<feed xmlns='http://www.w3.org/2005/Atom'>
<title>archsetup/docs/design/2026-08-07-podman-socket-and-camera-udev.md, branch main</title>
<subtitle>Builds a full dev workstation from a bare Arch Linux install.
</subtitle>
<id>https://git.cjennings.net/archsetup/atom?h=main</id>
<link rel='self' href='https://git.cjennings.net/archsetup/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/'/>
<updated>2026-08-09T16:47:36+00:00</updated>
<entry>
<title>feat: enable the podman API socket and ship the camera udev grant</title>
<updated>2026-08-09T16:47:36+00:00</updated>
<author>
<name>Craig Jennings</name>
<email>c@cjennings.net</email>
</author>
<published>2026-08-09T16:20:43+00:00</published>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/commit/?id=169dab71a063f4fab6c46f95e11d6e85b140cb8f'/>
<id>urn:sha1:169dab71a063f4fab6c46f95e11d6e85b140cb8f</id>
<content type='text'>
Two one-time machine setups from the winvm handoffs now happen at install time.

- The devops podman block enables the rootless podman API socket. Socket-activated, so it costs nothing idle, and API clients like Pods fail with an empty window without it. enable_user_service grew an optional wants-target argument because a socket unit's [Install] is WantedBy=sockets.target. The old default.target link would never socket-activate.
- install_camera_passthrough_rules ships 72-usb-passthrough-cameras.rules: GROUP="video", MODE="0660" plus the uaccess tag on the OBSBOT and BRIO USB IDs, so usbredirect can claim them for VM passthrough. The filename is load-bearing: logind's ACL is applied by 73-seat-late.rules, so the tag only works from a file sorting below 73. A test pins that property.

Both are live on ratio (the old 99- rules file is retired there). Whether uaccess alone would suffice from the corrected position is untested and stays documented as a hypothesis.
</content>
</entry>
<entry>
<title>docs: add the post-install checklist and podman/camera-udev notes</title>
<updated>2026-08-09T16:47:36+00:00</updated>
<author>
<name>Craig Jennings</name>
<email>c@cjennings.net</email>
</author>
<published>2026-08-08T09:55:52+00:00</published>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/commit/?id=f88dfa7620a289f1aff63e446ebdd31853ac3d51'/>
<id>urn:sha1:f88dfa7620a289f1aff63e446ebdd31853ac3d51</id>
<content type='text'>
The checklist is the standing home for manual post-first-boot steps: bluetooth pairing and the Proton Bridge login start it. The podman-socket and camera-udev notes carry the evidence for the filed install-time task, including why uaccess alone can't grant a raw USB node.
</content>
</entry>
</feed>
