Port v2.2 analysis features from upstream oraculovision into PyBLOCK's
Rich terminal UI:
- Add Transaction & Address Inspector (menu D) with flow, fees, BIP-110
flags, spam signals, UTXO balance, and mempool exposure
- Refactor bip110.py to pluggable detector architecture with flagged_raw
cache for pruned-node drill-down from Block Detail View
- Extend bitcoin-cli wrapper with getrawtransaction, scantxoutset, etc.
- Add unit tests and PR_ORACLEVISION_V2.2.md documentation
- Renumber Launch Full TUI to menu option E
Upstream: https://github.com/MarcanoFilms/oraculovision v2.2.0a1
- Fix detect_token_patterns to scan decoded ASCII instead of hex strings
- Handle malformed oraclevision.conf without crashing the menu
- Add security.py to validate executables, paths, and RPC method names
- Resolve subprocess targets before launch with nosemgrep audit notes
Integrate lightweight sovereign analysis tools from OracleVision into PyBLOCK's
Bitcoin menu. Adds modular BIP-110 violation scanning, Mempool Glass composition
via getblocktemplate, block detail view, and optional launch of the full
OracleVision TUI. Detection logic is separated from UI for community extension.
- Replace all shell=True subprocess calls with Python-native processing
(nodeconnection.py, SPV/nodeconnection.py, SPV/ppi.py)
- Mask sensitive inputs (private keys, passwords, tokens) with getpass
- Add threading.Lock to block_explorer.py shared state
- Use json.loads() instead of fragile string splitting in apisnd.py
- Add path validation before file open in apisnd.py
- Replace random.randint with secrets.randbelow for mining nonces
- Fix destructive exception handlers in clone.py and feed.py
- Replace bare except clauses with specific exceptions + logging
- Remove unused imports (psutil, xmltodict, block_visualizer, base64, say)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Replace all dynamic .split() patterns in subprocess calls with safe
alternatives: shlex.split(), explicit list args, and _run_btc/_run_ln
helpers in PyBlock.py. Covers PyBlock, block_visualizer, clockscript,
lastblockdetail, mempoolclock, nodeconnection, and ai/context.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1. Shell injection in readHexBlock/readHexTx (PyBlock.py):
- Validate user input with hex-only regex before use
- Replace shell=True pipe chain with subprocess list + piped stdin
- Same fix for OP_RETURN loop TX decoding
2. Shell injection in weather commands (ppi.py):
- Replace curl shell commands with requests.get()
- User input (city, lang, unit) no longer touches shell
- Upgraded from HTTP to HTTPS
3. Runtime crash in SPV/spvblock.py:
- os.path.isfile() called with 2 args (TypeError)
- Fixed to use 'and' for two separate checks
4. Config files added to .gitignore:
- pybitblock/config/*.conf (RPC creds, API keys, tokens)
- pybitblock/SPV/config/*.conf
- *.log files
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Centralize bitcoin-cli subprocess calls into a single _run_cli()
function with nosemgrep annotation. The cli path is already
sanitized via shlex.split() before reaching this function.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Add cyan separator lines (────) before and after AI responses
- Change prompt to 'pyblock>' in yellow to distinguish from AI text
- Balance shown below the closing separator in dim
- Add UTF-8 env vars to entrypoint.sh for ttyd/Docker contexts
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Rich Console renders to a StringIO buffer, then the result is
encoded as UTF-8 bytes and written directly to sys.stdout.buffer,
bypassing Python's stdout encoding which may not be UTF-8 in all
launch contexts (ttyd, Docker, pipes).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Reconfigure sys.stdout to UTF-8 when the ai module loads, ensuring
accented characters (á, é, ñ, ¡, ¿) render correctly regardless
of how PyBLOCK was launched.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Force Rich Console to use UTF-8 output encoding so Spanish
accented characters render correctly in the terminal.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Use shlex.split() to safely parse bitcoincli path before passing
to subprocess.run(), same pattern as clock/data.py fix.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
The status line after 'U' (usage) showed the old balance instead
of refreshing it from the API. Now calls get_balance() before
displaying the status line.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Major UX improvements inspired by KCode's terminal rendering:
- Continuous chat flow — no screen clearing between messages,
conversation scrolls naturally like a real chat
- Rich Markdown rendering for AI responses — proper tables,
