惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
I
InfoQ
The Register - Security
The Register - Security
L
LangChain Blog
H
Help Net Security
The GitHub Blog
The GitHub Blog
S
Schneier on Security
博客园 - 【当耐特】
W
WeLiveSecurity
Attack and Defense Labs
Attack and Defense Labs
IT之家
IT之家
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Google DeepMind News
Google DeepMind News
The Cloudflare Blog
H
Heimdal Security Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Y
Y Combinator Blog
雷峰网
雷峰网
N
Netflix TechBlog - Medium
Security Archives - TechRepublic
Security Archives - TechRepublic
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
L
Lohrmann on Cybersecurity
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
The Exploit Database - CXSecurity.com
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
V
Visual Studio Blog
博客园 - 聂微东
PCI Perspectives
PCI Perspectives
Last Week in AI
Last Week in AI
A
Arctic Wolf
宝玉的分享
宝玉的分享
T
The Blog of Author Tim Ferriss
S
Secure Thoughts
T
Threat Research - Cisco Blogs
GbyAI
GbyAI
云风的 BLOG
云风的 BLOG
D
Darknet – Hacking Tools, Hacker News & Cyber Security
S
SegmentFault 最新的问题
SecWiki News
SecWiki News
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏
Schneier on Security
Schneier on Security
P
Proofpoint News Feed
博客园 - Franky
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
AI
AI
Engineering at Meta
Engineering at Meta

