The redesign branch was cut before "Harden privileged command operands
against injection" landed on main; the rebase conflicts in users.rs,
power.rs, firewall.rs and capabilities/default.json were resolved to
keep the stricter side of each:
- users.rs: keep `chpasswd_input` / `valid_chpasswd_password` (validates
the *password* for `:` / newline, which the redesign's inline checks
missed) and `may_delete_user` (refuses root / the current user);
fold in the redesign's `--` argv separators and GECOS control-char
stripping on top.
- power.rs: keep `charge_threshold_write` (validates `which` ∈
{start,end} and clamps) + `util::run_with_stdin` for the tee pipe,
plus its test; take the redesign's brightness clamp.
- firewall.rs: keep the port-only `valid_firewall_rule` /
`valid_rule_number` allowlist from
|
||
|---|---|---|
| .forgejo/workflows | ||
| frontend | ||
| packaging | ||
| src | ||
| .gitignore | ||
| AGENTS.md | ||
| bakery.toml | ||
| CONTRIBUTING.md | ||
| LICENSE | ||
| README.md | ||
bos-settings
System settings app for BOS (Bread Operating System) — Tauri 2 + Svelte 5. Configures every bread* app's config plus core system settings (network, sound, power, users, firewall, snapshots, packages, AUR, firmware, Hyprland display/appearance/autostart) non-destructively.
Distributed via bakery. There is one long-lived branch, main; see CONTRIBUTING.md for the single-trunk / RC-tag release model shared across the bread ecosystem.
Building
The Svelte frontend lives in frontend/, the Rust backend in src/ (this repo's crate is not named src-tauri). cargo tauri build runs the frontend build hook; a plain cargo build does not.
cd frontend && npm ci && npm run build
cd ../src && cargo build --release
Dev (Vite + cargo tauri dev):
cd src && cargo tauri dev
Packaging / releasing
Bump src/Cargo.toml (and frontend/package.json) version, then follow CONTRIBUTING.md: work lands on main via feature/ / fix/ branches (every push to main publishes a bakery dev build). Tag vX.Y.Z-rc.N for beta, vX.Y.Z for the signed stable release. Do not push to a dev branch — there isn't one.