Repository navigation
Releases: Renegade-Penguin/Hammunition
Release list
v0.21.0
-
The console's Repeaters screen (
7on Home, #322): the repeater layers grouped by area with the active mark, the areas, and keys to fetch RepeaterBook by state (opening Secrets first whenREPEATERBOOKcannot be supplied), import an export, choose the active areas, remove a layer and look repeaters up by place, distance, band and mode; and, from both it and Secrets, an offer to installrepeaterbook-clientwhen it is missing, the fetch running after a successful install (#344). D-059, D-064, D-074, D-081, D-082. -
hammunition secrets status [--json]says where each secret the engine knows would come from (the environment, Doppler or nowhere), the unit and first command it unlocks and the exact ways to provide it, and never a value, a prefix or a length; the console gains a Secrets screen (3on Home) that reads it, names a Doppler project and config throughstation set, keeps a value entered for the session in the console's memory only (handed to the engine commands it starts, written nowhere, cleared on exit) and runsmaps repeaters fetch-repeaterbookonce a source answers. Built against fixtures and the fake engine; not yet run against the live RepeaterBook API or on the field laptop (#321, D-081, D-059). -
hammunition-consoleis a catalog unit (D-059, D-021; branchconsole-unit): a terminal front end in its own repository, pinned by its tag's source-archive sha256 like the tray, installed by name and in no profile, with a terminal menu entry. It reads only--jsondocuments and runs every change in a pane where a person types any consent.docs/getting-started/console.mdwalks the first run. Rename this fragment to<PR number>.added.mdwhen the pull request has a number. Superseded within this same release: the console moved into the engine ashammunition console(#302, below) and the unit is retired. -
Atheris fuzz targets for the parsers, run by GYST's
python-fuzz.yml(part of #333; branchfuzz-targets):fuzz/holds six targets (manifest loaders, repeater imports, Maidenhead, gpsd JSON,os-release, station config); afuzzjob inci.ymlruns them 30 s each on a pull request and 600 s on the weekly schedule;tests/test_fuzz_targets.pykeeps them runnable. Found and fixed: a bare carriage return in a CSV row escapedmaps repeaters importand the ETCC and Direwolf readers ascsv.Errorinstead of aRepeaterInputError, and a station file with a non-text key died with aTypeErrorinstead of aStationError. Rename this fragment to<PR number>.added.mdwhen the pull request has a number. -
hammunition hardware gps-resume-report(read-only,--jsonas agps-resume-reportdocument) shows whether the installed GPS resume step matches the engine's, the unit's last result, gpsd's device list and a data check, the receiver's USB facts and the step's last run's lines; the step now keeps those lines in/run/hammunition/gps-resume.logthrough a third filehardware applywrites (/etc/tmpfiles.d/hammunition-gps-resume.conf), so nosystemd-journalmembership is needed.hammunition time measure --minutes N [--pps]samplesntpq -pnandppstestfor the GPS-takeover bench. Part of #177 and #310 (D-058, D-059; the bench is session 14 ofdocs/reference/bench-verification-5430.md, not yet run). -
Infrastructure and EMCOMM layers are kept per region (issue #327, part of #326; D-075 amended, D-082):
maps infra importandfetch-fcc-asr/fetch-nwrwrite one layer per theme and installed region (infra-osm-medical-<region slug>), data-source layers clipped to each region's box, somaps activatedraws only the active regions' infrastructure in QMapShack, Navit and the browser map.--mergedkeeps one layer across every region; an older merged layer is left alone with a note, once;maps infra remove --layertakes a theme or<theme>-<region>; theinfradocuments' layer views carryarea. -
hammunition maps activate CODE|REGION ... | --all | --none [--dry-run]andmaps areasswitch the active area of operations (the station valueactive_areas,station set --active-areas,--clear-active-areas): QMapShack'spoiPaths(a directory of links to the active areas'.poifiles), Navit's map set and the browser map's list follow it,maps repeaters list --jsonand the infrastructure documents carryactiveper layer, and deactivating deletes nothing; also fixesensure_pathsswapping one path for another under one key. Built and tested on synthetic layers, not yet run in QMapShack, Navit or a browser (#328, part of #326, D-082). -
The
gpsdunit now installspps-toolswith it, sohammunition time measure --ppscan runppsteston a machine set up for GPS time on either route (ntpsec, D-058, or thechronyunit, D-072); closes #319. -