Hacker News

Introducing Claude Opus 4.7 Qwen Studio The Future of Everything is Lies, I Guess: Where Do We Go From Here? GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis Bonsai 1-bit WebGPU - a Hugging Face Space by webml-community Moving a large-scale metrics pipeline from StatsD to OpenTelemetry / Prometheus GitHub - Nightmare-Eclipse/RedSun: The Red Sun vulnerability repository GitHub - SethPyle376/hiraeth: Local AWS emulator focused on fast integration testing, with SQS support, SQLite-backed state, and a debug-friendly web UI. GitHub - macOS26/Agent: Any AI, replaces Claude Code, Cursor, OpenClaw. Over 18 LLM providers (Claude, OpenAI, Gemini, Ollama, Zai, HF, Qwen) wired into a native Mac app that writes code, builds Xcode projects, bumps versions, manages git, automates Safari, use AppleScript, JS or Accessibility, extend Agent! w/ MCP Servers, run tasks from your iPhone via Messages. YouTube now lets you turn off Shorts I Made a Terminal Pager Burgers | マクドナルド公式 Commands — HackerNews CLI documentation ChatGPT for Excel PiCore - Raspberry Pi Port of Tiny Core Linux Live Nation illegally monopolized ticketing market, jury finds Google Broke Its Promise to Me. Now ICE Has My Data. Founding Engineer at Adaptional | Y Combinator CRISPR takes important step toward silencing Down syndrome’s extra chromosome GitHub - saffron-health/libretto: The AI toolkit for building reliable browser automations US v. Heppner (S.D.N.Y. 2026) no attorney-client privilege for AI chats [pdf] Retrofitting JIT Compilers into C Interpreters IPv6 – Google The Accursèd Alphabetical Clock Cybersecurity Looks Like Proof of Work Now Fragments: April 14 Cal.com Goes Closed Source: Why AI Security Is Forcing Our Decision | Cal.com - Scheduling Software for Online Bookings Laravel raised money and now injects ads directly into your agent When moving fast, talking is the first thing to break Too much Discussion of the XOR swap trick – Heather Cafe Introduction to Spherical Harmonics for Graphics Programmers The Grand Line Building a Z-Machine in the worst possible language High-Level Rust: Getting 80% of the Benefits with 20% of the Pain GitHub - duguyue100/midnight-captain: Inspired by Midnight Commander, tailored to my taste. How to build a `git diff` driver · Jamie Tanna | Software Engineer Center for Responsible, Decentralized Intelligence at Berkeley The Local Universe’s Expansion Rate Is Clearer Than Ever, but Still Doesn’t Add Up - A new synthesis of astronomical measurements confirms a persistent mismatch that could point to physics beyond current models The air throughout our homes is infused with microplastics. But there are things you can do to breathe less of them The disturbing white paper Red Hat is trying to erase from the internet – OSnews The Future of Everything is Lies, I Guess: Annoyances ‘Abhorrent’: the inside story of the Polymarket gamblers betting millions on war Productive procrastination — Max van IJsselmuiden maps, territory and LMs 447 Terabytes per Square Centimetre at Zero Retention Energy: Non-Volatile Memory at the Atomic Scale on Fluorographane Show HN: Pardonned.com – A searchable database of US Pardons 20 Years on AWS and Never Not My Job The Seasons are Wrong Artemis II crew splashes down near San Diego after historic moon mission We gave an AI a 3 year retail lease in SF and asked it to make a profit | Andon Labs How a dancer with ALS used brainwaves to perform live On filing the corners off my MacBooks Installing every* Firefox extension OpenClaw’s memory is unreliable, and you don’t know when it will break Steve Blank Nowhere Is Safe Chimpanzees in Uganda locked in vicious 'civil war', say researchers watgo - a WebAssembly Toolkit for Go linux/Documentation/process/coding-assistants.rst at master · torvalds/linux GitHub - callumlocke/json-formatter: Makes JSON easy to read. Founding Product Engineer at Bild AI | Y Combinator A compelling title that is cryptic enough to get you to take action on it GitHub - Keychron/Keychron-Keyboards-Hardware-Design: Industrial design files for Keychron keyboards and mice. 100+ models with CAD assets in STEP, DXF, DWG, and PDF. Source-available, with commercial use allowed for original compatible accessories within the license terms. [ANNOUNCE] WireGuardNT v0.11 and WireGuard for Windows v0.6 Released 1D-Chess Helium Is Hard to Replace Cooperative Vectors Introduction | Evolve Keeping a Postgres queue healthy — PlanetScale Our response to the Axios developer tool compromise Do Americans read print books, e-books or audiobooks more? The Zettelkasten Method in Obsidian: A Practical Setup Guide Artemis II Is Competency Porn and We Are Starving For It WeakC4 Flight Viz — Cockpit View A Mexican surveillance giant you’ve never heard of is now watching the U.S. border Surelock: Deadlock-Free Mutexes for Rust RISC-V 101 – what is it and what does it mean for Canonical? | Ubuntu The Problem That Built an Industry How Much Linear Memory Access Is Enough? | Solidean Investigating Split Locks on x86-64 Simplest hash functions Sybilproof reputation mechanisms (2005) [pdf] What is a property? How Complex is my Code? Static code analysis in Kotlin — tools overview Toffoli gates are all you need PGLite evangelism dcmake: a new CMake debugger UI Clojure on Fennel part one: Persistent Data Structures Fragments: April 2 Python Release Python install manager 26.1 The Life and Death of the Book Review - Liberties Introducing Database Traffic Control — PlanetScale Bitcoin miners are losing $19,000 on every BTC produced as difficulty drops 7.8% God sleeps in the minerals Building slogbox Apple Silicon and Virtual Machines: Beating the 2 VM Limit Who was “Not Even Wrong” first? Pokemon Evolution Vs Darwinian Evolution The APL Programming Language Source Code
GitHub - kamaludu/bash4llm: Bash-first wrapper for Groq’s OpenAI-compatible API. Secure, portable, Termux-friendly.
kamaludu · 2026-06-28 · via Hacker News

Logo 320

CLI License: GPLv3 ShellCheck Smoke Tests

Bash4LLM⁺ — wrapper CLI sicuro, Bash‑first e completamente auditabile per l’API Chat Completions compatibile OpenAI di Groq (ed estendibile ad altri provider).

