Repository navigation
Reference Profile Sizing
Generated by scripts/gen_profile_sizing.py. Do not edit by hand —
regenerate. Every number below is derived from a measured inventory; the
profile set and its names are the curated part and are argued rather
than asserted.
Generated: 2026-09-03
Split threshold: anything over 80 packages is flagged
| Source | Basis | Units |
|---|---|---|
| Debian Blend |
blend-inventory.md, 12 tasks |
152 unique |
| Blend, installable on Debian 13 | container probe | 144 |
| AHRL survivors |
dispositions.md — CARRY + SUPERSEDE + REVIVE |
86 |
| 73Linux delta survivors |
dispositions.md — CARRY + ADD |
13 |
| Skywave delta | skywave-inventory.md |
9 |
| DragonOS Tier 1 | dragonos-tier1-inventory.md |
24 |
Union upper bound: ~284 units before de-duplication. Profiles are flat tags with overlap (D-003), so the same package appears in several profiles and the per-profile totals deliberately sum to more than the union.
8 Blend packages do not install on Debian 13: aethersdr, dump1090-mutability, fbb, not1mm, odr-audioenc, qlog, sdrangel, sdrpp. All but
odr-audioenc are in unstable, so most is release lag — but a user installing
today on a stable base does not get them. Per D-005, coverage counts only
where it installs, so the on stable column below is the honest one.
Blend counts task membership; on stable is how many of those actually
install on Debian 13. Other is AHRL, 73Linux, Skywave and DragonOS Tier 1
attributed by disposition and menu category — the one estimated column, and
estimated from measured survivor lists rather than from guesses.
| Profile | Blend tasks | Blend | on stable | Other | Total | Verdict |
|---|---|---|---|---|---|---|
station |
rigcontrol, tools
|
20 | 20 | 6 | 26 | ✅ |
logging |
logging |
10 | 8 |
4 | 14 | ✅ |
morse |
morse, training
|
13 | 13 | 2 | 15 | ✅ |
propagation |
— + 6 partial | 6 | 6 | 12 | 18 | ✅ |
digital-modes |
datamodes, digitalvoice
|
22 | 22 | 22 | 44 | ✅ |
packet |
packetmodes |
19 | 18 |
12 | 31 | ✅ |
satellite |
satellite |
3 | 3 | 5 | 8 | ✅ |
antenna |
antenna |
7 | 7 | 8 | 15 | ✅ |
sdr |
sdr |
39 | 36 |
6 | 45 | ✅ |
listening |
nonamateur |
22 | 20 |
11 | 33 | ✅ |
electronics |
— | 0 | 0 | 6 | 6 | ✅ |
rf-security |
— | 0 | 0 | 14 | 14 | ✅ |
rf-research |
— | 0 | 0 | 1 | 1 | post-1.0 |
rfid |
— | 0 | 0 | 6 | 6 | post-1.0 |
workstation |
— | 0 | 0 | 7 | 7 | post-1.0 |
editors |
— | 0 | 0 | 2 | 2 | post-1.0 |
mesh |
— | 0 | 0 | 8 | 8 | post-1.0 |
uconsole |
— | 0 | 0 | 5 | 5 | post-1.0 |
No profile exceeds 80. That is the point of the split proposed below, not an accident.
Profile names are the first thing an operator reads and effectively permanent
once published — they appear in hammunition install <name>, in documentation,
in forum posts, and in other people's shell history. Renaming one later breaks
all of that. So the names are argued here.
Four rules, applied consistently.
-
Name the activity, not the package set. An operator knows they want to
work satellites; they do not know they want
gpredictplussatdump. Every name below is something a person would say out loud about their own station. -
No adjectives, no size words.
ham-core,ham-extra,ham-fulldescribe our packaging decisions, not the operator's intent, and they force a reader to learn our taxonomy before they can choose.corein particular is a claim about importance that ages badly the moment someone disagrees with it. -
One word where one word works.
packet,satellite,antenna,logging,morse,sdr,listening,mesh. Hyphenate only when a single word would be ambiguous —digital-modes,rf-security. -
Say what it is, not what it is not.
nonamateuris the Blend's name for the task we map tolistening; it defines a category by exclusion, which tells a newcomer nothing.
Two names are deliberately not what you might expect.
station, not ham-core. core is the packaging word this project was
built to avoid — it invites "what's not core?" and makes everything else feel
optional-in-a-bad-way. station is what an operator calls the thing they are
building. hammunition install station reads as a sentence. It also survives the
split cleanly: station is what every station needs, and logging, morse and
propagation are things some stations want, which is exactly true.
rf-security, not sigint. Three reasons, in order of weight.
