Gabriel Brown e4409ed6aa Surface the login keyring, and offer to unlock it
The keyring is already unlocked at sign-in exactly as GNOME does it --
pam_gnome_keyring is in GDM's stack and the journal confirms it works
("gnome-keyring-daemon started properly and unlocked keyring"). So there
was no configuration bug to fix. What a bare Hyprland session lacks is
anywhere to see when that has stopped being true.

It stops being true rarely and expensively. gnome-keyring-daemon crashed
once on this machine -- an upstream abort in service_method_open_session,
with a core dump -- and D-Bus then activated a replacement. That
replacement never received the login password, so the keyring was locked
in the middle of a session that had unlocked it correctly at login.
Nothing announces this. What you see instead is a mail account that will
not authenticate, a git push that cannot find its key, or an integration
reporting "not configured", none of which mention keyrings. That is the
same root cause as the Home Assistant token failure earlier.

Privacy & Security now shows the state, offers an Unlock action that
raises the standard password dialog, and reports when the daemon holding
your secrets is a D-Bus replacement rather than PAM's -- because a
replacement that is currently unlocked was unlocked by hand and will not
survive a restart. The password never passes through Panama.

The contract stubs the secret service rather than touching the real one:
locking the login keyring breaks every saved password on the machine and
can only be undone by typing the password into a dialog, so it is not
something a test suite may do to a daily driver. Verified it catches a
helper that misreports locked as unlocked, and one that crashes instead
of reporting a missing service.

Worth recording: a locked keyring makes a NON-INTERACTIVE caller appear
to hang. It is not hung -- it is waiting on a dialog nobody is looking
at, which is exactly how the earlier secret-tool investigation lost an
hour.

Claude-Session: https://claude.ai/code/session_01BRvzt4H8XXLPVH5MyYdk9L
2026-08-18 10:34:41 -04:00
2026-08-18 07:31:11 -04:00
2026-08-18 07:31:11 -04:00

Panama

Formerly Sunhat. A personal config for Fedora, with the intention of helping a user set up their Fedora system with one command.

git clone https://git.gbrown.org/gib/Panama.git ~/.local/share/Panama
~/.local/share/Panama/install

install runs everything in setup/scripts/ in order:

Script Does
install-packages Repos (RPM Fusion, Terra, Hyprland COPR), then the four package lists in setup/packages/
link-dotfiles Symlinks config/dot/<name>~/.config/<name>
change-settings Copies config/copy/ over /, applies gsettings, enables user services

Existing configs are moved to config/old/ rather than overwritten.

Desktops

Panama configures two desktops that coexist. Both sessions stay available in GDM, so you can switch back and forth while you settle in.

GNOME

The original setup: Forge for tiling, Dash-to-Dock, Openbar, Vitals, AppIndicator support. Configured through config/dot/forge/ and gsettings.

Hyprland

A from-scratch replacement built to reproduce the GNOME setup closely enough that muscle memory transfers — same keybinds, same panel contents, same dock, same Tokyo Night Moon palette.

Piece What it is
config/dot/hypr/ Compositor config. Lua, not hyprlang — see its README
config/dot/quickshell/ The shell: bar, dock, Continuum overview, Settings, Screen Intelligence, focus sessions, quick settings, notifications, screenshot UI
config/dot/vicinae/ Raycast-style launcher, themed
config/dot/uwsm/ Session environment (see the uwsm caveat in the hypr README)
config/dot/wofi/ Fallback launcher, in case the shell fails to start
config/dot/xdg-desktop-portal/ Portal backend routing

Start here: config/dot/hypr/README.md — it covers the Lua migration, the uwsm environment gotcha, the HDR decision, the full keymap, and troubleshooting.

Log in as "Hyprland (uwsm-managed)", not plain "Hyprland".

Layout

bin/            Small user-facing commands on PATH
config/
  bash/         .bashrc, aliases, env (env is gitignored)
  copy/         Files copied verbatim over / (needs sudo)
  dot/          Symlinked into ~/.config
  old/          Backups of whatever was replaced (gitignored)
setup/
  packages/     One package per line
  scripts/      Run in order by ./install
S
Description
No description provided
Readme
6.1 MiB
Languages
QML 44.2%
Shell 38%
Python 11.2%
CSS 3.5%
Lua 2.1%
Other 0.9%