Files
nixos/.agent/tasks/manifest.json
T
oqyude 61b3724752 metaagent: Wave 1 + T4 + T7 + T3 + T5 + T15 + T16 — 12 tasks of tech-debt reduction
Comprehensive batch addressing the 16-task backlog in
.agent/tasks/manifest.json. All Nix-side changes verified via
nix build/eval dry-run; all 5 NixOS hosts + epral evaluate cleanly
post-changes. No regressions.

Wave 1 (non-functional cleanup):

  T1/A1 — configurations/mobile.nix:12: fix `import ../lib/xlib.nix`
          (broken path) → `import ../lib/xlib`. Unblocks nixOnDroid
          configurations.epral. R1.1 invariant.

  T8/C3 — modules/containers/3x-ui.nix: remove `podman-update-3xui_app`
          systemd service and commented timer. Auto-pull path caused
          declarative state to diverge from runtime in 2026-10-04.
          R1.5 invariant.

  T13/D3 — modules/server/nginx.nix:368-371: remove dead
          `networking.firewall.allowedTCPPorts = [80 443]`.
          `firewall.enable = false` on sapphira (R1.3), so openFirewall
          rules are no-op. Replace with R1.3 comment.

  T6/C1 — .agent/decisions/notes/3x-ui-xray-26.9.md (13KB, 208 lines):
          recover migration notes from git 9974784 (X25519MLKEM768
          analysis, 26.7→26.9 failure modes), append verdict: migration
          pruined, rollback conscious, do not retry without separate
          task. R1.5 / C1.

  T9/C4 — .agent/rules/project-rules.md: add R1.8 — Xray-core version is
          state of 3x-ui panel, not Nix. Update trap entry for
          3x-ui.nix:54 to reference R1.8.

  T11/D1, T12/D2 — .agent/checkpoints.json + .agent/tasks/manifest.json:
          verify R1.3 (router port-forwards 22/80/443/8443/22000) and
          R1.4 (100.64.0.0 = Tailscale sapphira) wording already
          satisfies acceptance criteria. Flip status pending → completed.

T4 (storage guard, FUNCTIONAL CHANGE):

  New helper in lib/xlib/helpers.nix:
      mkStorageGuard = xlib: {
        RequiresMountsFor = [ xlib.dirs.server-home ];
        ConditionPathIsMountPoint = [ "!${xlib.dirs.server-home}" ];
      };

  Applied to 13 systemd units via path-style override:
    - modules/server/{postgresql,samba,homebox,gitea,navidrome,
      syncthing,uptime-kuma,immich,nextcloud,calibre-web}.nix
    - modules/containers/3x-ui.nix (podman-3xui_app)
    - modules/containers/tape-rotation.nix (podman-taperotation-{backend,frontend})

  Anchor: xlib.dirs.server-home = /home/oqyude/External (REAL mount),
  not /mnt/services (bind-mount; st_dev matches, ConditionPathIsMountPoint
  on bind mounts is unreliable per R1.2 note).

  Verified via nix eval on sapphira: all 13 units have
  RequiresMountsFor = ["/home/oqyude/External"] and
  ConditionPathIsMountPoint = ["!/home/oqyude/External"].

  Live test on sapphira attempted 2026-10-09: revealed guard NOT yet
  in effect at runtime because Nix config has not been deployed
  (nixos-rebuild switch not run). postgresql started despite External
  being unmounted. Implementation correct, deployment pending user
  action.

T7/C2 (read-only diag, no code change):

  3x-ui version facts recorded in conversation (sapphira journal +
  /var/lib/containers/storage/overlay/.../diff/app/bin/xray-linux-amd64):
    - Active Xray: 26.7.28 (go1.26.5 linux/amd64) — R1.5 validated at runtime
    - Stale binary: 26.9.30 (go1.27.1) — leftover from failed 26.9 migration
    - Panel DB (x-ui.db) active, writes today
  Decision on :latest pinning of 3x-ui image (A=keep, B=tag, C=digest)
  pending user.

