All checks were successful
Check / eval (push) Successful in 3m22s
BACKLOG #103. Bernardo, live ISO 2026-07-14: still no browser, no office — "that makes a live iso useful". He is right, and it is the thing a user judges the distro by before installing, and what they boot to rescue a machine that won't start. It could do neither. The live HM user now names its own set: chromium, libreoffice-fresh, gnome-text-editor, amberol, snapshot. Firefox deliberately excluded (Bernardo's call): chromium already owns the HTTP mime default and ships in the installed template, so it is the browser that matches what a user gets post-install. I asked him to choose on a "~+2 GB" premise. The premise was wrong, and measuring rather than assuming is what corrected it: system.extraDependencies ALREADY pins the template's HM closure into the ISO for offline installs, so chromium/libreoffice/amberol were already in the image's store — merely absent from the live user's profile, so nothing put them on PATH or in the launcher. The live and template chromium resolve to the SAME store path, verified, so reusing the template's exact `chromium.override { enableWideVine = true; }` costs zero; a plain `chromium` would have been a second 2.5 GiB closure. Only gnome-text-editor and snapshot are new: 9 paths, 133 MiB uncompressed. His Firefox call still held for the right reason — it was the one item genuinely unpinned. V2. Measured ISO delta, both built from the same tree — the item's pass condition: 8.038 → 8.078 GiB = +41.2 MiB (+0.50%). New checks.live-baseline-apps asserts each app is on PATH *and* has a .desktop the launcher can see (a binary without one is invisible, which is the failure that matters), that HTTPS resolves to a chromium entry actually PRESENT (#94's exact trap — a mime default naming a package nothing ships), and that firefox has not crept back, since that is a size decision not a drive-by. The guard was proved to fail: dropping snapshot makes it name the missing entry. flake check, live-install-entry, option-docs, template-sot green. V3 pending: that the apps LAUNCH needs hardware — queued on the Acer M5-481T, from the launcher only, since that is the claim a file-level check cannot make. Also filed, from measuring the 8 GiB rather than speculating about it: * #120 (NEXT, Bernardo's call) — a netinstall ISO beside the offline one. Starts from numbers: the offline pin is only 4.02 of 18.03 GiB uncompressed (~22%), so dropping it still leaves a 14 GiB desktop (~6.3 GiB compressed). "No pin" is not the lighter ISO; and without a binary cache for Nomarchy's own outputs a netinstall trades a download for a from-source install. * #121 — the Widevine wrapper drags a SECOND 687 MiB unwrapped chromium in for its share/applications alone. Pre-existing, on every installed machine. * #119 — text/plain names vscode, which the live ISO never ships. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
509 lines
27 KiB
Markdown
509 lines
27 KiB
Markdown
# Backlog — the prioritized task queue
|
||
|
||
**This is the only executable work list for agents.** Product themes and
|
||
v1.0 intent live in [`docs/VISION.md`](../docs/VISION.md); design history
|
||
in [`docs/ROADMAP.md`](../docs/ROADMAP.md); map in
|
||
[`docs/README.md`](../docs/README.md) and [`agent/README.md`](README.md).
|
||
|
||
**Rules:**
|
||
- Agents take the topmost actionable item (see LOOP.md). Finished items
|
||
are **deleted** here — the journal + git log are the record; durable
|
||
design notes get a ✓-entry in docs/ROADMAP.md (and/or a note in VISION)
|
||
if worth keeping.
|
||
- Item numbers are **stable IDs** — never renumbered or reused. A gap in
|
||
the sequence means shipped (or dropped) work; new items take the next
|
||
free number regardless of tier.
|
||
- Tags: `[blocked:hw]` needs real hardware (see HARDWARE-QUEUE.md) ·
|
||
`[human]` needs Bernardo · `[stuck]` two failed attempts, needs help ·
|
||
`[big]` must be split before starting.
|
||
- Agents may append to **PROPOSED** and **Decisions** freely (include
|
||
`VISION § …` or `ROADMAP § …` when relevant); only Bernardo moves items
|
||
*out* of PROPOSED into the tiers.
|
||
|
||
---
|
||
|
||
## NOW
|
||
|
||
### Live ISO hardware findings — Acer Aspire M5-481T (Bernardo, 2026-07-13)
|
||
|
||
These are separate queue items from one real install/session pass. Preserve
|
||
that separation when fixing them: the installer blocker, unclear installer
|
||
copy, and post-install desktop failures have different verification paths.
