Skip to content

Releases: Renegade-Penguin/Hammunition

v0.21.0

Choose a tag to compare

@github-actions github-actions released this 05 Oct 02:16
383f9e3
  • The console's Repeaters screen (7 on Home, #322): the repeater layers grouped by area with the active mark, the areas, and keys to fetch RepeaterBook by state (opening Secrets first when REPEATERBOOK cannot be supplied), import an export, choose the active areas, remove a layer and look repeaters up by place, distance, band and mode; and, from both it and Secrets, an offer to install repeaterbook-client when it is missing, the fetch running after a successful install (#344). D-059, D-064, D-074, D-081, D-082.

  • hammunition secrets status [--json] says where each secret the engine knows would come from (the environment, Doppler or nowhere), the unit and first command it unlocks and the exact ways to provide it, and never a value, a prefix or a length; the console gains a Secrets screen (3 on Home) that reads it, names a Doppler project and config through station set, keeps a value entered for the session in the console's memory only (handed to the engine commands it starts, written nowhere, cleared on exit) and runs maps repeaters fetch-repeaterbook once a source answers. Built against fixtures and the fake engine; not yet run against the live RepeaterBook API or on the field laptop (#321, D-081, D-059).

  • hammunition-console is a catalog unit (D-059, D-021; branch console-unit): a terminal front end in its own repository, pinned by its tag's source-archive sha256 like the tray, installed by name and in no profile, with a terminal menu entry. It reads only --json documents and runs every change in a pane where a person types any consent. docs/getting-started/console.md walks the first run. Rename this fragment to <PR number>.added.md when the pull request has a number. Superseded within this same release: the console moved into the engine as hammunition console (#302, below) and the unit is retired.

  • Atheris fuzz targets for the parsers, run by GYST's python-fuzz.yml (part of #333; branch fuzz-targets): fuzz/ holds six targets (manifest loaders, repeater imports, Maidenhead, gpsd JSON, os-release, station config); a fuzz job in ci.yml runs them 30 s each on a pull request and 600 s on the weekly schedule; tests/test_fuzz_targets.py keeps them runnable. Found and fixed: a bare carriage return in a CSV row escaped maps repeaters import and the ETCC and Direwolf readers as csv.Error instead of a RepeaterInputError, and a station file with a non-text key died with a TypeError instead of a StationError. Rename this fragment to <PR number>.added.md when the pull request has a number.

  • hammunition hardware gps-resume-report (read-only, --json as a gps-resume-report document) shows whether the installed GPS resume step matches the engine's, the unit's last result, gpsd's device list and a data check, the receiver's USB facts and the step's last run's lines; the step now keeps those lines in /run/hammunition/gps-resume.log through a third file hardware apply writes (/etc/tmpfiles.d/hammunition-gps-resume.conf), so no systemd-journal membership is needed. hammunition time measure --minutes N [--pps] samples ntpq -pn and ppstest for the GPS-takeover bench. Part of #177 and #310 (D-058, D-059; the bench is session 14 of docs/reference/bench-verification-5430.md, not yet run).

  • Infrastructure and EMCOMM layers are kept per region (issue #327, part of #326; D-075 amended, D-082): maps infra import and fetch-fcc-asr/fetch-nwr write one layer per theme and installed region (infra-osm-medical-<region slug>), data-source layers clipped to each region's box, so maps activate draws only the active regions' infrastructure in QMapShack, Navit and the browser map. --merged keeps one layer across every region; an older merged layer is left alone with a note, once; maps infra remove --layer takes a theme or <theme>-<region>; the infra documents' layer views carry area.

  • hammunition maps activate CODE|REGION ... | --all | --none [--dry-run] and maps areas switch the active area of operations (the station value active_areas, station set --active-areas, --clear-active-areas): QMapShack's poiPaths (a directory of links to the active areas' .poi files), Navit's map set and the browser map's list follow it, maps repeaters list --json and the infrastructure documents carry active per layer, and deactivating deletes nothing; also fixes ensure_paths swapping one path for another under one key. Built and tested on synthetic layers, not yet run in QMapShack, Navit or a browser (#328, part of #326, D-082).

  • The gpsd unit now installs pps-tools with it, so hammunition time measure --pps can run ppstest on a machine set up for GPS time on either route (ntpsec, D-058, or the chrony unit, D-072); closes #319.

  • hammunition maps repeaters fetch-repeaterbook, the repeaterbook-client unit and one secrets helper (D-081, D-078; branch repeaterbook-api): resolve_secret(name) reads a key from an environment variable, then Doppler (station set --doppler-project/--doppler-config, --clear-doppler), and never from the repository, station file, argv or a log; the run log redacts it and any credential header. The verb runs the unofficial repeaterbook client (a hash-pinned venv unit, registered with RepeaterBook as App #114; the operator generates their own token for it) through an engine-owned runner, with the token in that subprocess's environment only, into an unverified, personal-use repeaterbook layer (0600, credited with a link, never mirrored, never listed by artifacts). Built against the documentation and the client's source; not yet run against the live API. Rename this fragment to <PR number>.added.md when the pull request has a number.