-
It is what CLAUDE.md already calls it. The docs section is
docs/rf-security/, the security requirement says "RF-security tooling lives in its own profile requiring explicit opt-in". Using a different word in the CLI than in the documentation is a defect. - SIGINT is a term of art with a specific meaning — signals intelligence, as practised by states. Most of what this profile contains is Wi-Fi auditing, Bluetooth sniffing, ISM decoding and protocol analysis. Calling that SIGINT overclaims what the tools do and mis-sets expectations in both directions.
-
It reads better on a shared machine. This runs alongside offensive tooling
on people's work laptops.
rf-securitydescribes a discipline;sigintdescribes an intelligence function, and the difference matters to whoever reads the operator's screen over their shoulder.
One name is held back. cellular is proposed but not defined, pending
Q-008. Naming a profile before deciding what goes in it is how you end up
renaming it.
name |
What the operator reads | Why this name |
|---|---|---|
station |
Station essentials | What every station needs before it can do anything else: rig control, hamlib, propagation-free basics, the tools that other profiles assume. |
logging |
Contest and DX logging | Most operators want one logger, not nine. Splitting it out means the choice is visible and the default is stated. |
morse |
CW and Morse training | Self-contained, and its two Blend tasks already overlap heavily. Nobody needs it to make a digital contact. |
propagation |
Propagation and spotting | Clocks, cluster clients, grid tools, beacon monitors. Genuinely optional and heavy on web-service dependencies, so it is the first thing a low-bandwidth or offline station wants to skip. |
digital-modes |
FT8, JS8 and the digital modes | The reason most people install something like this. Wide but coherent. |
packet |
Packet, Winlink and EMCOMM | The 73Linux delta lands here whole. AHRL has none of it. |
satellite |
Satellites and weather imaging | Small. SatDump carries most of the weight now that the APT decoders are retired. |
antenna |
Antennas and modelling | NEC modelling, coverage prediction, analyser tooling. |
sdr |
SDR receivers and device support | Large, and a third of the Blend's sdr task is per-hardware Soapy modules a one-dongle user does not need. See the hardware-detection note. |
listening |
Shortwave and utility listening | The Skywave delta lands here. Works with no transmitter and no licence, which makes it the best on-ramp we have. |
electronics |
Bench and electronics | KiCad, gerbv, spice. Fine software; not radio. Opt-in, per the PARITY-POLICY question reserved to the maintainer. |
rf-security |
RF security and spectrum analysis | DragonOS Tier 1, opt-in, with the legal framing CLAUDE.md requires. Its final shape depends on Q-008. |
rf-research (post-1.0)
|
Transmit-capable and interception-capable RF tooling | Consent-gated (D-021). Contents provisional pending Q-008 — the receive-only subset only, with transmit-capable cellular stacks excluded. |
rfid (post-1.0)
|
RFID and NFC |
Accepted, Q-010. Different domain, different range, different skills. Five of six are apt on every probed target; proxmark3 is apt on Kali only (4.21611-0kali1, measured 2026-08-26) and a pinned source build on the other three including the primary one, so it still needs the source backend. An earlier version of this line said nothing was packaged on any target — that was wrong and is corrected in Q-010. |
workstation (post-1.0)
|
Terminal and bench tooling |
Accepted, Q-011. Not radio software; a lab machine needs it. Deliberately boring, and the exclusion list is a required schema field so it stays that way. Sized at nine until 2026-09-03, when the two editors moved to editors — each needs a publisher's apt repository on most targets (D-040), and that gate was withholding the other seven (D-039). |
editors (post-1.0)
|
VS Code and VSCodium, opt-in | Split from workstation on 2026-09-03. Both are apt packages from a publisher's repository against a pinned key (D-040); the consent gate is per repository and --yes cannot satisfy it. Opt-in by construction. |
mesh (post-1.0)
|
Mesh and LoRa | Meshtastic, Reticulum. Post-1.0. |
uconsole (post-1.0)
|
ClockworkPi uConsole | Hardware-specific: display, audio routing, power. Post-1.0. |
The previous sizing put ham-core at ~62 — under the threshold, but the worst
profile to get wrong, because it is what a new user installs first and it forms
their impression of the whole project.
