Files
Nomarchy/agent/BACKLOG.md
Bernardo Magri bec826baf0
All checks were successful
Check / eval (push) Successful in 3m10s
fix(docking): the undock keyword is inert, not raced; escalate to reload
Round 7 FAILED: 5-6 consecutive unplugs on the dev box, the panel never came
back. Round 6's retry could not have worked, because round 6's diagnosis was
wrong — and so was the "phantom re-add" theory I brought to this session.

With ZERO enabled outputs — panel disabled by the dock, external gone —
Hyprland 0.55.4 accepts `hyprctl keyword monitor eDP-1,preferred,auto,1`,
prints `ok`, exits 0, and never flushes it: the rule waits for a DRM event
that is not coming. It is inert, not raced. Retrying it 25x/poll for 6 polls
bought 30s of black screen and nothing else.

What made this survive two rounds is worth more than the fix: every
`transition=undock result=ok` in the round-6 journal was Bernardo plugging
the cable back in because the screen was black. His hotplug flushed the
queued rule and the next poll took the credit. Success was indistinguishable
from the user working around the failure, so the logs confirmed whichever
story we brought to them. Ten minutes of probing on hardware killed both.

Probed live 2026-07-14 (dev box, cable out): keyword inert across 4s and 5s
in two runs; `dispatch forcerendererreload` inert too; only `hyprctl reload`
escapes — 99ms and 289ms. So: issue the keyword (enough whenever another
output is still enabled, e.g. the menu's Dock mode), and escalate to reload
only when `monitors` proves it inert. After a reload, re-assert the rule so a
config that parks the panel off cannot undo the undock, and restore per-device
keyboard layouts — a reload re-reads the config and drops the runtime
`device[<name>]:kb_layout` an external board depends on. The menu's `enable`
now proves itself against `monitors` too, instead of cheering for an exit code.

Verified V3 (partial): the fixed transition driven through a real unplug —
panel on, workspaces 1-3 home, 1.8s, `keyword=inert escalate=reload` ->
`enable=via-reload` -> `result=ok`. V2: nix flake check --no-build; docking-ux
+ dock-audio; monitor-fallback.nix; shellcheck clean on display-transition.

NOT proven, and queued as HARDWARE-QUEUE round 8: the watcher-driven path
(exec-once + baked store path = relogin required, the round-5 trap) and
repetition. The keyboard-restore path is untested — the dev box's keyboard
hangs off the dock's hub, so it leaves with the cable; round 8 adds a check
with a keyboard in the laptop. The VM harness still cannot reach any of this:
QEMU aborts Hyprland if the last active output is deleted while the DRM output
is disabled, which is the same zero-output degeneracy from the other side.

New BACKLOG #114 (PROPOSED): tuigreet ignores per-device keyboard layouts —
a VT has one keymap, so the greeter cannot honour `device[]:kb_layout`.
Bernardo hit it logging out while docked; not a regression, a design gap.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-14 12:28:06 +01:00

