Commit Graph
65 Commits
Author SHA1 Message Date
pastilhasandClaude Opus 5 0e893cc292 scripts: stop creating the /usr/local/bin/claude symlink
The symlink existed because the Claude sidecar hardcoded that path, and that
hardcoding came from the bwrap-sandboxed architecture: the jail ro-bound /usr
and could not see the installer's real target in ~/.local/bin. The sandbox is
gone, and claude-manager.ts now resolves the CLI itself — $CLAUDE_BIN, then
PATH, then ~/.local/bin/claude, /usr/local/bin/claude, /opt/homebrew/bin/claude.

Verified before removing rather than assumed:

- the only references left in the tree are the resolver's own fallback list and
  this step; nothing in capabilities, no systemd unit, no crontab, no ecosystem
  file and no shell rc mentions the path
- the agent sidecar's PATH under pm2 contains ~/.local/bin ahead of
  /usr/local/bin, so Bun.which resolves to the installer's target and the
  symlink is never consulted
- replaying the resolver in that exact environment with the symlink treated as
  absent returns the same path, so it is not load-bearing
- resolveClaudeBin runs at claude-manager module scope, which ES import ordering
  puts before user-instance.ts reassigns process.env.HOME — so the homedir()
  candidate is evaluated against the real home, not the managed one

The install-and-verify step above is untouched, so a failed claude-code install
is still reported. Only the sudo-owned link into /usr/local/bin goes, a
directory macOS does not ship at all.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-04 12:22:16 +00:00
pastilhasandClaude Opus 5 6b50ad978e merge the macos branch: setup script, mac pm2 ecosystem, claude binary resolution
Three files, all additive — nothing on master is modified by this beyond the
CLAUDE_BIN change below, and no file is deleted. The branch predates master by
about 180 commits, but it touches nothing master has touched since, so the
merge is clean.

The part that matters beyond macOS is claude-manager.ts. CLAUDE_BIN was pinned
to /usr/local/bin/claude, which dated from the bwrap-sandboxed architecture:
the jail ro-bound /usr and saw nothing else, so the installer's real target
(~/.local/bin/claude) had to be symlinked somewhere the sandbox could reach.
That sandbox is gone, and the hardcoded path left the sidecar unrunnable on any
host without it. It now resolves an explicit CLAUDE_BIN pin, then PATH, then the
locations Anthropic's installer actually writes to — mirroring how OPENCODE_BIN
is already resolved in the opencode sidecar.

ecosystem.mac.config.cjs is deliberately a trimmed set of processes rather than
a mac port of the full ecosystem. It is also stale in two specific ways, left
as-is here and worth fixing separately: it names officer-claude, which master
renamed to officer-anthropic-proxy, and its officer-pty runs
src/servers/api/terminal/pty-sidecar.mjs, which moved to
src/servers/sidecar/pty/index.mjs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-04 13:01:26 +01:00
pastilhasandClaude Opus 5 a8335bfdd6 scripts: validate the sudoers entry before installing it
The setup wrote /etc/sudoers.d/officer-service with tee and then chmod'd it.
Two problems, both with the same worst case: a malformed or wrongly-permissioned
file there breaks sudo completely, and you cannot sudo to repair it — on a
remote machine that means physical access or a rescue boot.

Generate into a temp file, gate on `visudo -c`, and only then install. Use
install(1) rather than tee+chmod so the content and the 0440 mode land in one
step; tee creates at the default umask first, and sudo refuses to read a sudoers
file with loose permissions, so the old ordering had a window where sudo could
reject its own configuration.

The re-run guard also grepped for the username anywhere in the file, so a
comment mentioning it counted as configured. Match the actual rule instead.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-04 11:34:33 +00:00
pastilhasandClaude Opus 5 593bcc1575 scripts: make setup.sh converge instead of trusting proxies
Two guards that checked something other than the state they were protecting.

