From ba1817a4e91fb7fffeab388cfbb22e93dd258f14 Mon Sep 17 00:00:00 2001 From: bastien Date: Mon, 28 Sep 2026 21:57:03 +0200 Subject: [PATCH] chore(memory): BDR-014 apt mirror choices, LRN-013 gitleaks version probe --- .claude/memory/decisions.md | 8 ++++++++ .claude/memory/learnings.md | 8 ++++++++ 2 files changed, 16 insertions(+) diff --git a/.claude/memory/decisions.md b/.claude/memory/decisions.md index 9473228..b70681b 100644 --- a/.claude/memory/decisions.md +++ b/.claude/memory/decisions.md @@ -108,3 +108,11 @@ never banned); 5/10m/1h from RECOVERY doc 01. (2) `20auto-upgrades` file instead install continues. Declined by user: auditd rules, ufw whitelist (site-specific ports, lockout risk → would be an offer, not systematic). Not included by design: PasswordAuthentication no / AllowUsers / X11Forwarding no (lockout or workflow risk). Status: done in repo (feature/security-baseline), live apply = user. + +## BDR-014 — install.sh mirrors machine apt set: GNOME + LAMP unconditional, NVIDIA via ubuntu-drivers +2026-09-28. Source: `apt-mark showmanual` + /var/log/apt/history.log diffed vs script. Added gitleaks, web stack +(mariadb-server imagemagick php-* unversioned → follows distro PHP), ubuntu-desktop-minimal before RDP setup +(gnome-remote-desktop needs GDM, bare server had none), `install_nvidia_driver()` = `lspci -d 10de:` gate + +`ubuntu-drivers install` (distro-recommended, 595-open today). Alternatives rejected: pin nvidia-driver-595-open +(ages, hardware-bound), LAMP behind confirm() offer (user: base list), GNOME left implicit (RDP fails silently). +Status: merged to develop. Live rerun of install.sh = user. diff --git a/.claude/memory/learnings.md b/.claude/memory/learnings.md index 6f5d05e..70d5ca5 100644 --- a/.claude/memory/learnings.md +++ b/.claude/memory/learnings.md @@ -93,3 +93,11 @@ templating, drifts if port changes) or `banaction = %(banaction_allports)s` (off irrelevant) — chose allports. Offline checks without fail2ban installed: python `configparser` with BasicInterpolation resolves `%(x)s` refs and proves the file parses; apt.conf → `apt-config --config-file= dump APT::Periodic`. sshd drop-ins can't be `sshd -t`-tested without root (host keys). + +## LRN-013 — distro package lags upstream: probe subcommand before calling it +2026-09-28. Ubuntu apt gitleaks = 8.16; lib pre-commit hook written for >= 8.19 (`gitleaks git --staged`). +"unknown command" exit 1 read as a leak → every commit blocked, silently (stderr swallowed). Script calling a +subcommand born in version N must probe `tool sub --help` and fall back (`protect --staged`). Test faking +"binary absent" via shorter PATH (`/usr/bin:/bin`) breaks once the binary lives in /usr/bin: symlink farm of +/usr/bin minus the binary instead. Apply: any tool install.sh pulls from apt while ~/.claude scripts assume +the upstream release. Fix: claude-config bugfix/gitleaks-protect-fallback.