Repository files navigation

dotfiles

Personal configuration for Bash and the applications used across Arch Linux, WSL Arch, Git Bash, Ubuntu, and macOS.

The repository is the source of truth. bash/bin/symlinks links supported configuration into $HOME and ~/.config.

Bash environment

~/.bashrc links to bash/bashrc. It establishes guarded sourcing and then loads bash/bashrc_personal. A file guard prevents the same configuration module from running more than once in a shell.

The personal configuration enables:

  • Vi command-line editing.
  • Unlimited, appended command history.
  • Automatic directory changes and spelling correction.
  • Dotfile globbing and multiline history preservation.
  • SSH agent keys and Neovim application aliases when available.

The bash/my_* modules load in this order:

  1. my_environment defines directory and service settings.
  2. my_functions provides reusable shell and path helpers.
  3. my_exports selects platform-aware applications and environment values.
  4. my_aliases defines commands, Vi mode, tmux behavior, and session keys.
  5. my_paths assembles Linux, WSL, language, and user executable paths.
  6. my_completions loads available platform and application completions.
  7. my_programs initializes optional tools such as fzf, NVM, uv, mise, and Starship.

Optional programs are guarded so a missing tool does not prevent Bash startup. Platform checks keep Linux, WSL, Git Bash, Ubuntu, and macOS behavior separate.

Readline

bash/inputrc is linked to ~/.inputrc. It enables Vi editing, Meta key support, colored completion, case-insensitive matching, and personal cursor and history bindings.

Run this after changing the file:

bind -f ~/.inputrc

Session bindings

sb/sessions.tsv is the source of truth for shared session bindings. bash/bin/generate-session-bindings generates Bash, tmux, and Hyprland configuration from that table.

On WSL, lowercase Alt bindings create or switch tmux sessions. Uppercase Alt bindings terminate them. For example:

  • Alt-W creates or switches to Work.
  • Alt-N creates or switches to Neovim.
  • Alt-Shift-W terminates Work.
  • Alt-Shift-N terminates Neovim.

tmux owns these keys while Neovim is running inside tmux, so Neovim does not need duplicate mappings.

Validate generated files with:

generate-session-bindings --check

Active Directory reconnect

adConnect does not run from .bashrc. Running it synchronously during shell startup can consume commands sent to new tmux panes and delay Bash, tmux, and Neovim.

Instead, ad-connect.timer schedules the ad-connect.service systemd user unit. The one-shot service:

  • Starts independently of interactive shell initialization.
  • Checks whether the AD network is reachable.
  • Detects Windows, WSL, and Linux reboots.
  • Uses ~/.config/krb5/user.keytab without reading terminal input.
  • Refreshes Kerberos credentials when reconnect state requires it.
  • Refreshes every eight hours by default, before a typical ten-hour ticket expires.
  • Uses noninteractive sudo for DNS and SSSD maintenance.
  • Records successful reconnect state and avoids repeated work.

The timer runs shortly after boot and retries periodically. vpnConnect continues to invoke adConnect with VPN-specific DNS behavior.

vpnConnect uses snx-rs to authenticate through DUO Mobile and establish the VPN tunnel. A DUO approval does not always mean the tunnel is ready: the VPN gateway can return is_authenticated=true without the SSL active_key that snx-rs needs to build the tunnel. In that case snx-rs exits with an error even though authentication succeeded. vpnConnect automatically retries this failure up to three total attempts by default. It invokes adConnect only after snx-rs reports Tunnel connected. Set SNX_MAX_ATTEMPTS or SNX_RETRY_DELAY to adjust the retry behavior.

Kerberos CIFS entries under /mnt can be accessed before the first ticket is available. Install the mount-unit retry policy so those early failures do not leave an automount permanently rate-limited:

sudo install -D -m 644 \
systemd/system/mnt-.mount.d/kerberos-retry.conf \
/etc/systemd/system/mnt-.mount.d/kerberos-retry.conf
sudo systemctl daemon-reload

The keytab is a local credential and must never be committed. Provision or replace it interactively with:

createUserKeytab

Recreate the keytab after changing the AD password.

Inspect the service with:

systemctl --user status ad-connect.timer --no-pager
systemctl --user status ad-connect.service --no-pager
journalctl --user -u ad-connect.service -b --no-pager
klist

Force an interactive recovery with:

adConnect -f

Installation

Create the configured links with:

bash/bin/symlinks --create

The script installs the systemd user units and enables ad-connect.timer. Reload systemd after changing a unit:

systemctl --user daemon-reload
systemctl --user restart ad-connect.timer

Validation

Useful checks after Bash changes:

bash -n bash/bashrc bash/bashrc_personal bash/my_*
bash -n bash/bin/adConnect bash/bin/adConnectService
bash -n bash/bin/createUserKeytab
generate-session-bindings --check
git diff --check

After a Windows or WSL reboot, open WSL normally. Bash and session bindings should be immediately usable while the systemd user timer handles AD reconnect work in the background.

About

My dotfiles re-born.

