BobShit pour les apps BobPhone / NoteOS
Runtime C v0.1.1 : tu écris du .shit, tu uploades une app custom,
le serveur l’exécute en sandbox.
1. Endpoint POST /api/bobshit/run
Alias publics (même handler) :
/api/bobshit/run,
/bobshit/run,
et côté BobPhone /bobphone/api/pk/run.
curl -X POST https://bob.xem.yt/api/bobshit/run \
-H 'Content-Type: application/json' \
-d '{
"script": "say \"hello bobshit\"",
"args": [],
"timeout": 5
}'
Payload
| Champ | Type | Oblig. | Détail |
|---|---|---|---|
script |
string | oui* | Source .shit. Alias acceptés : code, shit, source. |
args |
array | non | Args optionnels injectés en tête de script comme liste __args (strings/nombres). |
timeout |
number | non | Secondes (défaut 5, max 10). Au-delà → HTTP 408. |
strict |
bool | non | Mode strict runtime (-s). Défaut soft. |
// réponse OK
{
"ok": true,
"output": "hello bobshit\n",
"errors": "",
"stdout": "hello bobshit\n",
"stderr": "",
"exit_code": 0
}
Health check runtime :
GET https://bob.xem.yt/api/bobshit/health
→ {"ok":true,"version":"bobshit 0.1.1"}
2. Exemple minimal hello.shit
# hello.shit
say "salut, c'est BobShit"
name = "Bob"
say "moi c'est", name
curl -X POST https://bob.xem.yt/bobshit/run \
-H 'Content-Type: application/json' \
-d '{"script":"say \"salut, c'\''est BobShit\"\nname = \"Bob\"\nsay \"moi c'\''est\", name"}'
En local (repo) :
cd bobshit/lang && make && ./bobshit examples/hello.shit
3. Soumettre une app .shit depuis BobPhone
Upload store (app custom) : multipart avec un fichier app.shit
(extension .shit). Le serveur génère un wrapper JS qui appelle le runtime.
POST https://bob.xem.yt/bobphone/api/pk/publish
Content-Type: multipart/form-data
name=MaShitApp
author=toi
file=@app.shit
Puis run par id, ou snippet inline :
POST https://bob.xem.yt/bobphone/api/pk/run
{"id": "ma-shit-app"}
POST https://bob.xem.yt/bobphone/api/pk/run
{"script": "say \"yo\"", "timeout": 3}
UI : store BobPhone / page upload PK
(/bobphone/pk/).
Type accepté :
bobshit (en plus de javascript).
4. Limites de sécurité
| Limite | Valeur |
|---|---|
| Sandbox process | PATH minimal, HOME=/tmp, cwd /tmp, fichier temp éphémère |
| Timeout | 5 s (API publique) · 3 s (BobPhone) · max request 10 s |
| Taille source | 200 Ko max |
| Sortie stdout/stderr | 64 Ko max |
| Rate limit BobPhone | ~40 runs / min / client |
| Runtime C | pas de FS/réseau/exec depuis le script · 1M itérations boucle · 256 frames |
| Sanitize upload | HTML / <script> / PHP refusés |
Pas de scan trop large. Évite les crawls / find / grep récursifs
sur tout le disque pour « tester » — ça lag le serveur (déjà vu).
Timeout + sandbox suffisent pour valider un
.shit.
Boucles infinies → timeout. input() en HTTP n’a pas de stdin interactif.