pastilhas e930586878 plugins declare the host binaries they need, and the installer checks
Offscale was self-sufficient. Music is not — it shells out to ffmpeg and
ffprobe — and the way it fails without them is the reason this is a check
rather than a line in a README.

It does not fail. Missing ffprobe means the indexer catches the spawn error
and returns a track carrying its filename and nothing else: no title, artist,
album, duration or embedded lyrics. It then walks the whole library, writes a
complete cache tree and reports success. Five swallowed catches, no log, no
counter, and the only tell is coversSaved: 0 in a report nobody reads.

So `osDependencies` is a manifest field: the binary to probe on PATH, why it
is needed, and a package name per package manager. The shape is taken from
scripts/setup-old/setup.sh rather than invented — probe the binary, case on
$PM — and the names are per-manager rather than canonical-with-overrides
because lib/packages.sh already recorded why that indirection was rejected.
Probing the binary is what makes "built-in on this OS" free: on PATH means the
package map is never consulted.

Four decisions worth naming.

Missing and uninstallable REFUSES the install, first, before a table is
created or a row written — so there is nothing to undo, and the alternative is
a plugin that installs, answers 200 and quietly produces nothing.

The status is on GET /api/plugins and rendered before the button, because the
owner is deciding whether to let the server run a package manager as root and
that needs answering first. Installing by hand and watching it flip to present
is the escape hatch on a machine without passwordless sudo.

Package names get a deliberately narrow regex and reach Bun.spawn as an argv
ARRAY, never a shell. Both halves are load-bearing: the regex means a
metacharacter cannot get there, argv means it would be an argument rather than
syntax if it did. Narrower than package managers actually accept — no `:`, no
`+` version pins — because a plugin needing one wants a conversation.

Success is OBSERVED, not inferred: after installing, the binaries are re-probed.
A package manager exiting 0 having installed something that does not provide
the binary is exactly the failure this exists to catch.

installCommand mirrors lib/packages.sh's pkg_install_now exactly, including
apt's non-interactive environment, so there is one definition of "install a
package" rather than two that drift. sudo always gets -n: under PM2 a password
prompt is not a slow path, it is a hang. brew never escalates.

Verified live. ffmpeg and ffprobe were absent on this machine all evening; the
page showed both missing with the exact root command, the install streamed
`dependencies: installing ffmpeg with apt` then `ffprobe, ffmpeg now on PATH`,
and X-Audio-Duration appeared on a stream response for the first time. The
refusal path was exercised against a temporary probe dependency: HTTP 400,
steps: [], reason named.

THIS CHANGED THE MACHINE: ffmpeg 6.1.1-3ubuntu5 is now installed via apt.

Found on the way: a manifest is read once per process. Discovery does
`await import()` and the module cache holds it, so editing a manifest changes
nothing until pm2 restart officer — including `outdated`. Cost ten minutes and
is now in the runbook.

bunx tsgo clean. 797 tests, 787 pass, 7 fail — the same seven, +25 new.
2026-08-15 02:33:18 +00:00
2026-02-16 19:34:35 +00:00
2026-02-16 19:34:35 +00:00
2026-02-16 19:34:35 +00:00
2026-02-22 03:35:26 +00:00
2026-02-16 19:34:35 +00:00
2026-02-16 19:34:35 +00:00

The documentation, triaged

2026-08-13. A map of what is in here, what it is for, and what should happen to it. Made because there are 42 documents and 13,000 lines, and no way to tell from the filenames which describe the system as it is and which are a record of an afternoon in July.

How much I verified: the classifications below are from filenames, status lines, and greps for things that changed on 2026-08-13. Where I actually read the document or checked the code, it says so. The rest is a starting point for a conversation, not a verdict.


Living — these describe the system and must stay true

doc state
working-on-officer.md updated 2026-08-13. Operational guide.
secret-store.md updated 2026-08-13. Built; rotation still open.
install-variants.md new. The branch tree, for discussion.
http-secure-context-audit.md new. What breaks over plain http.
install-container-testing.md new. First container pass and its findings.
per-user-linux-accounts.md partly updated. OFFICER_OS_USERS is gone; check the rest.
navigation-audit.md authoritative on routing. Unverified against tonight's route removals.
workspace-panels.md + workspace-panel-todo.md the panel framework. 1,300 lines combined — likely the biggest cleanup here.
agent-coordination.md the north star for panel work.
deprovision-os-account.md implemented; the 'disabled' stage it may mention was deleted tonight.

Stale — describe things that changed on 2026-08-13

Each of these references something that no longer exists. Not yet corrected.

  • sidecar-topology.md — "ecosystem.config.cjs is the source of truth". It is generated now, and holds six processes.
  • sidecar-app-store.md — derives the catalogue from full light. Those files are gone, and catalogue.test.ts was rewritten.
  • sidecar-bootstrapping.md — "20 PM2 entries, 18 sidecar dirs". Six entries now.
  • mobile-api-keys.md — partly corrected; recheck the origin-checking claims.
  • wallet-key-custody.mdVAULT_STORE_KEY is now the per-purpose wallet key.
  • push-notifications.md — "agreed design, 2026-07-31". Notify is a plugin and unmounted.
  • chat-session-lifetime.md, chat-ui-walkthrough.md — reference officer-agent, renamed.

Historical — a record of a moment, and should stay one

Do not rewrite these to match today's code. They document how a decision was reached, and editing them destroys the reasoning. If they mislead, add a dated header pointing forward.

  • sidecar-audit-2026-07.md (1,377 lines)
  • claude-sidecar-isolation.md — records the officer-claudeofficer-agent rename that preceded tonight's officer-agentofficer-claude-code
  • open-threads-after-per-user-claude.md
  • two-agent-field-report-2026-08-12.md
  • api-method-changes-2026-08-06.md

The opencode cluster — nine documents for one migration

opencode-fork-decision · -parity · -api-2-assessment · -phase0-review · -phase1-report · -phase1-review · -serve-migration-plan · -serve-path · -testing-checklist

The migration landedopencode serve is in the sidecar, verified. So opencode-serve-migration-plan.md saying "Nothing here is implemented" is false.

This is the clearest consolidation candidate in the whole directory: one document recording what was decided and what shipped, replacing nine that describe stages of getting there. I did not do it because it needs reading all nine, and deleting documents unread is not a thing to do at 4am.

The mobile-dav thread — three documents, one conversation

mobile-dav-provisioning · -feedback · -reply. A correspondence. Almost certainly one document.

Unclassified — I have not looked

design-language-interface · file-sync · jobs-unification · mobile-photo-sync-api · nextcloud-replacement · agent-git-identity


The plugin split, which affects most of the above

A core install is six processes. Everything else is a plugin, switched off tonight but present on disk. Most documents here were written when the estate was twenty processes and every one of them was simply "there", so they describe availability that no longer holds.

The useful rewrite is usually one line, not a rewrite: say whether the thing described is core or a plugin, and if a plugin, that it is not mounted on a fresh install.

S
Description
No description provided
Readme
42 MiB
Languages
TypeScript 91%
Shell 4.6%
JavaScript 4.1%
CSS 0.2%
HTML 0.1%