code blocks with syntax highlighting, headers, bold, bullets
- Remove "Press Enter to continue" interruption from chat loop
- Compact status line showing balance + commands inline
- Ctrl+C returns to main menu cleanly
- Balance updates shown inline after each response
- Context refreshed on each query for up-to-date node data
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Client tries the public URL first (api.astrolexis.space), and
falls back to localhost:10400 on 404 or connection errors. This
handles CDN cache issues and provides resilience when the gateway
runs on the same machine as PyBLOCK.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
A function with yield is always a generator in Python, so
chat() with stream=False was returning a generator instead
of a dict. Split into chat() for non-streaming (returns dict)
and _stream_chat() for streaming (yields SSE chunks).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
New pybitblock/ai/ package integrating with Astrolexis AI Gateway
at https://api.astrolexis.space:
- client.py: API client for auth, top-up (Lightning), chat (SSE
streaming), and usage tracking
- context.py: Gathers Bitcoin/Lightning node data (via CLI, RPC,
or mempool.space API) for AI context injection
- ui.py: Terminal chat interface with conversation history,
Lightning top-up flow with QR codes, usage stats display,
and first-time token setup
Accessible from Main Menu as "I - AI Assistant". All queries go
through Astrolexis gateway — user pays in sats via Lightning.
Token stored in pyblocksettings.conf.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Remove 1000-sat Lightning invoice paywalls from LNBits, LNPay, and
OpenNode API integrations. All three now go directly to config setup
(same flow as TippinMe/TallyCoin which were already free).
Changes:
- Replace aaccPPiLNBits/LNPay/OpenNode() payment loops with direct
config-or-setup logic in both PyBlock.py and SPV/spvblock.py
- Change all menu labels from PAID/PREMIUM/LOCKED to FREE
- Remove LNURL file existence checks (lnbitSN.conf gates)
- Remove ~400 lines of payment invoice generation, QR display,
and payment polling code
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
ColdCore was non-functional due to literal '$HOME' paths that never
expanded, making all file checks always fail. The upstream project
(jamesob/coldcore) is experimental/alpha and requires Coldcard
hardware, limiting its audience.
Removed: callColdCore() function, menu entry "I" (ColdCore), and
handlers from PyBlock.py, SPV/spvblock.py, and umbrel-app.yml.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
The clock commit (8e27372) inadvertently reverted Rich Columns menus
(Bitcoin submenu, Lightning, API menus) back to plain ANSI format.
Restored from commit 3062a34 and reapplied clock changes on top:
- artist()/design() delegation to clock.run_clock()
- mainmenuControl unified clock launch
- menuSelection()/menuSelectionLN() using cfg singleton
- Settings D option with clockDisplaySettings()
- TUI startup using cfg.intro_mode
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Use shlex.split() instead of str.split() for bitcoin-cli commands
to prevent command injection via crafted config values
- Remove partial threading.Lock usage that only guarded writes but
not reads, relying on Python's GIL for atomic attribute assignment
- Remove unused threading import (Lock)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
The hash_art() function was hardcoding pad based on 80 columns.
Now accepts term_width parameter and the renderer passes the
real terminal width for proper centering.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Miner pool tag: shows who mined the last block (coinbase decode for local/remote, API for lite)
- Block weight meter: colored fullness bar (green/yellow/red)
- Block time histogram: sparkline of last 14 block intervals with color-coded speed + streak detection
- Peer count: network connections indicator with health coloring
- Moon phase: current lunar phase emoji + name
All toggleable via Settings → D (Clock Display Settings).
Also fixes negative countdown timer (clamp to 0) and countdown row tracking bug.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
New clock/ package replaces the old design() polling loop with a
flicker-free ANSI cursor-positioned renderer. Features include:
countdown timer, epoch/halving progress bar, fee rate indicator,
hashrate sparkline, matrix mining animation, odometer digit transition,
heartbeat pulse, zen mode, UTC time display, fireworks on milestone
blocks, generative hash art, and configurable sound modes.
All features are toggleable via Settings → D (Clock Display Settings).
