Files
config/.claude/tasks/TODO.md
T
bchanot f42e28807b feat(repo-sync): one local tree for every repo reachable on your forges
bin/repo-sync ports the Alphalink dotfiles repo/repo-reset zsh functions to
bash + zsh on Linux and macOS, for several forges at once: GitLab, GitHub
(+GHES), Gitea/Forgejo, Bitbucket Cloud, via curl + jq (no per-forge CLI).
Tokens live in ~/.config/repos/forges.conf (0600, parsed line by line, never
tracked), written by `repo-sync add`. Cache ~/.cache/repos/list refreshed
at most once a day (mkdir lock: flock is not on macOS), same namespace/project
on two forges kept once, archived and mirrors skipped. Layout
~/repos/<namespace with / as @>/<project>.

rc files: `repo <project> [namespace]` clones on demand and cd's, with
completion (bash compgen, zsh _describe), background refresh at shell start.
install.sh: jq in the apt and brew lists, chmod repo-sync.

Verified: shellcheck + bash -n, zsh -n; stub-curl harness over the four forges
(pagination, dedup, auth headers, lock, stale cache, path/clone); live GitLab
refresh (139 projects, 3s).
2026-10-07 15:31:03 +02:00

138 lines
10 KiB
Markdown

# TODO — onboard backlog (2026-05-27)
<!-- Generated by /onboard (right-sized). One entry per finding. -->
## Done this session
- [x] [P0] Fix install.sh broken /tmp/config paths (server+osx silent fail)
- [x] [P0] Fix bashism under #!/bin/sh → bash + set -euo pipefail
- [x] [P1] Fix nerdtree copy (cp -r / direct clone into bundle)
- [x] [P1] Guard apt-get behind command -v (osx no longer fails)
- [x] [P2] Drop redundant molokai clone
- [x] [P2] Create README.md, CLAUDE.md, .gitignore
- [x] [P2] Create .claude/memory + tasks + audits
## P2 — Moyenne
- [ ] [P2] [/hotfix] — vim/vimrc GenerateClassC: bare `name` → `a:name` (fixes :ClassC E121)
Files: vim/vimrc (GenerateClassC, ~line 80-104)
Source: .claude/memory/blockers.md BLK-001
## P3 — Basse
- [ ] [P3] [/code-clean] — bashrc-* legacy backticks → $(...) (SC2006), arithmetic SC2004
Files: bash/bashrc-linux, bash/bashrc-osx
Note: cosmetic only, no behavior change
## Post-MVP (optional, backlog)
- [ ] Runtime-test install.sh on a clean VM (all 4 targets) — not safe on dev machine
- [ ] Consider an `uninstall.sh` (restore from ~/Oldconfig)
- [x] LICENSE if repo ever goes public — done (GPL-3.0, BDR-008, 40c6524)
## Feature — /tmp on disk + SSH OOM guard + cloudpex installer (2026-09-22)
Branch: feature/tmp-disk-ssh-oom-cloudpex (off develop). Design approved in chat (bounded).
Root cause: /tmp is tmpfs (50% RAM) → agents fill it → RAM halved + ENOSPC breaks shells. Swap rejected.
- [x] etc/tmpfiles.d/tmp.conf (D /tmp 10d + q /var/tmp 30d — keep both upstream lines)
- [x] etc/systemd/ssh.service.d/override.conf (MemoryMin=256M, OOMScoreAdjust=-1000 — old server)
- [x] etc/default/earlyoom (old server args: -r 60 -m 10 -s 10 --avoid sshd… --prefer node…)
- [x] install.sh: confirm() TTY-guarded prompt helper
- [x] install.sh: offer_tmp_on_disk() — mask tmp.mount + tmpfiles rule, reboot notice, idempotent
- [x] install.sh: offer_ssh_memory_guard() — drop-in + daemon-reload/restart ssh + earlyoom, idempotent
- [x] install.sh: install_cloudpex() in Linux block; offers at end of script (Linux-gated)
- [x] cloudpex/install.sh — /usr/local/bin/cloudpex root 0755, /mnt/cloudpex, cifs-utils if missing
- [x] cloudpex/README.md (FR) — purpose, why on-demand not fstab, usage, install
- [x] README.md steps 12-14 + table rows; CLAUDE.md layout
- [x] shellcheck + bash -n (install.sh, cloudpex/install.sh); stub-sudo dry run of the offers
- [x] commit on feature branch (no gitea-deploy/, no .githooks changes)
## Round 2 — cloudpex config out of script, reconcile main/develop, capitalize, merge (2026-09-22)
- [x] cloudpex/cloudpex: constants → /etc/cloudpex.conf parsed line by line (never sourced), die if missing
- [x] cloudpex/install.sh: prompt host/share/user/mnt/vers (regex-validated), keep-existing [Y/n], no-TTY skip
- [x] cloudpex/README.md + README.md + CLAUDE.md: no site values, describe prompts + conf file
- [x] registries: BDR-010/011/012, LRN-009/010/011, BLK-005/006, EVAL-002, journal
- [x] reconcile: merge main (a210d01 dtach) into develop via lib helper
- [x] gitflow finish feature → develop (explicit user signal: "puis merge")
- [x] runbook for live apply on this machine
## Feature — security baseline in install.sh (2026-09-22)
Branch: feature/security-baseline (off develop). Scope approved: fail2ban, unattended-upgrades, sshd hardening. auditd + ufw declined.