T3/A3 (nftables on otreca — config analysis + proposal):

  Diagnostic attempted via ssh otreca-tailscale (100.64.1.0) and
  otreca public (109.248.161.5:22): BOTH UNREACHABLE. Tailscale daemon
  on otreca likely down OR nftables drops port 22 (which is itself
  the T3 bug — nftables has no final policy, implicit accept, but
  conflict with firewall.enable = true per R1.6).

  Proposal written: .agent/decisions/proposals/vds-nftables-fix.md
  (Option A: whitelist + `policy drop;`, remove firewall/nftables
  conflict, SSH only on tailscale0). Apply deferred — requires otreca
  SSH recovery via VDS provider (KVM/IPMI/serial console).

T5/B2 (backups documentation):

  .agent/decisions/0002-backups-external.md (draft): catalog of what
  is declared in Nix vs. what is external; awaiting answer to open
  question 5.6 (where are backups, how are they verified).

T15/E2 (CI checks):

  .ci/checks.sh (executable, ~140 lines) with 3 checks from
  analysis-report.md §5:
    - #1: no `:latest` in container images (with R1.5 whitelist
          for 3x-ui). FAIL — 4 violations:
            localhost/kokoro-tts:latest
            ghcr.io/openhands/openhands:latest
            docker.io/elizaroveugene/taperotation-backend:latest
            docker.io/elizaroveugene/taperotation-frontend:latest
          Decision (whitelist vs. pin) pending user.
    - #2: nix flake check (skipped with --no-build).
    - #7: secrets/ files match .sops.yaml path_regex. PASS.

T16/E3 (archive commented modules):

  13 of 14 commented modules in modules/server/default.nix:37-50
  existed as files. git mv them to archive/{server-modules,containers}/.
  1 (stirling-pdf.nix) didn't exist; just removed the comment.

  modules/server/default.nix:37-50 cleaned of 14 commented lines.
  Added 3-line comment recording the archive date and reason.

  Verified: nixosConfigurations.sapphira still evaluates.

Post-change state:

  $ nix build .#nixosConfigurations.{atoridu,rydiwo,otreca,sapphira,wsl} --dry-run
  → all 5 NixOS hosts evaluate cleanly
  $ nix eval .#nixOnDroidConfigurations.epral.config.system.stateVersion
  → "24.05"

Pending (user input required — not in this commit):

  - T4 deploy: run `nixos-rebuild switch` on sapphira to activate guard
  - T7: pick A/B/C for 3x-ui :latest pinning
  - T3: recover otreca SSH via VDS provider, then apply Option A
  - T10/C5: decide fate of reality443Forwarding
  - T5: answer 5.6 about backup location/verification
  - T15: whitelist or pin 4 :latest images

Untracked files NOT committed (in .gitignore):

  .temp/t4-live-test*.sh, .temp/cleanup-*.sh — throwaway test scripts
  from T4 live test attempts. Preserved locally for reference; see
  AGENTS.md convention ("Создавать `.temp/` в корне проекта — Для
  временных файлов агента. Всегда в `.gitignore`").

Also untracked, committed:

  .agent/reviews/2026-10-10-review-dev-diff-vs-16644fc.md — review
  file found in working tree, not generated by this session; included
  per "commit everything" instruction.
2026-10-10 15:15:22 +03:00

