From 4243038dd029e31996f6d6cf06c0988973ef9373 Mon Sep 17 00:00:00 2001 From: Patrick Singletary Date: Mon, 17 Aug 2026 13:02:04 -0400 Subject: [PATCH] Relocate live backup configs out of public repo + scrubs (red-team 2026-08-17) - config/backup3: live configs (drive UUIDs, machine policies) now live in ~/.config/backup3/ (local); bin/backup3.zsh + bin/backup-drive.zsh read ${XDG_CONFIG_HOME:-$HOME/.config}/backup3; repo keeps sanitized stub + README - docs/BACKUP3-PLAN.md: config paths -> ~/.config/backup3/, drive UUIDs -> / placeholders - plan.md: scrub SSH key filename / email / UseKeychain (SEC-03) - README.md: drop dead links to removed docs + GITHUB_TOKEN line (SEC-09) - project-bootstrap hermes-porkbun-mcp.sh: npx -y -> pinned local install (SEC-08) Deploy note: other machine needs ~/.config/backup3/ populated BEFORE resetting its clone to the rewritten history. --- README.md | 19 ++------- bin/backup-drive.zsh | 2 +- bin/backup3.zsh | 2 +- config/backup3/README.md | 15 +++++++ config/backup3/backup3.conf | 39 ------------------- config/backup3/drives.conf | 35 ----------------- config/backup3/machines/mac-studio.conf | 23 ----------- config/backup3/machines/ole-blu.conf | 22 ----------- docs/BACKUP3-PLAN.md | 17 ++++---- plan.md | 7 ++-- .../scripts/hermes-porkbun-mcp.sh | 5 ++- 11 files changed, 37 insertions(+), 149 deletions(-) create mode 100644 config/backup3/README.md delete mode 100644 config/backup3/backup3.conf delete mode 100644 config/backup3/drives.conf delete mode 100644 config/backup3/machines/mac-studio.conf delete mode 100644 config/backup3/machines/ole-blu.conf diff --git a/README.md b/README.md index b8cacb6..b447adc 100755 --- a/README.md +++ b/README.md @@ -1,6 +1,6 @@ # Hermes Agent Configuration & Tools -This OneDrive folder contains Hermes Agent configuration, scripts, and tools for use with Zed Editor. +This repo contains Hermes Agent configuration, scripts, and tools for use with Zed Editor. ## 📁 Directory Structure @@ -10,13 +10,8 @@ hermes/1/ ├── docs/ # Documentation │ ├── SYSTEMS_TEST_RESULTS.md # Systems test and configuration │ ├── kagi-cli-guide.md # Kagi CLI installation guide -│ ├── kagi-authentication-guide.md # Authentication reference -│ ├── MODEL_STRATEGY_GUIDE.md # Model selection strategy -│ └── agent_logging/ # Chat history logs -│ ├── README.md -│ ├── LOGIN.md -│ ├── chat_current.md -│ └── chat_history_*.md +│ ├── BACKUP3-PLAN.md # Three-location backup design +│ └── MODEL_STRATEGY_GUIDE.md # Model selection strategy ├── scripts/ # Executable tools │ ├── smart_chat.sh # Intelligent model router │ ├── budget_monitor.sh # Cost tracking & budget management @@ -71,7 +66,7 @@ kagi auth set --session-token "https://kagi.com/search?token=..." - **Python**: 3.14.6 - **Node.js**: v26.5.0 - **Git**: 2.55.0 -- **Nous Portal**: Authenticated (expires 2026-07-26) +- **Nous Portal**: Authenticated - **Model**: poolside/laguna-xs-2.1:free - **kagi-cli**: v0.15.0 (authenticated) @@ -82,23 +77,17 @@ kagi auth set --session-token "https://kagi.com/search?token=..." - TTS: ✓ Active via subscription - Speech-to-text: ✓ Active via subscription - Browser automation: ✓ Active via subscription -- GITHUB_TOKEN: ✓ Configured ## 📚 Documentation Index ### Getting Started - `docs/SYSTEMS_TEST_RESULTS.md` - Complete systems test results - `docs/kagi-cli-guide.md` - Full kagi-cli installation guide -- `docs/kagi-authentication-guide.md` - Authentication quick reference ### Model Strategy - `docs/MODEL_STRATEGY_GUIDE.md` - Tiered model selection guide - `config/model_config.yaml` - Model configuration file -### Chat History -- `docs/agent_logging/chat_current.md` - Current conversation -- `docs/agent_logging/chat_history_*.md` - Timestamped backups - ## 🎯 Model Strategy ### Tiered Approach: diff --git a/bin/backup-drive.zsh b/bin/backup-drive.zsh index 620a03a..a78819b 100755 --- a/bin/backup-drive.zsh +++ b/bin/backup-drive.zsh @@ -16,7 +16,7 @@ set -euo pipefail SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)" -CONFIG_DIR="$SCRIPT_DIR/../config/backup3" +CONFIG_DIR="${XDG_CONFIG_HOME:-$HOME/.config}/backup3" STATE_DIR="${XDG_STATE_HOME:-$HOME/.local/state}/drive-backup" mkdir -p "$STATE_DIR/logs" RUNLOG="$STATE_DIR/logs/run-$(date +%Y%m%d-%H%M%S).log" diff --git a/bin/backup3.zsh b/bin/backup3.zsh index 20716e9..f5743aa 100755 --- a/bin/backup3.zsh +++ b/bin/backup3.zsh @@ -17,7 +17,7 @@ set -euo pipefail SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)" -CONFIG_DIR="$SCRIPT_DIR/../config/backup3" +CONFIG_DIR="${XDG_CONFIG_HOME:-$HOME/.config}/backup3" STATE_DIR="${XDG_STATE_HOME:-$HOME/.local/state}/backup3" mkdir -p "$STATE_DIR/logs" RUNLOG="$STATE_DIR/logs/run-$(date +%Y%m%d-%H%M%S).log" diff --git a/config/backup3/README.md b/config/backup3/README.md new file mode 100644 index 0000000..6bf345b --- /dev/null +++ b/config/backup3/README.md @@ -0,0 +1,15 @@ +# config/backup3 — no live configs here (moved 2026-08-17) + +This repo is PUBLIC. Live machine configs (drive UUIDs, per-machine policies) +were moved out to the local dir `~/.config/backup3/` — sourced by +`bin/backup3.zsh` and `bin/backup-drive.zsh` via +`${XDG_CONFIG_HOME:-$HOME/.config}/backup3`. + +What stays here: the sanitized `machines/mac-studio.conf.stub` template only. + +Deploying to a new machine (order matters — BEFORE resetting the repo clone +after a force-push): + mkdir -p ~/.config/backup3/machines + # copy from the pre-reset clone if present, else re-create from the stub: + cp ~/dev/_shared/config/backup3/machines/mac-studio.conf.stub ~/.config/backup3/machines/ + # fill in real values (drive UUIDs, categories) locally. NEVER commit them. diff --git a/config/backup3/backup3.conf b/config/backup3/backup3.conf deleted file mode 100644 index 4724303..0000000 --- a/config/backup3/backup3.conf +++ /dev/null @@ -1,39 +0,0 @@ -# backup3.conf — shared defaults for the three-location backup (all machines). -# Source: ~/dev/_shared/config/backup3/backup3.conf (Tangled-synced). -# Design: ~/dev/_shared/docs/BACKUP3-PLAN.md - -# --- X10 (archive) identity --- -X10_NAME="Crucial X10" -# UUID from: diskutil info "/Volumes/Crucial X10" -> Disk / Partition UUID -X10_UUID="7A471DF2-9F4E-474B-B236-068C7EABC006" -X10_ROOT="/Volumes/Crucial X10" -ARCHIVE_ROOT="$X10_ROOT/archive" - -# --- OneDrive (active