Resources

Stars

33 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

dotfiles

Personal configuration for Bash and the applications used across Arch Linux, WSL Arch, Git Bash, Ubuntu, and macOS.

The repository is the source of truth. bash/bin/symlinks links supported configuration into $HOME and ~/.config.

Bash environment

~/.bashrc links to bash/bashrc. It establishes guarded sourcing and then loads bash/bashrc_personal. A file guard prevents the same configuration module from running more than once in a shell.

The personal configuration enables:

  • Vi command-line editing.
  • Unlimited, appended command history.
  • Automatic directory changes and spelling correction.
  • Dotfile globbing and multiline history preservation.
  • SSH agent keys and Neovim application aliases when available.

The bash/my_* modules load in this order:

  1. my_environment defines directory and service settings.
  2. my_functions provides reusable shell and path helpers.
  3. my_exports selects platform-aware applications and environment values.
  4. my_aliases defines commands, Vi mode, tmux behavior, and session keys.
  5. my_paths assembles Linux, WSL, language, and user executable paths.
  6. my_completions loads available platform and application completions.
  7. my_programs initializes optional tools such as fzf, NVM, uv, mise, and Starship.

Optional programs are guarded so a missing tool does not prevent Bash startup. Platform checks keep Linux, WSL, Git Bash, Ubuntu, and macOS behavior separate.

Readline

bash/inputrc is linked to ~/.inputrc. It enables Vi editing, Meta key support, colored completion, case-insensitive matching, and personal cursor and history bindings.

Run this after changing the file:

bind -f ~/.inputrc

Session bindings

sb/sessions.tsv is the source of truth for shared session bindings. bash/bin/generate-session-bindings generates Bash, tmux, and Hyprland configuration from that table.

On WSL, lowercase Alt bindings create or switch tmux sessions. Uppercase Alt bindings terminate them. For example:

  • Alt-W creates or switches to Work.
  • Alt-N creates or switches to Neovim.
  • Alt-Shift-W terminates Work.
  • Alt-Shift-N terminates Neovim.

tmux owns these keys while Neovim is running inside tmux, so Neovim does not need duplicate mappings.

Validate generated files with:

generate-session-bindings --check

Active Directory reconnect

adConnect does not run from .bashrc. Running it synchronously during shell startup can consume commands sent to new tmux panes and delay Bash, tmux, and Neovim.

Instead, ad-connect.timer schedules the ad-connect.service systemd user unit. The one-shot service:

  • Starts independently of interactive shell initialization.
  • Checks whether the AD network is reachable.
  • Detects Windows, WSL, and Linux reboots.
  • Uses ~/.config/krb5/user.keytab without reading terminal input.
  • Refreshes Kerberos credentials when reconnect state requires it.
  • Refreshes every eight hours by default, before a typical ten-hour ticket expires.
  • Uses noninteractive sudo for DNS and SSSD maintenance.
  • Records successful reconnect state and avoids repeated work.

The timer runs shortly after boot and retries periodically. vpnConnect continues to invoke adConnect with VPN-specific DNS behavior.

vpnConnect uses snx-rs to authenticate through DUO Mobile and establish the VPN tunnel. A DUO approval does not always mean the tunnel is ready: the VPN gateway can return is_authenticated=true without the SSL active_key that snx-rs needs to build the tunnel. In that case snx-rs exits with an error even though authentication succeeded. vpnConnect automatically retries this failure up to three total attempts by default. It invokes adConnect only after snx-rs reports Tunnel connected. Set SNX_MAX_ATTEMPTS or SNX_RETRY_DELAY to adjust the retry behavior.

Kerberos CIFS entries under /mnt can be accessed before the first ticket is available. Install the mount-unit retry policy so those early failures do not leave an automount permanently rate-limited:

sudo install -D -m 644 \
systemd/system/mnt-.mount.d/kerberos-retry.conf \
/etc/systemd/system/mnt-.mount.d/kerberos-retry.conf
sudo systemctl daemon-reload

The keytab is a local credential and must never be committed. Provision or replace it interactively with:

createUserKeytab

Recreate the keytab after changing the AD password.

Inspect the service with:

systemctl --user status ad-connect.timer --no-pager
systemctl --user status ad-connect.service --no-pager
journalctl --user -u ad-connect.service -b --no-pager
klist

Force an interactive recovery with:

adConnect -f

Installation

Create the configured links with:

bash/bin/symlinks --create

The script installs the systemd user units and enables ad-connect.timer. Reload systemd after changing a unit:

systemctl --user daemon-reload
systemctl --user restart ad-connect.timer

Validation

Useful checks after Bash changes:

bash -n bash/bashrc bash/bashrc_personal bash/my_*
bash -n bash/bin/adConnect bash/bin/adConnectService
bash -n bash/bin/createUserKeytab
generate-session-bindings --check
git diff --check

After a Windows or WSL reboot, open WSL normally. Bash and session bindings should be immediately usable while the systemd user timer handles AD reconnect work in the background.

About

My dotfiles re-born.

