Backtick‑Bash Protocol (BBP) Specification – Revision v7.2
Purpose Backtick‑Bash is a user‑defined execution, orchestration, provenance, persistence, tool‑management, and communication protocol for interacting with ChatGPT and available execution/tooling environments. It defines how an invocation is identified, when a request means execution rather than explanation, execution provenance, WebX/network separation, library/file ingress and egress, persistent state, tool acquisition and registration, mediated network communication, response inspection and sanitization, nested/backend execution contexts, capability versus protocol notation, failure and unavailable states, and version inheritance. BBP does not create capabilities; the actual runtime/tool schemas remain authoritative.
Governing Invariants 1. Observed reality outranks assumption. 2. Authorization does not equal capability (shell, root, sudo, filesystem, network, binaries, etc.). 3. Capability does not guarantee successful execution. 4. No fabrication of stdout, stderr, exit codes, PIDs, process state, filesystem state, network responses, package versions, hashes, installations, deployments, library writes, memory commits, proxy activity, WebX activity, tool availability, or successful execution. If no compatible executor exists, return an UNAVAILABLE observation.
Protocol Identity BBP identity is protocol continuity, not hidden model continuity. Distinguishes conversation, memory, library, execution, registry, and runtime capability states.
Core Execution Syntax Canonical form: `josh@localhost_gpt: <command>` inside a fenced block represents an execution request when a compatible real executor exists. Legacy forms (e.g., `josh@gpt: <command>`) are retained as BBP request notation, not native Bash syntax.
Voice Invocation Trigger: `B-Bash:` with optional web modifiers (`web off`, `web on`, `web only`).
Text Web Modifiers `!<command>` or fenced `!```...``` disables WebX. `?<command>` or `?```...``` enables WebX. `*```...```*` requests secluded WebX handling.
Triple‑Pipe Operator (`|||`) Prefix (`||| Josh@gpt: <command>`) requests ingress of library artifacts into the execution context. Suffix (`Josh@gpt: <command> |||`) requests egress of resulting artifacts. The egress resolves to a PIPE_FILE which must be derived from the actual execution result.
PIPE_FILE Handling Single file: resolve, read bytes, copy to temporary artifact, verify, transfer to library, verify transfer, then provide reference. Multiple files: resolve each, preserve paths, archive, verify, transfer, verify. Directory: resolve, enumerate recursively, archive, verify, transfer, verify.
Library Boundary The Library acts as a persistence/artifact intermediary between execution filesystem and downloadable references. No fabricated download references are permitted.
Tool Registry / Hive Located at `/BBP-Registry/` with subfolders OUTBOUND, INBOUND, config/registry.json, etc. Only real compatible tool results may be labeled ACTUAL.
Authorization Model Authorization tokens (e.g., `@T2`) do not prove root, sudo, kernel privilege, sandbox access, or execution success.
Autonomous Task Scope Within an authorized task, BBP permits autonomous continuation for inspection, building, testing, repair, verification, artifact generation, tool use, and dependency resolution. Expansion beyond the authorized scope requires additional authorization.
State Continuity Tiers S0 – Workspace continuity (source, files, config, artifacts). S1 – Restartable process continuity (command, cwd, env, dependencies). S2 – Live‑process checkpoint (requires CRIU, kernel, namespaces, cgroups, privileges).
Backtick State State bundles stored under `/mnt/data/backtick-states` include filesystem.tar.gz, environment.json, processes.json, recipes.json, manifest.json, SHA256SUMS. Checksums must be verified before restoration.
Tool Registry Commands Bootstrap: `|||REG BOOT` Status: `|||REG STATUS [tool]` Add: `|||REG ADD <tool>` Update, Verify, Restore, Remove, Migrate, Sync are also defined. Tool records contain canonical name, aliases, observed version, version probe, timestamp, ecosystem, installation method, integrity metadata, executable path, SHA‑256, runtime fingerprint, dependencies, MCP launch details, restoration strategies, verification procedures, provenance, limitations, and notes. Observations are append‑only; the newest verified observation determines operational state.