|
||
|
||
### 118. smartd fails where no drive has SMART, so the health icon greets you red
|
||
|
||
Bernardo, live ISO 2026-07-14: the Waybar doctor module shows a smartd error.
|
||
|
||
**Root cause, reproduced headlessly 2026-07-14** (scratch `runNixOSTest`, a
|
||
node whose only config is `services.smartd.enable = true` — the same block
|
||
`modules/nixos/default.nix:166` mkDefaults ON for every machine):
|
||
|
||
smartd[567]: In the system's table of devices NO devices found to scan
|
||
smartd[567]: Unable to monitor any SMART enabled devices. Exiting.
|
||
smartd.service: Main process exited, code=exited, status=17/n/a
|
||
Status: "No devices to monitor"
|
||
|
||
`smartctl --scan` prints **nothing** on such a machine — which is both the
|
||
cause and the ready-made gate. The rest of the chain is each part working
|
||
correctly: `systemctl --failed` lists `smartd.service`, so nomarchy-doctor's
|
||
generic failed-unit check (`nomarchy-doctor.sh:24-28`) reports "failed system
|
||
unit(s): smartd.service", and Waybar's `#custom-doctor` goes `@bad`. **Fix
|
||
smartd, not the doctor** — the doctor is telling the truth about a unit that
|
||
genuinely failed.
|
||
|
||
**Scope is wider than the live ISO** (which is why it's here and not filed as
|
||
a live-only nit): `services.smartd.enable` mkDefaults true on `nomarchy` as
|
||
well as `nomarchy-live`, and QEMU virtio disks expose no SMART — so a plain
|
||
VM install boots to a red health icon out of the box, as does a live USB whose
|
||
stick has no SMART. Every V2 QEMU run has been showing this.
|
||
|
||
Fix direction: **self-gate on the hardware**, the convention the rest of the
|
||
distro follows (`ExecCondition`, like the night-light; "each half self-gates
|
||
on its hardware"). A condition that runs `smartctl --scan` and skips the unit
|
||
when it finds nothing leaves the unit *inactive* rather than *failed*, so real
|
||
SMART failures on real drives still surface. Do **not** paper over it with
|
||
`SuccessExitStatus = 17` — that also swallows the case where smartd dies on a
|
||
machine that does have drives, which is the whole reason the daemon is here.
|
||
|
||
Pass = on a machine with no SMART-capable device the unit is inactive (not
|
||
failed), `systemctl --failed` is empty and the doctor is green; on a machine
|
||
with one, smartd runs as it does today; a permanent `checks.*` covers both
|
||
halves (the scratch repro above is most of it — the no-SMART node exists, the
|
||
with-SMART node needs a QEMU disk that answers SMART, or the gate script
|
||
tested directly against a stubbed `smartctl`).
|
||
|
||
### 94. Live ISO/install: no default browser observed
|
||
|
||
**Progress 2026-07-13:** installed path VERIFIED at V1 — the exact HM
|
||
generation the ISO pins for offline installs contains the chromium binary,
|
||
`chromium-browser.desktop`, and all three HTTP/HTML handlers
|
||
(mime.nix sets them; template ships the package). The Acer sighting is the
|
||
LIVE session, which shipped NO browser by design (mime defaults name chromium,
|
||
GIO skips it while absent).
|
||
|
||
**Update 2026-07-14:** the live half is **gone** — #103 shipped, so the live
|
||
session now carries chromium (plus office/editor/music/camera) on PATH and in
|
||
the launcher, and `checks.live-baseline-apps` asserts HTTPS still resolves to
|
||
`chromium-browser.desktop` *and* that the entry it names is actually present —
|
||
the exact "mime names a package nothing ships" trap this item found. What
|
||
remains here is only the **installed** path: a test-install VM run proving
|
||
chromium launches post-install (chain #97's Bluetooth-click V2 into the same
|
||
run).
|
||
|
||
Chromium is the resolved default-browser decision and is present in the
|
||
downstream template, but this hardware pass found no usable default browser.
|
||
Trace the live-to-installed Home Manager path rather than merely checking the
|
||
template source. Pass = Chromium launches after installation and HTTP/HTTPS
|
||
mime defaults resolve to `chromium-browser.desktop` (and the intended live-ISO
|
||
browser posture is explicit).
