- Change quick subparser --rules to dest=rule_files to prevent collision with the top-level --rules=store_true Hashmob download flag
- Update run_noninteractive to read args.rule_files instead of args.rules
- Move ATTACK_COMMANDS above run_noninteractive (Fix 5)
- Fix has_attack_subcommand to scan all argv elements (supports leading global flags like --debug)
- Replace raw input() dedup prompt with _auto_input() so non-interactive runs don't block
- Update existing quick dispatch tests to use rule_files= namespace key
- Add test_main_quick_with_rules_dispatches: proves --rules routes to crack, not download
- Add test_main_debug_flag_before_subcommand: proves leading global flags don't break routing
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Appends `run_noninteractive(ctx, args)` to noninteractive.py, which
dispatches quick/dict/brute/topmask commands to the appropriate hcat*
function. Returns 0 on success, 1 on bad inputs, 2 on unknown command.
Includes 6 new unit tests (12 total in file), all passing.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
ollamaUrl was built as "http://" + OLLAMA_HOST, so any value carrying a scheme
- the form Ollama's own tooling accepts - was mangled:
OLLAMA_HOST=https://ollama.example.com
-> http://https://ollama.example.com
The LLM attack then could not connect, and reaching a remote Ollama over TLS
was impossible. llm.py derives its client base URL as f"{ollamaUrl}/v1", so the
malformation propagated into the OpenAI-compatible client.
Extract _normalize_ollama_url() so the logic is unit-testable - ollamaUrl is
assigned at module import, which is otherwise only reachable via reload - and
prepend the scheme only when absent. Also strip trailing slashes, since callers
append paths. The bare host:port default is unchanged.
Fixes#119
Co-Authored-By: Claude <noreply@anthropic.com>
The UI polish, cracked-password mode, and target research were all written
into the [2.12.0] section on the assumption they would ship in that release.
They did not: auto-tag cuts a release per merge that contains feat/fix
commits, so #129 became v2.12.0 and #132 became v2.13.0.
Move those entries into a new [2.13.0] section so each heading lists what its
tag actually contains. No entry is duplicated or dropped.
Verified against 'git log v2.11.4..v2.12.0' and 'git log v2.12.0..v2.13.0'.
Co-Authored-By: Claude <noreply@anthropic.com>
2.12.0 is not yet tagged (latest tag is v2.11.4), so this work folds into that
entry rather than cutting a new version.
Co-Authored-By: Claude <noreply@anthropic.com>
- Remove [*] prefix from all input() prompts (10 sites); [*] is a
status/output marker and must not appear in user-facing input prompts.
print() calls that use [*] are untouched.
- Normalize default-value hints to the bare-parentheses form (7 instances
already used it vs. 1 using "default N"); the lone outlier
"\nEnter n-gram group size (default 3): " is rewritten to "(3)".
- Add \n prefix to combipow "Add spaces between words?" prompt so it does
not run flush against the last output line of the wordlist path loop.
- All other prompts already satisfy: capital first letter, ends with ": ",
and correct leading-whitespace context (tab-indented where the surrounding
menu uses tabs, plain \n or none where it follows un-indented output).
- No input() calls added or removed (verified: attacks.py 42→42,
main.py 26→26).
Co-Authored-By: Claude <noreply@anthropic.com>
Target-info mode (menu 12) asked for company, industry, and location as three
blank prompts. Once the company name is known the local Ollama model can often
supply the other two, so ask it and offer the answers as editable defaults.
- llm.research_target(): TargetResearchInput/TargetResearchOutput schemas plus a
research SystemPromptGenerator that tells the model to return empty strings
when it does not genuinely recognize the organization, so an unknown small
client yields blank prompts instead of a confident hallucination.
APITimeoutError is translated to LLMTimeoutError like generate_candidates.
- clean_research_field(): strips, collapses whitespace, caps at 80 chars, and
turns anything non-string into "" so model output cannot be pasted unbounded
into a prompt default.
- main.hcatOllamaResearchTarget(): runs the call inside the existing spinner and
degrades to blank suggestions on timeout or any other failure, so research can
never block the attack.
- attacks.ollama_attack(): shows suggestions as "Industry (freight rail): "
defaults, labelled explicitly as the model's GUESSES rather than OSINT.
- New ollamaAutoResearch config toggle (default true) in both config examples.
Research uses only the configured local Ollama server; the client name is never
sent to a search engine or third-party company-data API.
Co-Authored-By: Claude <noreply@anthropic.com>
The re-prompt loops repainted the whole multicolumn wordlist grid after every
typo, burying the error message under dozens of entries. Hoist the grid and the
p/q legend out of the loop so only the prompt repeats.
ollama_attack's loop also fell through to a silent redraw on an unrecognised
key, leaving no way to tell a rejected key from a repainted prompt.