Section 17 skipped the entire remote desktop setup when `dpkg -s ubuntu-desktop`
succeeded, treating one package being present as proof that seven steps of
configuration had run. A host can have ubuntu-desktop and still be missing GDM
auto-login, the forced Xorg session, the captured EDID and its kernel command
line, and the login-time mode setter — which is exactly what this machine was
on 2026-08-02, while the guard cheerfully reported "skip". setup-desktop.sh is
idempotent throughout, so the guard bought nothing and cost a converged host.

The starship step had the opposite bug: it cp'd over ~/.config/starship.toml on
every run, so a customised config was silently destroyed. The nvim step two
sections down already guards on its config's existence; this now matches, and
distinguishes "absent" (deploy) from "identical" (skip) from "yours differs"
(keep, and say how to take ours).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-04 11:32:14 +00:00
pastilhasandClaude Opus 5 16f5175205 scripts: rewrite the desktop teardown for the mirror-based setup
cleanup-desktop.sh still described the era when Officer installed a desktop of
its own — XFCE on a TigerVNC Xvnc — so tearing the remote desktop down meant
deleting a desktop nobody else used. That stopped being true when the setup
moved to mirroring the machine's existing session with x11vnc, and the script
was left actively dangerous: it purged dbus-x11 and Brave, deleted ~/.vnc, and
reinstalled gnome-keyring, all of which the current GNOME setup depends on or
deliberately removes. Running it today broke the desktop rather than cleaning
it up.

Rewritten as the actual inverse of setup-desktop.sh:

- removes what Officer added — x11vnc, ~/.vnc, the GDM auto-login and forced
  Xorg keys, the forced EDID and its kernel command line, the login-time mode
  setter, the legacy officer-vnc unit, the VNC entries in .env
- keeps ubuntu-desktop, gdm3 and dbus-x11, which are the machine's own desktop
  and not Officer's to delete
- still purges XFCE and TigerVNC when present, since a host set up by the older
  script carries them and they are precisely what this undoes
- Brave is opt-in behind --purge-brave: setup installs it, but by teardown time
  it is usually just the user's browser with their profile in it

The GRUB and GDM edits were checked against copies of the real files: stripping
the EDID parameters leaves other kernel arguments intact wherever they sit in
the line, and the GDM revert does not disturb the commented examples that ship
in custom.conf. The package matcher names each xfce-family prefix rather than
globbing '^libxf', which would have taken libxfixes, libxft and libxfont with it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-04 11:02:16 +00:00
pastilhasandClaude Opus 5 67d6a9702a scripts: name the desktop setup for what it installs
Section 17 was still labelled "XFCE + VNC" while the step it runs installs
ubuntu-desktop and is guarded on it, so the heading described a setup the
script had already stopped producing.

Also spell out why setup-desktop.sh disables lightdm: it is not a display
manager this script ever installs, it is residue on hosts set up by an earlier
version that did install XFCE, and left enabled it beats GDM to the seat.

Comments and one echo string; no behaviour change.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-03 00:32:27 +00:00
pastilhasandClaude Opus 5 a83f9cd378 delete the orphaned build script, and fix the second copy of the memo rule
scripts/build/runtime.ts had no caller after the build:editor scripts went. Its own usage
text gives away where it came from: --experiments, --tracking, --editor-setup, the same
phantom domain as the docs and examples cleaned up earlier. Nothing else references it —
the `./runtime` export in src/workspaces/types/package.json points at a different file,
which is untouched. helpers.ts stays; dashboard.ts and web.ts import it.

APP_CONVENTIONS.md carried its own copy of "React 19's compiler handles memoization. Never
use useCallback or useMemo." Correcting only CONVENTIONS.md would have left the two
contradicting each other, which is worse than either. Both now say the same thing and one
points at the other for the reasoning.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-31 18:12:19 +00:00
pastilhasandClaude Opus 5 af56eb36ff email: move the mail store and every route into the sidecar
Email was the one sidecar built inside out. The platform held ~1,800 lines — the per-account
SQLite store, all 14 HTTP routes, account CRUD, resync, IMAP validation — while the 314-line
sidecar was a scheduler that reached BACK into the platform to do anything
(`import { performResync } from '../../api/email/resync'`).

