feat(booter): ctx 1.54.0, process table v9, and Holepunch/POSIX proc parity

- Bump BARE_OS_CTX_API_VERSION to 1.54.0 and POSIX profile to 1.0.19
- Process table schema 9: nice/accountingSource, logical maps/threads /proc builders, renice
- disk.os: replication_operator_sketch v8, HyperDHT address sketch, pkg index surfaces
- Protomux operator sketch v4, security_posture v7, corestore snapshot UX hint, pear_stage_pointer v2
- Swarm: BARE_OS_SWARM_ATTEMPT_BURST_PER_SEC; HDMS: host booter warn logging; shell wait exit codes
- getconf/sysconf: additional _SC_* via bareOsGetconfSysconf; socketMsgSurface v6 (iovec/SUSv4 refs)
- Identity: vault rotation audit includes pathcap trusted key count
- CI/docs: holepunch drift report env, kernel STRUCTURE note, verify-bundle-throws comment, matrices and examples
This commit is contained in:
Raven Scott
2026-04-05 23:14:08 -04:00
parent 071edccfb3
commit 72e0c9c881
44 changed files with 958 additions and 549 deletions
+1 -1
View File
@@ -46,7 +46,7 @@ The [developer guide](developer-guide/README.md) is the **how-to** for `start(ct
### POSIX surface
Intentional coverage and gaps for utilities, shell, and VFS: [handbook — Chapter 9](handbook/09-posix-utilities-shell-and-vfs.md). Declared profile **`1.0.18`** (**`BARE_OS_POSIX_PROFILE_VERSION`**) with **`ctx`** API **`1.53.0`** — see [POSIX declared profile](docs/architecture/POSIX_DECLARED_PROFILE.md) and [compatibility matrix](docs/reference/compatibility-matrix.md). Machine-readable summary: [docs/reference/posix-compliance-matrix.json](docs/reference/posix-compliance-matrix.json) (verified in **`pretest`**).
Intentional coverage and gaps for utilities, shell, and VFS: [handbook — Chapter 9](handbook/09-posix-utilities-shell-and-vfs.md). Declared profile **`1.0.19`** (**`BARE_OS_POSIX_PROFILE_VERSION`**) with **`ctx`** API **`1.54.0`** — see [POSIX declared profile](docs/architecture/POSIX_DECLARED_PROFILE.md) and [compatibility matrix](docs/reference/compatibility-matrix.md). Machine-readable summary: [docs/reference/posix-compliance-matrix.json](docs/reference/posix-compliance-matrix.json) (verified in **`pretest`**).
## Quick start
+4 -2
View File
@@ -6,7 +6,7 @@ This document is the **normative contract** for how closely the stock Bare OS ke
| Constant | Value |
| -------- | ----- |
| `BARE_OS_POSIX_PROFILE_VERSION` | `1.0.18` |
| `BARE_OS_POSIX_PROFILE_VERSION` | `1.0.19` |
| `BARE_OS_POSIX_PROFILE_ID` | `bare-os-posix-like` |
| `BARE_OS_POSIX_PROFILE_REFERENCE` | Open Group Issue 7 index URL |
@@ -19,7 +19,7 @@ This document is the **normative contract** for how closely the stock Bare OS ke
Bare OS does **not** expose a C ABI. The following **observability contracts** stand in for “system calls”:
- **`/proc/bare_os/syscalls.json`** — Declares **fd model**, **signal model**, **errno hints**, **operation detail**, **`posixXsh`**, **`socketMsgSurface`**, and related adjuncts (schema **11** in stock builds; see [`docs/reference/posix-compliance-matrix.json`](../reference/posix-compliance-matrix.json)). **`ops`** lists invocable **`ctx.bareOsSyscall`** names (**`posix_fadvise`** as a simulated no-op hint; **`clock_gettime`** for REALTIME / MONOTONIC sketches alongside **`nanosleep`**); **`opsDetail`** also carries **POSIX.1 XSH** logical names (**`open`**, **`close`**, **`read`**, **`write`**, **`readv`**, **`writev`**, **`getsockopt`**, **`setsockopt`**, **`lseek`**, **`pipe`**, **`dup`**, **`dup2`**, **`fcntl`**, **`poll`**, **`select`**, **`umask`**, **`fsync`**, **`fdatasync`**, **`posix_fadvise`**, and **socket family** probes) with **`posixAlignment`** (**`simulated`**, **`partial`**, **`ENOTSUP`**) and **`mapsTo`** for traceability; stable **`susv4Refs`** string tokens (for example **`XSH/open`**) support audit cross-walks. The **`posixXsh`** object summarizes those XSH names (via **`bareOsPosixXshOpsCsv()`**); schema **3** pairs with syscall proc **11**. **`socketMsgSurface`** (schema **5**) documents **`sendmsg`** / **`recvmsg`** on the bridge: bounded **iovec** flattening for datagram and stream paths; binary ancillary control on **`sendmsg`** remains **`ENOTSUP`** with structured rejection metadata unless **`BARE_OS_POSIX_SOCKET_SCM_RIGHTS=1`**, in which case JSON-shaped **`cmsgs`** may request logical **`scmRightsLocalDup`** on **SOCK_STREAM** and **SOCK_DGRAM** bridge fds (guest logical FD duplication — not host **`SCM_RIGHTS`**); **`recvmsg`** reports **`controllen: 0`** on the receive path. **`fcntl`** supports **`F_GETFL`** / **`F_SETFL`** (Linux-shaped **`O_APPEND`** **`0x400`**, **`O_NONBLOCK`** **`0x800`**) and **cooperative advisory locks** via **`F_GETLK`** / **`F_SETLK`** / **`F_SETLKW`** using **`args.path`** (absolute) or **`args.fd`** whose logical target is an absolute path; contended **`F_SETLK`** returns **`EAGAIN`**. **`F_SETLKW`** also returns **`EAGAIN`** by default; with **`BARE_OS_POSIX_FCNTL_BLOCKING_WAIT`**, waiters are queued **FIFO per lock path** until the lock is free or **`BARE_OS_FCNTL_LOCK_WAIT_MS_MAX`** elapses (**`ETIMEDOUT`**; default **30000** ms, max **300000**). There is **no** cross-path global fairness and **no** host deadlock detection. Unknown FDs yield **`EBADF`**. **`readv`** / **`writev`** perform bounded scatter/gather on **`BARE_OS_POSIX_FD_SIM`** pipe read/write ends. **`poll`** / **`select`** share the same logical FD readiness probe when **`BARE_OS_POSIX_FD_SIM`** is enabled; with **`BARE_OS_POSIX_SOCKET_FD_BRIDGE=1`**, bridged **datagram** fds participate (**`SOCK_DGRAM`** via **`bareDgram`** when merged) with bounded **`recv`** / **`recvfrom`** queues (**`BARE_OS_POSIX_DGRAM_RECVQ_MAX`**, **`BARE_OS_POSIX_DGRAM_RECV_BLOCK_MS_MAX`**); passive **`SOCK_STREAM`** uses **`bind`/`listen`/`accept`** when **`bareTcp.Server`** is available. **Socket-shaped** syscalls default to **`ENOSYS`** / **`ENOTSUP`**; with **`BARE_OS_POSIX_SOCKET_FD_BRIDGE=1`**, **`socket`** + **`connect`** may use **`ctx.bare.bareTcp.Socket`** (**`SOCK_STREAM`**) or **`bareDgram`** (**`SOCK_DGRAM`**) when merged. The stock booter **caches** this JSON until warm read-cache invalidation.
- **`/proc/bare_os/process_table.json`** — **schema 8****PGID** / **SID**-style fields, **`parentName`** (from **`ppid`**), **signal routing**, initd binding, optional per-row accounting (**`threads`**, **`cpuMs*`**, I/O stubs, **`replicationHint`**) for the **logical** process table (not host PIDs).
- **`/proc/bare_os/process_table.json`** — **schema 9****PGID** / **SID**-style fields, **`parentName`** (from **`ppid`**), **signal routing**, initd binding, per-row **`nice`** (**`-20`..`19`**, via **`ctx.bareOsRenice`**), **`accountingSource`** on metrics fields, optional per-row accounting (**`threads`**, **`cpuMs*`**, I/O counters, **`replicationHint`**) for the **logical** process table (not host PIDs). Companion **`/proc/bare_os/process_maps.json`** (**schema 2**, model **`bare-os-logical-v1`**) and **`/proc/bare_os/process_threads.json`** (**schema 2**) describe **logical** layouts (not Linux **`/proc/pid/maps`**).
**Explicit non-goals**
@@ -73,6 +73,8 @@ Signal names accepted by **`kill`** and shell builtins follow POSIX **names** wh
Bump **`BARE_OS_POSIX_PROFILE_VERSION`** in `bare-os-protocol` when **intentional** utility, shell, VFS, or proc-contract behavior changes. Update this file, handbook ch.9, and §14a in the same change set.
**1.0.19****`ctx.bareOsRenice`** stores **logical nice** on **`process_table.json`** rows (no host scheduler). **`socketMsgSurface` schema 6** documents **`iovecSemantics`** and **`recvmsg`** **`susv4Refs`**. **`disk.os`** **`replication_operator_sketch` schema 8** adds **`hyperdhtAddressSketch`** (**`BARE_OS_HYPERDHT_ADDRESS_JSON`**) and **`pkgIndexSurface` / `pkg_index_get` schema 2** echoes. **`corestoreSnapshotUxHint` schema 4** adds **`recommendedWorkflow`**. **`security_posture` schema 7** adds **`replicationOperatorSketchCrossRef`**. **`pear_stage_pointer` schema 2** links **`pear-runtime-updater`**. Boot **`/proc/bare_os/boot_budget_summary.json`** may merge **`replicationLiveCoalesced`** after kernel handoff. Shell **`wait`** uses background job **`lastExitCode`**. Swarm **`BARE_OS_SWARM_ATTEMPT_BURST_PER_SEC`** caps connection attempts per rolling second (policy engine). Dynamic **`getconf`/`sysconf`** adds **`_SC_MONOTONIC_CLOCK_RES`** ( **`bare-hrtime`** when present), trace/timer negated constants, **`vault_save`** audit includes **`pathcapTrustedKeyCount`**.
**1.0.18****`awk`**: **`getline var < path`** reads from the guest VFS with per-path line caching; POSIX math builtins **`atan2`**, **`cos`**, **`sin`**, **`exp`**, **`log`**, **`sqrt`**; unary **`-`**; **`substr(s, start)`** two-argument suffix form; async evaluation path in the engine for I/O-capable builtins. Man page and handbook §7 updated. **`expr`**: POSIX **`: `** match-length operator (ECMA **`RegExp`** body under **`^(?:…)`**). **`test`**: **`FILE1 -nt FILE2`**, **`FILE1 -ot FILE2`**, **`FILE1 -ef FILE2`** using **`mtimeMs`** and optional **`dev`/`ino`**.
**1.0.17** — Syscalls proc **schema 11** (**`susv4Refs`** on **`opsDetail`**, **`posixXsh` schema 3**); **`ctx`** API **1.53.0**; **`disk.os`** **`replication_operator_sketch` schema 7** (**`corestoreSnapshotUxHint`**, **`pkgIndexSurface`**, **`bare_os.pkg_index_get`** + **`BARE_OS_PKG_INDEX_PATH`**); optional **Protomux cap channel** (**`BARE_OS_PROTOMUX_CAP_CHANNEL`**, feature bit); **`metrics_live.replicationLive`** collaboration hints + optional **`BARE_OS_COLLAB_SESSION_NDJSON`**; **`security_posture`** blind-relay posture sketch; **`ctx.bareOsVerifyPathCapabilityEnvelopeTrusted`** + **`BARE_OS_PATH_CAPABILITY_TRUSTED_PUBKEYS_HEX`**; **`/proc/bare_os/boot_budget_summary.json`**; warm-cache adaptive **jitter** (**`BARE_OS_VFS_WARM_REPL_ADAPTIVE_JITTER_PCT`**); shell unset-only default expansion (**`BARE_OS_SHELL_POSIX_UNSET_ONLY_DEFAULT`**); **`pathcap-verify --trusted`**; **`pkg-swarm-index`** **`list` / `get`** against drive manifest or HRPC.
+1 -1
View File
@@ -1,6 +1,6 @@
{
"schemaVersion": 1,
"generatedAt": "2026-04-06T03:01:17.886Z",
"generatedAt": "2026-04-06T03:12:51.824Z",
"normativeManifest": "packages/bare-os-booter/lib/bare-module-manifest.json",
"buildTool": "packages/bare-os-bare-libs/build.mjs",
"bundles": [
+1 -1
View File
@@ -1,6 +1,6 @@
{
"schema": 2,
"note": "pretest runs verify-holepunch-clone-drift only against repos[] (empty = no-op). Optional: BARE_OS_HOLEPUNCH_DRIFT_TIER1=1 checks tier1Repos[] instead (maintainer spine). For release gates, copy names from suggestedCriticalRepos into repos[] after git fetch origin main in each clone, or set BARE_OS_HOLEPUNCH_DRIFT_CHECK=0 to skip. Missing clones are skipped with a warning; listed clones must not lag origin/main. lockfilePackages drives scripts/report-holepunch-lockfile-drift.mjs (npm run audit:holepunch-clones). goldenPathRepos is emitted by scripts/sync-holepunch-clones.mjs as goldenPathRows (local HEAD vs origin/main ahead/behind) for maintainer review only — it does not gate CI.",
"note": "pretest runs verify-holepunch-clone-drift only against repos[] (empty = no-op). Optional: BARE_OS_HOLEPUNCH_DRIFT_TIER1=1 checks tier1Repos[] instead (maintainer spine). Optional: BARE_OS_HOLEPUNCH_DRIFT_WRITE_REPORT=1 writes docs/audit/holepunch-drift-last-run.md after a successful drift pass. For release gates, copy names from suggestedCriticalRepos into repos[] after git fetch origin main in each clone, or set BARE_OS_HOLEPUNCH_DRIFT_CHECK=0 to skip. Missing clones are skipped with a warning; listed clones must not lag origin/main. lockfilePackages drives scripts/report-holepunch-lockfile-drift.mjs (npm run audit:holepunch-clones). goldenPathRepos is emitted by scripts/sync-holepunch-clones.mjs as goldenPathRows (local HEAD vs origin/main ahead/behind) for maintainer review only — it does not gate CI.",
"repos": [],
"tier1Repos": [
"hypercore",
+2 -2
View File
@@ -14,7 +14,7 @@ Single place to compare **protocol**, **booter `ctx` API**, **feature-bit docume
## Version artifacts
**`bareOsCtxApiVersion`** (current stock: **`1.53.0`**) — Defined in [`packages/bare-os-booter/lib/bare-os-ctx-api.js`](../../packages/bare-os-booter/lib/bare-os-ctx-api.js). This is the semver string for the documented **`ctx`** contract; bump it when stable guest-visible behavior changes.
**`bareOsCtxApiVersion`** (current stock: **`1.54.0`**) — Defined in [`packages/bare-os-booter/lib/bare-os-ctx-api.js`](../../packages/bare-os-booter/lib/bare-os-ctx-api.js). This is the semver string for the documented **`ctx`** contract; bump it when stable guest-visible behavior changes.
**`BARE_OS_KERNEL_FEATURE_BITS_DOC`** (current stock: **`16`**) — Exported from [`packages/bare-os-protocol/lib/kernel-feature-bits.js`](../../packages/bare-os-protocol/lib/kernel-feature-bits.js). It versions the feature-bit documentation and related governance; keep it aligned with [`developer-guide/adr/001-kernel-feature-bits-governance.md`](../../developer-guide/adr/001-kernel-feature-bits-governance.md).
@@ -24,7 +24,7 @@ Single place to compare **protocol**, **booter `ctx` API**, **feature-bit docume
**Protocol package** — Workspace version in [`bare-os-protocol` `package.json`](../../packages/bare-os-protocol/package.json). Pair it with seeder and booter releases when you change wire behavior.