Resources

Stars

33 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

dotfiles

Personal configuration for Bash and the applications used across Arch Linux, WSL Arch, Git Bash, Ubuntu, and macOS.

The repository is the source of truth. bash/bin/symlinks links supported configuration into $HOME and ~/.config.

Bash environment

~/.bashrc links to bash/bashrc. It establishes guarded sourcing and then loads bash/bashrc_personal. A file guard prevents the same configuration module from running more than once in a shell.

The personal configuration enables:

  • Vi command-line editing.
  • Unlimited, appended command history.
  • Automatic directory changes and spelling correction.
  • Dotfile globbing and multiline history preservation.
  • SSH agent keys and Neovim application aliases when available.

The bash/my_* modules load in this order:

  1. my_environment defines directory and service settings.
  2. my_functions provides reusable shell and path helpers.
  3. my_exports selects platform-aware applications and environment values.
  4. my_aliases defines commands, Vi mode, tmux behavior, and session keys.
  5. my_paths assembles Linux, WSL, language, and user executable paths.
  6. my_completions loads available platform and application completions.
  7. my_programs initializes optional tools such as fzf, NVM, uv, mise, and Starship.

Optional programs are guarded so a missing tool does not prevent Bash startup. Platform checks keep Linux, WSL, Git Bash, Ubuntu, and macOS behavior separate.

Readline

bash/inputrc is linked to ~/.inputrc. It enables Vi editing, Meta key support, colored completion, case-insensitive matching, and personal cursor and history bindings.

Run this after changing the file:

bind -f ~/.inputrc

Session bindings

sb/sessions.tsv is the source of truth for shared session bindings. bash/bin/generate-session-bindings generates Bash, tmux, and Hyprland configuration from that table.

On WSL, lowercase Alt bindings create or switch tmux sessions. Uppercase Alt bindings terminate them. For example:

  • Alt-W creates or switches to Work.
  • Alt-N creates or switches to Neovim.
  • Alt-Shift-W terminates Work.
  • Alt-Shift-N terminates Neovim.

tmux owns these keys while Neovim is running inside tmux, so Neovim does not need duplicate mappings.

Validate generated files with:

generate-session-bindings --check

Active Directory reconnect

adConnect does not run from .bashrc. Running it synchronously during shell startup can consume commands sent to new tmux panes and delay Bash, tmux, and Neovim.

Instead, ad-connect.timer schedules the ad-connect.service systemd user unit. The one-shot service:

  • Starts independently of interactive shell initialization.
  • Checks whether the AD network is reachable.
  • Detects Windows, WSL, and Linux reboots.
  • Uses ~/.config/krb5/user.keytab without reading terminal input.
  • Refreshes Kerberos credentials when reconnect state requires it.
  • Refreshes every eight hours by default, before a typical ten-hour ticket expires.
  • Uses noninteractive sudo for DNS and SSSD maintenance.
  • Records successful reconnect state and avoids repeated work.

The timer runs shortly after boot and retries periodically. vpnConnect continues to invoke adConnect with VPN-specific DNS behavior.

vpnConnect uses snx-rs to authenticate through DUO Mobile and establish the VPN tunnel. A DUO approval does not always mean the tunnel is ready: the VPN gateway can return is_authenticated=true without the SSL active_key that snx-rs needs to build the tunnel. In that case snx-rs exits with an error even though authentication succeeded. vpnConnect automatically retries this failure up to three total attempts by default. It invokes adConnect only after snx-rs reports Tunnel connected. Set SNX_MAX_ATTEMPTS or SNX_RETRY_DELAY to adjust the retry behavior.

Kerberos CIFS entries under /mnt can be accessed before the first ticket is available. Install the mount-unit retry policy so those early failures do not leave an automount permanently rate-limited:

sudo install -D -m 644 \
systemd/system/mnt-.mount.d/kerberos-retry.conf \
/etc/systemd/system/mnt-.mount.d/kerberos-retry.conf
sudo systemctl daemon-reload

The keytab is a local credential and must never be committed. Provision or replace it interactively with:

createUserKeytab

Recreate the keytab after changing the AD password.

Inspect the service with:

systemctl --user status ad-connect.timer --no-pager
systemctl --user status ad-connect.service --no-pager
journalctl --user -u ad-connect.service -b --no-pager
klist

Force an interactive recovery with:

adConnect -f

Installation

Create the configured links with:

bash/bin/symlinks --create

The script installs the systemd user units and enables ad-connect.timer. Reload systemd after changing a unit:

systemctl --user daemon-reload
systemctl --user restart ad-connect.timer

Validation

Useful checks after Bash changes:

bash -n bash/bashrc bash/bashrc_personal bash/my_*
bash -n bash/bin/adConnect bash/bin/adConnectService
bash -n bash/bin/createUserKeytab
generate-session-bindings --check
git diff --check

After a Windows or WSL reboot, open WSL normally. Bash and session bindings should be immediately usable while the systemd user timer handles AD reconnect work in the background.

About

My dotfiles re-born.