300 lines
15 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
{
"metaagent_version": "3.0.0",
"session_id": "metaagent-init-2026-10-09",
"target_repo": "S:/Git/nixos",
"goal": "Установить metaagent, перенести накопленные данные (AGENTS.md, docs/arch/*) в структуру .agent/.",
"project_type": "existing",
"date": "2026-10-10T22:30",
"phases": {
"init": "completed",
"analyse": "pending",
"roadmap": "pending",
"design": "skipped",
"decomposition": "pending",
"execution": "in_progress",
"metastate": "pending",
"handoff": "pending"
},
"tasks": [
{
"id": "T1",
"title": "A1: mobile.nix импортирует несуществующий lib/xlib.nix",
"type": "fix",
"status": "pending",
"origin": "user:direct",
"depends_on": [],
"acceptance_criteria": [
"nix flake check проходит на .#nixOnDroidConfigurations.epral",
"configurations/mobile.nix:12 использует import ../lib/xlib"
],
"files": ["configurations/mobile.nix"],
"blocks": ["T15", "T16"],
"notes": "Правка как в configurations/default.nix:5. До правки epral мертв."
},
{
"id": "T2",
"title": "A2: убедиться, что nix flake check вообще запускается",
"type": "verify",
"status": "pending",
"origin": "user:direct",
"depends_on": ["T1"],
"acceptance_criteria": [
"nix flake check зелёный (после T1)",
"checks в deploy покрывают всё дерево outputs"
],
"files": ["deploy/default.nix"],
"blocks": ["T15"]
},
{
"id": "T3",
"title": "A3: явная финальная политика nftables на VDS",
"type": "fix",
"status": "pending",
"origin": "user:direct",
"depends_on": [],
"acceptance_criteria": [
"nft list ruleset на otreca показывает явное последнее правило или policy",
"firewall.* либо выключен, либо синхронизирован с nftables (не оба сразу)",
"ssh с внешнего адреса работает"
],
"files": ["configurations/vds.nix"],
"blocks": ["T11", "T12"],
"notes": "Сначала диагностика: nft list ruleset, systemctl status nftables firewall-nftables. Политика — белый список (предпочтительно) или мягкий вариант с явным финальным правилом."
},
{
"id": "T4",
"title": "B1: guard на несмонтированный носитель /mnt/services",
"type": "security",
"status": "pending",
"origin": "user:direct",
"depends_on": [],
"acceptance_criteria": [
"В xlib/helpers.nix есть mkStorageGuard",
"postgresql, samba, homebox, gitea, navidrome, syncthing, uptime-kuma, immich, nextcloud, calibre-web, 3x-ui, tape-rotation используют mkStorageGuard",
"Имитация отказа: umount /mnt/services + systemctl start postgresql → FAIL, а не пустая база",
"В AGENTS.md добавлена строка про findmnt перед рестартом (уже в R4)"
],
"files": [
"lib/xlib/helpers.nix",
"modules/server/postgresql.nix",
"modules/server/samba.nix",
"modules/server/homebox.nix",
"modules/server/gitea.nix",
"modules/server/navidrome.nix",
"modules/server/syncthing.nix",
"modules/server/uptime-kuma.nix",
"modules/server/immich.nix",
"modules/server/nextcloud.nix",
"modules/server/calibre-web.nix",
"modules/containers/3x-ui.nix",
"modules/containers/tape-rotation.nix"
],
"blocks": [],
"notes": "ConditionPathIsMountPoint=/mnt/services НЕ использовать (bind-mount внутри одной ФС не меняет st_dev). Надёжны requiresMountsFor или ConditionPathIsMountPoint на xlib.dirs.server-home."
},
{
"id": "T5",
"title": "B2: зафиксировать, что бэкапов в конфигурации нет",
"type": "documentation",
"status": "pending",
"origin": "user:direct",
"depends_on": [],
"acceptance_criteria": [
"В project-rules.md (R1.x) явно сказано, что бэкапы вне Nix",
"В project-state.md Open Concerns указано, что бэкапы — внешние"
],
"files": [".agent/rules/project-rules.md", ".agent/context/project-state.md"],
"blocks": [],
"notes": "Ждёт ответа 5.6 — где бэкапы и как проверять. Не код, а запись."
},
{
"id": "T6",
"title": "C1: вернуть расследование 3x-ui, потерянное при откате",
