||
|
|
6ae8265730 |
Say what a keybind is for, rather than guessing from its name
The Shortcuts page grouped shortcuts by matching substrings in their descriptions, which put "Close window" and "Close the notification list" in the same group and left anything phrased unusually in whichever bucket matched first. The cheatsheet that comes next would have inherited the same guesswork. keybinds.lua says it outright now. Its sections already were the categories, so a section sets one and the binds below inherit it: one line per section instead of one per bind, and a new bind lands in the category of the section somebody wrote it in without having to remember anything. Hyprland reports a Lua bind's dispatcher as __lua with a bytecode offset, so nothing can be attached to a bind that survives into `hyprctl binds`. The config writes a manifest at load instead, keyed by the chord actually bound so the shell can join on what it sees. Writing never raises: a read-only state directory costs the grouping, never the keymap, and the shell keeps the old derivation as its fallback so a machine that has not reloaded its compositor still works. The one failure mode is a section that forgets to set a category and silently inherits the one above. That is not hypothetical -- it happened while writing this, because the dictation section sits in the middle of the media binds and its category leaked onto the volume, media and brightness keys below it. The contract walks the file for sections with binds and no category, and spot-checks the boundaries where inheritance is doing the work. |
||
|
|
317b7a0962 |
Give a reconnected display the arrangement it had
hypr/monitors.lua applies the stored per-output entries when the compositor reads its config, and never again. A monitor plugged in an hour later got the compositor's automatic placement instead of the position, scale and rotation this machine was told to use, and the only way back was to open Settings and apply it again. Docking should not cost you your desk. Deliberately not a confirmed transaction. applyLayout arms a fifteen second countdown because it is about to show you something you might not be able to undo; this restores a layout you already confirmed, on hardware you already had, and a countdown would be asking you to re-approve your own decision every time you sat down. It refuses rather than guesses when the stored mode is one the connected panel does not offer -- DP-1 on one dock is not DP-1 on another -- and when the surviving layout would name no primary. Both land on the compositor's automatic placement plus a toast that opens the Displays page, which is recoverable; silence would not be. That toast needed a new open-settings verb in StatusEvents, whose page name goes through ShellState's existing allow-list. The decision is split from the action as plannedRestore so it can be tested without driving a real compositor, and the harness sets topology and stored arrangement in one call because a real query landing between two would replace the fixture. Both fixtures travel base64: qs ipc call splits a JSON array of several objects into one argument per object, so a two-monitor fixture was arriving as an extra argument. |
||
|
|
50a99a5ad0 |
Closing the lid at a desk is not closing it in a bag
logind handles the lid correctly except for the one case it cannot see: an external display means a closed lid is a docked machine, not one being put away. Its own docked test looks for an ACPI docking station that modern hardware does not have. Panama does not take the lid over to fix that. It holds a logind handle-lid-switch inhibitor while an external display is connected and releases it when the last one goes, which needs no lid watcher, no polling, and no drop-in. The direction it fails in is the point: if the guard dies, logind's default comes back and a docked laptop suspends, which is annoying. A drop-in setting HandleLidSwitch=ignore plus a watcher of our own fails the other way, leaving a lid that does nothing at all on a machine being carried out of a building. Locking on the way down needed no work: hypridle's before_sleep_cmd already runs loginctl lock-session, so a lid-close suspend is a locked suspend. The contract fails anything that duplicates it. Not yet verified against a real lid, which is stated in the helper's header rather than implied by silence. The decision logic, the inhibitor's shape, and every machine that should hold none of it are covered. |
||
|
|
bc6d63b70f |
Let the idle timings know whether you are plugged in
An idle screen costs a screen on wall power and the rest of your afternoon on battery, so they should not be the same number. hypridle has no concept of a power source -- one config, one set of timeouts -- so rather than maintaining two configs and swapping them, panama-idle builds the single config from whichever key set applies, and IdleLock rebuilds it when the charger comes or goes. That runs through the same 400ms debounce a settings change uses, so a loose charger cannot restart hypridle in a loop. The battery keys fall back to their AC counterparts rather than to the schema defaults. Without that, unplugging would silently override a deliberately long timing with a shipped short one, which is the kind of thing you would notice only by losing work. A machine with no battery reads none of it and generates exactly what it generated before. The contract pins that alongside the two obvious directions, and was checked by sabotaging the detection to confirm it fails rather than passing vacuously. |
||
|
|
3c359f3f7e |
Notice the battery, and the machine it is or is not in
Panama had no idea whether it was running on a laptop. No upower, no battery, no lid, no AC: hypridle.conf says "This is a desktop" in its own header, and that was true of the code as well as the machine. panama-hw answers hardware questions one at a time, exits 0 or 1, and prints nothing, so scripts, services and contracts all ask the same way. The definition the rest of the laptop work hangs on is one line: clamshell is lid-closed AND an external monitor. A machine with no mains supply at all reports as being on wall power, because a desktop cannot run out of it. The battery service follows Vitals: sysfs through FileView, an availability flag, and no subprocess on the timer. Globbing is the one thing QML cannot do -- a battery is BAT0 or BAT1 or CMB0, mains is AC or ADP1 or ACAD -- so panama-battery resolves the names once and the shell reads the files directly after. Nothing falls back to a plausible zero: a desktop shows no indicator, no card, and no charge limit control where the firmware has no ceiling. Also repairs two contracts that were already failing and had not been noticed, because only the full suite runs them. The dependency scanner treated line-initial variable assignments, case labels, comments and heredoc bodies as commands, and `count`, `host`, `cancel` and `import` are all real binaries on Fedora, so `command -v` could not filter them out. It now drops comments and heredoc bodies and requires a command to be followed by whitespace. Verified it still catches a genuinely undeclared dependency rather than passing quietly. The launcher command contract had not been told about the fourteen commands added earlier today. |
||
|
|
e446a1072c |
Give an installed machine a way to catch up
./install only ever adds. It copies over /, links dotfiles, installs packages -- and has no way to say "remove that file", "disable that unit", "that symlink points nowhere now". So a machine set up months ago keeps whatever this repository has since decided was wrong, and the only thing that ever fixes it is somebody reading a commit message. With a curl installer in the README, that stopped being hypothetical. A migration is one script that performs one repair, exactly once, on the machines that need it. Named by the commit timestamp that authored it, so glob order is chronological without a sequence number two branches could both pick. Marked in ~/.local/state on success and only on success, so a repair that failed stays pending rather than being recorded as done and hidden forever. Ordered, and stopped at the first failure, because a later repair may assume an earlier one landed. A fresh install marks everything without running it, the way Migrations.qml stamps a pre-versioning settings file at its baseline. The first real one removes the dangling ~/.config/forge symlink left behind when the GNOME session was cut: link-dotfiles could link it but never unlink it. Verified both ways -- a no-op on a machine that never had it, an actual repair on one that did. Root work goes through panama-sudo --reason so the password prompt names the repair, and the contract fails any migration reaching for bare sudo. |