Resources

Stars

33 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

dotfiles

Personal configuration for Bash and the applications used across Arch Linux, WSL Arch, Git Bash, Ubuntu, and macOS.

The repository is the source of truth. bash/bin/symlinks links supported configuration into $HOME and ~/.config.

Bash environment

~/.bashrc links to bash/bashrc. It establishes guarded sourcing and then loads bash/bashrc_personal. A file guard prevents the same configuration module from running more than once in a shell.

The personal configuration enables:

  • Vi command-line editing.
  • Unlimited, appended command history.
  • Automatic directory changes and spelling correction.
  • Dotfile globbing and multiline history preservation.
  • SSH agent keys and Neovim application aliases when available.

The bash/my_* modules load in this order:

  1. my_environment defines directory and service settings.
  2. my_functions provides reusable shell and path helpers.
  3. my_exports selects platform-aware applications and environment values.
  4. my_aliases defines commands, Vi mode, tmux behavior, and session keys.
  5. my_paths assembles Linux, WSL, language, and user executable paths.
  6. my_completions loads available platform and application completions.
  7. my_programs initializes optional tools such as fzf, NVM, uv, mise, and Starship.

Optional programs are guarded so a missing tool does not prevent Bash startup. Platform checks keep Linux, WSL, Git Bash, Ubuntu, and macOS behavior separate.

Readline

bash/inputrc is linked to ~/.inputrc. It enables Vi editing, Meta key support, colored completion, case-insensitive matching, and personal cursor and history bindings.

Run this after changing the file:

bind -f ~/.inputrc

Session bindings

sb/sessions.tsv is the source of truth for shared session bindings. bash/bin/generate-session-bindings generates Bash, tmux, and Hyprland configuration from that table.

On WSL, lowercase Alt bindings create or switch tmux sessions. Uppercase Alt bindings terminate them. For example:

  • Alt-W creates or switches to Work.
  • Alt-N creates or switches to Neovim.
  • Alt-Shift-W terminates Work.
  • Alt-Shift-N terminates Neovim.

tmux owns these keys while Neovim is running inside tmux, so Neovim does not need duplicate mappings.

Validate generated files with:

generate-session-bindings --check

Active Directory reconnect

adConnect does not run from .bashrc. Running it synchronously during shell startup can consume commands sent to new tmux panes and delay Bash, tmux, and Neovim.

Instead, ad-connect.timer schedules the ad-connect.service systemd user unit. The one-shot service:

  • Starts independently of interactive shell initialization.
  • Checks whether the AD network is reachable.
  • Detects Windows, WSL, and Linux reboots.
  • Uses ~/.config/krb5/user.keytab without reading terminal input.
  • Refreshes Kerberos credentials when reconnect state requires it.
  • Refreshes every eight hours by default, before a typical ten-hour ticket expires.
  • Uses noninteractive sudo for DNS and SSSD maintenance.
  • Records successful reconnect state and avoids repeated work.

The timer runs shortly after boot and retries periodically. vpnConnect continues to invoke adConnect with VPN-specific DNS behavior.

vpnConnect uses snx-rs to authenticate through DUO Mobile and establish the VPN tunnel. A DUO approval does not always mean the tunnel is ready: the VPN gateway can return is_authenticated=true without the SSL active_key that snx-rs needs to build the tunnel. In that case snx-rs exits with an error even though authentication succeeded. vpnConnect automatically retries this failure up to three total attempts by default. It invokes adConnect only after snx-rs reports Tunnel connected. Set SNX_MAX_ATTEMPTS or SNX_RETRY_DELAY to adjust the retry behavior.

Kerberos CIFS entries under /mnt can be accessed before the first ticket is available. Install the mount-unit retry policy so those early failures do not leave an automount permanently rate-limited:

sudo install -D -m 644 \
systemd/system/mnt-.mount.d/kerberos-retry.conf \
/etc/systemd/system/mnt-.mount.d/kerberos-retry.conf
sudo systemctl daemon-reload

The keytab is a local credential and must never be committed. Provision or replace it interactively with:

createUserKeytab

Recreate the keytab after changing the AD password.

Inspect the service with:

systemctl --user status ad-connect.timer --no-pager
systemctl --user status ad-connect.service --no-pager
journalctl --user -u ad-connect.service -b --no-pager
klist

Force an interactive recovery with:

adConnect -f

Installation

Create the configured links with:

bash/bin/symlinks --create

The script installs the systemd user units and enables ad-connect.timer. Reload systemd after changing a unit:

systemctl --user daemon-reload
systemctl --user restart ad-connect.timer

Validation

Useful checks after Bash changes:

bash -n bash/bashrc bash/bashrc_personal bash/my_*
bash -n bash/bin/adConnect bash/bin/adConnectService
bash -n bash/bin/createUserKeytab
generate-session-bindings --check
git diff --check

After a Windows or WSL reboot, open WSL normally. Bash and session bindings should be immediately usable while the systemd user timer handles AD reconnect work in the background.

About

My dotfiles re-born.

