Architecture: - Remove Chrome extension (project fully device-side, no target-machine deps) - Update all docs from "three-layer" to "two-layer" privacy (video redact + network intercept) - Add comprehensive architecture docs (overview, subsystem designs) Services: - kvm_agent: hybrid planner (template/local/cloud), screen state detection, mouse-first architecture, app launcher, visual workflow tests - privacy_gateway: upload scanner, privacy LLM integration, REST API - doc_processor: new document processing service Deployment: - Add kvm-bridge, kvm-meta, kvm-privacy deb package definitions - New systemd services (doc-processor, kvm-gateway, rkllm-server) - Network deploy configs, journald forwarding - Remove secrets.env templates from packages Plans & Docs: - HDMI-TX DRM local output + OSD design (drm_output.c, VOP2 multi-plane) - AI Agent token optimization plan (72% savings via caching/pruning/fingerprint) - Model sync: all RKNN/ONNX models now in project directory - Native H.264 adaptive bitrate plan Submodules updated: - deps/KVM: WebUI i18n, RBAC, DDNS, Agent API, OCR models (LFS) - deps/embedding: models synced (LFS), benchmarks, Ollama backend - deps/info-privacy-rs: regex PII detection, face detection integration Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
19 lines
550 B
Plaintext
19 lines
550 B
Plaintext
# /etc/systemd/journald.conf.d/kvm.conf
|
|
#
|
|
# KVM-Privacy journald configuration for NanoPC-T6 (eMMC protection).
|
|
# Volatile mode keeps logs in RAM only — protects eMMC from write wear.
|
|
# Ring buffer capped at 128M, entries retained for 7 days max.
|
|
#
|
|
# Install: cp deploy/systemd/journald-kvm.conf /etc/systemd/journald.conf.d/kvm.conf
|
|
# Reload: systemctl restart systemd-journald
|
|
|
|
[Journal]
|
|
Storage=volatile
|
|
RuntimeMaxUse=128M
|
|
RuntimeKeepFree=64M
|
|
RuntimeMaxFileSize=32M
|
|
MaxRetentionSec=7day
|
|
RateLimitIntervalSec=5s
|
|
RateLimitBurst=1000
|
|
Compress=yes
|