The sidecar now serves its own HTTP listener and announces `email:server`, and
/api/email/* on the platform is createSidecarProxy like every other one: 1,801 lines down
to 22, with no mail knowledge left in it — not a message, not a folder, not a credential.

The routes moved verbatim, Hono and all. http.ts only reconstructs what the platform's
middleware used to provide: `user` on the context, from the X-Officer-User header the proxy
injects (trusted because this server binds loopback), and an error handler that turns
custom-errors into status codes.

The /email/events SSE stream went with them, which removes a whole round trip: the IDLE
watcher used to send `email:new` over the registration socket so the platform could push to
its SSE clients. Those clients are here now, so it calls broadcastEmailNew in-process and
`email:new` is gone from the wire protocol.

DELIBERATELY NOT DONE YET, and left backwards on purpose rather than half-moved:

- The two sync handlers (email-sync 381 lines, gmail-sync 712) still run in the platform's
  queue and now import the store from its new home — a platform → sidecar import, which is
  the wrong direction and is temporary. Moving them is option (A) from the plan: the sidecar
  schedules its own syncs, independent of the platform Jobs list.
- accounts.ts still imports queue/init to enqueue a sync and to report sync status, and
  index.ts still carries the queue-over-WS shim that inversion needs.
- The three channel handlers still open the mail store directly rather than asking over HTTP.

Two things worth knowing while testing: a from-scratch sync holds a proxied request open
well past the 60s idle default, hence timeoutSeconds on the proxy; and `gmail-sync` is
hardcoded in all three channel handlers even though the only account is provider=gmail with
auth_type=password, which routes to IMAP — so "sync emails" from a chat channel is
almost certainly already broken, and folds into the next stage.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-31 12:10:35 +00:00
pastilhasandClaude Opus 4.8 1159c0787d soulseek: render cached shares as a tree, not a path list
slskd's browse response is flat: every folder is a full backslash-delimited
path. Rendered as-is, a filter for "pogues" gave 26 rows that all began with
the same 31 characters, and the real hierarchy — which is the only way to tell
an artist folder from an album folder — was invisible.

The shape is now derived once, at ingest, in the sidecar: buildTree() links
each path to its parent, synthesizes any ancestor slskd omitted (measured:
exactly one missing across ~30k folders on two real peers, but a single gap
would strand a whole subtree), and rolls subtree file counts and sizes up
bottom-up. A parent's own files are usually just cover art, so the number
worth showing on a collapsed row is the subtree's.

Storing the shape rather than recomputing it is what lets the UI open one
level at a time. Levels are still paged, because fan-out is brutal — the
widest folder measured has 1,181 children.

Filtering keeps the tree instead of falling back to a list: the search route
returns matches plus every ancestor, and the UI renders that skeleton
pre-expanded, so you see where a hit lives. Matching runs against the whole
path, so a matched folder implies its descendants match too and a matched
subtree arrives complete. The match cap is reported in the payload and shown
in the UI rather than passed off as the whole answer.

The two existing snapshots were backfilled by scripts/rebuild-soulseek-tree.ts,
which runs the same buildTree + finishSoulseekBrowse the ingest path runs — no
second implementation to drift, and no peer contact needed. Kept for the next
time the tree shape changes.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-30 01:05:22 +00:00
pastilhasandClaude Opus 5 35142df5a7 add a macos setup script and a trimmed pm2 ecosystem
setup.sh targets an ubuntu server and is left untouched. this is the
laptop equivalent: file browser, claude/opencode chat, terminal. no go,
rust, cliamp, pulseaudio, neovim, shell dotfiles, vnc desktop, sudoers
grant or power management — 510 lines against 1033.