hammunition maps repeaters fetch-repeaterbook, therepeaterbook-clientunit and one secrets helper (D-081, D-078; branchrepeaterbook-api):resolve_secret(name)reads a key from an environment variable, then Doppler (station set --doppler-project/--doppler-config,--clear-doppler), and never from the repository, station file, argv or a log; the run log redacts it and any credential header. The verb runs the unofficialrepeaterbookclient (a hash-pinned venv unit, registered with RepeaterBook as App #114; the operator generates their own token for it) through an engine-owned runner, with the token in that subprocess's environment only, into an unverified, personal-userepeaterbooklayer (0600, credited with a link, never mirrored, never listed byartifacts). Built against the documentation and the client's source; not yet run against the live API. Rename this fragment to<PR number>.added.mdwhen the pull request has a number. -
hammunition maps repeaters list [--layer ID] [--json]reads the repeater layers back as arepeaters-listdocument for front ends: layers withpersonal_useandunverified, the joined rows with their layer, the credits to print, and the layers it could not read, exit 0 on a partial list; read-only (#312; D-074 amended 2026-10-04, D-059, D-081). -
Repeaters have a mode vocabulary (
FM,DMR,D-STAR,YSF,P25,NXDN,M17,TETRA,ATV), a band and the digital details a source actually supplies;maps repeaters listgains--near GRID|LAT,LON,--within KM,--bandand--modewith distance and bearing, nearest first; the QMapShack POI has one category per mode and every name carriesN0CALL 146.940 2m FM DMRfor a text search (#313; D-074 amended 2026-10-04). -
Reticulum, NomadNet and LXMF (Track C, PR 2, issue #105, D-080). Three
hash-pinned per-user venvs,rns,lxmfandnomadnet, because no archive
carries any of them:rnsexposes every console script Reticulum declares
(rnsd,rnstatus,rnpath,rnprobe,rnid,rncp,rnx,rnsh, the
RNode flasherrnodeconfand the rest) and installs a user service,
hammunition-rnsd, that keeps one shared instance per machine (the first
operator's service runs it and another account's attaches as a client; enabled at
install, started at next login; an abstract local socket, not a TCP port,
measured in a Debian 13 container);lxmfgiveslxmdand starts nothing;
nomadnetgives the terminal messenger and a menu entry. The Reticulum
License (MIT plus two use restrictions, not OSI-approved) is printed on the
plan line that installs the venv and never gated; NomadNet isGPL-3.0-only
by its shipped text. The engine writes no Reticulum configuration and
uninstall leaves~/.reticulum,~/.nomadnetwork,~/.lxmdand~/.rnsh.
New post-1.0meshprofile (the three pluspython3-meshtasticand
gtk-meshtastic-client), arnodehardware entry (untested: no identifier
of its own), anddocs/guides/mesh-and-reticulum.mdwith four
troubleshooting entries. Engine: a user service'sexecmay start
{venv}/..., and a venv block may state itslicenceandlicence_urlon
its plan line. Two containers on one bridge found each other, exchanged an
LXMF message and ranrnsh; no LoRa link has been run. -
hammunition self-updatepulls the engine's own checkout and re-runsbootstrap.sh, and--version, every--jsondocument anddoctorsay when the venv lags the checkout (#303, #311). The verb fetches, fast-forwards toorigin/main(or the newestv*tag with--release) and re-runs bootstrap, each step printed before it runs,--dry-runprinting the commits that would arrive; it refuses a dirty tree, a detached or non-mainbranch and a non-fast-forward, and never touches apt, units or the station; its run is teed to a D-077 log.hammunition --versionprints0.20.0 (checkout), 0.19.0 (installed); runhammunition self-update`` when the editable install's metadata is behindpyproject.toml, the `engine` field of every document is the checkout's version, `doctor` gains an `engine version` check with the fix as argv, and the console's Home offers the update with `U`. -
hammunition console: the terminal console is part of the engine (#302, D-059 amended 2026-10-04):hammunition_consolemoved tosrc/hammunition/console/with its tests intests/console/, one release and one version, soENGINE_FLOOR,EngineTooOldand the fixtures'enginefield are gone. urwid is the optionalconsoleextra; without it the subcommand prints one line naming the install command and exits 2. The console runs the engine as<interpreter> -m hammunition. Thehammunition-consoleunit is retired,menus applywrites the engine's own entry for it, andtests/console/capture_fixtures.pyrefuses to run unless HOME is a temporary directory it made itself. The old repository is archived; see the console reference atdocs/console/index.md. -
hammunition-hillpinned to v1.2.0 (the repeaters panel with any-centre lookup and mode filters, hill #83/#85), its digest from t...