|
||
|
||
### 119. `text/plain` names vscode, which the live ISO does not ship
|
||
|
||
Found while shipping #103 (2026-07-14), deliberately not fixed there — same
|
||
bug class as #94, one mime key over. `modules/home/mime.nix:48` assigns
|
||
`text/plain = code.desktop`, and vscode ships only in the **template**, never
|
||
on the live ISO. GIO silently skips an entry whose desktop file is absent, so
|
||
opening a text file in the live session finds no handler at all — the exact
|
||
shape of the no-default-browser bug, and now the only one left of its kind
|
||
since #103 put chromium on the live medium.
|
||
|
||
Two ways it bites, and a fix should settle both: (1) the live session, which
|
||
now ships `gnome-text-editor` (`org.gnome.TextEditor.desktop`) — the obvious
|
||
live handler; (2) any installed machine where the user takes the template at
|
||
its word and deletes the `vscode` line (opt-out = delete the line, per the
|
||
option-surface convention), which silently breaks `text/plain` with no warning.
|
||
|
||
The general trap is worth fixing once rather than per-key: a mime default
|
||
naming a package the profile does not carry is invisible until a user
|
||
double-clicks a file. `checks.live-baseline-apps` now guards exactly this for
|
||
HTTPS (asserts the named .desktop is present, not merely named) — the cheap
|
||
version of this item is extending that assertion to every key in
|
||
`defaultApplications`, which would have caught both #94 and this. Pass = no
|
||
mime default names a desktop entry the profile lacks, on the live ISO and on
|
||
a template install, and a guard fails on a regression.
|
||
|
||
### 95. Live ISO/install: Ghostty does not open
|
||
|
||
Reproduce from the launcher and a terminal, capture its stderr/journal, and
|
||
fix the packaging/session/runtime cause. Pass = the default terminal opens in
|
||
the installed graphical session and the SUPER+Return path works.
|
||
|
||
### 98. Boreal: button text renders black and is difficult to read
|
||
|
||
Audit GTK button foreground/background contrast under Boreal, including the
|
||
installer surface where it was observed. Follow THEME-DESIGN's two-theme
|
||
visual protocol. Pass = normal, hover, focused, and disabled button labels
|
||
remain legible and palette-consistent.
|
||
|
||
**Progress 2026-07-13:** scripted checks pass all 24 themes — not
|
||
palette-level. Stylix gtk.css for Boreal audited: fg roles are light
|
||
(#d3dae0); the near-black values are `accent/warning/error_fg_color`
|
||
(#21272f) on their pastel bgs (deliberate, ~4.4:1). Candidate surfaces:
|
||
adw-gtk3 (light base) + dark recolor edge cases, or gum's TUI confirm
|
||
buttons in the installer (VM gum screens under Boreal look legible —
|
||
artifacts in `/tmp/nomarchy-v2-swap-93/`). Needs Bernardo's screenshot or
|
||
an Acer repro to pin the actual widget before fixing.
|
||
|
||
### 113. Live session: offline theme switch rebuilds the world from source
|
||
|
||
Surfaced by #99's evidence run (2026-07-13, `/tmp/nomarchy-v2-theme-99/`):
|
||
in the **live ISO** session, offline `nomarchy-theme-sync apply gruvbox`
|
||
fails — its `home-manager switch` tries to build **1176 derivations** from
|
||
the `stage0`/`hex0` bootstrap up, then dies on offline source fetches
|
||
(`vala`, `yasm`, `config.jsonc`, `ghostty-config`, `easyeffects.svg`,
|
||
`typogrify`…), ending `error: Build failed due to failed dependency`. This
|
||
contradicts docs/TESTING.md item 6 ("apply gruvbox → switch runs offline").
|
||
The failing generation is `bvl30ggn…-home-manager-generation.drv`; it is
|
||
**not** the drv the ISO pins (the pin is the *default*-theme
|
||
`homeConfigurations.${username}.activationPackage`, i.e. Boreal — confirmed
|
||
drv-identical to the failing one only for gruvbox state, so a non-default
|
||
theme's generation is unpinned). NOT caused by #99's git-seed: the drv is
|
||
byte-identical path-seeded vs git-seeded. **Decide the contract:** either
|
||
pin every baked theme's live activationPackage into the ISO (size cost) or
|
||
scope the offline-switch promise to the shipped theme + correct
|
||
TESTING.md/MEMORY. Pass = a fresh live ISO either switches to any baked
|
||
theme offline, or fails with a clear "needs network for this theme" message
|
||
and accurate docs. **Not caused by anything in today's batch** — separate
|
||
pre-existing ISO-pinning gap.