**POSIX-like profile****`BARE_OS_POSIX_PROFILE_VERSION`** (**`1.0.18`**) and **`BARE_OS_POSIX_PROFILE_ID`** (**`bare-os-posix-like`**) in [`bare-os-protocol/lib/bare-os-posix-profile.js`](../../packages/bare-os-protocol/lib/bare-os-posix-profile.js). Surfaced under **`/proc/bare_os_features`** as **`capabilitySurface.posixProfile`** and in **`/proc/bare_os/syscalls.json`**.
**POSIX-like profile****`BARE_OS_POSIX_PROFILE_VERSION`** (**`1.0.19`**) and **`BARE_OS_POSIX_PROFILE_ID`** (**`bare-os-posix-like`**) in [`bare-os-protocol/lib/bare-os-posix-profile.js`](../../packages/bare-os-protocol/lib/bare-os-posix-profile.js). Surfaced under **`/proc/bare_os_features`** as **`capabilitySurface.posixProfile`** and in **`/proc/bare_os/syscalls.json`**.
**`/proc/bare_os/syscalls.json`** — Schema **11** (see also [handbook ch.9 §2.3](../../handbook/09-posix-utilities-shell-and-vfs.md#23-pseudo-proc-sys-run-dev-and-session-tmp)) adds **`susv4Refs`** tokens on **`opsDetail`** and bumps **`posixXsh` schema** to **3**; schema **10** added **`posix_fadvise`** as a simulated **`ctx.bareOsSyscall`** no-op and retains **`clock_gettime`** (REALTIME / MONOTONIC sketch); earlier schema fields remain: cooperative **`fcntl`** advisory locks (optional **`BARE_OS_POSIX_FCNTL_BLOCKING_WAIT`** for **`F_SETLKW`**-shaped waits), optional **`BARE_OS_POSIX_SOCKET_FD_BRIDGE`** **`socket`/`connect`** (**`SOCK_STREAM`** via **`bareTcp`**, **`SOCK_DGRAM`** via **`bareDgram`** when merged) with bounded **`send`/`sendmsg`/`recv`/`recvfrom`/`recvmsg`** on bridged datagram fds (**`BARE_OS_POSIX_DGRAM_RECVQ_MAX`**, **`BARE_OS_POSIX_DGRAM_RECV_BLOCK_MS_MAX`**), **`socketMsgSurface`** schema **5** (**`sendmsg`/`recvmsg`** partial on bridge; binary ancillary **`ENOTSUP`**; optional **`logicalScmRightsOnSend`** when **`BARE_OS_POSIX_SOCKET_SCM_RIGHTS`**; **`recvmsg`** **`controllen` 0**), and retains socket-family **probes** plus **`posixXsh`**. Earlier schemas added **`fdModel`**, **`signalModel`**, **`opsDetail`**, **`errnoHints`**, and **`posixProfile`**. The stock booter **caches** the JSON text until **`vfs.bareOsClearWarmReadCaches()`** / **`ctx.bareOsInvalidateWarmReadCaches()`** (same invalidation path as **`/bin`** warm cache; **`boot/init.js`** and **`lib/init/**` batch puts also invalidate). Example payload: [`kernel/etc/bare-os/syscalls.example.json`](../../kernel/etc/bare-os/syscalls.example.json); JSON Schema: [`docs/schemas/bare-os-syscalls.schema.json`](../schemas/bare-os-syscalls.schema.json).
@@ -1,16 +1,16 @@
// Auto-generated by scripts/gen-ctx-client-helper.mjs — do not edit by hand.
/** Canonical `ctx` API semver from `packages/bare-os-booter/lib/bare-os-ctx-api.js`. */
export const BARE_OS_CTX_API_CLIENT_VERSION = '1.53.0' as const
export const BARE_OS_CTX_API_CLIENT_VERSION = '1.54.0' as const
/** Relative path to the hand-maintained TypeScript contract (schema source of truth). */
export const BARE_OS_CTX_DTS_SOURCE = 'packages/bare-os-booter/lib/bare-os-ctx.d.ts' as const
/** Approximate count of `bareOs…` members in the DTS (diagnostic only; regenerate on contract edits). */
export const BARE_OS_CTX_DTS_BAREOS_MEMBER_APPROX = 156 as const
export const BARE_OS_CTX_DTS_BAREOS_MEMBER_APPROX = 157 as const
/** Byte length of `bare-os-ctx.d.ts` when this file was generated. */
export const BARE_OS_CTX_DTS_BYTES = 20232 as const
export const BARE_OS_CTX_DTS_BYTES = 20491 as const
/** Pointers for external client generators (OpenAPI / JSON Schema follow-ups). */
export const BARE_OS_CTX_SCHEMA_HINT = {
@@ -117,10 +117,12 @@ The list below is one **bullet per variable** in the form **name — component
- `BARE_OS_KERNEL_HOT_RELOAD` — Booter — Dev: allow **`ctx.bareOsRequestKernelReload()`** to re-read **`/boot/init.js`**.
- `BARE_OS_KERNEL_EXT_D_HOT_RELOAD` — Stock kernel — When **`1`** / **`true`**, after boot the kernel exposes **`ctx.bareOsReloadKernelExtDropinsSafe()`**, which re-scans **`/etc/bare-os/kernel.ext.d`** and runs only extension scripts not yet recorded (**append-only**; does not unload). When **`ctx.vfs.writeFile`** exists, each reload appends **`kernelExtReloadSchemaVersion`** lines to **`/run/bare-os/kernel-ext-reload.ndjson`**.
- `BARE_OS_VFS_HYPERBLOBS_DEDUP` — Booter / features proc — When **`1`** / **`true`**, surfaces an operator hint under **`/proc/bare_os/features`** that host mirror / hyperblob pipelines may use content-defined chunking; the guest VFS does not enable hyperblobs by itself.
- `BARE_OS_HYPERBLOBS_STATS_JSON` — Booter / **`disk.os`** — Optional non-secret JSON parsed into **`replication_operator_sketch.hyperblobsDedupSketch`** (merged into **`disk.os`** response **schema 7**).
- `BARE_OS_CORESTORE_STATS_JSON` — Booter / **`disk.os`** — Optional non-secret JSON parsed into **`replication_operator_sketch.corestoreOperatorSketch`** (**`bare_os.replication_operator_sketch`** response **schema 7**). Use for namespace counts, open-core tallies, or other **non-secret** Corestore operator metrics (no keys or paths to private material). Together with **`BARE_OS_CORESTORE_SNAPSHOT_JSON`**, **`corestoreSnapshotUxHint`** (schema **3**) surfaces non-secret merge counts for rollback UX.
- `BARE_OS_HYPERBLOBS_STATS_JSON` — Booter / **`disk.os`** — Optional non-secret JSON parsed into **`replication_operator_sketch.hyperblobsDedupSketch`** (merged into **`disk.os`** **`replication_operator_sketch`** response **schema 8**).
- `BARE_OS_CORESTORE_STATS_JSON` — Booter / **`disk.os`** — Optional non-secret JSON parsed into **`replication_operator_sketch.corestoreOperatorSketch`** (**`bare_os.replication_operator_sketch`** response **schema 8**). Use for namespace counts, open-core tallies, or other **non-secret** Corestore operator metrics (no keys or paths to private material). Together with **`BARE_OS_CORESTORE_SNAPSHOT_JSON`**, **`corestoreSnapshotUxHint`** (schema **4**) surfaces non-secret merge counts for rollback UX.
- `BARE_OS_HYPERDHT_ADDRESS_JSON` — Booter / **`disk.os`** — Optional non-secret JSON parsed into **`replication_operator_sketch.hyperdhtAddressSketch`** (same RPC; align with **hyperdht-address** operator payloads — keep bounded and non-secret).
- `BARE_OS_BLIND_PEER_TOPOLOGY_V3_JSON` — Booter / **`disk.os`** — Optional non-secret JSON parsed into **`replication_operator_sketch.blindTopologySketchV3`** (**schema 3** sketch object).
- `BARE_OS_SUBPROCESS_BRIDGE_META_JSON` — Booter / **`process_table.json`** — Optional JSON (**host-injected**); the stock snapshot exposes a non-secret summary under **`subprocessBridgeMeta`** (**schema 7** **`process_table`**) for **`bare-process`** / **`bare-subprocess`** bridge alignment.
- `BARE_OS_PROCESS_ACCOUNTING` — Booter / **`process_table.json`** — When **`1`** / **`true`**, per-row accounting fields use **`accountingSource: guest-accounting-env`** (reserved for future Bare-threadbacked counters; defaults remain zero until wired).
- `BARE_OS_XARGS_MAX_PROCS`**`/bin/xargs`** — Raises the cap for **`-P`** parallelism (still bounded by a hard maximum of **32** and by delegate concurrency when **`runBinCommand`** uses workers); default effective cap **8** when unset.
- `BARE_OS_PEER_FIREWALL_E2E_JSON` — Booter / replication proc — Optional operator JSON merged into **`/proc/bare_os/replication`** for peer-firewall end-to-end checks (**invalid JSON yields an error object** in proc).
- `BARE_OS_REPLICATION_PLAN_JSON` — Booter — Optional JSON string merged into **`/proc/bare_os/replication`** as **`guestReplicationPlan`** (operator warm-replication / mirror-drive style hints; guest does not execute the plan).
@@ -139,7 +141,8 @@ The list below is one **bullet per variable** in the form **name — component
- `BARE_OS_SWARM_MAX_PEERS` — Booter — Integer passed to Hyperswarm **`maxPeers`** when set (non-empty positive integer string).
- `BARE_OS_SWARM_MAX_CLIENT_CONNECTIONS` — Booter — Cap inbound client connections (**Hyperswarm** **`maxClientConnections`**).
- `BARE_OS_SWARM_MAX_SERVER_CONNECTIONS` — Booter — Cap outbound server connections (**Hyperswarm** **`maxServerConnections`**).
- `BARE_OS_SWARM_MAX_PARALLEL` — Booter — Integer passed to Hyperswarm **`maxParallel`** when set. Effective values echo under **`/proc/bare_os/swarm`** **`connectionBudget`** and **`disk.os` `replication_operator_sketch`** (**schema 7**).
- `BARE_OS_SWARM_MAX_PARALLEL` — Booter — Integer passed to Hyperswarm **`maxParallel`** when set. Effective values echo under **`/proc/bare_os/swarm`** **`connectionBudget`** and **`disk.os` `replication_operator_sketch`** (**schema 8**).
- `BARE_OS_SWARM_ATTEMPT_BURST_PER_SEC` — Booter — Optional positive integer; caps **connection attempt** accounting in the swarm policy engine (**rolling 1s window**; increments when **`consumeReconnectBudget`** runs). **`shouldAttemptPeer`** returns false when the burst is exhausted.
- `BARE_OS_PEAR_SECURE_ENCLAVE_JSON` — Booter / security posture — Non-secret JSON pointer for optional Pear secure-enclave key storage hints; treat as opaque unless host policy attests hardware backing (see [vault threat model](../security/vault-threat-model.md)).
- `BARE_OS_ACCOUNT_KEY_ROTATION_STATE_JSON` — Booter / security posture — Non-secret JSON for signing continuity across overlapping trust windows during account key rotation (not private keys).
- `BARE_OS_VAULT_MULTISIG_CONTINUITY_JSON` — Booter / **`/proc/bare_os/hyper_multisig_trust_pointer.json`** — Optional operator JSON merged as **`vaultMultisigContinuity`** when the proc builder uses **schema 2** (pointer-only multisig continuity sketch; no secret keys).
+3 -1
View File
@@ -21,7 +21,9 @@ Bare OS splits **hand-authored kernel code** from **vendored Holepunch runtime b
**`pkg-swarm-index` / path capabilities:** Drive manifest **`/etc/bare-os/pkg-index.json`** (or HRPC **`bare_os.pkg_index_get`**) may attach **`pathCapabilityEnvelope`** on entries; **`pkg-swarm-index get`** calls **`ctx.bareOsVerifyPathCapabilityEnvelope`** when present and prints **`pathCapabilityEnvelopeVerify`** (see [`kernel/etc/bare-os/pkg-index.example.json`](../../kernel/etc/bare-os/pkg-index.example.json)). VFS read enforcement remains under **`BARE_OS_PATH_CAPABILITY_*`** as documented in the POSIX profile.
After **initd**, **`SwarmDisk`** wires **`disk.os`** via [`createBareOsDiskOsBridge`](../../packages/bare-os-booter/lib/bare-os-disk-os-bridge.js): peer **`searchLocal`**, whitelisted **`bare_os.*`** **`execRpc`** methods including **`bare_os.replication_operator_sketch`** (**schema 5** JSON: replication status, **`swarmPeerCount`**, Hyperswarm **`connectionBudget`**, protomux operator sketch fields, env mirrors for pause/backpressure, optional **`corestoreOperatorSketch`** from **`BARE_OS_CORESTORE_STATS_JSON`**), and optional cap-gated **`bare_os.replication_operator_intent`** when **`BARE_OS_DISK_OS_OPERATOR_INTENT_RPC=1`** (append-only audit via **`ctx.bareOsAuditLogAppendBatch`** when the booter supplies **`auditBatch`**). Narrative: [Handbook ch.3](../../handbook/03-protocol-and-disk.md).
After **initd**, **`SwarmDisk`** wires **`disk.os`** via [`createBareOsDiskOsBridge`](../../packages/bare-os-booter/lib/bare-os-disk-os-bridge.js): peer **`searchLocal`**, whitelisted **`bare_os.*`** **`execRpc`** methods including **`bare_os.replication_operator_sketch`** (**schema 8** JSON: replication status, **`swarmPeerCount`**, Hyperswarm **`connectionBudget`**, protomux operator sketch fields, **`hyperdhtAddressSketch`** from **`BARE_OS_HYPERDHT_ADDRESS_JSON`**, **`pkgIndexSurface`**, env mirrors for pause/backpressure, **`corestoreSnapshotUxHint`**, optional **`corestoreOperatorSketch`** from **`BARE_OS_CORESTORE_STATS_JSON`**), and optional cap-gated **`bare_os.replication_operator_intent`** when **`BARE_OS_DISK_OS_OPERATOR_INTENT_RPC=1`** (append-only audit via **`ctx.bareOsAuditLogAppendBatch`** when the booter supplies **`auditBatch`**). Narrative: [Handbook ch.3](../../handbook/03-protocol-and-disk.md).
**bare-module alignment:** Compare local Holepunch clones **`bare-module`**, **`bare-module-traverse`**, and **`bare-pack`** against boot policy keys **`denyBareModuleSpecifierPatterns`**, **`requireBareCryptoMin`**, and extension **`signaturePointer`** / **`extensionSignerPins`** when evolving the guest **`ctx.bare`** merge — resolver parity is enforced in **`packages/bare-os-booter/lib/kernel-extension-resolver.js`** and **`kernel/lib/init/fragments/30-init-kernel-extensions.js`**.
