chore(memory): BDR-014 apt mirror choices, LRN-013 gitleaks version probe
This commit is contained in:
@@ -108,3 +108,11 @@ never banned); 5/10m/1h from RECOVERY doc 01. (2) `20auto-upgrades` file instead
|
|||||||
install continues. Declined by user: auditd rules, ufw whitelist (site-specific ports, lockout risk → would be an
|
install continues. Declined by user: auditd rules, ufw whitelist (site-specific ports, lockout risk → would be an
|
||||||
offer, not systematic). Not included by design: PasswordAuthentication no / AllowUsers / X11Forwarding no
|
offer, not systematic). Not included by design: PasswordAuthentication no / AllowUsers / X11Forwarding no
|
||||||
(lockout or workflow risk). Status: done in repo (feature/security-baseline), live apply = user.
|
(lockout or workflow risk). Status: done in repo (feature/security-baseline), live apply = user.
|
||||||
|
|
||||||
|
## BDR-014 — install.sh mirrors machine apt set: GNOME + LAMP unconditional, NVIDIA via ubuntu-drivers
|
||||||
|
2026-09-28. Source: `apt-mark showmanual` + /var/log/apt/history.log diffed vs script. Added gitleaks, web stack
|
||||||
|
(mariadb-server imagemagick php-* unversioned → follows distro PHP), ubuntu-desktop-minimal before RDP setup
|
||||||
|
(gnome-remote-desktop needs GDM, bare server had none), `install_nvidia_driver()` = `lspci -d 10de:` gate +
|
||||||
|
`ubuntu-drivers install` (distro-recommended, 595-open today). Alternatives rejected: pin nvidia-driver-595-open
|
||||||
|
(ages, hardware-bound), LAMP behind confirm() offer (user: base list), GNOME left implicit (RDP fails silently).
|
||||||
|
Status: merged to develop. Live rerun of install.sh = user.
|
||||||
|
|||||||
@@ -93,3 +93,11 @@ templating, drifts if port changes) or `banaction = %(banaction_allports)s` (off
|
|||||||
irrelevant) — chose allports. Offline checks without fail2ban installed: python `configparser` with
|
irrelevant) — chose allports. Offline checks without fail2ban installed: python `configparser` with
|
||||||
BasicInterpolation resolves `%(x)s` refs and proves the file parses; apt.conf → `apt-config
|
BasicInterpolation resolves `%(x)s` refs and proves the file parses; apt.conf → `apt-config
|
||||||
--config-file=<f> dump APT::Periodic`. sshd drop-ins can't be `sshd -t`-tested without root (host keys).
|
--config-file=<f> dump APT::Periodic`. sshd drop-ins can't be `sshd -t`-tested without root (host keys).
|
||||||
|
|
||||||
|
## LRN-013 — distro package lags upstream: probe subcommand before calling it
|
||||||
|
2026-09-28. Ubuntu apt gitleaks = 8.16; lib pre-commit hook written for >= 8.19 (`gitleaks git --staged`).
|
||||||
|
"unknown command" exit 1 read as a leak → every commit blocked, silently (stderr swallowed). Script calling a
|
||||||
|
subcommand born in version N must probe `tool sub --help` and fall back (`protect --staged`). Test faking
|
||||||
|
"binary absent" via shorter PATH (`/usr/bin:/bin`) breaks once the binary lives in /usr/bin: symlink farm of
|
||||||
|
/usr/bin minus the binary instead. Apply: any tool install.sh pulls from apt while ~/.claude scripts assume
|
||||||
|
the upstream release. Fix: claude-config bugfix/gitleaks-protect-fallback.
|
||||||
|
|||||||
Reference in New Issue
Block a user