- [x] etc/fail2ban/jail.d/local.conf — sshd jail, backend systemd, allports ban, RFC1918 ignoreip
- [x] etc/apt/apt.conf.d/20auto-upgrades — Periodic Update-Package-Lists + Unattended-Upgrade = 1
- [x] etc/ssh/sshd_config.d/20-hardening.conf — PermitRootLogin no, MaxAuthTries 3, LoginGraceTime 20
- [x] install.sh: install_fail2ban / install_unattended_upgrades / harden_sshd (sshd -t gated), called in Linux block
- [x] README.md (table, step 13, packages) + CLAUDE.md layout
- [x] shellcheck + bash -n; stub harness harden_sshd (accept / reject paths); configparser check of jail file
- [x] commit; registries (BDR-013, LRN-012); runbook. No finish without explicit signal.
## Feature — install.sh mirrors this machine's apt packages (2026-09-28)
Branch: feature/apt-packages (off develop). Source: apt-mark showmanual + /var/log/apt/history.log diffed against install.sh.
- [x] gitleaks in the base list (backs the pre-commit hook)
- [x] web stack group: mariadb-server imagemagick + unversioned php-* modules (approved: base list, not an offer)
- [x] ubuntu-desktop-minimal before setup_remote_desktop (approved)
- [x] install_nvidia_driver(): lspci vendor 10de gate + ubuntu-drivers install (approved: no version pin)
- [x] README steps 11 + packages; shellcheck + bash -n; stub run of the NVIDIA helper
- [x] commit on the feature branch. No finish without explicit signal.
## Feature — macOS support, parity with Linux minus apt (2026-10-05)
Branch: feature/macos-support (off develop). User choices: Docker = colima + CLI; login shell → brew bash 5.
- [x] install.sh: Darwin block — ensure Homebrew, brew update/upgrade, brew formula list mirroring apt list
- [x] install.sh: colima + docker CLI (compose/buildx plugin dir), code-server + mariadb via brew services
- [x] install.sh: brew bash → /etc/shells + chsh; ~/.bash_profile sources ~/.bashrc (Terminal = login shell)
- [x] install.sh: `cp -rupv` → `cp -Rpv` (BSD cp has no -u; target dir is fresh anyway)
- [x] install.sh: end-of-run report of Linux items not installed on macOS
- [x] bash/bashrc-osx: mirror bashrc-linux (ls -G, brew shellenv, EPOCHREALTIME timer, dtach_claude w/o systemd-run)
- [x] bin/dt: portable _cwd_of (lsof) + _starttime_of (BSD date), help sed -E
- [x] README + CLAUDE.md macOS section
- [x] shellcheck + bash -n; runtime test bashrc-osx + dt on this Mac; stub run of Darwin block
## Feature — macOS: choose zsh (oh-my-zsh) or bash as login shell (2026-10-05)
Same branch. Prompt at start of Darwin block (MACOS_SHELL=bash|zsh env overrides, no TTY → bash).
- [x] zsh/zshrc-osx: brew env, PATH, history, GCC_COLORS, VIUSER, cc/d + dtach-router, oh-my-zsh, ~/.zshrc.local hook
- [x] zsh/bchanot.zsh-theme: same prompt as bashrc (✔/✘ + timer, user [ cwd ], git [branch -*+], root red)
- [x] install.sh: choose_macos_shell, install_oh_my_zsh (unattended, keep zshrc), deploy_zsh_config (backup → Oldconfig)
- [x] install.sh: use_brew_bash_login_shell → set_login_shell <path>, called at end with chosen shell
- [x] README + CLAUDE.md
- [x] shellcheck/bash -n/zsh -n; runtime: theme in zsh (prompt render, timer, git bits), dtach-router sourced in zsh; harness both choices
## Feature — user-scope ~/.gitconfig from repo template, VIUSER/VIMAIL → USER/EMAIL (2026-10-06)
- [x] rc files (bashrc-linux, bashrc-osx, zshrc-osx): `VIUSER`/`VIMAIL` → `USER`/`EMAIL`
- [x] `gitconfig` template: git never expands `$VAR` → `@USER@`/`@EMAIL@` placeholders, `excludesfile = ~/.gitignore`
- [x] install.sh `deploy_gitconfig`: values read from deployed bashrc, rendered → ~/.gitconfig, differing old one → ~/.gitconfig.backup-<date>
- [x] install.sh: `$USER` → `$(id -un)` (dscl, code-server unit): rc now overrides USER with identity
- [x] README + CLAUDE.md layout
- [x] Verify: shellcheck, bash -n, render to temp HOME, `git config --file` reads values
- [x] `git-delta` added to apt + brew lists (gitconfig pager = delta)
## Feature — macOS tmux config (tmux.conf + tpm) ; cloudpex becomes an offer (2026-10-06)
Branch: feature/tmux-config (off develop, "met ca dans develop" = finish into develop). tmux already in the brew list.