### Blind relay / Protomux proc hints (schema 2)
+4 -4
View File
@@ -1,7 +1,7 @@
{
"schema": 1,
"profileId": "bare-os-posix-like",
"note": "Machine-readable summary; normative detail remains in handbook ch.9 and environment POSIX appendix. Profile 1.0.18 / syscalls schema 11: awk getline + math builtins + substr(s,start) + unary minus; expr : match-length; test -nt -ot -ef; plus 1.0.17 — opsDetail susv4Refs tokens; posixXsh schema 3; ctx API 1.53.0; process_table.json schema 8 (optional accounting + initd replicationHint); disk.os replication_operator_sketch schema 7 (pkgIndexSurface + corestoreSnapshotUxHint from BARE_OS_CORESTORE_SNAPSHOT_JSON vs BARE_OS_CORESTORE_STATS_JSON counts; BARE_OS_CORESTORE_STATS_JSON corestoreOperatorSketch); bare_os.pkg_index_get HRPC + BARE_OS_PKG_INDEX_PATH; optional BARE_OS_PROTOMUX_CAP_CHANNEL + feature bit; collaborationSession on metrics_live.replicationLive; BARE_OS_COLLAB_SESSION_NDJSON host log; security_posture blindRelayPosture; path capability trusted verify ctx.bareOsVerifyPathCapabilityEnvelopeTrusted + BARE_OS_PATH_CAPABILITY_TRUSTED_PUBKEYS_HEX; /proc/bare_os/boot_budget_summary.json from kernel boot-budget-summary; warm-cache adaptive jitter BARE_OS_VFS_WARM_REPL_ADAPTIVE_JITTER_PCT; shell BARE_OS_SHELL_POSIX_UNSET_ONLY_DEFAULT ${name-default}; pathcap-verify --trusted; pkg-swarm-index list|get. Retains prior 1.0.16 items: posix_fadvise; guest /.bare deny; personal acct prefix; warm replication invalidation; peer admission schema 2; Hyperswarm BARE_OS_SWARM_MAX_*; replication_snapshot schema 2.",
"note": "Profile 1.0.19 / ctx API 1.54.0 / process_table.json schema 9 (nice + accountingSource; logical process_maps + process_threads companions); syscalls schema 11 + socketMsgSurface schema 6 (iovecSemantics + recvmsg susv4Refs); disk.os replication_operator_sketch schema 8 (hyperdhtAddressSketch BARE_OS_HYPERDHT_ADDRESS_JSON; pkgIndexSurface schema 2; pkg_index_get response schema 2); corestoreSnapshotUxHint schema 4 (recommendedWorkflow); security_posture schema 7 (replicationOperatorSketchCrossRef); pear_stage_pointer schema 2; protomuxOperatorSketch schema 4 multiplexPeerCountEcho; boot_budget_summary merges replicationLiveCoalesced after kernel; bareOsRenice stores logical nice; shell wait uses job lastExitCode; swarm BARE_OS_SWARM_ATTEMPT_BURST_PER_SEC; getconf/sysconf _SC_MONOTONIC_CLOCK_RES and trace/timer caps; vault_save checkpoint pathcapTrustedKeyCount. Retains 1.0.18 awk/expr/test extensions and prior POSIX/P2P items.",
"utilities": {
"tier1_bin": "high",
"sed_awk_grep": "issue7_inspired_js_engines",
@@ -11,7 +11,7 @@
"grammar": "line_at_a_time_subset",
"posix_mode_grouped_lists": "BARE_OS_SHELL_POSIX_MODE=1 enables ( compound-list ) without forked subshell",
"pipes": "simulated_capture",
"job_control": "logical_jobs_only (jobControlModel logical_no_fork; no fork(2)); fg sets foregroundPgid; suspend-job + bg/fg cooperative yield between background statements; kill / bareOsSendSignal negative target = pgid on shellBackgroundJobs; wait skips completed jobs by default",
"job_control": "logical_jobs_only (jobControlModel logical_no_fork; no fork(2)); fg sets foregroundPgid; suspend-job + bg/fg cooperative yield between background statements; kill / bareOsSendSignal negative target = pgid on shellBackgroundJobs; wait skips completed jobs by default; wait exit status from job lastExitCode (last non-zero for multi-wait; wait -n first completion)",
"loop_control": "BARE_OS_SHELL_LOOP_CONTROL for break continue in while for",
"errexit": "BARE_OS_SHELL_ERREXIT / set -e or set -o errexit (+e / +o errexit to clear) stops further semicolon lists inside if-then/else and loop bodies; top-level ;-separated statements; condition lists in if/while suppress errexit between predicates",
"nounset": "BARE_OS_SHELL_NOUNSET / set -u or set -o nounset (+u / +o nounset to clear) errors on expansion of unset parameters (except $? and positional digits when absent treated as unbound only if env key missing)"
@@ -27,8 +27,8 @@
},
"synthetic_proc": {
"syscalls_json_schema": 11,
"process_table_schema": 8,
"process_table_schema": 9,
"paths": ["/proc/bare_os/syscalls.json", "/proc/bare_os/process_table.json", "/proc/bare_os/boot_budget_summary.json"],
"posix_xsh_surface": "open,close,read,write,readv,writev,getsockopt,setsockopt,lseek,nanosleep,clock_gettime,posix_fadvise,pipe,dup,dup2,fcntl cooperative F_GETLK/F_SETLK/F_SETLKW + F_GETFL/F_SETFL,poll,select,umask,fsync,fdatasync,socket,bind,listen,accept,connect,send,recv,recvfrom,sendmsg,recvmsg,shutdown in syscalls.json posixXsh.namesCsv; ctx.bareOsSyscall nanosleep; ctx.bareOsSyscall clock_gettime; ctx.bareOsSyscall posix_fadvise; ctx.bareOsSyscall fsync/fdatasync no-op; bridge getsockopt/setsockopt partial SO_KEEPALIVE/TCP_NODELAY; default socket ENOSYS-shaped without bridge; BARE_OS_POSIX_SOCKET_FD_BRIDGE SOCK_STREAM connect via bareTcp; passive SOCK_STREAM bind+listen+accept via bareTcp.Server; stream fds use send/recv with bounded tcpRecvQueue (connect and accept paths); TCP half-close: shutdown how 0/1 (SHUT_RD/SHUT_WR), default how 2 full close; recv EOF after peer FIN; send EPIPE after local SHUT_WR; poll readable on queued TCP data, peer FIN/EOF, or socket error; poll writable when SHUT_WR not set; SOCK_DGRAM passive bind via bareDgram.Socket.bind, connect optional after bind, send with explicit port+host when udp_bound without default peer; connect+send path unchanged; BARE_OS_POSIX_DGRAM_RECVQ_MAX / BARE_OS_POSIX_DGRAM_RECV_BLOCK_MS_MAX; BARE_OS_POSIX_ACCEPT_QUEUE_MAX; poll/select mark UDP bridge fds (connected or udp_bound) readable when dgram queue non-empty; listening fds when accept queue non-empty; ctx.bareOsSyscall readv/writev on POSIX_FD_SIM pipes; ctx.bareOsPosixPoll; socketMsgSurface schema 5 + optional BARE_OS_POSIX_SOCKET_SCM_RIGHTS logical fd dup on sendmsg for SOCK_STREAM and SOCK_DGRAM bridge fds (recvmsg controllen 0)"
"posix_xsh_surface": "open,close,read,write,readv,writev,getsockopt,setsockopt,lseek,nanosleep,clock_gettime,posix_fadvise,pipe,dup,dup2,fcntl cooperative F_GETLK/F_SETLK/F_SETLKW + F_GETFL/F_SETFL,poll,select,umask,fsync,fdatasync,socket,bind,listen,accept,connect,send,recv,recvfrom,sendmsg,recvmsg,shutdown in syscalls.json posixXsh.namesCsv; ctx.bareOsSyscall nanosleep; ctx.bareOsSyscall clock_gettime; ctx.bareOsSyscall posix_fadvise; ctx.bareOsSyscall fsync/fdatasync no-op; bridge getsockopt/setsockopt partial SO_KEEPALIVE/TCP_NODELAY; default socket ENOSYS-shaped without bridge; BARE_OS_POSIX_SOCKET_FD_BRIDGE SOCK_STREAM connect via bareTcp; passive SOCK_STREAM bind+listen+accept via bareTcp.Server; stream fds use send/recv with bounded tcpRecvQueue (connect and accept paths); TCP half-close: shutdown how 0/1 (SHUT_RD/SHUT_WR), default how 2 full close; recv EOF after peer FIN; send EPIPE after local SHUT_WR; poll readable on queued TCP data, peer FIN/EOF, or socket error; poll writable when SHUT_WR not set; SOCK_DGRAM passive bind via bareDgram.Socket.bind, connect optional after bind, send with explicit port+host when udp_bound without default peer; connect+send path unchanged; BARE_OS_POSIX_DGRAM_RECVQ_MAX / BARE_OS_POSIX_DGRAM_RECV_BLOCK_MS_MAX; BARE_OS_POSIX_ACCEPT_QUEUE_MAX; poll/select mark UDP bridge fds (connected or udp_bound) readable when dgram queue non-empty; listening fds when accept queue non-empty; ctx.bareOsSyscall readv/writev on POSIX_FD_SIM pipes; ctx.bareOsPosixPoll; socketMsgSurface schema 6 (iovecSemantics + recvmsg susv4Refs) + optional BARE_OS_POSIX_SOCKET_SCM_RIGHTS logical fd dup on sendmsg for SOCK_STREAM and SOCK_DGRAM bridge fds (recvmsg controllen 0)"
}
}
+4 -4
View File
@@ -10,14 +10,14 @@ Normative narrative: [`docs/architecture/POSIX_DECLARED_PROFILE.md`](../architec
| --- | --- | --- |
| Profile | profileId | bare-os-posix-like |
| Profile | schema | 1 |
| Profile | note | Machine-readable summary; normative detail remains in handbook ch.9 and environment POSIX appendix. Profile 1.0.18 / syscalls schema 11: awk getline + math builtins + substr(s,start) + unary minus; expr : match-length; test -nt -ot -ef; plus 1.0.17 — opsDetail susv4Refs tokens; posixXsh schema 3; ctx API 1.53.0; process_table.json schema 8 (optional accounting + initd replicationHint); disk.os replication_operator_sketch schema 7 (pkgIndexSurface + corestoreSnapshotUxHint from BARE_OS_CORESTORE_SNAPSHOT_JSON vs BARE_OS_CORESTORE_STATS_JSON counts; BARE_OS_CORESTORE_STATS_JSON corestoreOperatorSketch); bare_os.pkg_index_get HRPC + BARE_OS_PKG_INDEX_PATH; optional BARE_OS_PROTOMUX_CAP_CHANNEL + feature bit; collaborationSession on metrics_live.replicationLive; BARE_OS_COLLAB_SESSION_NDJSON host log; security_posture blindRelayPosture; path capability trusted verify ctx.bareOsVerifyPathCapabilityEnvelopeTrusted + BARE_OS_PATH_CAPABILITY_TRUSTED_PUBKEYS_HEX; /proc/bare_os/boot_budget_summary.json from kernel boot-budget-summary; warm-cache adaptive jitter BARE_OS_VFS_WARM_REPL_ADAPTIVE_JITTER_PCT; shell BARE_OS_SHELL_POSIX_UNSET_ONLY_DEFAULT ${name-default}; pathcap-verify --trusted; pkg-swarm-index list\|get. Retains prior 1.0.16 items: posix_fadvise; guest /.bare deny; personal acct prefix; warm replication invalidation; peer admission schema 2; Hyperswarm BARE_OS_SWARM_MAX_*; replication_snapshot schema 2. |
| Profile | note | Profile 1.0.19 / ctx API 1.54.0 / process_table.json schema 9 (nice + accountingSource; logical process_maps + process_threads companions); syscalls schema 11 + socketMsgSurface schema 6 (iovecSemantics + recvmsg susv4Refs); disk.os replication_operator_sketch schema 8 (hyperdhtAddressSketch BARE_OS_HYPERDHT_ADDRESS_JSON; pkgIndexSurface schema 2; pkg_index_get response schema 2); corestoreSnapshotUxHint schema 4 (recommendedWorkflow); security_posture schema 7 (replicationOperatorSketchCrossRef); pear_stage_pointer schema 2; protomuxOperatorSketch schema 4 multiplexPeerCountEcho; boot_budget_summary merges replicationLiveCoalesced after kernel; bareOsRenice stores logical nice; shell wait uses job lastExitCode; swarm BARE_OS_SWARM_ATTEMPT_BURST_PER_SEC; getconf/sysconf _SC_MONOTONIC_CLOCK_RES and trace/timer caps; vault_save checkpoint pathcapTrustedKeyCount. Retains 1.0.18 awk/expr/test extensions and prior POSIX/P2P items. |
| Utilities | tier1_bin | high |
| Utilities | sed_awk_grep | issue7_inspired_js_engines |
| Utilities | coreutils | see packages/bare-os-coreutils/src |
| Shell | grammar | line_at_a_time_subset |
| Shell | posix_mode_grouped_lists | BARE_OS_SHELL_POSIX_MODE=1 enables ( compound-list ) without forked subshell |
| Shell | pipes | simulated_capture |
| Shell | job_control | logical_jobs_only (jobControlModel logical_no_fork; no fork(2)); fg sets foregroundPgid; suspend-job + bg/fg cooperative yield between background statements; kill / bareOsSendSignal negative target = pgid on shellBackgroundJobs; wait skips completed jobs by default |
| Shell | job_control | logical_jobs_only (jobControlModel logical_no_fork; no fork(2)); fg sets foregroundPgid; suspend-job + bg/fg cooperative yield between background statements; kill / bareOsSendSignal negative target = pgid on shellBackgroundJobs; wait skips completed jobs by default; wait exit status from job lastExitCode (last non-zero for multi-wait; wait -n first completion) |
| Shell | loop_control | BARE_OS_SHELL_LOOP_CONTROL for break continue in while for |
| Shell | errexit | BARE_OS_SHELL_ERREXIT / set -e or set -o errexit (+e / +o errexit to clear) stops further semicolon lists inside if-then/else and loop bodies; top-level ;-separated statements; condition lists in if/while suppress errexit between predicates |
| Shell | nounset | BARE_OS_SHELL_NOUNSET / set -u or set -o nounset (+u / +o nounset to clear) errors on expansion of unset parameters (except $? and positional digits when absent treated as unbound only if env key missing) |
@@ -29,6 +29,6 @@ Normative narrative: [`docs/architecture/POSIX_DECLARED_PROFILE.md`](../architec
| VFS | bin_cache | BARE_OS_VFS_BIN_CACHE; warm cache clear via ctx.bareOsInvalidateWarmReadCaches / vfs.bareOsClearWarmReadCaches; BARE_OS_VFS_WARM_CACHE_INVALIDATE_ON_REPLICATION metrics_live path; bareOsVfsBatchWrite clears on bin/lib/bare puts; manifest-only puts use vfs.bareOsEvictLibBareBundlesFromManifest + ctx.bareOsInvalidateWarmReadCachesFromBareManifestJson |
| VFS | lib_bare_cache | BARE_OS_VFS_LIB_BARE_CACHE with bin cache |
| synthetic /proc | syscalls_json_schema | 11 |
| synthetic /proc | process_table_schema | 8 |
| synthetic /proc | process_table_schema | 9 |
| synthetic /proc | paths | /proc/bare_os/syscalls.json, /proc/bare_os/process_table.json, /proc/bare_os/boot_budget_summary.json |
| synthetic /proc | posix_xsh_surface | open,close,read,write,readv,writev,getsockopt,setsockopt,lseek,nanosleep,clock_gettime,posix_fadvise,pipe,dup,dup2,fcntl cooperative F_GETLK/F_SETLK/F_SETLKW + F_GETFL/F_SETFL,poll,select,umask,fsync,fdatasync,socket,bind,listen,accept,connect,send,recv,recvfrom,sendmsg,recvmsg,shutdown in syscalls.json posixXsh.namesCsv; ctx.bareOsSyscall nanosleep; ctx.bareOsSyscall clock_gettime; ctx.bareOsSyscall posix_fadvise; ctx.bareOsSyscall fsync/fdatasync no-op; bridge getsockopt/setsockopt partial SO_KEEPALIVE/TCP_NODELAY; default socket ENOSYS-shaped without bridge; BARE_OS_POSIX_SOCKET_FD_BRIDGE SOCK_STREAM connect via bareTcp; passive SOCK_STREAM bind+listen+accept via bareTcp.Server; stream fds use send/recv with bounded tcpRecvQueue (connect and accept paths); TCP half-close: shutdown how 0/1 (SHUT_RD/SHUT_WR), default how 2 full close; recv EOF after peer FIN; send EPIPE after local SHUT_WR; poll readable on queued TCP data, peer FIN/EOF, or socket error; poll writable when SHUT_WR not set; SOCK_DGRAM passive bind via bareDgram.Socket.bind, connect optional after bind, send with explicit port+host when udp_bound without default peer; connect+send path unchanged; BARE_OS_POSIX_DGRAM_RECVQ_MAX / BARE_OS_POSIX_DGRAM_RECV_BLOCK_MS_MAX; BARE_OS_POSIX_ACCEPT_QUEUE_MAX; poll/select mark UDP bridge fds (connected or udp_bound) readable when dgram queue non-empty; listening fds when accept queue non-empty; ctx.bareOsSyscall readv/writev on POSIX_FD_SIM pipes; ctx.bareOsPosixPoll; socketMsgSurface schema 5 + optional BARE_OS_POSIX_SOCKET_SCM_RIGHTS logical fd dup on sendmsg for SOCK_STREAM and SOCK_DGRAM bridge fds (recvmsg controllen 0) |
| synthetic /proc | posix_xsh_surface | open,close,read,write,readv,writev,getsockopt,setsockopt,lseek,nanosleep,clock_gettime,posix_fadvise,pipe,dup,dup2,fcntl cooperative F_GETLK/F_SETLK/F_SETLKW + F_GETFL/F_SETFL,poll,select,umask,fsync,fdatasync,socket,bind,listen,accept,connect,send,recv,recvfrom,sendmsg,recvmsg,shutdown in syscalls.json posixXsh.namesCsv; ctx.bareOsSyscall nanosleep; ctx.bareOsSyscall clock_gettime; ctx.bareOsSyscall posix_fadvise; ctx.bareOsSyscall fsync/fdatasync no-op; bridge getsockopt/setsockopt partial SO_KEEPALIVE/TCP_NODELAY; default socket ENOSYS-shaped without bridge; BARE_OS_POSIX_SOCKET_FD_BRIDGE SOCK_STREAM connect via bareTcp; passive SOCK_STREAM bind+listen+accept via bareTcp.Server; stream fds use send/recv with bounded tcpRecvQueue (connect and accept paths); TCP half-close: shutdown how 0/1 (SHUT_RD/SHUT_WR), default how 2 full close; recv EOF after peer FIN; send EPIPE after local SHUT_WR; poll readable on queued TCP data, peer FIN/EOF, or socket error; poll writable when SHUT_WR not set; SOCK_DGRAM passive bind via bareDgram.Socket.bind, connect optional after bind, send with explicit port+host when udp_bound without default peer; connect+send path unchanged; BARE_OS_POSIX_DGRAM_RECVQ_MAX / BARE_OS_POSIX_DGRAM_RECV_BLOCK_MS_MAX; BARE_OS_POSIX_ACCEPT_QUEUE_MAX; poll/select mark UDP bridge fds (connected or udp_bound) readable when dgram queue non-empty; listening fds when accept queue non-empty; ctx.bareOsSyscall readv/writev on POSIX_FD_SIM pipes; ctx.bareOsPosixPoll; socketMsgSurface schema 6 (iovecSemantics + recvmsg susv4Refs) + optional BARE_OS_POSIX_SOCKET_SCM_RIGHTS logical fd dup on sendmsg for SOCK_STREAM and SOCK_DGRAM bridge fds (recvmsg controllen 0) |
+1 -1
View File
@@ -12,7 +12,7 @@ If you come from Linux or macOS, Bare OS **feels** like a small Unix: **`ls`**,
**Declared profile (single spec):** [POSIX_DECLARED_PROFILE.md](../docs/architecture/POSIX_DECLARED_PROFILE.md) — contract for XCU/XSH-like behavior, proc stand-ins for “syscalls,” and explicit non-goals.
