for file in $(git diff --cached --name-only) is unquoted, so a staged path
containing whitespace split into tokens, every token failed the [ -f ] guard, and
the file was never measured. A 17MB "my big file.dat" passed the 5MB ceiling
without the check ever running — REVIEWED-105's class (a check that passes
because it could not run), in the guard rather than in a declared check.
Now null-delimited (-z / read -d ''), fed by process substitution rather than a
pipe so `exit 1` still refuses the commit from inside the loop body.
Controls, run before committing:
space-in-name 17MB -> REFUSED (the fix; previously committed)
plain 17MB -> REFUSED (unchanged)
small file -> COMMITTED (unchanged)
staged deletion -> COMMITTED, no crash (the [ -f ] guard is intact)
newline+unicode name-> REFUSED (impossible under the old loop)
Narrows nothing and widens nothing: it makes the check do what it already said.
The 5MB ceiling and the LFS advice line are UNTOUCHED — that is the policy
question in PENDING-163, and it is the steward's.
Also files PENDING-163 AMENDMENT 1 (joins, replaces nothing), raised by the jurist
reading the item against REVIEWED-100/105 and verified empirically here:
- CONFIRMED: option (ii) does NOT widen permissions generally. git cat-file -s
reads the staged blob: an LFS-tracked 17MB file stages at 133 bytes, a plain
one stages at 17825792 and is still refused. The item's "widens what may be
committed everywhere" is withdrawn as false. That error is why the fork went
to the steward as a policy question at all.
- ACCEPTED: .gitattributes already is the per-repo versioned declaration that
option (iii) proposed to build. (iii) WITHDRAWN.
- CONFIRMED, and worse than visible from outside: (iii) inverts REVIEWED-100's
polarity, and the parser would refuse an exemption line as malformed.
- The jurist's fourth point does NOT hold — line 46's [ -f "$file" ] guard is
present, so staged deletions never reach wc -c. Flagged by them as inferred,
and it was. But the class they predicted is real, at line 45, by a different
mechanism. The inference was wrong; the instinct was not.
Recommendation changes from "(i) now, (iii) later" to "(ii)". Still the steward's.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NvZAKSf9aqratbqHbU9LK5
🖖 David's Dotfiles - "Engage!"
"Make it so!" - A complete macOS setup system inspired by Star Trek's efficiency and elegance.
From zero to fully configured macOS in minutes. This dotfiles repository provides a comprehensive, automated setup for developers, writers, and knowledge workers.
🚀 Quick Start
One command to rule them all:
# From GitHub
git clone https://github.com/davidglidden/dotfiles.git ~/dotfiles && ~/dotfiles/engage
# From Gitea (alternative mirror)
git clone git@git.davidglidden.eu:davidglidden/dotfiles.git ~/dotfiles && ~/dotfiles/engage
That's it! The engage script will guide you through a complete system setup.
✨ What This System Provides
📦 Software Management
- 120+ CLI tools via Homebrew (development, media, security)
- 40+ Applications via casks (productivity, creativity, utilities)
- 20+ Mac App Store apps via
mas(native macOS apps)
🔧 Configuration Management
- Shell setup: Zsh with Antidote, Powerlevel10k, history sync
- Development tools: Git hooks, SSH templates, NPM config
- Application configs: LaunchBar, Hazel, Bartender, Karabiner
- Obsidian vault: Complete knowledge management system
🖥️ macOS System Configuration
- System preferences: Dock, Finder, keyboard, security
- Security hardening: Firewall, privacy, authentication
- Keyboard shortcuts: Mission Control, app shortcuts
- Developer settings: Safari dev tools, Terminal enhancements
🛡️ Backup & Security Strategy
- Encrypted backups for sensitive files (SSH keys, credentials)
- History management with daily snapshots and retention
- Git hooks for security and code quality
- Application data backup and restore scripts
📁 Repository Structure
dotfiles/
├── engage # 🖖 Master installation script
├── Brewfile # Package management (brew/cask/mas)
├── README.md # This file
├── .gitconfig # Git configuration
├── .npmrc # NPM defaults
├── .zshrc # Shell configuration
├── .vimrc # Vim configuration
├── bin/ # Custom scripts
│ ├── backup-dotfiles # Quick dotfiles backup
│ └── check-app-configs # Configuration status checker
├── git/ # Git configuration
│ └── hooks/ # Global git hooks
├── macos/ # macOS system configuration
│ ├── setup-macos.sh # Master macOS setup
│ ├── defaults.sh # System preferences
│ ├── security.sh # Security hardening
│ └── keyboard-shortcuts.sh # Custom shortcuts
├── macos-apps/ # macOS app configurations
│ └── backup-app-configs.sh # App settings backup
├── obsidian/ # Obsidian knowledge vault
│ ├── setup-obsidian.sh # Vault configuration
│ └── community-plugins.json # Essential plugins
├── scripts/ # Installation scripts
│ └── symlinks.sh # Dotfile linking
├── shell/ # Shell enhancements
│ └── history-sync.zsh # History management
└── ssh/ # SSH configuration
├── config.example # SSH config template
└── README.md # SSH setup guide
🎯 Core Philosophy
This system balances automation with choice:
- Smart defaults that work out of the box
- Interactive modes for customization
- Modular design - use what you need
- Security first - encrypted backups, secure defaults
- Documentation - clear guides and examples
Inspired by the best dotfiles repositories but designed for real-world complexity.
📱 Essential Applications Included
Development
- iTerm2 + Kitty - Terminal emulators
- BBEdit - Text editor with deep macOS integration
- GitHub Desktop - Git GUI
- Docker - Containerization
Productivity
- Obsidian - Knowledge management powerhouse
- 1Password - Password management
- LaunchBar - Application launcher
- Hazel - Automated file organization
- Drafts - Quick capture and text processing
Utilities
- Karabiner-Elements - Keyboard customization
- Bartender - Menu bar organization
- Keka - Archive utility
- Oversight - Privacy monitoring
- Signal - Secure messaging
Creative & Media
- VLC - Media player
- HandBrake - Video transcoding
- Transmit - File transfer
- Calibre - E-book management
🛠️ Advanced Usage
Manual Installation Steps
If you prefer granular control:
# 1. Install packages only
brew bundle install --file=~/dotfiles/Brewfile
# 2. Set up dotfiles
~/dotfiles/scripts/symlinks.sh
# 3. Configure macOS
~/dotfiles/macos/setup-macos.sh
# 4. Set up applications
~/dotfiles/macos-apps/backup-app-configs.sh
Customization
Modify the Brewfile to add/remove applications:
# Add new CLI tool
brew "your-tool"
# Add new application
cask "your-app"
# Add Mac App Store app
mas "App Name", id: 123456789
Customize macOS defaults in macos/defaults.sh:
# Change dock position
defaults write com.apple.dock orientation -string "left"
# Adjust key repeat speed
defaults write NSGlobalDomain KeyRepeat -int 1
Backup Strategy
Before making changes:
# Backup current dotfiles
~/dotfiles/bin/backup-dotfiles
# Backup macOS settings
~/dotfiles/macos/backup-defaults.sh
# Backup sensitive files (encrypted)
~/dotfiles/backup-scripts/backup-sensitive.sh
🔐 Security Features
- SSH keys encrypted with GPG
- Firewall enabled with stealth mode
- Privacy settings optimized
- Git hooks prevent secrets in commits
- Secure defaults for Safari and system
- Application permissions documented
🧠 Obsidian Knowledge System
Includes a sophisticated personal knowledge management setup:
- 13 essential plugins for advanced functionality
- Template system with Templater integration
- Daily/weekly/monthly review cycles
- Christopher Alexander pattern language philosophy
- Multilingual support (EN/ES/FR/CA)
🤝 Contributing
This is a personal dotfiles repository, but ideas and improvements are welcome:
- Fork the repository
- Create a feature branch
- Test thoroughly on a fresh macOS installation
- Submit a pull request with clear description
📜 License
MIT License - Use, modify, and share freely.
🙏 Acknowledgments
Inspired by:
- Mathias Bynens' dotfiles
- ptb/mac-setup
- Homebrew Bundle
- The Star Trek universe for the best command ever: "Engage!"
Live long and prosper! 🖖
Made with ❤️ for the macOS community