<feed xmlns='http://www.w3.org/2005/Atom'>
<title>archsetup, branch main</title>
<subtitle>Builds a full dev workstation from a bare Arch Linux install.
</subtitle>
<id>https://git.cjennings.net/archsetup/atom?h=main</id>
<link rel='self' href='https://git.cjennings.net/archsetup/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/'/>
<updated>2026-09-16T19:10:34+00:00</updated>
<entry>
<title>chore(tasks): file the MT7925 Bluetooth bug and the AX210 swap</title>
<updated>2026-09-16T19:10:34+00:00</updated>
<author>
<name>Craig Jennings</name>
<email>c@cjennings.net</email>
</author>
<published>2026-09-16T19:10:34+00:00</published>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/commit/?id=221bf506a5619ae4d635ced55f13f5549dc351d4'/>
<id>urn:sha1:221bf506a5619ae4d635ced55f13f5549dc351d4</id>
<content type='text'>
Three headsets drop HFP call audio on velox's MT7925, and the kernel's sentinel-handle errors match a pending upstream firmware report, so I'm replacing the card with an Intel AX210. I also filed the net doctor captive-portal task and archived two aged completed tasks.
</content>
</entry>
<entry>
<title>chore(tasks): archive the closed velox and wttrin tasks</title>
<updated>2026-09-13T14:58:25+00:00</updated>
<author>
<name>Craig Jennings</name>
<email>c@cjennings.net</email>
</author>
<published>2026-09-13T14:58:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/commit/?id=12ee214f1ab1271b9e4082e05ca44d6cd8a4b03a'/>
<id>urn:sha1:12ee214f1ab1271b9e4082e05ca44d6cd8a4b03a</id>
<content type='text'>
The velox reinstall drill, the lock-screen clock bug and the rescued wttrin commit move to Resolved, and one aged resolved task moves to the archive file.
</content>
</entry>
<entry>
<title>chore(tasks): close the rescued emacs-wttrin commit</title>
<updated>2026-09-13T14:55:55+00:00</updated>
<author>
<name>Craig Jennings</name>
<email>c@cjennings.net</email>
</author>
<published>2026-09-13T14:55:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/commit/?id=02e8481c84cf123d31219955cafd74eec808441c'/>
<id>urn:sha1:02e8481c84cf123d31219955cafd74eec808441c</id>
<content type='text'>
The commit that existed only on velox's old disk is now on emacs-wttrin's release/0.4.0, with fixes for the two bugs it carried. The bundle's other heads were already on the remote, and the landed patch matches the rescued one. I deleted the bundle and its working dir.
</content>
</entry>
<entry>
<title>chore(tasks): close the velox reinstall drill and the lock-clock bug</title>
<updated>2026-09-13T14:23:39+00:00</updated>
<author>
<name>Craig Jennings</name>
<email>c@cjennings.net</email>
</author>
<published>2026-09-13T14:23:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/commit/?id=2f81174b1de13d9148113fb9f3d389ca6c61ac5c'/>
<id>urn:sha1:2f81174b1de13d9148113fb9f3d389ca6c61ac5c</id>
<content type='text'>
The reinstall drill finished on 2026-08-14 and every finding it surfaced already has its own task, so what remained was the record. I filed its working-dir artifacts into permanent homes. The runbook went to docs/ with an Outcome section, since the checklist was never ticked as it ran. The UEFI boot-entry reference went to docs/ too. The three reinstall-gap reports went to docs/design/. The rescued wttrin bundle moved into its own working dir under the task that owns it. Every inbound link is repointed and working/velox-reinstall/ is gone.

The lock-screen clock bug is closed because it no longer happens on velox. I couldn't identify the commit that fixed it from the dotfiles or archsetup logs, and the note says so. Its manual-testing check retires with it.
</content>
</entry>
<entry>
<title>chore: file the legacy inbox references and two unfiled captures</title>
<updated>2026-09-13T12:22:10+00:00</updated>
<author>
<name>Craig Jennings</name>
<email>c@cjennings.net</email>
</author>
<published>2026-09-13T12:22:10+00:00</published>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/commit/?id=c9f9a9881548114e49752d5bc4feba4a83ed4d84'/>
<id>urn:sha1:c9f9a9881548114e49752d5bc4feba4a83ed4d84</id>
<content type='text'>
The inbox held 64 processed-but-kept handoffs from July and August. The inbox discipline no longer allows that state: a file is a task, reference content in a tracked home, or gone. I read each one. Fifty-six were acknowledgments, FYIs, lint pipeline files or requests whose work had already landed. Those are deleted.

Eight carried content worth keeping. The 2026-07-15 velox boot-failure diagnosis moves to docs/design, linked from the retrospective task. The three 2026-08-14 reinstall-gap reports move into the velox reinstall working dir, linked from the post-rebuild task. The two Maeda applets and their notes join the clock display references.