every step is optional, prompted, and presettable non-interactively with
SETUP_* variables, so it also works as a repair tool for one piece.

nothing calls sudo. node@22 goes on PATH with brew link --force, pm2 into
~/.local, and the claude cli no longer needs a /usr/local/bin symlink now
that the sidecar resolves it.

postgres is detected before anything is installed — a server already
listening on 5432 (docker) is used as-is.

notes on the differences from setup.sh:
- set -e is on, but every optional step is guarded, so a failure warns and
  the run continues to a summary instead of aborting mid-way.
- .env is written 0600 and the generated JWT_SECRET is length-checked
  before use, since jwt.ts throws on anything under 32 chars.
- PUBLIC_BUILD_ENV=development, which is what lets plain http://localhost
  work with no reverse proxy in front.
- xcode command line tools are not required to build: node-pty and argon2
  both ship darwin prebuilds. they still matter for git on a fresh mac.

ecosystem.mac.config.cjs drops officer-vnc (x11vnc needs xorg),
officer-email and officer-music, and pins cwd on every app so bun picks
up .env wherever pm2 is started from.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-28 14:15:01 +01:00
pastilhasandClaude Opus 4.8 9bf9b708cb reindex-music: show discography count in the report
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-26 09:40:58 +00:00
brunorezioandClaude Opus 5 592cc72f85 setup-desktop: configure the headless display
x11vnc mirrors :0, but with no monitor attached the connector has no EDID and no
CRTC, so GNOME renders nothing and the remote desktop is black. Reproduced the
hard way on this box: the desktop only worked because the session had started
while a screen was plugged in, and survived exactly until the next restart.

The step captures a connected monitor's EDID, installs it as
drm.edid_firmware with video=<connector>:1920x1080e so the connector reports
permanently attached, and adds a login-time hook to raise the resolution — the
replayed EDID's *preferred* mode is the captured panel's native one, which can be
tiny, and GNOME picks preferred. monitors.xml is the documented override but its
monitor matching did not take.

The EDID can only be captured from a screen that is plugged in, so a headless run
skips with instructions rather than pretending to succeed. Re-running is safe:
GRUB is left alone once the argument is present, and the mode setter no-ops when
the mode is already right.

officer-set-display.sh discovers the output and the largest mode within a cap
rather than hardcoding either, since setup runs before X exists and cannot know
them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-26 06:02:10 +01:00
brunorezioandClaude Opus 5 02662fc780 setup.sh: actually start the services, and verify they are running
setup.sh installed pm2 but never ran anything with it, so a fresh install
finished with every dependency in place and nothing listening. That is not
cosmetic: /desktop returns 503 until officer-vnc is connected, and chat needs
officer-claude.

Adds a step that runs `pm2 startOrRestart ecosystem.config.cjs`, saves the
process list, and enables the boot unit when it is not already there. Using
startOrRestart rather than start means apps added to the ecosystem since the last
run get picked up — officer-music is in the ecosystem on this box but was never
running, for exactly that reason.

The verification block now reports which services are up, with the names read
from ecosystem.config.cjs so the list cannot drift as sidecars are added.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-26 05:19:27 +01:00
brunorezioandClaude Opus 5 7556c9ed00 fix /desktop: break the VNC password deadlock, drop the vncpasswd dependency
The desktop page has never worked on a fresh install. Two faults, both fatal.

The password could never be created. DesktopView fetches /desktop/vnc-password
before opening the WebSocket, but ensureVncPassword ran only from startSession,
which only the WebSocket triggers — so the endpoint answered "not configured",
the UI stopped, and the socket that would have provisioned it was never opened.
A new vnc:ensure-password sidecar command provisions it directly; the endpoint
asks for it instead of returning 500.

The rfbauth file could never be written either. ensureVncPassword shelled out to
tigervnc's `vncpasswd -f`, which is not installed — and, contrary to the comment
in setup-desktop.sh, is not in tigervnc-common, which ships only tigervncconfig.
The failure was swallowed because only a zero exit wrote the file, so x11vnc got
-rfbauth pointing at nothing. x11vnc writes that format itself with -storepasswd,
so the dependency is gone and a failure now throws.