**Declared profile (constants):** the protocol package publishes **`BARE_OS_POSIX_PROFILE_VERSION`** / **`BARE_OS_POSIX_PROFILE_ID`** (`bare-os-posix-like`), surfaced on **`/proc/bare_os_features`** and in **`/proc/bare_os/syscalls.json`** (schema **10** for that file — adds **`posix_fadvise`** simulated hint and **`clock_gettime`**; **`fdModel`** / **`signalModel`** plus **`opsDetail`** / **`posixXsh`** (schema **2**) / **`socketMsgSurface`** (schema **5**: binary ancillary **`ENOTSUP`**; optional **`BARE_OS_POSIX_SOCKET_SCM_RIGHTS`** JSON **`cmsgs`** → logical **`scmRightsLocalDup`** on **`sendmsg`** for **SOCK_STREAM** and **SOCK_DGRAM** bridge fds; **`recvmsg`** **`controllen: 0`**) / **`errnoHints`**, including cooperative **`fcntl`** advisory locks with optional **`F_SETLKW`** blocking wait (**`BARE_OS_POSIX_FCNTL_BLOCKING_WAIT`**) and optional socket-bridge datagram **`bind`/`connect`/`send`/`sendmsg`/`recv`/`recvfrom`/`recvmsg`** (passive UDP **`bind`**, optional **`connect`** on the same fd, **`send`** with explicit **`port`/`host`** when bound without default peer) with bounded queues; **`/proc/bare_os/index.json`** uses schema **8**). **`getconf BARE_OS_POSIX_XSH_OPS`** lists the XSH names; **`getconf BARE_OS_SYSCALL_OPS`** lists ctx op names only. Cold-boot wall time vs **`BARE_OS_BOOT_BUDGET_MS_COLD`** is also written to **`/run/bare-os/boot-perf.json`** when the VFS supports it. **`metrics_live`** includes **`initdReadiness`** (schema **2**), **`bootBudgetTelemetry`** (schema **2**, unified with **`boot-perf.json`**), and paths such as **`utilitiesIndexPath`** → **`/etc/bare-os/posix_utilities.json`** when present. **Dashboard:** [POSIX + P2P consolidated hub](../docs/README.md#posix--p2p-consolidated-dashboard).
**Declared profile (constants):** the protocol package publishes **`BARE_OS_POSIX_PROFILE_VERSION`** / **`BARE_OS_POSIX_PROFILE_ID`** (`bare-os-posix-like`), surfaced on **`/proc/bare_os_features`** and in **`/proc/bare_os/syscalls.json`** (schema **11** for that file — adds **`posix_fadvise`** simulated hint and **`clock_gettime`**; **`fdModel`** / **`signalModel`** plus **`opsDetail`** / **`posixXsh`** (schema **3**) / **`socketMsgSurface`** (schema **6**: **`iovecSemantics`** + **`recvmsg`** **`susv4Refs`**; binary ancillary **`ENOTSUP`**; optional **`BARE_OS_POSIX_SOCKET_SCM_RIGHTS`** JSON **`cmsgs`** → logical **`scmRightsLocalDup`** on **`sendmsg`** for **SOCK_STREAM** and **SOCK_DGRAM** bridge fds; **`recvmsg`** **`controllen: 0`**) / **`errnoHints`**, including cooperative **`fcntl`** advisory locks with optional **`F_SETLKW`** blocking wait (**`BARE_OS_POSIX_FCNTL_BLOCKING_WAIT`**) and optional socket-bridge datagram **`bind`/`connect`/`send`/`sendmsg`/`recv`/`recvfrom`/`recvmsg`** (passive UDP **`bind`**, optional **`connect`** on the same fd, **`send`** with explicit **`port`/`host`** when bound without default peer) with bounded queues; **`/proc/bare_os/index.json`** uses schema **8**). **`process_table.json`** is **schema 9** with per-row **`nice`** and logical companions **`process_maps.json`** / **`process_threads.json`**. **`getconf BARE_OS_POSIX_XSH_OPS`** lists the XSH names; **`getconf BARE_OS_SYSCALL_OPS`** lists ctx op names only. Cold-boot wall time vs **`BARE_OS_BOOT_BUDGET_MS_COLD`** is also written to **`/run/bare-os/boot-perf.json`** when the VFS supports it. **`metrics_live`** includes **`initdReadiness`** (schema **2**), **`bootBudgetTelemetry`** (schema **2**, unified with **`boot-perf.json`**), and paths such as **`utilitiesIndexPath`** → **`/etc/bare-os/posix_utilities.json`** when present. **Dashboard:** [POSIX + P2P consolidated hub](../docs/README.md#posix--p2p-consolidated-dashboard).
---
+10
View File
@@ -146,6 +146,16 @@ const CONF = {
_SC_HOST_NAME_MAX: '255',
_POSIX_HOST_NAME_MAX: '255',
_SC_MONOTONIC_CLOCK: '1',
/** Dynamic when `ctx.bareOsGetconfSysconf` + native bare-hrtime; static default 0. */
_SC_MONOTONIC_CLOCK_RES: '0',
_SC_TRACE: '-1',
_SC_TRACE_VERSION: '-1',
_SC_RAW_SOCKETS: '-1',
_SC_ADVISORY_INFO: '0',
_SC_BARRIERS: '-1',
_SC_SPIN_LOCKS: '1',
_SC_TIMER_MAX: '32',
_SC_DELAYTIMER_MAX: '0',
_SC_ATEXIT_MAX: '32',
_SC_LINE_MAX: '2048',
_SC_BC_BASE_MAX: '99',
+1 -1
View File
@@ -1,7 +1,7 @@
{
"schema": 2,
"profileId": "bare-os-posix-like",
"generatedAt": "2026-04-06T03:01:17.010Z",
"generatedAt": "2026-04-06T03:12:50.834Z",
"note": "Sparse POSIX Issue 7 coverage hints for /bin utilities. Omitted command names are not yet profiled here.",
"commandIndex": [
{
+14 -5
View File
@@ -1,9 +1,9 @@
{
"schemaVersion": 11,
"ctxApiVersion": "1.53.0",
"ctxApiVersion": "1.54.0",
"posixProfile": {
"id": "bare-os-posix-like",
"version": "1.0.18"
"version": "1.0.19"
},
"ops": ["readFile", "writeFile", "socket"],
"opsDetail": [
@@ -33,7 +33,12 @@
"namesCsv": "open,close,read,write,readv,writev,getsockopt,setsockopt,lseek,nanosleep,clock_gettime,pipe,dup,dup2,fcntl,poll,select,umask,socket,bind,listen,accept,connect,send,recv,recvfrom,sendmsg,recvmsg,shutdown"
},
"socketMsgSurface": {
"schema": 4,
"schema": 6,
"iovecSemantics": {
"sendmsg": "bounded_flatten_all_iovs_into_single_wire_payload",
"recvmsg": "first_iov_primary_datagram_buffer_partial_ok_remainder_truncated",
"susv4Refs": ["XSH/sendmsg", "XSH/recvmsg"]
},
"ancillaryControl": {
"supported": false,
"errno": "ENOTSUP",
@@ -51,7 +56,11 @@
"syscallResultField": "scmRightsLocalDup"
},
"sendmsg": { "bridgePartial": true, "defaultErrno": "ENOTSUP" },
"recvmsg": { "bridgePartial": true, "defaultErrno": "ENOTSUP" }
"recvmsg": {
"bridgePartial": true,
"defaultErrno": "ENOTSUP",
"susv4Refs": ["XSH/recvmsg"]
}
},
"errnoHints": {
"ENOENT": 2,
@@ -60,7 +69,7 @@
"fdModel": {
"schema": 1,
"stdio": [0, 1, 2],
"processTableSchema": 8
"processTableSchema": 9
},
"signalModel": {
"schema": 1,
+218 -218
View File
@@ -7,12 +7,6 @@
"b4a"
]
},
{
"path": "/lib/bare/bundles/compactEncoding.js",
"keys": [
"compactEncoding"
]
},
{
"path": "/lib/bare/bundles/safetyCatch.js",
"keys": [
@@ -26,9 +20,9 @@
]
},
{
"path": "/lib/bare/bundles/protomux.js",
"path": "/lib/bare/bundles/compactEncoding.js",
"keys": [
"protomux"
"compactEncoding"
]
},
{
@@ -38,9 +32,9 @@
]
},
{
"path": "/lib/bare/bundles/barePath.js",
"path": "/lib/bare/bundles/protomux.js",
"keys": [
"barePath"
"protomux"
]
},
{
@@ -49,6 +43,12 @@
"bareEncoding"
]
},
{
"path": "/lib/bare/bundles/barePath.js",
"keys": [
"barePath"
]
},
{
"path": "/lib/bare/bundles/bareEvents.js",
"keys": [
@@ -61,6 +61,12 @@
"bareAbort"
]
},
{
"path": "/lib/bare/bundles/bareReadline.js",
"keys": [
"bareReadline"
]
},
{
"path": "/lib/bare/bundles/bareAbortController.js",
"keys": [
@@ -73,12 +79,6 @@
"bareAnsiEscapes"
]
},
{
"path": "/lib/bare/bundles/bareReadline.js",
"keys": [
"bareReadline"
]
},
{
"path": "/lib/bare/bundles/bareAddonResolve.js",
"keys": [
@@ -86,9 +86,9 @@
]
},
{
"path": "/lib/bare/bundles/bareCrypto.js",
"path": "/lib/bare/bundles/fetch.js",
"keys": [
"bareCrypto"
"fetch"
]
},
{
@@ -104,9 +104,9 @@
]
},
{
"path": "/lib/bare/bundles/bareAssert.js",
"path": "/lib/bare/bundles/bareCrypto.js",
"keys": [
"bareAssert"
"bareCrypto"
]
},
{
@@ -116,9 +116,9 @@
]
},
{
"path": "/lib/bare/bundles/bareAtomics.js",
"path": "/lib/bare/bundles/bareAssert.js",
"keys": [
"bareAtomics"
"bareAssert"
]
},
{
@@ -128,9 +128,15 @@
]
},
{
"path": "/lib/bare/bundles/fetch.js",
"path": "/lib/bare/bundles/bareAtomics.js",
"keys": [
"fetch"
"bareAtomics"
]
},
{
"path": "/lib/bare/bundles/bareBundle.js",
"keys": [
"bareBundle"
]
},
{
@@ -152,9 +158,9 @@
]
},
{
"path": "/lib/bare/bundles/bareBundle.js",
"path": "/lib/bare/bundles/bareBoot.js",
"keys": [
"bareBundle"
"bareBoot"
]
},
{
@@ -170,9 +176,9 @@
]
},
{
"path": "/lib/bare/bundles/bareBoot.js",
"path": "/lib/bare/bundles/bareDebugLog.js",
"keys": [
"bareBoot"
"bareDebugLog"
]
},
{
@@ -181,30 +187,24 @@
"bareBundleId"
]
},
{
"path": "/lib/bare/bundles/bareDaemon.js",
"keys": [
"bareDaemon"
]
},
{
"path": "/lib/bare/bundles/bareChannel.js",
"keys": [
"bareChannel"
]
},
{
"path": "/lib/bare/bundles/bareDebugLog.js",
"keys": [
"bareDebugLog"
]
},
{
"path": "/lib/bare/bundles/bareDelta.js",
"keys": [
"bareDelta"
]
},
{
"path": "/lib/bare/bundles/bareDaemon.js",
"keys": [
"bareDaemon"
]
},
{
"path": "/lib/bare/bundles/bareDiagnosticsChannel.js",
"keys": [
@@ -224,15 +224,15 @@
]
},
{
"path": "/lib/bare/bundles/bareExif.js",
"path": "/lib/bare/bundles/bareCov.js",
"keys": [
"bareExif"
"bareCov"
]
},
{
"path": "/lib/bare/bundles/bareFfmpeg.js",
"path": "/lib/bare/bundles/bareExif.js",
"keys": [
"bareFfmpeg"
"bareExif"
]
},
{
@@ -242,9 +242,15 @@
]
},
{
"path": "/lib/bare/bundles/bareCov.js",
"path": "/lib/bare/bundles/bareFfmpeg.js",
"keys": [
"bareCov"
"bareFfmpeg"
]
},
{
"path": "/lib/bare/bundles/bareFormData.js",
"keys": [
"bareFormData"
]
},
{
@@ -259,42 +265,12 @@
"bareFormat"
]
},
{
"path": "/lib/bare/bundles/bareFormData.js",
"keys": [
"bareFormData"
]
},
{
"path": "/lib/bare/bundles/bareFileLogger.js",
"keys": [
"bareFileLogger"
]
},
{
"path": "/lib/bare/bundles/bareFs.js",
"keys": [
"bareFs"
]
},
{
"path": "/lib/bare/bundles/bareGif.js",
"keys": [
"bareGif"
]
},
{
"path": "/lib/bare/bundles/bareHrtime.js",
"keys": [
"bareHrtime"
]
},
{
"path": "/lib/bare/bundles/bareGtk.js",
"keys": [
"bareGtk"
]
},
{
"path": "/lib/bare/bundles/bareHeif.js",
"keys": [
@@ -302,15 +278,33 @@
]
},
{
"path": "/lib/bare/bundles/bareHttpParser.js",
"path": "/lib/bare/bundles/bareFileLogger.js",
"keys": [
"bareHttpParser"
"bareFileLogger"
]
},
{
"path": "/lib/bare/bundles/bareImageResample.js",
"path": "/lib/bare/bundles/bareGtk.js",
"keys": [
"bareImageResample"
"bareGtk"
]
},
{
"path": "/lib/bare/bundles/bareHrtime.js",
"keys": [
"bareHrtime"
]
},
{
"path": "/lib/bare/bundles/bareFs.js",
"keys": [
"bareFs"
]
},
{
"path": "/lib/bare/bundles/bareHttpParser.js",
"keys": [
"bareHttpParser"
]
},
{
@@ -319,24 +313,30 @@
"bareIco"
]
},
{
"path": "/lib/bare/bundles/bareImageResample.js",
"keys": [
"bareImageResample"
]
},
{
"path": "/lib/bare/bundles/bareHttp1.js",
"keys": [
"bareHttp1"
]
},
{
"path": "/lib/bare/bundles/bareInspect.js",
"keys": [
"bareInspect"
]
},
{
"path": "/lib/bare/bundles/bareHttps.js",
"keys": [
"bareHttps"
]
},
{
"path": "/lib/bare/bundles/bareInspect.js",
"keys": [
"bareInspect"
]
},
{