|
||
|
||
## NEXT
|
||
|
||
### 120. A netinstall ISO, next to the fat offline one
|
||
|
||
Bernardo 2026-07-14, after seeing the measured size: **keep the current ISO
|
||
exactly as it is** — the guaranteed offline install is the feature it buys —
|
||
and ship a **much lighter netinstall variant alongside it**. Two products, one
|
||
distro: "works on a plane" and "8 GiB is absurd to download" are both true, and
|
||
a second target settles them without compromising either.
|
||
|
||
**Measured facts (2026-07-14), so this starts from numbers, not vibes:**
|
||
- Current ISO **8.078 GiB** compressed; **18.03 GiB** of store uncompressed
|
||
(`zstd -19`, 2.23:1 — compression is already near-max, not the lever).
|
||
- The offline pin (`system.extraDependencies`, 60 roots: a representative
|
||
installed system + the template HM closure + all flake inputs) is **4.02 GiB
|
||
uncompressed of that — only ~22%**. Dropping it entirely still leaves a
|
||
**14.01 GiB** desktop → roughly **6.3 GiB** compressed at the same ratio.
|
||
**So "no pin" alone is NOT the lighter ISO** — this is the trap to avoid.
|
||
- The 14 GiB desktop's own top weights: libreoffice 1457 MiB, initrd 1369,
|
||
linux-firmware 770, chromium ×2 (1391 combined — see #121), llvm-lib 540,
|
||
bibata-cursors 322, mesa 264, mbrola-voices 259, nerd-fonts ~420 combined.
|
||
|
||
**So the real decision is what a netinstall ISO IS**, and it should be settled
|
||
first (`[human]`): (a) the full try-before-install desktop minus the pin
|
||
(~6.3 GiB — barely lighter, probably not worth a second target); (b) a **TUI
|
||
installer only, no desktop** (~1 GiB, the actual "netinstall" in the Debian
|
||
sense) which drops "try before install" from that medium — the fat ISO still
|
||
offers it; (c) a middle desktop (no libreoffice/chromium — but note #103 just
|
||
put those there deliberately, and a *demo* desktop that can't browse is the
|
||
bug #103 fixed).
|
||
|
||
**The gotcha that decides feasibility:** without the pin, a netinstall target
|
||
fetches from `cache.nixos.org` for stock nixpkgs paths — but **Nomarchy's own
|
||
derivations are in no binary cache**, so they would build *from source on the
|
||
user's machine* during install. That is the same failure `tools/vm/gap-analysis.py`
|
||
exists to diagnose (and #113 is a live instance of). So this item probably
|
||
depends on a public binary cache (cachix) for the flake's own outputs, or it
|
||
trades an 8 GiB download for a 40-minute install. Establish that before
|
||
building the target.
|
||
|
||
Pass = a second, documented ISO target that is *substantially* smaller (state
|
||
the measured number, both ISOs built from one tree), installs successfully with
|
||
a network in a QEMU run, says clearly at boot that it needs one, and leaves the
|
||
offline ISO's behaviour untouched (`checks.*` for the offline path stay green).
|
||
|
||
### 121. The Widevine chromium wrapper drags a second 687 MiB chromium along
|
||
|
||
Found while measuring #103 (2026-07-14). **Pre-existing and not live-only** —
|
||
it is in the template HM closure, so it is on **every installed Nomarchy
|
||
machine** and in the ISO, and predates #103 by however long chromium has been
|
||
the default browser.
|
||
|
||
`templates/downstream/home.nix` ships `chromium.override { enableWideVine =
|
||
true; }` (correctly — DRM for Netflix/Spotify). The resulting wrapper depends on
|
||
**two** unwrapped builds:
|
||
|
||
704 MiB chromium-unwrapped-150.0.7871.114-wv ← the browser it runs
|
||
687 MiB chromium-unwrapped-150.0.7871.114 ← plain build, pulled in for
|
||
`share/applications` ONLY
|
||
|
||
`nix why-depends --precise` on the live closure shows the wrapped
|
||
`chromium-…/share/applications` symlinking into the *plain* unwrapped output,
|
||
which retains the whole 687 MiB derivation for a directory of `.desktop` files.