307 lines
15 KiB
Markdown
Raw Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Backlog — the prioritized task queue
**This is the only executable work list for agents.** Product themes and
v1.0 intent live in [`docs/VISION.md`](../docs/VISION.md); design history
in [`docs/ROADMAP.md`](../docs/ROADMAP.md); map in
[`docs/README.md`](../docs/README.md) and [`agent/README.md`](README.md).
**Rules:**
- Agents take the topmost actionable item (see LOOP.md). Finished items
are **deleted** here — the journal + git log are the record; durable
design notes get a ✓-entry in docs/ROADMAP.md (and/or a note in VISION)
if worth keeping.
- Item numbers are **stable IDs** — never renumbered or reused. A gap in
the sequence means shipped (or dropped) work; new items take the next
free number regardless of tier.
- Tags: `[blocked:hw]` needs real hardware (see HARDWARE-QUEUE.md) ·
`[human]` needs Bernardo · `[stuck]` two failed attempts, needs help ·
`[big]` must be split before starting.
- Agents may append to **PROPOSED** and **Decisions** freely (include
`VISION § …` or `ROADMAP § …` when relevant); only Bernardo moves items
*out* of PROPOSED into the tiers.
---
## NOW
### Live ISO hardware findings — Acer Aspire M5-481T (Bernardo, 2026-07-13)
These are separate queue items from one real install/session pass. Preserve
that separation when fixing them: the installer blocker, unclear installer
copy, and post-install desktop failures have different verification paths.
### 94. Live ISO/install: no default browser observed
**Progress 2026-07-13:** installed path VERIFIED at V1 — the exact HM
generation the ISO pins for offline installs contains the chromium binary,
`chromium-browser.desktop`, and all three HTTP/HTML handlers
(mime.nix sets them; template ships the package). The Acer sighting is the
LIVE session, which ships NO browser by design (mime defaults name chromium,
GIO skips it while absent) — #103 adds live baseline apps. Live posture is
now explicit in the flake comment. Remains: a test-install VM run proving
chromium launches post-install (chain #97's Bluetooth-click V2 into the
same run).
Chromium is the resolved default-browser decision and is present in the
downstream template, but this hardware pass found no usable default browser.
Trace the live-to-installed Home Manager path rather than merely checking the
template source. Pass = Chromium launches after installation and HTTP/HTTPS
mime defaults resolve to `chromium-browser.desktop` (and the intended live-ISO
browser posture is explicit).
### 95. Live ISO/install: Ghostty does not open
Reproduce from the launcher and a terminal, capture its stderr/journal, and
fix the packaging/session/runtime cause. Pass = the default terminal opens in
the installed graphical session and the SUPER+Return path works.
### 98. Boreal: button text renders black and is difficult to read
Audit GTK button foreground/background contrast under Boreal, including the
installer surface where it was observed. Follow THEME-DESIGN's two-theme
visual protocol. Pass = normal, hover, focused, and disabled button labels
remain legible and palette-consistent.
**Progress 2026-07-13:** scripted checks pass all 24 themes — not
palette-level. Stylix gtk.css for Boreal audited: fg roles are light
(#d3dae0); the near-black values are `accent/warning/error_fg_color`
(#21272f) on their pastel bgs (deliberate, ~4.4:1). Candidate surfaces:
adw-gtk3 (light base) + dark recolor edge cases, or gum's TUI confirm
buttons in the installer (VM gum screens under Boreal look legible —
artifacts in `/tmp/nomarchy-v2-swap-93/`). Needs Bernardo's screenshot or
an Acer repro to pin the actual widget before fixing.
### 113. Live session: offline theme switch rebuilds the world from source
Surfaced by #99's evidence run (2026-07-13, `/tmp/nomarchy-v2-theme-99/`):
in the **live ISO** session, offline `nomarchy-theme-sync apply gruvbox`
fails — its `home-manager switch` tries to build **1176 derivations** from
the `stage0`/`hex0` bootstrap up, then dies on offline source fetches
(`vala`, `yasm`, `config.jsonc`, `ghostty-config`, `easyeffects.svg`,
`typogrify`…), ending `error: Build failed due to failed dependency`. This
contradicts docs/TESTING.md item 6 ("apply gruvbox → switch runs offline").
The failing generation is `bvl30ggn…-home-manager-generation.drv`; it is
**not** the drv the ISO pins (the pin is the *default*-theme
`homeConfigurations.${username}.activationPackage`, i.e. Boreal — confirmed
drv-identical to the failing one only for gruvbox state, so a non-default
theme's generation is unpinned). NOT caused by #99's git-seed: the drv is
byte-identical path-seeded vs git-seeded. **Decide the contract:** either
pin every baked theme's live activationPackage into the ISO (size cost) or
scope the offline-switch promise to the shipped theme + correct
TESTING.md/MEMORY. Pass = a fresh live ISO either switches to any baked
theme offline, or fails with a clear "needs network for this theme" message
and accurate docs. **Not caused by anything in today's batch** — separate
pre-existing ISO-pinning gap.
