Your Name
d817c37652
fix: stabilization pass — fail-closed auth, ai flag validation, lint/config/security hardening, regression tests
...
gates / consistency-and-conventions (push) Successful in 26s
17-point code-level audit executed via Explorer->Architect->Builder->Tester->Reviewer;
Reviewer accepted (APPROVE_WITH_NOTES; 3 block-list items resolved):
- security: telegram sender-owner AND-gate + TELEGRAM_OWNER_ID, matrix
MATRIX_ROOM_ID fail-closed, gpg --passphrase-fd 3 (no argv secret),
/dev/tcp positional-arg form (checkport/smb-client/share-lib/NET_PROBE),
eval deny-by-default + --no-command-execution carried by both chat bridges,
tty-gated --trust; config/{telegram,matrix}.env reference templates
- ai: all ExecStart flags validated against installed llama.cpp
(requested->error, default->omit+warn, CONFIG_REQUESTED_FLAGS); single-file
hf download failure rc=1 + no .hf-meta; LLAMACPP_HOST coherent;
POS_SUBCMDS + metadata gaps closed
- tooling: lint-conventions Bash-native rewrite (~24-30x faster, rules and
output byte-identical, :num restored); pos system uninstall covers all 12
libs + scale-tail + flags dir + systemd user units (|| true) + plugin
markers; anchored .bash_completion/.bashrc removal replaces sed -i '/pos/d'
- config: canonical load_env_file in lib/config-ui.sh (CRLF strip, env-wins,
XDG, LOADED_ENV_KEYS); 9 tools migrated; entertainment-lib collapsed to
wrappers; docker-compose deliberately unmigrated (source semantics)
- tests: first committed regression suite — tests/run-tests.sh zero-dep
runner + make test; 12 files / 179 checks / 0 skip / ~52s; hard skip
contract; systemd-analyze verify on generated unit PASS
Verified: make gen idempotent; make check green; make lint 0 FAIL, 0 WARN;
make test green; bash -n clean; git diff --check clean. Audit deliverables +
agent reports + AGENT_TODO Done entry included.
2026-09-06 07:25:44 -04:00
Your Name
e969234ca5
feat: command registry, alias wrapper scripts, config-ui readability
...
gates / consistency-and-conventions (push) Successful in 1m28s
- lib/registry.sh: shared query API over POS_* headers (reg_scan, reg_list,
reg_lookup, reg_tools_in, reg_each, reg_config_scopes/keys). Replaces
per-consumer sed/grep header parsing.
- bin/pos-tree + bin/pos _pos_category_help(): migrated to registry API.
Category help now shows [deps: ...] annotations. Tree output preserved.
- New optional headers # POS_DEPS: and # POS_EXAMPLES: in tool metadata.
Added to pos-network-download (aria2c jq curl), pos-media-sync (lsblk jq),
pos-system-backup (tar), pos-docker-ps (docker) as initial adopters.
- scripts/gen-docs.sh: extended tools array with deps/examples fields;
conditional column rendering in gen_dispatch; deps annotation in gen_tree.
Fixed URL-unsafe // joiner (→ middle dot ·) and \x1f caption delimiter
collision in config-ui.
- bin/pos-ai-alias: rewrote activation from bash aliases (source-time-frozen)
to executable wrapper scripts at ~/.local/bin. Staleness eliminated:
edits apply on next invocation with no shell reload. _alias_sync()
reconciliation on every subcommand, marker-guarded lifecycle, collision
refusal, legacy .sh retirement. Fixed dup-table bug (option 4 no-op).
- lib/config-ui.sh: @caption/@[KEY=alt] conditional captions, *providers=<tag>
tagged wildcards, uniform typography tier (bold/cyan/dim), honest prompt.
Active provider keys bold, inactive dimmed with reason. Backward-compatible.
- bin/pos-system-uninstall: marker-scan for wrapper script cleanup.
- Docs synced: AGENTS.md (new headers + registry), DOC/SCRIPTS.md (registry
section + lib list), DOC/POS.md (alias wrapper activation), MAINTENANCE.md
(M-024). Lint fixed: pos-ai-alias registered in INTERACTIVE_CMDS.
