The active station device is discovered rather than assumed from an interface name.
Rows retain iwd order and show connection state and signal strength.
Refresh races retain known managed rows rather than flashing an empty list.
Users can scan, connect, disconnect, forget, and toggle Wi-Fi.
Scan remains visibly active while asynchronous results settle.
An already-running scan is not shown as a hard failure.
Open and known networks connect directly.
A new secured network reveals an inline password field, submits once, and clears immediately.
Buttons visibly react to hover and press.
Bluetooth and connectivity
The existing native Bluetooth list and actions remain unchanged and refresh after asynchronous actions.
Supplemental connectivity status must not create another Wi-Fi row model or write path.
Security
SSIDs and passphrases are passed as discrete process arguments, never interpolated into shell commands.
A passphrase exists only for the transient connect call.
Passphrases never enter state, action history, errors, diagnostics, or logs.
Brief passphrase visibility in process arguments for a new secured network is the accepted single-user tradeoff.
Live Wi-Fi mutation is performed only by the controlling user, never by build or test workers.
Interface constraints
Existing connectivity and self-test IPC remains available.
State retains Wi-Fi enabled state, compact signal, exact network identity, and the minimal shader state required by its consumer.
Missing or malformed replies produce safe empty state rather than exceptions.
Acceptance
Sanitized fixtures cover managed objects, ordered networks, decoded names, known state, refresh races, signal shaping, malformed replies, and diagnostics.
Runtime self-test passes.
Live controller verification confirms scan, toggle, known or open connection, password handling, and unchanged Bluetooth behavior.
Fixture-based build verification performs no live mutation.
---
id: NL-SPEC-F1CFB1D7
type: spec
title: Connectivity popup
---
# Connectivity popup
## Wi-Fi behavior
- iwd is the single Wi-Fi read and write authority.
- The active station device is discovered rather than assumed from an interface name.
- Rows retain iwd order and show connection state and signal strength.
- Refresh races retain known managed rows rather than flashing an empty list.
- Users can scan, connect, disconnect, forget, and toggle Wi-Fi.
- Scan remains visibly active while asynchronous results settle.
- An already-running scan is not shown as a hard failure.
- Open and known networks connect directly.
- A new secured network reveals an inline password field, submits once, and clears immediately.
- Buttons visibly react to hover and press.
## Bluetooth and connectivity
- The existing native Bluetooth list and actions remain unchanged and refresh after asynchronous actions.
- Supplemental connectivity status must not create another Wi-Fi row model or write path.
## Security
- SSIDs and passphrases are passed as discrete process arguments, never interpolated into shell commands.
- A passphrase exists only for the transient connect call.
- Passphrases never enter state, action history, errors, diagnostics, or logs.
- Brief passphrase visibility in process arguments for a new secured network is the accepted single-user tradeoff.
- Live Wi-Fi mutation is performed only by the controlling user, never by build or test workers.
## Interface constraints
- Existing connectivity and self-test IPC remains available.
- State retains Wi-Fi enabled state, compact signal, exact network identity, and the minimal shader state required by its consumer.
- Missing or malformed replies produce safe empty state rather than exceptions.
## Acceptance
- Sanitized fixtures cover managed objects, ordered networks, decoded names, known state, refresh races, signal shaping, malformed replies, and diagnostics.
- Runtime self-test passes.
- Live controller verification confirms scan, toggle, known or open connection, password handling, and unchanged Bluetooth behavior.
- Fixture-based build verification performs no live mutation.