## NEXT
### 107. Rename `theme.json` to reflect that it is the system state
The state file long ago stopped being about themes: it carries night-light,
keyboard memory, display resolution and profiles, auto-commit, services and
more, so `theme.json` now misnames its own contents and misleads anyone
reading the flake. Rename it to `state.json` (Bernardo's call, 2026-07-14 —
settled, do not revisit), and carry the `nomarchy-theme-sync` tool name along
with it.
Standalone task — do not fold it into a feature. Ships with a compatibility
shim that keeps reading an existing `theme.json` so downstream checkouts do
not break on a pull, plus a migration note. Pass = a fresh install and an
existing downstream checkout both work, every in-repo reference (modules,
tools, template, docs) uses the new name, and the shim is documented with the
release it can be dropped in.
### 103. Live ISO baseline desktop applications
Make Chromium and Firefox, `libreoffice-fresh`, GNOME Text Editor, Amberol, and
GNOME Snapshot explicitly available in the live profile and application
launcher. Text Editor and Snapshot are the maintained gedit/Cheese successors;
HTTP remains assigned to Chromium. Pass = all six launch in the live session
and the resulting ISO-size delta is recorded.
### 104. Runtime Airplane mode
Add Airplane mode under System connectivity controls. It must disable Wi-Fi
and Bluetooth together, remember their prior states, and restore those states
when disengaged. Pass = the runtime round trip works, and a Waybar indicator is
visible only while engaged with parity across every whole-bar swap.
### 105. `[big]` System-menu information architecture
Keep exactly six root menu entries while reorganizing System into
Connectivity, Devices, Recovery, and Preferences. This item must be split into
scoped implementation/verification tasks before work starts. Pass = every
current route has one deliberate home, navigation remains shallow, and no
root-level entry is added or lost.
### 106. Internal menu Back/Left navigation contract
Reproduce the reported internal leaf with neither Back nor Left behavior, then
fix any breach of the already-intended navigation contract. Add a permanent
guard covering every internal leaf; external GUIs and free-text prompts retain
their explicit Esc exceptions. Pass = no internal leaf can strand the user and
the guard fails on a regression.
### 108. Keybindings menu presentation and completeness audit
Group the menu as Window, Workspace, Menu, and Media, then prove every live
Hyprland binding appears from the canonical source. Do not repeat the obsolete
claim that float/move bindings are absent. Pass = presentation is scannable and
an automated comparison detects omissions or stale displayed bindings.
### 110. `[big]` Retire Control Center safely
Split this into two phases before implementation: first build a migration/drop
matrix for every unique setting, then remove the package and all references.
Keyboard and terminal replacements must reject unsafe free-text values. Pass =
no supported setting silently disappears and the second phase leaves no stale
launcher, menu, package, documentation, or generated-artifact reference.
### 111. Scope-first Recovery menu
Replace confusing Rollback/Snapshots duplication with explicit Desktop
generation, System boot generation, and Files/root BTRFS scopes. Pass = labels
state what is restored and from where before action, with destructive or reboot
effects made clear and each existing recovery path represented once.
### 112. Installer disk-picker safety
Exclude floppy, pseudo, tiny, and otherwise non-installable devices such as
`/dev/fd0`; never select them by default. **Reproduced in QEMU 2026-07-13**
(#93's V2 run): with OVMF the guest exposes `/dev/fd0` and the picker listed
it FIRST — a blind Enter selected it (artifacts:
`/tmp/nomarchy-v2-swap-93/20-review.png`, `Disk: /dev/fd0 (WILL BE ERASED)`). Pass = the real install disk is clear,
invalid devices cannot reach destructive setup, a permanent guard covers the
filter/default logic, and a pre-destructive KVM run proves the picker behavior.
## LATER
- **Wallpapers artifact split** (ROADMAP § Faster switches — decided,
deferred): pinned `Nomarchy-wallpapers` input so a state write stops
re-copying 86 MB. Follow-on: pre-built theme variants if switches are
still slow after.
- **Installer round 2** (ROADMAP § Installer): multi-disk BTRFS RAID,
impermanence, BIOS/legacy boot.
- **Boot-from-snapshot**: a systemd-boot equivalent of grub-btrfs.
- **MIPI/IPU software-ISP camera** support (no-UVC machines).
- **NixOS release bump → v2** `[human]`: deliberate, hand-edited, never
automated; the previous attempt was discarded (2026-06-22) over a
Hyprland OOM blocker — see MEMORY.md before retrying (NOW#3 should
also soften that blocker class).
## FUTURE (decided deferred — not the agent queue head)
Work we **intend** someday but explicitly **not** NEXT. Agents do not
pick these unless Bernardo promotes one into NEXT/NOW.
### 20. KVM runner → VM suite in CI `[human]`
**Status (2026-07-10):** keep **eval-only** CI on the current Gitea
stack (act_runner in docker-compose on the 4c/4GB IONOS VPS). Nested
