Skip to content

Fix CI, audit all scripts, add new utilities and incremental GitHub backups - #53

Merged
djeada merged 5 commits into
masterfrom
cleanup/audit-and-ci-fix
Oct 3, 2026
Merged

djeada merged 5 commits into
masterfrom
cleanup/audit-and-ci-fix

Conversation

@djeada

@djeada djeada commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Summary

Gets CI green again, fixes bugs found by auditing every script in src/, adds new utilities and a smoke-test suite, and makes download_all_github_repos.sh back up only repositories that changed.

CI fix

  • run_audiocraft.sh / run_videogen.sh had blank lines before the shebang (SC1128)
  • beautysh formatting in backup.sh, install_signal.sh and the two scripts above
  • several files were missing the trailing empty line required by last_line_empty.sh
  • beautysh drops file permissions when formatting in place; beautify_script.sh now restores them, and exec bits are restored on all scripts

Script audit (~110 scripts)

Highlights:

  • Destructive: resize_to_a4.sh overwrote originals by default (now writes ./resized); strip_python_comments.sh mangled code/strings; strip_digits.sh deleted whole words; web_block.sh --clear removed localhost from /etc/hosts; extract.sh wrote .gz output over the directory path; backup.sh could leave an unencrypted archive when encryption failed
  • Broken outright: random_password.sh, system_info.sh, squash_branch.sh, dead_code.sh, fetch_github_repos_names.sh
  • in-place editors keep permissions and skip .git / binary files
  • eval on user input removed; errors go to stderr with non-zero exit codes; leading-zero numbers no longer parsed as octal; missing dependencies reported up front

Behavior changes worth noting: strip_python_comments.sh keeps docstrings, are_anagrams.sh exits 1 for non-anagrams, system_info.sh without options shows everything, month_to_number.sh accepts full month names.

download_all_github_repos.sh

  • Incremental backups: DEST/backup-manifest.json records each repo's HEAD commit, refs fingerprint, settings, output path, size and timestamps. git ls-remote (no API quota) is checked first and unchanged repositories are skipped. Backups live in DEST/repos / DEST/archives instead of a new runs/<timestamp>/ copy each run; archives are named by commit, with --keep-archives N, --force and --backup-manifest FILE.
  • --auth auto|token|gh|public for discover and backup; gh uses the GitHub CLI login. Global git credential helpers are disabled for these git calls so public is truly anonymous.
  • Note: existing backups under runs/ are not reused, so the first run after this change downloads everything once.

New scripts

retry.sh, wait_for_port.sh, find_duplicate_files.sh, find_large_files.sh, ssl_cert_expiry.sh, git_cleanup_branches.sh

CI and tooling

  • workflow renamed to ci.yml: actions/checkout@v4, setup-python, apt-get update, pinned beautysh, concurrency cancel
  • new tests/smoke_test.sh job: shebang/exec-bit/syntax checks for every script plus behavior tests for the pure ones
  • hooks/_run_all.sh works from any directory, also checks tests/, and summarizes failures
  • .editorconfig; README lists all scripts with corrected descriptions

Testing

  • ./hooks/_run_all.sh and ./tests/smoke_test.sh (400 checks) pass locally
  • download_all_github_repos.sh tested offline against local bare repos (mirror/clone/sparse/archive, change detection, relocation, pruning) and against GitHub with --auth gh, token and public on a private repository

Known issues left as-is

  • fetch_github_repos_names.sh takes the token on the command line (visible in ps)
  • purge_and_reinstall_nodejs.sh --all-users runs rm -rf as root under other users' homes
  • server_health_monitor.sh re-sends the alert email every interval

djeada added 5 commits October 3, 2026 23:29
- run_audiocraft.sh / run_videogen.sh: remove blank lines before the
  shebang (SC1128), mark executable, reformat with 4-space indents
- install_signal.sh: reformat to repo indent style
- backup.sh: collapse multi-line subshells that beautysh mis-indents
Go through every script in src/ and fix bugs, misleading help text and
leftover cruft while keeping each script's interface and style.

Notable fixes:
- random_password.sh always failed with no output; squash_branch.sh,
  system_info.sh, dead_code.sh and fetch_github_repos_names.sh were
  broken outright
- resize_to_a4.sh overwrote originals by default (now writes ./resized)
- strip_python_comments.sh mangled code and strings; strip_digits.sh
  deleted whole words instead of digits
- web_block.sh --clear removed localhost entries; all actions now stay
  inside the managed section of the hosts file
- backup.sh: no plaintext archive left on encryption failure, rsync
  errors propagate, passphrase no longer visible in ps, retention is
  scoped per host
- extract.sh wrote .gz output over the directory path; convert_to_mp4.sh
  could overwrite its own input
- in-place editors (last_line_empty, remove_*_whitespace, beautify, ...)
  now preserve file permissions and skip .git and binary files
- beautify_script.sh --check now fails on beautysh parse errors
- disk_usage.sh, clear_cache.sh, purge_and_reinstall_nodejs.sh,
  cpu_temp.sh, network_bandwidth.sh: option handling and locale fixes
- leading-zero numbers no longer parsed as octal across math scripts
- eval on user input removed (clear_cache.sh, empty_trash.sh, sum_args.sh)
- errors go to stderr with non-zero exit codes; missing dependencies are
  reported up front
- restore the executable bit on scripts that had lost it
- rename workflow to ci.yml, use actions/checkout@v4 and setup-python,
  apt-get update before installing, pin beautysh, cancel stale runs
- add a smoke-test job: every script is checked for shebang, executable
  bit and syntax, and pure scripts are run against known outputs
- hooks/_run_all.sh works from any directory, also checks tests/, and
  prints a summary of failing hooks
- add .editorconfig matching the repo's formatting rules
New scripts:
- retry.sh: retry a command with exponential backoff
- wait_for_port.sh: wait for a TCP port, then optionally run a command
- find_duplicate_files.sh: find identical files and report wasted space
- find_large_files.sh: list the largest files or directories
- ssl_cert_expiry.sh: check TLS certificate expiry for hosts (cron friendly)
- git_cleanup_branches.sh: delete merged or upstream-gone local branches

README: list the new scripts and the previously undocumented
run_audiocraft.sh, run_videogen.sh and setup_obs_background_blur.sh,
correct descriptions that no longer matched behavior, document how to
run the checks locally, and normalize repository link casing.
Incremental backups:
- keep backups in DEST/repos and DEST/archives instead of a fresh
  runs/<timestamp>/ copy on every run (runs/ now holds only the summary
  and checksums)
- write DEST/backup-manifest.json with each repository's HEAD commit,
  remote refs fingerprint, settings fingerprint, output path, size,
  archive SHA-256 and timestamps; paths are stored relative to DEST so
  the backup directory can be moved
- check remote refs with git ls-remote before each backup and skip
  repositories whose refs and settings are unchanged and whose backup
  still exists
- download archives at the exact commit and name them
  owner__repo@<sha>.tar.gz; add --keep-archives N to prune old ones
- add --force to back up everything and --backup-manifest FILE to
  relocate the record; summaries count unchanged repositories

Authentication:
- add --auth auto|token|gh|public for discover and backup; gh uses the
  GitHub CLI login via "gh auth token"
- disable the user's git credential helpers for HTTPS so public mode is
  really anonymous and token/gh modes use exactly the chosen token
- send the token to git as basic auth (x-access-token), which GitHub's
  git-over-HTTPS endpoint accepts
@djeada
djeada merged commit bedf017 into master Oct 3, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant