diff --git a/.claude/tasks/TODO.md b/.claude/tasks/TODO.md index 6eb8913..0425793 100644 --- a/.claude/tasks/TODO.md +++ b/.claude/tasks/TODO.md @@ -25,3 +25,19 @@ - [ ] Runtime-test install.sh on a clean VM (all 4 targets) — not safe on dev machine - [ ] Consider an `uninstall.sh` (restore from ~/Oldconfig) - [x] LICENSE if repo ever goes public — done (GPL-3.0, BDR-008, 40c6524) + +## Feature — /tmp on disk + SSH OOM guard + cloudpex installer (2026-09-22) +Branch: feature/tmp-disk-ssh-oom-cloudpex (off develop). Design approved in chat (bounded). +Root cause: /tmp is tmpfs (50% RAM) → agents fill it → RAM halved + ENOSPC breaks shells. Swap rejected. +- [x] etc/tmpfiles.d/tmp.conf (D /tmp 10d + q /var/tmp 30d — keep both upstream lines) +- [x] etc/systemd/ssh.service.d/override.conf (MemoryMin=256M, OOMScoreAdjust=-1000 — old server) +- [x] etc/default/earlyoom (old server args: -r 60 -m 10 -s 10 --avoid sshd… --prefer node…) +- [x] install.sh: confirm() TTY-guarded prompt helper +- [x] install.sh: offer_tmp_on_disk() — mask tmp.mount + tmpfiles rule, reboot notice, idempotent +- [x] install.sh: offer_ssh_memory_guard() — drop-in + daemon-reload/restart ssh + earlyoom, idempotent +- [x] install.sh: install_cloudpex() in Linux block; offers at end of script (Linux-gated) +- [x] cloudpex/install.sh — /usr/local/bin/cloudpex root 0755, /mnt/cloudpex, cifs-utils if missing +- [x] cloudpex/README.md (FR) — purpose, why on-demand not fstab, usage, install +- [x] README.md steps 12-14 + table rows; CLAUDE.md layout +- [x] shellcheck + bash -n (install.sh, cloudpex/install.sh); stub-sudo dry run of the offers +- [x] commit on feature branch (no gitea-deploy/, no .githooks changes) diff --git a/CLAUDE.md b/CLAUDE.md index ed55dd8..2975c04 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -23,9 +23,16 @@ vim/colors/ molokai colorscheme (committed) bash/bashrc-{linux,osx} OS-detected bashrc bin/{dt,dtach-router,claude-provider} CLI scripts deployed to ~/.local/bin etc/profile.d/disk-usage-warning.sh login-time low-disk warning → /etc/profile.d (Linux only) +etc/tmpfiles.d/tmp.conf disk-backed /tmp cleanup rules (offer: /tmp on disk) +etc/systemd/ssh.service.d/override.conf sshd OOM-exempt drop-in (offer: SSH memory guard) +etc/default/earlyoom earlyoom args, spare sshd / kill node first (same offer) +cloudpex/{cloudpex,install.sh,README.md} on-demand CloudPex SMB mount helper → /usr/local/bin (FR docs) .claude/{tasks,memory,audits}/ Claude working state ``` +`/tmp` is a RAM-backed tmpfs on Ubuntu (50% of RAM): agent runs fill it, which is why +install.sh offers to mask `tmp.mount`. Swap is not the fix (the cap and ENOSPC stay). + `pymupdf`/`markdown_py` are NOT tracked — they are pipx entry-point shims, recreated by `pipx install PyMuPDF Markdown` in install.sh. `claude-provider` reads `$OPENROUTER_API_KEY` from the env — never hardcode it (the @@ -35,8 +42,8 @@ original had a live key; it was scrubbed — see decisions/blockers). | Task | Command | | ----- | ---------------------------------------- | -| Lint | `shellcheck *.sh bash/bashrc-*` | -| Syntax check | `bash -n install.sh remote-install.sh` | +| Lint | `shellcheck *.sh cloudpex/install.sh cloudpex/cloudpex bash/bashrc-*` | +| Syntax check | `bash -n install.sh remote-install.sh cloudpex/install.sh` | | Install | `./install.sh` (OS auto-detected) | | Remote install | `curl -fsSL /remote-install.sh \| bash` | diff --git a/README.md b/README.md index e0a7882..08f2eee 100644 --- a/README.md +++ b/README.md @@ -16,7 +16,11 @@ curl -fsSL https://git.bchanot.fr/bchanot/config/raw/branch/master/remote-instal | Path | Purpose | | -------------------- | -------------------------------------------------------------- | -| `install.sh` | Installs apt packages + Docker + code-server + RDP (gnome-remote-desktop), backs up old config, deploys vim + bashrc (OS-detected), installs CLI scripts, pipx tools, and a low-disk login warning. | +| `install.sh` | Installs apt packages + Docker + code-server + RDP (gnome-remote-desktop), backs up old config, deploys vim + bashrc (OS-detected), installs CLI scripts, pipx tools, a low-disk login warning and the `cloudpex` NAS mount helper; ends by offering two system changes (`/tmp` on disk, SSH memory guard). | +| `cloudpex/` | On-demand SMB mount of the CloudPex NAS share (`cloudpex` command + its installer). French README inside. | +| `etc/tmpfiles.d/tmp.conf` | Cleanup rules for a disk-backed `/tmp` (wiped at boot, 10-day purge). Deployed by the `/tmp` on disk offer. | +| `etc/systemd/ssh.service.d/override.conf` | `ssh.service` drop-in: sshd exempt from the OOM killer + memory reclaim protection. Deployed by the SSH memory guard offer. | +| `etc/default/earlyoom` | earlyoom arguments: spare sshd/systemd, kill node/java first. Deployed by the SSH memory guard offer. | | `vim/vimrc` | Vim config: pathogen, molokai, syntastic (C with `-Wall -Werror -Wextra`), NERDTree, 42-style canonical class generators (`:ClassH`, `:ClassC`). | | `vim/autoload/` | `pathogen.vim` plugin loader (committed). | | `vim/colors/` | `molokai.vim` colorscheme (committed). | @@ -61,6 +65,9 @@ What it does: 9. On Linux, installs `etc/profile.d/disk-usage-warning.sh` to `/etc/profile.d/` (needs `sudo`) so each login warns when `/` or `/home` cross 85% usage. 10. On Linux, installs **code-server** (VS Code in the browser) via its vendor script — skipped if already present — and enables the `code-server@$USER` systemd service. 11. On Linux, sets up **RDP remote login** via `gnome-remote-desktop` (Wayland-native): installs the daemon + `openssl`, generates a self-signed TLS cert once, and prompts interactively for shared "gate" credentials (skipped when no terminal is attached, or already set). Disables `xrdp` if present; opens UFW port `3389` only when UFW is already active. +12. On Linux, installs the **`cloudpex`** NAS mount helper to `/usr/local/bin` via `cloudpex/install.sh` (nothing is mounted, no credential stored, see [`cloudpex/README.md`](cloudpex/README.md)). +13. On Linux, at the very end, **offers** (`[y/N]`, skipped when no terminal is attached) to move **`/tmp` to disk**: Ubuntu mounts `/tmp` as a RAM-backed tmpfs capped at 50% of RAM, which agent runs fill, halving the RAM and breaking every shell with "No space left on device". Accepting masks `tmp.mount` and installs `etc/tmpfiles.d/tmp.conf` (wipe at boot, 10-day purge). Effective at the next reboot. +14. On Linux, at the very end, **offers** to keep **SSH reachable under memory pressure**: installs the `ssh.service` drop-in (`OOMScoreAdjust=-1000`, `MemoryMin=256M`) and `earlyoom` with `etc/default/earlyoom` (kills the largest process, `node`/`java` first and never `sshd`, once free RAM and swap both drop under 10%). Restarting `ssh` keeps open sessions. Note: `MemoryMin` protects the sshd daemon only; login sessions live in `user.slice`, so no setting can reserve RAM for a future shell. earlyoom acting in time is the real protection. ### Packages installed (apt) @@ -72,6 +79,7 @@ What it does: - **Docker**: `docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin` (via Docker's repo) - **Remote access**: `gnome-remote-desktop