cloud) --- -ONEDRIVE_ROOT="$HOME/Library/CloudStorage/OneDrive-Personal" - -# --- Size split --- -# Entries >= SIZE_THRESHOLD_MB go to X10; smaller go to OneDrive (per category policy). -SIZE_THRESHOLD_MB=500 - -# --- rsync --- -# exFAT-safe: no perms/owner/group, 2s timestamp window (exFAT mtime granularity), -# no xattr copy (avoids ._ AppleDouble sidecars). Never --delete (archive is sacred). -RSYNC_OPTS=( - -rt - --no-perms --no-owner --no-group - --modify-window=2 - --exclude=.DS_Store --exclude='._*' --exclude=.localized - --exclude=node_modules -) -# NOTE: CHECKSUM_MAX_MB was REMOVED 2026-08-16. It was passed to rsync as -# --max-size, which SKIPS (never transfers) files over the limit while -# --remove-source-files still deletes them from the source — silent data loss -# (4 .mov files, ~3.3GB). --checksum now applies to every file unconditionally. - -# --- Ledger --- -# sha256 recorded for moved files up to this size; larger files record size only. -LEDGER_HASH_MAX_MB=100 - -# --- X10 cleanup pass (report-only for duplicates in v1) --- -CLEANUP_CRUFT_PATTERNS=('._*' '.DS_Store' '.localized' 'desktop.ini' 'System Volume Information' 'Start.exe') diff --git a/config/backup3/drives.conf b/config/backup3/drives.conf deleted file mode 100644 index 7309d4f..0000000 --- a/config/backup3/drives.conf +++ /dev/null @@ -1,35 +0,0 @@ -# drives.conf — drive identities + migration map for the dedup drive backup -# (inventory.zsh / dedup-drive.zsh / backup-drive.zsh). Tangled-synced. -# UUIDs captured 2026-08-16 (reviewer, live diskutil); X10 UUID from backup3.conf. - -# --- Crucial X10 (archive destination) --- -X10_NAME="Crucial X10" -X10_UUID="7A471DF2-9F4E-474B-B236-068C7EABC006" -X10_ROOT="/Volumes/Crucial X10" - -# --- Crucial 2TB (media host, SOURCE; APFS, volume named "photos library iCloud") --- -SRC_NAME="photos library iCloud" -SRC_UUID="3E52F2FB-5556-4C94-B52F-1F7EAEE29321" -SRC_ROOT="/Volumes/photos library iCloud" - -# --- microSD-512 (migration source; ExFAT, WRITABLE — copy-only rule applies) --- -MICROSD_NAME="MicroSD-512" -MICROSD_UUID="9C4B1FB6-DD0A-3C37-A18B-A8A1A55CDD60" -MICROSD_ROOT="/Volumes/MicroSD-512" - -# --- Dest layout (DP-2 decided 2026-08-16): X10/backup// mirror --- -DRIVE_BACKUP_ROOT="$X10_ROOT/backup" -DRIVE_BACKUP_DEST="$DRIVE_BACKUP_ROOT/$SRC_NAME" - -# --- Migration mapping (user-decided 2026-08-16; all of microSD migrates) --- -# Format: microSD-relative|2TB-relative. P0 gate checks per-mapping equality. -MIGRATION_MAP=( - "Jellyfin|Media/Jellyfin" - "archive|Media/archive" - "QBT|QBT" - "stacher|stacher" - "Pictures|Pictures" -) - -# --- State dir (inventory TSVs, manifests, ledger; NOT on any drive) --- -DRIVE_BACKUP_STATE="${XDG_STATE_HOME:-$HOME/.local/state}/drive-backup" diff --git a/config/backup3/machines/mac-studio.conf b/config/backup3/machines/mac-studio.conf deleted file mode 100644 index 59f6563..0000000 --- a/config/backup3/machines/mac-studio.conf +++ /dev/null @@ -1,23 +0,0 @@ -# machine: mac-studio (Mac Studio 2022) — hostname "Mac-Studio-2022.localdomain" -# Per-machine overrides for backup3. Same schema as ole-blu.conf. -MACHINE_ID="mac-studio" - -# Category rules: name|source|onedrive_base|x10_base|always_x10 -# - always_x10=yes : whole category goes to X10 regardless of size -# - always_x10=no : per-entry size split (>= SIZE_THRESHOLD_MB -> x10, else onedrive) -# Targets get a per-machine subdir appended: ///... -CATEGORIES=( - "Music|$HOME/Music|$ONEDRIVE_ROOT|$ARCHIVE_ROOT|no" - "Pictures|$HOME/Pictures|$ONEDRIVE_ROOT|$ARCHIVE_ROOT|no" - "Documents|$HOME/Documents|$ONEDRIVE_ROOT|$ARCHIVE_ROOT|no" - "Desktop|$HOME/Desktop|$ONEDRIVE_ROOT|$ARCHIVE_ROOT|no" - "Movies|$HOME/Movies|$ONEDRIVE_ROOT|$ARCHIVE_ROOT|yes" -) -# ~/Downloads has bespoke routing in backup3.zsh (route_downloads): -# stacher/ -> X10/archive/stacher/mac-studio -# Media/ -> X10/archive/media/mac-studio -# Music/ -> OneDrive/Music/mac-studio -# *.dmg/pkg/exe/msi/iso/zip/tar/gz/tgz/bz2/xz/7z -> X10/archive/installers/mac-studio -# *.pdf -> OneDrive/Documents/mac-studio -# everything else -> size split: OneDrive/Downloads/mac-studio vs X10/archive/downloads/mac-studio -# (Studio Downloads is ~133G — the >=500MB size split sends most of it to X10) diff --git a/config/backup3/machines/ole-blu.conf b/config/backup3/machines/ole-blu.conf deleted file mode 100644 index 7038ae1..0000000 --- a/config/backup3/machines/ole-blu.conf +++ /dev/null @@ -1,22 +0,0 @@ -# machine: ole-blu (MacBook Air) — hostname "ole-Blu" -# Per-machine overrides for backup3. Same schema for mac-studio (see stub). -MACHINE_ID="ole-blu" - -# Category rules: name|source|onedrive_base|x10_base|always_x10 -# - always_x10=yes : whole category goes to X10 regardless of size -# - always_x10=no : per-entry size split (>= SIZE_THRESHOLD_MB -> x10, else onedrive) -# Targets get a per-machine subdir appended: ///... -CATEGORIES=( - "Music|$HOME/Music|$ONEDRIVE_ROOT|$ARCHIVE_ROOT|no" - "Pictures|$HOME/Pictures|$ONEDRIVE_ROOT|$ARCHIVE_ROOT|no" - "Documents|$HOME/Documents|$ONEDRIVE_ROOT|$ARCHIVE_ROOT|no" - "Desktop|$HOME/Desktop|$ONEDRIVE_ROOT|$ARCHIVE_ROOT|no" - "Movies|$HOME/Movies|$ONEDRIVE_ROOT|$ARCHIVE_ROOT|yes" -) -# ~/Downloads has bespoke routing in backup3.zsh (route_downloads): -# stacher/ -> X10/archive/stacher/ole-blu -# Media/ -> X10/archive/media/ole-blu -# Music/ -> OneDrive/Music/ole-blu -# *.dmg/pkg/exe/msi/iso/zip/tar/gz/tgz/bz2/xz/7z -> X10/archive/installers/ole-blu -# *.pdf -> OneDrive/Documents/ole-blu -# everything else -> size split: OneDrive/Downloads/ole-blu vs X10/archive/downloads/ole-blu diff --git a/docs/BACKUP3-PLAN.md b/docs/BACKUP3-PLAN.md index 88276bd..9cb0705 100644 --- a/docs/BACKUP3-PLAN.md +++ b/docs/BACKUP3-PLAN.md @@ -5,10 +5,11 @@ Owner: Patrick Singletary Canonical copy: `~/dev/_shared/docs/BACKUP3-PLAN.md` (Tangled-synced) Artifacts: - `bin/backup3.zsh` — the backup/move engine -- `config/backup3/backup3.conf` — shared defaults -- `config/backup3/machines/ole-blu.conf` — ole-Blu policy -- `config/backup3/machines/mac-studio.conf.stub` — Studio stub -- `launchd/com.psingletary.backup3.plist` — launchd agent template +- `~/.config/backup3/backup3.conf` — shared defaults (local, NOT in repo) +- `~/.config/backup3/machines/ole-blu.conf` — ole-Blu policy (local, NOT in repo) +- `config/backup3/machines/mac-studio.conf.stub` — sanitized Studio stub (only config kept