{"_id":"@22elix3r/fence-linux-x64-gnu","name":"@22elix3r/fence-linux-x64-gnu","dist-tags":{"alpha":"0.1.0-alpha.2","latest":"0.1.0-alpha.2"},"versions":{"0.1.0-alpha.2":{"name":"@22elix3r/fence-linux-x64-gnu","version":"0.1.0-alpha.2","description":"Fence CLI binary for x86-64 GNU/Linux","license":"MIT OR Apache-2.0","repository":{"type":"git","url":"git+https://github.com/22elix3r/fence.git"},"os":["linux"],"cpu":["x64"],"libc":["glibc"],"publishConfig":{"access":"public","provenance":true},"_id":"@22elix3r/fence-linux-x64-gnu@0.1.0-alpha.2","bugs":{"url":"https://github.com/22elix3r/fence/issues"},"homepage":"https://github.com/22elix3r/fence#readme","_integrity":"sha512-UuwnSDQKAz/l+qjt3ks+MgsrpIttKP2XEYYrGm/U82U3OJwha4YD3oTztkM8XG3NCmg9biL0qZ/BanlmaeABxw==","_resolved":"/home/runner/work/fence/fence/npm-tarballs/22elix3r-fence-linux-x64-gnu-0.1.0-alpha.2.tgz","_from":"file:/home/runner/work/fence/fence/npm-tarballs/22elix3r-fence-linux-x64-gnu-0.1.0-alpha.2.tgz","_nodeVersion":"24.18.0","_npmVersion":"11.5.1","dist":{"integrity":"sha512-UuwnSDQKAz/l+qjt3ks+MgsrpIttKP2XEYYrGm/U82U3OJwha4YD3oTztkM8XG3NCmg9biL0qZ/BanlmaeABxw==","shasum":"47b424444eaea153e417602bc80da4365ae7df2f","tarball":"https://registry.npmjs.org/@22elix3r/fence-linux-x64-gnu/-/fence-linux-x64-gnu-0.1.0-alpha.2.tgz","fileCount":7,"unpackedSize":8362716,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@22elix3r%2ffence-linux-x64-gnu@0.1.0-alpha.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCpVJVpQSYLlZyryEFhEZT/0aLPy3moNtC+7RAK+bMBBQIhAOeW/TRJ+lN4b58QL1z2HRdJ4N5Ahzr1UY2ehMBhPT/4"}]},"_npmUser":{"name":"elix3r","email":"connectarko711@outlook.com"},"directories":{},"maintainers":[{"name":"elix3r","email":"connectarko711@outlook.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/fence-linux-x64-gnu_0.1.0-alpha.2_1785765160534_0.35181491031113254"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-03T13:52:40.399Z","0.1.0-alpha.2":"2026-08-03T13:52:40.780Z","modified":"2026-08-03T13:52:41.121Z"},"maintainers":[{"name":"elix3r","email":"connectarko711@outlook.com"}],"description":"Fence CLI binary for x86-64 GNU/Linux","homepage":"https://github.com/22elix3r/fence#readme","repository":{"type":"git","url":"git+https://github.com/22elix3r/fence.git"},"bugs":{"url":"https://github.com/22elix3r/fence/issues"},"license":"MIT OR Apache-2.0","readme":"# Fence\n\nFence is an open-source, local-first Rust CLI for reviewing filesystem changes\nobserved during an interactive command session.\n\n```console\nfence run -- codex\nfence run -- claude\nfence run -- aider\nfence run -- opencode\nfence run -- bash\n```\n\nFence snapshots the worktree before launching the command and again after it\nexits. Existing staged, unstaged, and untracked work is part of the before\nsnapshot, so a later restore does not mean “reset to Git.” Fence does not invoke\nthe `git` executable, create commits, modify refs, or use Git object storage.\n\n> Fence reports **session-window changes**. It cannot prove which process or\n> person wrote them.\n\n## Project status\n\nFence is security-sensitive public-alpha software. Test recovery first in a\ndisposable repository, preserve the store when recovery is uncertain, and do\nnot run Fence with elevated privileges merely to bypass a permission refusal.\nThe implemented safety-first subset is:\n\n- lossless Unix-byte and Windows-WTF-16 path records;\n- immutable BLAKE3-addressed, Zstandard-compressed raw-byte objects;\n- versioned CBOR manifests and session records;\n- content-addressed per-session inclusion policy freezing global excludes,\n  common `info/exclude`, in-tree ignore bytes, tracked overlays, and repository\n  boundaries;\n- read-only Git discovery, index capture, tracked-path and ignore awareness via\n  `gix`;\n- stable before/after capture around inherited interactive terminal or console streams;\n- Unix signal forwarding with an after-capture attempt after