Tool Acquisition Workflow Identify missing capability → search registry/library → acquire/restore/build/connect → verify → register → continue original task. Only report unavailable after all legitimate paths are exhausted.
Ruflo Orchestration Layer Ruflo is the default orchestration mechanism when technically executable. It handles task invocation, ensures Ruflo availability, acquires/restores needed tools, verifies, registers, decomposes, parallelizes dependency‑safe work, reconciles results, and continues the task. Serial execution is used for true dependencies, resource conflicts, rate limits, safety constraints, and acquisition/restoration dependencies.
Encrypted Canonical Protocol Memory Implemented with AES‑256‑GCM, random nonce, AAD, ciphertext, hashes, key fingerprint, and metadata. Keys must never be stored in library, saved memory, registry, plaintext documents, manifests, logs, handoff files, or source‑code constants.
Memory Commands `|||MEM BOOT`, `|||MEM UNLOCK`, `|||MEM LOCK`, `|||MEM COMMIT`, `|||MEM REKEY`. Boot sequence locates canonical capsule, decrypts, verifies AES‑GCM, verifies hashes/manifests, loads ephemeral state, boots registry, and verifies runtime tools.
Secret Boundary Reusable secrets (AES keys, API tokens, passwords, cookies, authentication headers, private keys, session tokens, Firebase credentials, Ruflo secrets, Picovoice AccessKeys, raw biometric data, face/fingerprint templates, raw voice enrollment, reusable speaker embeddings) must not be persisted. Credential metadata may be retained where necessary.
Cross‑Plane Networking (v6.0) Library‑backed store‑and‑forward enables indirect network access without native guest Internet. Flow: Guest request → local BB proxy → serialized request → Library → outer networked retrieval plane → serialized response → Library → guest response spool → reconstructed response. No arbitrary TCP, CONNECT, SSH, raw sockets, or unattended Internet services are provided.
Recursive Non‑Stopping Invariant (v6.0.3) If stopping would violate the protocol while a legitimate continuation exists, continue via diagnosis, acquisition, restoration, building, connecting, reconfiguring, changing execution plane, decomposing, or retrying through another authorized mechanism.
Provenance Chain Requests, invocations, inspections, tool execution, results, response inspection, sanitization, acceptance, and delivery must be preserved in order. Mediated networking adds outbound, network, inbound steps.
Failure Handling Report actual failures without conversion. For packaging or verification failures, retain the actual execution result but indicate the specific failure. If no executor is available, return UNAVAILABLE.
Version Lineage v1.x → v2.0 → v2.0.1 → v2.0.1[2.4] → v3.x → v5.x (v5.0‑v5.5) → v6.0 (v6.0.1‑v6.0.4) → v7.x (v7.0.1, v7.2).
Known Version Changes Key additions per version are listed in the source (e.g., structured tool registry, additive preservation, local proxy inspection, PIPE_FILE semantics, verified library transfer, multiple‑file packaging, Ruflo orchestration, encrypted memory, cross‑plane networking, recursive invariant, inbound/outbound inspection pipeline, nested/backend execution).
Interpretation Priority 1. Explicit current user instruction 2. Explicit current BBP revision 3. Inherited BBP syntax 4. Actual runtime/tool schema 5. Verified Library/registry state 6. General protocol semantics.
Implementation Model for ChatGPT BBP is interpreted as a request/orchestration convention layered over actual exposed tools. The request is parsed, the operation identified, a compatible tool selected, the tool invoked, the result observed, provenance classified, and the result returned. The actual tool schema remains authoritative.
Non‑Negotiable Rule ACTUAL MEANS ACTUAL – protocol notation does not equal execution, authorization does not equal capability, capability does not equal success, historical state does not equal current state, local artifact does not equal Library persistence, protocol‑defined proxy does not equal running proxy, requested execution does not equal observed execution. If an actual result exists, report it; otherwise report UNAVAILABLE/UNVERIFIED. Never fabricate missing results.
Source status The primary source `bbp-v7-update.txt` contains 18,098 lines and consolidates earlier BBP material. Reconstruction notes explicitly prohibit inventing unrecovered historical wording. A web search was performed only for external verification and did not replace the supplied source material.