Overview & Architecture Principles
🇮🇹 Bash4LLM⁺ è un framework client POSIX Bash progettato per eseguire operazioni con Modelli Linguistici di Grandi Dimensioni (LLM) in ambienti shell ristretti, pipeline CI/CD, container e dispositivi embedded (incluso Android Termux).
🇬🇧 Bash4LLM⁺ is a production-grade POSIX Bash client framework designed to execute Large Language Model operations in restricted shell environments, CI/CD pipelines, container instances, and embedded platforms (including Android Termux).
It achieves sub-10ms cold-start execution with zero third-party package dependencies for core CLI and TUI execution (no Python, Node.js, Docker, or pip/npm modules required), relying strictly on base system POSIX utilities, curl, and jq.
Key Capabilities
Multi-Provider Engine
Groq core provider by default, extensible to Gemini, Mistral, and Hugging Face via dynamic checksum-verified modules with Provider API contract versioning.
SSE Streaming & TUI Chat
Supports real-time Server-Sent Events (SSE) responses and features an interactive terminal UI chat REPL (extras/chat/tui-repl.sh) with multi-language i18n support.
Web GUI Interface
Optional WebApp interface (extras/gui-py/) powered by FastAPI and Vanilla ES6. Features Server-Sent Events (SSE) streaming and WCAG AAA compliant visual interface.
Encrypted Secret Vault
OpenSSL AES-256-CBC PBKDF2 encrypted vault for API keys. Memory-volatile RAM unlock context with mandatory policy enforcement (BASH4LLM_REQUIRE_VAULT=1).
Persistent Thread Sessions
Multi-turn conversation histories stored in line-delimited JSON (NDJSON) with automated SHA-256 thread ID anonymization (SAFE_THREAD_ID) and gzip rotation.
Security Invariants & Protections
- Zero Dynamic Code Evaluation: Guarantees zero usage of shell
eval, eliminating dynamic script injection vectors. - Zero Process Table Secret Leaking: API credentials are passed via
_exec_curl_secure, which allocates an isolated temporary header file with0600permissions passed to cURL via-H @"$hdr_file"and unlinked immediately post-execution, preventing credential exposure inps auxprocess listings. - Zero Shared Temp Directory Usage: Enforces private runtime execution directories created under
umask 077. - Memory-Locked Function Guards: Critical security and network routing functions are sealed using
readonly -f. - Ed25519 Manifest Signature Verification: Extension modules are validated against
manifest.sha256andmanifest.sha256.sigusing anti-TOCTOU staging copy isolation.
Runtime Requirements & System Footprint
Execution requires standard base OS utilities available in $PATH:
- Shell Runtime:
bash(version 4.0 or newer). - HTTP Transport & Data Processing:
curlandjq. - POSIX Core Utilities (20):
mktemp,stat,base64,find,awk,sed,grep,xargs,tr,sort,head,wc,tee,date,mv,chmod,cp,rm,printf,comm. - Optional Web GUI Runtime:
Python ≥ 3.10withfastapi,uvicorn, andpydantic(required strictly for--gui/--webappexecution; core CLI and TUI operate with zero external runtimes). - Optional Binaries (Auto-Fallback):
flock(reverts to atomicmkdirlocking),openssl,ssh-keygen,gzip,shred/dd.
CLI Quick Start
# Basic single-prompt query
./bash4llm "Explain quantum computing in two sentences."
# Real-time Server-Sent Events (SSE) streaming
./bash4llm --stream "Generate a POSIX shell script for sorting files."
# Launch interactive TUI REPL chat
./bash4llm --chat
# Launch Web GUI interface
./bash4llm --gui
# Execute within persistent conversation thread
./bash4llm --thread project_refactor "Analyze the auth architecture."
# Enforce Vault key retrieval policy
BASH4LLM_REQUIRE_VAULT=1 ./bash4llm "Query using encrypted vault credentials"
Canonical Exit Codes
| Code | Symbolic Alias | Description |
|---|---|---|
10 |
BASH4LLM_ERR_NO_API_KEY |
Missing, unreadable, or unauthenticated API credential. |
11 |
BASH4LLM_ERR_BAD_MODEL |
Unsupported, missing, or invalid model target specification. |
12 |
BASH4LLM_ERR_CURL_FAILED |
Network transport failure, timeout, or curl execution error. |
13 |
BASH4LLM_ERR_PARSE |
JSON parsing error, or response syntax/SML/REGEX validation failure. |
14 |
BASH4LLM_ERR_NO_PROMPT |
Missing prompt text or unreadable input source. |
15 |
BASH4LLM_ERR_TMP |
File I/O error, permission error, missing core utility, or lock timeout. |
16 |
BASH4LLM_ERR_API |
Upstream API error payload or non-2xx HTTP status code. |
17 |
BASH4LLM_ERR_SEC |
Security policy violation, rate limit exceeded, or signature check failure. |
Documentation Index
Explore full technical documentation and specifications:
- llms.txt Specification Index — Standard structured markdown index for AI crawlers and LLM agents.
- Architecture Specification (English) — Comprehensive system internals and bootstrap pipeline.
- Timeless Architecture Spec — Security invariants and immutable negative constraints.
- Security Specification — Threat model, token redaction, and vault operations.
- Providers Specification — Provider contracts, models, and module verification.