<feed xmlns='http://www.w3.org/2005/Atom'>
<title>console.git, branch master</title>
<subtitle>Monitor for my server
</subtitle>
<id>http://cgit.dandokmang.com/console.git/atom?h=master</id>
<link rel='self' href='http://cgit.dandokmang.com/console.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='http://cgit.dandokmang.com/console.git/'/>
<updated>2026-07-01T10:11:15Z</updated>
<entry>
<title>Document abbreviate_rule's nat/rdr blind spot and ddclient's log gap</title>
<updated>2026-07-01T10:11:15Z</updated>
<author>
<name>batsumaru</name>
<email></email>
</author>
<published>2026-07-01T10:11:15Z</published>
<link rel='alternate' type='text/html' href='http://cgit.dandokmang.com/console.git/commit/?id=126ba66a627a9625fae77c29abe99dce19477e7c'/>
<id>urn:sha1:126ba66a627a9625fae77c29abe99dce19477e7c</id>
<content type='text'>
From a fresh-agent review of AGENTS.md against two hypothetical tasks:

- abbreviate_rule() in pf.sh has only ever been developed/tested
  against filter-rule (-sr) syntax, despite also running on -sn
  (nat/rdr) output. It degrades safely (unshortened passthrough) but
  a new nat/rdr rule shape isn't guaranteed to compress as tightly -
  noted both in the code comment and in AGENTS.md's compression
  writeup so this doesn't need rediscovering.

- ddclient logging isn't enabled on the box, so "is the last DNS
  update actually succeeding" can't be built by tailing a log that
  doesn't exist - it'd need the cache file or a public-IP comparison
  instead. Recorded in AGENTS.md's topology section since ddclient.sh
  currently only checks the process is running, not update success.

Co-Authored-By: Claude Sonnet 5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>Remove dangling reference to a handover doc that isn't in the repo</title>
<updated>2026-07-01T09:52:23Z</updated>
<author>
<name>batsumaru</name>
<email></email>
</author>
<published>2026-07-01T09:52:23Z</published>
<link rel='alternate' type='text/html' href='http://cgit.dandokmang.com/console.git/commit/?id=7904f1221e6bb35c8b1abf807a6030e70598ed33'/>
<id>urn:sha1:7904f1221e6bb35c8b1abf807a6030e70598ed33</id>
<content type='text'>
The original handover was only ever pasted into a conversation, never
committed as a file - a fresh agent session has nothing to "see." State
the project's origin and goal directly instead.

Co-Authored-By: Claude Sonnet 5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>Expand AGENTS.md: topology, one-line-fit preference, real-time triggers</title>
<updated>2026-07-01T09:49:25Z</updated>
<author>
<name>batsumaru</name>
<email></email>
</author>
<published>2026-07-01T09:49:25Z</published>
<link rel='alternate' type='text/html' href='http://cgit.dandokmang.com/console.git/commit/?id=92062d94f8150e4502ad305d74b62bbb678ded41'/>
<id>urn:sha1:92062d94f8150e4502ad305d74b62bbb678ded41</id>
<content type='text'>
Homelab topology: pulled the infrastructure context from the original
handover doc (FreeBSD version, WireGuard/Caddy/ZFS/jail network
layout) that isn't otherwise captured now that check.sh is gone.

Design preference: documents "rows should fit on one line" as a
standing preference (not a one-off ask), with checks/pf.sh's
abbreviate_rule() development as the worked example of how to compress
long/variable-length output - strip ruleset-specific boilerplate,
verify symbol choices against the font's actual glyph coverage, prefer
legible bracket-letter tags over clever-but-obscure unicode when a
distinction has real meaning, and always confirm via a rendered
preview rather than eyeballing character counts.

When cron + static HTML stops being enough: concrete signals (need for
alerting, history/trends, sub-minute or push-based updates, render
time approaching the cron interval) that mean this architecture is
being outgrown, so a future ask crossing one of these gets flagged
explicitly instead of worked around within the current design.