Resources

Stars

33 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

dotfiles

Personal configuration for Bash and the applications used across Arch Linux, WSL Arch, Git Bash, Ubuntu, and macOS.

The repository is the source of truth. bash/bin/symlinks links supported configuration into $HOME and ~/.config.

Bash environment

~/.bashrc links to bash/bashrc. It establishes guarded sourcing and then loads bash/bashrc_personal. A file guard prevents the same configuration module from running more than once in a shell.

The personal configuration enables:

  • Vi command-line editing.
  • Unlimited, appended command history.
  • Automatic directory changes and spelling correction.
  • Dotfile globbing and multiline history preservation.
  • SSH agent keys and Neovim application aliases when available.

The bash/my_* modules load in this order:

  1. my_environment defines directory and service settings.
  2. my_functions provides reusable shell and path helpers.
  3. my_exports selects platform-aware applications and environment values.
  4. my_aliases defines commands, Vi mode, tmux behavior, and session keys.
  5. my_paths assembles Linux, WSL, language, and user executable paths.
  6. my_completions loads available platform and application completions.
  7. my_programs initializes optional tools such as fzf, NVM, uv, mise, and Starship.

Optional programs are guarded so a missing tool does not prevent Bash startup. Platform checks keep Linux, WSL, Git Bash, Ubuntu, and macOS behavior separate.

Readline

bash/inputrc is linked to ~/.inputrc. It enables Vi editing, Meta key support, colored completion, case-insensitive matching, and personal cursor and history bindings.

Run this after changing the file:

bind -f ~/.inputrc

Session bindings

sb/sessions.tsv is the source of truth for shared session bindings. bash/bin/generate-session-bindings generates Bash, tmux, and Hyprland configuration from that table.

On WSL, lowercase Alt bindings create or switch tmux sessions. Uppercase Alt bindings terminate them. For example:

  • Alt-W creates or switches to Work.
  • Alt-N creates or switches to Neovim.
  • Alt-Shift-W terminates Work.
  • Alt-Shift-N terminates Neovim.

tmux owns these keys while Neovim is running inside tmux, so Neovim does not need duplicate mappings.

Validate generated files with:

generate-session-bindings --check

Active Directory reconnect

adConnect does not run from .bashrc. Running it synchronously during shell startup can consume commands sent to new tmux panes and delay Bash, tmux, and Neovim.

Instead, ad-connect.timer schedules the ad-connect.service systemd user unit. The one-shot service:

  • Starts independently of interactive shell initialization.
  • Checks whether the AD network is reachable.
  • Detects Windows, WSL, and Linux reboots.
  • Uses ~/.config/krb5/user.keytab without reading terminal input.
  • Refreshes Kerberos credentials when reconnect state requires it.
  • Refreshes every eight hours by default, before a typical ten-hour ticket expires.
  • Uses noninteractive sudo for DNS and SSSD maintenance.
  • Records successful reconnect state and avoids repeated work.

The timer runs shortly after boot and retries periodically. vpnConnect continues to invoke adConnect with VPN-specific DNS behavior.

vpnConnect uses snx-rs to authenticate through DUO Mobile and establish the VPN tunnel. A DUO approval does not always mean the tunnel is ready: the VPN gateway can return is_authenticated=true without the SSL active_key that snx-rs needs to build the tunnel. In that case snx-rs exits with an error even though authentication succeeded. vpnConnect automatically retries this failure up to three total attempts by default. It invokes adConnect only after snx-rs reports Tunnel connected. Set SNX_MAX_ATTEMPTS or SNX_RETRY_DELAY to adjust the retry behavior.

Kerberos CIFS entries under /mnt can be accessed before the first ticket is available. Install the mount-unit retry policy so those early failures do not leave an automount permanently rate-limited:

sudo install -D -m 644 \
systemd/system/mnt-.mount.d/kerberos-retry.conf \
/etc/systemd/system/mnt-.mount.d/kerberos-retry.conf
sudo systemctl daemon-reload

The keytab is a local credential and must never be committed. Provision or replace it interactively with:

createUserKeytab

Recreate the keytab after changing the AD password.

Inspect the service with:

systemctl --user status ad-connect.timer --no-pager
systemctl --user status ad-connect.service --no-pager
journalctl --user -u ad-connect.service -b --no-pager
klist

Force an interactive recovery with:

adConnect -f

Installation

Create the configured links with:

bash/bin/symlinks --create

The script installs the systemd user units and enables ad-connect.timer. Reload systemd after changing a unit:

systemctl --user daemon-reload
systemctl --user restart ad-connect.timer

Validation

Useful checks after Bash changes:

bash -n bash/bashrc bash/bashrc_personal bash/my_*
bash -n bash/bin/adConnect bash/bin/adConnectService
bash -n bash/bin/createUserKeytab
generate-session-bindings --check
git diff --check

After a Windows or WSL reboot, open WSL normally. Bash and session bindings should be immediately usable while the systemd user timer handles AD reconnect work in the background.

About

My dotfiles re-born.