Verified on the box: the endpoint returns a password, .vnc/{passwd,password} are
written 0600, and the sidecar reports mirroring :0 on 5900 with x11vnc using the
generated rfbauth file.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-26 05:15:46 +01:00
pastilhasandClaude Opus 4.8 6224f6be51 music: SSE reindex progress stream + reindex-music CLI
Adds a live progress channel for the library index:
- indexer.ts: progress subscribers (onIndexProgress) + throttled emit during the
  walk, and buildReport() for a final summary.
- sidecar: GET /reindex/stream (SSE) — triggers a build if idle (?trigger=0 to
  watch only), streams `progress` events, ends with a `done` event carrying the
  report; auto-proxied at /api/music/reindex/stream for the app. Sidecar also
  writes DATA_PATH/music/.server (its port) for local tooling.
- scripts/reindex-music.ts: CLI that reads the port file, follows the SSE, prints
  live progress + a final report. Run: bun scripts/reindex-music.ts

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-26 03:18:41 +00:00
brunorezioandClaude Opus 5 1d0842cc01 setup.sh: generate index.gen.html and apply the schema
A fresh clone has neither: index.gen.html is gitignored and built from
PUBLIC_URL, and the database schema is applied with push rather than migrations.
Without both, setup finishes on a checkout that cannot serve a page or reach a
table.

Runs after .env is written, since both depend on it. Failures warn rather than
abort so the rest of the verification still reports.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-26 01:49:17 +01:00
brunorezioandClaude Opus 5 52ddf7df0e generate index.html's absolute URLs from PUBLIC_URL
index.html hardcoded the deployment's domain in eight places, so every instance
had to carry its own edit of the file — the only thing separating the rezio
branch from master.

The tags genuinely need absolute URLs. OpenGraph is fetched standalone by
crawlers, and Bun's HTML bundler treats a root-relative href as an asset to
resolve on disk, failing the build with "Could not resolve: /favicon.ico" —
external URLs are the only form it passes through untouched.

Bun's HTML import offers no substitution hook, so scripts/gen-index.ts swaps
__PUBLIC_URL__ for the value in .env and writes index.gen.html, which the server
imports. index.html is the tracked template and is now identical on every
deployment; index.gen.html is gitignored. predev/prestart run the generator, and
it is idempotent so --watch does not loop.

Substituting also fixes the manifest: an absolute URL puts its fetch in CORS
mode, which failed whenever the hardcoded domain was not the serving origin.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-26 01:49:17 +01:00
brunorezioandClaude Opus 5 044aacf4d5 remove the dead multi-user surface
Officer is single-user: the server owner is the only account, created once by
/auth/bootstrap. Everything that existed to serve additional users was
unreachable, so it is gone rather than left looking like it does something.

Accounts: drop the invite / resend-invite / delete / list-users routes and the
Users settings screen, the inert /auth/signup handler, and the account
verification chain it fed (verify, resend-verification, VerifyScreen, the
UserInvite + VerifyAdmin + VerifyRegistration templates). /auth/verify-token
survives for password resets only, and now requires a reset-password token
rather than accepting any signed JWT.

Roles: drop the users.role column and the four-value USER_ROLES enum. The
permissions table granted every role identical methods, and every
role === 'Super Admin' check was permanently true. The JWT no longer carries a
role claim.