"path": "/lib/bare/bundles/bareJpeg.js",
"keys": [
@@ -361,12 +361,6 @@
"bareLief"
]
},
{
"path": "/lib/bare/bundles/bareLogger.js",
"keys": [
"bareLogger"
]
},
{
"path": "/lib/bare/bundles/bareInspector.js",
"keys": [
@@ -374,9 +368,9 @@
]
},
{
"path": "/lib/bare/bundles/bareLink.js",
"path": "/lib/bare/bundles/bareLogger.js",
"keys": [
"bareLink"
"bareLogger"
]
},
{
@@ -386,15 +380,9 @@
]
},
{
"path": "/lib/bare/bundles/bareModule.js",
"path": "/lib/bare/bundles/bareLink.js",
"keys": [
"bareModule"
]
},
{
"path": "/lib/bare/bundles/bareModuleResolve.js",
"keys": [
"bareModuleResolve"
"bareLink"
]
},
{
@@ -404,9 +392,15 @@
]
},
{
"path": "/lib/bare/bundles/bareNdk.js",
"path": "/lib/bare/bundles/bareModuleResolve.js",
"keys": [
"bareNdk"
"bareModuleResolve"
]
},
{
"path": "/lib/bare/bundles/bareModule.js",
"keys": [
"bareModule"
]
},
{
@@ -416,21 +410,9 @@
]
},
{
"path": "/lib/bare/bundles/bareNative.js",
"path": "/lib/bare/bundles/bareNdk.js",
"keys": [
"bareNative"
]
},
{
"path": "/lib/bare/bundles/bareMedia.js",
"keys": [
"bareMedia"
]
},
{
"path": "/lib/bare/bundles/bareNet.js",
"keys": [
"bareNet"
"bareNdk"
]
},
{
@@ -439,42 +421,72 @@
"bareNodeFetch"
]
},
{
"path": "/lib/bare/bundles/bareOs.js",
"keys": [
"bareOs"
]
},
{
"path": "/lib/bare/bundles/bareOpen.js",
"keys": [
"bareOpen"
]
},
{
"path": "/lib/bare/bundles/bareNet.js",
"keys": [
"bareNet"
]
},
{
"path": "/lib/bare/bundles/bareMedia.js",
"keys": [
"bareMedia"
]
},
{
"path": "/lib/bare/bundles/bareNative.js",
"keys": [
"bareNative"
]
},
{
"path": "/lib/bare/bundles/bareOs.js",
"keys": [
"bareOs"
]
},
{
"path": "/lib/bare/bundles/barePack.js",
"keys": [
"barePack"
]
},
{
"path": "/lib/bare/bundles/barePackDrive.js",
"keys": [
"barePackDrive"
]
},
{
"path": "/lib/bare/bundles/barePerformance.js",
"keys": [
"barePerformance"
]
},
{
"path": "/lib/bare/bundles/bareNodeRuntime.js",
"keys": [
"bareNodeRuntime"
]
},
{
"path": "/lib/bare/bundles/barePackDrive.js",
"keys": [
"barePackDrive"
]
},
{
"path": "/lib/bare/bundles/barePng.js",
"keys": [
"barePng"
]
},
{
"path": "/lib/bare/bundles/bareDev.js",
"keys": [
"bareDev"
]
},
{
"path": "/lib/bare/bundles/barePipe.js",
"keys": [
@@ -487,30 +499,6 @@
"barePrebuild"
]
},
{
"path": "/lib/bare/bundles/bareNodeRuntime.js",
"keys": [
"bareNodeRuntime"
]
},
{
"path": "/lib/bare/bundles/bareProcess.js",
"keys": [
"bareProcess"
]
},
{
"path": "/lib/bare/bundles/bareQuerystring.js",
"keys": [
"bareQuerystring"
]
},
{
"path": "/lib/bare/bundles/bareDev.js",
"keys": [
"bareDev"
]
},
{
"path": "/lib/bare/bundles/barePunycode.js",
"keys": [
@@ -529,12 +517,6 @@
"bareQueueMicrotask"
]
},
{
"path": "/lib/bare/bundles/bareRuntime.js",
"keys": [
"bareRuntime"
]
},
{
"path": "/lib/bare/bundles/barePromClient.js",
"keys": [
@@ -542,15 +524,21 @@
]
},
{
"path": "/lib/bare/bundles/bareRpc.js",
"path": "/lib/bare/bundles/bareQuerystring.js",
"keys": [
"bareRpc"
"bareQuerystring"
]
},
{
"path": "/lib/bare/bundles/bareRepl.js",
"path": "/lib/bare/bundles/bareRuntime.js",
"keys": [
"bareRepl"
"bareRuntime"
]
},
{
"path": "/lib/bare/bundles/bareProcess.js",
"keys": [
"bareProcess"
]
},
{
@@ -560,15 +548,15 @@
]
},
{
"path": "/lib/bare/bundles/bareSemver.js",
"path": "/lib/bare/bundles/bareRpc.js",
"keys": [
"bareSemver"
"bareRpc"
]
},
{
"path": "/lib/bare/bundles/bareRun.js",
"path": "/lib/bare/bundles/bareSemver.js",
"keys": [
"bareRun"
"bareSemver"
]
},
{
@@ -578,9 +566,9 @@
]
},
{
"path": "/lib/bare/bundles/bareStringDecoder.js",
"path": "/lib/bare/bundles/bareRun.js",
"keys": [
"bareStringDecoder"
"bareRun"
]
},
{
@@ -590,9 +578,15 @@
]
},
{
"path": "/lib/bare/bundles/bareStream.js",
"path": "/lib/bare/bundles/bareStringDecoder.js",
"keys": [
"bareStream"
"bareStringDecoder"
]
},
{
"path": "/lib/bare/bundles/bareRepl.js",
"keys": [
"bareRepl"
]
},
{
@@ -602,15 +596,15 @@
]
},
{
"path": "/lib/bare/bundles/bareStdio.js",
"path": "/lib/bare/bundles/bareStream.js",
"keys": [
"bareStdio"
"bareStream"
]
},
{
"path": "/lib/bare/bundles/bareStructuredClone.js",
"path": "/lib/bare/bundles/bareStdio.js",
"keys": [
"bareStructuredClone"
"bareStdio"
]
},
{
@@ -620,9 +614,9 @@
]
},
{
"path": "/lib/bare/bundles/bareTap.js",
"path": "/lib/bare/bundles/bareStructuredClone.js",
"keys": [
"bareTap"
"bareStructuredClone"
]
},
{
@@ -631,6 +625,12 @@
"bareSystemLogger"
]
},
{
"path": "/lib/bare/bundles/bareTap.js",
"keys": [
"bareTap"
]
},
{
"path": "/lib/bare/bundles/bareSubprocess.js",
"keys": [
@@ -643,30 +643,30 @@
"bareTiff"
]
},
{
"path": "/lib/bare/bundles/bareTimers.js",
"keys": [
"bareTimers"
]
},
{
"path": "/lib/bare/bundles/bareThread.js",
"keys": [
"bareThread"
]
},
{
"path": "/lib/bare/bundles/bareTpl.js",
"keys": [
"bareTpl"
]
},
{
"path": "/lib/bare/bundles/bareTcp.js",
"keys": [
"bareTcp"
]
},
{
"path": "/lib/bare/bundles/bareTimers.js",
"keys": [
"bareTimers"
]
},
{
"path": "/lib/bare/bundles/bareTpl.js",
"keys": [
"bareTpl"
]
},
{
"path": "/lib/bare/bundles/bareType.js",
"keys": [
@@ -685,18 +685,18 @@
"bareUiKit"
]
},
{
"path": "/lib/bare/bundles/bareTty.js",
"keys": [
"bareTty"
]
},
{
"path": "/lib/bare/bundles/bareUnpack.js",
"keys": [
"bareUnpack"
]
},
{
"path": "/lib/bare/bundles/bareTty.js",
"keys": [
"bareTty"
]
},
{
"path": "/lib/bare/bundles/bareV8.js",
"keys": [
@@ -709,18 +709,18 @@
"bareVm"
]
},
{
"path": "/lib/bare/bundles/bareWalkHandles.js",
"keys": [
"bareWalkHandles"
]
},
{
"path": "/lib/bare/bundles/bareUnionBundle.js",
"keys": [
"bareUnionBundle"
]
},
{
"path": "/lib/bare/bundles/bareWalkHandles.js",
"keys": [
"bareWalkHandles"
]
},
{
"path": "/lib/bare/bundles/bareWebKit.js",
"keys": [
@@ -728,9 +728,9 @@
]
},
{
"path": "/lib/bare/bundles/bareWebp.js",
"path": "/lib/bare/bundles/bareWebKitGtk.js",
"keys": [
"bareWebp"
"bareWebKitGtk"
]
},
{
@@ -739,18 +739,18 @@
"bareV8ToIstanbul"
]
},
{
"path": "/lib/bare/bundles/bareWebKitGtk.js",
"keys": [
"bareWebKitGtk"
]
},
{
"path": "/lib/bare/bundles/bareUtils.js",
"keys": [
"bareUtils"
]
},
{
"path": "/lib/bare/bundles/bareWebp.js",
"keys": [
"bareWebp"
]
},
{
"path": "/lib/bare/bundles/bareWhich.js",
"keys": [
@@ -769,18 +769,18 @@
"bareXdiff"
]
},
{
"path": "/lib/bare/bundles/bareZmq.js",
"keys": [
"bareZmq"
]
},
{
"path": "/lib/bare/bundles/bareZlib.js",
"keys": [
"bareZlib"
]
},
{
"path": "/lib/bare/bundles/bareZmq.js",
"keys": [
"bareZmq"
]
},
{
"path": "/lib/bare/bundles/bareWs.js",
"keys": [
@@ -1595,8 +1595,8 @@
],
"bundleProvenance": {
"schemaVersion": 1,
"generatedAt": "2026-04-06T03:01:17.869Z",
"gitCommit": "8f61d0bea8efc674a1063df176d7383a09f85b46",
"generatedAt": "2026-04-06T03:12:51.812Z",
"gitCommit": "071edccfb3f074d3ee00c901d5df2a514063815d",
"nodeVersion": "v22.22.0",
"bundleTier": "all",
"normativeManifest": "packages/bare-os-booter/lib/bare-module-manifest.json",
+1 -1
View File
@@ -1,6 +1,6 @@
{
"schema": 1,
"atMs": 1775444477009,
"atMs": 1775445170834,
"commands": [
"arch",
"awk",
+2
View File
@@ -19,3 +19,5 @@ Staged paths: **`/lib/init/init-main.js`**, **`/lib/init/fragments/*`**, and bun
| Interactive loop | readline / REPL after boot stages | `init-main.js` |
After editing any fragment or `init-main.js`, run `node scripts/bundle-kernel-init.mjs` and sync the seeder tree (`rsync -a --delete kernel/ packages/bare-os-seeder/kernel/`). CI: `verify-init-bundle-recipe.mjs`, `verify-kernel-seeder-parity.mjs`, `verify-runtime-no-incomplete-markers.mjs`.
**Boot footprint:** keep heavy optional paths (for example deep selftest or auxiliary REPL wiring) behind **boot policy** / env gates inside existing fragments rather than adding new concatenation slots unless `verify-init-bundle-recipe.mjs` is updated—this preserves a single `/boot/init.js` artifact while allowing cold-boot skipping of gated sections.
File diff suppressed because one or more lines are too long
+2 -1
View File
@@ -7,7 +7,7 @@ Authoritative **version alignment** with protocol and telemetry schema numbers l
- **`baretop` snapshot**: **`ctx.bareOsReadBareTopSnapshot({ lite: true })`** returns a reduced **`files`** map (see **`BARE_TOP_SNAPSHOT_LITE_ENTRIES`** in **`packages/bare-os-coreutils/lib/baretop-snapshot.js`**). Full batch includes **`securityPosture`** → **`/proc/bare_os/security_posture.json`**. **`metrics_live`** JSON uses **`schema: 4`** with embedded **`processTable`** when present; kernel counters include optional **`vfs.readfile.samples`** ( **`BARE_OS_VFS_READ_METRICS`** ), **`initd.unit_failed_final`**, and **`shell.pipeline_last_stages`** gauge from the shell.
- **`/proc/bare_os/net_summary.json`**: **`schemaVersion` 2** adds scalar **`replicationQueueDepth`**, firewall session totals, optional **`BARE_OS_BSD_SOCKET_BRIDGE_STATS_JSON`** merge into **`bsdSocketGuestBridge`**; **`peer_firewall_stats`** field alignment documented in **`bare-os-protocol`** channel handler.
- **Host filesystem**: first-party booter and seeder sources use **`import … from '#host-fs'`** / **`#host-path`** (and seeder **`#host-fs-promises`**) so Bare resolves **`bare-fs`** / **`bare-path`** and Node resolves the built-in **`fs`** / **`path`** modules via the default **`imports`** condition. **`bare-fs`** is a direct **`dependencies`** entry of **`bare-os-booter`**. CI: **`scripts/verify-pear-no-static-node-import.mjs`** rejects bare **`fs`** / **`path`** specifiers.
- **POSIX / proc**: **`/proc/bare_os/syscalls.json`** schema **11** with **`susv4Refs`** on **`opsDetail`**, **`posixXsh` schema 3**, **`socketMsgSurface` schema 5** (`logicalScmRightsOnSend`); includes **`posix_fadvise`** simulated, **`fdModel.processTableSchema` 8**, **`errnoHints`**; JSON text **cached** until **`vfs.bareOsClearWarmReadCaches`**. **`/proc/bare_os/process_table.json`** schema **8**; **`/proc/bare_os/protomux.json`** wire text schema **2**; **`/dev/shm`** in-memory named segments. **`/proc/bare_os/security_posture.json`** — **`blindRelayPosture`**, **`blindPeeringOperatorSketch`** env gate pointers; **`vaultCryptoPrimitives`**, **`bareCryptoReportedVersion`**, **`peerAdmission`**. **`/proc/bare_os/boot_budget_summary.json`** mirrors kernel **`/run/bare-os/boot-budget-summary.json`**. **`/proc/bare_os_features`**: **`protomuxAppChannel`**, optional **`protomuxCapChannel`**, **`pearIpcConservativeAdvertisement`**. Protocol export **`BARE_OS_POSIX_PROFILE_*`**.