||
|
|
32bebc2b07 |
One door per name on the IPC bus
A second IpcHandler with an already-used target does not error -- it silently shadows the first, and for the polkit target that means the agent's authentication requests stop reaching the prompt: every password dialog on the desktop, gone without a message. That duplicate nearly shipped once, because the handlers live scattered through a long shell.qml. The contract pairs every IpcHandler with its quoted target across the shell's QML (harnesses excluded -- each is its own root), fails on any name declared twice, and refuses to pass on an empty scan so a declaration-format change cannot quietly blind it. |
||
|
|
c02329ac3c |
Copy a password without leaving a trace of it
The launcher's Copy Password command, built alone and last as the plan required, because every line of it is the security design: the secret travels rbw to wl-copy through a pipe -- never argv, never a file -- and the copy carries wl-clipboard's --sensitive hint, which vicinae's clipboard history documents it ignores. That claim was not taken on faith: a plain probe landed in the live history database and a sensitive one did not, before any of this was written. A transient timer clears the clipboard after thirty seconds. An unconfigured rbw gets a setup message; a vault that locks between list and get gets an honest failure instead of an empty copy claiming success. rbw joins desktop-packages, and the contract pins the whole journey with a stub vault, including that the secret never appears on a command line. |
||
|
|
4e978bf3b7 |
Teach the launcher what an operating system knows
The OS-parity batch from the vicinae plan, tasks 1 through 7. The audit came back better than the plan guessed: the calculator already links libqalculate, the built-in file index answers in under 100ms across all of home, quicklinks and snippets ship as built-in stores -- so zero new packages, and `vicinae dmenu` replaces the planned compiled extension outright. What was missing gets built: a power menu (lock, suspend, log out through uwsm, restart, power off), reminders as transient systemd timers with a pick-to-cancel list, a color picker over hyprpicker, and dmenu pick-lists for window switching, force quit, kill process, SSH hosts, and recent files -- all through one panama-pick helper. The launcher commands contract exercises the reminder parsing and every pick-list against stubs, including killing its own sacrificial sleep. |
||
|
|
f42b3cfe0e |
Let the password prompt say why
panama-sudo is pkexec with a stated reason: the reason travels to the shell over the existing polkit IPC target, and the prompt renders it labeled "Stated reason (unverified)" beside polkitd's real action message -- beside, never instead of, because any process can claim any reason and the action text is the trust anchor. Reasons are single-shot and expire in ten seconds, so a stale one cannot dress up an unrelated prompt; without a reason, a running shell, or qs the wrapper is exactly pkexec. Built for agents, so the person typing their password learns what for. Verified live end to end -- reason shown, consumed once, expired when stale, cleared on dismissal -- and pinned by the polkit reason contract. |
||
|
|
51ceb19480 |
One command from fresh Fedora to the front door
`boot` is the script the README now leads with: curl it, and it installs git if the machine lacks it, clones the repository to PANAMA_PATH, and hands off to ./install -- reattaching the terminal first, because a piped stdin would strand the interview. Deliberately dumb: a curled copy leaves the repository the moment it runs, so nothing that can drift lives in it. Re-running is the recovery path: an existing clone is fast-forwarded, never re-cloned, and a refused fast-forward installs from what is there rather than stopping mid-repair. All of it pinned by the boot contract, against stub git and a throwaway clone. |
||
|
|
9f563c8f94 |
Configure the Kuycon by what it is, not where it is plugged in
The panel's 4500x3000 mode, 1.5 scale, and 10-bit request were a rule for connector DP-2 outright, which handed them to whatever monitor a stranger's machine had on its most common DisplayPort connector. The rule is now matched by description, the per-output prefs loop covers every connector including DP-2, and the displays contract pins the policy to the description rather than the port. |
||
|
|
bd9a55c8eb |
Fail when failing, stop when stopped, and survive what is neither
Four installer bugs, all in the space between exit codes and intent: - A flatpak-only extras category -- most of them -- died at the grep that filters out its dnf half, because grep exits 1 on zero matches and set -e read that as failure. sed deletes lines without editorial comment. The extras contract now runs a flatpak-only category under the installer's own strict options so this stays fixed. - A rate-limited GitHub API call aborted the whole package stage while resolving the RustDesk URL, even though the empty-result fallback was sitting right below it. The pipeline is now guarded so the fallback is reachable. - Ctrl-C did not stop the install: the INT trap ran cleanup and bash carried on with the remaining stages, MOK enrollment and firmware included. INT and TERM now exit explicitly; cleanup rides EXIT. - change-settings and link-dotfiles ran without set -e, so a failed copy over / or a failed symlink fell through to guarded no-ops and the stage reported success. Turning strictness on immediately caught what it had been hiding: link-dotfiles never created ~/.config, so on a truly fresh HOME every symlink was failing silently. |
||
|
|
86825e7327 |
Judge the document portal by its mount, not by its service
No flatpak would launch. Every one of them failed in bwrap with "Can't find
source path /run/user/1000/doc/by-app/<id>", because xdg-document-portal's fuse
mount was gone -- /run/user/1000/doc was a plain empty directory. That mount is
bound into every sandbox bwrap builds, so losing it takes out all 34 flatpaks at
once, never a subset.
It had been gone for three days. The shipped unit is Type=dbus with Restart=no,
so nothing retries it on failure: after it exited 21 it came back only because a
flatpak called its bus name two seconds later, and that activation landed on the
dying instance's mountpoint and came up with no mount at all. systemctl reports
active (running) either way -- the fusermount3 helper is still sitting there as a
child, in this case for two and a half days without ever completing the mount.
Nothing running notices, which is what makes it so quiet. A sandbox needs the
mount only while it is being constructed, so everything already open keeps
working and the symptom arrives whenever you next open a flatpak you had not
opened yet. Here that was three days later, and it presented as "gearlever is
missing" -- an application that was installed, healthy, and entirely innocent.
Two changes, because there are two failures: it does not recover, and nothing
says so.
The drop-in clears the mountpoint before each start, so an activation that
follows a crash lands on clean ground. ExecStartPre rather than ExecStopPost
precisely because nothing restarts this unit -- the next start is whenever
something next wants it, and that is the moment that has to be safe. `-` because
a clean start has nothing to unmount and fusermount3 exits 1 saying so.
/etc/systemd/user rather than a per-user drop-in so it covers every account, and
change-settings reloads the user manager so it applies without a re-login.
The check asks the mount table whether $XDG_RUNTIME_DIR/doc is mounted
fuse.portal. Deliberately not a service probe, and deliberately not folded into
desktop.portals: that one asks about xdg-desktop-portal, a different service
which was up and healthy throughout. Service state is exactly the question that
lied here, so asking it again in a new place would have been no check at all.
Warning carries a restart repair, verified end to end rather than assumed.
The mount table is injectable, like every other path this script reads, so the
contract covers unmounted, wrong-filesystem-at-the-right-path, and unreadable
against written fixtures rather than against whatever /proc happens to say --
coupling the test to this machine's live flatpak state is the same mistake in
miniature. Stubbing the check to always return ok fails the contract, which was
confirmed rather than hoped.
What is not fixed is the crash itself: one occurrence, and restarting the
service to get the desktop working destroyed the evidence. The exit was 21, it
landed 21 seconds after xdg-desktop-portal restarted, and that is one sample and
not a theory. What this buys is that the next one is a two-second blip the
doctor names, rather than three silent days.