Gates: make gen && make check && make lint = 0 FAIL, 0 WARN
2026-08-27 02:30:27 -04:00
Your Name
692cb6b362
feat: menu doors for media-sync/backup/compose/schedule/vbox/download; firewall menu → stderr+/dev/tty mechanics
gates / consistency-and-conventions (push) Successful in 2m10s
2026-08-24 14:44:25 -04:00
he
16bda822ff
feat: pos media sync — incremental Music→USB sync (mp3/mp4) + shared lib/usb-lib.sh
gates / consistency-and-conventions (push) Successful in 46s
2026-08-14 18:02:03 -04:00
he
03dd92370c
feat: pos system backup -- optional --no-encrypt (BACKUP_ENCRYPT=0)
2026-08-14 17:19:17 -04:00
he
28fae8a684
feat: pos system backup — smart USB detection with mount offer for unmounted sticks
gates / consistency-and-conventions (push) Successful in 45s
2026-08-14 16:58:47 -04:00
Your Name
d4d38ad901
feat: pos system backup copies to USB after verification — sha256-proven 100%
...
Once the archive verifies, USB detection runs (so a stick plugged in while
the backup ran is found): mounted removable storage is auto-detected via
lsblk -J + a recursive jq filter (rm, mounted, type part|disk — JSON makes
spacey mountpoints safe), or BACKUP_USB_ROOT pins a fixed stick and skips
detection. None mounted → one re-scan prompt ('s' skips, EOF from cron
skips silently, rc stays 0); one stick → y/N confirm; several → numbered
pick (0 = skip). The copy lands in <usb>/backups/ (mkdir -p, chmod 600
best-effort — a vfat chmod failure warns, never fails the copy) and the
transfer is proven 100% by sha256 source-vs-copy before any success is
announced; a mismatch warns with both hashes, notifies 'USB copy FAILED',
and exits 1. The ERR trap is re-armed before the USB phase so a copy
failure no longer notifies 'Backup FAILED'. Docs: usage() Environment,
POS.md backup row, howto/system.md (USB section + env table + mismatch
troubleshooting), DEV.md system.env list. Stub suite
(/tmp/opencode/backup-test, HOME-isolated, sudo/gpg/lsblk/sender stubs,
corrupting-cp + vfat-chmod overrides, per-test lsblk JSON fixtures):
40/40 green.
2026-08-13 03:23:30 -04:00
Your Name
3536f267c7
refactor: move usb/nfs tools into new 'share' category
...
- rename bin/pos-usb-server -> pos-share-usb-server, pos-system-nfs-{client,server} -> pos-share-nfs-{client,server}
- update # POS: headers, usage strings, INTERACTIVE_CMDS, usage() EXAMPLES, notify-scope comment
- docs: new DOC/howto/share.md (USB+NFS consolidated), drop usb.md + system.md NFS sections,
POS.md ### share section, HOWTO/README/AGENT_Context/README/DEV/AGENTS updates
- make gen && make check green
2026-08-11 14:52:18 -04:00
Your Name
fe7708f142
ai need continue
2026-08-09 04:57:28 -04:00
Your Name
025971ca1e
feat: multi-platform alerting + shared system.env config with dynamic help values
...
- lib/notify.sh: route notify_send to every platform in NOTIFY_PLATFORM
(notify.env, default telegram; comma-separated = send to all). New
platforms need only a bin/pos-communication-<p> sender implementing
'send <value> [--markdown]' (Matrix/Synapse ready)
- pos-communication-telegram: add --markdown as alias for --parse-mode
markdown to match the sender contract
- lib/common.sh: load_system_env() — shared ~/.config/linux_post_install/
system.env for pos-system-* tools (env exported > file > default)
- pos-system-health/backup: load system.env and show effective dynamic
values (NOTIFY_PLATFORM, HEALTH_BACKUP_MAX_AGE_DAYS, BACKUP_SERVICE_ROOTS)
in --help
- config/system.env + config/notify.env templates copied by postinstall
- systemd/pos-health.service: EnvironmentFile for both configs so the
daily digest honors them
2026-08-06 02:37:56 -04:00
Your Name
9a94329dd0
feat: add pos system health, lib/notify.sh, and daily Telegram digest timer
...
- bin/pos-system-health: host dashboard (disk, RAM, failed units, backup age,
fail2ban, docker); exits 1 on any FAIL; --send/--markdown via Telegram
- lib/notify.sh: self-contained opt-in alerting helper; silent-fails, wired
into pos-system-backup (success + ERR trap) and pos-system-firewall
- systemd/pos-health.{service,timer}: 08:00 digest as installing user;
postinstall enables timer once telegram.env exists, now copies *.timer
- AGENT_TODO.md: worklist with Now/Next/Later/Done history; linked from AGENTS.md
2026-08-06 02:25:23 -04:00
Your Name
e62626b55c
ai need to continue ...
2026-08-05 05:47:45 -04:00
ciya
e7c8c176ed
feat: add pos system backup — encrypted folder snapshots with --service picker
2026-08-03 08:58:38 -04:00