Gabriel Brown fd99569666 Add a Firewall page, led by what is actually reachable
Listing zones and services is what firewall-cmd already does. The
question it does not answer needs both halves at once: a port is
reachable only when something is LISTENING on a network address AND the
firewall permits it.

On this machine that crossing is the whole story. The rules look
unremarkable -- one zone, three services, a port range -- and what they
mean is that PostgreSQL and Redis, published by rootless containers on
every interface, are reachable by anyone on the network. Neither half
says that alone, which is exactly how a tidy rules list coexists with an
open database. Nothing was misconfigured: Fedora's default zone met
podman's default publish behaviour.

Ephemeral client sockets are excluded. A browser's outbound UDP port is
indistinguishable from a service in ss, and listing twenty of them
buried the two rows that mattered.

Closing the port range names what it would cut off, by service, before
doing it, and removing ssh says so when someone is connected over it.
Rich rules are shown and never edited: a syntax is not a setting, but
hiding it would misrepresent the configuration.

The contract needed a recorded firewall, and the reason is worth
keeping. The rule this page exists for cannot be tested against this
machine -- its zone permits everything above 1024, so "listening" and
"listening and permitted" give identical answers, and a blocked listener
needs a port below 1024, which needs root. With the crossing deleted,
the contract passed. It now runs against a fixture where two listeners
are blocked, and catches it.

Also here: polkit response files are written 0600 rather than at the
default mask, the agent sweeps requests left by an instance that did not
exit cleanly, and the write sweep waits for its harness to be ready
instead of reporting the startup race as settings that failed.

Claude-Session: https://claude.ai/code/session_01BRvzt4H8XXLPVH5MyYdk9L
2026-08-19 19:46:16 -04:00

Panama

Formerly Sunhat. A personal config for Fedora, with the intention of helping a user set up their Fedora system with one command.

git clone https://git.gbrown.org/gib/Panama.git ~/.local/share/Panama
~/.local/share/Panama/install

install runs everything in setup/scripts/ in order:

Script Does
install-packages Repos (RPM Fusion, Terra, Hyprland COPR), then the four package lists in setup/packages/
link-dotfiles Symlinks config/dot/<name>~/.config/<name>
change-settings Copies config/copy/ over /, applies gsettings, enables user services

Existing configs are moved to config/old/ rather than overwritten.

Desktops

Panama configures two desktops that coexist. Both sessions stay available in GDM, so you can switch back and forth while you settle in.

GNOME

The original setup: Forge for tiling, Dash-to-Dock, Openbar, Vitals, AppIndicator support. Configured through config/dot/forge/ and gsettings.

Hyprland

A from-scratch replacement built to reproduce the GNOME setup closely enough that muscle memory transfers — same keybinds, same panel contents, same dock, same Tokyo Night Moon palette.

Piece What it is
config/dot/hypr/ Compositor config. Lua, not hyprlang — see its README
config/dot/quickshell/ The shell: bar, dock, Continuum overview, Settings, Screen Intelligence, focus sessions, quick settings, notifications, screenshot UI
config/dot/vicinae/ Raycast-style launcher, themed
config/dot/uwsm/ Session environment (see the uwsm caveat in the hypr README)
config/dot/wofi/ Fallback launcher, in case the shell fails to start
config/dot/xdg-desktop-portal/ Portal backend routing

Start here: config/dot/hypr/README.md — it covers the Lua migration, the uwsm environment gotcha, the HDR decision, the full keymap, and troubleshooting.

Log in as "Hyprland (uwsm-managed)", not plain "Hyprland".

Layout

bin/            Small user-facing commands on PATH
config/
  bash/         .bashrc, aliases, env (env is gitignored)
  copy/         Files copied verbatim over / (needs sudo)
  dot/          Symlinked into ~/.config
  old/          Backups of whatever was replaced (gitignored)
setup/
  packages/     One package per line
  scripts/      Run in order by ./install
S
Description
No description provided
Readme
6.1 MiB
Languages
QML 44.2%
Shell 38%
Python 11.2%
CSS 3.5%
Lua 2.1%
Other 0.9%