interruption;\n- stale-session abandonment after the inherited child lock is free;\n- path-level diffs with unique exact-content rename detection;\n- bounded, control-character-sanitized unified text diffs;\n- a side-by-side terminal reviewer with narrow-layout fallback and confirmed\n  file-level restore actions;\n- structured three-state restoration planning;\n- bounded inverse three-way text merge with structured overlap conflicts;\n- single-path regular-file, symlink, and empty-directory restore when safety is proven;\n- preview-token-bound whole-session restore of all unambiguous included paths,\n  with staged outputs and a recoverable multi-path journal;\n- exact raw-index restore when the current index still equals the\n  session-end index (split indexes are refused);\n- byte-verified rollback of interrupted file, index, and pre-commit batch\n  transactions, plus roll-forward cleanup after a verified batch commit point;\n- refusal when current bytes, type, symlink target, mode, HEAD, or repository\n  operation state is ambiguous;\n- storage integrity checking and reachability-based garbage collection.\n- experimental native Windows capture/review with handle-relative no-follow\n  traversal, protected per-user storage, and kill-on-close child containment;\n  the internal mutation backend remains publicly refused.\n\nNot yet implemented: combining index restoration into the worktree batch,\nand hunk-level restore. Those cases are refused rather than approximated.\n\n## Install\n\nFence uses Rust 2024 and has an MSRV of Rust 1.85.\n\n```console\nnpm install -g fence-cli@0.1.0-alpha.2\n# or compile the exact prerelease from crates.io\ncargo install fence-cli --version 0.1.0-alpha.2 --locked\n\nfence --version\n```\n\nThe npm package name is `fence-cli`; it installs the `fence` command. The\nunscoped npm name `fence` belongs to an unrelated project. Alpha npm packages\nsupport GNU/Linux x86-64 and Intel/Apple-silicon macOS. They contain prebuilt\nbinaries and have no npm lifecycle scripts or installation-time downloader.\n\nSee the [installation and verification guide](docs/installation.md) for direct\nGitHub archives, checksums, build attestations, PATH setup, upgrades, and source\nbuilds. See [supported platforms](docs/platforms.md) before installing on a\nnon-Ubuntu Linux distribution. The runtime has no network dependency and does\nnot require the `git` executable.\n\n## Five-minute recovery walkthrough\n\nFence creates its private store lazily on the first `fence run`; there is no\nseparate `init` command. Capture is part of `run`, not a standalone command.\n\n```console\nfence run -- sh -c 'printf \"session change\\n\" > example.txt'\nfence sessions\nfence diff <session-id>\nfence restore <session-id> --file example.txt\nfence restore <session-id> --file example.txt --yes\nfence doctor\n```\n\nThe first restore command is a nonmutating preview. Conflicts preserve current\nstate and exit with status 4. Work through the disposable-repository\n[quickstart](docs/quickstart.md) and [first recovery example](docs/recovery.md)\nbefore restoring important files.\n\nThe Fence rename is a deliberate pre-alpha compatibility break. The `fence`\nbinary does not provide an `anchor` alias, read `ANCHOR_*` environment\nvariables, interpret `.anchorignore`, auto-discover old Anchor stores, or\nmigrate them. If a legacy Anchor store is present for the same repository,\n`fence doctor` reports it and mutation/session start refuses; the old data is\nleft untouched. Opaque pre-alpha wire-domain strings and object magic remain\nunchanged where changing them would add no safety and would complicate\nforensics.\n\n## Usage\n\nRun any interactive command from inside a non-bare Git worktree:\n\n```console\nfence run -- codex\nfence sessions\nfence show <session-id>\nfence diff <session-id>\nfence diff <session-id> --current\nfence diff <session-id> --drift\nfence diff <session-id> --format json\nfence review <session-id>\n```\n\nIn the reviewer, `r` exits raw terminal mode and asks for confirmation before\ncalling the same exact single-path restore service. Exact renames are disabled\nas a one-file TUI action because they span two paths.