Bash4LLM⁺ è un singolo script Bash, auto‑contenuto, leggibile e verificabile.
Scaricalo, rendilo eseguibile, esporta la tua API key e inizia subito a usarlo.

Compatibile con ambienti Unix‑like: Linux, macOS, WSL, Cygwin, Termux (Android), BSD.


Caratteristiche principali

  • Lista modelli dinamica
    tramite GET https://api.groq.com/openai/v1/models
    → nessun modello hardcoded.

  • Sicurezza by design
    → nessun uso di /tmp, nessun eval, permessi restrittivi, validazione provider avanzata.

  • Struttura modulare a sezioni
    → PRECORE_BOOT, PRECORE_RUN, PROVIDER, CORE_SETUP, CORE_PROVIDER.

  • Sistema di Stato UI (ui_state)
    → il CORE espone costantemente metadati in formato JSON atomico per l'integrazione con GUI o strumenti esterni (es. Home Assistant).

  • Streaming e non‑streaming
    → output in tempo reale o completo a fine risposta.

  • Salvataggio automatico
    → per output lunghi oltre una soglia configurabile.

  • Gestione modelli avanzata
    → refresh, lista, default persistente, whitelist dinamica, auto‑selezione.

  • Extras opzionali
    → provider aggiuntivi (come Gemini, Hugging Face, Mistral), template, documentazione, strumenti di sicurezza.

  • Pronto per Termux / Android
    → rileva automaticamente l'ambiente Termux bypassando flock (spesso instabile o limitato a livello kernel/SELinux su Android) e devia trasparentemente la gestione della concorrenza sul robusto meccanismo di directory lock (mkdir atomico).


Modello di minaccia (versione breve)

Bash4LLM⁺ è progettato per ambienti single‑user (PC/laptop, server personali).

  • I provider sono codice eseguito nella tua shell: devono risiedere in directory sicure di tua proprietà.
  • Variabili come BASH4LLM_EXTRAS_DIR e BASH4LLM_TMPDIR sono considerate configurazione fidata.
  • Lo script non esegue mai l’output del modello.
  • I rischi TOCTOU e i limiti del parsing JSON/SSE sono mitigati e documentati.

Dettagli completi in SECURITY.


Requisiti

Bash4LLM⁺ richiede che i seguenti pacchetti (o equivalenti) siano disponibili nel PATH:

  • bash
  • coreutils
  • findutils
  • util-linux
  • gawk
  • curl
  • jq

Installazione

Tip

⏩ FAST FORWARD (Installazione Rapida)

Esegui questi comandi nel tuo terminale per avviare subito Bash4LLM⁺:

# 1. Clona il repository (solo l'ultimo commit per massima velocità)
git clone --depth 1 --branch main https://github.com/kamaludu/bash4llm.git repo-bash4llm  

# 2. Crea una cartella di lavoro ed estrai l'eseguibile
mkdir -p bash4llm
cp repo-bash4llm/bin/bash4llm bash4llm/
chmod +x bash4llm/bash4llm

# 3. Entra nella cartella e aggiorna i modelli 
cd bash4llm 
./bash4llm --refresh-models

Lo script ti chiederà l'inserimento della tua chiave API per il provider di default (Groq): Enter API key for provider groq (env GROQ_API_KEY):

Inserisci la tua API key, poi esportala per non doverla più inserire durante la sessione:

export GROQ_API_KEY="gsk_xxxxxxxxxxxxxxxxx"

Consigliato: installa gli Extras opzionali:

# 4. Installazione degli Extras
./bash4llm --install-extras ../repo-bash4llm/extras/

Usa Bash4llm ⚡

Istruzioni dettagliate in: INSTALL

In breve:

chmod +x bash4llm
export GROQ_API_KEY="gsk_xxxxxxxxxxxxxxxxx"
./bash4llm --help

Extras opzionali:

