# Backlog — the prioritized task queue The forward-looking half of the old docs/ROADMAP.md, reworked as a queue agents can execute. Detailed design notes and decision records stay in `docs/ROADMAP.md` (referenced as "ROADMAP § "); this file is *what's next, in what order*. **Rules:** - Agents take the topmost actionable item (see LOOP.md). Finished items are **deleted** here — the journal + git log are the record; durable design notes get a ✓-entry in docs/ROADMAP.md if worth keeping. - Item numbers are **stable IDs** — never renumbered or reused. A gap in the sequence means shipped (or dropped) work; new items take the next free number regardless of tier. - Tags: `[blocked:hw]` needs real hardware (see HARDWARE-QUEUE.md) · `[human]` needs Bernardo · `[stuck]` two failed attempts, needs help · `[big]` must be split before starting. - Agents may append to **PROPOSED** and **Decisions** freely; only Bernardo moves items *out* of PROPOSED into the tiers. --- ## NOW ### 20. Confirm the Forgejo runner is alive `[human]` The checks-on-push workflow (`.forgejo/workflows/check.yml`) shipped; the repo has `has_actions: true` and the legacy `check.yml` ran 57 times on an act_runner, but whether that runner still exists is not API-visible without auth. Check the first run of the new workflow at https://git.bemagri.xyz/bernardo/Nomarchy/actions — if it sits queued, re-register an act_runner (docker, `ubuntu-latest` label). **Stretch:** a second runner on a NixOS host with `/dev/kvm` (label `nix-kvm`) — then uncomment the workflow's `vm-checks` job and the VM suite + real builds run in CI too (that upgrades half of item 14 for free). ### 3. Memory-pressure protection (no more frozen desktops) New. A workstation that compiles from source *will* hit memory exhaustion (the discarded release bump died to a Hyprland OOM; a big `nix build` can freeze the session today — nothing mitigates OOM). Ship a default-on userspace OOM killer: pick `systemd-oomd` (`systemd.oomd` + the NixOS enables for user slices) or `earlyoom` — write the choice + rationale into the commit; consider protecting the session (Hyprland/greetd) and sacrificing `nix-daemon` build slices first. **Why:** "rock-stable" means the UI never locks up. **Done when:** on by default (`lib.mkDefault`), overridable natively; the choice documented in README's "beyond the surface" note. **Verify:** V2 — a VM check that memory pressure kills the hog, not the session. ### 4. btrfs-assistant segfault — attempt the nixpkgs override fix ROADMAP § Snapshot browse/restore. btrfs-assistant 2.2 crashes in `libbtrfsutil.so.1.4.0` (ABI mismatch, confirmed not a VM artifact); the `nomarchy-snapshots` fzf fallback ships. Try an override aligning its libbtrfsutil (or a version bump/pin); if upstream nixpkgs has since fixed it, just verify and re-point the menu. **Done when:** the GUI launches in the VM test, or the attempt is written up as infeasible (then re-check on each lock bump). **Verify:** V2 — extend the snapper VM check to launch the binary. ### 5. Keyboard layouts — cycle bind + summer-bar parity ROADMAP § Keyboard layouts, remaining bullets: (a) a multi-layout cycle bind (`hyprctl switchxkblayout` current-device, or xkb `grp:` option) when >1 session layout, in the cheatsheet; (b) add `hyprland/language` to the summer-day/night `waybar.jsonc` whole-swaps (parity rule — the generated bar has it, the static ones don't; gating doesn't translate, decide the static behavior and note it). **Verify:** V1 + `jq` the rendered configs; V3 queue the on-hardware cycle check. ### 6. Full docs review & restructure ROADMAP § Full docs review. The roadmap/backlog split is done (this file); remaining: reconcile every README option table against the live `nomarchy.