openssl` (apt) + `code-server` (via its vendor install script, not apt) — RDP remote login + browser VS Code - **pipx**: `PyMuPDF` (`pymupdf`), `Markdown` (`markdown_py`) +- **Optional (end-of-install offer, Linux)**: `earlyoom` The script is re-runnable: each run re-backs up to `~/Oldconfig` (overwriting the previous backup), re-clones plugins, skips Docker if already installed, and re-deploys the `bin/` scripts. diff --git a/etc/default/earlyoom b/etc/default/earlyoom new file mode 100644 index 0000000..052dded --- /dev/null +++ b/etc/default/earlyoom @@ -0,0 +1,8 @@ +# earlyoom settings, sourced by earlyoom.service (rules of the previous server). +# -r 60 memory report in the journal every minute +# -m 10 act when available RAM drops under 10% ... +# -s 10 ... and free swap under 10% (both conditions) +# --avoid never kill sshd, systemd, logind, dbus, containerd +# --prefer kill the agent runtimes first: java, node, pnpm, esbuild +# Quotes inside the value are honoured by systemd's $VAR word splitting. +EARLYOOM_ARGS="-r 60 -m 10 -s 10 --avoid '^(sshd|systemd|systemd-logind|dbus-daemon|containerd)$' --prefer '^(java|node|pnpm|esbuild)$'" diff --git a/etc/systemd/ssh.service.d/override.conf b/etc/systemd/ssh.service.d/override.conf new file mode 100644 index 0000000..21f8c0d --- /dev/null +++ b/etc/systemd/ssh.service.d/override.conf @@ -0,0 +1,8 @@ +# ssh.service drop-in: keep sshd alive when RAM runs out (rules of the previous server). +# OOMScoreAdjust=-1000 the kernel OOM killer never selects sshd. +# MemoryMin=256M reclaim protection for the daemon's own cgroup. Login sessions +# live in user.slice (logind), so this cannot reserve RAM for an +# interactive shell — earlyoom is what frees memory in time. +[Service] +MemoryMin=256M +OOMScoreAdjust=-1000 diff --git a/etc/tmpfiles.d/tmp.conf b/etc/tmpfiles.d/tmp.conf new file mode 100644 index 0000000..59fa9f6 --- /dev/null +++ b/etc/tmpfiles.d/tmp.conf @@ -0,0 +1,5 @@ +# /tmp on disk (install.sh masks tmp.mount): keep the tmpfs semantics — wipe /tmp +# at boot (D) and purge entries untouched for 10 days. Same file name as +# /usr/lib/tmpfiles.d/tmp.conf, so this REPLACES it: the /var/tmp rule must stay. +D /tmp 1777 root root 10d +q /var/tmp 1777 root root 30d diff --git a/install.sh b/install.sh index d0ebe21..114047d 100755 --- a/install.sh +++ b/install.sh @@ -133,6 +133,87 @@ unwire_dtach_profile() { ' "$profile" > "$profile.tmp" && mv "$profile.tmp" "$profile" } +# NAS helper: deploys the on-demand CloudPex SMB mount command to /usr/local/bin +# (see cloudpex/README.md). Nothing is mounted and no credential is stored. +# Linux-only (cifs-utils); the helper's own installer is idempotent. +install_cloudpex() { + echo "Installing the cloudpex mount helper" + bash "$SCRIPT_DIR/cloudpex/install.sh" +} + +# Yes/no prompt for the optional system changes offered at the end of the install. +# Declines (returns 1) when no terminal is attached (curl | bash), so an offer is +# skipped with a hint instead of blocking; re-run ./install.sh from a terminal to +# get it offered again. +confirm() { + local answer="" + if [ ! -t 0 ]; then + echo "Skipped (no terminal attached): $1" >&2 + return 1 + fi + read -rp "$1 [y/N] " answer || true + case "$answer" in + [yY]|[yY][eE][sS]) return 0 ;; + *) return 1 ;; + esac +} + +# /tmp on disk instead of the tmpfs Ubuntu mounts by default (RAM-backed, capped at +# 50% of RAM). Agent runs fill it: that eats half the RAM and, once the cap is hit, +# every temp-file creation fails with ENOSPC — which is what breaks shells. Masking +# tmp.mount leaves /tmp on the root