-
Notifications
You must be signed in to change notification settings - Fork 0
Security Model
j3w1zsh is fail-closed around platform authority, filesystem destinations, Git history, workspace lifecycle, and private state.
Private keys, tokens, passwords, OAuth/Codex sessions, GitHub CLI hosts data, histories, private projects, and databases are not committed, migrated, printed, hashed, or transformed. Public keys still require an explicit local reason.
Detection occurs before mutation. Production has no platform-forcing escape hatch. Test overrides work only in test mode. Termux rejects root, privilege wrappers, system services, absolute managed destinations, shell evaluation, and host-level adapters.
Managed destinations remain under the intended home or one exact platform adapter. Conflicts are preserved. Updates stop on authored/staged/untracked/deleted/renamed/ahead/divergent state and fast-forward only. Migration captures protected bytes and unique refs before stopping.
Recursive forced cleanup is confined to the normal-runtime and standalone-migration guarded ephemeral helpers. Both require exact registration, a resolved allowed parent, an exact basename prefix shape, a non-symlink directory, and a regular ownership marker before removal. The runtime marker is process-owned. Persistent recovery generations, generated product paths, user destinations, workspaces, config/state/cache roots, and repository checkouts cannot be registered through this interface.
Package reconciliation fails closed: each aggregate phase runs once, a child failure stops all later phases, and provenance requires positive exact-manager verification. Known Corepack/Pacman pnpm shims become a manual checkpoint; ambiguous path ownership is protected. The bounded provenance repair revalidates exact named records and manager state, preserves evidence, and cannot install, remove, or alter packages.
Profiles are strict JSON. Apply requires candidate review, explicit platform target, tracked-clean profile and sources, displayed digest, explicit trust, supported unqualified executable, and direct argv. Shells, env, privilege wrappers, traversal, symlinks, dirty indirection, arbitrary system destinations, and unsupported executables are rejected.
Development commands are displayed and never auto-started. Environment guards parse selected .env fields without sourcing the file and enforce loopback/local/SQLite constraints where declared.
j3w1zsh 1.0.0 documentation — one shell. every machine. zero compromise. — MIT licensed.
- Getting Started
- Installation Methods
- CLI and Help
- Package Layers and Presets
- Theme Architecture
- Native Arch Linux
- Arch WSL 2
- Termux on Android
- Remote Hosts
- Workspace Schema v2
- Planning
- Updating
- Migration
- Configuration
- Architecture
- Security
- Backup and Recovery
- Troubleshooting
- Maintenance and Releases
- Agent Guide
- Sources