v0.20.0
-
tar1090, the ADS-B aircraft map, as a page in
reference serve
(D-071 amended 2026-10-02; D.10b's route). A newtar1090unit
(listening, depends onreadsb, so deferred by name where readsb is) is a
dataunit: GitHub's archive of upstream's commite784ee5(no tags, no
distribution packages it: own-choice pin, D-024), sha256 pinned,html/and
the GPL-2.0-or-later licence kept. Its rootwget | bashinstaller and
lighttpd on port 80 are not used.hammunition reference serveserves the
page at/aircraft/on 127.0.0.1, withdata/read from readsb's directory
(/run/readsb, or--readsb-json DIR), read-only. The page cannot call
out: tar1090's settings for photographs, routes and overlays are switched
off, its online layers are replaced by the station's PMTiles map (a blank
background, with the reason on the page, whenosm-pmtilesis absent), and
every response carries a Content-Security-Policy that names no host. The
page is given a reducedreceiver.jsonso it reads plainaircraft.json
(readsb 3.14.1630 also writesaircraft.binCraft.zst, which tar1090 would
otherwise ask for). The aircraft database is not carried (upstream's one commit cannot be pinned).
Tested in headless Chromium: the aircraft appear, no request leaves
loopback, the same page as upstream ships it does ask other hosts, and the
policy alone refuses them. Not measured: a live receiver, Firefox, a real
region at street zoom. -
Every run leaves a log (D-077).
install,uninstall,update,
menus apply,hardware apply|unapply|park|wake, everymaps ...,
reference serve,services ...andtime mode----dry-runincluded --
write<state dir>/logs/<UTC>-<command>-<pid>.log: the argv with station
flags redacted, everything printed on stdout and stderr, each command run with
its output as it arrives and its exit code, aresultline; 0600, flushed
per line, owner-aware under sudo. Rotated at the start of each run to 30
files and 200 MB, never a run in progress. Newhammunition logs [--last | --path | --json];doctorreports the logs; a run endsLog: <path>. The
transaction log now rotates past 1 MiB intotransactions-<NNNNNN>-<UTC>.jsonl
archives that every reader walks in order (never deleted);statusis tested
identical before and after.docs/reference/run-logs.md. -
SuperSDR joins the
listeningprofile. Its profile documentation states
the D-033 position for its missing upstream licence and that it is never
mirrored. -
Transaction history is now readable (#243, D-077).
hammunition transactions [--last N] [--json]lists the live and archived transaction
records in chronological order, including deferred units and whether a run
completed, failed, aborted or is still in progress. -
Live feedback while an install step runs (#270, D-077). On a terminal a
command that runs longer than two seconds gets one in-place status line under
its$line,… 1m 42s <the command's last output line>, erased when the
command ends;install -v/--verbose(anduninstall) stream every output
line as it arrives instead. Nothing is added when stdout is not a terminal,
and the run log is byte-for-byte what it was in every mode. The status line and
the sudo keepalive's warnings share one terminal writer (progress.LiveStatus),
so they cannot interleave. A step the backend knows is long (a submodule fetch,
acmake/make/qmakecompile, a venvpip install, a node build) says
this step can take several minutesin the plan and at step start, with no
invented duration;StepViewgainslong_runningin--json. -
HydraSDR RFOne and RigExpert Fobos SDR: host software and device entries,
from upstream's own files, for hardware nobody here owns (D-024,
D-027, D-028, D-029, D-032). Five units:hydrasdr-host(the
library and its seventeen tools) andsoapysdr-module-hydrasdr, and
libfobos,libfobos-sdr-agileandsoapysdr-module-fobos, the last
needing both libraries to build. Kali and Ubuntu 26.04 take the HydraSDR
units from apt; every other target builds the tags Debian packages
(v1.1.1, v1.0.1). Nothing Fobos is packaged anywhere, solibfobos(head
1e0fab3) andsoapysdr-module-fobos(aa8d486) are commit pins with a
pin_review,libfobos-sdr-agileis upstream's tag. Two entries under
catalog/hardware/devices/:hydrasdr-rfone(38af:0001,status: supportedin D-027's shape, with 1d50:60a1 recorded inrejected_ids
because the Airspy R2 and Mini use it and no rule can tell them apart, and
the NXP DFU recovery id marked shared with the HackRF) andfobos-sdr
(16d0:132e,untested; both firmware families present it and differ only
in bcdDevice). Identifiers are cited as commit-pinned URLs into the vendors'
repositories;scripts/check_rule_citations.pynow ignores a rules file
named inside a URL, since the sweep covers distribution packages only.