*` surface; drift pass over docs/OVERRIDES.md, docs/TESTING.md, templates/downstream/README.md; read the install/first-run story end to end; add a short **recovery runbook** (desktop won't start → boot an older generation / `nomarchy-snapshots` / greetd journal — the pieces exist, the story isn't written). Site-vs-markdown is a Decision (below). **Verify:** V0 + a mechanical option-surface diff (eval the options, compare to the tables — consider making that a permanent check). ### 7. Webcam follow-ups (small) ROADMAP § Webcam: ship `v4l-utils` + `cameractrls` (commented app-suite entries or alongside the camera toggle — respect the option-surface rule) for genuine-tuning cases; write up the portal/Flatpak libcamera-path gap (internal IR still listed there) as a PROPOSED item with options. **Verify:** V1. ## NEXT ### 8. Complete-workstation viewers + default applications New. The template ships mpv but **no PDF viewer and no image viewer**, and nothing sets xdg-mime defaults — so "open a PDF/photo" falls to whatever GTK guesses (GIMP for images). Two halves: (a) add a themed, lightweight PDF viewer + image viewer to the template's active `home.packages` (candidates: zathura or GNOME Papers; imv or loupe — prefer what Stylix themes well); (b) a mime-defaults module setting `xdg.mimeApps` associations (browser/PDF/image/video/text, `mkDefault`) — real config, so unlike bare packages this *is* module territory, but it must degrade gracefully when the user deletes a package from the suite. **Verify:** V1 + assert the rendered mimeapps.list; V3 queue an open-a-file smoke. ### 9. Update & rollback UX New; extends the update-awareness story to the other half: what changed, and how do I get back. (a) `sys-update` prints a human diff of what the update changed (`nvd diff` between system generations, or `nix store diff-closures`); (b) a **System → Rollback** menu flow: desktop = pick a recent `home-manager generations` entry and activate it (the theme history is already generations); system = point at the boot-menu generation flow + `nomarchy-snapshots` rather than reimplementing it — destructive steps keep the typed-`yes` gate. **Why:** informative + rock-stable means undo is one menu away, not a Nix lesson. **Verify:** V1; V2 for the generation-activate path in a VM. ### 10. `nomarchy-doctor` — one-shot health check New. A single command (+ System-menu entry) that checks the things that actually break user machines and prints a themed pass/fail sheet: failed systemd units (system + user), disk space (/, /boot, the nix store), state-file parses + is git-tracked, downstream flake dirty/ diverged, last rebuild generation age, snapper timeline running (when enabled). Read-only, no auto-fixing; each failure prints the one command that fixes it. Optionally later: a self-gating Waybar warning fed by the same script. **Verify:** V2 — a VM check with an induced failure. ### 11. State-file validation & friendly errors New; "the user never has to master Nix" must include *error messages*. A hand-edited theme-state.json (trailing comma, wrong type, unknown theme slug) today surfaces as a raw Nix eval stack. Add (a) `nomarchy- theme-sync validate` + validate-before-write on every set/apply; (b) an eval-time schema assertion in `theme.nix` whose message says the field, the problem, and the fix in plain language. **Verify:** V1 + a corpus of broken-state fixtures round-tripped through validate; V2 if cheap. ### 12. Screen recording in the Capture submenu New; screenshots ship, recording doesn't — a standard workstation need. Extend `nomarchy-menu capture`: record region/full → `wl-screenrec` (fallback `wf-recorder`), saved next to Screenshots, with a self-gating Waybar recording indicator that stops the recording on click (the only sane "stop" surface). Optional audio toggle. Parity rule applies. **Verify:** V1 + `bash -n`; V2 headless if the software-GL recipe supports it, else V3 queue. ### 13. Small niceties batch (one slice per iteration) Each is a small, self-contained polish item in the existing patterns: - **Idle-inhibit (caffeine) toggle:** Waybar `idle_inhibitor` module (blocks hypridle lock/suspend during video/presentations) + summer whole-swap parity + cheatsheet mention. - **Low-battery notifications:** the bar colors at 25/10% but nothing *notifies*; gate on `power.laptop` (poweralertd, or a small upower watcher consistent with how the bar reads state). - **Color picker:** `hyprpicker` → clipboard as a Tools › entry + `SUPER+CTRL` bind; pairs naturally