Co-Authored-By: Claude <noreply@anthropic.com>
- ollama_attack: convert generation-mode menu to interactive_menu with
dynamic items list (option 3 only present when cracked file exists);
cancel via 99 or Escape; re-prompts in a while loop
- omen_attack: convert existing-model menu to interactive_menu; cancel
via 99 or Escape (replaces hard-coded "3. Cancel"); re-prompts in loop
- _omen_pick_training_wordlist: replace abort-on-invalid with re-prompt
loop; add explicit 'q' cancel key so users can exit without being
trapped; callers already handle None correctly
- _markov_pick_training_source: same re-prompt-loop + 'q' cancel fix;
callers already handle None correctly
- Update all affected tests to patch interactive_menu at
hate_crack.attacks.interactive_menu (module-level import path) and
drive follow-up prompts via builtins.input
- Add new tests: arrow-menu reach, Escape/99 cancel, re-prompt loop
coverage for both pickers, and conditional option-3 key presence
Co-Authored-By: Claude <noreply@anthropic.com>
Adds a third LLM Attack generation mode ("cracked") that samples the
plaintexts already recovered this session from <hashfile>.out and asks the
model to infer the target organization's password conventions and emit new
candidates in the same style.
- llm.py: new _CRACKED_PROMPT (offensive candidate generation, explicitly
not the denylist-oriented _WORDLIST_PROMPT), a _PROMPTS mode->prompt map,
and a "cracked" branch in _build_request that tells the model not to
repeat already-cracked passwords.
- main.py: extract the wordlist sampling logic into the shared module-level
helper _sample_plaintext_file(path, cap, source_label) and call it from
both the wordlist and cracked branches of hcatOllama; guard missing and
empty .out files.
- attacks.py: offer mode 3 only when <hashfile>.out exists and is non-empty
(matching _markov_pick_training_source), with a clear message otherwise.
- README: document the three modes and the widened ollamaMaxSampleLines
scope.
Co-Authored-By: Claude <noreply@anthropic.com>
Clearing before the join left a race in the normal path: a spinner thread
sitting just past its stop_event.is_set() check could repaint the line after
the erase, leaving the terminal dirty. Join first so no further writes are
possible, and nest the erase in a finally so an interrupted join (hate_crack
raises DoubleInterrupt on a second SIGINT) still leaves a clean line.
Co-Authored-By: Claude <noreply@anthropic.com>
- Remove review-artifact "Defect 2" comment in main.py:2076; replace with
accurate description of the invalid-cap fallback. Same label removed from
the test section header in test_ollama_wordlist_sampling.py.
- Lift nested _usable helper to module-level _usable_plaintext in main.py,
placed alongside the other private wordlist helpers after _wordlist_path.
Add six direct unit tests covering blank, whitespace, plain, hash:pw,
multi-colon, and empty-plaintext cases.
- Move spinner line-clear before thread.join() in progress.py so the terminal
is cleaned up even if join() is interrupted by a DoubleInterrupt/second Ctrl-C.
Add test_tty_clears_line_even_if_join_raises to cover this path.
- Replace time.sleep-based elapsed-counter test with a deterministic version
that patches time.monotonic; assert on actual rendered format with r"\d+s".
Drop the misleading 0.05s sleep in test_tty_clears_line_on_exit (shorter
than one tick, so no frame was ever guaranteed).
- Add missing ollama* keys to hate_crack/config.json.example (package-data
copy); root config.json.example already had them.
Co-Authored-By: Claude <noreply@anthropic.com>
- Defect 1 (main.py): Replace floating-point stride loop with exact
floor(k * total / cap) index formula so sampling always returns
EXACTLY cap items for any 1 <= cap <= total_usable, including the
stride < 2 regime where the old approach returned cap-1 items.
- Defect 2 (main.py): Validate ollamaMaxSampleLines before computing
the stride; values <= 0 are nonsensical and fall back to 500
(same as the default) rather than raising ZeroDivisionError.
- Defect 3 (test_progress_spinner.py): Rewrite test_non_tty_no_extra_thread
to patch threading.Thread and assert it was never called, so the test
actually fails when the spinner starts a thread in the non-TTY path.
- Defect 4 (test_progress_spinner.py): Simplify test_non_tty_prints_message
to use monkeypatch.setattr instead of the dead mock.patch.object +
manual assign/restore layering; removes two # type: ignore comments.
- docs(README.md): Document ollamaMaxSampleLines alongside ollamaNumCtx /
ollamaTimeout in the Ollama Configuration section.
- tests: Add boundary-case tests for stride < 2 (total==cap, total==cap+1,
total=3/cap=2, cap=1) and zero-cap fallback; make
test_ollama_max_sample_lines_default exercise behaviour rather than
the ambient config value.
