- The agent prompt's username field is user-editable. It was passed
straight to `auth::authenticate`, so a request scoped to specific
accounts (e.g. root only) could have its PAM conversation redirected
to any local user. `resolve_user` now accepts only the `unix-user`
identities from `BeginAuthentication` (empty = the prefilled default);
anything else re-shows the prompt with an explanation. PAM still has to
clear polkit's own authorization, but this closes the foot-gun at the
one place the identity list is known.
- A failed single-instance lock now exits(1) instead of continuing: a
second agent would `serve_at` the same object path, and a prompt held
by a process that couldn't take the lock is ambiguous state.
Toolchain drift (clippy 0.1.97): pre-existing on main, all mechanical
and behaviour-preserving.
- bread-theme/gtk.rs: `type AppCssBuilder` alias for the repeated
`Rc<dyn Fn(&Palette) -> String>` (type_complexity ×4).
- bread-theme/lib.rs: `sort_by_key(|..| Reverse(len))` (unnecessary_sort_by).
- bread-theme/output.rs: `io::Error::other`; struct-init in a test.
- bread-utils/singleton.rs: explicit `.truncate(false)` on the lock file
open — we only clear it after winning the lock (suspicious_open_options).
- bread-polkit/identity.rs: elide `pick_user` lifetimes.
Not added to registry/bread-ecosystem.toml: that would put it on the
bakery index (and risk the BOS ISO) without a lockfile update. bakery.toml
declares the binary and contrib desktop file; README/CONTRIBUTING note
that it stays unpublished.
Each Hyprland/GDK connector can have its own palette and stylesheet
under $XDG_RUNTIME_DIR/bread/{palettes,themes}/. GTK apps bind a
widget-level provider so two windows in one process can follow
different wallpapers. Bump workspace version to 0.7.4 for the tag.
bread-app is the GTK bootstrap new tools should use instead of another
copied main.rs: com.breadway.* app id, singleton lock, optional
gtk_popup re-export, optional bread.command.<app>.** listen loop.
Tests cover app-id helpers and command-verb parse. Existing apps are
not migrated.
bread-polkit is an own PolicyKit1 session authentication agent with a
bread-theme GTK4 password prompt (not a polkit-gnome wrapper).
Autostart via contrib/bread-polkit.desktop or exec-once. Not a bakery
product; not added to the BOS ISO lockfile.