aboutsummaryrefslogtreecommitdiff
path: root/todo.org
diff options
context:
space:
mode:
Diffstat (limited to 'todo.org')
-rw-r--r--todo.org36
1 files changed, 29 insertions, 7 deletions
diff --git a/todo.org b/todo.org
index 179054a..dad3a6b 100644
--- a/todo.org
+++ b/todo.org
@@ -1795,9 +1795,9 @@ Re-scope before building. The 1:7 ratio this task argues from is gone, and two
of the three things it cites as noise are fixed at the source rather than
filtered.
-=87ff0b7= gave check 2 a machine-local expected-disabled list, so the four unit
+=3397463= gave check 2 a machine-local expected-disabled list, so the four unit
findings are declared intent rather than noise, and an entry whose unit turns
-out to be enabled is itself reported so the list cannot rot. =3fbf3e0= dropped
+out to be enabled is itself reported so the list cannot rot. =3686500= dropped
=.claude= from check 4's expected set, since the gitignore sweep writes that
line into every project whether or not one exists. velox went 8 findings to 1.
@@ -2330,13 +2330,30 @@ anticipated this ("fresh clones automatically carry the post-purge rewritten
git history"); nobody closed the task once the reinstall took that route.
Verified rather than assumed: both repos are level with =origin/main= today —
-archsetup at =6faa31c=, dotfiles at =65940f2=, both trees clean.
+archsetup at =41fea69=, dotfiles at =65940f2=, both trees clean.
One thing the reinstall did leave, and it is filed separately: the installer
cloned both repos =--depth 1=, so the history was present-but-truncated until
today's =git fetch --unshallow= (see the shallow-clone =[#A]=). A reconcile
against the rewritten remote was still unnecessary — a shallow clone of the
right history is not a diverged clone of the wrong one.
+
+*** 2026-10-06 Tue @ 06:08:06 -0600 Scrubbed the Signal pager number from this repo's history
+The agent's Signal identity number sat in two tracked files from 08-17
+(a post-rebuild-check fixture) and 09-13 (a filed design note). A
+working-tree redaction landed on 10-05, but the number stayed reachable in
+history for anyone cloning over cgit, so I rewrote it out: =git filter-repo
+--replace-text= in a fresh clone, verified by content search, diff search and
+a grep over every revision (all zero) and by a byte-identical HEAD tree, then
+a force-push of main, a server-side reflog expire and =gc --prune=now= on the
+bare repo (the old head object is gone), and a hard reset of the velox and
+ratio clones, each followed by a reflog expire and =gc --prune=now= so the
+old objects are gone there too. 59 of 951 commits changed SHA, every
+descendant of the 08-17 post-rebuild-check commit; tag v0.5 predates it and
+is unchanged.
+The old-to-new map is =assets/2026-10-06-history-rewrite-commit-map.txt=,
+and the citations in this file, the task archive, the topgrade spec and the
+KB nodes are remapped. Session logs keep the old SHAs; use the map.
** TODO [#B] Move archsetup off cgit to cjennings@cjennings.net :chore:security:
:PROPERTIES:
:LAST_REVIEWED: 2026-08-17
@@ -2348,7 +2365,7 @@ Plan: create a bare repo under cjennings's control off the cgit scan-path (e.g.
Ran the task's own verification step as it stands today, which is the honest
way to check an unstarted task rather than reading its body back. Anonymous
=git ls-remote https://git.cjennings.net/archsetup.git= succeeded with no
-credentials and returned =6faa31c= — this afternoon's HEAD. So the repo is
+credentials and returned =41fea69= — this afternoon's HEAD. So the repo is
still world-cloneable and current to the commit, not a stale published
snapshot.
@@ -5356,6 +5373,11 @@ Rewrote the bare =if $var= boolean conditionals (=show_status_only=, =fresh_inst
*** 2026-05-26 Tue @ 15:27:09 -0500 eval task moot — the line-434 eval is gone, the survivor is deliberate
Verified: the only =eval= left in =archsetup= is line 578 in =retry_install=, and it's intentional and documented — it captures =$?= directly from =eval "$cmd"= to dodge the if-compound-swallows-exit-code trap. Replacing it with an array would reintroduce that bug. The line-434 eval this task pointed at no longer exists. Nothing to change.
+*** 2026-10-06 Tue @ 06:08:06 -0600 One secret scrubbed from history; the full pre-release scan is still owed
+The Signal pager number was rewritten out of every commit on 10-06 (details
+on the cgit audit task). That was one known string; before the public push,
+run a full-history secrets scan rather than trusting the tree alone.
+
** TODO [#C] The audio doctor never checks the microphone :bug:audio:
:PROPERTIES:
:LAST_REVIEWED: 2026-08-25
@@ -5702,13 +5724,13 @@ fix + verify the backup timer (runbook Phase 5).
*** 2026-09-13 Sun @ 07:16:27 -0500 Applied the two live convergence steps on velox
Ratio got both by hand on 2026-09-12 while velox was off the tailnet; velox
came back on 2026-09-13 and got them over ssh: =systemctl disable --now
-wsdd.service= (no Samba host to advertise; 43acf51 stops the installer
+wsdd.service= (no Samba host to advertise; 64cccef stops the installer
enabling it) and =systemctl mask passim.service= (the unit is static, so the
-09-12 disable was a no-op; 38b1758 masks it in the installer, but
+09-12 disable was a no-op; 495d16d masks it in the installer, but
supplemental_software is a completed step there and doesn't re-run).
Verified after: wsdd inactive/disabled, passim inactive/masked, zero
listeners on 5357 and 27500. Same pass fast-forwarded velox's dotfiles to
-f56fd1a and archsetup to dc00a62, and confirmed the headless Proton Bridge
+f56fd1a and archsetup to 9c77b07, and confirmed the headless Proton Bridge
service is still disabled there.
*** 2026-09-13 Sun @ 07:56:37 -0500 Closed the drill and filed its working-dir artifacts