- **POSIX / proc**: **`/proc/bare_os/syscalls.json`** schema **11** with **`susv4Refs`** on **`opsDetail`**, **`posixXsh` schema 3**, **`socketMsgSurface` schema 6** (**`iovecSemantics`**, **`recvmsg.susv4Refs`**); includes **`posix_fadvise`** simulated, **`fdModel.processTableSchema` 9**, **`errnoHints`**; JSON text **cached** until **`vfs.bareOsClearWarmReadCaches`**. **`/proc/bare_os/process_table.json`** schema **9** (**`nice`**, **`accountingSource`**); logical **`process_maps.json`** / **`process_threads.json`**; **`/proc/bare_os/protomux.json`** wire text schema **2**; **`/dev/shm`** in-memory named segments. **`/proc/bare_os/security_posture.json`** — **`blindRelayPosture`**, **`blindPeeringOperatorSketch`**, **`replicationOperatorSketchCrossRef`**; **`vaultCryptoPrimitives`**, **`bareCryptoReportedVersion`**, **`peerAdmission`**. **`/proc/bare_os/boot_budget_summary.json`** mirrors kernel **`/run/bare-os/boot-budget-summary.json`** and may merge **`replicationLiveCoalesced`**. **`/proc/bare_os_features`**: **`protomuxAppChannel`**, optional **`protomuxCapChannel`**, **`pearIpcConservativeAdvertisement`**. Protocol export **`BARE_OS_POSIX_PROFILE_*`**.
- **Protomux cap channel**: inbound **`bare-os-cap-v1`** messages are accepted only up to **65536** bytes (**`BARE_OS_PROTOMUX_CAP_CHANNEL_MESSAGE_MAX_BYTES`** in **`lib/swarm-disk.js`**); larger payloads log **`protomux_cap_payload_oversized`** and do not increment **`protomuxCapChannelRxTotal`**.
- **Wasm (sync imports)**: optional **`BARE_OS_WASM_KERNEL_POSIX_PROFILE_PEEK`** adds **`env.bare_os_posix_profile_peek`** (declared **`BARE_OS_POSIX_PROFILE_VERSION`** string, bounded).
- **Blind-relay / pairing / geo proc** (default): **`bareOsProcBlindPeerRelayHintsMinimal`** returns **schema 1** with **`operatorRedacted: true`**. The legacy export **`bareOsProcBlindPeerRelayHintsStub`** was removed; use **`bareOsProcBlindPeerRelayHintsMinimal`** only.
@@ -22,6 +22,7 @@ Authoritative **version alignment** with protocol and telemetry schema numbers l
| Version | Booter (workspace) | Notes |
| ------- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| 1.54.0 | 0.1.0 | **`ctx.bareOsRenice`** stores **logical nice** on **`process_table.json`**. **`disk.os` `replication_operator_sketch` schema 8** — **`hyperdhtAddressSketch`**, **`pkgIndexSurface`/`pkg_index_get` schema 2**, **`corestoreSnapshotUxHint` schema 4** (**`recommendedWorkflow`**). **`protomuxOperatorSketch` schema 4** (**`multiplexPeerCountEcho`**). **`security_posture` schema 7** (**`replicationOperatorSketchCrossRef`**). **`pear_stage_pointer` schema 2** (**pear-runtime-updater** cross-link). **`socketMsgSurface` schema 6**. Shell **`wait`** exit status from job **`lastExitCode`**. Swarm **`BARE_OS_SWARM_ATTEMPT_BURST_PER_SEC`**. Expanded **`bareOsGetconfSysconf`** (**`_SC_MONOTONIC_CLOCK_RES`**, trace/timer caps). Vault save audit **`pathcapTrustedKeyCount`**. Optional **`BARE_OS_HOLEPUNCH_DRIFT_WRITE_REPORT`**. |
| 1.53.0 | 0.1.0 | **`disk.os` `bare_os.replication_operator_sketch`** JSON **schema 7****`corestoreSnapshotUxHint`** (env merge counts), **`pkgIndexSurface`**, prior operator fields. **`ctx.bareOsHrpcRequest`** routes **`bare_os.pkg_index_get`**; **`BARE_OS_HRPC_ROUTE_TABLE_SCHEMA_VERSION` `3`**. **`/proc/bare_os/syscalls.json`** schema **11** (**`susv4Refs`**); **`posixXsh` schema 3**. Optional **Protomux cap channel** (**`BARE_OS_PROTOMUX_CAP_CHANNEL`**, **`bare-os-cap-v1`**). **`ctx.bareOsVerifyPathCapabilityEnvelopeTrusted`** + **`BARE_OS_PATH_CAPABILITY_TRUSTED_PUBKEYS_HEX`**. **`/proc/bare_os/boot_budget_summary.json`**. Warm-cache adaptive **jitter** (**`BARE_OS_VFS_WARM_REPL_ADAPTIVE_JITTER_PCT`**). Shell **`BARE_OS_SHELL_POSIX_UNSET_ONLY_DEFAULT`**. Wasm **`env.bare_os_posix_bridge_peek`**. **`protomux_extensions.json` `schemaVersion` 4** (**`guestContractVersion`**, **`channelLifecycle`**). |
| 1.52.0 | 0.1.0 | **`disk.os` `searchLocal`** — optional **`/etc/bare-os/path-manifest.json`** acceleration (**`BARE_OS_DISK_OS_PATH_MANIFEST`**, **`BARE_OS_DISK_OS_SEARCH_MANIFEST_ONLY`**, **`BARE_OS_DISK_OS_MANIFEST_CACHE_MS`**) + **`bare_os.disk_os_hints`** JSON **schema 3** (**`pathSearchLocal`** metrics). Stock **`ctx.bareOsHrpcRequest`** route **`bare_os.search_local`** (**`payload.query`**, max 512 chars). **`BARE_OS_HRPC_ROUTE_TABLE_SCHEMA_VERSION` `2`**. Optional **path capabilities**: **`ctx.bareOsVerifyPathCapabilityEnvelope`**, VFS gate **`BARE_OS_PATH_CAPABILITY_ENFORCE_READ`** + **`BARE_OS_PATH_CAPABILITY_PREFIX`**, **`/bin/pathcap-verify`**, example **`kernel/etc/bare-os/path-capability.envelope.example.json`**. |
| 1.51.1 | 0.1.0 | **`disk.os` `bare_os.replication_snapshot`** JSON **schema 2** — merges seed snapshot hints / manifest slice / chain + **`BARE_OS_CORESTORE_SNAPSHOT_JSON`**. Shell **`BARE_OS_SHELL_NOUNSET`** / **`set -u`** / **`set -o nounset`**. Wasm **`BARE_OS_WASM_KERNEL_HOSTNAME_IMPORT`** → **`env.bare_os_hostname_peek`**. **`ctx.bareOsTrySpawnHostSubprocess`** merges default **`timeoutMs`** from **`BARE_OS_BARE_SUBPROCESS_TIMEOUT_MS`**. **`/proc/bare_os_features`**: **`protomuxAppChannel`**. **`/proc/bare_os/security_posture.json`** schema **5** (**`blindPeeringOperatorSketch`**). Swarm disk: **`BARE_OS_MBR_READ_TIMEOUT_MS`**, **`BARE_OS_MBR_READ_TIMEOUT_ADAPTIVE`**. Kernel **`kernel-ext-resolution.json`** schema **3** + **`BARE_OS_KERNEL_EXT_RESOLUTION_JSON_ALWAYS`**. Seeder multisig logs via **`seedLog`**. |
+113 -28
View File
@@ -217,7 +217,11 @@ import {
} from './lib/bare-os-kernel-metrics.js'
import { bareOsSwarmLifecycleSnapshot } from './lib/bare-os-swarm-lifecycle.js'
import { bareOsReadHostProfile } from './lib/bare-os-host-profile.js'
import { bareOsProcessTableSnapshot } from './lib/bare-os-process-table.js'
import {
bareOsProcessTableSnapshot,
bareOsBuildLogicalMemoryMapsProc,
bareOsBuildProcessThreadsProc
} from './lib/bare-os-process-table.js'
import { buildBareOsProtomuxExtensionsProcJson } from './lib/bare-os-protomux-extensions-proc.js'
import { bareOsStatvfsFromHyperdrive } from './lib/bare-os-statvfs-from-drive.js'
import {
@@ -874,6 +878,8 @@ async function executeKernel(disk, store, swarm, initSource) {
const vfsMountRef = { getMounts: () => new Map() }
/** @type {Map<number, { signal: string, atMs: number }>} */
const bareOsVirtualSignalState = new Map()
/** Logical nice values (-20..19) for synthetic PIDs (surfaced on process_table.json). */
const bareOsLogicalNiceByPid = new Map()
const ipcMaxRaw = Number.parseInt(
shellEnv.BARE_OS_IPC_MAX_BYTES || '1048576',
10
@@ -1613,8 +1619,8 @@ async function executeKernel(disk, store, swarm, initSource) {
}
}
return `${JSON.stringify({
schema: 6,
note: 'Non-secret security posture snapshot; no vault or key material. Schema 6 adds blindRelayPosture key sample.',
schema: 7,
note: 'Non-secret security posture snapshot; no vault or key material. Schema 7 adds replicationOperatorSketchCrossRef; schema 6 blindRelayPosture key sample.',
bootPolicyMerged: bootPol,
bootPolicyStrict: strict,
sandboxScript:
@@ -1675,6 +1681,15 @@ async function executeKernel(disk, store, swarm, initSource) {
schema: 1,
note: 'Replication RPC may carry attestation blobs; guests verify only when operator policy enables pinned validators.'
},
replicationOperatorSketchCrossRef: {
schema: 1,
diskOsRpc: 'bare_os.replication_operator_sketch',
declaredSketchSchema: 8,
hyperdhtAddressEnv: 'BARE_OS_HYPERDHT_ADDRESS_JSON',
blindRelayStatsEnv: 'BARE_OS_BLIND_RELAY_STATS_JSON',
note:
'Guests read non-secret sketches via disk.os; JSON payloads stay env/host-local — never echoed in this proc.'
},
blindPeeringOperatorSketch: {
schema: 1,
blindPeerTopologyV3JsonEnv: 'BARE_OS_BLIND_PEER_TOPOLOGY_V3_JSON',
@@ -2733,7 +2748,8 @@ async function executeKernel(disk, store, swarm, initSource) {
liveCtxForTable && liveCtxForTable.bareOsLogicalSigaction
? liveCtxForTable.bareOsLogicalSigaction
: null,
env: shellEnv
env: shellEnv,
niceByPid: bareOsLogicalNiceByPid
})
const sysNow = repLive.systemCoreLength
const perNow = repLive.personalCoreLength
@@ -2994,7 +3010,8 @@ async function executeKernel(disk, store, swarm, initSource) {
liveCtx && liveCtx.bareOsLogicalSigaction
? liveCtx.bareOsLogicalSigaction
: null,
env: shellEnv
env: shellEnv,
niceByPid: bareOsLogicalNiceByPid
})
)}\n`
},
@@ -3013,7 +3030,8 @@ async function executeKernel(disk, store, swarm, initSource) {
liveCtx && liveCtx.bareOsLogicalSigaction
? liveCtx.bareOsLogicalSigaction
: null,
env: shellEnv
env: shellEnv,
niceByPid: bareOsLogicalNiceByPid
})
const byPid = (snap.processes || []).map((row) => ({
pid: row && typeof row === 'object' ? row.pid : undefined,
@@ -3034,20 +3052,50 @@ async function executeKernel(disk, store, swarm, initSource) {
})}\n`
},
procBareOsProcessThreadsText() {
return `${JSON.stringify({
schema: 1,
atMs: Date.now(),
note: 'Stub for future per-PID thread rows; baretop column when populated.',
byPid: []
})}\n`
const { shellJobs, ipcStats } = bareOsLiveShellJobsAndIpcStats()
const liveCtx = bareOsInteractiveCtxRef.ctx
const snap = bareOsProcessTableSnapshot({
sessionId: bareOsSessionId,
bootStartedMs,
signalState: bareOsVirtualSignalState,
shellJobs,
ipcStats,
logicalFdRows: bareOsCollectLogicalFdRows(),
initdReadiness: bareInitdReadinessSnapshot(),
sigactionHandlers:
liveCtx && liveCtx.bareOsLogicalSigaction
? liveCtx.bareOsLogicalSigaction
: null,
env: shellEnv,
niceByPid: bareOsLogicalNiceByPid
})
const bareLib =
liveCtx && liveCtx.bare && typeof liveCtx.bare === 'object'
? liveCtx.bare
: null
return `${JSON.stringify(
bareOsBuildProcessThreadsProc(snap, bareLib)
)}\n`
},
procBareOsProcessMapsText() {
return `${JSON.stringify({
schema: 1,
atMs: Date.now(),
note: 'Educational stub — not Linux /proc/pid/maps.',
regions: []
})}\n`
const { shellJobs, ipcStats } = bareOsLiveShellJobsAndIpcStats()
const liveCtx = bareOsInteractiveCtxRef.ctx
const snap = bareOsProcessTableSnapshot({
sessionId: bareOsSessionId,
bootStartedMs,
signalState: bareOsVirtualSignalState,
shellJobs,
ipcStats,
logicalFdRows: bareOsCollectLogicalFdRows(),
initdReadiness: bareInitdReadinessSnapshot(),
sigactionHandlers:
liveCtx && liveCtx.bareOsLogicalSigaction
? liveCtx.bareOsLogicalSigaction
: null,
env: shellEnv,
niceByPid: bareOsLogicalNiceByPid
})
return `${JSON.stringify(bareOsBuildLogicalMemoryMapsProc(snap))}\n`
},
procBareOsSyscallsText() {
if (bareOsSyscallsProcJsonCache == null) {
@@ -4496,7 +4544,8 @@ async function executeKernel(disk, store, swarm, initSource) {
logicalFdRows: bareOsCollectLogicalFdRows(),
initdReadiness: bareInitdReadinessSnapshot(),
sigactionHandlers: this.bareOsLogicalSigaction,
env: shellEnv
env: shellEnv,
niceByPid: bareOsLogicalNiceByPid
})
},
/**
@@ -4629,7 +4678,7 @@ async function executeKernel(disk, store, swarm, initSource) {
}
},
/**
* Logical nice adjustment for synthetic PIDs (stub: returns ENOSYS until scheduler hooks land).
* Logical nice adjustment for synthetic PIDs (stored on **`process_table.json`** rows; host scheduler is not affected).
* @param {number} pid
* @param {number} [delta]
*/
@@ -4642,12 +4691,17 @@ async function executeKernel(disk, store, swarm, initSource) {
if (!Number.isFinite(d)) {
throw new Error('bareOsRenice: invalid delta')
}
const clampNice = (n) =>
Math.max(-20, Math.min(19, Math.trunc(Number.isFinite(n) ? n : 0)))
const cur = clampNice(bareOsLogicalNiceByPid.get(p) ?? 0)
const next = clampNice(cur + d)
bareOsLogicalNiceByPid.set(p, next)
return {
ok: false,
errno: 'ENOSYS',
ok: true,
pid: p,
delta: d,
note: 'Logical renice is not applied; reserved for future kernel scheduling hints.',
nice: next,
previousNice: cur,
atMs: Date.now()
}
},
@@ -5154,6 +5208,16 @@ async function executeKernel(disk, store, swarm, initSource) {
if (n === '_SC_TTY_NAME_MAX') return '32'
if (n === '_SC_LOGIN_NAME_MAX') return '256'
if (n === '_SC_MONOTONIC_CLOCK') return '1'
if (n === '_SC_MONOTONIC_CLOCK_RES') {
return bootHrtimeNowNs ? '1' : '0'
}
if (n === '_SC_TRACE' || n === '_SC_TRACE_VERSION') return '-1'
if (n === '_SC_RAW_SOCKETS') return '-1'
if (n === '_SC_ADVISORY_INFO') return '0'
if (n === '_SC_BARRIERS') return '-1'
if (n === '_SC_SPIN_LOCKS') return '1'
if (n === '_SC_TIMER_MAX') return '32'
if (n === '_SC_DELAYTIMER_MAX') return '0'
if (n === '_SC_ATEXIT_MAX') return '32'
if (n === '_SC_LINE_MAX') return '2048'
if (n === '_SC_BC_BASE_MAX') return '99'
@@ -7132,7 +7196,7 @@ async function executeKernel(disk, store, swarm, initSource) {
flags: 0,
controllen: 0,
note:
'TCP bridge: single flat buffer; recv ancillary controllen 0 (socketMsgSurface schema 5).'
'TCP bridge: single flat buffer; recv ancillary controllen 0 (socketMsgSurface schema 6).'