  • hammunition maps repeaters list [--layer ID] [--json] reads the repeater layers back as a repeaters-list document for front ends: layers with personal_use and unverified, the joined rows with their layer, the credits to print, and the layers it could not read, exit 0 on a partial list; read-only (#312; D-074 amended 2026-10-04, D-059, D-081).

  • Repeaters have a mode vocabulary (FM, DMR, D-STAR, YSF, P25, NXDN, M17, TETRA, ATV), a band and the digital details a source actually supplies; maps repeaters list gains --near GRID|LAT,LON, --within KM, --band and --mode with distance and bearing, nearest first; the QMapShack POI has one category per mode and every name carries N0CALL 146.940 2m FM DMR for a text search (#313; D-074 amended 2026-10-04).

  • Reticulum, NomadNet and LXMF (Track C, PR 2, issue #105, D-080). Three
    hash-pinned per-user venvs, rns, lxmf and nomadnet, because no archive
    carries any of them: rns exposes every console script Reticulum declares
    (rnsd, rnstatus, rnpath, rnprobe, rnid, rncp, rnx, rnsh, the
    RNode flasher rnodeconf and the rest) and installs a user service,
    hammunition-rnsd, that keeps one shared instance per machine (the first
    operator's service runs it and another account's attaches as a client; enabled at
    install, started at next login; an abstract local socket, not a TCP port,
    measured in a Debian 13 container); lxmf gives lxmd and starts nothing;
    nomadnet gives the terminal messenger and a menu entry. The Reticulum
    License (MIT plus two use restrictions, not OSI-approved) is printed on the
    plan line that installs the venv and never gated; NomadNet is GPL-3.0-only
    by its shipped text. The engine writes no Reticulum configuration and
    uninstall leaves ~/.reticulum, ~/.nomadnetwork, ~/.lxmd and ~/.rnsh.
    New post-1.0 mesh profile (the three plus python3-meshtastic and
    gtk-meshtastic-client), a rnode hardware entry (untested: no identifier
    of its own), and docs/guides/mesh-and-reticulum.md with four
    troubleshooting entries. Engine: a user service's exec may start
    {venv}/..., and a venv block may state its licence and licence_url on
    its plan line. Two containers on one bridge found each other, exchanged an
    LXMF message and ran rnsh; no LoRa link has been run.

  • hammunition self-update pulls the engine's own checkout and re-runs bootstrap.sh, and --version, every --json document and doctor say when the venv lags the checkout (#303, #311). The verb fetches, fast-forwards to origin/main (or the newest v* tag with --release) and re-runs bootstrap, each step printed before it runs, --dry-run printing the commits that would arrive; it refuses a dirty tree, a detached or non-main branch and a non-fast-forward, and never touches apt, units or the station; its run is teed to a D-077 log. hammunition --version prints 0.20.0 (checkout), 0.19.0 (installed); run hammunition self-update`` when the editable install's metadata is behind pyproject.toml, the `engine` field of every document is the checkout's version, `doctor` gains an `engine version` check with the fix as argv, and the console's Home offers the update with `U`.

  • hammunition console: the terminal console is part of the engine (#302, D-059 amended 2026-10-04): hammunition_console moved to src/hammunition/console/ with its tests in tests/console/, one release and one version, so ENGINE_FLOOR, EngineTooOld and the fixtures' engine field are gone. urwid is the optional console extra; without it the subcommand prints one line naming the install command and exits 2. The console runs the engine as <interpreter> -m hammunition. The hammunition-console unit is retired, menus apply writes the engine's own entry for it, and tests/console/capture_fixtures.py refuses to run unless HOME is a temporary directory it made itself. The old repository is archived; see the console reference at docs/console/index.md.

  • hammunition-hill pinned to v1.2.0 (the repeaters panel with any-centre lookup and mode filters, hill #83/#85), its digest from t...