./bash4llm --install-extras

Con opzioni:

  • --source <dir>
  • --force
  • --dry-run
  • installazione selettiva:
    ./bash4llm --install-extras provider1 templateA

Uso rapido

Prompt diretto:

./bash4llm "scrivi una breve poesia in italiano"

Prompt multilinea:

./bash4llm <<'EOF'
scrivi una breve poesia
in italiano
EOF

Input da file:

Pipe:

echo "spiegami la relatività" | ./bash4llm

Modello specifico:

./bash4llm -m llama-3.3-70b-versatile "scrivi un saggio breve"

Dry run:

./bash4llm --dry-run "ciao"

Provider esterno (se installato):

./bash4llm --provider gemini "traduci questo"

Comandi, flag e opzioni disponibili

Modelli e provider

Flag Argomento Effetto
--refresh-models, --refresh-model no Aggiorna la lista modelli (richiede API key).
--list-models no Stampa lista modelli (formato interattivo).
--list-models-raw no Stampa lista modelli in formato raw (una riga per modello).
--list-providers no Stampa lista provider.
--list-providers-raw no Stampa provider in formato raw.
--set-default <model> Imposta modello di default persistente per il provider attivo.
-m <model>, --model <model> Imposta modello per questa esecuzione.
--provider <name> Imposta provider da CLI.
--provider no Se senza argomento → apre selezione interattiva.

Input (file, JSON, template, batch)

Flag Argomento Effetto
-f <file> Aggiunge file a FILE_INPUTS.
--json-input <json> Imposta input JSON (formato OpenAI-like).
--template <name> Applica template da BASH4LLM_TEMPLATES_DIR.
--batch <file> Esegue richieste batch (una riga = un prompt).

Sessioni

Flag Argomento Effetto
--session <id> Abilita sessione con ID specifico.
--session-window [n] opzionale Imposta finestra sessione (default 10 se non fornito).

Parametri modello / generazione

Flag Argomento Effetto
--system <text> Imposta system prompt.
--ture <n> Imposta parametro temperatura (da 0.0 a 2.0, alias canonico).
--temperature <n> Alias di --ture.
--max <n> Imposta max token.

Output e salvataggio

Flag Argomento Effetto
--save no Forza salvataggio output.
--nosave no Disabilita salvataggio.
--out <path> Percorso file/directory output.
--threshold <n> Soglia dimensione in byte per salvataggio automatico (default: 1000).
--json no Output JSON raw integro.
--pretty no Output JSON formattato.
--text no Output testuale standard estratto (comportamento predefinito).
--raw no Output testuale grezzo escludendo separazioni finali.

Modalità operative

Flag Argomento Effetto
--dry-run no Nessuna chiamata API reale (comportamento simulato).
--quiet no Riduce l'output non necessario e sopprime i titoli su TTY.
--stream no Streaming asincrono attivo.
--no-stream no Disattiva streaming asincrono.
--chat no Modalità chat interattiva REPL.
--bootstrap-only no Esegue solo validazione percorsi/lock e termina.

Configurazione e diagnostica

Flag Argomento Effetto
--show-config no Mostra configurazione completa attiva.
--diagnostics no Esegue diagnostica completa del sistema.
--version no Stampa versione dello script e termina.
-h, --help no Mostra help interattivo formattato da file.

Installazione extras

Flag Argomento Effetto
--install-extras opzionale Installa extras; può accettare directory sorgente.
--install-extras=<dir> Installa extras da directory sorgente specifica.

Terminazione parsing

Flag Effetto
-- Termina parsing opzioni.
-* Opzione sconosciuta → errore.
* Argomento posizionale → aggiunto a ARGS.

