d817c37652
gates / consistency-and-conventions (push) Successful in 26s
17-point code-level audit executed via Explorer->Architect->Builder->Tester->Reviewer;
Reviewer accepted (APPROVE_WITH_NOTES; 3 block-list items resolved):
- security: telegram sender-owner AND-gate + TELEGRAM_OWNER_ID, matrix
MATRIX_ROOM_ID fail-closed, gpg --passphrase-fd 3 (no argv secret),
/dev/tcp positional-arg form (checkport/smb-client/share-lib/NET_PROBE),
eval deny-by-default + --no-command-execution carried by both chat bridges,
tty-gated --trust; config/{telegram,matrix}.env reference templates
- ai: all ExecStart flags validated against installed llama.cpp
(requested->error, default->omit+warn, CONFIG_REQUESTED_FLAGS); single-file
hf download failure rc=1 + no .hf-meta; LLAMACPP_HOST coherent;
POS_SUBCMDS + metadata gaps closed
- tooling: lint-conventions Bash-native rewrite (~24-30x faster, rules and
output byte-identical, :num restored); pos system uninstall covers all 12
libs + scale-tail + flags dir + systemd user units (|| true) + plugin
markers; anchored .bash_completion/.bashrc removal replaces sed -i '/pos/d'
- config: canonical load_env_file in lib/config-ui.sh (CRLF strip, env-wins,
XDG, LOADED_ENV_KEYS); 9 tools migrated; entertainment-lib collapsed to
wrappers; docker-compose deliberately unmigrated (source semantics)
- tests: first committed regression suite — tests/run-tests.sh zero-dep
runner + make test; 12 files / 179 checks / 0 skip / ~52s; hard skip
contract; systemd-analyze verify on generated unit PASS
Verified: make gen idempotent; make check green; make lint 0 FAIL, 0 WARN;
make test green; bash -n clean; git diff --check clean. Audit deliverables +
agent reports + AGENT_TODO Done entry included.
4.4 KiB
4.4 KiB
Optional Apps Reference
apps/ holds 18 optional desktop application installers, one script per app in apps/<category>/<name>.sh. They are not installed by the core bootstrap — run the picker explicitly.
The picker — apps/install.sh
Purpose: discover every app under apps/ and install/uninstall the selection. Apps are auto-discovered from the directory structure — no registration step.
Usage
bash apps/install.sh # interactive install selection
bash apps/install.sh --all # install everything
bash apps/install.sh brave vscode # install specific apps
bash apps/install.sh --uninstall # interactive uninstall selection
bash apps/install.sh --uninstall --all # uninstall everything
bash apps/install.sh --uninstall brave # uninstall a specific app
(Also reachable via ./install.sh --apps / --full.)
How it works
- Parses
--all,--uninstall, and positional app names. - Scans
apps/<category>/*.shto build the catalog (skips non-app dirs). - Picks apps three ways: named on the command line (unknown names are skipped with a warning),
--all, or an interactive y/n picker grouped by category. - Runs
bash apps/<category>/<name>.sh [uninstall]for each selected app, with a progress header and an overall elapsed-time banner.
Configuration
- Categories:
ai,browsers,development,media,networking,remote-access,system,utilities. - Adding an app = dropping
apps/<category>/<name>.shinto the folder. See DEV.md for the required installer conventions.
How an app installer works
Every app script follows the same shape:
install_<name>() { … } # idempotent: checks command -v (or flatpak list) first
uninstall_<name>() { … } # also idempotent; purges and removes any added repos/keys
case "${1:-}" in
uninstall) uninstall_<name> ;;
*) install_<name> ;;
esac
Installation methods used across the catalog:
| Method | Example |
|---|---|
apt package |
sudo apt install -y obs-studio |
| Official installer script | curl -fsSL https://tailscale.com/install.sh | sh |
| Custom apt repo (added at install, removed at uninstall) | Brave, VS Code |
.deb file |
curl → dpkg -i → apt-get install -f -y |
| GitHub release archive | scrcpy (tar.gz → /usr/local/lib/) |
| AppImage | AFFiNE (/opt/affine + desktop entry) |
| Flatpak | LocalSend (flatpak install -y flathub …) |
App catalog
| App | Category | What it is | Install method |
|---|---|---|---|
| llama.cpp | ai | Local LLM inference server (llama-server) | GitHub release → /usr/local/lib/llama.cpp-<tag> + /usr/local/bin symlinks |
| Brave | browsers | Brave browser | apt repo + apt install brave-browser |
| opencode | development | AI coding agent | official script → ~/.opencode/bin |
| VS Code | development | Code editor | Microsoft apt repo + apt install code |
| OBS Studio | media | Screen recording / streaming | apt install obs-studio |
| scrcpy | media | Android mirror/control | GitHub release (latest) → /usr/local/lib/scrcpy-<v> + desktop entry |
| VLC | media | Media player | apt install vlc |
| NetBird | networking | Mesh VPN | official script; join with sudo netbird up --setup-key <key> |
| Tailscale | networking | WireGuard-based VPN | official script; start with sudo tailscale up |
| ZeroTier | networking | Virtual LAN | official script; join with sudo zerotier-cli join <id> |
| Termius | remote-access | SSH client | .deb from termius.com |
| VNC Viewer | remote-access | VNC client (TigerVNC) | apt install tigervnc-viewer |
| Docker Engine | system | Container runtime | get.docker.com; adds user to docker group (re-login needed) |
| QEMU + KVM | system | Virtualization + virt-manager | apt install (qemu-system, libvirt, bridge-utils, virt-manager); adds user to libvirt/kvm groups |
| AFFiNE | utilities | Knowledge base (AppImage) | GitHub release → /opt/affine + desktop entry |
| btop | utilities | Resource monitor | apt install btop |
| LocalSend | utilities | Local file sharing | flatpak (installs flatpak + flathub if missing) |
| tsui | utilities | Tailscale config TUI (official install script from neuralink.com) | curl | bash → /usr/local/bin/tsui |