filebot
Retired — functionality merged into avwatch.
retired 2026-05-31This tool has moved
filebot was a Python CLI for event-driven file routing and
quarantine — TOML rules with condition filters + actions
(move, rename, hash, quarantine, log) and a polling daemon.
Every command has been absorbed into
avwatch as the
route subcommand, with several improvements:
- Atomic move with cross-filesystem fallback —
std::fs::renamefirst, then a cleancopy + removewhen the destination is on another mount point (the Python build raisedEXDEV). - Per-rule rate-limit + per-(rule, path) dedup window (
rate_limit_secs/dedup_window_secs). Storms of inotify-style events no longer repeatedly fire the same action. - Dedicated
quarantineaction — moves to$AVWATCH_HOME/quarantine/<date>/and writes a.sha256sidecar for chain-of-custody. - JSONL audit log — append-only, one action per line, parseable by
jq. (filebot used SQLite;avwatch route auditqueries the JSONL with filters identical to the oldfilebot logs.) - Rule hot-reload — the watcher re-checks every
.tomlfile's mtime every 30 ticks and reloads in place. No daemon restart needed when editing rules. - Same 18 conditions + 8 original actions ported verbatim (extension, size_gt/lt/between, age_gt/lt, modified_before/after, mime_type, filename_regex with named captures, etc.).
avwatch route test <rule> <file>— dry-runs a single rule against a specific file (Python'stestonly validated config syntax).
Migration
# Old (filebot)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- filebot
filebot init
filebot rules validate
filebot run ~/Downloads --dry-run
filebot watch
filebot test quarantine-executables ~/Downloads/payload.exe
filebot logs --tail 100 --format json
# New (avwatch route)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- avwatch
avwatch route init
avwatch route validate
avwatch route run ~/Downloads --dry-run
avwatch route watch
avwatch route test quarantine-executables ~/Downloads/payload.exe
avwatch route audit --tail 100 --format json
Why retired?
filebot and avwatch both watched directories and reacted to file
events — filebot for routing, avwatch for integrity
baselining and signature scans. Folding them into one binary
lets a single polling loop service both jobs and lets
avwatch scan share the action engine (a future
--on-hit quarantine flag is the obvious next step).
Operators install one binary instead of two.
Deferred to a follow-up session: the
--tui rich-based interactive menu (low ratio of
value to maintenance burden), desktop / webhook notifications
(Python's notify action also collapsed to a log
line), and SIGHUP-based hot-reload (the avwatch port reloads on
a 30-tick mtime check instead, which is equivalent in practice).