diff --git a/.devcontainer/entry.fish b/.devcontainer/entry.fish index 8aa7bdfc15..c279d102cd 100644 --- a/.devcontainer/entry.fish +++ b/.devcontainer/entry.fish @@ -504,28 +504,28 @@ cd /home/me log_step "PHASE 6: SSL certificates" ensure_ssl_dev_certs -log_step "PHASE 7: GitHub authentication" -# Login to Github - use GH_TOKEN from vault if available -set -l gh_authenticated 1 -if not gh auth status >/dev/null 2>&1 - if test -n "$GH_TOKEN" - log_info "Authenticating to GitHub using GH_TOKEN..." - echo $GH_TOKEN | gh auth login --with-token - if gh auth status >/dev/null 2>&1 - log_ok "GitHub authentication successful" - else - log_error "GitHub authentication failed" - log_warn "Continuing without GitHub auth; vault/git operations may be limited." - set gh_authenticated 0 - end - else - log_warn "Not logged into GitHub and no GH_TOKEN available." - log_warn "Continuing startup without GitHub auth." - set gh_authenticated 0 - end -else - log_ok "Already authenticated to GitHub" -end +log_step "PHASE 7: GitHub authentication" +# Login to Github - use GH_TOKEN from vault if available +set -l gh_authenticated 1 +if not gh auth status >/dev/null 2>&1 + if test -n "$GH_TOKEN" + log_info "Authenticating to GitHub using GH_TOKEN..." + echo $GH_TOKEN | gh auth login --with-token + if gh auth status >/dev/null 2>&1 + log_ok "GitHub authentication successful" + else + log_error "GitHub authentication failed" + log_warn "Continuing without GitHub auth; vault/git operations may be limited." + set gh_authenticated 0 + end + else + log_warn "Not logged into GitHub and no GH_TOKEN available." + log_warn "Continuing startup without GitHub auth." + set gh_authenticated 0 + end +else + log_ok "Already authenticated to GitHub" +end log_step "PHASE 8: Git configuration" if test -n "$GIT_USER_EMAIL" @@ -544,15 +544,15 @@ git config --global --add safe.directory /home/me/aesthetic-computer # Set rebase as default for pull operations. git config --global pull.rebase true -# Disable GPG signing to prevent commit issues in dev environment -git config --global commit.gpgsign false - -# Make sure git is setup and authorized for making commits via `gh`. -if test $gh_authenticated -eq 1 - gh auth setup-git -else - log_warn "Skipping 'gh auth setup-git' because GitHub auth is unavailable." -end +# Disable GPG signing to prevent commit issues in dev environment +git config --global commit.gpgsign false + +# Make sure git is setup and authorized for making commits via `gh`. +if test $gh_authenticated -eq 1 + gh auth setup-git +else + log_warn "Skipping 'gh auth setup-git' because GitHub auth is unavailable." +end # Ensure GPG signing is disabled at both global and local levels (GitHub CLI might re-enable it) git config --global commit.gpgsign false @@ -673,66 +673,62 @@ if test -d /home/me/.ssh log_ok "Fixed permissions for /home/me/.ssh" end -# Fix Copilot CLI directory permissions (volume mount may have root ownership) -if test -d /home/me/.copilot - sudo chown -R me:me /home/me/.copilot 2>/dev/null - sudo chmod 700 /home/me/.copilot 2>/dev/null +# Fix Copilot CLI directory permissions (volume mount may have root ownership) +if test -d /home/me/.copilot + sudo chown -R me:me /home/me/.copilot 2>/dev/null + sudo chmod 700 /home/me/.copilot 2>/dev/null # Ensure pkg directory exists and is writable for package extraction mkdir -p /home/me/.copilot/pkg 2>/dev/null chmod 755 /home/me/.copilot/pkg 2>/dev/null - sudo chmod 600 /home/me/.copilot/config.json 2>/dev/null - echo "✅ Fixed permissions for /home/me/.copilot (Copilot CLI config)" -end - -# Fix Claude/Codex config directory permissions after bind mounts are attached. -# On Linux hosts, these mounts keep host ownership, so UID remapping is the main -# fix; this container-side pass normalizes modes when ownership is already writable. -for dir in /home/me/.claude /home/me/.codex - if test -d $dir - sudo chown -R me:me $dir 2>/dev/null - chmod 700 $dir 2>/dev/null - find $dir -type d -exec chmod 700 {} + 2>/dev/null - find $dir -type f -exec chmod 600 {} + 2>/dev/null - echo "✅ Fixed permissions for $dir" - end -end - -if test -f /home/me/.claude.json - sudo chown me:me /home/me/.claude.json 2>/dev/null - chmod 600 /home/me/.claude.json 2>/dev/null - echo "✅ Fixed permissions for /home/me/.claude.json" -end - -# Fix VS Code extension SecretStorage persistence paths. -for dir in /home/me/.config/Code/User/globalStorage /home/me/.config/Code/User/workspaceStorage - if test -d $dir - sudo chown -R me:me $dir 2>/dev/null - find $dir -type d -exec chmod 700 {} + 2>/dev/null - find $dir -type f -exec chmod 600 {} + 2>/dev/null - echo "✅ Fixed permissions for $dir" - end -end - -if test -d /home/me/.local/share/keyrings - sudo chown -R me:me /home/me/.local/share/keyrings 2>/dev/null - chmod 700 /home/me/.local/share/keyrings 2>/dev/null - find /home/me/.local/share/keyrings -type f -exec chmod 600 {} + 2>/dev/null - echo "✅ Fixed permissions for /home/me/.local/share/keyrings" -end - -# --- GPG agent: cache passphrase for the entire container lifetime --- -mkdir -p /home/me/.gnupg 2>/dev/null -chmod 700 /home/me/.gnupg + sudo chmod 600 /home/me/.copilot/config.json 2>/dev/null + echo "✅ Fixed permissions for /home/me/.copilot (Copilot CLI config)" +end + +# Fix Claude/Codex config directory permissions after bind mounts are attached. +# On Linux hosts, these mounts keep host ownership, so UID remapping is the main +# fix; this container-side pass normalizes modes when ownership is already writable. +for dir in /home/me/.claude /home/me/.codex + if test -d $dir + sudo chown -R me:me $dir 2>/dev/null + chmod 700 $dir 2>/dev/null + find $dir -type d -exec chmod 700 {} + 2>/dev/null + find $dir -type f -exec chmod 600 {} + 2>/dev/null + echo "✅ Fixed permissions for $dir" + end +end + +if test -f /home/me/.claude.json + sudo chown me:me /home/me/.claude.json 2>/dev/null + chmod 600 /home/me/.claude.json 2>/dev/null + echo "✅ Fixed permissions for /home/me/.claude.json" +end + +# Fix VS Code extension SecretStorage persistence paths. +for dir in /home/me/.config/Code/User/globalStorage /home/me/.config/Code/User/workspaceStorage + if test -d $dir + sudo chown -R me:me $dir 2>/dev/null + find $dir -type d -exec chmod 700 {} + 2>/dev/null + find $dir -type f -exec chmod 600 {} + 2>/dev/null + echo "✅ Fixed permissions for $dir" + end +end + +if test -d /home/me/.local/share/keyrings + sudo chown -R me:me /home/me/.local/share/keyrings 2>/dev/null + chmod 700 /home/me/.local/share/keyrings 2>/dev/null + find /home/me/.local/share/keyrings -type f -exec chmod 600 {} + 2>/dev/null + echo "✅ Fixed permissions for /home/me/.local/share/keyrings" +end + +# --- GPG agent: cache passphrase for the entire container lifetime --- +mkdir -p /home/me/.gnupg 2>/dev/null +chmod 700 /home/me/.gnupg printf "allow-loopback-pinentry\npinentry-program /usr/sbin/pinentry-curses\ndefault-cache-ttl 999999\nmax-cache-ttl 999999\n" > /home/me/.gnupg/gpg-agent.conf gpgconf --reload gpg-agent 2>/dev/null log_ok "GPG agent configured (passphrase cached for container lifetime)" -if not test -d /home/me/aesthetic-computer/aesthetic-computer-code - gh repo clone whistlegraph/aesthetic-computer-code /home/me/aesthetic-computer/aesthetic-computer-code -else - cd /home/me/aesthetic-computer/aesthetic-computer-vault - git pull -end +cd /home/me/aesthetic-computer/aesthetic-computer-vault +git pull # Function to check and install npm dependencies in a directory set -g NODE_DEPS_CHECK_SCRIPT /workspaces/aesthetic-computer/.devcontainer/scripts/check-node-deps.mjs diff --git a/.gitignore b/.gitignore index 0305192968..a27fe80a27 100644 --- a/.gitignore +++ b/.gitignore @@ -71,9 +71,6 @@ system/public/index.html # any instance of the aesthetic-computer-vault repository aesthetic-computer-vault/ -# any instance of the aesthetic-computer-code repository -aesthetic-computer-code/ - # Local clones of external repos feral-file/ modes/ diff --git a/.vscode/settings.json b/.vscode/settings.json index 3b03b98494..f60dba53f4 100644 --- a/.vscode/settings.json +++ b/.vscode/settings.json @@ -42,7 +42,6 @@ "**/.emacs.d": true, "**/.netlify": true, "**/.vscode-test-web/**": true, - "**/aesthetic-computer-code/**": false, "**/aesthetic-computer-vault/**": false, "**/ac-event-daemon/target/**": true, "**/ac-event-daemon/Cargo.lock": true,