BobPhone BobShit docs · v0.1.1

BobShit pour les apps BobPhone / NoteOS

Runtime C v0.1.1 : tu écris du .shit, tu uploades une app custom, le serveur l’exécute en sandbox.

runtime 0.1.1 POST /api/bobshit/run sandbox + timeout

1. Endpoint POST /api/bobshit/run

Alias publics (même handler) : /api/bobshit/run, /bobshit/run, et côté BobPhone /bobphone/api/pk/run.

curl -X POST https://bob.xem.yt/api/bobshit/run \
  -H 'Content-Type: application/json' \
  -d '{
    "script": "say \"hello bobshit\"",
    "args": [],
    "timeout": 5
  }'

Payload

ChampTypeOblig.Détail
script string oui* Source .shit. Alias acceptés : code, shit, source.
args array non Args optionnels injectés en tête de script comme liste __args (strings/nombres).
timeout number non Secondes (défaut 5, max 10). Au-delà → HTTP 408.
strict bool non Mode strict runtime (-s). Défaut soft.
// réponse OK
{
  "ok": true,
  "output": "hello bobshit\n",
  "errors": "",
  "stdout": "hello bobshit\n",
  "stderr": "",
  "exit_code": 0
}

Health check runtime : GET https://bob.xem.yt/api/bobshit/health → {"ok":true,"version":"bobshit 0.1.1"}

2. Exemple minimal hello.shit

# hello.shit
say "salut, c'est BobShit"
name = "Bob"
say "moi c'est", name
curl -X POST https://bob.xem.yt/bobshit/run \
  -H 'Content-Type: application/json' \
  -d '{"script":"say \"salut, c'\''est BobShit\"\nname = \"Bob\"\nsay \"moi c'\''est\", name"}'

En local (repo) : cd bobshit/lang && make && ./bobshit examples/hello.shit

3. Soumettre une app .shit depuis BobPhone

Upload store (app custom) : multipart avec un fichier app.shit (extension .shit). Le serveur génère un wrapper JS qui appelle le runtime.

POST https://bob.xem.yt/bobphone/api/pk/publish
Content-Type: multipart/form-data

name=MaShitApp
author=toi
file=@app.shit

Puis run par id, ou snippet inline :

POST https://bob.xem.yt/bobphone/api/pk/run
{"id": "ma-shit-app"}

POST https://bob.xem.yt/bobphone/api/pk/run
{"script": "say \"yo\"", "timeout": 3}
UI : store BobPhone / page upload PK (/bobphone/pk/). Type accepté : bobshit (en plus de javascript).

4. Limites de sécurité

LimiteValeur
Sandbox processPATH minimal, HOME=/tmp, cwd /tmp, fichier temp éphémère
Timeout5 s (API publique) · 3 s (BobPhone) · max request 10 s
Taille source200 Ko max
Sortie stdout/stderr64 Ko max
Rate limit BobPhone~40 runs / min / client
Runtime Cpas de FS/réseau/exec depuis le script · 1M itérations boucle · 256 frames
Sanitize uploadHTML / <script> / PHP refusés
Pas de scan trop large. Évite les crawls / find / grep récursifs sur tout le disque pour « tester » — ça lag le serveur (déjà vu). Timeout + sandbox suffisent pour valider un .shit. Boucles infinies → timeout. input() en HTTP n’a pas de stdin interactif.