Also fixes hardcoded config paths in menuSelection(), menuSelectionLN(),
and TUI startup to use the cfg singleton instead.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Config now reads these env vars (with priority over config files):
Bitcoin Core:
BITCOIN_RPC_HOST, BITCOIN_RPC_PORT, BITCOIN_RPC_USER, BITCOIN_RPC_PASS
BITCOIN_CLI_PATH
Lightning (LND):
LND_HOST, LND_GRPC_PORT, LND_TLS_CERT_PATH, LND_MACAROON_PATH
LND_CLI_PATH
Mode:
PYBLOCK_MODE (A=Bitcoin+Lightning, B=Bitcoin, C=Lite)
When env vars are set, config files are auto-generated for consistency.
This enables zero-config deployment on Umbrel where credentials are
injected via docker-compose environment.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Major improvements to callColdCore():
- Fix $HOME path bug: use os.path.expanduser() for all paths
- Rich status panel showing: Bitcoin CLI, ColdCore install, wallet file
- Step-by-step setup guide with Rich panels when public.txt missing
- Auto-create ~/.pyblock directory with confirmation
- Show wallet balances from bitcoin-cli before launching
- Install ColdCore to ~/.pyblock/coldcore with --depth 1
- Proper error handling with show_error()
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
PyBlock.py has a local function console() (bitcoin-cli console).
The Rich Console import was shadowing it. Renamed to rich_console.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Replace the flat 25-item single-column ANSI menu with Rich Columns
organized by category:
- BLOCKCHAIN: Console, Info, Run Numbers, Latest, Moscow Time, Genesis
- MONITORING: Mempool, Unconfirmed, Visualizer, Block/Node/Mempool/Peers
- TOOLS: Decode HEX, QR, Tx Confirm, Search, OP_RETURN, Misc, ColdCore
- STATS & MINING: Stats, Hashrate, CLI/OwnNode Miner, Vanity, Wallet
Each category has its own color (orange, cyan, green, yellow) and
header. Much easier to scan and find features.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Major visual upgrade to the block treemap:
- Squarified treemap algorithm for proper space-filling layout
- Half-block characters (▀) for 2x vertical resolution
- mempool.space-inspired color scale (turquoise→blue→purple→orange→red)
- Dark borders between transactions for visual separation
- Wider treemap (up to 120 cols) and taller (up to 30 rows)
- Improved legend with Low/High labels
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
New block_viz.py replacing the old asciimatics-based block_visualizer:
- Colorful transaction treemap (purple→blue→green→yellow→red fee scale)
- Block info panel: height, hash, pool, tx count, size, weight, fees
- Top 8 fee transactions table with color-coded fee rates
- Fee distribution histogram with 8 color-coded buckets
- Works with bitcoin-cli and mempool.space API
- Interactive navigation: prev/next/latest/goto block
- Launch standalone: python3 block_viz.py [height]
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Bring back the Panel borders for sysinfo, status bar, header, and menu
but use style='on default' which inherits the terminal's background
color instead of Rich's default dark gray. border_style='dim' keeps
the borders subtle.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Tables pad columns with spaces that show a different background color.
Switch sysinfo and menu to console.print() with markup strings instead,
which render with the terminal's native background color.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Replace Panel() wrappers with plain text output for status_bar and
header — Panels create a visible background box that clashes with
dark terminal themes. Error/warning panels kept as-is since they
should visually stand out.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Use transparent backgrounds instead of forced dark grays in panels
- Replace ░ block chars with ─ dashes for progress bar empty space
- Set console highlight=False to prevent unwanted auto-styling
- Remove pyblock.dim style from panels (used default dim instead)
Rich elements now blend seamlessly with the terminal's own background.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- artist(): catch KeyboardInterrupt explicitly so Ctrl+C breaks the
block display loop and returns to caller
- main(): change KeyboardInterrupt handler from sys.exit(0) to
continue, which loops back to menuSelection()
Users can now press Ctrl+C to exit any screen and return to the menu.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
When bitcoincli is empty, go straight to Lite Mode instead of trying
remote mode (which also fails without tls/macaroon). Also validate
remote mode has tls configured before attempting connection.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
codecs is used in 10+ places for macaroon encoding but was previously
available only via star imports that were removed in the security audit.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>