It was large because it absorbed five Blend tasks at once. Split four ways:
| Profile | Absorbs | Why it is a coherent thing to name |
|---|---|---|
station |
rigcontrol, tools
|
The floor. Rig control, hamlib, the utilities everything else assumes. Installs fast, contains no surprises. |
logging |
logging |
An operator wants a logger. Nine is a menu, not a feature. Splitting makes the default an explicit, documented choice. |
morse |
morse, training
|
Already self-contained — the two Blend tasks overlap by five packages and by nothing else. |
propagation |
AHRL's HF_Propagation cluster | Clocks, cluster clients, grid and beacon tools. Optional, and the heaviest user of external web services in the catalog. |
Each of the four passes the test a profile should pass: an operator can name it without being told what is in it, and can explain why they do or do not want it.
station is the one to keep small. Everything that gets added to it is
something a first-time user did not ask for and has to wait through.
rf-security measures well under the threshold, so this is not a size problem.
It is a kind problem, and Q-008 is the open question.
The DragonOS Tier 1 inventory found that the units divide by transmit, not by topic:
| Group | Contents | Character |
|---|---|---|
| Analysis and audit |
wireshark, aircrack-ng, hcxdumptool/hcxtools, ubertooth, inspectrum, rtl-433, kismet
|
Receive, capture, decode. The bulk of the profile. |
| Cellular, receive-only |
gr-gsm (apt on three of four targets), QCSuper, the LTE decoders |
Legality varies by jurisdiction — interception statutes rather than spectrum rules. |
| Cellular, transmit |
srsRAN_4G, Osmocom core, osmo-trx, intrusive-lte-mme
|
Operates a network. Requires authorisation an ordinary user will not have. |
Recommendation: one rf-security profile for 1.0 containing the analysis and
audit group plus the receive-only cellular subset, with the legal framing
docs/rf-security/ already requires — and cellular deferred as a named,
undefined post-1.0 profile rather than folded in quietly.
That keeps the 1.0 profile honest about what it is, keeps gr-gsm — apt on
Debian 13, Kali and Parrot, though not on Ubuntu 26.04, which is a capability-
matrix row rather than a reason to drop it — and does not put a rogue base
station one command away from a machine that also holds offensive tooling.
This is a recommendation. Q-008 is the maintainer's to answer, and the answer changes the profile's contents, not its name.
The Blend's sdr task is 39 packages, of which 12 are
soapysdr-module-*. Those are per-hardware backends, and a user with one
dongle needs one of them. Skywave ships the full set for the same reason the
Blend lists it — a live ISO cannot know what will be plugged in. We can.
Recommend installing soapysdr-tools plus the modules matching detected
hardware, treating the rest as available-not-installed. That single decision
removes 11 of the 12 from the common case, and it is now supported by two
independent sources rather than one. This is a design requirement on M4, not
a catalog nicety: profile resolution has to be able to consult detected hardware.
logging loses 2 packages on stable. The Blend task is
10 packages and only 8 install on Debian 13 — the
missing ones are qlog, which overlaps.md picks as the recommended default,
and not1mm. A profile whose recommended default does not install on the stable
Debian base most of our targets derive from is a capability-matrix row, not a
footnote — and overlaps.md needs to say so.
The Blend uses Recommends for almost every entry. Its metapackages are
opt-out; our profiles are opt-in. Task membership means "belongs to this
category", never "install this by default". Importing it directly would make
every profile maximal.
Overlap is expected and correct. splat is in antenna and tools; cw,
cwcp, xcwcp, aldo and morse are in morse and training. Per D-003
that is one tag appearing twice, not a modelling error.
nonamateur maps to listening, not to anything amateur. It mixes ADS-B,
DAB, GNSS and utility decoding. It also contains dump1090-mutability, which
overlaps.md supersedes with readsb and which does not install on Debian 13
anyway.
Generated from docs/ at commit b2ea01255815. Canonical site: https://renegade-penguin.github.io/Hammunition/. Edit docs/ by pull request, not this wiki.
- Home
- Software by activity
- Activity hubs
- Installation
- Profiles
-
Guides
- Operating
- Modes
- Receiving
- In the field
- Troubleshooting
- Getting started
- Packages
-
Hardware
- Park and wake devices
- SDR receivers and transceivers
- Radios, GPS and mesh
- Security and research hardware
- Programmers
- Laptop radios and camera (parkable)
- LibreVNA (vector network analyser)
- RF security
-
Reference
- The engine
- Coverage
- Inventories
- Hardware measurements
- Verification
- Contributing