Second time for this bug.
|
||
|
|
89417cd6d4 |
Take Claude Desktop from the repository that now carries it
It was `panama app claude-desktop`: a source build, because nothing packaged it. Upstream publishes an RPM repository now, so the exception shrinks to adding that repository -- and the result upgrades with `dnf upgrade` along with everything else instead of needing a slow rebuild every time a version ships. That moves it out of setup/apps/ and into the third-party section of install-packages, beside Bun, Claude Code and RustDesk. It also means it is part of ./install for the first time. The reason it was kept out was the build: slow, wants the network throughout, and fails on an upstream that moved, which is the failure the interview exists to prevent. A dnf install is none of those, and the default dock pins com.anthropic.Claude, so a fresh machine was shipping a pin for something the install had never put there. The repository is added with upstream's own setup script rather than a .repo file written out here. A baseurl copied into this repository is a pin by another name; the script is the part upstream keeps correct. Both halves are skipped when already present, so a re-run costs nothing. The desktop entry id does not change -- it is still com.anthropic.Claude -- so the dock pin and the notification rules carry over untouched. The new package drops the nodejs dependency, which is what used to hide the missing-npm bug the launcher search contract guards; its comment said "depends" in the present tense and now says what actually happened. |
||
|
|
185d7edaa5 |
Open the windows you open together, together
Arrange the desktop, run "Save Layout as Project" from the launcher, name it. "Open Project" lays it out again on free workspaces, so it never lands on top of what you are already doing. Saved layouts are listed on the Desktop settings page, which is where they are removed. Recorded rather than written by hand, and a terminal's directory is most of why it is worth having: without it a project opens three terminals in your home folder and you change directory three times. This machine had two terminals in the same project when it was written, and reopening there is the difference between a layout and a working desktop. Four things had to be found by running it, none of which reading would have shown. A terminal's directory is not the terminal's working directory -- that is where it was launched from. The shell inside it is what has been cd'd. Reading the wrong one looked correct for exactly as long as the terminals under test had been started from the right place, which they had. gtk-launch cannot place a window. It activates over D-Bus, so the process Hyprland started exits and a [workspace N silent] rule has nothing left to apply to; Nautilus landed on whatever workspace was in front of you. The Exec line from the desktop entry is run directly instead. But DBusActivatable applications do the same thing regardless, so the window is found afterwards and moved by address -- which also means a window that never appeared is reported rather than assumed. /proc/PID/task/PID/children is a file of pids, not a directory. Listing it as one always raised, so the fast path was never once taken and everything went through pgrep. And kitty's --directory needs an equals sign or the short -d; the space-separated long form is accepted and silently ignored. The contract exercises a save and open round trip against a stubbed compositor, and reads a terminal's directory out of a real process tree rather than grepping the source for a shell name -- an earlier version passed against a helper that had been changed back, because the constant was still there. Claude-Session: https://claude.ai/code/session_01Q84axqUE5inJhf5Jz9CFy1 |
||
|
|
538c0a887c |
Save things where the rest of the software already saves them
Screenshots and recordings offered three folders to choose between, and three
guesses cannot include the folder somebody's other software already writes to --
which is the only folder that matters. This machine has had ~/Pictures/Screenshots
and ~/Videos/Screencasts since long before Panama, and Panama was writing
recordings to a Videos/Recordings it invented. Both are free text now, and the
recording default is the folder that was already there.
Wallpapers were swept from four directories at once, so the distribution's stock
images arrived mixed in with the user's own and there was no way to ask for just
one. Where wallpapers live is something somebody knows about their own machine.
It is a setting, not a search.
All three accept an absolute path as well as one relative to home, which meant
fixing Capture: it prefixed $HOME unconditionally, so naming /mnt/captures would
have written screenshots to ~/mnt/captures and left nobody able to find them.
The generator turned out to skip any entry whose comment sits inside the braces
rather than above them -- it looks for `key:` immediately after `{`. Three
settings were invisible in the reference because of it, one of them dockScreens,
which has never appeared there at all. The staleness contract could not see it
either: regenerating reproduced the same omission, so the copy was current and
incomplete at once. It now counts what was declared against what it could read
and refuses rather than quietly documenting less than exists.
Claude-Session: https://claude.ai/code/session_01Q84axqUE5inJhf5Jz9CFy1
|
||
|
|
033d5b21f8 |
Build the launcher's extension on a machine that has only nvm
The search extension is compiled, and the stage that compiles it checked for npm and skipped quietly when it found none. On this machine it always found one -- but only because Claude Desktop depends on nodejs and dragged a system npm in. Nowhere else would. Node moved to nvm when the shell config turned out to have been assuming it for months, and nvm is a shell function in a file only an interactive shell sources; a stage is not one. So a fresh install would have set up the launcher, printed one line about extensions not being built, and left somebody wondering why typing in it suggested nothing. The stage sources nvm before looking, and the contract pins that it does -- checking for npm is not the same as being able to find it. Claude-Session: https://claude.ai/code/session_01Q84axqUE5inJhf5Jz9CFy1 |
||
|
|
7cd4131327 |
Hold a key, speak, and the words are typed
Super+D holds the microphone open, releasing it transcribes on the GPU and types the result wherever the cursor is. Roughly 150ms for a normal utterance once the model is resident, measured rather than hoped for. Getting there meant discarding two approaches. Fedora 44 cannot install any GPU-capable Whisper for Python -- openai-whisper needs a numba that needs an llvmlite that does not exist for 3.14, and faster-whisper needs a ctranslate2 nobody packaged. The whisper-cpp package IS built with HIP but ships libraries with no binary and no bindings, and hand-writing ctypes for a large by-value struct is a segfault waiting for a version bump. So a container, as suggested. Vulkan rather than ROCm, and upstream's image rather than one built here. ROCm is seven gigabytes and serves AMD alone; Vulkan compute runs on the AMD, Intel and NVIDIA machines this config is used on, in a twentieth of the space. The Vulkan tag already contains whisper-server, so there is no Containerfile to keep working -- an earlier draft of this commit had one, and it was strictly worse. Two bugs found by using it rather than by reading it. Whisper describes silence as the literal text "[BLANK_AUDIO]", and the first working version pasted that string into the clipboard; a transcription that is nothing but such markers is now discarded. And the server answers with a line per segment, which typed into a window is an Enter press -- sending the half-written message, submitting the form. Whitespace is collapsed to one line. Neither the image nor the model is installed by ./install. Together they are over two gigabytes that want the network, and Settings offers both as one action instead. Nothing starts at login either: whisper-server holds the model from the moment it starts, so the first press of the key is what brings it up. The contract pins both text bugs, that the server stays on loopback, and that it does not start at login. Reverting the [BLANK_AUDIO] guard did not fail it at first -- the check was still correct, it had simply stopped being called -- so it now checks the call site too. Claude-Session: https://claude.ai/code/session_01Q84axqUE5inJhf5Jz9CFy1 |
||
|
|
b280bd02d7 |
Let the Home Assistant contract skip a server that is not there
It already meant to skip when no token was configured, and could not: the helper exits 2 for any catalog it cannot complete, so `set -e` aborted at the capture before the skip was reached. The contract failed with no output at all, which reads as a crash rather than as a skip, and the branch written to prevent that had never once run. So the status is taken deliberately, and there are now two skips rather than one. No token is not a defect in Panama. Neither is a bridge that does not answer -- off the network, VPN down, the server asleep -- which is the same reasoning the extras contract already uses for dnf and Flathub being unreachable. Only "unreachable" skips, which the helper raises exclusively for a timeout or a socket error. A bridge that answers and refuses still fails: authentication rejected, a bad response, a catalog of the wrong shape. Those are what this contract is for, and all seven paths were exercised against a stubbed helper to confirm which fail and which do not. 129 contracts pass, with none of them red for a reason nobody intends to fix -- which was the point. A suite expected to be red stops being read. Claude-Session: https://claude.ai/code/session_01Q84axqUE5inJhf5Jz9CFy1 |
||
|
|
4c77bc2f61 |
Decide whether the other screens join in on workspaces