|
||
Nothing runs it.
|
||
|
||
Investigate whether this is a nixpkgs wrapper bug (the wrapper should take its
|
||
desktop entry from the same variant it wraps) — fix upstream and/or work around
|
||
it locally, but **verify the fix by closure diff, not by reading the
|
||
expression**: `nix path-info -r <hm-generation> | grep chromium-unwrapped`
|
||
should list one full build plus the small sandbox. Do **not** "fix" it by
|
||
dropping `enableWideVine` — that silently removes DRM playback, which is a
|
||
feature decision (ROADMAP § Default application suite), not a size cleanup.
|
||
Pass = one full chromium in the closure, DRM still works (V3: a Widevine page
|
||
plays on hardware), and the measured install/ISO delta is recorded.
|
||
|
||
### 115. Suspend-then-hibernate, with a way to set it up
|
||
|
||
Bernardo, 2026-07-14: a suspended laptop should be able to fall through to
|
||
hibernate after a while, so a bag-carried machine stops draining, and setting
|
||
that up must be easy — not a systemd-sleep man-page trip.
|
||
|
||
The mechanism is `systemd`'s `suspend-then-hibernate` plus
|
||
`HibernateDelaySec`; the work is the surfacing, and the constraints are
|
||
already in the tree. Hibernate needs the resume offset + swap the installer
|
||
detects (`resumeOffset`/`rootUuid` in patch-template.py) — on a machine
|
||
without them this must self-gate, not fail at suspend time, the way Battery
|
||
limit gates on a battery. `modules/nixos/default.nix` already declines to
|
||
hyprlock before an encrypted hibernate (the LUKS resume gates it); check that
|
||
reasoning still holds when the suspend leads to hibernate. Menu placement: it
|
||
belongs with the power settings, not the root (§ menu placement convention).
|
||
|
||
Settle first (`[human]`): whether the delay is a preset list (30 min / 1 h /
|
||
2 h / never) or a free-form entry, and whether it applies on battery only or
|
||
always — the same on-AC question `modules/home/idle.nix`'s suspend listener
|
||
already answers with `${onAc} ||`.
|
||
|
||
In-flake state like the rest (`settings.*`), menu-writable, and read via
|
||
`theme-state-read.nix` on the NixOS side — NOT `config.nomarchy.settings`,
|
||
which does not exist there (ROADMAP § *NixOS-side state bridges (#116)*; copy
|
||
the `bluetooth.enable` shape in `modules/nixos/default.nix` and add a case to
|
||
`checks.state-bridges`). Pass = the toggle survives a rebuild,
|
||
a suspended machine hibernates after the configured delay and resumes, and a
|
||
machine without hibernate support hides the row instead of offering a
|
||
suspend that never wakes.
|
||
|
||
### 107. Rename `theme.json` to reflect that it is the system state
|
||
|
||
The state file long ago stopped being about themes: it carries night-light,
|
||
keyboard memory, display resolution and profiles, auto-commit, services and
|
||
more, so `theme.json` now misnames its own contents and misleads anyone
|
||
reading the flake. Rename it to `state.json` (Bernardo's call, 2026-07-14 —
|
||
settled, do not revisit), and carry the `nomarchy-theme-sync` tool name along
|
||
with it.
|
||
|
||
Standalone task — do not fold it into a feature. Ships with a compatibility
|
||
shim that keeps reading an existing `theme.json` so downstream checkouts do
|
||
not break on a pull, plus a migration note. Pass = a fresh install and an
|
||
existing downstream checkout both work, every in-repo reference (modules,
|
||
tools, template, docs) uses the new name, and the shim is documented with the
|
||
release it can be dropped in.
|
||
|
||
### 104. Runtime Airplane mode
|
||
|
||
Add Airplane mode under System connectivity controls. It must disable Wi-Fi
|
||
and Bluetooth together, remember their prior states, and restore those states
|
||
when disengaged. Pass = the runtime round trip works, and a Waybar indicator is
|
||
visible only while engaged with parity across every whole-bar swap.
|
||
|
||
### 105. `[big]` System-menu information architecture
|
||
|
||
Keep exactly six root menu entries while reorganizing System into
|
||
Connectivity, Devices, Recovery, and Preferences. This item must be split into
|
||
scoped implementation/verification tasks before work starts. Pass = every
|
||
current route has one deliberate home, navigation remains shallow, and no
|
||
root-level entry is added or lost.
