modules/nixos/oom.nix — running out of memory now kills the offending process (with a desktop notification via systembus-notify) instead of freezing the desktop for minutes until the kernel OOM killer fires. earlyoom over systemd-oomd, deliberately: oomd kills whole cgroups, and a Hyprland session runs as ONE scope (nothing here spawns per-app systemd scopes, unlike GNOME) — under pressure oomd would take out the entire desktop to save it. earlyoom kills the single largest process before the thrash point. nixpkgs default-enables oomd in an inert state (no slices monitored); it is disabled outright so there is one owner. Session plumbing is --avoid-listed (unanchored — NixOS wrappers rename comm to .foo-wrapped); no --prefer tuning, largest-RSS selection already finds the hog. All mkDefault; opt out with services.earlyoom.enable = false (README note added). Verified: V0 (flake check) + V2 — new checks.oom-protection runNixOSTest, executed: a chunked allocator (686 MB peak, 1 GB VM) is SIGTERM'd by earlyoom in 0.1 s, a bystander unit survives (the process-level granularity the module exists for), and systemd-oomd is asserted inactive. 25 s runtime. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
12 KiB
Backlog — the prioritized task queue
The forward-looking half of the old docs/ROADMAP.md, reworked as a queue
agents can execute. Detailed design notes and decision records stay in
docs/ROADMAP.md (referenced as "ROADMAP § "); this file is what's
next, in what order.
Rules:
- Agents take the topmost actionable item (see LOOP.md). Finished items are deleted here — the journal + git log are the record; durable design notes get a ✓-entry in docs/ROADMAP.md if worth keeping.
- Item numbers are stable IDs — never renumbered or reused. A gap in the sequence means shipped (or dropped) work; new items take the next free number regardless of tier.
- Tags:
[blocked:hw]needs real hardware (see HARDWARE-QUEUE.md) ·[human]needs Bernardo ·[stuck]two failed attempts, needs help ·[big]must be split before starting. - Agents may append to PROPOSED and Decisions freely; only Bernardo moves items out of PROPOSED into the tiers.
NOW
20. Confirm the first CI run goes green [human]
Runner registration — resolved: the runner was alive all along
(gitea/act_runner via docker-compose, ubuntu-latest label); the
workflow was in .forgejo/workflows/, which Gitea ignores — moved
to .gitea/workflows/. Remaining: watch the first real run at
https://git.bemagri.xyz/bernardo/Nomarchy/actions — the eval job's
container recipe is inherited from the legacy repo but this flake's
eval is new territory (memory headroom of the runner container is the
likely failure mode; the legacy repo OOM'd on heavy evals). Stretch
(unchanged): a second runner on a host with /dev/kvm + nix (label
nix-kvm, host mode) unlocks the workflow's commented vm-checks job
— the VM suite + real builds in CI (upgrades half of item 14 free).
4. btrfs-assistant segfault — attempt the nixpkgs override fix
ROADMAP § Snapshot browse/restore. btrfs-assistant 2.2 crashes in
libbtrfsutil.so.1.4.0 (ABI mismatch, confirmed not a VM artifact); the
nomarchy-snapshots fzf fallback ships. Try an override aligning its
libbtrfsutil (or a version bump/pin); if upstream nixpkgs has since
fixed it, just verify and re-point the menu. Done when: the GUI
launches in the VM test, or the attempt is written up as infeasible
(then re-check on each lock bump). Verify: V2 — extend the snapper
VM check to launch the binary.
5. Keyboard layouts — cycle bind + summer-bar parity
ROADMAP § Keyboard layouts, remaining bullets: (a) a multi-layout cycle
bind (hyprctl switchxkblayout current-device, or xkb grp: option)
when >1 session layout, in the cheatsheet; (b) add hyprland/language
to the summer-day/night waybar.jsonc whole-swaps (parity rule — the
generated bar has it, the static ones don't; gating doesn't translate,
decide the static behavior and note it). Verify: V1 + jq the
rendered configs; V3 queue the on-hardware cycle check.
