David F Glidden 2e83b2c3a6 [PROPOSAL→AUTHORIZED] Control Kernel v1.0 FROZEN — soundness by construction for the Fool false-positive control
Steward accepted draft-2. Frozen; nothing has been written or reduced against
it prior to this commit, which is the freeze anchor.

The kernel answers a question the programme had been getting wrong. The false-
positive control needs a document on which 'nothing found' is correct, and I had
claimed soundness cannot be known by construction. The steward corrected the
framing: unconditioned soundness cannot, but OPERATIONAL soundness relative to a
declared axiomatic kernel is the standard trick behind proof assistants — and it
is the same regress the central path already terminates by binding claims rather
than certifying parties. The kernel is therefore a TCB: small, declared in
advance, published rather than hidden, because a secret trusted base is a
contradiction in terms.

Design: axiom set declared and hashed (CLAUDE.md, REVIEWED.md); every sentence
typed D/Q/A/N/X; kernel-sound iff every sentence is tagged and every Q resolves
verbatim; tags stripped before the model sees anything, byte-verified, so the
control cannot be passed by tag-matching without reading.

Two rules were paid for in evidence rather than reasoned. §2a forbids a
limitations section: in trial 03 Qwen located Part VII, classified it as
author-named limitation, and skipped it wholesale — a collected section turns
reading into lookup. §2c forbids multi-primitive sentences, with the grading
rule that a blend the model catches VOIDS the document rather than counting as a
false positive, so a missed blend indicts the author.

Steward review supplied three structural findings, all adopted: tag
co-occurrence (taken by decomposition; precedence rejected because it converts a
flagged demonstrated-half into an echo and deflates the very number the control
produces, under a standing caveat that the grader is the party under test),
transitive assumption creep (D now requires resting only on axioms or earlier
D/Q — assumptions cascade, and that cost is accepted as correct), and
rhetorical presupposition in X (X iff declarative conversion yields no
load-bearing claim; headings included). Applying them surfaced a fourth I had
missed: Q's scope-of-use was judgement and absent from §4 — the exact defect the
jurist caught in my own package on 2026-07-19.

§4's residue list grew from three to five. Its DIRECTION did not: all five remain
ways for me to make a document look sound, none makes it look worse. That
one-directionality is the property under watch.

Cost incurred and recorded: the steward's review materially improved the kernel
and thereby coupled him to it. §6.2's adversarial falsifier therefore falls to a
third party — the jurist or a differently-formed model — not to him.
2026-08-02 17:32:18 +02:00
2025-07-27 13:40:44 +02:00

🖖 David's Dotfiles - "Engage!"

"Make it so!" - A complete macOS setup system inspired by Star Trek's efficiency and elegance.

From zero to fully configured macOS in minutes. This dotfiles repository provides a comprehensive, automated setup for developers, writers, and knowledge workers.

🚀 Quick Start

One command to rule them all:

# From GitHub
git clone https://github.com/davidglidden/dotfiles.git ~/dotfiles && ~/dotfiles/engage

# From Gitea (alternative mirror)
git clone git@git.davidglidden.eu:davidglidden/dotfiles.git ~/dotfiles && ~/dotfiles/engage

That's it! The engage script will guide you through a complete system setup.

✨ What This System Provides

📦 Software Management

  • 120+ CLI tools via Homebrew (development, media, security)
  • 40+ Applications via casks (productivity, creativity, utilities)
  • 20+ Mac App Store apps via mas (native macOS apps)

🔧 Configuration Management

  • Shell setup: Zsh with Antidote, Powerlevel10k, history sync
  • Development tools: Git hooks, SSH templates, NPM config
  • Application configs: LaunchBar, Hazel, Bartender, Karabiner
  • Obsidian vault: Complete knowledge management system

🖥️ macOS System Configuration

  • System preferences: Dock, Finder, keyboard, security
  • Security hardening: Firewall, privacy, authentication
  • Keyboard shortcuts: Mission Control, app shortcuts
  • Developer settings: Safari dev tools, Terminal enhancements

🛡️ Backup & Security Strategy

  • Encrypted backups for sensitive files (SSH keys, credentials)
  • History management with daily snapshots and retention
  • Git hooks for security and code quality
  • Application data backup and restore scripts