with theme work. ### 14. Automated upstream lock bumps (maintainer CI, slices b+c) `[big]` ROADMAP § Automated upstream lock bumps — the scheduled half (the checks-on-push workflow shipped; see item 20 for the runner status): weekly job runs `nix flake update` (within pinned release branches) → full check suite → lands on `main` on green; `v1` promotion stays human. Plus the fast-lane note for security bumps. Note the current runner is eval-only (no KVM) — a green bump run guards eval, not the VM suite, until item 20's stretch runner exists. ### 15. Display profiles — docked/undocked switching ROADMAP § Display / monitor management, remaining: true profile switching of the *same* outputs (multi-layout toggles, beyond per-output hotplug rules), optionally workspace-to-monitor binding. Design first (state-file shape, menu surface) — write the plan into this entry before coding. ### 16. Greeter theming from the JSON ROADMAP § Greeter. tuigreet themed from theme-state.json at system rebuild (same model as Plymouth's tint). Scope: tuigreet only (no SDDM). ### 17. Launch-or-focus UX scripts ROADMAP § launch-or-focus. Hyprland dispatch scripts: a bind launches an app or focuses its existing window. Curate which apps get binds; cheatsheet entries via keybinds.nix. ### 18. "nomarchy" control center + first-boot welcome `[big]` ROADMAP § control center. A single front-end over the common toggles on the same `nomarchy-theme-sync` surface, + a first-boot guided "pick your theme / essentials" flow. Needs a design pass (TUI vs GUI) → write options into Decisions before implementing. Note: items 9–11 (rollback menu, doctor, validation) are natural panels of it — design them as composable commands, not dead ends. ### 19. Look & Feel menu category ROADMAP § Menu system, remaining: group Theme + night-light (+ wallpaper cycle, future appearance toggles) under a Look & Feel submenu once it earns ≥3 entries — keep the root at six. ## LATER - **Wallpapers artifact split** (ROADMAP § Faster switches — decided, deferred): pinned `Nomarchy-wallpapers` input so a state write stops re-copying 86 MB. Follow-on: pre-built theme variants if switches are still slow after. - **Installer round 2** (ROADMAP § Installer): multi-disk BTRFS RAID, impermanence, BIOS/legacy boot. - **Boot-from-snapshot**: a systemd-boot equivalent of grub-btrfs. - **Night-light geo mode**: lat/long auto sunset/sunrise (means wlsunset). - **Per-theme icon overrides** / more icon packs (ROADMAP § Icon themes). - **MIPI/IPU software-ISP camera** support (no-UVC machines). - **OCR screenshot-to-text**: a Capture › entry (grim region → tesseract → clipboard) — cheap once recording (#12) reshapes the submenu. - **Auto-timezone Waybar tooltip** showing the detected zone (optional). - **VPN exit-node richer display** (country/city) (optional). - **NixOS release bump → v2** `[human]`: deliberate, hand-edited, never automated; the previous attempt was discarded (2026-06-22) over a Hyprland OOM blocker — see MEMORY.md before retrying (NOW#3 should also soften that blocker class). ## PROPOSED (agent suggestions — await human triage) *Agents: append here with a one-paragraph pitch (what/why/cost). Do not implement. Bernardo moves accepted items into a tier.* - *(empty)* ## Decisions `[human]` Open calls only Bernardo can make; agents add options/evidence but never decide. - **Formatter adoption:** repo deliberately has none; `nixfmt-rfc-style` would flatten the aligned hand-formatting of ~33 files. Adopt or declare never? - **Docs site vs Markdown-in-repo** (from the docs-review item). - **Control center form factor:** TUI (gum/ratatui-style) vs GUI vs "the rofi menu *is* the control center, just add a first-boot flow". - **zram swap:** faster under pressure and pairs with NOW#3, but it interacts with the hibernation-swapfile story (resume device/priority ordering) — adopt, adopt-with-hibernation-guard, or skip? - **Default browser:** the template comments Firefox out; item #8's mime defaults need *something* to point `text/html` at — ship a browser active in the suite, or leave browserless-by-default and let mime defaults degrade?