6. Full docs review & restructure
ROADMAP § Full docs review. The roadmap/backlog split is done (this
file); remaining: reconcile every README option table against the live
nomarchy.* surface; drift pass over docs/OVERRIDES.md, docs/TESTING.md,
templates/downstream/README.md; read the install/first-run story end to
end; add a short recovery runbook (desktop won't start → boot an
older generation / nomarchy-snapshots / greetd journal — the pieces
exist, the story isn't written). Site-vs-markdown is a Decision (below).
Verify: V0 + a mechanical option-surface diff (eval the options,
compare to the tables — consider making that a permanent check).
7. Webcam follow-ups (small)
ROADMAP § Webcam: ship v4l-utils + cameractrls (commented app-suite
entries or alongside the camera toggle — respect the option-surface
rule) for genuine-tuning cases; write up the portal/Flatpak
libcamera-path gap (internal IR still listed there) as a PROPOSED item
with options. Verify: V1.
NEXT
8. Complete-workstation viewers + default applications
New. The template ships mpv but no PDF viewer and no image viewer,
and nothing sets xdg-mime defaults — so "open a PDF/photo" falls to
whatever GTK guesses (GIMP for images). Two halves: (a) add a themed,
lightweight PDF viewer + image viewer to the template's active
home.packages (candidates: zathura or GNOME Papers; imv or loupe —
prefer what Stylix themes well); (b) a mime-defaults module setting
xdg.mimeApps associations (browser/PDF/image/video/text, mkDefault)
— real config, so unlike bare packages this is module territory, but
it must degrade gracefully when the user deletes a package from the
suite. Verify: V1 + assert the rendered mimeapps.list; V3 queue an
open-a-file smoke.
9. Update & rollback UX
New; extends the update-awareness story to the other half: what changed,
and how do I get back. (a) sys-update prints a human diff of what the
update changed (nvd diff between system generations, or nix store diff-closures); (b) a System → Rollback menu flow: desktop = pick a
recent home-manager generations entry and activate it (the theme
history is already generations); system = point at the boot-menu
generation flow + nomarchy-snapshots rather than reimplementing it —
destructive steps keep the typed-yes gate. Why: informative +
rock-stable means undo is one menu away, not a Nix lesson. Verify:
V1; V2 for the generation-activate path in a VM.
10. nomarchy-doctor — one-shot health check
New. A single command (+ System-menu entry) that checks the things that actually break user machines and prints a themed pass/fail sheet: failed systemd units (system + user), disk space (/, /boot, the nix store), state-file parses + is git-tracked, downstream flake dirty/ diverged, last rebuild generation age, snapper timeline running (when enabled). Read-only, no auto-fixing; each failure prints the one command that fixes it. Optionally later: a self-gating Waybar warning fed by the same script. Verify: V2 — a VM check with an induced failure.
11. State-file validation & friendly errors
New; "the user never has to master Nix" must include error messages.
A hand-edited theme-state.json (trailing comma, wrong type, unknown
theme slug) today surfaces as a raw Nix eval stack. Add (a) nomarchy- theme-sync validate + validate-before-write on every set/apply; (b) an
eval-time schema assertion in theme.nix whose message says the field,
the problem, and the fix in plain language. Verify: V1 + a corpus of
broken-state fixtures round-tripped through validate; V2 if cheap.
12. Screen recording in the Capture submenu
New; screenshots ship, recording doesn't — a standard workstation need.
Extend nomarchy-menu capture: record region/full → wl-screenrec
(fallback wf-recorder), saved next to Screenshots, with a self-gating
Waybar recording indicator that stops the recording on click (the only
sane "stop" surface). Optional audio toggle. Parity rule applies.
Verify: V1 + bash -n; V2 headless if the software-GL recipe
supports it, else V3 queue.
13. Small niceties batch (one slice per iteration)
Each is a small, self-contained polish item in the existing patterns:
- Idle-inhibit (caffeine) toggle: Waybar
idle_inhibitormodule (blocks hypridle lock/suspend during video/presentations) + summer whole-swap parity + cheatsheet mention. - Low-battery notifications: the bar colors at 25/10% but nothing
notifies; gate on
power.laptop(poweralertd, or a small upower watcher consistent with how the bar reads state). - Color picker:
hyprpicker→ clipboard as a Tools › entry +SUPER+CTRLbind; pairs naturally with theme work.