|
||
|
||
### 106. Internal menu Back/Left navigation contract
|
||
|
||
Reproduce the reported internal leaf with neither Back nor Left behavior, then
|
||
fix any breach of the already-intended navigation contract. Add a permanent
|
||
guard covering every internal leaf; external GUIs and free-text prompts retain
|
||
their explicit Esc exceptions. Pass = no internal leaf can strand the user and
|
||
the guard fails on a regression.
|
||
|
||
### 108. Keybindings menu presentation and completeness audit
|
||
|
||
Group the menu as Window, Workspace, Menu, and Media, then prove every live
|
||
Hyprland binding appears from the canonical source. Do not repeat the obsolete
|
||
claim that float/move bindings are absent. Pass = presentation is scannable and
|
||
an automated comparison detects omissions or stale displayed bindings.
|
||
|
||
### 110. `[big]` Retire Control Center safely
|
||
|
||
Split this into two phases before implementation: first build a migration/drop
|
||
matrix for every unique setting, then remove the package and all references.
|
||
Keyboard and terminal replacements must reject unsafe free-text values. Pass =
|
||
no supported setting silently disappears and the second phase leaves no stale
|
||
launcher, menu, package, documentation, or generated-artifact reference.
|
||
|
||
**Facts for the matrix, from #116 (2026-07-14):** its Bluetooth and Printing
|
||
rows write `settings.{bluetooth,printing}.enable`, and those keys became live
|
||
bridges to the NixOS config in a9f3a64 — until then they wrote JSON nothing
|
||
read, so *these two toggles have never actually worked for any user*. That
|
||
cuts both ways: "preserve existing behavior" is not a reason to keep them
|
||
(there is no behavior to preserve), but the state keys and their bridges are
|
||
real now and outlive the TUI — dropping the rows must not drop the keys, or a
|
||
machine whose theme-state.json already says `bluetooth.enable = false` will
|
||
silently flip back on at the next rebuild. `checks.state-bridges` covers those
|
||
two keys and will fail loudly if the bridges go with the tool; keep it green,
|
||
and if a key is deliberately retired, remove its case in the same commit.
|
||
Whatever inherits the rows should rebuild on toggle rather than print
|
||
"requires rebuild" (#117). Updates (`settings.updates.enable`) is HM-side,
|
||
where `nomarchy.settings` genuinely exists, and needs none of this.
|
||
|
||
### 111. Scope-first Recovery menu
|
||
|
||
Replace confusing Rollback/Snapshots duplication with explicit Desktop
|
||
generation, System boot generation, and Files/root BTRFS scopes. Pass = labels
|
||
state what is restored and from where before action, with destructive or reboot
|
||
effects made clear and each existing recovery path represented once.
|
||
|
||
### 112. Installer disk-picker safety
|
||
|
||
Exclude floppy, pseudo, tiny, and otherwise non-installable devices such as
|
||
`/dev/fd0`; never select them by default. **Reproduced in QEMU 2026-07-13**
|
||
(#93's V2 run): with OVMF the guest exposes `/dev/fd0` and the picker listed
|
||
it FIRST — a blind Enter selected it (artifacts:
|
||
`/tmp/nomarchy-v2-swap-93/20-review.png`, `Disk: /dev/fd0 (WILL BE ERASED)`). Pass = the real install disk is clear,
|
||
invalid devices cannot reach destructive setup, a permanent guard covers the
|
||
filter/default logic, and a pre-destructive KVM run proves the picker behavior.
|
||
|
||
## LATER
|
||
|
||
- **Wallpapers artifact split** (ROADMAP § Faster switches — decided,
|
||
deferred): pinned `Nomarchy-wallpapers` input so a state write stops
|
||
re-copying 86 MB. Follow-on: pre-built theme variants if switches are
|
||
still slow after.
|
||
- **Installer round 2** (ROADMAP § Installer): multi-disk BTRFS RAID,
|
||
impermanence, BIOS/legacy boot.
|
||
- **Boot-from-snapshot**: a systemd-boot equivalent of grub-btrfs.
|
||
- **MIPI/IPU software-ISP camera** support (no-UVC machines).