}
}
return base
@@ -9577,7 +9641,7 @@ async function executeKernel(disk, store, swarm, initSource) {
? disk.swarmConnectionBudget
: null,
protomuxOperatorSketch: {
schema: 3,
schema: 4,
protomuxAppChannelRxTotal:
typeof disk.protomuxAppChannelRxTotal === 'number'
? disk.protomuxAppChannelRxTotal
@@ -9591,8 +9655,12 @@ async function executeKernel(disk, store, swarm, initSource) {
tuningFromEnv: bareOsProtomuxTuningFromEnv(shellEnv),
tuningEnvKey: 'BARE_OS_PROTOMUX_TUNING_JSON',
hyperswarmConstructorOptsEcho: bareOsHyperswarmOptsFromEnv(shellEnv),
multiplexPeerCountEcho:
disk.peers && typeof disk.peers.size === 'number'
? disk.peers.size
: null,
note:
'Schema 3: adds protomuxCapChannelRxTotal + BARE_OS_PROTOMUX_CAP_CHANNEL. Schema 2: BARE_OS_PROTOMUX_TUNING_JSON + Hyperswarm opt echo (advisory).'
'Schema 4: multiplexPeerCountEcho + protomuxWire correlation with swarm peers. Schema 3: protomuxCapChannelRxTotal + BARE_OS_PROTOMUX_CAP_CHANNEL.'
},
auditBatch: (entries) => {
try {
@@ -9619,8 +9687,25 @@ async function executeKernel(disk, store, swarm, initSource) {
await runKernelFromSource(b4a.toString(currentInit), ctx)
try {
const bb = await vfs.readFile('/run/bare-os/boot-budget-summary.json')
if (bb && bb.byteLength)
bootBudgetSummaryProcRef.text = b4a.toString(bb)
if (bb && bb.byteLength) {
let txt = b4a.toString(bb)
try {
const o = JSON.parse(txt)
if (o && typeof o === 'object') {
const peerRep = disk.peers?.size ?? 0
o.replicationLiveCoalesced = buildBareOsReplicationLiveSketch(
disk,
peerRep
)
if (typeof o.bootBudgetSchemaVersion !== 'number')
o.bootBudgetSchemaVersion = 2
txt = JSON.stringify(o) + '\n'
}
} catch {
/* keep raw kernel summary */
}
bootBudgetSummaryProcRef.text = txt
}
} catch {
/* optional */
}
@@ -2,4 +2,4 @@
* Semantic version of the booter `ctx` contract for custom kernels.
* Bump when adding/removing/renaming documented `ctx` fields or changing behavior.
*/
export const BARE_OS_CTX_API_VERSION = '1.53.0'
export const BARE_OS_CTX_API_VERSION = '1.54.0'
+13 -1
View File
@@ -1,6 +1,6 @@
/**
* Stable shapes for custom kernels and `/bin` utilities (best-effort; full `ctx` is assembled in `index.js`).
* Match `BARE_OS_CTX_API_VERSION` in `bare-os-ctx-api.js` (stock **1.53.0**).
* Match `BARE_OS_CTX_API_VERSION` in `bare-os-ctx-api.js` (stock **1.54.0**).
*/
export interface BareOsAbortOpts {
@@ -361,6 +361,18 @@ export interface BareOsKernelContext {
ignored?: boolean
atMs?: number
}
/** Logical nice (-20..19) for synthetic PIDs; surfaced on `process_table.json`. */
bareOsRenice?(
pid: number,
delta?: number
): {
ok: boolean
pid: number
delta: number
nice: number
previousNice: number
atMs: number
}
/** FD → logical VFS/IPC target; see `/proc/bare_os/syscalls.json` fdModel. */
bareOsLogicalFds?: Record<string, string>
/** `fcntl` F_SETFL bits (O_APPEND | O_NONBLOCK) per decimal fd key. */
@@ -422,8 +422,11 @@ export function createBareOsDiskOsBridge(opts) {
const peerPrioritySketch = parseEnvJson(
'BARE_OS_REPLICATION_PEER_PRIORITY_JSON'
)
const hyperdhtAddressSketch = parseEnvJson(
'BARE_OS_HYPERDHT_ADDRESS_JSON'
)
return JSON.stringify({
schema: 7,
schema: 8,
ok: true,
seedReplicationStatus:
sr && typeof sr === 'object' ? sr : null,
@@ -439,14 +442,16 @@ export function createBareOsDiskOsBridge(opts) {
? opts.protomuxOperatorSketch
: null,
pkgIndexSurface: {
schema: 1,
schema: 2,
diskOsRpc: 'bare_os.pkg_index_get',
hrpcRoute: 'bare_os.pkg_index_get',
defaultManifestPath: '/etc/bare-os/pkg-index.json',
envManifestPath: 'BARE_OS_PKG_INDEX_PATH',
listingKeyCap: 512,
note:
'Hyperbee-backed indexes replicate separately; this JSON is a static drive manifest for operators.'
'Schema 2: listingKeyCap + manifest schema echo. Hyperbee-backed indexes replicate separately; drive JSON is a static manifest for operators.'
},
hyperdhtAddressSketch,
corestoreSnapshotUxHint: bareOsCorestoreSnapshotOperatorHint(
opts.corestore ?? null
),
@@ -472,7 +477,7 @@ export function createBareOsDiskOsBridge(opts) {
corestoreOperatorSketch: corestoreSketch,
peerPrioritySketch,
note:
'Schema 7: adds corestoreSnapshotUxHint (BARE_OS_CORESTORE_SNAPSHOT_JSON vs BARE_OS_CORESTORE_STATS_JSON merge counts; advisory). Schema 6: pkgIndexSurface. Schema 5: corestoreOperatorSketch from BARE_OS_CORESTORE_STATS_JSON.'
'Schema 8: hyperdhtAddressSketch from BARE_OS_HYPERDHT_ADDRESS_JSON (non-secret); pkgIndexSurface schema 2. Schema 7: corestoreSnapshotUxHint advisory counts. Schema 6: pkgIndexSurface. Schema 5: corestoreOperatorSketch from BARE_OS_CORESTORE_STATS_JSON.'
})
}
@@ -705,20 +710,26 @@ export function createBareOsDiskOsBridge(opts) {
typeof j.packages === 'object'
? /** @type {Record<string, unknown>} */ (j.packages)
: {}
const manifestSchema =
j && typeof j === 'object' && typeof j.schema === 'number'
? j.schema
: 1
if (!want) {
return JSON.stringify({
schema: 1,
schema: 2,
ok: true,
path: rel,
manifestSchema,
keys: Object.keys(pkgs).slice(0, 512)
})
}
const ent =
Object.prototype.hasOwnProperty.call(pkgs, want) ? pkgs[want] : null
return JSON.stringify({
schema: 1,
schema: 2,
ok: ent != null,
path: rel,
manifestSchema,
key: want,
entry: ent
})
@@ -22,9 +22,13 @@ export function buildBareOsBareModuleCryptoStagingProcJson(id, env) {
switch (id) {
case 'pear_stage_pointer':
return {
schema: 1,
schema: 2,
pointer: parseJsonEnv('BARE_OS_PEAR_STAGE_POINTER_JSON'),
note: 'pear-stage metadata pointer (non-secret).',
pearRuntimeUpdaterPackage: 'pear-runtime-updater',
updaterStateProc: 'pear_updater_state',
updaterStateEnv: 'BARE_OS_PEAR_UPDATER_STATE_JSON',
note:
'Schema 2: cross-link pear-runtime-updater state env for co-versioning with stage pointer (non-secret).',
atMs: now
}
case 'pear_updater_state':
@@ -44,9 +44,126 @@ function subprocessBridgeMetaFromEnv(env) {
* logicalFdRows?: Array<{ fd: number, target: string }>,
* initdReadiness?: { units?: Array<{ name: string, phase: string, startedAtMs: number, error?: string }>, schema?: number } | null,
* sigactionHandlers?: Record<string, string> | null,
* env?: Record<string, string | undefined> | null
* env?: Record<string, string | undefined> | null,
* niceByPid?: Map<number, number> | null
* }} opts
*/
function bareOsClampNice(n) {
if (!Number.isFinite(n)) return 0
return Math.max(-20, Math.min(19, Math.trunc(n)))
}
/**
* @param {number} pid
* @param {Map<number, number> | null | undefined} niceByPid
*/
function niceForPid(pid, niceByPid) {
if (!(niceByPid instanceof Map)) return 0
const v = niceByPid.get(pid)
return bareOsClampNice(typeof v === 'number' ? v : 0)
}
/**
* Logical `/proc/bare_os/process_maps.json` from a process table snapshot (not host VMAs).
* @param {ReturnType<typeof bareOsProcessTableSnapshot>} snap
*/
export function bareOsBuildLogicalMemoryMapsProc(snap) {
const processes = Array.isArray(snap.processes) ? snap.processes : []
/** @type {Record<string, unknown>[]} */
const regions = []
for (const p of processes) {
const pid = p && typeof p.pid === 'number' ? p.pid : NaN
if (!Number.isFinite(pid)) continue
const base = 0x40000000 + (pid | 0) * 0x00100000
const toHex = (x) => '0x' + (x >>> 0).toString(16)
regions.push({
pid,
start: toHex(base),
end: toHex(base + 0x80000),
perms: 'r--p',
kind: 'guest-text',
pathname: '/boot/init.js (logical guest image)'
})
regions.push({
pid,
start: toHex(base + 0x100000),
end: toHex(base + 0x300000),
perms: 'rw-p',
kind: 'guest-data',
pathname: '(anonymous logical)'
})
}
return {
schema: 2,
model: 'bare-os-logical-v1',
processTableSchemaRef:
typeof snap.schemaVersion === 'number'
? snap.schemaVersion
: typeof snap.schema === 'number'
? snap.schema
: null,
atMs: Date.now(),
note: 'Logical memory regions per synthetic PID for dashboards; not Linux /proc/pid/maps and not host VMAs.',
regions
}
}
/**
* @param {ReturnType<typeof bareOsProcessTableSnapshot>} snap
* @param {unknown} bareLib ctx.bare when available
*/
export function bareOsBuildProcessThreadsProc(snap, bareLib) {
const processes = Array.isArray(snap.processes) ? snap.processes : []
/** @type {Record<string, unknown>[]} */
const byPid = []
let bareThreadPresent = false
try {
const bt =
bareLib &&
typeof bareLib === 'object' &&
/** @type {{ bareThread?: unknown }} */ (bareLib).bareThread
bareThreadPresent = !!(bt && typeof bt === 'object')
} catch {
bareThreadPresent = false
}
for (const p of processes) {
const pid = p && typeof p.pid === 'number' ? p.pid : NaN
if (!Number.isFinite(pid)) continue
/** @type {Record<string, unknown>[]} */
const threads = [
{
tid: pid,
name: 'main',
state: String((p && p.state) || 'unknown'),
accountingSource: 'logical-main'
}
]
if (bareThreadPresent && pid === 3) {
threads.push({
tid: pid + 1_000_000,
name: 'bare-runtime',
state: 'attached',
accountingSource: 'ctx.bare.bareThread'
})
}
byPid.push({ pid, threads })
}
return {
schema: 2,
model: 'bare-os-logical-v1',
processTableSchemaRef:
typeof snap.schemaVersion === 'number'
? snap.schemaVersion
: typeof snap.schema === 'number'
? snap.schema
: null,
atMs: Date.now(),
note: 'One logical main thread per synthetic PID; optional bare-runtime row on PID 3 when ctx.bare exposes bareThread.',
bareThreadModulePresent: bareThreadPresent,
byPid
}
}
export function bareOsProcessTableSnapshot(opts = {}) {
const sid = String(opts.sessionId || '').trim().slice(0, 128)
const boot = typeof opts.bootStartedMs === 'number' ? opts.bootStartedMs : 0
@@ -57,7 +174,15 @@ export function bareOsProcessTableSnapshot(opts = {}) {
for (const [pid, v] of sigState.entries()) {
virtualSignalDeliveries.push({ pid, signal: v.signal, atMs: v.atMs })
}
const v8m = () => ({
const accountingOn =
opts.env &&
(opts.env.BARE_OS_PROCESS_ACCOUNTING === '1' ||
opts.env.BARE_OS_PROCESS_ACCOUNTING === 'true')
const accountingSource = accountingOn
? 'guest-accounting-env'
: 'synthetic-default'
const niceByPid = opts.niceByPid
const v8m = (pid) => ({
threads: 1,
cpuMsTotal: 0,
cpuMsWindow: 0,
@@ -66,7 +191,9 @@ export function bareOsProcessTableSnapshot(opts = {}) {
syscallsDelta: 0,
memRssBytes: null,
wchan: '',
ioPrio: null
ioPrio: null,
accountingSource,
nice: niceForPid(pid, niceByPid)
})
const mk = (pid, ppid, name, startedAtMs, pgid, sessionId) => {
const sig = sigState.get(pid)
@@ -82,7 +209,7 @@ export function bareOsProcessTableSnapshot(opts = {}) {
startedAtMs,
lastSignal: sig ? sig.signal : undefined,
lastSignalAtMs: sig ? sig.atMs : undefined,
...v8m()
...v8m(pid)
}
}
const jobs = Array.isArray(opts.shellJobs) ? opts.shellJobs : []
@@ -104,7 +231,7 @@ export function bareOsProcessTableSnapshot(opts = {}) {
role: 'shell_job',
label: typeof j.label === 'string' ? j.label.slice(0, 256) : undefined,
stopped: !!j.stopped,
...v8m()
...v8m(pid)
}
})
const zombieJobs = jobs.filter((j) => j && j.done === true && typeof j.id === 'number')
@@ -126,7 +253,7 @@ export function bareOsProcessTableSnapshot(opts = {}) {
label: typeof j.label === 'string' ? j.label.slice(0, 256) : undefined,
cwd: '/',
fds: [],
...v8m()
...v8m(pid)
}
})
const stdioTable = [
@@ -192,7 +319,7 @@ export function bareOsProcessTableSnapshot(opts = {}) {
cwd: '/',
fds: [],
fdTable: [],
...v8m(),
...v8m(pid),
...(replicationHint ? { replicationHint } : {})
})
}
@@ -214,7 +341,6 @@ export function bareOsProcessTableSnapshot(opts = {}) {
cwd: typeof p.cwd === 'string' ? p.cwd : '/',
fds: Array.isArray(p.fds) ? p.fds : [0, 1, 2],
fdTable: [...stdioTable],
...v8m(),
threads: p.threads ?? 1
})),
...zombieProcs
@@ -233,9 +359,9 @@ export function bareOsProcessTableSnapshot(opts = {}) {
}))
return {
schema: 8,
schemaVersion: 8,
note: 'Synthetic rows; Bare OS guests do not expose host OS processes. v8 adds optional accounting fields (threads, cpuMs*, read/writeBytes, syscallsDelta, memRssBytes, wchan, ioPrio), replicationHint on failed net-related initd units, and stub counters for baretop dashboards. v7 fields retained.',
schema: 9,
schemaVersion: 9,
note: 'Synthetic rows; Bare OS guests do not expose host OS processes. v9 adds per-row nice (-20..19) via ctx.bareOsRenice, accountingSource on accounting fields, and companions process_maps.json / process_threads.json (logical models). v8 optional accounting + initd replicationHint retained.',
signalModel: {
schema: 1,
note: 'Virtual deliveries via ctx.bareOsSendSignal (not full sigaction/sigprocmask).',
@@ -290,6 +416,8 @@ export function bareOsProcessTableSnapshot(opts = {}) {
? 'first_failing_stage_in_pipeline'
: 'last_stage_posix_default',
waitReapsCompletedJobs: true,
waitExitCodeRule:
'When background jobs record lastExitCode, wait uses last non-zero exit among waited jobs (all-target wait); wait -n uses the first completed job exit.',
note: 'Mirrors BARE_OS_SHELL_PIPEFAIL and BARE_OS_SHELL_POSIX_MODE; see handbook ch.9 §3.'