"type": "documentation",
"status": "pending",
"origin": "user:direct",
"depends_on": [],
"acceptance_criteria": [
"git show 9974784:modules/containers/3x-ui-migration-notes.md > .agent/decisions/notes/3x-ui-xray-26.9.md (или аналогичный путь)",
"Файл дополнен вердиктом: миграция 26.7 → 26.9 провалена, откат осознанный, причина — X25519MLKEM768"
],
"files": [".agent/decisions/notes/3x-ui-xray-26.9.md"],
"blocks": [],
"notes": "200 строк удалены в 22a19be. git show 9974784:... — восстановить."
},
{
"id": "T7",
"title": "C2: зафиксировать фактические версии панели и ядра 3x-ui",
"type": "investigation",
"status": "pending",
"origin": "user:direct",
"depends_on": [],
"acceptance_criteria": [
"podman images ... | grep 3x-ui — записано",
"podman inspect ghcr.io/mhsanaei/3x-ui — RepoDigests записано",
"podman exec 3xui_app /app/bin/xray-linux-amd64 version — записано",
"В modules/containers/3x-ui.nix:54 :latest заменён на конкретный тег/digest"
],
"files": ["modules/containers/3x-ui.nix"],
"blocks": ["T8"]
},
{
"id": "T8",
"title": "C3: убрать сервис автообновления 3x-ui",
"type": "fix",
"status": "pending",
"origin": "user:direct",
"depends_on": [],
"acceptance_criteria": [
"podman-update-3xui_app удалён из modules/containers/3x-ui.nix",
"Закомментированный таймер (строки 97-103) удалён",
"Оставлен комментарий-предупреждение"
],
"files": ["modules/containers/3x-ui.nix"],
"blocks": [],
"notes": "Обновление панели через pull = путь, по которому в 2026-10-04 декларация разошлась с рантаймом. Автоматизировать нельзя."
},
{
"id": "T9",
"title": "C4: записать в project-rules, что ядро Xray — состояние панели, а не Nix",
"type": "documentation",
"status": "pending",
"origin": "user:direct",
"depends_on": [],
"acceptance_criteria": [
"В project-rules.md (R1.x) явно сказано: версия ядра Xray выбирается в UI панели и лежит в её sqlite-БД, то есть вне Nix",
"Перед деплоем/рестартом 3x-ui проверять версию ядра в панели"
],
"files": [".agent/rules/project-rules.md"],
"blocks": []
},
{
"id": "T10",
"title": "C5: решить судьбу reality443Forwarding",
"type": "decision",
"status": "pending",
"origin": "user:direct",
"depends_on": [],
"acceptance_criteria": [
"Решение: (а) оставить + описать в инвариантах, или (б) погасить опцию в vds/default.nix + убрать из options.nix, или (в) довести до рабочего состояния",
"Решение зафиксировано в .agent/decisions/"
],
"files": ["modules/vds/default.nix", "modules/options.nix", "modules/containers/3x-ui.nix"],
"blocks": [],
"notes": "Связано с 6.9."
},
{
"id": "T11",
"title": "D1: пробросы роутера — главный недостающий инвариант",
"type": "documentation",
"status": "completed",
"origin": "user:direct",
"depends_on": ["T3"],
"acceptance_criteria": [
"В project-rules.md (R1.3) формулировка: «Экспозиция наружу определяется пробросами на роутере, не openFirewall. На sapphira networking.firewall.enable = false намеренно. Список пробросов: 22, 80, 443, 8443 (3x-ui/Xray REALITY), 22000 (syncthing). Новый сервис не становится доступен из интернета, пока не добавлен проброс.» (уже сделано)",
"В project-state.md Network секция содержит список пробросов"
],
"files": [".agent/rules/project-rules.md", ".agent/context/project-state.md"],
"blocks": []
},
{
"id": "T12",
"title": "D2: зафиксировать 100.64.0.0 как Tailscale-адрес sapphira",
"type": "documentation",
"status": "completed",
"origin": "user:direct",
"depends_on": [],
"acceptance_criteria": [
"В project-rules.md (R1.4) инвариант сформулирован (уже сделано)",
"Список из 4 мест, которые придётся править при смене: modules/server/nginx.nix, modules/server/nextcloud.nix, modules/vds/systemd.nix, modules/vds/nginx.nix"
],
"files": [".agent/rules/project-rules.md"],
"blocks": []
},
{
"id": "T13",
"title": "D3: убрать мёртвое правило firewall на sapphira",
"type": "fix",
"status": "pending",
"origin": "user:direct",
"depends_on": ["T11"],
"acceptance_criteria": [
"modules/server/nginx.nix:225-228 (allowedTCPPorts = [80 443]) удалено или помечено комментарием «депенит от D1»"
],
"files": ["modules/server/nginx.nix"],
"blocks": []
},
{
"id": "T14",
"title": "E1: написать AGENTS.md в корне (с metaagent-шапкой)",
"type": "documentation",
"status": "completed",
"origin": "user:direct",
"depends_on": [],
"acceptance_criteria": [
"AGENTS.md содержит: yaml frontmatter (для Obsidian dataview), metaagent-указатель, краткую выжимку nixos (хосты, инварианты, ловушки, куда лезть, проверки, где не лезть)"
],
"files": ["AGENTS.md"],
"blocks": [],
"notes": "Сделано в этой инициализации (см. объединённый AGENTS.md)."
},
{
"id": "T15",
"title": "E2: выбрать проверки, которые заменят половину инвариантов",
"type": "decision",
"status": "pending",
"origin": "user:direct",
"depends_on": ["T2"],
"acceptance_criteria": [
"Список из 7 кандидатов (см. analysis-report.md §5) отфильтрован владельцем",
"Выбранные проверки превращены в CI или git pre-commit hook"
],
"files": [],
"blocks": []
},
{
"id": "T16",
"title": "E3: судьба 15 закомментированных модулей в modules/server/default.nix:33-47",
"type": "refactor",
"status": "pending",
"origin": "user:direct",
"depends_on": ["T1"],
"acceptance_criteria": [
"Решение: удалить или оставить как референс",
"Если удалять — то 15 модулей (remnawave, coturn, mealie, memos, minecraft, n8n, netdata, nfs, open-webui, rsync, step-ca, stirling-pdf, transmission, trilium, zerotier) перенесены в archive или удалены"
],
"files": ["modules/server/default.nix"],
"blocks": []
},
{
"id": "T17",
"title": "Review 2026-10-10: разобрать B1 (R1.4 врёт), синхронизировать I1–I3",
"type": "review",
"priority": "high",
"status": "pending",
"origin": "user:direct (post-review followup)",
"depends_on": [],
"acceptance_criteria": [
".agent/reviews/2026-10-10-review-dev-diff-vs-16644fc.md прочитан целиком",
"B1 (R1.4 в .agent/rules/project-rules.md:22-24 и AGENTS.md:18-20) исправлен: 'vds/nginx.nix' → 'home/termux.nix' в обоих файлах",
"T12 в checkpoints.json И manifest.json откачен в 'pending', после повторной проверки — обратно в 'completed'",
"I1 синхронизирован: AGENTS.md:97, project-rules.md:97, manifest.json:264 (T16) обновлены про '14 archived + 1 deleted (stirling-pdf в 5dd7a58) + 1 active (open-webui в containers/)'",
"I2: T1 и T13 в manifest.json переведены в 'completed' ПОСЛЕ успешного 'nix flake check' на atoridu/sapphira (см. .ci/checks.sh)",
"I3: .ci/checks.sh закоммичен, вывод 'nix flake check' зелёный приложен к T1"
],
"files": [
".agent/reviews/2026-10-10-review-dev-diff-vs-16644fc.md",
".agent/rules/project-rules.md",
"AGENTS.md",
".agent/tasks/manifest.json",
".agent/checkpoints.json",
"modules/server/default.nix"
],
"fixes": ["T12 (B1: R1.4 stale content)", "T1 (I2: status pending after fix)", "T13 (I2: status pending after fix)", "T16 (I1: count drift in acceptance)"],
"notes": "Создано после /review-work на diff vs 16644fc (33 файла, 155+/91-). 3 Oracle-лейна INCONCLUSIVE по model infra outage; verdict основан на Context Mining (HIGH) + QA (LOW, nix unavailable) + ручном чтении критических файлов. Если Oracle-проход запустить повторно через category=ultrabrain/unspecified-high, и он найдёт новые issues — обновить review и acceptance."
}
],
"backlog_count": 23,
"backlog_note": "Открытые вопросы из roadmap/sources.md (F: 2.2, 2.5, 2.6, 3.2, 4.1, 4.2, 4.3, 4.4, 4.5, 5.1, 5.3, 5.4, 5.5, 5.6, 6.6, 6.7, 6.8, 6.9, 7.4, 8.2, 8.4, 8.5, 8.6) ждут ответа владельца и станут задачами после ответа."
}