|
||
- **NixOS release bump → v2** `[human]`: deliberate, hand-edited, never
|
||
automated; the previous attempt was discarded (2026-06-22) over a
|
||
Hyprland OOM blocker — see MEMORY.md before retrying (NOW#3 should
|
||
also soften that blocker class).
|
||
|
||
## FUTURE (decided deferred — not the agent queue head)
|
||
|
||
Work we **intend** someday but explicitly **not** NEXT. Agents do not
|
||
pick these unless Bernardo promotes one into NEXT/NOW.
|
||
|
||
### 20. KVM runner → VM suite in CI `[human]`
|
||
**Status (2026-07-10):** keep **eval-only** CI on the current Gitea
|
||
stack (act_runner in docker-compose on the 4c/4 GB IONOS VPS). Nested
|
||
KVM + RAM headroom on that host are a poor fit next to Gitea; full
|
||
`checks.*` VMs stay local / promotion-time until a **separate**
|
||
KVM-capable machine exists.
|
||
|
||
**When ready:** register a second runner (host-mode nix + `/dev/kvm`,
|
||
label `nix-kvm` — not the existing docker eval runner), then uncomment
|
||
the `vm-checks` job in `.gitea/workflows/check.yml` (`runs-on: nix-kvm`,
|
||
`nix flake check` + toplevel/HM builds). Do not enable the job until
|
||
that label is online (Gitea queues forever otherwise).
|
||
|
||
### Formatter — adopt later `[human]`
|
||
**Intent:** add a Nix formatter (likely `nixfmt-rfc-style`) in a dedicated
|
||
pass: reformat the tree once, document in CONVENTIONS, optional CI
|
||
check. **Not** the queue head — no drive-by reformats until that pass.
|
||
|
||
## PROPOSED (agent suggestions — await human triage)
|
||
|
||
*Agents: append here with a one-paragraph pitch (what/why/cost). Do not
|
||
implement. Bernardo moves accepted items into a tier.*
|
||
|
||
*Open work only. Shipped exam/A–C items (#47–#63, #14, #52 theme
|
||
high-ROI, etc.) live in the journal + ROADMAP — not here.*
|
||
|
||
### Product / day-2
|
||
|
||
### 117. Control Center says "requires rebuild" and leaves the user to do it
|
||
|
||
**Filed as an input to #110 (Retire Control Center safely), not as standalone
|
||
work** — Bernardo 2026-07-14: the Control Center is going away, so fixing its
|
||
toggles would be building on a condemned surface. Recorded because the
|
||
observation outlives the tool: it is a fact the #110 migration matrix needs,
|
||
and whatever menu inherits these settings must not repeat it.
|
||
|
||
Noticed while fixing #116 (2026-07-14). `nomarchy-control-center.sh`'s
|
||
Bluetooth, Printing and Updates toggles set the state and print "… (requires
|
||
rebuild)", so the setting only lands whenever the user next thinks to run
|
||
`nomarchy-rebuild`. Every menu toggle written since does the rebuild itself
|
||
and toasts the outcome (`nomarchy-autologin`, `nomarchy-fingerprint`,
|
||
`nomarchy-autotimezone`) — the state-write-then-rebuild shape. A user who
|
||
toggles Bluetooth off and sees Bluetooth still running cannot tell "needs a
|
||
rebuild" from "the toggle is broken again", which is exactly the symptom #116
|
||
removed. Migrating these rows into the rofi menu resolves it for free, since
|
||
that shape is the convention there.
|
||
|
||
### 114. Greeter ignores per-device keyboard layouts
|
||
|
||
Found by Bernardo 2026-07-14: logging out while docked lands on tuigreet,
|
||
where his external keyboard (remembered as `us` via
|
||
`settings.keyboard.devices`) types the session layout `gb` — so the password
|
||
prompt fights him. Not a regression and not docking-related: per-device
|
||
layouts are applied with `hyprctl keyword device[<name>]:kb_layout`, which
|
||
only exists inside a running Hyprland session, while tuigreet draws on a
|
||
kernel VT whose single keymap comes from `console.useXkbConfig` ←
|
||
`services.xserver.xkb.layout`. A VT structurally cannot do per-device
|
||
layouts, so this is a design gap, not a bug to patch. Options, cheapest
|
||
first: (a) document it and stop there; (b) a greeter layout-cycle key
|
||
(tuigreet has no such feature — would need the keymap swapped under it);
|
||
(c) host tuigreet inside a small Wayland compositor (cage/labwc), which
|
||
*does* get per-device XKB and would let the greeter honour the same
|
||
in-flake state the session uses — real work, and it changes the greeter's
|
||
whole rendering path (`modules/nixos/greeter.nix` themes tuigreet through
|
||
the 16 ANSI console slots, so (c) is not a drop-in). Worth deciding whether
|
||
the greeter is meant to be layout-aware at all before costing it.
