Shibuna Discussions
Index of Shibuna Discussion (SID) records.
published
SID 0001: The Shibuna Discussion Process and Engineering Standards
Defines the SID lifecycle, numbering workflow, TigerStyle engineering standards, structural code limits, and Elm-style diagnostic error reporting for the sibuna monorepo.
published
SID 0002: Sibuna: Foundation Architecture, Delivery Plan, and Performance Contract
Foundational architectural specification, zero-allocation pipeline, two-tier proof-of-work engine, keyed-hash session tokens, product surfaces, measured performance contract, and delivery record for the Sibuna pure-Zig monorepo
published
SID 0003: Declarative Rule Policy Engine
Specification of Sibuna's zero-allocation declarative rule engine: JSON policy files, multi-criteria matching over path, user agent, headers, and IPv4/IPv6 CIDRs, WEIGH scoring with thresholds, per-rule challenge parameters, the evaluation order, and dynamic policies replicated through Zaxonlite.
published
SID 0004: Semantic Attack Inspection and GCRA Rate Limiting: The Shield Surface
Design and measured implementation of Sibuna's Shield surface: a single-pass tagged signature automaton, single-pass structural tokenizers for SQL injection, cross-site scripting, path traversal, and command injection, the byte-class pre-scan and canonicalisation gate, the GCRA rate limiter, the ban table, and incident recording.
published
SID 0005: Distributed Storage Architecture: Zaxonlite Integration for Dynamic Policies, Replicated Reputation, and Incident Forensics
Specifies and records the implementation of Sibuna's Edge surface: the embedded Zaxonlite store (replicated SQLite on paxos-zig) for cluster-wide dynamic policies, IP reputation, and forensic incident search, the read-copy-update engine slot that keeps the request path free of database access, the lock-free incident ring, and campaign clustering of attack payloads.
published
SID 0006: Mathematical Foundations of Sibuna: Sequential Work, Symmetric Authentication, Bounded State, and Linear-Time Inspection
A paper-style record of the mathematics behind every Sibuna hot-path primitive: the Cohen–Pietrzak proof of sequential work and the geometric hashcash tier, keyed-hash tokens and stateless challenges with work-bounded state, GCRA rate limiting, Robin Hood spent sets, Aho–Corasick and single-pass tokenizers for inspection, read-copy-update engine slots, adaptive difficulty, and feature-hashed campaign clustering, each with definitions, lemmas, proofs, citations, and the exact pure-Zig implementation and measurement that realises it.
committed
SID 0007: The Sibuna Console: A Real-Time Management Interface for Nodes and Clusters
Specifies the Sibuna Console, a complete management interface: a management module started from the Sibuna CLI, serving a real-time web interface over HTTP and WebSockets, rendering pages from a WebAssembly module styled with daisyUI 5, keeping users, sessions, audit, minute statistics, and a GeoIP database in the embedded Zaxonlite store, managing one node or a cluster, with explicit isolation targets and inconclusive container measurements, an authenticated live GeoIP globe dashboard, complete route wireframes, resolved design decisions, protocol, data model, build pipeline, and delivery plan.
discussion
SID 0008: AI Bot Traffic Identification, Multi-Tier Verification, and Operator Console Analytics
Specifies the architecture for identifying, verifying, and monitoring AI crawler and automated bot traffic in Sibuna: zero-allocation single-pass signature matching, sub-microsecond Radix CIDR verification for major providers (OpenAI, Anthropic, Google Gemini, Perplexity, Meta, Apple, ByteDance), multi-tier confidence classification, bounded telemetry extensions, and a real-time console dashboard delivering visual composition, time-series analysis, and granular tabular analytics contrasting bot traffic against actual human traffic.
committed
SID 0009: Chunked Request Bodies: Strict In-Place Decoding, Canonical Re-Framing, and Inspection Equivalence
Specifies how the reverse proxy accepts chunked request bodies without a heap allocation or a second buffer: a strict RFC 9112 chunk grammar that rejects every known terminator and extension ambiguity, an in-place decoder whose output never overtakes its input, Content-Length forwarding for bodies that complete within the connection buffer and canonical re-chunking for the rest, and proofs that inspection sees exactly the bytes a Content-Length request would show and that the origin cannot observe the client's framing.