Co-Authored-By: Claude Sonnet 5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>Add AGENTS.md for cross-session agent context</title>
<updated>2026-07-01T09:42:01Z</updated>
<author>
<name>batsumaru</name>
<email></email>
</author>
<published>2026-07-01T09:42:01Z</published>
<link rel='alternate' type='text/html' href='http://cgit.dandokmang.com/console.git/commit/?id=d35a7d3b24fa71e13e48fd85e299c12a93e6aab8'/>
<id>urn:sha1:d35a7d3b24fa71e13e48fd85e299c12a93e6aab8</id>
<content type='text'>
Covers what a fresh session needs that statuspage/README.md doesn't:
the Windows-checkout-vs-FreeBSD-runtime split (nothing here actually
executes the check scripts' real commands), the git push/pull
deployment loop, the core.fileMode/pre-commit-hook setup, and five
gotchas hit and fixed this session (usec/sec substring match, ntpq's
"+" prefix, grep -c's exit-1-on-zero, Windows ln -s on directories
falling back to a copy, font glyph coverage).

CLAUDE.md is a pointer to AGENTS.md rather than a symlink or a
duplicate copy - this checkout can't reliably create real symlinks
(same root cause noted in AGENTS.md itself), and a stale copy would
silently drift out of sync as AGENTS.md changes.

Co-Authored-By: Claude Sonnet 5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>Fix clock offset extraction dropping positive values</title>
<updated>2026-07-01T09:35:27Z</updated>
<author>
<name>batsumaru</name>
<email></email>
</author>
<published>2026-07-01T09:35:27Z</published>
<link rel='alternate' type='text/html' href='http://cgit.dandokmang.com/console.git/commit/?id=958dfa35fd030e5b609298b1236692c85b6ffafc'/>
<id>urn:sha1:958dfa35fd030e5b609298b1236692c85b6ffafc</id>
<content type='text'>
ntpq's "rv 0 offset" prefixes non-negative offsets with an explicit
"+" (e.g. "offset=+0.030208"), which wasn't in the sed capture class
([-0-9.]). Since the capture group is starred, the regex still
"matched" with an empty capture instead of failing outright, silently
producing "no response" for every positive/zero offset while negative
ones (which do use "-", already in the class) worked fine. Confirmed
against the real box: earlier renders with negative drift worked,
then it started showing "no response" once the drift crossed zero.

Co-Authored-By: Claude Sonnet 5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>Distinguish pf state-tracking modes with bracketed letter tags</title>
<updated>2026-07-01T09:22:17Z</updated>
<author>
<name>batsumaru</name>
<email></email>
</author>
<published>2026-07-01T09:22:17Z</published>
<link rel='alternate' type='text/html' href='http://cgit.dandokmang.com/console.git/commit/?id=f3f4d8bcde122a711000bb79c4a30f1edd9874ff'/>
<id>urn:sha1:f3f4d8bcde122a711000bb79c4a30f1edd9874ff</id>
<content type='text'>
Previously "keep state" and "modulate state" both collapsed to the
same generic "[state]" tag, losing a real distinction: modulate state
hardens TCP ISN generation and synproxy state (not handled at all
before) proxies the handshake against spoofed SYN floods - neither is
just "some tracking is happening." Now [N]/[K]/[M]/[S] map to no/keep/
modulate/synproxy state respectively, documented in a comment since
the mapping isn't self-evident without pf.conf familiarity.

Considered thematic unicode symbols from the font's supported blocks
(Mathematical Operators, Geometric Shapes) instead, but a bracketed
letter is unambiguous without a legend - a clever but obscure glyph
isn't actually more compact once you factor in "what does this mean."

Co-Authored-By: Claude Sonnet 5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>Sort pf rules by interface, iconify from/to, drop redundant nat prefix</title>
<updated>2026-07-01T09:01:39Z</updated>
<author>
<name>batsumaru</name>
<email></email>
</author>
<published>2026-07-01T09:01:39Z</published>
<link rel='alternate' type='text/html' href='http://cgit.dandokmang.com/console.git/commit/?id=f035b94c216a8324e5b0d1637340c3736227781f'/>
<id>urn:sha1:f035b94c216a8324e5b0d1637340c3736227781f</id>
<content type='text'>
Filter rules now sort by (interface, in-before-out) rather than
pfctl's raw eval order, which just reflects pf.conf's authoring order
and reads as arbitrarily interleaved (an "out" rule sandwiched between
unrelated "in" rules for the same interface). Display-only reorder -
pf's actual evaluation order and quick/first-match semantics on the
box are untouched, only the informational listing is re-sorted.