\n\nRestore one worktree-root-relative path:\n\n```console\nfence restore <session-id> --file src/main.rs\nfence restore <session-id> --file src/main.rs --yes\nfence restore <session-id> --file src/main.rs --merge\nfence restore <session-id> --file src/main.rs --merge --yes \\\n  --expect-merged <previewed-object-id>\nfence restore <session-id> --all\nfence restore <session-id> --all --yes \\\n  --expect-current <previewed-manifest-id>\nfence rollback <session-id>\nfence rollback <session-id> --yes \\\n  --expect-current <previewed-manifest-id>\nfence rollback <session-id> --format json\nfence restore <session-id> --file src/main.rs --yes --format json\nfence restore-index <session-id> --yes\n```\n\nThe restore either applies a byte-verified inverse, reports that no action is\nneeded, or exits with a visible conflict. It does not overwrite post-session\ndrift. Without `--yes`, exact restore prints the diff-review command and makes\nno change. `--merge` previews a clean, bounded inverse text merge without changing\nthe worktree and prints its object ID. `--merge --yes --expect-merged <id>`\nrecalculates and applies only that exact result. Overlapping edits,\nbinary/opaque input, and oversized text remain conflicts.\n\n`rollback` is the clearer alias for `restore --all`; both first perform a\nnonmutating preview. They apply only when every changed\npath is unambiguous and `--expect-current` matches a freshly recaptured whole\nworktree manifest. All outputs are staged before any target is evacuated. A\npersistent batch journal retains every backup until all targets verify. Fence\nrefuses a batch that would require reconstructing a missing parent directory;\nit does not infer uncaptured structural directories. The index remains a\nseparate opt-in operation.\n\nVerify retained data and preview garbage collection:\n\n```console\nfence doctor\nfence gc --dry-run\nfence gc\nfence recover\nfence recover-transactions --yes\nfence delete <session-id> --yes\nfence deleted-sessions\nfence undelete <session-id>\n```\n\n`fence diff` returns `1` when differences exist. Restore conflicts return `4`.\nThe `run` command returns the wrapped child’s exit code (or `128 + signal` on\nUnix) after attempting the after-snapshot.\n\nThe default diff is `before → session end`. `--current` is `before → current`;\n`--drift` is `session end → current` and separately reports repository and raw\nindex drift. `fence recover` never guesses a missing session end: after it can\nacquire the worktree lock, it marks stale nonterminal records `Abandoned`.\n`fence recover-transactions --yes` is separate: it validates the immutable\nrestore plan, byte-verifies, and rolls back interrupted single-path/index or\npre-commit batch transactions.\nOnce every batch target verified, recovery instead finishes backup cleanup\nbecause that state is the durable commit point. Legacy incomplete journals\nremain visible but require manual recovery because they lack sufficient state.\n\nSession deletion is recoverable by default. Tombstoned sessions continue to\nprotect their manifests and objects from garbage collection. `fence purge\n<id> --yes` permanently removes only the tombstoned record; a later `fence gc`\ncan then reclaim newly unreachable immutable data.\n\n## Inclusion and limits\n\nBy default Fence includes tracked files and nonignored untracked files. It\nexcludes Git metadata, its own store, ignored files, and submodule contents. A\nroot `.fenceignore` adds Git-style exclusions but cannot re-include a\nGit-ignored path. `.fenceignore` itself is captured.