Sandbox: remove sidecar/sandbox.ts and its five call sites. bwrap was selected
only for non-Super-Admin users, so it never ran. It was also not a usable agent
jail as written — --share-net, the project root (with .env) bound read-only,
and runuser dropping to the server's own uid. Rebuilding it for agent
containment would be a different construction, and git history keeps this one.

getHomeDir keeps its DATA_PATH meaning; the new getOwnerHomeDir resolves the
owner's real login home, which is what terminals, chats and task runs use.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-25 23:30:20 +01:00
pastilhasandClaude Opus 4.8 92de996412 setup.sh: symlink claude into /usr/local/bin
The Claude sidecar execs /usr/local/bin/claude (claude-manager.ts), but the
Anthropic installer only puts the CLI in ~/.local/bin — so on a fresh host that
path doesn't exist and claude chat fails with
"ENOENT … posix_spawn '/usr/local/bin/claude'". Symlink ~/.local/bin/claude →
/usr/local/bin/claude after install (idempotent; tracks Claude's self-updates).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-25 17:22:26 +00:00
pastilhasandClaude Opus 4.8 f226542de3 setup.sh: prompt for OFFICER_ITEMS_DIR in .env generation
The item store location wasn't written to .env, so a fresh server fell back to
<repo>/officer-items and booted with an empty store. Prompt for it (default: a
sibling of the repo) and write it to .env.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-25 16:45:59 +00:00
pastilhasandClaude Opus 4.8 f7b8cbe3f3 setup-desktop: install tigervnc-common for vncpasswd
The VNC sidecar builds its .vnc/passwd rfbauth file with `vncpasswd -f`
(vnc-manager.ts) — x11vnc alone doesn't ship vncpasswd. The GNOME-on-Xorg
rewrite dropped tigervnc, so the mirror couldn't create its password and
/desktop failed with "VNC password not configured". Add tigervnc-common back.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-25 16:26:31 +00:00
pastilhasandClaude Opus 4.8 1e789b4c44 setup: Ubuntu GNOME-on-Xorg desktop + setup.sh hardening
setup-desktop.sh now installs ubuntu-desktop + gdm3 + x11vnc and forces the
Xorg session (WaylandEnable=false) with auto-login — x11vnc can only mirror an
Xorg :0, not Wayland. vnc-manager.ts resolves the X authority from the GDM
per-session path (/run/user/<uid>/gdm/Xauthority) with a ~/.Xauthority fallback.

setup.sh fixes:
- desktop step gates on `dpkg -s ubuntu-desktop` (was the decommissioned
  officer-vnc service, which never matched so setup-desktop re-ran every time)
- remove Pi (install, --list-models validation, verification check)
- export GOPATH before the cliamp build so `go install` lands where it's checked
  even when Go was already present this run
- write PUBLIC_BUILD_ENV=production and quote all .env values
- guard the interactive .env block behind a TTY check so non-interactive runs
  skip cleanly instead of aborting on read EOF under set -e
- restart systemd-logind only when a key actually changed
- sed prefix-strip instead of `tr -d` (which deletes characters, not a prefix)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-25 15:32:28 +00:00
pastilhasandClaude Opus 4.8 33a0bb4578 email: store emails.db per account under email_accounts/<account>/
Reorganizes email storage: the DB moves from DATA_PATH/<user>/emails.db to
DATA_PATH/<user>/email_accounts/<accountEmail>/emails.db, with a shared
email_accounts/attachment_cache/ (was Gmail/emails/attachments). openEmailDb now
takes (owner, account); a new openUserEmailDb(owner, userId) resolves the user's
configured account (first enabled) for read paths. Threads the account through
email.ts, accounts, resync, queue sync, channel handlers, and the email_db MCP
tool path. Drops the dead getUserEmailDir helper.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 13:34:29 +00:00
pastilhasandClaude Opus 4.8 f3492512ba unify agent items into a flat file-based store, drop the marketplace
Replace the marketplace service dependency and the native/global/user
scope tiers with a single external directory ($OFFICER_ITEMS_DIR) holding
skills, tools, tasks, processes and extensions as plain files.