filesystem; the tmpfiles rule keeps the tmpfs +# semantics (wiped at boot, entries older than 10 days purged). Takes effect at the +# next reboot: a busy /tmp is never unmounted live. Idempotent. +offer_tmp_on_disk() { + if [ "$(systemctl is-enabled tmp.mount 2>/dev/null)" = "masked" ]; then + echo "/tmp already on disk (tmp.mount masked) — skipping" + return 0 + fi + if [ "$(findmnt -n -o FSTYPE -T /tmp)" != "tmpfs" ]; then + echo "/tmp is not a tmpfs — nothing to do" + return 0 + fi + confirm "Move /tmp from RAM (tmpfs) to disk? Agents fill it and break shells" || return 0 + sudo systemctl mask tmp.mount + sudo install -D -m 0644 "$SCRIPT_DIR/etc/tmpfiles.d/tmp.conf" /etc/tmpfiles.d/tmp.conf + echo "/tmp moves to disk at the next reboot." +} + +# Keep SSH reachable when RAM runs out — the two rules the previous server ran: +# - ssh.service drop-in: OOMScoreAdjust=-1000 (the kernel OOM killer never picks +# sshd) + MemoryMin=256M (reclaim protection for the daemon's cgroup); +# - earlyoom: kills the single largest process (node preferred, sshd/systemd spared) +# once free RAM and free swap both drop under 10%, before the box thrashes. +# MemoryMin covers sshd only: logind puts login sessions in user.slice, so nothing can +# reserve RAM for a future shell — earlyoom acting in time is the real protection. +# Idempotent: each piece is skipped when already in place. Restarting ssh keeps the +# current sessions alive (KillMode=process). +offer_ssh_memory_guard() { + local dropin="/etc/systemd/system/ssh.service.d/override.conf" + local ssh_done=0 oom_done=0 + cmp -s "$SCRIPT_DIR/etc/systemd/ssh.service.d/override.conf" "$dropin" && ssh_done=1 + if cmp -s "$SCRIPT_DIR/etc/default/earlyoom" /etc/default/earlyoom \ + && [ "$(systemctl is-enabled earlyoom 2>/dev/null)" = "enabled" ]; then + oom_done=1 + fi + if [ "$ssh_done" = 1 ] && [ "$oom_done" = 1 ]; then + echo "SSH memory guard already in place — skipping" + return 0 + fi + confirm "Protect SSH under memory pressure (sshd OOM-exempt + earlyoom)?" || return 0 + if [ "$ssh_done" = 0 ]; then + sudo install -D -m 0644 "$SCRIPT_DIR/etc/systemd/ssh.service.d/override.conf" "$dropin" + sudo systemctl daemon-reload + sudo systemctl restart ssh + fi + if [ "$oom_done" = 0 ]; then + sudo apt-get install -y earlyoom + sudo install -m 0644 "$SCRIPT_DIR/etc/default/earlyoom" /etc/default/earlyoom + sudo systemctl enable earlyoom + sudo systemctl restart earlyoom + fi +} + # System packages: Debian/Ubuntu only. Skipped where apt-get is absent (e.g. macOS). if command -v apt-get >/dev/null 2>&1; then sudo apt-get update @@ -161,6 +242,9 @@ if command -v apt-get >/dev/null 2>&1; then # Low-disk login warning (system-wide profile.d snippet). install_disk_warning + + # On-demand NAS mount helper (cloudpex/). + install_cloudpex else echo "apt-get not found — skipping system packages (install vim/git manually)." fi @@ -219,6 +303,13 @@ chmod +x "$HOME"/.local/bin/dt "$HOME"/.local/bin/dtach-router "$HOME"/.local/bi # Remove any stale dtach wiring from ~/.profile (the menu now ships in ~/.bashrc; see above). unwire_dtach_profile +# Optional system changes, offered last so the base install is complete even when +# declined. Linux/systemd only. Each prompts [y/N] on a terminal, is skipped otherwise. +if command -v apt-get >/dev/null 2>&1; then + offer_tmp_on_disk + offer_ssh_memory_guard +fi + echo "Done. Restart your shell or run: source ~/.bashrc" echo "If you use zsh, switch to bash to enjoy these settings =)" echo "Note: the deployed bashrc puts ~/.local/bin on PATH — re-login or run: source ~/.bashrc"