Files
config/.claude/memory/journal.md
T

81 lines
6.5 KiB
Markdown

# Journal
3-5 lines/session. Caveman + English.
## 2026-05-27 — onboard (right-sized)
Onboarded dotfiles repo. Archetype dotfiles-meta HAUTE. 8 files, ~405 lines, graphify skipped.
Found + fixed install.sh: broken /tmp/config paths (server+osx silent fail), bashism under sh,
missing cp -r nerdtree, redundant molokai clone, unquoted vars, no set -eu. shellcheck CLEAN.
Created README, CLAUDE.md, .gitignore, .claude memory/tasks/audits. No secrets found.
Open: vimrc GenerateClassC bug (BLK-001), bashrc backtick style nits.
Then: install.sh arg dropped → uname OS-detect (Darwin→osx else linux). Deleted bashrc-server.
Added remote-install.sh curl|bash bootstrap (BDR-004). shellcheck CLEAN. Docs synced.
Committed in 4 atomic commits (chore claude / refactor install / feat remote-install / docs).
Slip: staged deletion swept into commit 1; fixed via soft-reset + restore --staged. Unpushed.
## 2026-06-23 — xrdp install fix
Added/fixed xrdp in install.sh. Found uncommitted block: `enable xrdb` typo (aborts set -e
installer, BLK-003) + `apt-get install xrdp` no -y. Built idempotent install_xrdp() — ssl-cert group
+ polkit .rules (verified polkit 127) + conditional ufw 3389 + enable/restart (LRN-003). Also fixed
adjacent: code-server@"$USER" quoting, broken .profile dtach block (invalid `[ ! grep ]` test +
heredoc unterminated indented EOF). shellcheck + bash -n CLEAN. Not run live / RDP untested.
## 2026-06-23 — RDP pivot xrdp → gnome-remote-desktop
xrdp abandoned (Wayland-only GNOME kills Xorg session). Replaced install_xrdp → setup_remote_desktop
(g-r-d system Remote Login): TLS cert + rdp enable + service. Live debug mstsc 0x904/0x7 = gate creds
empty (BLK-004); 2-layer auth gate→GDM PAM (LRN-004). Added ensure_rdp_credentials (prompt, TTY-guard,
idempotent). Connection CONFIRMED live. install.sh committed 0bd936b (bash -n + shellcheck CLEAN);
push blocked here (HTTPS remote, no creds in env) → user pushes. TPM GKeyFile-fallback warn harmless.
## 2026-06-24 — disk-usage login warning
Added etc/profile.d/disk-usage-warning.sh (POSIX sh, warns bold red when / or /home ≥85%).
install_disk_warning() in install.sh: sudo install -D -m 0644 → /etc/profile.d, gated in apt block
(Linux-only: df --output=pcent GNU-only + /etc/profile.d Debian convention). shellcheck + sh -n CLEAN,
both code paths runtime-verified. README + CLAUDE.md synced. Not committed (master, user to confirm).
## 2026-06-24 — dtach login wiring fix (source not execute) + cc/d aliases
Old ~/.profile block EXECUTED dtach-router + parsed "Aucune session dtach." → broken: executing breaks
the script's return-based interactive guard → falls through → fzf/`dt at >/dev/tty` errors `/dev/tty: No
such device` in every non-interactive login shell (repro'd live on each Bash init). Replaced with guarded
SOURCE `case $- in *i*) ... . dtach-router` via idempotent wire_dtach_profile() (awk strips legacy +
marker block, re-appends marker block). Added cc (create) / d (re-summon) aliases to bashrc-linux.
shellcheck + bash -n CLEAN; migration simulated on real .profile copy. LRN-006 + BDR-007. README synced.
Not committed; live ~/.profile not yet re-migrated.
## 2026-06-25 — dtach menu: ~/.profile → ~/.bashrc (VS Code non-login fix)
User: dtach resume menu never fires at session start, even post-install. Root cause: user runs VS Code
Remote-SSH → its Linux terminals are NON-login → skip ~/.profile (where BDR-007 wired it). Proven by process
tree (VSCODE_IPC_HOOK_CLI, no sshd/login-bash) + provably-correct ~/.profile wiring + existing session yet zero
menu. Fix: source dtach-router from bashrc-linux (every interactive shell); install.sh wire_dtach_profile() →
unwire_dtach_profile() strips stale ~/.profile block (avoids double-prompt on plain SSH). User chose simplest
(per-tab) over once-per-connection sentinel. shellcheck install.sh CLEAN, bash -n OK, strip proven idempotent
on .profile copy. BDR-009 (supersedes BDR-007) + LRN-008. Live needs ./install.sh re-run.
## 2026-09-22 — /tmp on disk + SSH OOM guard + cloudpex conf
User: swap for /tmp? keep RAM for ssh, old-server rules, cloudpex README+installer. Found /tmp = tmpfs 50% RAM
→ swap rejected, mask tmp.mount offer (BDR-010). Old rules in NAS RECOVERY/40-systeme: ssh drop-in + earlyoom →
end-of-install offers (BDR-011). cloudpex tracked; site values → /etc/cloudpex.conf prompted by installer
(BDR-012). shellcheck/bash -n CLEAN, stub harnesses (LRN-011; EVAL-002 open until live apply). Reconciled
main→develop (a210d01 dtach was main-only), feature finished via lib → develop 836bb67. Not applied live.
Flagged: secrets in NAS transfert/root (BLK-005), remote-install.sh BRANCH=master stale vs main, gitea-deploy/
untracked, remote feature branch left on origin (lib deletes local only).
Later same day: security baseline always-on in install.sh (fail2ban all-ports + RFC1918 ignore, unattended-
upgrades file, sshd limits drop-in sshd -t gated) on feature/security-baseline (BDR-013, LRN-012: old jail
banned 22 not 337). auditd + ufw declined. shellcheck/bash -n CLEAN, stub harness incl. sshd -t reject path,
configparser + apt-config checks. Branch pushed, NOT finished (no merge signal). Live apply = user runbook.
Update: user said merge → feature/security-baseline finished via lib, develop a6c416e pushed.
Cleanup: user asked all-in-develop + delete branches. Hooks refresh committed (a42e8f6). All 3 remote feature
branches verified merged; `git push --delete` DENIED by permission layer → user runs it. gitea-deploy/ (untracked
Gitea server deploy project, 31 files, no secrets) moved to ~/Documents/gitea-deploy, own repo via gitflow init,
pushed main+develop to git.bchanot.fr (push-to-create worked). deploy.conf gitignored.
## 2026-09-28
- feature/apt-packages (0bc9e3f, unmerged): install.sh mirrors machine apt set. Diff `apt-mark showmanual` +
apt history vs script → added gitleaks, web stack (mariadb-server imagemagick php-* unversioned),
ubuntu-desktop-minimal before RDP, install_nvidia_driver() (lspci 10de gate, `ubuntu-drivers install`, no pin).
User approved 3 choices (GNOME in, ubuntu-drivers, LAMP unconditional). shellcheck + bash -n + stub run OK.
- Blocked mid-commit: lib pre-commit ran `gitleaks git --staged`, Ubuntu apt gitleaks = 8.16 (no `git` subcmd,
exit 1 read as leak). Fixed in claude-config bugfix/gitleaks-protect-fallback (347073a, unmerged): probe
`gitleaks git --help`, fallback `protect --staged`; T16c symlink-farm PATH. make test 0. Hooks refreshed here (9e49b9d).
- Note: `gh` in install.sh list but not installed on this box (script not rerun since added).