Watch
1
0
Fork
You've already forked SouveraineOS
0
SouveraineOS/saf/surface/02-session-start.md
Fimeg bde961c6f2 saf: one spine — device, state, and work under the index
PAF becomes saf/device (history kept), STATE.md dissolves
into saf/state.md with the dated era archived, the substrate
SAF moves up from souveraine, and every agreement points at
saf/INDEX.md and nowhere else. one map, nothing to remember
2026-08-18 09:47:30 -04:00

102 lines
4.8 KiB
Markdown

# Session start
The graphical session is one dependency graph. A green system
`graphical.target` proves only that greetd may run; it does not prove that the
user authority or a drawing shell exists.
## The order
`souveraine-session-viewtop` is the session leader. It starts viewtop, waits
for the compositor's Wayland socket, and imports that socket and the Souveraine
desktop identity into the user systemd manager. Only then can the rest begin:
1. `souveraine-session-pre.target` pulls in systemd's
`graphical-session-pre.target`. `souveraine-sessiond` belongs here because
it needs Wayland in order to take ext-session-lock, and it must hold that
lock before a drawing surface appears.
2. The leader waits for `$XDG_RUNTIME_DIR/souveraine/sessiond.sock`. A
`Type=simple` service is considered started before it serves; the socket is
the readiness fact until sessiond becomes `Type=notify`.
3. `souveraine-session.target` pulls in `graphical-session.target`, which
starts `souveraine-shell.service` and the other surfaces that belong to the
session.
4. When viewtop exits, the leader stops the two Souveraine targets. Their
bindings let systemd stop everything whose lifetime is the graphical
session.
The two Souveraine targets are necessary because the stock graphical-session
targets carry `RefuseManualStart=yes`. A session leader cannot start those
stock units directly. It starts its own targets; their dependencies may pull
the stock targets into the transaction in the way systemd permits.
This graph raises [session authority](../authority/01-session.md); it does not
replace it. systemd owns process lifetime and dependency order. Sessiond owns
session policy once its socket is ready.
## The principal split still owed
This is the process-order graph that exists; it is not yet the final security
boundary. All of its units are currently user units and therefore inherit the
human graphical session's UID. The target moves sessiond's lock lifecycle to
the dedicated `souveraine-session` principal described in
[session authority](../authority/01-session.md), while the user manager keeps
only the presentation and application lifetimes that belong there.
The compositor must offer that principal a narrow way to hold
ext-session-lock and render the fallback without granting it Casey's home or
general session bus. The lock authority must be ready before the user home is
decrypted and remain ready after the Personal key is evicted. Changing unit
placement without proving the Wayland connection, PAM path, handoff, crash
retake, and key-eviction order would only move the black screen to a new UID.
## Package boundary
`souveraine-viewtop` owns the compositor and the session edge on both x86_64
and aarch64:
- `/usr/bin/viewtop`
- `/usr/bin/souveraine-session-viewtop`
- `/usr/lib/systemd/user/souveraine-session-pre.target`
- `/usr/lib/systemd/user/souveraine-session.target`
- `/usr/lib/systemd/user/souveraine-shell.service`
The package depends on `souveraine` for sessiond and on the virtual
`quickshell` package for `qs`. Both architecture artifacts carry and verify the
same start contract. Architecture changes the compositor binary, not the
meaning of a Souveraine session.
Versioned QML and face assets remain a separate surface-package boundary. The
session unit names what launches them; it must not own a mutable
`~/.config/quickshell` tree or turn a development compose into an installed
artifact.
## No shadow starts
A unit under `~/.config/systemd/user` or `/etc/systemd/user` outranks the
package copy under `/usr/lib/systemd/user`. Such a file may prove a repair, but
it is a splint: once the package carries the same unit, the higher-priority
copy must move out of systemd's search path. Otherwise pacman can update the
owned unit forever while the machine keeps booting the old answer.
The same distinction holds across delivery:
- source says what could ship;
- a green package job says what was built and signed;
- `pacman -Qo` and file identity say what is installed;
- a fresh session start says the dependency graph actually raised the glass.
Do not collapse those into "fixed."
## The failure this closes
On 2026-08-17 blueline reached system `graphical.target` with greetd and
viewtop alive, but user `souveraine-session.target`, sessiond, and QuickShell
were all dead. The installed r117 leader had directly requested the refused
stock targets. Viewtop failed closed with no lock surface and the panel was
black. Starting the Souveraine wrapper target recovered sessiond, loaded
QuickShell, transferred the lock surface, and showed the session without a
reboot.
That recovery proved the dependency shape. It did not become durable until the
leader, both targets, the shell unit, their runtime dependencies, and artifact
content checks travelled together through the signed package path.