Resources

Stars

33 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

dotfiles

Personal configuration for Bash and the applications used across Arch Linux, WSL Arch, Git Bash, Ubuntu, and macOS.

The repository is the source of truth. bash/bin/symlinks links supported configuration into $HOME and ~/.config.

Bash environment

~/.bashrc links to bash/bashrc. It establishes guarded sourcing and then loads bash/bashrc_personal. A file guard prevents the same configuration module from running more than once in a shell.

The personal configuration enables:

  • Vi command-line editing.
  • Unlimited, appended command history.
  • Automatic directory changes and spelling correction.
  • Dotfile globbing and multiline history preservation.
  • SSH agent keys and Neovim application aliases when available.

The bash/my_* modules load in this order:

  1. my_environment defines directory and service settings.
  2. my_functions provides reusable shell and path helpers.
  3. my_exports selects platform-aware applications and environment values.
  4. my_aliases defines commands, Vi mode, tmux behavior, and session keys.
  5. my_paths assembles Linux, WSL, language, and user executable paths.
  6. my_completions loads available platform and application completions.
  7. my_programs initializes optional tools such as fzf, NVM, uv, mise, and Starship.

Optional programs are guarded so a missing tool does not prevent Bash startup. Platform checks keep Linux, WSL, Git Bash, Ubuntu, and macOS behavior separate.

Readline

bash/inputrc is linked to ~/.inputrc. It enables Vi editing, Meta key support, colored completion, case-insensitive matching, and personal cursor and history bindings.

Run this after changing the file:

bind -f ~/.inputrc

Session bindings

sb/sessions.tsv is the source of truth for shared session bindings. bash/bin/generate-session-bindings generates Bash, tmux, and Hyprland configuration from that table.

On WSL, lowercase Alt bindings create or switch tmux sessions. Uppercase Alt bindings terminate them. For example:

  • Alt-W creates or switches to Work.
  • Alt-N creates or switches to Neovim.
  • Alt-Shift-W terminates Work.
  • Alt-Shift-N terminates Neovim.

tmux owns these keys while Neovim is running inside tmux, so Neovim does not need duplicate mappings.

Validate generated files with:

generate-session-bindings --check

Active Directory reconnect

adConnect does not run from .bashrc. Running it synchronously during shell startup can consume commands sent to new tmux panes and delay Bash, tmux, and Neovim.

Instead, ad-connect.timer schedules the ad-connect.service systemd user unit. The one-shot service:

  • Starts independently of interactive shell initialization.
  • Checks whether the AD network is reachable.
  • Detects Windows, WSL, and Linux reboots.
  • Uses ~/.config/krb5/user.keytab without reading terminal input.
  • Refreshes Kerberos credentials when reconnect state requires it.
  • Refreshes every eight hours by default, before a typical ten-hour ticket expires.
  • Uses noninteractive sudo for DNS and SSSD maintenance.
  • Records successful reconnect state and avoids repeated work.

The timer runs shortly after boot and retries periodically. vpnConnect continues to invoke adConnect with VPN-specific DNS behavior.

vpnConnect uses snx-rs to authenticate through DUO Mobile and establish the VPN tunnel. A DUO approval does not always mean the tunnel is ready: the VPN gateway can return is_authenticated=true without the SSL active_key that snx-rs needs to build the tunnel. In that case snx-rs exits with an error even though authentication succeeded. vpnConnect automatically retries this failure up to three total attempts by default. It invokes adConnect only after snx-rs reports Tunnel connected. Set SNX_MAX_ATTEMPTS or SNX_RETRY_DELAY to adjust the retry behavior.

Kerberos CIFS entries under /mnt can be accessed before the first ticket is available. Install the mount-unit retry policy so those early failures do not leave an automount permanently rate-limited:

sudo install -D -m 644 \
systemd/system/mnt-.mount.d/kerberos-retry.conf \
/etc/systemd/system/mnt-.mount.d/kerberos-retry.conf
sudo systemctl daemon-reload

The keytab is a local credential and must never be committed. Provision or replace it interactively with:

createUserKeytab

Recreate the keytab after changing the AD password.

Inspect the service with:

systemctl --user status ad-connect.timer --no-pager
systemctl --user status ad-connect.service --no-pager
journalctl --user -u ad-connect.service -b --no-pager
klist

Force an interactive recovery with:

adConnect -f

Installation

Create the configured links with:

bash/bin/symlinks --create

The script installs the systemd user units and enables ad-connect.timer. Reload systemd after changing a unit:

systemctl --user daemon-reload
systemctl --user restart ad-connect.timer

Validation

Useful checks after Bash changes:

bash -n bash/bashrc bash/bashrc_personal bash/my_*
bash -n bash/bin/adConnect bash/bin/adConnectService
bash -n bash/bin/createUserKeytab
generate-session-bindings --check
git diff --check

After a Windows or WSL reboot, open WSL normally. Bash and session bindings should be immediately usable while the systemd user timer handles AD reconnect work in the background.

About

My dotfiles re-born.