- [x] install.sh `deploy_tmux_config` (Darwin): tmux.conf → ~/.config/tmux/tmux.conf (differing one → .backup-<date>, stray ~/.tmux.conf moved aside since tmux reads it first), clone tpm, headless `install_plugins`, libtmux for tmux-window-name (non-fatal)
- [x] bashrc-osx + zshrc-osx: export XDG_CACHE_HOME (tmux.conf resurrect dir needs it, else "/tmux/")
- [x] README macOS step + CLAUDE.md layout
- [x] shellcheck, bash -n, zsh -n; run deploy_tmux_config against a temp HOME; tmux parses the config
- [x] cloudpex: `install_cloudpex` → `offer_cloudpex` ([y/N] via confirm, with the other Linux offers); README/CLAUDE.md wording
## tmux follow-ups (2026-10-06, branch bugfix/tmux-macos-keys)
- [x] tmux.conf: pbcopy/pbpaste, `bind C-a send-prefix`, is_vim via pane_current_command
- [x] pane moves ctrl+u/h/j/k (arrow layout, AZERTY/QWERTY invariant), resize mirrors with prefix; C-l free
- [x] splits: prefix i (side by side) and prefix - (stacked), h/j/k/l kept
- [x] Linux: deploy_tmux_config on both OSes (gated on tmux), clipboard if-shell (pbcopy else tmux buffer + OSC 52), XDG_CACHE_HOME in bashrc-linux
- [x] Verified: shellcheck/bash -n, macOS test server, Ubuntu 24.04 container (tmux 3.4) full deploy + bindings + split + plugins + libtmux
## Feature — identity asked at install, no hardcoded USER/EMAIL in tracked rc files (2026-10-06)
Branch: feature/identity-prompt (off develop). Values were visible to anyone reading the repo.
- [x] rc templates (bashrc-linux, bashrc-osx, zshrc-osx): `export USER="@USER@"` / `export EMAIL="@EMAIL@"`
- [x] install.sh resolve_identity: existing ~/.bashrc / ~/.zshrc export wins silently → IDENTITY_USER/IDENTITY_EMAIL env → prompt (TTY) → default (id -un, empty email)
- [x] install.sh: render_identity_template (generic, replaces render_gitconfig); bashrc + zshrc rendered, gitconfig unchanged (reads the rendered bashrc)
- [x] vim/vimrc: g:_author / g:_email from $USER / $EMAIL
- [x] README, CLAUDE.md (CHANGELOG left to the release step, like the tmux work)
- [x] Verify: shellcheck, bash -n, zsh -n; temp-HOME render (env preset, existing rc reuse); vim reads the env
## Feature — repo-sync: one local tree for every reachable git repo, multi-forge (2026-10-07)
Branch: feature/repo-sync (off develop). Design approved in chat: name `repo-sync`, tokens in
`~/.config/repos/forges.conf` 0600 (never tracked), root `~/repos`, Bitbucket Cloud only.
Port of the Alphalink dotfiles `repo` / `repo-reset` zsh functions, bash + zsh, Linux + macOS.
- [x] bin/repo-sync — add / refresh (daily, mkdir lock) / list / tree / path / clone; curl + jq
fetchers for gitlab, github (+GHES), gitea/forgejo, bitbucket cloud; dedup namespace/project
- [x] bash/bashrc-linux, bash/bashrc-osx, zsh/zshrc-osx — `repo` function (cd), completion, background refresh
- [x] install.sh — jq in apt + brew lists, chmod repo-sync
- [x] README.md (table + CLI section) + CLAUDE.md layout
- [x] shellcheck + bash -n; stub-curl harness per forge (fixtures), live GitLab run
- [ ] commit on feature branch; registries. No finish without explicit signal.