📁 Repository Structure

dotfiles/
├── engage                     # 🖖 Master installation script
├── Brewfile                   # Package management (brew/cask/mas)
├── README.md                  # This file
├── .gitconfig                 # Git configuration
├── .npmrc                     # NPM defaults
├── .zshrc                     # Shell configuration
├── .vimrc                     # Vim configuration
├── bin/                       # Custom scripts
│   ├── backup-dotfiles        # Quick dotfiles backup
│   └── check-app-configs      # Configuration status checker
├── git/                       # Git configuration
│   └── hooks/                 # Global git hooks
├── macos/                     # macOS system configuration
│   ├── setup-macos.sh         # Master macOS setup
│   ├── defaults.sh            # System preferences
│   ├── security.sh            # Security hardening
│   └── keyboard-shortcuts.sh  # Custom shortcuts
├── macos-apps/                # macOS app configurations
│   └── backup-app-configs.sh  # App settings backup
├── obsidian/                  # Obsidian knowledge vault
│   ├── setup-obsidian.sh      # Vault configuration
│   └── community-plugins.json # Essential plugins
├── scripts/                   # Installation scripts
│   └── symlinks.sh            # Dotfile linking
├── shell/                     # Shell enhancements
│   └── history-sync.zsh       # History management
└── ssh/                       # SSH configuration
    ├── config.example         # SSH config template
    └── README.md              # SSH setup guide

🎯 Core Philosophy

This system balances automation with choice:

  • Smart defaults that work out of the box
  • Interactive modes for customization
  • Modular design - use what you need
  • Security first - encrypted backups, secure defaults
  • Documentation - clear guides and examples

Inspired by the best dotfiles repositories but designed for real-world complexity.

📱 Essential Applications Included

Development

  • iTerm2 + Kitty - Terminal emulators
  • BBEdit - Text editor with deep macOS integration
  • GitHub Desktop - Git GUI
  • Docker - Containerization

Productivity

  • Obsidian - Knowledge management powerhouse
  • 1Password - Password management
  • LaunchBar - Application launcher
  • Hazel - Automated file organization
  • Drafts - Quick capture and text processing

Utilities

  • Karabiner-Elements - Keyboard customization
  • Bartender - Menu bar organization
  • Keka - Archive utility
  • Oversight - Privacy monitoring
  • Signal - Secure messaging

Creative & Media

  • VLC - Media player
  • HandBrake - Video transcoding
  • Transmit - File transfer
  • Calibre - E-book management

🛠️ Advanced Usage

Manual Installation Steps

If you prefer granular control:

# 1. Install packages only
brew bundle install --file=~/dotfiles/Brewfile

# 2. Set up dotfiles
~/dotfiles/scripts/symlinks.sh

# 3. Configure macOS
~/dotfiles/macos/setup-macos.sh

# 4. Set up applications
~/dotfiles/macos-apps/backup-app-configs.sh

Customization

Modify the Brewfile to add/remove applications:

# Add new CLI tool
brew "your-tool"

# Add new application
cask "your-app"

# Add Mac App Store app
mas "App Name", id: 123456789

Customize macOS defaults in macos/defaults.sh:

# Change dock position
defaults write com.apple.dock orientation -string "left"

# Adjust key repeat speed
defaults write NSGlobalDomain KeyRepeat -int 1

Backup Strategy

Before making changes:

# Backup current dotfiles
~/dotfiles/bin/backup-dotfiles

# Backup macOS settings  
~/dotfiles/macos/backup-defaults.sh

# Backup sensitive files (encrypted)
~/dotfiles/backup-scripts/backup-sensitive.sh

🔐 Security Features

  • SSH keys encrypted with GPG
  • Firewall enabled with stealth mode
  • Privacy settings optimized
  • Git hooks prevent secrets in commits
  • Secure defaults for Safari and system
  • Application permissions documented

🧠 Obsidian Knowledge System

Includes a sophisticated personal knowledge management setup:

  • 13 essential plugins for advanced functionality
  • Template system with Templater integration
  • Daily/weekly/monthly review cycles
  • Christopher Alexander pattern language philosophy
  • Multilingual support (EN/ES/FR/CA)

🤝 Contributing

This is a personal dotfiles repository, but ideas and improvements are welcome:

  1. Fork the repository
  2. Create a feature branch
  3. Test thoroughly on a fresh macOS installation
  4. Submit a pull request with clear description

📜 License

MIT License - Use, modify, and share freely.

🙏 Acknowledgments

Inspired by:


Live long and prosper! 🖖

Made with ❤️ for the macOS community

S
Description
🖖 Complete macOS dotfiles system - 'Engage!'
Readme
14 MiB
Languages
Python 73%
Shell 25.1%
JavaScript 1.2%
Ruby 0.7%