Resources

Stars

33 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

dotfiles

Personal configuration for Bash and the applications used across Arch Linux, WSL Arch, Git Bash, Ubuntu, and macOS.

The repository is the source of truth. bash/bin/symlinks links supported configuration into $HOME and ~/.config.

Bash environment

~/.bashrc links to bash/bashrc. It establishes guarded sourcing and then loads bash/bashrc_personal. A file guard prevents the same configuration module from running more than once in a shell.

The personal configuration enables:

  • Vi command-line editing.
  • Unlimited, appended command history.
  • Automatic directory changes and spelling correction.
  • Dotfile globbing and multiline history preservation.
  • SSH agent keys and Neovim application aliases when available.

The bash/my_* modules load in this order:

  1. my_environment defines directory and service settings.
  2. my_functions provides reusable shell and path helpers.
  3. my_exports selects platform-aware applications and environment values.
  4. my_aliases defines commands, Vi mode, tmux behavior, and session keys.
  5. my_paths assembles Linux, WSL, language, and user executable paths.
  6. my_completions loads available platform and application completions.
  7. my_programs initializes optional tools such as fzf, NVM, uv, mise, and Starship.

Optional programs are guarded so a missing tool does not prevent Bash startup. Platform checks keep Linux, WSL, Git Bash, Ubuntu, and macOS behavior separate.

Readline

bash/inputrc is linked to ~/.inputrc. It enables Vi editing, Meta key support, colored completion, case-insensitive matching, and personal cursor and history bindings.

Run this after changing the file:

bind -f ~/.inputrc

Session bindings

sb/sessions.tsv is the source of truth for shared session bindings. bash/bin/generate-session-bindings generates Bash, tmux, and Hyprland configuration from that table.

On WSL, lowercase Alt bindings create or switch tmux sessions. Uppercase Alt bindings terminate them. For example:

  • Alt-W creates or switches to Work.
  • Alt-N creates or switches to Neovim.
  • Alt-Shift-W terminates Work.
  • Alt-Shift-N terminates Neovim.

tmux owns these keys while Neovim is running inside tmux, so Neovim does not need duplicate mappings.

Validate generated files with:

generate-session-bindings --check

Active Directory reconnect

adConnect does not run from .bashrc. Running it synchronously during shell startup can consume commands sent to new tmux panes and delay Bash, tmux, and Neovim.

Instead, ad-connect.timer schedules the ad-connect.service systemd user unit. The one-shot service:

  • Starts independently of interactive shell initialization.
  • Checks whether the AD network is reachable.
  • Detects Windows, WSL, and Linux reboots.
  • Uses ~/.config/krb5/user.keytab without reading terminal input.
  • Refreshes Kerberos credentials when reconnect state requires it.
  • Refreshes every eight hours by default, before a typical ten-hour ticket expires.
  • Uses noninteractive sudo for DNS and SSSD maintenance.
  • Records successful reconnect state and avoids repeated work.

The timer runs shortly after boot and retries periodically. vpnConnect continues to invoke adConnect with VPN-specific DNS behavior.

vpnConnect uses snx-rs to authenticate through DUO Mobile and establish the VPN tunnel. A DUO approval does not always mean the tunnel is ready: the VPN gateway can return is_authenticated=true without the SSL active_key that snx-rs needs to build the tunnel. In that case snx-rs exits with an error even though authentication succeeded. vpnConnect automatically retries this failure up to three total attempts by default. It invokes adConnect only after snx-rs reports Tunnel connected. Set SNX_MAX_ATTEMPTS or SNX_RETRY_DELAY to adjust the retry behavior.

Kerberos CIFS entries under /mnt can be accessed before the first ticket is available. Install the mount-unit retry policy so those early failures do not leave an automount permanently rate-limited:

sudo install -D -m 644 \
systemd/system/mnt-.mount.d/kerberos-retry.conf \
/etc/systemd/system/mnt-.mount.d/kerberos-retry.conf
sudo systemctl daemon-reload

The keytab is a local credential and must never be committed. Provision or replace it interactively with:

createUserKeytab

Recreate the keytab after changing the AD password.

Inspect the service with:

systemctl --user status ad-connect.timer --no-pager
systemctl --user status ad-connect.service --no-pager
journalctl --user -u ad-connect.service -b --no-pager
klist

Force an interactive recovery with:

adConnect -f

Installation

Create the configured links with:

bash/bin/symlinks --create

The script installs the systemd user units and enables ad-connect.timer. Reload systemd after changing a unit:

systemctl --user daemon-reload
systemctl --user restart ad-connect.timer

Validation

Useful checks after Bash changes:

bash -n bash/bashrc bash/bashrc_personal bash/my_*
bash -n bash/bin/adConnect bash/bin/adConnectService
bash -n bash/bin/createUserKeytab
generate-session-bindings --check
git diff --check

After a Windows or WSL reboot, open WSL normally. Bash and session bindings should be immediately usable while the systemd user timer handles AD reconnect work in the background.

About

My dotfiles re-born.