14. Automated upstream lock bumps (maintainer CI, slices b+c) [big]
ROADMAP § Automated upstream lock bumps — the scheduled half (the
checks-on-push workflow shipped; see item 20 for the runner status):
weekly job runs nix flake update (within pinned release branches) →
full check suite → lands on main on green; v1 promotion stays
human. Plus the fast-lane note for security bumps. Note the current
runner is eval-only (no KVM) — a green bump run guards eval, not the VM
suite, until item 20's stretch runner exists.
15. Display profiles — docked/undocked switching
ROADMAP § Display / monitor management, remaining: true profile switching of the same outputs (multi-layout toggles, beyond per-output hotplug rules), optionally workspace-to-monitor binding. Design first (state-file shape, menu surface) — write the plan into this entry before coding.
16. Greeter theming from the JSON
ROADMAP § Greeter. tuigreet themed from theme-state.json at system rebuild (same model as Plymouth's tint). Scope: tuigreet only (no SDDM).
17. Launch-or-focus UX scripts
ROADMAP § launch-or-focus. Hyprland dispatch scripts: a bind launches an app or focuses its existing window. Curate which apps get binds; cheatsheet entries via keybinds.nix.
18. "nomarchy" control center + first-boot welcome [big]
ROADMAP § control center. A single front-end over the common toggles on
the same nomarchy-theme-sync surface, + a first-boot guided
"pick your theme / essentials" flow. Needs a design pass (TUI vs GUI)
→ write options into Decisions before implementing. Note: items 9–11
(rollback menu, doctor, validation) are natural panels of it — design
them as composable commands, not dead ends.
19. Look & Feel menu category
ROADMAP § Menu system, remaining: group Theme + night-light (+ wallpaper cycle, future appearance toggles) under a Look & Feel submenu once it earns ≥3 entries — keep the root at six.
LATER
- Wallpapers artifact split (ROADMAP § Faster switches — decided,
deferred): pinned
Nomarchy-wallpapersinput so a state write stops re-copying 86 MB. Follow-on: pre-built theme variants if switches are still slow after. - Installer round 2 (ROADMAP § Installer): multi-disk BTRFS RAID, impermanence, BIOS/legacy boot.
- Boot-from-snapshot: a systemd-boot equivalent of grub-btrfs.
- Night-light geo mode: lat/long auto sunset/sunrise (means wlsunset).
- Per-theme icon overrides / more icon packs (ROADMAP § Icon themes).
- MIPI/IPU software-ISP camera support (no-UVC machines).
- OCR screenshot-to-text: a Capture › entry (grim region → tesseract → clipboard) — cheap once recording (#12) reshapes the submenu.
- Auto-timezone Waybar tooltip showing the detected zone (optional).
- VPN exit-node richer display (country/city) (optional).
- NixOS release bump → v2
[human]: deliberate, hand-edited, never automated; the previous attempt was discarded (2026-06-22) over a Hyprland OOM blocker — see MEMORY.md before retrying (NOW#3 should also soften that blocker class).
PROPOSED (agent suggestions — await human triage)
Agents: append here with a one-paragraph pitch (what/why/cost). Do not implement. Bernardo moves accepted items into a tier.
- (empty)
Decisions [human]
Open calls only Bernardo can make; agents add options/evidence but never decide.
- Formatter adoption: repo deliberately has none;
nixfmt-rfc-stylewould flatten the aligned hand-formatting of ~33 files. Adopt or declare never? - Docs site vs Markdown-in-repo (from the docs-review item).
- Control center form factor: TUI (gum/ratatui-style) vs GUI vs "the rofi menu is the control center, just add a first-boot flow".
- zram swap: faster under pressure and pairs with NOW#3, but it interacts with the hibernation-swapfile story (resume device/priority ordering) — adopt, adopt-with-hibernation-guard, or skip?
- Default browser: the template comments Firefox out; item #8's mime
defaults need something to point
text/htmlat — ship a browser active in the suite, or leave browserless-by-default and let mime defaults degrade?