Read more

v0.20.0

Choose a tag to compare

@github-actions github-actions released this 04 Oct 00:32
1558f7d
  • tar1090, the ADS-B aircraft map, as a page in reference serve
    (D-071 amended 2026-10-02; D.10b's route). A new tar1090 unit
    (listening, depends on readsb, so deferred by name where readsb is) is a
    data unit: GitHub's archive of upstream's commit e784ee5 (no tags, no
    distribution packages it: own-choice pin, D-024), sha256 pinned, html/ and
    the GPL-2.0-or-later licence kept. Its root wget | bash installer and
    lighttpd on port 80 are not used. hammunition reference serve serves the
    page at /aircraft/ on 127.0.0.1, with data/ read from readsb's directory
    (/run/readsb, or --readsb-json DIR), read-only. The page cannot call
    out: tar1090's settings for photographs, routes and overlays are switched
    off, its online layers are replaced by the station's PMTiles map (a blank
    background, with the reason on the page, when osm-pmtiles is absent), and
    every response carries a Content-Security-Policy that names no host. The
    page is given a reduced receiver.json so it reads plain aircraft.json
    (readsb 3.14.1630 also writes aircraft.binCraft.zst, which tar1090 would
    otherwise ask for). The aircraft database is not carried (upstream's one commit cannot be pinned).
    Tested in headless Chromium: the aircraft appear, no request leaves
    loopback, the same page as upstream ships it does ask other hosts, and the
    policy alone refuses them. Not measured: a live receiver, Firefox, a real
    region at street zoom.

  • Every run leaves a log (D-077). install, uninstall, update,
    menus apply, hardware apply|unapply|park|wake, every maps ...,
    reference serve, services ... and time mode -- --dry-run included --
    write <state dir>/logs/<UTC>-<command>-<pid>.log: the argv with station
    flags redacted, everything printed on stdout and stderr, each command run with
    its output as it arrives and its exit code, a result line; 0600, flushed
    per line, owner-aware under sudo. Rotated at the start of each run to 30
    files and 200 MB, never a run in progress. New hammunition logs [--last | --path | --json]; doctor reports the logs; a run ends Log: <path>. The
    transaction log now rotates past 1 MiB into transactions-<NNNNNN>-<UTC>.jsonl
    archives that every reader walks in order (never deleted); status is tested
    identical before and after. docs/reference/run-logs.md.

  • SuperSDR joins the listening profile. Its profile documentation states
    the D-033 position for its missing upstream licence and that it is never
    mirrored.

  • Transaction history is now readable (#243, D-077). hammunition transactions [--last N] [--json] lists the live and archived transaction
    records in chronological order, including deferred units and whether a run
    completed, failed, aborted or is still in progress.

  • Live feedback while an install step runs (#270, D-077). On a terminal a
    command that runs longer than two seconds gets one in-place status line under
    its $ line, … 1m 42s <the command's last output line>, erased when the
    command ends; install -v / --verbose (and uninstall) stream every output
    line as it arrives instead. Nothing is added when stdout is not a terminal,
    and the run log is byte-for-byte what it was in every mode. The status line and
    the sudo keepalive's warnings share one terminal writer (progress.LiveStatus),
    so they cannot interleave. A step the backend knows is long (a submodule fetch,
    a cmake/make/qmake compile, a venv pip install, a node build) says
    this step can take several minutes in the plan and at step start, with no
    invented duration; StepView gains long_running in --json.

  • HydraSDR RFOne and RigExpert Fobos SDR: host software and device entries,
    from upstream's own files, for hardware nobody here owns
    (D-024,
    D-027, D-028, D-029, D-032). Five units: hydrasdr-host (the
    library and its seventeen tools) and soapysdr-module-hydrasdr, and
    libfobos, libfobos-sdr-agile and soapysdr-module-fobos, the last
    needing both libraries to build. Kali and Ubuntu 26.04 take the HydraSDR
    units from apt; every other target builds the tags Debian packages
    (v1.1.1, v1.0.1). Nothing Fobos is packaged anywhere, so libfobos (head
    1e0fab3) and soapysdr-module-fobos (aa8d486) are commit pins with a
    pin_review, libfobos-sdr-agile is upstream's tag. Two entries under
    catalog/hardware/devices/: hydrasdr-rfone (38af:0001, status: supported in D-027's shape, with 1d50:60a1 recorded in rejected_ids
    because the Airspy R2 and Mini use it and no rule can tell them apart, and
    the NXP DFU recovery id marked shared with the HackRF) and fobos-sdr
    (16d0:132e, untested; both firmware families present it and differ only
    in bcdDevice). Identifiers are cited as commit-pinned URLs into the vendors'
    repositories; scripts/check_rule_citations.py now ignores a rules file
    named inside a URL, since the sweep covers distribution packages only.
    Built in rootless containers on Debian 13, Ubuntu 24.04, Ubuntu 26.04 and
    Kali (x86_64): all five units build and install, hydrasdr_info and
    fobos_devinfo run without a board, SoapySDRUtil --info lists both
    modules. Three defects of upstream's builds are handled in the manifests,
    each measured: libfobos-sdr-agile wrote /etc/udev/rules.d as root (a
    CRLF-preserving patch removes it), SoapyHydraSDR also wrote into dpkg's
    module directory (a define), and nothing a build into /usr/local links
    was found without ldconfig (an embedded run path). Not owned, not run
    against a board; the units stay out of the sdr profile (D-020). The
    HydraSDR tree states two licences (per-directory LICENSE.md files, and a
    debian/copyright reading "licensed exclusively for HydraSDR products"); the
    unit's page says so and the catalog follows the LICENSE.md files (D-033).

