chore(memory): BDR-014 apt mirror choices, LRN-013 gitleaks version probe
This commit is contained in:
@@ -108,3 +108,11 @@ never banned); 5/10m/1h from RECOVERY doc 01. (2) `20auto-upgrades` file instead
|
||||
install continues. Declined by user: auditd rules, ufw whitelist (site-specific ports, lockout risk → would be an
|
||||
offer, not systematic). Not included by design: PasswordAuthentication no / AllowUsers / X11Forwarding no
|
||||
(lockout or workflow risk). Status: done in repo (feature/security-baseline), live apply = user.
|
||||
|
||||
## BDR-014 — install.sh mirrors machine apt set: GNOME + LAMP unconditional, NVIDIA via ubuntu-drivers
|
||||
2026-09-28. Source: `apt-mark showmanual` + /var/log/apt/history.log diffed vs script. Added gitleaks, web stack
|
||||
(mariadb-server imagemagick php-* unversioned → follows distro PHP), ubuntu-desktop-minimal before RDP setup
|
||||
(gnome-remote-desktop needs GDM, bare server had none), `install_nvidia_driver()` = `lspci -d 10de:` gate +
|
||||
`ubuntu-drivers install` (distro-recommended, 595-open today). Alternatives rejected: pin nvidia-driver-595-open
|
||||
(ages, hardware-bound), LAMP behind confirm() offer (user: base list), GNOME left implicit (RDP fails silently).
|
||||
Status: merged to develop. Live rerun of install.sh = user.
|
||||
|
||||
@@ -93,3 +93,11 @@ templating, drifts if port changes) or `banaction = %(banaction_allports)s` (off
|
||||
irrelevant) — chose allports. Offline checks without fail2ban installed: python `configparser` with
|
||||
BasicInterpolation resolves `%(x)s` refs and proves the file parses; apt.conf → `apt-config
|
||||
--config-file=<f> dump APT::Periodic`. sshd drop-ins can't be `sshd -t`-tested without root (host keys).
|
||||
|
||||
## LRN-013 — distro package lags upstream: probe subcommand before calling it
|
||||
2026-09-28. Ubuntu apt gitleaks = 8.16; lib pre-commit hook written for >= 8.19 (`gitleaks git --staged`).
|
||||
"unknown command" exit 1 read as a leak → every commit blocked, silently (stderr swallowed). Script calling a
|
||||
subcommand born in version N must probe `tool sub --help` and fall back (`protect --staged`). Test faking
|
||||
"binary absent" via shorter PATH (`/usr/bin:/bin`) breaks once the binary lives in /usr/bin: symlink farm of
|
||||
/usr/bin minus the binary instead. Apply: any tool install.sh pulls from apt while ~/.claude scripts assume
|
||||
the upstream release. Fix: claude-config bugfix/gitleaks-protect-fallback.
|
||||
|
||||
Reference in New Issue
Block a user