Two captures had never landed anywhere: the waybar module separator I captured on 2026-07-20 ([#B]) and the window-configuration research idea from 2026-07-24 ([#C]). Both are filed. The velox reinstall task records the two live steps (wsdd off, passim masked) applied over ssh once velox came back, and the health-check log now says velox is masked.
</content>
</entry>
<entry>
<title>chore(tasks): file the maint probe bugs from the velox health check</title>
<updated>2026-09-13T12:02:39+00:00</updated>
<author>
<name>Craig Jennings</name>
<email>c@cjennings.net</email>
</author>
<published>2026-09-13T12:02:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/commit/?id=dc00a625906eafd52bc791fe3ba117225e7851da'/>
<id>urn:sha1:dc00a625906eafd52bc791fe3ba117225e7851da</id>
<content type='text'>
I filed two bugs against maint. backup_freshness reads /var/log/rsyncshot.log, which the backup_run remedy never writes, so a by-hand daily stays CRITICAL until cron runs ([#C]). The listeners probe flags loopback-only binds such as docker-proxy on 127.0.0.1, a permanent warn on both daily drivers ([#B]).

I folded two findings into existing tasks: the topgrade spec task gets the containers step failing on local images and the initramfs gate needing root, and the Proton profiles task gets the NM drop-in already matching wgpvpn. I added #+PRIORITIES: A D D so org-lint knows [#D] is in bounds here.
</content>
</entry>
<entry>
<title>docs(health-check): record the velox 2026-09-12 findings</title>
<updated>2026-09-13T12:02:39+00:00</updated>
<author>
<name>Craig Jennings</name>
<email>c@cjennings.net</email>
</author>
<published>2026-09-13T12:02:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/commit/?id=c667485437e9e34a2517c963152a1a86dbc19972'/>
<id>urn:sha1:c667485437e9e34a2517c963152a1a86dbc19972</id>
<content type='text'>
These come from velox's 2026-09-12 health check. The Framework 04.02 BIOS update re-enabled Secure Boot, which rejects the unsigned ZFSBootMenu loader and reads as "no bootable device" while the boot entries are intact. I added a pre-firmware-update checklist to Phase 3 and a check-Secure-Boot-first section to the velox boot-entry reference.

Four Known Issues entries cover the Secure Boot flip, fwupdmgr activating passim, the topgrade containers step failing on local images and the harmless mkinitcpio firmware warnings. Phase 3 also notes why lsinitcpio needs sudo: the images are 0600, so an unprivileged run errors on stderr with an empty stdout, and a piped count reads 0.
</content>
</entry>
<entry>
<title>fix(install): mask passim when fwupd is installed</title>
<updated>2026-09-13T12:02:39+00:00</updated>
<author>
<name>Craig Jennings</name>
<email>c@cjennings.net</email>
</author>
<published>2026-09-13T12:02:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/commit/?id=38b1758716f5e5086eac9e9cdc0f0adfba9e54e5'/>
<id>urn:sha1:38b1758716f5e5086eac9e9cdc0f0adfba9e54e5</id>
<content type='text'>
passim is fwupd's LAN metadata-sharing daemon and listens publicly on 0.0.0.0:27500. Any fwupdmgr run D-Bus-activates it. The unit is static, so disabling it is a no-op and it comes back on the next run. Masking is what holds. Every install gets it, not only laptops: the listener is public on any host, and ratio has run with it masked since July without fwupd missing it. Velox had only been disabled and got the mask on 2026-09-12.
</content>
</entry>
<entry>
<title>fix(install): stop enabling the WS-Discovery host daemon</title>
<updated>2026-09-13T12:02:39+00:00</updated>
<author>
<name>Craig Jennings</name>
<email>c@cjennings.net</email>
</author>
<published>2026-09-13T12:02:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/commit/?id=43acf51c4eb036c867df2fbeef99dcaef17a09a4'/>
<id>urn:sha1:43acf51c4eb036c867df2fbeef99dcaef17a09a4</id>
<content type='text'>
wsdd.service advertises this machine as a Samba host to Windows clients. Nothing the installer sets up runs Samba, so it advertised a share server that doesn't exist while listening on every interface, VPN and tailscale links included. Browsing Windows shares is the other direction: gvfs-wsdd spawns its own wsdd in discovery mode, so the package stays and only the service goes. A re-run on a machine set up before this disables the unit. A fresh install has no unit yet and skips quietly.
</content>
</entry>
<entry>
<title>feat(install): default DNS over TLS off on the Proton tunnel links</title>
<updated>2026-09-13T12:02:39+00:00</updated>
<author>
<name>Craig Jennings</name>
<email>c@cjennings.net</email>
</author>
<published>2026-09-13T12:02:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/commit/?id=2e303a07d1a6e4de85277a34669f8da61f7fdb6e'/>
<id>urn:sha1:2e303a07d1a6e4de85277a34669f8da61f7fdb6e</id>
<content type='text'>
The resolved drop-in pins DNSOverTLS=yes for every link. Proton VPN (proton0) and the static Proton WireGuard profiles (wgpvpn) push an in-tunnel resolver (10.2.0.1) that answers plain port 53 and never completes TLS on 853, so every lookup through the tunnel hung. The Proton client recreates its NetworkManager profile on each connect, so a per-profile setting can't stick.

NM pushes a [connection-tunnel-dot] default matched on those two interface names to resolved on every activation. Wifi and everything else keep the strict setting. Ratio and velox already carry the drop-in by hand. This makes a rebuild carry it too.
</content>
</entry>
</feed>