  • requires_java: a plan-time Java floor measured with java -version
    (D-037, amended 2026-10-02). default-jre-headless is a metapackage that
    says nothing about the Java major, so GraphHopper (17, from its pom and the
    jar's class-file major) planned cleanly on Ubuntu 22.04 and Pop!_OS 22.04 and
    failed at run time. A manifest names requires_java; the plan runs java -version once and defers a profile member, or refuses a typed unit, below the
    floor, stating the measured version and the archive's openjdk-N-jre-headless
    that would meet it. Nothing is fetched. BRouter is set to 11, its measured
    build target (the ruling said 17; the build file says 11).

  • Profile state in list --json (#259). list --json profile entries gain members, installed and installed_size_bytes (apt members only, from one dpkg-query call), and the text table shows installed N of M with a size: engine prerequisite E1 of the hammunition-console design spec (branch console-spec).

  • Unverified repeater snapshots can sit on a Bunker; the bring-your-own-data
    principle is recorded; Canada's sources measured and not carried

    (D-078, D-074 amendment of 2026-10-03). hammunition artifacts --json lists the three on-request lists (ETCC, Brandmeister, hearham) as
    unit repeater-snapshots, check unverified-fetch (no digest, the
    publisher's URL, the size from a HEAD, the licence position), so a Bunker
    can hold them under hold_unverified; maps repeaters fetch-etcc,
    fetch-brandmeister and fetch-hearham read the station's mirror first at
    <mirror>/repeater-snapshots/<name> (--no-mirror skips it) and the
    publisher on any failure, still marked unverified. Operators bring their own
    export or key for questionable or personal data, the project never hosts it,
    and no licence letters are sent on its behalf. Canada's TAFL (no amateur
    rows, licensee names and addresses) and ISED's call-sign file (names and
    addresses) are not carried.

  • A GitHub wiki generated from docs/ (wiki-mirror). scripts/gen_wiki.py writes one flat wiki page per nav document and package page, a Home banner, a sidebar from the nav, a footer naming the source commit, and Software-by-activity from the menu vocabulary (D-055); links to project records the site excludes point at GitHub. .github/workflows/wiki.yml publishes it on every push to main, and fails naming the one-time first-page step while the wiki has none. tests/test_wiki.py covers it.

  • A repeat plan no longer asks publishers about data it already installed
    (#197, D-049 amended 2026-10-02). A terrain or 3DEP tile, US Topo or
    FSTopo sheet, Kiwix book or CoMaps map that the transaction log attributes
    as installed is planned as "installed, not re-checked (attributed DATE)" and
    makes no request while the attribution is under seven days old
    (RECHECK_AFTER_DAYS); one older than that, or whose file is not the one the
    log recorded, is asked again, and a re-check that fails is a note, never a
    refusal. The plan counts what it skipped and names the oldest attribution;
    install --json gains publisher_checks (checked, reason,
    attributed). New install --recheck asks every publisher regardless. An
    item on disk the log does not attribute behaves as before. install-data
    log entries now carry size (and digest for books and maps).

  • The plan groups repeated same-shape steps; --dry-run --full expands them
    (D-016 amendment, 2026-10-02). A unit that repeats one step per sheet,
    tile or book (ustopo-qmapshack, contours, SPLAT, terrain tiles, FSTopo,
    Kiwix, the vector-tile builds) printed hundreds of near-identical blocks. The
    text now prints the template once with <placeholders>, the first item in
    full, every item's own values and the totals; a group is kept only if it
    rebuilds every step exactly. --full prints every step as before; the JSON
    document, the transaction log and the real run are unchanged.

  • **Plan and run steps...

Read more

v0.7.0 — alpha

v0.7.0 — alpha Pre-release
Pre-release

Choose a tag to compare

@ChiefGyk3D ChiefGyk3D released this 02 Sep 11:26

Hammunition v0.7.0 — alpha

The whole catalog (242 manifests) installs on five targets with zero hard
failures: Parrot 7.3, Debian 13, Kali rolling, Ubuntu 24.04, Ubuntu 26.04.
Every unit installs and is confirmed on at least one target, or is refused
at plan time with its reason (docs/reference/m5-parity-verified.md).

Five backends: apt, source, git, binary, venv. Effect verification after
every transaction (D-031), including the executable a build declares.
Plan-time refusal (D-016), consent gates (D-021), transaction log and
uninstall for every backend, generated launchers and per-DE menus (D-036),
station configuration (D-035), memory-sized builds.

Last release of the direct-to-main phase; work continues by pull request.