Built in rootless containers on Debian 13, Ubuntu 24.04, Ubuntu 26.04 and
Kali (x86_64): all five units build and install,hydrasdr_infoand
fobos_devinforun without a board,SoapySDRUtil --infolists both
modules. Three defects of upstream's builds are handled in the manifests,
each measured: libfobos-sdr-agile wrote/etc/udev/rules.das root (a
CRLF-preserving patch removes it), SoapyHydraSDR also wrote into dpkg's
module directory (a define), and nothing a build into/usr/locallinks
was found withoutldconfig(an embedded run path). Not owned, not run
against a board; the units stay out of thesdrprofile (D-020). The
HydraSDR tree states two licences (per-directory LICENSE.md files, and a
debian/copyright reading "licensed exclusively for HydraSDR products"); the
unit's page says so and the catalog follows the LICENSE.md files (D-033). -
requires_java: a plan-time Java floor measured withjava -version
(D-037, amended 2026-10-02).default-jre-headlessis a metapackage that
says nothing about the Java major, so GraphHopper (17, from its pom and the
jar's class-file major) planned cleanly on Ubuntu 22.04 and Pop!_OS 22.04 and
failed at run time. A manifest namesrequires_java; the plan runsjava -versiononce and defers a profile member, or refuses a typed unit, below the
floor, stating the measured version and the archive'sopenjdk-N-jre-headless
that would meet it. Nothing is fetched. BRouter is set to 11, its measured
build target (the ruling said 17; the build file says 11). -
Profile state in
list --json(#259).list --jsonprofile entries gainmembers,installedandinstalled_size_bytes(apt members only, from onedpkg-querycall), and the text table showsinstalled N of Mwith a size: engine prerequisite E1 of the hammunition-console design spec (branch console-spec). -
Unverified repeater snapshots can sit on a Bunker; the bring-your-own-data
principle is recorded; Canada's sources measured and not carried
(D-078, D-074 amendment of 2026-10-03).hammunition artifacts --jsonlists the three on-request lists (ETCC, Brandmeister, hearham) as
unitrepeater-snapshots, checkunverified-fetch(no digest, the
publisher's URL, the size from aHEAD, the licence position), so a Bunker
can hold them underhold_unverified;maps repeaters fetch-etcc,
fetch-brandmeisterandfetch-hearhamread the station's mirror first at
<mirror>/repeater-snapshots/<name>(--no-mirrorskips it) and the
publisher on any failure, still marked unverified. Operators bring their own
export or key for questionable or personal data, the project never hosts it,
and no licence letters are sent on its behalf. Canada's TAFL (no amateur
rows, licensee names and addresses) and ISED's call-sign file (names and
addresses) are not carried. -
A GitHub wiki generated from
docs/(wiki-mirror).scripts/gen_wiki.pywrites one flat wiki page per nav document and package page, a Home banner, a sidebar from the nav, a footer naming the source commit, andSoftware-by-activityfrom the menu vocabulary (D-055); links to project records the site excludes point at GitHub..github/workflows/wiki.ymlpublishes it on every push tomain, and fails naming the one-time first-page step while the wiki has none.tests/test_wiki.pycovers it. -
A repeat plan no longer asks publishers about data it already installed
(#197, D-049 amended 2026-10-02). A terrain or 3DEP tile, US Topo or
FSTopo sheet, Kiwix book or CoMaps map that the transaction log attributes
as installed is planned as "installed, not re-checked (attributed DATE)" and
makes no request while the attribution is under seven days old
(RECHECK_AFTER_DAYS); one older than that, or whose file is not the one the
log recorded, is asked again, and a re-check that fails is a note, never a
refusal. The plan counts what it skipped and names the oldest attribution;
install --jsongainspublisher_checks(checked,reason,
attributed). Newinstall --recheckasks every publisher regardless. An
item on disk the log does not attribute behaves as before.install-data
log entries now carrysize(anddigestfor books and maps). -
The plan groups repeated same-shape steps;
--dry-run --fullexpands them
(D-016 amendment, 2026-10-02). A unit that repeats one step per sheet,
tile or book (ustopo-qmapshack, contours, SPLAT, terrain tiles, FSTopo,
Kiwix, the vector-tile builds) printed hundreds of near-identical blocks. The
text now prints the template once with<placeholders>, the first item in
full, every item's own values and the totals; a group is kept only if it
rebuilds every step exactly.--fullprints every step as before; the JSON
document, the transaction log and the real run are unchanged. -
**Plan and run steps...
v0.7.0 — alpha
Hammunition v0.7.0 — alpha
The whole catalog (242 manifests) installs on five targets with zero hard
failures: Parrot 7.3, Debian 13, Kali rolling, Ubuntu 24.04, Ubuntu 26.04.
Every unit installs and is confirmed on at least one target, or is refused
at plan time with its reason (docs/reference/m5-parity-verified.md).
Five backends: apt, source, git, binary, venv. Effect verification after
every transaction (D-031), including the executable a build declares.
Plan-time refusal (D-016), consent gates (D-021), transaction log and
uninstall for every backend, generated launchers and per-DE menus (D-036),
station configuration (D-035), memory-sized builds.
Last release of the direct-to-main phase; work continues by pull request.