GNOME's Multitasking panel asked one workspace question worth reproducing, and it is not which workspace goes on which screen. It is whether the second screen participates at all: workspaces on the primary display only, or each screen with its own. Ten rows of per-workspace assignment would be more powerful and worse. Off is Hyprland's own behaviour and emits nothing. On pins workspaces 1 to 10 -- however many ALT+1..ALT+0 actually reach, read from keybinds.lua rather than written down twice -- to whichever output is recorded as primary. With no primary recorded, nothing is pinned: guessing one would move every workspace onto whichever output happened to sort first, and this machine is in exactly that state. Applying is a reload, which is the part that shaped the design. Hyprland reads workspace rules at config time and will not remove one afterwards -- a rule written with an empty monitor keeps its old binding, which was checked rather than assumed. Only a reload clears them, so the config is the only honest source and the page cannot pretend a change has landed before one happens. Hence a service that reads `hyprctl workspacerules` back rather than inferring success from having written the preference, and a Reload row that exists only while the two disagree. Verified end to end against the live compositor and put back: off emits nothing, on emits ten rules naming the primary, and turning it off clears them. The settings file came back byte-identical. Claude-Session: https://claude.ai/code/session_01Q84axqUE5inJhf5Jz9CFy1 |
||
|
|
9092a80f66 |
Search from the launcher, and give the touchpad something to do
Four things a Hyprland desktop can do that this one was not. Searching from the launcher needed no launcher work at all: Vicinae already models it, so this is a script command with one percent-encoded argument. Make it the fallback command and anything typed that matches nothing else offers to search it. Bangs come free -- they are a property of where the query is sent, not of the launcher -- so !yt reaches YouTube without a line of bang parsing. Suggestions could not be a script command. They need a view that reacts as you type, which is an extension: TypeScript, compiled, querying the same endpoint Firefox's address bar uses. It debounces, and aborts the request in flight on every keystroke -- typing is faster than the network, and an older answer landing after a newer one leaves the list describing a query that is no longer on screen. A bang skips suggestions entirely, because Google has no useful guesses about "!yt". The engine is now written down twice, once in each. The contract pins that they agree, since searching from the fallback and searching from the suggestions reaching different places is the kind of wrong that looks fine. Gestures mirror GNOME: three fingers sideways for workspaces, up for the overview, down to dismiss it. Open and close rather than toggle both ways -- toggling means swiping up from an open overview closes it, which is not what the fingers meant. Hyprland reads gesture registrations at startup so they cannot be a setting, but distance and direction can be, and are. Window swallowing is off by default and a preference like every other misc setting here. A terminal that vanishes when you did not ask for it is confusing rather than broken, which is worse. Claude-Session: https://claude.ai/code/session_01Q84axqUE5inJhf5Jz9CFy1 |
||
|
|
725e274ef4 |
Install the Node this shell config has always assumed
config/bash/shell sources /etc/profile.d/nvm.sh, switches Node per project from .nvmrc, and puts PNPM_HOME on PATH. None of it worked on a fresh machine. nvm was never installed -- it is a Terra package, present here since before Panama -- and the source was unconditional, so every shell on a new box opened with an error before it got as far as failing to find nvm. That is the second instance of the same bug. $HOME/.cargo/env was the first, and fixing it one file at a time is why this one survived: the dependency contract scanned setup/scripts, bin and the quickshell helpers, but never config/bash -- the one place in this repository whose entire job is to name tools and source the files that provide them. So it scans it now, and checks the shape rather than the instance: a literal path sourced without testing it exists is a finding, wherever it appears. It found the nvm line, and authselect behind the fingerprint aliases. Node and pnpm move to nvm with it. They were declared as dnf packages while the machine ran them from ~/.nvm, which is not a preference so much as a contradiction -- a system Node earlier on PATH wins every `nvm use`, so the per-project switching this shell config sets up could never have worked. nvm install --lts, then pnpm inside it, so pnpm travels with the Node version it belongs to instead of outliving it. Claude-Session: https://claude.ai/code/session_01Q84axqUE5inJhf5Jz9CFy1 |
||
|
|
f09763ef5d |
Check the two facts the README states about itself
It claimed 121 contracts when there were 125, one day after the number was written, and it documented every panama subcommand except the one added last -- so `panama apps` existed and the README did not mention it. A number in prose is worth something as a claim somebody relies on and nothing once it is wrong, so it is either checked or it should not be there. This checks it, counted the way the runner collects the suite rather than by a second idea of what a contract is, and checks that every subcommand the README documents is one the dispatcher actually handles -- a listed command that errors reads as a broken install rather than a stale document. Claude-Session: https://claude.ai/code/session_01Q84axqUE5inJhf5Jz9CFy1 |
||
|
|
215da285f3 |
Let applications be chosen a few at a time
The catalog held fourteen applications. This machine runs thirty-four flatpaks, so most of what is actually used had no way to be installed from here at all -- Zoom, Slack, Obsidian, Spotify, LibreOffice, OBS and its sixteen plugins. So the catalog is seeded from the machine, and `panama apps` opens it: pick a category, tick what you want, install just those. ./install still offers the same catalog as whole categories, because during a first install you want coarse and fast. Both read setup/lib/extras-catalog. Two parsers would eventually disagree about what a category contains, and the one that disagreed quietly would be the one that runs unattended. Two pieces of syntax earn their keep. A `| Name` suffix gives the menu something readable, since com.obsproject.Studio is not a name anybody wants to pick from a list. An indented line belongs to the entry above it, which is how OBS carries its plugins as one thing to tick rather than seventeen -- they are extensions of the flatpak, useless alone. That is also why creative moved from dnf to Flathub: the plugins attach only to the flatpak, so the dnf build cannot have them. The rest of the category followed rather than leave one machine with GIMP from dnf and its neighbour from Flathub. The contract now reads the catalog through the same parser instead of keeping a third idea of the format, and checks the two things this syntax can break silently: a label leaking into an install command, and a bundle that installs the application without its plugins. It caught a typo in the Pixelorama id on the first run. It also got slow enough to be worth fixing -- fifty-one names, each its own network call. One bulk query per manager took it from minutes to four seconds. That query needs `flatpak remote-ls --all`: without it, end-of-life applications are hidden and read as missing, which reported yuzu as gone from Flathub when it installs perfectly well. Claude-Session: https://claude.ai/code/session_01Q84axqUE5inJhf5Jz9CFy1 |
||
|
|
f457c1eb9f |
Build the two applications nobody packages, on purpose rather than in passing
Claude Desktop and ChatGPT Desktop ship for macOS and Windows. The Linux path for both is a community wrapper that converts the official build into an RPM -- so what lands is still a package dnf owns and can remove, which is the part of the dnf/flatpak rule that actually matters. What they need an exception for is the build itself, and there is no packaged form to prefer over it. `panama app` builds one by name, and is deliberately not part of ./install. A source build is slow, wants the network throughout, and depends on an upstream that moves -- twenty minutes in, an error, with nobody at the keyboard, which is the exact failure the interview exists to prevent. Asking for one is something you do on purpose, and it is also the rebuild path when a new version ships. Nothing is pinned. Each build takes the current default branch and the current upstream release, and reports a failure rather than working around it, leaving the tree where the error can be read. sunhat pinned versions and every pin was a 404 within a release cycle. Adding one is adding a file to setup/apps/, and the file has to say why the exception exists -- the contract fails a definition that does not, because the guard against this list growing by habit is having to write the reason down. sunhat had seventy-odd installers and a reason recorded for none of them. The contract had a bug worth recording: `while read` on the right of a pipe runs in a subshell, so two of its three per-definition checks recorded findings into an array that went out of scope at the end of the loop. It reported PASS on a definition with no description and no build function. Found by standing one in deliberately and noticing only the third check spoke up. Also: nautilus-open-any-terminal is now declared, and Panama's copy of the extension is gone. Fedora packages that extension AND its gsettings schema, and Panama shipped its own fork of the .py over the same path while declaring neither -- so a fresh machine got an extension whose schema did not exist. It worked here only because the RPM has been installed since sunhat. The fork was also 63 lines behind the packaged version, missing its newer Nautilus and Caja handling. Auditing the rest of config/copy for the same shape found nothing else: dnf.conf is a config file its package expects to be replaced, and the GPU udev rules are Panama's own. 125 contracts pass. Claude-Session: https://claude.ai/code/session_01NvgBuSWB5sE43yWmg21ozj |
||
|
|
6016efa436 |
Meet main where it has moved since this branch was written
The rebase itself is the previous five commits replayed onto main; this is what
they needed once they landed there, kept separate so the replay stays readable.