Generalized the "from X to Y" abbreviation beyond the from-any-to-any-
port special case, and replaced pfctl's own "-&gt;" (nat rewrite target)
with the unicode arrow for consistency with the in/out arrows already
in use. Also dropped the "nat: " prefix, which was redundant with the
rule text already starting with "nat". Applied the same "-&gt;" -&gt; "→"
consistency swap to jails.sh's http child-row label.

Co-Authored-By: Claude Sonnet 5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>Abbreviate pf rule text so rows fit the column without wrapping</title>
<updated>2026-07-01T08:46:33Z</updated>
<author>
<name>batsumaru</name>
<email></email>
</author>
<published>2026-07-01T08:46:33Z</published>
<link rel='alternate' type='text/html' href='http://cgit.dandokmang.com/console.git/commit/?id=018f92b5a0d7ee97747720e28d48bdf8b0134f2e'/>
<id>urn:sha1:018f92b5a0d7ee97747720e28d48bdf8b0134f2e</id>
<content type='text'>
pfctl's verbose syntax (flags S/SA, quick, from any to any port = X,
proto tcp/udp/icmp) was overflowing the .section column width and
wrapping mid-rule. abbreviate_rule() in pf.sh strips the near-
universal boilerplate tokens on this ruleset and swaps in/out for
arrows - cuts each rule to roughly 35-45% of its original length.

Deliberately not a real pf syntax parser: it's a handful of targeted
sed substitutions, so a rule shape it doesn't recognize just passes
through unshortened rather than mangling. Only uses the Arrows block
(confirmed shipped in the scientifica font) - avoided Dingbats
(checkmark/X) since that block isn't included in this font.

Co-Authored-By: Claude Sonnet 5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>Add scientifica bitmap font and wire it into the status page</title>
<updated>2026-07-01T08:46:11Z</updated>
<author>
<name>batsumaru</name>
<email></email>
</author>
<published>2026-07-01T08:46:11Z</published>
<link rel='alternate' type='text/html' href='http://cgit.dandokmang.com/console.git/commit/?id=df56450813b04c09cd24783c6ae3093f189c4519'/>
<id>urn:sha1:df56450813b04c09cd24783c6ae3093f189c4519</id>
<content type='text'>
Bundle scientifica.ttf/Bold/Italic in statuspage/fonts/ (dropped the
.bdf/.otb variants - those are X11/console bitmap formats, browsers
can't load them via @font-face). Mark font extensions as binary in
.gitattributes so git never attempts CRLF conversion on them.

render.sh now symlinks fonts/ into the Caddy-served output directory
on every run (idempotent) since Caddy serves /usr/local/www/status,
not this checkout - the font file has to physically exist next to
index.html for the browser to fetch it.

Also: fixed bad kerning/cramped line spacing from an earlier attempt
at applying the font's recommended Terminal.app settings (which don't
translate 1:1 to CSS), and added a hanging indent (.label class,
text-indent + padding-left) so long wrapped label text - notably
pf.sh's rule listing - aligns under the label instead of the status
square when it wraps to a second line.

Co-Authored-By: Claude Sonnet 5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>Say "never scrubbed" instead of "unknown" for pools with no scan history</title>
<updated>2026-07-01T08:12:46Z</updated>
<author>
<name>batsumaru</name>
<email></email>
</author>
<published>2026-07-01T08:12:46Z</published>
<link rel='alternate' type='text/html' href='http://cgit.dandokmang.com/console.git/commit/?id=47bc0a5a7091bcf716ba1518b3c0ea18a64dc462'/>
<id>urn:sha1:47bc0a5a7091bcf716ba1518b3c0ea18a64dc462</id>
<content type='text'>
Confirmed against the real box: a pool that's never had a scrub or
resilver has no `scan:` line in `zpool status` output at all - it's
not omitted due to a parsing bug, there's just nothing to report yet.
"unknown" wrongly implied a parse failure.

Co-Authored-By: Claude Sonnet 5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
</feed>