|
||
|
||
- **NVIDIA first-class options** — **deferred past v1** (Bernardo
|
||
2026-07-10). Keep #59 commented install guidance; no
|
||
`nomarchy.hardware.nvidia.*` until a hybrid maintainer + queue.
|
||
|
||
- **Post-install hardware hints** (`VISION § B`) — After the general
|
||
“you're set” card (#81), optionally fire **one** additional
|
||
self-gated notify when the machine actually has the hardware:
|
||
(a) `fwupdmgr` on PATH → “System › Firmware to check LVFS updates”;
|
||
(b) `fprintd-list` on PATH → “System › Fingerprint to enroll”.
|
||
One-shot markers in `settings.*` (same in-checkout discipline as
|
||
`firstBootShown`); never a permanent MOTD nag. Cost: small — extend
|
||
`nomarchy-first-boot` or a sibling oneshot + `checks.first-boot`
|
||
fixture. Control-center / MOTD already mention these; the gap is the
|
||
silent first *graphical* session for people who never open those.
|
||
|
||
_(#80–#83 + #85–#88 shipped 2026-07-11. Theme A day-2 + neon-glass finish
|
||
shipped — VISION ✓. Dock/hibernate V3 → HARDWARE-QUEUE. Parallel
|
||
fingerprint-or-password shipped 2026-07-12 (Bernardo promoted it live;
|
||
`fingerprint.parallel`, pam-fprint-grosshack) — reader V3 →
|
||
HARDWARE-QUEUE.)_
|
||
|
||
### v1.0 pointer
|
||
|
||
See **VISION**. Open PROPOSED: post-install hardware hints; NVIDIA
|
||
deferred past v1; IR portal (b)/(c) need T14s (HARDWARE-QUEUE § T14s).
|
||
Standing calls: browser = Chromium; power = PPD.
|
||
|
||
|
||
## Decisions `[human]`
|
||
|
||
Open calls only Bernardo can make; agents add options/evidence but never
|
||
decide. **Resolved** entries stay for history; agents treat them as closed.
|
||
|
||
### Resolved (2026-07-10)
|
||
|
||
- **Docs site vs Markdown-in-repo** — **markdown in-repo for now**
|
||
(`docs/`, README). A rendered docs site is FUTURE if wanted.
|
||
- **Default browser** — **ship Chromium** in
|
||
`templates/downstream/home.nix`; mime → `chromium-browser.desktop`.
|
||
Opt out: delete the line / override mime.
|
||
- **Default power backend** — **keep PPD** (`nomarchy.system.power.backend`
|
||
default). TLP remains the one-line opt-in. Rationale: stability + live
|
||
profile API for menu/Waybar; Omarchy’s TLP experiment reverted.
|
||
|
||
### Resolved (2026-07-10, more)
|
||
|
||
- **Formatter adoption** — **yes, but not now.** Tracked as FUTURE
|
||
(below). Nix-source style only (`nixfmt-rfc-style` or similar); one
|
||
bulk reformat + CI/check when promoted. Until then: hand-aligned
|
||
style per CONVENTIONS.
|
||
|
||
- **Hibernation** — **want by default** (product intent). Needs a
|
||
disk-backed swap (file or partition) sized for resume; not zram alone.
|
||
**Shipped as #76**; V3 power-cycle PASSED on TuringMachine 2026-07-12
|
||
(ROADMAP § Hibernation + zram by default).
|
||
|
||
### Resolved (2026-07-10, #76 design)
|
||
|
||
- **Swap sizing** — **exactly RAM** (installer default, unchanged). Hibernate
|
||
image ≤ RAM; zram takes day-to-day paging. **`swapSize=0`** stays no-swap.
|
||
- **Migration** — **docs runbook** (`docs/MIGRATION.md`), not a tool.
|
||
- **No-swap Hibernate** — keep the menu row; **notify on failure**.
|