The shell did not start. A Column in this branch's notification settings menu
assigned its own implicitWidth and implicitHeight, which a Qt 6 positioner
computes and does not let you set. That took out every contract that launches a
shell -- six of the seven failures were this one line, and none of them said so
until the error was read to the bottom. A Column already measures itself from its
children, so the bindings are simply gone.
Three assertions pinned an implementation main has since replaced, and each is
updated to pin the intent rather than the mechanism:
- The display picker now reads primaryFirstMonitors, which is monitors sorted
with the primary first. Still populated from what is connected, which is what
the contract is for; the sorted list is the point, so the picker opens on the
display somebody is most likely to mean. This branch made that change and
broke its own contract without noticing.
- The accent swatches come from the accentName schema rather than
Object.keys(Theme.accents). Same swatches, same order, one source shared with
every other enum row.
- The OSD used to take no pointer input at all. It takes some now, because this
branch's own design calls for a secondary click on a visible OSD to open its
settings, and a Wayland input region cannot admit one button and refuse
another. The rule that survives is that the region stays bounded to the OSD's
own card: it floats over other windows for a couple of seconds, and a region
bigger than the card would swallow clicks meant for something underneath.
Theme's accent table moved to ThemeProfiles, which is this branch's point -- a
curated accent and a custom profile become the same kind of record. main had
meanwhile given each accent a `gnome` member, the nearest name in GNOME's fixed
accent-color enum, which is what makes libadwaita applications recolor instead of
staying in GNOME blue. That member moved into the curated table rather than being
dropped, and adwaita-accent-contract now reads it where it lives.
Where main had simply moved further along the same path, main won: the focused
border driven by the chosen accent rather than a hardcoded pair, the gradient
built through the shared serializer rather than a hand-rolled string, the
multi-edge dock geometry. This branch's context menu, keyboard focus and
accessibility work sit on top of those rather than beside them.
Three new contracts arrived carrying .sh and lost it, along with the references
in this branch's own plan.
124 contracts pass.
Claude-Session: https://claude.ai/code/session_01NvgBuSWB5sE43yWmg21ozj
|
||
|
|
ed428e87c4 | Complete the Panama theme system | ||
|
|
69ecec7ecf | Complete contextual desktop controls | ||
|
|
a90f6eb357 | Fix wallpaper scan cap exit status | ||
|
|
c4642919f7 | Close desktop safety gaps | ||
|
|
e1faaf7a76 |
Drop the extension, and give the test suite a front door
Phase 6, the last of the fresh-install spec. 159 scripts lose their .sh: 110 contracts, 47 Vicinae commands, 2 compositor contracts. A shebang and the executable bit already select the interpreter. The extension only ever added something that had to stay in sync, and the rename proved the point twice over in the space of an hour. The spec's stated risk was Vicinae's script discovery. One script was renamed and reloaded on its own before the other 46 followed; it came back as scripts:panama.capture and all 47 resolve. What the probe turned up instead is that the extension was never only a filename: Vicinae's command IDs embed it, so every ID changed. Nothing in this repository refers to them, so nothing breaks. The only trace is Vicinae's metadata.json, whose visited map had two Panama entries that are now orphaned -- two commands lost their usage ranking and will earn it back. Worth knowing before anyone renames these again on a machine that has a keybind pointing at one. Rewriting the references by exact filename missed two things it structurally could not see: a name built from a variable, settings-$page.sh, and a glob, -name '*.sh'. Both were in the contract that counts the generated commands, which promptly reported 47 expected and 0 found. The mechanical part of a rename is the part that looks finished. The three subcommands. panama doctor fronts a health check that already existed and already ran at the end of every install but could not be reached from a terminal. panama upgrade re-runs the installer from anywhere. panama test runs the suite, which had no entry point at all -- 121 files that were the main safety net in this repository and were invisible in it. Writing that runner found three tests nothing was running. calendar_agenda_bridge_test, home_assistant_bridge_test and kdeconnect_bridge_test are unittest suites without the executable bit, so no contract invoked them and the first draft of the runner skipped them silently. All three pass, and have passed unobserved for weeks. The runner collects *_test.py as well now, because a runner with a blind spot is worse than no runner for the same reason a dependency checker with one is: it reports PASS. Six worktrees pruned. Each was re-checked rather than trusted to the spec's list, and two needed it: panama-commands is not on feat/panama-commands but on feat/gnome-tweaks-parity, and fix/panama-displays-review reads [ahead 3] -- ahead of its remote, not of main, with every commit patch-equivalent to landed work. roadmap-completion stays; it has five commits that are genuinely unlanded. The branches are left alone: pruning a worktree costs nothing, deleting a branch is a decision. 121 contracts pass. Claude-Session: https://claude.ai/code/session_01NvgBuSWB5sE43yWmg21ozj |
||
|
|
47f29f9fa9 |
Stop describing a desktop this repository does not install
Phase 5. The README advertised two desktops that coexist -- GNOME with Forge, Dash-to-Dock, Openbar and Vitals, alongside Hyprland -- and nothing in setup/ installed or configured any of the first one. Panama configures one desktop, and now says so. config/dot/forge is deleted along with its entry in link-dotfiles. It was the hedge from when the GNOME session was still the fallback and Hyprland was being built beside it; the hedge has been paid off. Nine files, six of which were Forge's own editor backups that should never have been committed. Searching for the rest of GNOME found nothing else to cut, which is recorded in the spec so nobody goes looking again. change-settings never enabled an extension. The mentions of Dash-to-Dock, Openbar and Vitals through the shell are comments saying what a component was modelled on -- which intellihide behaviour the dock reproduces, where a colour came from -- and DESKTOP-PARITY.md is the table of what replaced what. That is provenance, and it is the reason those components behave the way they do. Vitals in services/ is Panama's own bar service and merely shares a name with the extension it replaced. The handoff panel list was wrong in two places. It named Wacom, which nothing hands off to, and Region, which is a subpage of System rather than a panel. The nine real ones are read off the call sites and the allow-list that gates them. The spec said it, the comment on gnome-control-center repeated it, and the README would have made it three. One test gap turned up and is closed. The assets contract caught a directory under config/dot/ that nothing links, but not the inverse: a name left in the dirs array with nothing behind it, which makes link-dotfiles point ~/.config/<name> at a path that does not exist. Deleting Forge is the exact move that introduces that, and nothing would have failed if the array entry had been left. A dangling symlink is worse than a missing one, because everything that looks there finds something. Verified by putting the entry back and watching it fail. The audit of docs/settings.md this phase asked for needed nothing: it is generated from PreferenceSchema.qml, a contract already fails when it goes stale, and it carries no claim about GNOME or Forge. The README gained the section it was missing instead -- the 121 contracts under tests/ were the main safety net in this repository and went entirely unmentioned in it. Claude-Session: https://claude.ai/code/session_01NvgBuSWB5sE43yWmg21ozj |
||
|
|
88497826ec |
