Files
config/.claude/tasks/TODO.md
T

6.5 KiB

TODO — onboard backlog (2026-05-27)

Done this session

  • [P0] Fix install.sh broken /tmp/config paths (server+osx silent fail)
  • [P0] Fix bashism under #!/bin/sh → bash + set -euo pipefail
  • [P1] Fix nerdtree copy (cp -r / direct clone into bundle)
  • [P1] Guard apt-get behind command -v (osx no longer fails)
  • [P2] Drop redundant molokai clone
  • [P2] Create README.md, CLAUDE.md, .gitignore
  • [P2] Create .claude/memory + tasks + audits

P2 — Moyenne

  • [P2] [/hotfix] — vim/vimrc GenerateClassC: bare name → a:name (fixes :ClassC E121) Files: vim/vimrc (GenerateClassC, ~line 80-104) Source: .claude/memory/blockers.md BLK-001

P3 — Basse

  • [P3] [/code-clean] — bashrc-* legacy backticks → $(...) (SC2006), arithmetic SC2004 Files: bash/bashrc-linux, bash/bashrc-osx Note: cosmetic only, no behavior change

Post-MVP (optional, backlog)

  • Runtime-test install.sh on a clean VM (all 4 targets) — not safe on dev machine
  • Consider an uninstall.sh (restore from ~/Oldconfig)
  • LICENSE if repo ever goes public — done (GPL-3.0, BDR-008, 40c6524)

Feature — /tmp on disk + SSH OOM guard + cloudpex installer (2026-09-22)

Branch: feature/tmp-disk-ssh-oom-cloudpex (off develop). Design approved in chat (bounded). Root cause: /tmp is tmpfs (50% RAM) → agents fill it → RAM halved + ENOSPC breaks shells. Swap rejected.

  • etc/tmpfiles.d/tmp.conf (D /tmp 10d + q /var/tmp 30d — keep both upstream lines)
  • etc/systemd/ssh.service.d/override.conf (MemoryMin=256M, OOMScoreAdjust=-1000 — old server)
  • etc/default/earlyoom (old server args: -r 60 -m 10 -s 10 --avoid sshd… --prefer node…)
  • install.sh: confirm() TTY-guarded prompt helper
  • install.sh: offer_tmp_on_disk() — mask tmp.mount + tmpfiles rule, reboot notice, idempotent
  • install.sh: offer_ssh_memory_guard() — drop-in + daemon-reload/restart ssh + earlyoom, idempotent
  • install.sh: install_cloudpex() in Linux block; offers at end of script (Linux-gated)
  • cloudpex/install.sh — /usr/local/bin/cloudpex root 0755, /mnt/cloudpex, cifs-utils if missing
  • cloudpex/README.md (FR) — purpose, why on-demand not fstab, usage, install
  • README.md steps 12-14 + table rows; CLAUDE.md layout
  • shellcheck + bash -n (install.sh, cloudpex/install.sh); stub-sudo dry run of the offers
  • commit on feature branch (no gitea-deploy/, no .githooks changes)

Round 2 — cloudpex config out of script, reconcile main/develop, capitalize, merge (2026-09-22)

  • cloudpex/cloudpex: constants → /etc/cloudpex.conf parsed line by line (never sourced), die if missing
  • cloudpex/install.sh: prompt host/share/user/mnt/vers (regex-validated), keep-existing [Y/n], no-TTY skip
  • cloudpex/README.md + README.md + CLAUDE.md: no site values, describe prompts + conf file
  • registries: BDR-010/011/012, LRN-009/010/011, BLK-005/006, EVAL-002, journal
  • reconcile: merge main (a210d01 dtach) into develop via lib helper
  • gitflow finish feature → develop (explicit user signal: "puis merge")
  • runbook for live apply on this machine

Feature — security baseline in install.sh (2026-09-22)

Branch: feature/security-baseline (off develop). Scope approved: fail2ban, unattended-upgrades, sshd hardening. auditd + ufw declined.

  • etc/fail2ban/jail.d/local.conf — sshd jail, backend systemd, allports ban, RFC1918 ignoreip
  • etc/apt/apt.conf.d/20auto-upgrades — Periodic Update-Package-Lists + Unattended-Upgrade = 1
  • etc/ssh/sshd_config.d/20-hardening.conf — PermitRootLogin no, MaxAuthTries 3, LoginGraceTime 20
  • install.sh: install_fail2ban / install_unattended_upgrades / harden_sshd (sshd -t gated), called in Linux block
  • README.md (table, step 13, packages) + CLAUDE.md layout
  • shellcheck + bash -n; stub harness harden_sshd (accept / reject paths); configparser check of jail file
  • commit; registries (BDR-013, LRN-012); runbook. No finish without explicit signal.

Feature — install.sh mirrors this machine's apt packages (2026-09-28)

Branch: feature/apt-packages (off develop). Source: apt-mark showmanual + /var/log/apt/history.log diffed against install.sh.

  • gitleaks in the base list (backs the pre-commit hook)
  • web stack group: mariadb-server imagemagick + unversioned php-* modules (approved: base list, not an offer)
  • ubuntu-desktop-minimal before setup_remote_desktop (approved)
  • install_nvidia_driver(): lspci vendor 10de gate + ubuntu-drivers install (approved: no version pin)
  • README steps 11 + packages; shellcheck + bash -n; stub run of the NVIDIA helper
  • commit on the feature branch. No finish without explicit signal.

Feature — macOS support, parity with Linux minus apt (2026-10-05)

Branch: feature/macos-support (off develop). User choices: Docker = colima + CLI; login shell → brew bash 5.

  • install.sh: Darwin block — ensure Homebrew, brew update/upgrade, brew formula list mirroring apt list
  • install.sh: colima + docker CLI (compose/buildx plugin dir), code-server + mariadb via brew services
  • install.sh: brew bash → /etc/shells + chsh; ~/.bash_profile sources ~/.bashrc (Terminal = login shell)
  • install.sh: cp -rupv → cp -Rpv (BSD cp has no -u; target dir is fresh anyway)
  • install.sh: end-of-run report of Linux items not installed on macOS
  • bash/bashrc-osx: mirror bashrc-linux (ls -G, brew shellenv, EPOCHREALTIME timer, dtach_claude w/o systemd-run)
  • bin/dt: portable _cwd_of (lsof) + _starttime_of (BSD date), help sed -E
  • README + CLAUDE.md macOS section
  • shellcheck + bash -n; runtime test bashrc-osx + dt on this Mac; stub run of Darwin block

Feature — macOS: choose zsh (oh-my-zsh) or bash as login shell (2026-10-05)

Same branch. Prompt at start of Darwin block (MACOS_SHELL=bash|zsh env overrides, no TTY → bash).

  • zsh/zshrc-osx: brew env, PATH, history, GCC_COLORS, VIUSER, cc/d + dtach-router, oh-my-zsh, ~/.zshrc.local hook
  • zsh/bchanot.zsh-theme: same prompt as bashrc (✔/✘ + timer, user [ cwd ], git [branch -*+], root red)
  • install.sh: choose_macos_shell, install_oh_my_zsh (unattended, keep zshrc), deploy_zsh_config (backup → Oldconfig)
  • install.sh: use_brew_bash_login_shell → set_login_shell , called at end with chosen shell
  • README + CLAUDE.md
  • shellcheck/bash -n/zsh -n; runtime: theme in zsh (prompt render, timer, git bits), dtach-router sourced in zsh; harness both choices