in repo) +- launchd agent (installed at ~/Library/LaunchAgents/; template preserved + locally at ~/dev/_shared-local/launchd/, not in repo) --- @@ -113,8 +114,8 @@ Excluded entirely: ~/Library, ~/dev (git/Tangled), ~/.hermes, ~/.npm, ~/.cache, - Modes: dry-run (default), `--apply`, `--cleanup`, `--cleanup --apply`, `--status`, `--help` - Mount check: `/Volumes/Crucial X10` exists AND partition UUID matches - `7A471DF2-9F4E-474B-B236-068C7EABC006` (prevents acting on a wrong drive at that path) -- Machine: hostname-derived (ole-blu / mac-studio), loads `config/backup3/machines/.conf` + `` (prevents acting on a wrong drive at that path) +- Machine: hostname-derived (ole-blu / mac-studio), loads `~/.config/backup3/machines/.conf` - Verify-then-delete: rsync `-rt --no-perms --no-owner --no-group --modify-window=2 --checksum --remove-source-files` (checksum ALL files — see the max-size pitfall below; size+mtime was never a fallback) @@ -184,8 +185,8 @@ X10 content. Full plan + red-team review: `.hermes/plans/2026-08-16_135930-dedup-crucial2tb-x10.md` (+ `.review.md`). - Drives: microSD-512 (ExFAT, writable — copy-only rule), Crucial 2TB - ("photos library iCloud", APFS, UUID 3E52F2FB-...), X10 (UUID - 7A471DF2-...). Identity + migration map in `config/backup3/drives.conf`. + ("photos library iCloud", APFS, UUID ), X10 (UUID + ). Identity + migration map in `~/.config/backup3/drives.conf`. - Tooling: `bin/inventory.zsh` (+inventory_core.py, two-tier NUL-safe inventory), `bin/dedup-drive.zsh` (+dedup_core.py, hash-only join -> unique + skip manifests), `bin/backup-drive.zsh` (copy-only rsync diff --git a/plan.md b/plan.md index 37b7a23..1190414 100644 --- a/plan.md +++ b/plan.md @@ -1,15 +1,14 @@ # Mac Studio dev setup ## 1. SSH key for Tangled -ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519_tangled -C "studio@psingletary.com" -# Add ~/.ssh/id_ed25519_tangled.pub at https://tangled.org/settings (SSH keys) +ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519_ -C "" +# Add ~/.ssh/id_ed25519_.pub at https://tangled.org/settings (SSH keys) cat >> ~/.ssh/config <<'CFG' Host tangled.org User git - IdentityFile ~/.ssh/id_ed25519_tangled + IdentityFile ~/.ssh/id_ed25519_ IdentitiesOnly yes AddKeysToAgent yes - UseKeychain yes CFG ssh -T git@tangled.org # expect: "Hi @psingletary.com!" diff --git a/skills/productivity/project-bootstrap/scripts/hermes-porkbun-mcp.sh b/skills/productivity/project-bootstrap/scripts/hermes-porkbun-mcp.sh index f7165f8..67a353e 100644 --- a/skills/productivity/project-bootstrap/scripts/hermes-porkbun-mcp.sh +++ b/skills/productivity/project-bootstrap/scripts/hermes-porkbun-mcp.sh @@ -45,4 +45,7 @@ fi # ── Launch MCP server ────────────────────────────────────────────────────── -exec npx -y @porkbunllc/mcp-server \ No newline at end of file +# Pinning: @porkbunllc/mcp-server installed locally at ~/scripts/porkbun-mcp/ +# (version pinned in package.json + package-lock.json). NEVER use npx -y — +# resolve-at-launch pulls the latest published package (supply-chain risk). +exec node "$HOME/scripts/porkbun-mcp/node_modules/@porkbunllc/mcp-server/dist/index.js" \ No newline at end of file -- 2.51.2