No description
  • Scheme 46.9%
  • Rust 43.9%
  • Shell 4.3%
  • C 1.8%
  • Makefile 1.6%
  • Other 1.5%
Find a file
Jaime Fournier 2381112c96 fix for loop
2026-07-30 19:52:01 -06:00
.jerboa Add shell security gate and sanitize evidence 2026-06-25 20:12:46 -06:00
.jpkg add jpkg 2026-07-24 14:46:53 -06:00
docs Never use sibling ~/mine checkout for jerboa-shell-extras; default embed dir to ~/.embed 2026-07-23 14:34:45 -06:00
jerboa-src/src Allow dev FFI loading with preload environment 2026-07-30 11:01:19 -06:00
patches/jerboa-native-rs Add cross-platform build targets 2026-07-16 21:48:58 -06:00
rust-coreutils Add cross-platform build targets 2026-07-16 21:48:58 -06:00
support fix: delegate linux-amd64/arm64 to jerboa-shell-extras when extras features requested 2026-07-24 17:54:43 -06:00
test fix for loop 2026-07-30 19:52:01 -06:00
tools new AGENTS.md 2026-07-24 11:54:42 -06:00
.build.yml fixes for while : 2026-07-23 20:08:32 -06:00
.gitattributes Initial modern minimal jsh build 2026-06-18 20:57:29 -06:00
.gitignore jpkg: complete binary package setup 2026-07-30 15:32:22 -06:00
.gitsafe.json Initial modern minimal jsh build 2026-06-18 20:57:29 -06:00
.jerbuild Harden process isolation and FFI loading 2026-07-11 17:25:56 -06:00
.jerbuild.freebsd-amd64 Add cross-platform build targets 2026-07-16 21:48:58 -06:00
.jerbuild.linux-amd64 fix: delegate linux-amd64/arm64 to jerboa-shell-extras when extras features requested 2026-07-24 17:54:43 -06:00
.jerbuild.linux-amd64-native Add cross-platform build targets 2026-07-16 21:48:58 -06:00
.jpkgignore jpkg: complete binary package setup 2026-07-30 15:32:22 -06:00
AGENTS.md docs: remove jerboa-emacs restriction 2026-07-30 15:47:21 -06:00
arithmetic.ss Strip jsh to compact shell 2026-06-18 22:17:25 -06:00
ast.ss Strip jsh to compact shell 2026-06-18 22:17:25 -06:00
bash-compatibility.md Fix all real-world stdin gaps and missing builtins 2026-07-25 12:21:08 -06:00
bench-smp.chez.ss Security hardening and release readiness 2026-06-23 10:51:16 -06:00
bench-smp.ss Initial modern minimal jsh build 2026-06-18 20:57:29 -06:00
bench.ss Initial modern minimal jsh build 2026-06-18 20:57:29 -06:00
build-all.ss Add cross-platform build targets 2026-07-16 21:48:58 -06:00
build-jsh-cross.ss Bundle SSM copy command with AWS feature 2026-07-28 18:38:06 -06:00
build-jsh-freebsd-cross.ss Add cross-platform build targets 2026-07-16 21:48:58 -06:00
build-jsh-freebsd.sh Add cross-platform build targets 2026-07-16 21:48:58 -06:00
build-jsh-freebsd.ss Bundle SSM copy command with AWS feature 2026-07-28 18:38:06 -06:00
build-jsh-macos.sh Add cross-platform build targets 2026-07-16 21:48:58 -06:00
build-jsh-macos.ss Bundle SSM copy command with AWS feature 2026-07-28 18:38:06 -06:00
build-jsh-musl.sh Add cross-platform build targets 2026-07-16 21:48:58 -06:00
build-jsh-musl.ss Bundle SSM copy command with AWS feature 2026-07-28 18:38:06 -06:00
build-jsh.ss Add cross-platform build targets 2026-07-16 21:48:58 -06:00
builtins.ss Fix all real-world stdin gaps and missing builtins 2026-07-25 12:21:08 -06:00
CLAUDE.md Strip jsh to compact shell 2026-06-18 22:17:25 -06:00
completion.ss Strip jsh to compact shell 2026-06-18 22:17:25 -06:00
control.ss Initial modern minimal jsh build 2026-06-18 20:57:29 -06:00
environment.ss Fix all real-world stdin gaps and missing builtins 2026-07-25 12:21:08 -06:00
executor.ss Security hardening and release readiness 2026-06-23 10:51:16 -06:00
expander.ss Fix all real-world stdin gaps and missing builtins 2026-07-25 12:21:08 -06:00
feature-resolve.ss Add cross-platform build targets 2026-07-16 21:48:58 -06:00
features.def Bundle SSM copy command with AWS feature 2026-07-28 18:38:06 -06:00
ffi-shim.c Harden process isolation and FFI loading 2026-07-11 17:25:56 -06:00
functions.ss Strip jsh to compact shell 2026-06-18 22:17:25 -06:00
fuzzy.ss Strip jsh to compact shell 2026-06-18 22:17:25 -06:00
gen-embed.ss Add cross-platform build targets 2026-07-16 21:48:58 -06:00
glob.ss Initial modern minimal jsh build 2026-06-18 20:57:29 -06:00
history.ss Fix history expansion: treat ! before closing quote as literal 2026-07-21 18:44:11 -06:00
jobs.ss Harden process isolation and FFI loading 2026-07-11 17:25:56 -06:00
jpkg.lock jpkg: complete binary package setup 2026-07-30 15:32:22 -06:00
jpkg.policy.sexp jpkg: complete binary package setup 2026-07-30 15:32:22 -06:00
jpkg.sexp jpkg: complete binary package setup 2026-07-30 15:32:22 -06:00
jsh-generate.ss Add cross-platform build targets 2026-07-16 21:48:58 -06:00
jsh.ss fixes 2026-07-19 17:46:25 -06:00
lexer.ss Strip jsh to compact shell 2026-06-18 22:17:25 -06:00
lib.ss Add embeddable jsh library module 2026-07-30 10:30:32 -06:00
LICENSE Switch to MIT license 2026-07-21 13:42:19 -06:00
lineedit.ss Preserve typeahead when checking terminal input 2026-07-13 13:05:42 -06:00
macros.ss Strip jsh to compact shell 2026-06-18 22:17:25 -06:00
main.ss Preserve interactive typeahead during commands 2026-07-27 11:05:10 -06:00
Makefile Point Oils jsh tests at Forgejo 2026-07-30 19:49:53 -06:00
parser.ss fix for loop 2026-07-30 19:52:01 -06:00
pipeline.ss Fix all real-world stdin gaps and missing builtins 2026-07-25 12:21:08 -06:00
pregexp-compat.ss Initial modern minimal jsh build 2026-06-18 20:57:29 -06:00
prompt.ss Fix Git branch prompt detection 2026-07-30 16:53:00 -06:00
README.md updates 2026-07-16 21:51:35 -06:00
redirect.ss fix: input redirect nofollow, history symlink protection, SIGWINCH 2026-07-21 10:42:00 -06:00
registry.ss fixes 2026-07-19 17:46:25 -06:00
script.ss fixes for while : 2026-07-23 20:08:32 -06:00
SECURITY.md updates 2026-07-16 21:51:35 -06:00
shell-missing.md Point Oils jsh tests at Forgejo 2026-07-30 19:49:53 -06:00
signals.ss Strip jsh to compact shell 2026-06-18 22:17:25 -06:00
startup.ss Strip jsh to compact shell 2026-06-18 22:17:25 -06:00
util.ss Security hardening and release readiness 2026-06-23 10:51:16 -06:00
VERSION Initial modern minimal jsh build 2026-06-18 20:57:29 -06:00