Let a machine say what it is for, and give Firefox its face back
Phase 4: the optional application categories, and the Firefox chrome. Everything Panama installed until now was what every machine gets, which meant a work laptop acquired emulators and a desktop that wanted Steam had to be told about it by hand. The interview now offers the categories in setup/packages/extras/ as a checklist -- gaming, creative, communication, virtualization -- and nothing is preselected, because a default here installs applications nobody chose on a machine whose owner answered a question they thought was about something else. A category is one file, and a category mixes both package managers because the applications do: Steam is in RPM Fusion, Slack publishes only a flatpak. So a bare line is a dnf package and a flatpak: line is a Flathub ID, and one file holds the whole answer rather than splitting each category across two. The menu is read from the directory rather than written down, so adding a category is adding a file. Every name in all four was resolved against the actual repositories before being written down, and the contract re-resolves them -- the point of admitting applications one at a time is that they stay installable, and a typo here fails on somebody else's machine, not this one. Firefox is declared, and its chrome is Edge-Frfox, vendored into config/firefox. sunhat carried that theme with no license and no attribution; it is MIT, and now it says so and says whose it is. It is the only piece of Panama's configuration that does not go to a path this repository chooses. Firefox owns the profile directory, names it with a random salt, and does not create one until the browser has been run -- so link-dotfiles finds or creates a profile and links both halves into it. Both, or neither works: chrome/ is the CSS and user.js sets the preference that makes Firefox read chrome/ at all, without which the theme is a directory of dead files. Two assumptions there were wrong, and the contract exists for both. Firefox has moved to the XDG directories -- the profile root is ~/.config/mozilla/firefox on this build, not ~/.mozilla/firefox, and writing to the wrong one themes nothing and says nothing about it. And -CreateProfile turns out to be non-interactive, so a fresh machine gets the theme on the first install rather than the second. The contract runs link-dotfiles for real against a throwaway home with no profile in it and looks at what came out; it was checked by pointing the search at the legacy path only and watching it fail. Also: the enrolment/enrollment spellings from the last commit are corrected. This repository is US-spelled everywhere else -- color 1131 times against colour never -- and consistency in prose is worth as much as it is in code. Claude-Session: https://claude.ai/code/session_01NvgBuSWB5sE43yWmg21ozj |
||
|
|
b319d1a5e1 |
Stop handing dnf the comments that explain the package lists
Every list in setup/packages/ is annotated -- which package exists for which settings page, why an exception was made -- and install-packages passed the whole file to dnf, comment lines included. dnf does not ignore an argument it cannot match. It reports "No match for argument: #" and exits 1, and with set -euo pipefail at the top of that script the first annotated list ends the stage. initial-packages carries four comments and is the first list read, so a fresh machine got the repositories, the group updates, and then nothing. Two things hid it. On a machine that already has everything, a re-run matches every real name and fails only on the comments, so the failure looks like noise rather than the stage dying. And every contract that reads these lists strips comments with sed before comparing -- the tests were reading a file the installer was not, which is why a repository with a dependency contract, an assets contract and a doctor still reported PASS across the board. The fix is one filter used at all five call sites. The contract lifts that filter out of the script and runs it, rather than describing what it should do, so deleting or renaming it fails here instead of passing quietly. It also checks the inverse -- that stripping comments does not strip packages -- because trading a loud failure for a silent one would be worse than the bug. Found while adding the extras lists for phase 4, which are annotated the same way and would have hit the same wall. Claude-Session: https://claude.ai/code/session_01NvgBuSWB5sE43yWmg21ozj |
||
|
|
13f3648e4d |
Install the driver, enrol the key, and still never ask twice
Phase 3 of the fresh-install spec: the parts of a run that depend on what the machine actually is. NVIDIA, Secure Boot, Fedora's preinstalled extras, firmware. Two of these looked like they would force a compromise, and neither did. sunhat opened an editor in the middle of its run so grub could be hand-corrected, and that single step is why walking away from an install did not work. The step existed to delete duplicated kernel arguments -- and grubby replaces an argument that already exists rather than appending a second copy, so the duplicates cannot accumulate and there is nothing to correct. The editor was load-bearing for a problem that a different tool does not have. MOK enrolment needs a password now and the same password at the next boot's blue screen, which reads like a prompt that has to happen mid-run. mokutil has --generate-hash and --hash-file for exactly this: the interview asks, hashes it on the spot, and records only the hash. The plaintext never reaches the answers file, the environment, or a command line, and the stage runs without asking. The stage runs last rather than fourth as the spec's table had it. The constraint was always "late" and fourth of eight is not late: enrolment arms a prompt for the next boot and firmware may want a reboot, so a machine that reboots out of this stage should already be completely configured. Every question names what was found -- the card, the packages actually installed -- and is not asked at all on a machine it would do nothing to. sunhat's debloat list no longer describes Fedora 44: totem became showtime and LibreOffice is not preinstalled, so the list is curated and a package that is not installed is never passed to dnf, which is what lets it outlive a release. This stage cannot be verified by running it. It installs a proprietary driver and queues a Secure Boot enrolment, and this machine is an AMD desktop. So every privileged command is stood in on PATH and the contract asserts which answer led to which call: that no answers means no commands, that a failed driver install is not followed by arguments and services for a driver that is not there, that the hash reaches mokutil through a file and never a command line, and that removal is offered only for packages that are installed. The contract was checked by breaking the stage three ways and confirming it caught each. It does not verify that akmod-nvidia builds, and says so where a reader would otherwise assume it did. The README's stage table listed three of seven stages; the interview and identity work never reached it. Corrected rather than extended, since a table that lists three of seven is worse than one that lists none. The Desktops section still describes a GNOME session nothing installs -- that is phase 5. Claude-Session: https://claude.ai/code/session_01NvgBuSWB5sE43yWmg21ozj |
||
|
|
359fb922aa |
Install the four applications this desktop assumed you had
Helium was already declared. Podman Desktop is on Flathub, so it joins the flatpak list beside the podman it fronts. RustDesk was the interesting one. panama-doctor has checked `rustdesk.service` for as long as it has existed, and autostart.lua works around the tray that service spawns -- so RustDesk was already part of this desktop, installed by nothing. The flatpak cannot register a root-owned system service, so unattended access needs the RPM. Claude Code has no RPM and no flatpak either, so it takes the official installer and keeps itself updated afterwards. Neither pins a version. sunhat pinned upscayl 2.11.5, LACT 0.5.4 and a fedora-40 RPM, and every one of those was a 404 within a release cycle; the RustDesk URL is resolved from whatever the latest release happens to be. Both are skipped when already present, and a failure is logged and stepped over rather than aborting a stage that has already installed the desktop. That leaves three exceptions to the dnf-or-flatpak rule, all named in one place with a reason each. The dependency contract now knows they are installed out of band, so probing for them with `command -v` is not read as an undeclared dependency -- narrowly, per command, so a genuine omission still fails. Claude-Session: https://claude.ai/code/session_01Q84axqUE5inJhf5Jz9CFy1 |