\n\nFence freezes the selected global Git excludes, common `info/exclude`, nested\n`.gitignore`, root `.fenceignore`, case mode, and repository boundaries before\nthe initial capture. Session-end and current captures use those retained bytes\neven if live ignore files later change; drift is shown separately. Older\nsession schemas remain readable but are review-only because they cannot prove a\ncomplete current-state scope.\n\nDefault capture limits are 250,000 included manifest entries, 2 GiB of raw\nregular-file content, and 256 MiB per regular file. Regular files, symlinks, and\nempty directories all consume the entry ceiling. Exceeding a limit aborts\nbefore the child starts. Ignored files are not a security boundary: a\nnonignored `.env`, credential, or key file is stored exactly like source code.\n\nCommand arguments are not retained by default because they commonly contain\ntokens and other secrets. Use `fence run --record-arguments -- <command>` only\nwhen the complete invocation is safe to store. Capture limits and the two\ndegraded-behavior switches can be configured or overridden explicitly; see\n[Configuration](docs/configuration.md).\n\nSee [Safety and threat model](docs/safety.md), [architecture](docs/architecture.md),\nand [storage format](docs/storage.md) before using Fence on sensitive\nworktrees. Operational failures are covered by the\n[troubleshooting guide](docs/troubleshooting.md), and old Anchor users must\nfollow the [migration refusal guide](docs/migration-from-anchor.md). Automation\nshould follow the [schema-1 JSON and exit-status contract](docs/json-api.md)\nrather than parse human output.\nIndependent reviewers can start with the\n[audit guide](docs/audit-guide.md). Implemented and remaining work is tracked\nin the [implementation roadmap](docs/roadmap.md).\n\nTagged Unix alpha releases provide `.tar.gz` archives for Linux x86-64 and\nmacOS x86-64/arm64. Verify the central SHA-256 manifest before installing:\n\n```console\nsha256sum --check --ignore-missing fence-0.1.0-alpha.2-SHA256SUMS\ntar -xzf fence-0.1.0-alpha.2-<target>.tar.gz\ninstall fence-0.1.0-alpha.2-<target>/fence ~/.local/bin/fence\n```\n\nOn macOS, use `shasum -a 256 -c` in place of `sha256sum --check`. GitHub build\nprovenance can additionally be checked with:\n\n```console\ngh attestation verify fence-0.1.0-alpha.2-<target>.tar.gz \\\n  -R 22elix3r/fence\n```\n\nRelease owners follow the [public alpha release\nchecklist](docs/release-checklist.md).\n\n## Platform support summary\n\n| Platform | Capture/review | Filesystem restore |\n|---|---|---|\n| Linux | Supported | Experimental single-path and batch |\n| macOS | Supported | Experimental single-path and batch |\n| Windows | Experimental native support | Not claimed; metadata-safe mutation is pending |\n\nWindows does not receive an npm or direct-download artifact in `alpha.2`.\nLinux ARM, Windows ARM, and Alpine/musl are also unsupported. See the complete\n[platform policy](docs/platforms.md).\n\nWindows paths and command arguments retain exact WTF-16. Capture uses pinned\ndirectory handles, 128-bit file identities, reparse-point inspection, and\nalternate-stream detection. A native no-replace transaction backend exists,\nbut the current manifest records extended-metadata observation as unavailable,\nso public worktree mutation remains refused until that proof gap is closed.\nStores live under the current user's Local AppData and receive a protected\ncurrent-user/SYSTEM DACL. The wrapped process tree is assigned to a\nkill-on-close Job object. Windows capture/review remains experimental while its\nreal-runner compatibility matrix grows, especially for non-NTFS volumes,\nantivirus sharing interference, unusual case-sensitive directories, and\nthird-party console applications.\n\n## Contributing\n\nSee [CONTRIBUTING.md](CONTRIBUTING.md). Security issues should follow\n[SECURITY.md](SECURITY.md).\n\n## License\n\nLicensed under either Apache-2.0 or MIT, at your option.\n","readmeFilename":"README.md","_rev":"1-2fa56d54835cd68ba3b89e59360e94a9"}