jerboa-shell

jerboa-shell is jsh: a compact shell written in Jerboa Scheme. It focuses on familiar bash/zsh-style command execution: parsing, expansion, builtins, redirection, pipelines, jobs, history, completion, and POSIX process behavior.

Security posture, threat model, native-boundary notes, and release evidence are tracked in SECURITY.md, docs/threat-model.md, docs/ffi-boundary.md, and docs/release-evidence.md. jsh is a shell, not a sandbox.

Build

make jsh-macos
./jsh-macos -c 'echo ok'

The build uses jerbuild from Jerboa. The Makefile prefers ./jerbuild, then .jerboa/bin/jerbuild, then jerbuild on PATH; if none are available it fetches the configured Jerboa release tool.

The default targets build only the bare shell. To open the optional-feature menu, fetch the extras bundle and its selected dependencies, and produce ./jsh-extras, run:

make extras

The optional bundle currently covers 20 selectable groups, including built-in coreutils, mux, encrypted embed/pass/vault storage, SSH, YubiKey, AWS, wormhole, recording, sandboxing, resource limits, profiling, proxying, WireGuard, process watching, hardening, AWK, and sed. See docs/extras.md for the complete command reference, selection rules, platform requirements, security boundaries, and known limitations.

The top-level target uses _vendor/jerboa-shell-extras/embed as its embed input. It does not automatically read or encrypt ~/.embed; the extras guide shows the explicit encrypted build command.

Test

make test
make test-native
make test-security-regressions
make audit
make release-evidence
make test-binary
make compat-smoke

The Oils spec runner under test/ measures shell compatibility. Benchmark scripts live here so speed work stays close to the shell implementation. make release-evidence records unit tests, native FFI audit output, SBOM manifests, and reproducibility output under dist/release-evidence/.

Command substitution is drained concurrently and is limited to 8 MiB by default. Set JSH_COMMAND_SUB_MAX_BYTES to a positive byte limit no greater than 1 GiB when a workload needs a different bound. Exceeding the limit aborts the expansion after the producer has been drained, rather than hanging it on a full pipe.

Interpreted development runs load libjsh-ffi only when JSH_FFI_DEV_NATIVE=1 and JSH_FFI_LIB names an absolute, non-symlink directory. Standalone builds register the shim statically; neither mode searches the current directory or a bare library name. Development loading also rejects ambient DYLD/LD search overrides and verifies the JSH1 ABI canary.

History

Interactive jsh writes normal line-oriented shell history to $HISTFILE (default: ~/.jsh_history). Set HISTSIZE and HISTFILESIZE to control the in-memory and saved entry limits.

History recording can be disabled from startup config with the bash-style history option:

# ~/.jshrc
case "$PWD/" in
  "$HOME/mine/obersh/"*) set +o history ;;
esac

For memory-only session history without saving a file, unset HISTFILE, set HISTFILE=, or set HISTFILE=/dev/null.

Layout

*.ss                  shell source modules
jerboa-src/src/       small compatibility modules used by the build
support/              build helpers
test/                 unit, binary, and Oils compatibility tests
bench*.ss             shell benchmark scripts