Files
Panama/setup/scripts/change-settings
T
Gabriel Brown 86825e7327 Judge the document portal by its mount, not by its service
No flatpak would launch. Every one of them failed in bwrap with "Can't find
source path /run/user/1000/doc/by-app/<id>", because xdg-document-portal's fuse
mount was gone -- /run/user/1000/doc was a plain empty directory. That mount is
bound into every sandbox bwrap builds, so losing it takes out all 34 flatpaks at
once, never a subset.

It had been gone for three days. The shipped unit is Type=dbus with Restart=no,
so nothing retries it on failure: after it exited 21 it came back only because a
flatpak called its bus name two seconds later, and that activation landed on the
dying instance's mountpoint and came up with no mount at all. systemctl reports
active (running) either way -- the fusermount3 helper is still sitting there as a
child, in this case for two and a half days without ever completing the mount.

Nothing running notices, which is what makes it so quiet. A sandbox needs the
mount only while it is being constructed, so everything already open keeps
working and the symptom arrives whenever you next open a flatpak you had not
opened yet. Here that was three days later, and it presented as "gearlever is
missing" -- an application that was installed, healthy, and entirely innocent.

Two changes, because there are two failures: it does not recover, and nothing
says so.

The drop-in clears the mountpoint before each start, so an activation that
follows a crash lands on clean ground. ExecStartPre rather than ExecStopPost
precisely because nothing restarts this unit -- the next start is whenever
something next wants it, and that is the moment that has to be safe. `-` because
a clean start has nothing to unmount and fusermount3 exits 1 saying so.
/etc/systemd/user rather than a per-user drop-in so it covers every account, and
change-settings reloads the user manager so it applies without a re-login.

The check asks the mount table whether $XDG_RUNTIME_DIR/doc is mounted
fuse.portal. Deliberately not a service probe, and deliberately not folded into
desktop.portals: that one asks about xdg-desktop-portal, a different service
which was up and healthy throughout. Service state is exactly the question that
lied here, so asking it again in a new place would have been no check at all.
Warning carries a restart repair, verified end to end rather than assumed.

The mount table is injectable, like every other path this script reads, so the
contract covers unmounted, wrong-filesystem-at-the-right-path, and unreadable
against written fixtures rather than against whatever /proc happens to say --
coupling the test to this machine's live flatpak state is the same mistake in
miniature. Stubbing the check to always return ok fails the contract, which was
confirmed rather than hoped.

What is not fixed is the crash itself: one occurrence, and restarting the
service to get the desktop working destroyed the evidence. The exit was 21, it
landed 21 seconds after xdg-desktop-portal restarted, and that is one sample and
not a theory. What this buys is that the next one is a two-second blip the
doctor names, rather than three silent days.

Second time for this bug. ac231ee found the same dead mount in August while
chasing "can't open Bitwarden", fixed it by hand, and recorded it as "not a
config issue, so nothing to commit there". That judgement is why it was paid for
twice, and it is the part most worth writing down.
2026-08-21 15:26:20 -04:00

79 lines
3.7 KiB
Bash
Executable File

#!/usr/bin/env bash
# --- Helper functions ---
log() { echo -e "\033[1;34m[INFO]\033[0m $*"; }
exists() { command -v "$1" >/dev/null 2>&1; }
# --- Defined Paths ---
PANAMA_PATH="$HOME/.local/share/Panama"
echo -e "\n--- Copying System & User files ---"
log "Changing DNF Settings"
sudo cp -r "$PANAMA_PATH/config/copy/." "/"
# The GPU symlink rules land via the copy above. Apply them without a reboot so
# AQ_DRM_DEVICES resolves on the first Hyprland login rather than the second.
if [[ -f /etc/udev/rules.d/99-panama-gpu.rules ]]; then
log "Reloading udev rules for stable GPU symlinks"
sudo udevadm control --reload
sudo udevadm trigger --subsystem-match=drm
fi
# The document-portal drop-in lands via the same copy. A user unit's drop-ins
# are read at daemon-reload, so without this the guard applies from the next
# login rather than from now -- and the failure it guards against is one you
# only find days later, when you next open a flatpak you had not opened yet.
if [[ -f /etc/systemd/user/xdg-document-portal.service.d/panama-stale-mount.conf ]]; then
log "Reloading the user manager so the document-portal drop-in applies"
systemctl --user daemon-reload || log "Could not reload the user manager"
fi
echo -e "\n--- Desktop appearance ---"
# GTK and Qt apps read these directly from gsettings; there is no settings
# daemon outside GNOME, so they must be correct rather than merely overridden.
# These match config/dot/gtk-3.0/settings.ini and quickshell's Theme.qml.
if exists gsettings; then
log "Applying interface settings"
gsettings set org.gnome.desktop.interface gtk-theme 'adw-gtk3-dark'
gsettings set org.gnome.desktop.interface icon-theme 'Adwaita'
gsettings set org.gnome.desktop.interface color-scheme 'prefer-dark'
gsettings set org.gnome.desktop.interface font-name 'Adwaita Sans 11'
gsettings set org.gnome.desktop.interface monospace-font-name 'VictorMono Nerd Font 10'
gsettings set org.gnome.desktop.interface cursor-theme 'oreo_blue_cursors'
# Deliberately NOT setting cursor-size. GNOME here is on 16 (smaller than
# GNOME's own default of 24) and changing it would visibly alter the working
# GNOME session. Hyprland uses XCURSOR_SIZE=24 from uwsm/env; if the cursor
# feels too large there, change that one value rather than this one.
fi
echo -e "\n--- Hyprland session services ---"
# Deliberately NOT enabling these.
#
# hyprpaper / hypridle / hyprpolkitagent / vicinae all ship units that are
# WantedBy=graphical-session.target -- and that target is active under GNOME
# too. Enabling them would start hypridle alongside GNOME's own idle handling
# (two daemons blanking and locking the screen on different timers) and start
# hyprpaper where there is no layer shell for it to draw on.
#
# Instead hypr/autostart.lua runs `systemctl --user start ...` on
# hyprland.start, which scopes them to the Hyprland session. They still get the
# correct uwsm activation environment and still stop in order, because they are
# PartOf=graphical-session.target.
log "Hyprland services are started per-session by hypr/autostart.lua, not enabled globally"
# Notification daemons must NOT be installed: mako, dunst and swaync all
# register Name=org.freedesktop.Notifications for D-Bus activation, which races
# Quickshell's own notification server at login. Whoever wins keeps the name.
for pkg in mako dunst SwayNotificationCenter; do
if rpm -q "$pkg" >/dev/null 2>&1; then
log "WARNING: $pkg is installed and will fight Quickshell for the notification D-Bus name."
log " Fix with: systemctl --user mask ${pkg,,}.service"
fi
done
# Select the launcher theme once vicinae exists.
if exists vicinae; then
log "Setting vicinae theme"
vicinae theme set tokyonight-moon >/dev/null 2>&1 || true
fi