- tasks move from Postgres to TASK.md files (new file-backed task layer);
  task editing now works, which the DB path never supported
- skills/tools/processes collapse into one shared file router (single dir)
- remove the marketplace client (sync-marketplace/sync-version) and the
  boot-time sync; pi-bridge/pi-manager/sandbox point at the flat store
- drop the dead tasks + vestigial skills/tools/processes/extensions +
  item_chats tables (migration 0004)
- one-time migration script exports DB tasks and consolidates disk items

Migration verified: all 6 tasks round-trip through the runtime parser
identically to their DB rows (pipeline steps, triggers, script impls and
agentic bodies all intact).

NOTE: not yet functionally tested end-to-end — every item (each task mode,
tool, skill, extension) still needs to be run/exercised in the app before
this is trusted. To be done manually.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 00:39:17 +00:00
pastilhasandClaude Opus 4.6 24ac7ac796 replace gmail resync with Gmail REST API, remove mbsync dependency
First sync still uses IMAP with app password. Subsequent syncs use
Gmail API history.list + messages.get with OAuth for faster, more
reliable incremental sync. Dispatch gmail-sync handler for gmail
accounts instead of generic email-sync. Show sync button for synced
accounts.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-12 07:24:44 +00:00
pastilhasandClaude Opus 4.6 ea31014d72 user-local installs for claude and pi, fix sandbox mounts
Move claude and pi from sudo global installs to ~/.local. Claude
binary is copied to /usr/local/bin for sandbox visibility, pi runs
via node from ~/.local/lib (ro-mounted). Fix bwrap intermediate dir
traversal by setting 0755 perms on auto-created HOME dirs.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-08 01:08:45 +00:00
pastilhasandClaude Opus 4.6 56f8da8907 remove seed directory, clean up provisioning and sync modules
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-08 00:07:50 +00:00
pastilhas 6c4595279a fine tuning 2026-03-07 00:52:20 +00:00
pastilhasandClaude Opus 4.6 d88fe3cac7 task logs: migrate from filesystem to postgresql; refactor sidecars into submodules
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 11:49:39 +00:00
pastilhasandClaude Opus 4.6 daf5580c39 vnc sidecar: per-user desktop sessions via sidecar architecture
replaces the single hardcoded systemd VNC service with a dynamic
sidecar that manages per-user VNC sessions on demand. any authenticated
user can now access their own desktop, not just Super Admin.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 10:49:53 +00:00
pastilhas 6cfa40bad1 Merge remote-tracking branch 'origin/email-imap' 2026-03-06 07:27:45 +00:00
pastilhasandClaude Opus 4.6 7bbcccabf1 wip: remove opencode, searxng, resources; fix user settings read
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 07:27:19 +00:00
pastilhasandClaude Opus 4.6 170bd6d41b wip: email sync via imap with status tracking and auto cron
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 04:57:30 +00:00
pastilhasandClaude Opus 4.6 28f5cefb5b gmail sync: locale-agnostic folder mapping and import all mail
[Google Mail] locale variant was not matched by hardcoded [Gmail] paths,
so Sent/Starred/Important/Drafts were never labeled. All Mail was skipped
entirely, losing ~9k archived emails. Now normalizes the prefix, imports
everything with proper labels, and processes All Mail last so specific
folder labels take priority.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 09:29:22 +00:00
pastilhasandClaude Opus 4.6 b7a017d8e2 docker compose setup and .env generation in monorepo scripts
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 04:23:49 +00:00
pastilhasandClaude Opus 4.6 e966a71180 isolate user data with personal group ownership
- chown user dirs to pastilhas:<username> instead of pastilhas:officerdev
  so users cannot access each other's data
- chmod 2770 (setgid) gives only the owning user terminal access
- setup.sh: ensure home dir is traversable (o+x) for provisioned users

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 02:44:44 +00:00
pastilhasandClaude Opus 4.6 3df47bb48d shared group provisioning, upload context menu, go path fix
- provision linux users with pastilhas:officerdev ownership so server
  can always read/write, terminal users get group access
- add officerdev shared group setup to setup.sh
- move go install to ~/.local/go with GOPATH at ~/.local/go-path
- add upload file/folder items to file browser context menu