Co-Authored-By: Claude <noreply@anthropic.com>
Defect 1 — hcatOllama showed a plain print then blocked silently for
up to 300 s while waiting for the LLM. A new generic context manager
`hate_crack/progress.py::spinner()` now runs a daemon thread that
repaints a single line with a frame + elapsed-seconds counter every
~120 ms. TTY guard ensures non-TTY/test environments get a single
plain print instead of ANSI control characters. The line is erased
with \033[2K\r on exit (normal and exceptional).
Defect 2 — the wordlist path materialised every line in memory and
built a prompt that could massively overflow ollamaNumCtx on large
wordlists. The path now does a two-pass evenly-spaced sample: pass 1
counts usable lines, pass 2 stride-selects up to `ollamaMaxSampleLines`
(default 500, new config key) spread across the full file. When no
capping occurs the message reads "Loaded N passwords"; when capping
occurs it reads "Sampled N of M passwords".
Co-Authored-By: Claude <noreply@anthropic.com>
requires-python is ">=3.13", so a fresh worktree's "uv sync --dev" picks the
newest interpreter on the box - currently CPython 3.15.0a7 - and the build
fails because pyo3 0.26 (via jiter/fastuuid/pydantic-core) does not support
3.15 yet:
error: failed to run custom build command for `pyo3-ffi v0.26.0`
CI already pins 3.13 via setup-uv, so this only bit local worktrees. Pinning
matches CI and leaves requires-python alone.
Co-Authored-By: Claude <noreply@anthropic.com>
The Atomic Agents client was built with no timeout, so an Ollama server that
accepted the TCP connection but never replied (most commonly a large model still
loading into VRAM) left the CLI blocked in agent.run() forever. The caller's
`except Exception` handler only ever fired on connection-refused.
- llm.generate_candidates() takes a `timeout` parameter (default
DEFAULT_TIMEOUT_SECONDS = 300.0) and forwards it to the OpenAI client.
- openai.APITimeoutError is translated into a new domain-level
llm.LLMTimeoutError so main.py need not import openai itself, keeping the
atomic-agents/instructor dependency isolated to llm.py as documented.
- hcatOllama passes the new `ollamaTimeout` config value and prints
timeout-specific guidance (elapsed seconds, VRAM-loading hint, the setting to
raise) instead of the misleading "ensure Ollama is running" message.
- Documented `ollamaTimeout` in config.json.example and README.
Also closes two test gaps: the defensive `except ValueError` handler in
hcatOllama now has coverage, and the misleadingly-named `test_unknown_mode_raises`
is split into explicit unit tests of _build_request's mode validation. Ticked the
completed steps in the LLM Atomic Agents plan doc.
Co-Authored-By: Claude <noreply@anthropic.com>
hate_crack/llm.py imports all three directly, but only atomic-agents was
declared -- they were available purely as transitive deps. A future
atomic-agents release that loosened its coupling to any of them would make
`uv sync` silently omit it and break `import hate_crack.llm` at runtime.
Co-Authored-By: Claude <noreply@anthropic.com>
Conflicts resolved:
- CHANGELOG.md: kept both [2.12.0] (branch) and [2.11.4] (main), newest first
- pyproject.toml: kept main's tighter version pins (click>=8.4.2, requests>=2.34.2,
packaging>=26.2, pytest-cov==7.1.0) and the branch's atomic-agents>=2.0.0 dep
Co-Authored-By: Claude <noreply@anthropic.com>
The repo had no CI: ruff/ty/pytest ran only in local prek pre-push hooks, so
a commit pushed without hooks installed reached main unvalidated -- and
auto-tag would then cut a release from it. Adds ci.yml (ruff, ty, pytest on
3.13) and gates tagging on it.
Auto-tagged versions also never produced a release. The tag is pushed with
the default GITHUB_TOKEN, and GitHub suppresses workflow triggers for
GITHUB_TOKEN-created events, so the tag-triggered release.yml never fired --
v2.11.3 was tagged with no release. auto-tag now creates the release itself,
idempotently; release.yml stays as the manual-tag path.
Also fixes version logic that matched the `!` breaking marker but only ever
bumped minor (and never saw BREAKING CHANGE: footers, since only subjects
were inspected), serializes concurrent merges that both computed the same
tag, and repins softprops/action-gh-release from an arbitrary master commit
to v2.6.2 with all workflows on one actions/checkout version.
Clears the pre-existing ty error in notify/tailer.py that would have made
the new type-check step red: _read_new_lines read self._file_pos
(int | None) while its only None-guard lived in the caller, so the position
is passed in explicitly as an int. Behavior unchanged.
Co-Authored-By: Claude <noreply@anthropic.com>