Design discussionsView source ↗

Shibuna Discussions

Index of Shibuna Discussion (SID) records.

published

SID 0001: The Shibuna Discussion Process and Engineering Standards

Defines the SID lifecycle, numbering workflow, TigerStyle engineering standards, structural code limits, and Elm-style diagnostic error reporting for the sibuna monorepo.

Area: documentation Category: Process Memo Status: Published Created: 2026-09-07 Updated: 2026-09-07 Source: docs/sid/records/0001-sid-process.typ

published

SID 0002: Sibuna: Foundation Architecture, Delivery Plan, and Performance Contract

Foundational architectural specification, zero-allocation pipeline, two-tier proof-of-work engine, keyed-hash session tokens, product surfaces, measured performance contract, and delivery record for the Sibuna pure-Zig monorepo

Area: architecture Category: Architectural Specification Status: Published Created: 2026-09-07 Updated: 2026-09-07 Source: docs/sid/records/0002-sibuna-foundation-architecture.typ

published

SID 0003: Declarative Rule Policy Engine

Specification of Sibuna's zero-allocation declarative rule engine: JSON policy files, multi-criteria matching over path, user agent, headers, and IPv4/IPv6 CIDRs, WEIGH scoring with thresholds, per-rule challenge parameters, the evaluation order, and dynamic policies replicated through Zaxonlite.

Area: policy Category: Architectural Specification Status: Published Created: 2026-09-07 Updated: 2026-09-07 Source: docs/sid/records/0003-declarative-policy-engine.typ

published

SID 0004: Semantic Attack Inspection and GCRA Rate Limiting: The Shield Surface

Design and measured implementation of Sibuna's Shield surface: a single-pass tagged signature automaton, single-pass structural tokenizers for SQL injection, cross-site scripting, path traversal, and command injection, the byte-class pre-scan and canonicalisation gate, the GCRA rate limiter, the ban table, and incident recording.

Area: security Category: Architectural Specification Status: Published Created: 2026-09-07 Updated: 2026-09-07 Source: docs/sid/records/0004-semantic-inspection.typ

published

SID 0005: Distributed Storage Architecture: Zaxonlite Integration for Dynamic Policies, Replicated Reputation, and Incident Forensics

Specifies and records the implementation of Sibuna's Edge surface: the embedded Zaxonlite store (replicated SQLite on paxos-zig) for cluster-wide dynamic policies, IP reputation, and forensic incident search, the read-copy-update engine slot that keeps the request path free of database access, the lock-free incident ring, and campaign clustering of attack payloads.

Area: storage Category: Architectural Specification Status: Published Created: 2026-09-07 Updated: 2026-09-07 Source: docs/sid/records/0005-zaxonlite-storage-architecture.typ

published

SID 0006: Mathematical Foundations of Sibuna: Sequential Work, Symmetric Authentication, Bounded State, and Linear-Time Inspection

A paper-style record of the mathematics behind every Sibuna hot-path primitive: the Cohen–Pietrzak proof of sequential work and the geometric hashcash tier, keyed-hash tokens and stateless challenges with work-bounded state, GCRA rate limiting, Robin Hood spent sets, Aho–Corasick and single-pass tokenizers for inspection, read-copy-update engine slots, adaptive difficulty, and feature-hashed campaign clustering, each with definitions, lemmas, proofs, citations, and the exact pure-Zig implementation and measurement that realises it.

Area: cryptography Category: Architectural Specification Status: Published Created: 2026-09-07 Updated: 2026-09-07 Source: docs/sid/records/0006-mathematical-foundations.typ

committed

SID 0007: The Sibuna Console: A Real-Time Management Interface for Nodes and Clusters

Specifies the Sibuna Console, a complete management interface: a management module started from the Sibuna CLI, serving a real-time web interface over HTTP and WebSockets, rendering pages from a WebAssembly module styled with daisyUI 5, keeping users, sessions, audit, minute statistics, and a GeoIP database in the embedded Zaxonlite store, managing one node or a cluster, with explicit isolation targets and inconclusive container measurements, an authenticated live GeoIP globe dashboard, complete route wireframes, resolved design decisions, protocol, data model, build pipeline, and delivery plan.

Area: console Category: Architectural Specification Status: Committed Created: 2026-09-08 Updated: 2026-10-02 Source: docs/sid/records/0007-console-management-interface.typ

discussion

SID 0008: AI Bot Traffic Identification, Multi-Tier Verification, and Operator Console Analytics

Specifies the architecture for identifying, verifying, and monitoring AI crawler and automated bot traffic in Sibuna: zero-allocation single-pass signature matching, sub-microsecond Radix CIDR verification for major providers (OpenAI, Anthropic, Google Gemini, Perplexity, Meta, Apple, ByteDance), multi-tier confidence classification, bounded telemetry extensions, and a real-time console dashboard delivering visual composition, time-series analysis, and granular tabular analytics contrasting bot traffic against actual human traffic.

Area: analytics Category: Architectural Specification Status: Open for Discussion Created: 2026-09-15 Updated: 2026-09-15 Source: docs/sid/records/0008-ai-bot-traffic-monitoring.typ

committed

SID 0009: Chunked Request Bodies: Strict In-Place Decoding, Canonical Re-Framing, and Inspection Equivalence

Specifies how the reverse proxy accepts chunked request bodies without a heap allocation or a second buffer: a strict RFC 9112 chunk grammar that rejects every known terminator and extension ambiguity, an in-place decoder whose output never overtakes its input, Content-Length forwarding for bodies that complete within the connection buffer and canonical re-chunking for the rest, and proofs that inspection sees exactly the bytes a Content-Length request would show and that the origin cannot observe the client's framing.

Area: http Category: Architectural Specification Status: Committed Created: 2026-10-02 Updated: 2026-10-02 Source: docs/sid/records/0009-chunked-request-bodies.typ
Search the documentation