||
|
|
b6448c9876 |
Give the revealed Dock back the pointer that revealed it
The bottom dock came up when the cursor reached the edge and hid again a quarter-second later with the cursor still sitting there. The input region has two shapes: a three-pixel strip along the whole edge while hidden, and a region over the body once revealed. Teaching the dock about left and right rewrote both, and the bottom case was folded into the branch that serves a left dock -- x 0. That is right for a dock that hugs the left edge and wrong for one that is centred on the bottom: the region landed on the left third of the screen while the pointer that summoned the dock was in the middle. Hover dropped on the very frame the dock arrived, and the hide timer did the rest. Approaching from the far left worked, which is the only reason it looked intermittent rather than broken. Bottom is centred, so the region starts where the body starts. Nothing measured the input region, which is why "bottom is unchanged" passed while bottom was broken -- the contract read the window and the window was fine. It now probes the mask in both states on all three edges and asserts the point a hand actually aims at, the middle of the edge the dock lives on, is still inside the region after the dock arrives. It fails on the old binding with the coordinates that were wrong. Claude-Session: https://claude.ai/code/session_01NvgBuSWB5sE43yWmg21ozj |
||
|
|
15d54b16f6 |
Ask everything first, then run without needing anybody
sunhat's failure mode was a question twenty minutes into a run. Walking away from an install meant coming back to a prompt that had been waiting an hour. So the questions move to the front. A new interview stage asks what Panama needs to be told -- hostname, git identity, whether to sign in to GitHub, whether to make an SSH key -- shows the answers back, and asks once to proceed. After that nothing asks again. gum is bootstrapped before it runs, because the interview is built on gum and gum arrives with a stage that has not run yet. Answers reach the stages through a mktemp file that install sources and the existing trap deletes, since a child process cannot export into its siblings. They are not remembered between runs: there is no state file to go stale, and one of the answers is an email address. The interview asks only what a stage in this repository actually consumes. Extras, hardware and debloat questions arrive with the stages that act on them -- a prompt whose answer nothing reads is a control that lies. The new contract pins that in both directions, and four deliberate mutations confirmed it catches a question nobody reads, a stage reading something nobody asks, an answers file left on disk, and a declined interview that fails to stop the run. The run now ends with panama-doctor, because a failed-stage count says nothing about a service that did not start. It never changes the exit code: on a fresh machine, unconfigured is the honest answer, not a failure. espanso and oh-my-posh stop being exceptions -- Terra packages espanso-wayland and Fedora packages oh-my-posh, so the curl installer is gone. bun is now the only remaining one. Claude-Session: https://claude.ai/code/session_01Q84axqUE5inJhf5Jz9CFy1 |
||
|
|
96e4085919 |
Install the desktop this repository already describes
The shell named a font, a pointer theme and a wallpaper that no package list installed and no stage placed. It went unnoticed because this machine collected all three under sunhat and never lost them; a fresh Fedora box would have come up with tofu for every shell glyph, the default pointer, and no wallpaper -- while Wallpaper.qml called that missing file `shippedPath`. The dependency contract reported PASS throughout, because it reads commands that scripts invoke and none of these are one. The new assets contract covers what it structurally cannot: fonts and pointer themes named in configs and gsettings, a shipped wallpaper that must exist, commands launched from QML, and directories nothing puts into service. Written against the broken tree first, where it found ten faults. Four of those were packages nobody had noticed were missing -- gnome-calendar, podman, pipewire-utils and flatpak -- alongside gnome-control-center, which backs fifteen rows of Panama's own Settings and is commented so it is not mistaken for GNOME-session residue later. Fonts turned out to need no install stage at all. Terra, which install-packages already enables, packages every Nerd Font, so sunhat's wget-and-unzip is replaced by five lines in a package list. The pointer theme had no such luck: it is packaged nowhere, so it is vendored rather than downloaded from a URL that can rot. espanso stays undeclared. It is in no enabled repository, and building it from source is the install method this repository is trying to stop using. Claude-Session: https://claude.ai/code/session_01Q84axqUE5inJhf5Jz9CFy1 |
||
|
|
3b01f1e020 |
Let the Dock choose an edge, choose its screens, and be dragged into order
Three things that were parked, and the reasons they were parked turned out to be the useful part of doing them. The Dock can sit on the left or the right as well as the bottom. Everything that assumed the bottom edge is now asked which edge it is on: the anchors, the axis that gets an implicit size, the sliver of input region that survives hiding, the direction the body slides away in, and which side a tooltip opens towards. The body was a Row and is a Grid, because one declaration then serves both orientations -- Row and Column would each need their own children, and the cross-axis anchors that centre items in a Row are the wrong axis in a Column. Bottom is unchanged in every particular, and the settings default to it, so a hot reload in the middle of this work left the running dock exactly where it was. One bug worth recording because static review would never have found it: a dock spans the edge it lives on, which means anchoring BOTH ends of that edge. The first side dock anchored top and left only, was free to collapse to its implicit height, and came out one pixel tall. It parsed, it loaded, and it rendered nothing. The contract measures the geometry rather than reading the source for that reason, and was verified by putting the single-ended anchor back. Per-screen is a list of names where empty means every screen, because a list is what goes stale when a display is unplugged and "all" should not be spelled as one. Turning off the last screen collapses to "all" rather than leaving no dock anywhere and no obvious way back. Pins can be dragged by a grip. The objection this file recorded for a long time was real -- dragging inside a Flickable inside a scrolling page fails in a way that reads as breakage -- and the answer is preventStealing on the grip, so the page cannot claim a gesture that started there. The arrow buttons stay: they are the keyboard-reachable path and a grip is not. The order is held locally during the drag and written once on release, rather than rewriting settings.json for every slot crossed. Claude-Session: https://claude.ai/code/session_01BRvzt4H8XXLPVH5MyYdk9L |
||
|
|
23141673a2 |
Hang the Control Center where every other popover hangs