Configurazione e modelli

File di configurazione

  • $BASH4LLM_CONFIG_DIR/config
    → parametri locali (MODEL, TURE, MAX_TOKENS, FORMAT, THRESHOLD)

  • $BASH4LLM_CONFIG_DIR/model.$PROVIDER
    → modello predefinito per provider

  • $MODELS_FILE
    → whitelist modelli aggiornata da --refresh-models

Precedenza selezione modello

  1. -m/--model
  2. model.$PROVIDER
  3. auto‑selezione provider (auto_select_model_<provider>)
  4. prima voce della whitelist (models.txt)
  5. configurazione globale legacy config (MODEL=...)

File temporanei e output

  • Nessun uso di /tmp a livello di sistema operativo condiviso.
  • File temporanei isolati in directory $RUN_TMPDIR con permessi 700 (umask 077).
  • File salvati con permessi 600.
  • Con --out Bash4LLM⁺ crea la directory se possibile.

📁 Sistema di Stato UI (ui_state)

Bash4LLM⁺ espone metadati operativi destinati a GUI/strumenti esterni tramite file JSON atomici in:

$BASH4LLM_CONFIG_DIR/ui_state

Contiene:

  • sessions/<id>.json → stato sessione (active, msg_count, last_ts)
  • sessions/index.json → elenco sessioni
  • last_api.json → ultimo risultato API (http_status, req_id, edgecase_detected, ecc.)
  • last_history.json → ultimo salvataggio history
  • provider_capabilities.json → capacità provider attivo (streaming, refresh_models)

La GUI (extra opzionale) legge solo questi file per i placeholder CGI.


📘 Memoria contestuale in Bash4LLM⁺

Bash4LLM⁺ non mantiene memoria da solo.
La memoria esiste solo se attivi una sessione tramite --session.

Ogni sessione crea un file NDJSON persistente:

$BASH4LLM_HISTORY_DIR/sessions/<session_id>.ndjson

E Bash4LLM⁺ mantiene i metadati della sessione in:

$BASH4LLM_CONFIG_DIR/ui_state/sessions/<session_id>.json

Questi metadati sono la fonte canonica per GUI/strumenti esterni.


🟩 Uso corretto di --session

./bash4llm --session chat1 "Ciao"
./bash4llm --session chat1 "Riassumi ciò che ho detto"

🟩 Uso corretto di --session-window

./bash4llm --session chat1 --session-window 10 "continua"

🟧 Regola fondamentale

Per avere memoria contestuale devi sempre includere --session <id>.


Note di sicurezza

  • Nessun eval.
  • Nessuna esecuzione dell’output del modello.
  • Provider = codice: mantieni extras/providers sicuro.
  • Variabili d’ambiente = configurazione fidata.
  • TOCTOU mitigato.

Codici di uscita

Codice Variabile Significato
0 - Successo
10 BASH4LLM_ERR_NO_API_KEY API key mancante
11 BASH4LLM_ERR_BAD_MODEL Modello non valido o non in whitelist
12 BASH4LLM_ERR_CURL_FAILED Errore rete/curl
14 BASH4LLM_ERR_NO_PROMPT Nessun prompt fornito
15 BASH4LLM_ERR_TMP Errore generico filesystem / temporanei
16 BASH4LLM_ERR_API Errore HTTP/API del fornitore

Variabili principali

Variabile Necessaria Descrizione
GROQ_API_KEY sì per chiamate API API key provider Groq.
BASH4LLM_CONFIG_DIR consigliata Directory configurazione.
BASH4LLM_MODELS_DIR consigliata Directory modelli.
BASH4LLM_TMPDIR Directory temporanea.
BASH4LLM_HISTORY_DIR consigliata Directory sessioni e cronologia.
MODEL no Modello attivo.
PROVIDER no Provider attivo.
ALLOWED_MODELS no Whitelist modelli ammessi.

Licenza

Bash4LLM⁺ è distribuito sotto licenza GPL v3.
Vedi LICENSE.


Contatti

Autore: Cristian Evangelisti
Email: opensource​@​cevangel.​anonaddy.​me
Repository: https://github.com/kamaludu/bash4llm