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 02:34:38 +00:00
pastilhasandClaude Opus 4.6 451a61afb4 fix cliamp panel header, home dir lookup, and go install path
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 01:30:15 +00:00
pastilhasandClaude Opus 4.6 aa0207436c improve gmail sync: email input, permanent errors, auto-dock
- add isync to setup.sh
- ask for gmail address alongside app password in integrations
- add PermanentError to job queue (skips retries for non-recoverable failures)
- use PermanentError for missing credentials, missing executable, auth failures
- auto-add /email to dock after successful gmail sync
- invalidate dock cache on sync completion for seamless UI update

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-04 23:13:55 +00:00
pastilhasandClaude Opus 4.6 4c2e40a46b install yt-dlp via pip instead of apt for latest version
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-04 20:13:51 +00:00
pastilhasandClaude Opus 4.6 d5245e5418 read vnc password and port from user home instead of env vars
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-04 19:59:59 +00:00
pastilhas ebebac0114 better startup scripts 2026-03-04 18:11:33 +00:00
pastilhas ba36629cdc better startup scripts 2026-03-04 18:05:50 +00:00
pastilhas 3249378984 revert: use chmod 770 instead of 775 for user directories
770 (rwxrwx---) is more secure - only owner and group can access, excluding 'others'.

The service user can still access because it's added to the user's group via:
  usermod -aG shellUsername serviceUser

The real fix was wrapping chmodSync in try/catch in email-db.ts so it doesn't
crash when trying to chmod files owned by other users.
2026-03-04 02:59:56 +00:00
pastilhas e43f738a52 fix: update provision-existing-users.sh to use chmod 775 (was 770)
Consistency fix with src/servers/api/users/provision.ts which was updated to use:
- chmod 775 (rwxrwxr-x) instead of 770 (rwxrwx---)
- Recursive chmod to fix all subdirectories

This allows the service user (in the user's group) to read/write files
for background jobs like email sync.

Also added helpful comment explaining the permission choice.
2026-03-04 02:59:06 +00:00
pastilhas 698c1ff297 feat: disable auto-suspend in setup.sh for server environments
- Mask sleep.target, suspend.target, hibernate.target, hybrid-sleep.target
- Configure systemd-logind to:
  - Ignore lid switch events
  - Ignore power key presses
  - Disable idle action
  - Set runtime directory size
- Restart systemd-logind to apply changes

Servers running Officer shouldn't go to sleep when idle.
This prevents unexpected suspends during setup or normal operation.
2026-03-04 02:45:33 +00:00
pastilhas e521d8214f fix: configure npm prefix to /usr/local for system-wide package access
- Set npm prefix to /usr/local (system location) instead of user-specific ~/.npm-global
- Ensures all users can access installed npm packages
- Fixes issue where packages installed to one user's home directory
- All npm global packages now available system-wide to all users

This ensures that after running setup.sh:
- pi, claude, and other tools are at /usr/local/bin/
- Accessible to all users (pastilhas, andrepadez, etc.)
- New users automatically get access too
2026-03-04 02:38:18 +00:00
pastilhas a8976ad8fb improvement: use explicit system npm path to avoid nvm conflicts
- When installing global npm packages, explicitly use /usr/bin/npm
- Falls back to $(which npm) if system npm not found
- Ensures packages go to system location, not nvm location
- Works around nvm PATH interference during setup
2026-03-04 02:16:07 +00:00
pastilhas b1af3ede47 fix: add missing fail() function in setup-pty-sidecar.sh
- Added RED color constant
- Added fail() function definition
- Fixes 'fail: command not found' error during setup
2026-03-04 02:15:49 +00:00
pastilhas c9560c27c7 fix: remove duplicate else block in npm packages section
Fixes syntax error: 'syntax error near unexpected token else'
The npm global packages section had a duplicate else block.
2026-03-04 02:15:03 +00:00