KVM + RAM headroom on that host are a poor fit next to Gitea; full
`checks.*` VMs stay local / promotion-time until a **separate**
KVM-capable machine exists.
**When ready:** register a second runner (host-mode nix + `/dev/kvm`,
label `nix-kvm` — not the existing docker eval runner), then uncomment
the `vm-checks` job in `.gitea/workflows/check.yml` (`runs-on: nix-kvm`,
`nix flake check` + toplevel/HM builds). Do not enable the job until
that label is online (Gitea queues forever otherwise).
### Formatter — adopt later `[human]`
**Intent:** add a Nix formatter (likely `nixfmt-rfc-style`) in a dedicated
pass: reformat the tree once, document in CONVENTIONS, optional CI
check. **Not** the queue head — no drive-by reformats until that pass.
## PROPOSED (agent suggestions — await human triage)
*Agents: append here with a one-paragraph pitch (what/why/cost). Do not
implement. Bernardo moves accepted items into a tier.*
*Open work only. Shipped exam/AC items (#47#63, #14, #52 theme
high-ROI, etc.) live in the journal + ROADMAP — not here.*
### Product / day-2
### 114. Greeter ignores per-device keyboard layouts
Found by Bernardo 2026-07-14: logging out while docked lands on tuigreet,
where his external keyboard (remembered as `us` via
`settings.keyboard.devices`) types the session layout `gb` — so the password
prompt fights him. Not a regression and not docking-related: per-device
layouts are applied with `hyprctl keyword device[<name>]:kb_layout`, which
only exists inside a running Hyprland session, while tuigreet draws on a
kernel VT whose single keymap comes from `console.useXkbConfig`
`services.xserver.xkb.layout`. A VT structurally cannot do per-device
layouts, so this is a design gap, not a bug to patch. Options, cheapest
first: (a) document it and stop there; (b) a greeter layout-cycle key
(tuigreet has no such feature — would need the keymap swapped under it);
(c) host tuigreet inside a small Wayland compositor (cage/labwc), which
*does* get per-device XKB and would let the greeter honour the same
in-flake state the session uses — real work, and it changes the greeter's
whole rendering path (`modules/nixos/greeter.nix` themes tuigreet through
the 16 ANSI console slots, so (c) is not a drop-in). Worth deciding whether
the greeter is meant to be layout-aware at all before costing it.
- **NVIDIA first-class options** — **deferred past v1** (Bernardo
2026-07-10). Keep #59 commented install guidance; no
`nomarchy.hardware.nvidia.*` until a hybrid maintainer + queue.
- **Post-install hardware hints** (`VISION § B`) — After the general
“you're set” card (#81), optionally fire **one** additional
self-gated notify when the machine actually has the hardware:
(a) `fwupdmgr` on PATH → “System Firmware to check LVFS updates”;
(b) `fprintd-list` on PATH → “System Fingerprint to enroll”.
One-shot markers in `settings.*` (same in-checkout discipline as
`firstBootShown`); never a permanent MOTD nag. Cost: small — extend
`nomarchy-first-boot` or a sibling oneshot + `checks.first-boot`
fixture. Control-center / MOTD already mention these; the gap is the
silent first *graphical* session for people who never open those.
_(#80#83 + #85#88 shipped 2026-07-11. Theme A day-2 + neon-glass finish
shipped — VISION ✓. Dock/hibernate V3 → HARDWARE-QUEUE. Parallel
fingerprint-or-password shipped 2026-07-12 (Bernardo promoted it live;
`fingerprint.parallel`, pam-fprint-grosshack) — reader V3 →
HARDWARE-QUEUE.)_
### v1.0 pointer
See **VISION**. Open PROPOSED: post-install hardware hints; NVIDIA
deferred past v1; IR portal (b)/(c) need T14s (HARDWARE-QUEUE § T14s).
Standing calls: browser = Chromium; power = PPD.
## Decisions `[human]`
Open calls only Bernardo can make; agents add options/evidence but never
decide. **Resolved** entries stay for history; agents treat them as closed.
### Resolved (2026-07-10)
- **Docs site vs Markdown-in-repo** — **markdown in-repo for now**
(`docs/`, README). A rendered docs site is FUTURE if wanted.
- **Default browser** — **ship Chromium** in
`templates/downstream/home.nix`; mime → `chromium-browser.desktop`.
Opt out: delete the line / override mime.
- **Default power backend** — **keep PPD** (`nomarchy.system.power.backend`
default). TLP remains the one-line opt-in. Rationale: stability + live
profile API for menu/Waybar; Omarchys TLP experiment reverted.
### Resolved (2026-07-10, more)
- **Formatter adoption** — **yes, but not now.** Tracked as FUTURE
(below). Nix-source style only (`nixfmt-rfc-style` or similar); one
bulk reformat + CI/check when promoted. Until then: hand-aligned
style per CONVENTIONS.
- **Hibernation** — **want by default** (product intent). Needs a
disk-backed swap (file or partition) sized for resume; not zram alone.
**Shipped as #76**; V3 power-cycle PASSED on TuringMachine 2026-07-12
(ROADMAP § Hibernation + zram by default).
### Resolved (2026-07-10, #76 design)
- **Swap sizing** — **exactly RAM** (installer default, unchanged). Hibernate
image ≤ RAM; zram takes day-to-day paging. **`swapSize=0`** stays no-swap.
- **Migration** — **docs runbook** (`docs/MIGRATION.md`), not a tool.
- **No-swap Hibernate** — keep the menu row; **notify on failure**.