Resources

Stars

33 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

dotfiles

Personal configuration for Bash and the applications used across Arch Linux, WSL Arch, Git Bash, Ubuntu, and macOS.

The repository is the source of truth. bash/bin/symlinks links supported configuration into $HOME and ~/.config.

Bash environment

~/.bashrc links to bash/bashrc. It establishes guarded sourcing and then loads bash/bashrc_personal. A file guard prevents the same configuration module from running more than once in a shell.

The personal configuration enables:

  • Vi command-line editing.
  • Unlimited, appended command history.
  • Automatic directory changes and spelling correction.
  • Dotfile globbing and multiline history preservation.
  • SSH agent keys and Neovim application aliases when available.

The bash/my_* modules load in this order:

  1. my_environment defines directory and service settings.
  2. my_functions provides reusable shell and path helpers.
  3. my_exports selects platform-aware applications and environment values.
  4. my_aliases defines commands, Vi mode, tmux behavior, and session keys.
  5. my_paths assembles Linux, WSL, language, and user executable paths.
  6. my_completions loads available platform and application completions.
  7. my_programs initializes optional tools such as fzf, NVM, uv, mise, and Starship.

Optional programs are guarded so a missing tool does not prevent Bash startup. Platform checks keep Linux, WSL, Git Bash, Ubuntu, and macOS behavior separate.

Readline

bash/inputrc is linked to ~/.inputrc. It enables Vi editing, Meta key support, colored completion, case-insensitive matching, and personal cursor and history bindings.

Run this after changing the file:

bind -f ~/.inputrc

Session bindings

sb/sessions.tsv is the source of truth for shared session bindings. bash/bin/generate-session-bindings generates Bash, tmux, and Hyprland configuration from that table.

On WSL, lowercase Alt bindings create or switch tmux sessions. Uppercase Alt bindings terminate them. For example:

  • Alt-W creates or switches to Work.
  • Alt-N creates or switches to Neovim.
  • Alt-Shift-W terminates Work.
  • Alt-Shift-N terminates Neovim.

tmux owns these keys while Neovim is running inside tmux, so Neovim does not need duplicate mappings.

Validate generated files with:

generate-session-bindings --check

Active Directory reconnect

adConnect does not run from .bashrc. Running it synchronously during shell startup can consume commands sent to new tmux panes and delay Bash, tmux, and Neovim.

Instead, ad-connect.timer schedules the ad-connect.service systemd user unit. The one-shot service:

  • Starts independently of interactive shell initialization.
  • Checks whether the AD network is reachable.
  • Detects Windows, WSL, and Linux reboots.
  • Uses ~/.config/krb5/user.keytab without reading terminal input.
  • Refreshes Kerberos credentials when reconnect state requires it.
  • Refreshes every eight hours by default, before a typical ten-hour ticket expires.
  • Uses noninteractive sudo for DNS and SSSD maintenance.
  • Records successful reconnect state and avoids repeated work.

The timer runs shortly after boot and retries periodically. vpnConnect continues to invoke adConnect with VPN-specific DNS behavior.

vpnConnect uses snx-rs to authenticate through DUO Mobile and establish the VPN tunnel. A DUO approval does not always mean the tunnel is ready: the VPN gateway can return is_authenticated=true without the SSL active_key that snx-rs needs to build the tunnel. In that case snx-rs exits with an error even though authentication succeeded. vpnConnect automatically retries this failure up to three total attempts by default. It invokes adConnect only after snx-rs reports Tunnel connected. Set SNX_MAX_ATTEMPTS or SNX_RETRY_DELAY to adjust the retry behavior.

Kerberos CIFS entries under /mnt can be accessed before the first ticket is available. Install the mount-unit retry policy so those early failures do not leave an automount permanently rate-limited:

sudo install -D -m 644 \
systemd/system/mnt-.mount.d/kerberos-retry.conf \
/etc/systemd/system/mnt-.mount.d/kerberos-retry.conf
sudo systemctl daemon-reload

The keytab is a local credential and must never be committed. Provision or replace it interactively with:

createUserKeytab

Recreate the keytab after changing the AD password.

Inspect the service with:

systemctl --user status ad-connect.timer --no-pager
systemctl --user status ad-connect.service --no-pager
journalctl --user -u ad-connect.service -b --no-pager
klist

Force an interactive recovery with:

adConnect -f

Installation

Create the configured links with:

bash/bin/symlinks --create

The script installs the systemd user units and enables ad-connect.timer. Reload systemd after changing a unit:

systemctl --user daemon-reload
systemctl --user restart ad-connect.timer

Validation

Useful checks after Bash changes:

bash -n bash/bashrc bash/bashrc_personal bash/my_*
bash -n bash/bin/adConnect bash/bin/adConnectService
bash -n bash/bin/createUserKeytab
generate-session-bindings --check
git diff --check

After a Windows or WSL reboot, open WSL normally. Bash and session bindings should be immediately usable while the systemd user timer handles AD reconnect work in the background.

About

My dotfiles re-born.

Resources

Stars

33 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages