Phase 6, the last of the fresh-install spec. 159 scripts lose their .sh: 110 contracts, 47 Vicinae commands, 2 compositor contracts. A shebang and the executable bit already select the interpreter. The extension only ever added something that had to stay in sync, and the rename proved the point twice over in the space of an hour. The spec's stated risk was Vicinae's script discovery. One script was renamed and reloaded on its own before the other 46 followed; it came back as scripts:panama.capture and all 47 resolve. What the probe turned up instead is that the extension was never only a filename: Vicinae's command IDs embed it, so every ID changed. Nothing in this repository refers to them, so nothing breaks. The only trace is Vicinae's metadata.json, whose visited map had two Panama entries that are now orphaned -- two commands lost their usage ranking and will earn it back. Worth knowing before anyone renames these again on a machine that has a keybind pointing at one. Rewriting the references by exact filename missed two things it structurally could not see: a name built from a variable, settings-$page.sh, and a glob, -name '*.sh'. Both were in the contract that counts the generated commands, which promptly reported 47 expected and 0 found. The mechanical part of a rename is the part that looks finished. The three subcommands. panama doctor fronts a health check that already existed and already ran at the end of every install but could not be reached from a terminal. panama upgrade re-runs the installer from anywhere. panama test runs the suite, which had no entry point at all -- 121 files that were the main safety net in this repository and were invisible in it. Writing that runner found three tests nothing was running. calendar_agenda_bridge_test, home_assistant_bridge_test and kdeconnect_bridge_test are unittest suites without the executable bit, so no contract invoked them and the first draft of the runner skipped them silently. All three pass, and have passed unobserved for weeks. The runner collects *_test.py as well now, because a runner with a blind spot is worse than no runner for the same reason a dependency checker with one is: it reports PASS. Six worktrees pruned. Each was re-checked rather than trusted to the spec's list, and two needed it: panama-commands is not on feat/panama-commands but on feat/gnome-tweaks-parity, and fix/panama-displays-review reads [ahead 3] -- ahead of its remote, not of main, with every commit patch-equivalent to landed work. roadmap-completion stays; it has five commits that are genuinely unlanded. The branches are left alone: pruning a worktree costs nothing, deleting a branch is a decision. 121 contracts pass. Claude-Session: https://claude.ai/code/session_01NvgBuSWB5sE43yWmg21ozj
109 lines
3.9 KiB
Bash
Executable File
109 lines
3.9 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
|
|
# panama-keyring reports the login keyring's state, and the Settings page reads
|
|
# nothing but its JSON.
|
|
#
|
|
# The state that matters is LOCKED, and it is also the one that cannot be
|
|
# rehearsed on a real desktop: locking the login keyring breaks every saved
|
|
# password on the machine and can only be undone by typing the password into a
|
|
# dialog. So the secret service is stubbed here instead. Nothing touches the
|
|
# real keyring -- this contract is safe to run on the daily driver, which is the
|
|
# entire reason it is written this way.
|
|
|
|
set -uo pipefail
|
|
|
|
repo_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
|
|
helper="$repo_dir/config/dot/quickshell/scripts/panama-keyring"
|
|
|
|
fail() {
|
|
printf 'keyring helper contract: %s\n' "$1" >&2
|
|
exit 1
|
|
}
|
|
|
|
stub_dir="$(mktemp -d /tmp/panama-keyring.XXXXXX)"
|
|
trap 'rm -rf "$stub_dir"' EXIT
|
|
|
|
# A stand-in for the `gi` module the helper imports. PANAMA_KEYRING_FAKE decides
|
|
# what the fake service reports, so one stub covers every case.
|
|
mkdir -p "$stub_dir/gi/repository"
|
|
cat >"$stub_dir/gi/__init__.py" <<'STUB'
|
|
def require_version(*_args, **_kwargs):
|
|
return None
|
|
STUB
|
|
cat >"$stub_dir/gi/repository/__init__.py" <<'STUB'
|
|
import os
|
|
|
|
|
|
class _Collection:
|
|
def __init__(self, label, locked):
|
|
self._label = label
|
|
self._locked = locked
|
|
|
|
def get_label(self):
|
|
return self._label
|
|
|
|
def get_locked(self):
|
|
return self._locked
|
|
|
|
|
|
class _Service:
|
|
def get_collections(self):
|
|
mode = os.environ.get("PANAMA_KEYRING_FAKE", "unlocked")
|
|
if mode == "nologin":
|
|
return [_Collection("Some App", False)]
|
|
return [_Collection("Login", mode == "locked"), _Collection("", False)]
|
|
|
|
|
|
class _ServiceFactory:
|
|
@staticmethod
|
|
def get_sync(_flags, _cancellable):
|
|
if os.environ.get("PANAMA_KEYRING_FAKE") == "unavailable":
|
|
raise RuntimeError("no secret service")
|
|
return _Service()
|
|
|
|
# unlock_sync is what the `unlock` action calls; record that it was reached.
|
|
@staticmethod
|
|
def _noop(*_args, **_kwargs):
|
|
return None
|
|
|
|
|
|
class Secret:
|
|
class ServiceFlags:
|
|
LOAD_COLLECTIONS = 1
|
|
|
|
Service = _ServiceFactory
|
|
STUB
|
|
|
|
run() {
|
|
PYTHONPATH="$stub_dir" PANAMA_KEYRING_FAKE="$1" python3 "$helper" "${2:-status}"
|
|
}
|
|
|
|
# ── Unlocked: the normal state after any sign-in ─────────────────────────────
|
|
out="$(run unlocked)"
|
|
jq -e . >/dev/null 2>&1 <<<"$out" || fail "status did not emit JSON: $out"
|
|
jq -e '.available == true and .locked == false and .hasLogin == true' >/dev/null <<<"$out" \
|
|
|| fail "an unlocked login keyring was misreported: $out"
|
|
|
|
# ── Locked: the state the whole card exists for ──────────────────────────────
|
|
out="$(run locked)"
|
|
jq -e '.available == true and .locked == true' >/dev/null <<<"$out" \
|
|
|| fail "a locked login keyring was not reported as locked: $out"
|
|
|
|
# ── No secret service at all is a state, not a crash ─────────────────────────
|
|
out="$(run unavailable)"
|
|
jq -e . >/dev/null 2>&1 <<<"$out" \
|
|
|| fail "a missing secret service produced no JSON, so the page would show nothing: $out"
|
|
jq -e '.available == false and .error != ""' >/dev/null <<<"$out" \
|
|
|| fail "a missing secret service must be reported with a reason: $out"
|
|
|
|
# ── No login keyring: not locked, because there is nothing to lock ───────────
|
|
out="$(run nologin)"
|
|
jq -e '.available == true and .hasLogin == false and .locked == false' >/dev/null <<<"$out" \
|
|
|| fail "a machine with no login keyring must not report itself locked: $out"
|
|
|
|
# ── The daemon origin is reported, since it is the crash diagnostic ──────────
|
|
jq -e '.daemon | test("^(pam|dbus|none|unknown)$")' >/dev/null <<<"$(run unlocked)" \
|
|
|| fail "the daemon origin must be one of pam/dbus/none/unknown"
|
|
|
|
printf 'keyring helper contract: PASS\n'
|