No description
  • Scheme 81.5%
  • Shell 10.4%
  • Python 4.3%
  • Makefile 3.6%
  • Common Lisp 0.2%
Find a file
ober cb74f75037
All checks were successful
required-ci / required (push) Successful in 5m2s
Merge pull request #9
2026-09-12 21:13:00 -04:00
.forgejo Use FreeBSD Forgejo CI runner 2026-08-03 14:45:37 -06:00
.jerboa Security hardening and release readiness 2026-06-23 10:48:56 -06:00
bin Security hardening and release readiness 2026-06-23 10:48:56 -06:00
docs Security hardening and release readiness 2026-06-23 10:48:56 -06:00
scripts fix: implement awk fflush 2026-09-05 18:22:40 -06:00
src/jerboa-awk fix: implement awk fflush 2026-09-05 18:22:40 -06:00
support fix: implement awk fflush 2026-09-05 18:22:40 -06:00
tests fix: implement awk fflush 2026-09-05 18:22:40 -06:00
.gitignore jpkg: complete binary package setup 2026-07-30 14:55:25 -06:00
.gitsafeignore Set up Forgejo CI/CD policy 2026-08-03 12:50:48 -06:00
.jerbuild build: build jawk with installed jerbuild (no jerboa checkout) 2026-05-28 15:57:17 -06:00
AGENTS.md docs(agents): add checkout hygiene policy (work dirs under ~/work, cleanup when done) 2026-09-12 19:10:52 -06:00
jpkg.lock jpkg: complete binary package setup 2026-07-30 14:55:25 -06:00
jpkg.policy.sexp jpkg: complete binary package setup 2026-07-30 14:55:25 -06:00
jpkg.sexp Use FreeBSD Forgejo CI runner 2026-08-03 14:45:37 -06:00
LICENSE Switch to MIT license 2026-07-21 13:41:54 -06:00
Makefile fix: implement awk fflush 2026-09-05 18:22:40 -06:00
README.md Harden runtime input and bootstrap handling 2026-07-11 17:22:54 -06:00
SECURITY.md Security hardening and release readiness 2026-06-23 10:48:56 -06:00
VERSION fix: implement awk fflush 2026-09-05 18:22:40 -06:00

jerboa-awk

jawk is an AWK interpreter implemented in Jerboa Scheme.

Build and Test

make verify
make release-evidence

make verify runs the source security gate, import check, parser regression tests, deterministic parser corpus evidence, native binary build, CLI smoke tests, and secure-default policy tests. make release-evidence also records SBOM/toolchain evidence and a two-pass clean-build reproducibility report for the generated jawk binary, repeated parser corpus output, and target proof status.

Secure Defaults

AWK programs are treated as hostile input unless the caller explicitly opts into legacy AWK capabilities:

  • JAWK_ALLOW_SYSTEM=1 enables system() and pipe redirections.
  • JAWK_ALLOW_FILE_IO=1 enables script-driven print > file and getline < file I/O. CLI input files and -f program files remain supported.
  • JAWK_EXPOSE_ENVIRON=1 exposes a small allowlist of process environment variables through ENVIRON; by default ENVIRON is empty.
  • JAWK_MAX_PROGRAM_CHARS caps program text, default 1 MiB.
  • JAWK_MAX_RECORD_CHARS caps input records, default 1 MiB.
  • JAWK_MAX_REGEX_CACHE_ENTRIES bounds each evaluation's dynamic-regex LRU, default 64. Regex, range-pattern, random-number, and multi-character record-buffer state is never shared between evaluations. Transient caches and buffers are cleared during evaluation cleanup.

Library embeddings must create an independent environment with make-initial-env for each evaluation and use it only from the thread that created it. Runtime entry points reject cross-thread reuse. Concurrent evaluations are supported when each worker creates and owns its own environment.

Generated jawk binaries and native build artifacts are ignored and must not be tracked.

Production support also requires a reviewed JAWK_TARGET_PROOF_FILE with the markers documented in docs/release-evidence.md. JAWK_REQUIRE_TARGET_PROOF=1 fails closed when that target proof is missing or incomplete.

Example

echo "hello world" | ./jawk '{print $1}'
echo "a,b,c" | ./jawk -F, '{print $2}'

Security Docs

  • SECURITY.md
  • docs/threat-model.md
  • docs/parser-hardening.md
  • docs/release-evidence.md