Five surfaces sat 12 pixels under the bar -- the date menu, the activity panel, notification toasts, signal glass and the clipboard, all using barGap * 2. The Control Center sat at 2, through a constant of its own, which left the widest surface in the shell hanging ten pixels higher than the date menu beside it. That constant arrived with the original Control Center and carried no reason, while barGap directly above it explains itself. The clipboard even cites QuickSettings in a comment for how it derived its own margin, and still landed on 12. It reads as an early value nothing else converged on rather than a decision, which is why it is going rather than being documented and kept. The contract that guarded it pinned the literal, and that same file already records where pinning a literal led: it once asserted the buggy margin expression, so the code and the test agreed and a 38-pixel gap was invisible to both. Replacing one number with another would have repeated it. It now reads the top margin out of the Control Center and out of the date menu and requires them to match, so drift in either direction fails -- verified by moving each one in turn and watching it break. Claude-Session: https://claude.ai/code/session_01BRvzt4H8XXLPVH5MyYdk9L |
||
|
|
4cbab01ae2 |
Show what has actually been installed
Automatic updates leave no other trace. The Flatpak that sat here as "1 update available" installed itself at 00:14 this morning and nothing on the machine would have said so. Both sources are asked in their own machine-readable form and merged on time, so the answer reads as one history rather than two lists to interleave by eye. Two parsing traps worth recording next to the code. flatpak's --json prints timestamps as "Aug 20 08:07:46" with no year in them, so the year is inferred and a date that would land in the future is read as last year's. And dnf5's start_time is epoch UTC while its own history table prints that same value as though it were local -- checked against rpm, and the local rendering here is the correct one. The contract asserts entries are newest first, that none is dated in the future, and that both sources parse; it was verified to fail by breaking the year inference so every flatpak entry landed tomorrow. Loaded on demand rather than with the page, because it reads both full transaction logs. Claude-Session: https://claude.ai/code/session_01BRvzt4H8XXLPVH5MyYdk9L |
||
|
|
de45f205ad |
Carry settings between machines by allow-list, not by stripping
panama-settings-backup already snapshots this machine so it can be put back exactly as it was, arrangement and all. This is the other thing: an export meant to travel, carrying the preferences that describe taste rather than hardware. The export is an allow-list read from the preference schema rather than a deny-list of things to remove. A key added later that happens to hold a token cannot leak into a file somebody emails to themselves; being wrong in this direction loses a setting, being wrong the other way publishes a secret. It earned that immediately -- this machine's store holds an orphaned shadowOffset from a setting that no longer exists anywhere in the source, and it was left behind without anyone having to know about it. Three settings stay: the display arrangement, which is keyed by output names that mean nothing elsewhere; the last page opened, which is session noise; and schemaVersion, which belongs to the store rather than to a person. Import is a merge, so settings a file does not mention are left alone, and it is idempotent. Two bugs made and caught here, in opposite directions. Validation missed 36 settings because "real" was spelled "float" and enums fell through entirely, so an out-of-range or nonsense value would have been written straight into the store. Correcting that then broke numeric enums -- vrrPolicy is an enum of 0..3 and the options were read with a regex that only matched quoted values, so those settings had no known choices, were declared unverifiable and were refused: valid settings dropped silently in transit. The contract could not see the second one. It checked only that bad values are refused, and when numeric enums were unreadable they never reached the bundle at all, so every "did it arrive" assertion was satisfied by their absence. It now requires the export to carry what it should as well as withhold what it should not, and was verified to fail in both directions. Claude-Session: https://claude.ai/code/session_01BRvzt4H8XXLPVH5MyYdk9L |
||
|
|
52e2a83a78 |
Add an SSH Keys page, and refuse the one control that would lie
The page shows which keys exist, what the agent is holding, and the hosts this machine has met, with a two-press forget for a host whose key has changed. Nothing here reads private key material. Fingerprints and comments come from the .pub file, and "does this key need a passphrase" is answered by asking ssh-keygen to derive the public half with an empty one -- it succeeds for an unencrypted key and fails for an encrypted one, and either way the only thing it can emit is public. The contract checks that against the payload that actually reaches the page rather than against the source, because what the code intends and what it ships are different claims. Unloading a key from the agent is refused, with its reason. On this desktop `ssh-add -d` prints "Identity removed" and the key is still offered a second later: gnome-keyring's agent lists every key it finds in ~/.ssh, so a removed one comes straight back off disk. That was measured rather than assumed -- a plain ssh-agent removes durably, this one does not -- and a button reporting success while changing nothing is worse than no button. The page says so and names the thing that does work: move the file out of ~/.ssh. SSH_AUTH_SOCK is not set in a normal shell here, so a naive check reports "no agent" while one is plainly running. The helper falls back to the keyring socket, and an agent started by hand still wins. That gap is the same one that made reaching these servers awkward in the first place. Generating a key is deliberately absent. A passphrase cannot reach ssh-keygen without going somewhere it should not -- -N puts it in argv, which every process on the machine can read -- and driving the prompt over a pty did not work. Offering to generate an unencrypted key instead would be a downgrade dressed as a feature, so the page does not offer to generate at all. Claude-Session: https://claude.ai/code/session_01BRvzt4H8XXLPVH5MyYdk9L |
||
|
|
79b3d5cb85 |
Close the sweep's last blind spot, and stop shortcuts silently colliding
gapsIn and gapsOut were the only two compositor settings the write sweep had never verified: Hyprland answers for them in CSS shorthand, "5 5 5 5", and the sweep had no way to compare that. The preference behind each is a single int that Hyprland expands to four sides, so a uniform reading compares exactly. A non-uniform one is not something the preference can express, and is skipped rather than collapsed to a number it never wrote. 63 of 63 verified live now, none skipped. Wallpaper thumbnails are cached. The report that five of them sat at "Loading…" was a screenshot taken 1.1 seconds after the page opened -- decoding one of these at tile size takes between 1.2 and 2.6 seconds and about ten start at once, which the code already said. Measuring it did turn up something real though: without a cache, scrolling back up pays that decode again for every tile. The tradeoff is a wallpaper replaced in place showing a stale thumbnail until restart, which is worth it for a directory of files that are added rather than edited. A chord already in use is now named rather than taken: "Super+Q is already Terminal". Two actions on one chord means whichever Hyprland reads last wins, which is not a thing to find out later by pressing it. Rebinding a shortcut to the chord it already holds is correctly not a conflict. Also: Open Appearance lands on the Windows tab now that the page has tabs, Storage points at reclaimable container space, and a dock row shows its desktop id only when two pinned applications share a name -- it is developer text, and repeating it under fifteen recognisable names made the list harder to scan. Written down because it cost the shell: QML has no default parameter values, and `function openSettings(page: string, section: string = "")` fails the entire configuration rather than the one function -- so the bar and dock went with it, and 43 contracts failed at once pointing at the same line. qmllint --bare passes that, which is why the usual check before touching the running shell did not catch it. openSettingsSection exists as a separate function for that reason. Claude-Session: https://claude.ai/code/session_01BRvzt4H8XXLPVH5MyYdk9L |