},
ipcProcessGroups:
@@ -79,6 +79,8 @@ export class BareOsSwarmPeerPolicyEngine {
this._peers = new Map()
/** @type {number} */
this._globalReconnectBudget = 256
/** @type {{ start: number, n: number } | null} */
this._attemptBurstWindow = null
}
_key(peerKey) {
@@ -158,6 +160,15 @@ export class BareOsSwarmPeerPolicyEngine {
if (this._env) {
const adm = evaluateBareOsPeerAdmission(this._env, k, meta)
if (adm.verdict === 'deny') return false
const burstMax = Number.parseInt(
String(this._env.BARE_OS_SWARM_ATTEMPT_BURST_PER_SEC || ''),
10
)
if (Number.isFinite(burstMax) && burstMax > 0) {
const now = Date.now()
const w = this._attemptBurstWindow
if (w && now - w.start <= 1000 && w.n >= burstMax) return false
}
}
const st = this._peers.get(k)
const now = Date.now()
@@ -176,6 +187,22 @@ export class BareOsSwarmPeerPolicyEngine {
const st = this._getOrCreate(k)
if (st.reconnectBudget > 0) st.reconnectBudget--
if (this._globalReconnectBudget > 0) this._globalReconnectBudget--
if (this._env) {
const burstMax = Number.parseInt(
String(this._env.BARE_OS_SWARM_ATTEMPT_BURST_PER_SEC || ''),
10
)
if (Number.isFinite(burstMax) && burstMax > 0) {
const now = Date.now()
if (
!this._attemptBurstWindow ||
now - this._attemptBurstWindow.start > 1000
) {
this._attemptBurstWindow = { start: now, n: 0 }
}
this._attemptBurstWindow.n++
}
}
}
/**
@@ -215,6 +242,10 @@ export class BareOsSwarmPeerPolicyEngine {
return {
schema: 2,
cfg: { ...this._cfg },
attemptBurstEnv: 'BARE_OS_SWARM_ATTEMPT_BURST_PER_SEC',
attemptBurstWindow: this._attemptBurstWindow
? { ...this._attemptBurstWindow }
: null,
globalReconnectBudget: this._globalReconnectBudget,
peers: [...this._peers.entries()].map(([id, st]) => ({
id,
@@ -34,11 +34,18 @@ export function buildBareOsSyscallsProcJson(p) {
opsDetail,
posixXsh: {
schema: 3,
note: 'POSIX.1 XSH-style names: logical names in opsDetail; schema 11 adds susv4Refs tokens (Issue 7 index) on mapped operations. Schema 10: posix_fadvise simulated no-op. Socket family: ENOSYS without BARE_OS_POSIX_SOCKET_FD_BRIDGE. readv/writev: partial posix-pipe facades. nanosleep / clock_gettime via ctx.bareOsSyscall. sendmsg/recvmsg: socketMsgSurface schema 5; optional SCM_RIGHTS logical dup.',
note: 'POSIX.1 XSH-style names: logical names in opsDetail; schema 11 adds susv4Refs tokens (Issue 7 index) on mapped operations. Schema 10: posix_fadvise simulated no-op. Socket family: ENOSYS without BARE_OS_POSIX_SOCKET_FD_BRIDGE. readv/writev: partial posix-pipe facades. nanosleep / clock_gettime via ctx.bareOsSyscall. sendmsg/recvmsg: socketMsgSurface schema 6 (iovecSemantics + recvmsg susv4Refs); optional SCM_RIGHTS logical dup.',
namesCsv: bareOsPosixXshOpsCsv()
},
socketMsgSurface: {
schema: 5,
schema: 6,
iovecSemantics: {
sendmsg:
'bounded_flatten_all_iovs_into_single_wire_payload (see BARE_OS_POSIX_SOCKET_* caps)',
recvmsg:
'first_iov_primary_datagram_buffer_partial_ok_remainder_truncated (XSH/recvmsg partial read alignment)',
susv4Refs: ['XSH/sendmsg', 'XSH/recvmsg']
},
ancillaryControl: {
supported: false,
errno: 'ENOTSUP',
@@ -68,6 +75,7 @@ export function buildBareOsSyscallsProcJson(p) {
recvmsg: {
bridgePartial: true,
defaultErrno: 'ENOTSUP',
susv4Refs: ['XSH/recvmsg'],
note: 'recvmsg returns buf + msgHdr.name from peer/rinfo; controllen 0 (no queued ancillary on receive path).'
}
},
@@ -78,7 +86,7 @@ export function buildBareOsSyscallsProcJson(p) {
stdio: [0, 1, 2],
register: 'ctx.bareOsRegisterLogicalFd',
processTablePath: '/proc/bare_os/process_table.json',
processTableSchema: 8,
processTableSchema: 9,
posixLike: {
schema: 1,
note: 'POSIX open/read/write/close/pipe/dup/fcntl analogs; see docs/architecture/POSIX_DECLARED_PROFILE.md.',
@@ -76,9 +76,14 @@ export function bareOsCorestoreSnapshotOperatorHint(store) {
}
}
return {
schema: 3,
note: 'Wire the holepunch corestore-snapshot package on the host; guests receive this descriptor only. Schema 3 adds non-secret merge hints when BARE_OS_CORESTORE_SNAPSHOT_JSON and BARE_OS_CORESTORE_STATS_JSON parse.',
schema: 4,
note: 'Wire the holepunch corestore-snapshot package on the host; guests receive this descriptor only. Schema 4 adds recommendedWorkflow; schema 3 adds merge hints when BARE_OS_CORESTORE_SNAPSHOT_JSON and BARE_OS_CORESTORE_STATS_JSON parse.',
corestoreSnapshotPackage: 'corestore-snapshot',
recommendedWorkflow: [
'Run corestore-snapshot (holepunchto/corestore-snapshot) on the host store.',
'Export JSON into BARE_OS_CORESTORE_SNAPSHOT_JSON and pair BARE_OS_CORESTORE_STATS_JSON for operator diff UX.',
'Use replication_operator_sketch.corestoreSnapshotUxHint counts in /proc and disk.os RPC.'
],
hasLiveStore: !!(store && typeof store === 'object'),
guestSuspendResume: 'ENOTSUP',
guestSuspendResumeNote:
+10 -4
View File
@@ -11,6 +11,7 @@ import Hyperbee from 'hyperbee'
import hcCrypto from 'hypercore-crypto'
import idEnc from 'hypercore-id-encoding'
import { parseHdmsPairArgv } from './hdms-cli-argv.js'
import { bareOsHostBooterWarn } from './bare-os-host-booter-log.js'
import {
HDMS_AUTOPASS_SHARE_KEY,
HDMS_AUTOPASS_SHARE_RW_KEY,
@@ -288,9 +289,10 @@ export class HdmsController {
try {
await this._openEntry(entry)
} catch (err) {
console.warn(
'[hdms] skip drive ' + entry.label + ':',
err?.message || err
bareOsHostBooterWarn(
'hdms_skip_drive',
'skip drive ' + entry.label,
err?.message || String(err)
)
}
}
@@ -301,7 +303,11 @@ export class HdmsController {
try {
await opts.onAfterActivate({ labels: [...this.byLabel.keys()] })
} catch (e) {
console.warn('[hdms] onAfterActivate:', e?.message || e)
bareOsHostBooterWarn(
'hdms_on_after_activate',
'onAfterActivate failed',
e?.message || String(e)
)
}
}
}
@@ -887,10 +887,17 @@ export async function saveVaultToDrive(ctx) {
secureZero(vaultKey)
const fileCount = Object.keys(indexFiles).length
ctx.console.log(`Vault saved (${fileCount} files)`)
const pathcapTrustedRaw = String(
env.BARE_OS_PATH_CAPABILITY_TRUSTED_PUBKEYS_HEX || ''
).trim()
const pathcapTrustedKeyCount = pathcapTrustedRaw
? pathcapTrustedRaw.split(/[\s,]+/).filter(Boolean).length
: 0
try {
await bareOsAppendVaultRotationCheckpoint(ctx, {
kind: 'vault_save',
fileCount,
pathcapTrustedKeyCount,
...(snapHint ? { preSnapshotHintEmitted: true } : {})
})
mirrorVaultCheckpointToAuditChain(ctx, {
+27 -6
View File
@@ -1930,8 +1930,16 @@ async function execParsedPipeline(ctx, pipeline) {
ctx.exitCode = 0
} else {
try {
await Promise.race(target.map((j) => j.promise))
ctx.exitCode = 0
const doneJob = await Promise.race(
target.map((j) => j.promise.then(() => j))
)
const ec =
doneJob &&
typeof doneJob === 'object' &&
typeof doneJob.lastExitCode === 'number'
? doneJob.lastExitCode
: 0
ctx.exitCode = ec
} catch {
ctx.exitCode = 1
}
@@ -1950,7 +1958,13 @@ async function execParsedPipeline(ctx, pipeline) {
} else {
try {
await Promise.all(target.map((j) => j.promise))
ctx.exitCode = 0
let ec = 0
for (const j of target) {
const c =
j && typeof j.lastExitCode === 'number' ? j.lastExitCode : 0
if (c !== 0) ec = c
}
ctx.exitCode = ec
} catch {
ctx.exitCode = 1
}
@@ -2166,7 +2180,7 @@ function scheduleBackgroundShell(ctx, toks) {
.slice(0, 6)
.join(' ')
const childCtx = Object.assign({}, ctx)
/** @type {{ id: number, label: string, promise: Promise<string>, done: boolean, stopped: boolean, pgid: number, sid: number, jobControlModel: string }} */
/** @type {{ id: number, label: string, promise: Promise<string>, done: boolean, stopped: boolean, pgid: number, sid: number, jobControlModel: string, lastExitCode?: number }} */
const entry = {
id,
label,
@@ -2175,7 +2189,8 @@ function scheduleBackgroundShell(ctx, toks) {
stopped: false,
pgid,
sid,
jobControlModel: 'logical_no_fork'
jobControlModel: 'logical_no_fork',
lastExitCode: 0
}
entry.promise = (async () => {
const statements = splitTopLevelStatements(toks)
@@ -2183,9 +2198,15 @@ function scheduleBackgroundShell(ctx, toks) {
await waitWhileShellJobStopped(entry)
if (!stmt.length) continue
const r = await dispatchShellStatement(childCtx, stmt)
if (r === 'exit') return r
if (r === 'exit') {
entry.lastExitCode =
typeof childCtx.exitCode === 'number' ? childCtx.exitCode : 0
return r
}
}
syncBareOsExitStatusEnv(childCtx)
entry.lastExitCode =
typeof childCtx.exitCode === 'number' ? childCtx.exitCode : 0
return 'ok'
})()
ctx.shellBackgroundJobs.list.push(entry)
+6 -5
View File
@@ -1396,7 +1396,7 @@ test('buildBareOsSyscallsProcJson exposes posixLike fd mapping', async (t) => {
t.ok(j.posixXsh.namesCsv.includes('sendmsg'))
t.ok(j.posixXsh.namesCsv.includes('recvmsg'))
t.ok(j.posixXsh.namesCsv.includes('shutdown'))
t.is(j.socketMsgSurface?.schema, 5)
t.is(j.socketMsgSurface?.schema, 6)
t.is(j.socketMsgSurface?.logicalScmRightsOnSend?.syscallResultField, 'scmRightsLocalDup')
t.is(j.socketMsgSurface?.ancillaryControl?.supported, false)
t.is(j.socketMsgSurface?.ancillaryControl?.errno, 'ENOTSUP')
@@ -1583,9 +1583,10 @@ test('disk.os replication_snapshot and replication_operator_sketch RPCs', async
t.ok(typeof sj.writable === 'boolean')
const op = await bridge.execRpc('bare_os', 'replication_operator_sketch', [])
const oj = JSON.parse(op)
t.is(oj.schema, 7)
t.is(oj.schema, 8)
t.is(oj.protomuxOperatorSketch?.schema, 2)
t.is(oj.corestoreSnapshotUxHint?.schema, 3)
t.ok(Object.prototype.hasOwnProperty.call(oj, 'hyperdhtAddressSketch'))
t.is(oj.corestoreSnapshotUxHint?.schema, 4)
t.is(oj.corestoreSnapshotPackageRef?.npmPackage, 'corestore-snapshot')
t.is(oj.seedReplicationStatus?.depth, 1)
t.is(oj.swarmPeerCount, null)
@@ -6843,7 +6844,7 @@ test('process table snapshot includes processGroups metadata', async (t) => {
t.ok(s.processGroups)
t.is(s.processGroups.schema, 1)
t.ok(String(s.processGroups.killpgAnalog).includes('killpg'))
t.is(s.schemaVersion, 8)
t.is(s.schemaVersion, 9)
t.ok(s.jobControlSemantics && s.jobControlSemantics.pipefail === true)
const booter = s.processes.find((p) => p && p.pid === 2)
t.ok(booter && booter.parentName === 'bare-os-kernel')
@@ -7232,7 +7233,7 @@ test('disk.os replication_operator_sketch mirrors blind v3 and hyperblobs env JS
})
const op = await bridge.execRpc('bare_os', 'replication_operator_sketch', [])
const oj = JSON.parse(op)
t.is(oj.schema, 7)
t.is(oj.schema, 8)
t.is(oj.blindTopologySketchV3?.schema, 3)
t.is(oj.hyperblobsDedupSketch?.chunkCount, 4)
t.is(oj.corestoreOperatorSketch?.namespaceCount, 2)
+10
View File
@@ -57,6 +57,16 @@ const CONF = {
_SC_HOST_NAME_MAX: '255',
_POSIX_HOST_NAME_MAX: '255',
_SC_MONOTONIC_CLOCK: '1',
/** Dynamic when `ctx.bareOsGetconfSysconf` + native bare-hrtime; static default 0. */
_SC_MONOTONIC_CLOCK_RES: '0',
_SC_TRACE: '-1',
_SC_TRACE_VERSION: '-1',
_SC_RAW_SOCKETS: '-1',
_SC_ADVISORY_INFO: '0',
_SC_BARRIERS: '-1',
_SC_SPIN_LOCKS: '1',
_SC_TIMER_MAX: '32',
_SC_DELAYTIMER_MAX: '0',
_SC_ATEXIT_MAX: '32',
_SC_LINE_MAX: '2048',
_SC_BC_BASE_MAX: '99',
@@ -1,5 +1,5 @@
{
"schema": 8,
"schema": 9,
"processes": [
{
"pid": 2,
@@ -7,7 +7,8 @@
"pgid": 2,
"sid": 1,
"name": "bare-os-booter",
"state": "running"
"state": "running",
"nice": 0
},
{
"pid": 3,
@@ -15,7 +16,8 @@
"pgid": 3,
"sid": 1,
"name": "bare-os-shell",
"state": "running"
"state": "running",
"nice": 0
}
]
}
@@ -4,7 +4,7 @@
*/
/** Semver for the documented POSIX-like surface (handbook ch.9 + environment appendix). */
export const BARE_OS_POSIX_PROFILE_VERSION = '1.0.18'
export const BARE_OS_POSIX_PROFILE_VERSION = '1.0.19'
/** Short identifier for telemetry and `/proc` mirrors. */
export const BARE_OS_POSIX_PROFILE_ID = 'bare-os-posix-like'
@@ -146,6 +146,16 @@ const CONF = {
_SC_HOST_NAME_MAX: '255',
_POSIX_HOST_NAME_MAX: '255',
_SC_MONOTONIC_CLOCK: '1',
/** Dynamic when `ctx.bareOsGetconfSysconf` + native bare-hrtime; static default 0. */
_SC_MONOTONIC_CLOCK_RES: '0',
_SC_TRACE: '-1',
_SC_TRACE_VERSION: '-1',
_SC_RAW_SOCKETS: '-1',
_SC_ADVISORY_INFO: '0',
_SC_BARRIERS: '-1',
_SC_SPIN_LOCKS: '1',
_SC_TIMER_MAX: '32',
_SC_DELAYTIMER_MAX: '0',
_SC_ATEXIT_MAX: '32',
_SC_LINE_MAX: '2048',
_SC_BC_BASE_MAX: '99',
@@ -1,7 +1,7 @@
{
"schema": 2,
"profileId": "bare-os-posix-like",
"generatedAt": "2026-04-06T03:01:17.010Z",
"generatedAt": "2026-04-06T03:12:50.834Z",
"note": "Sparse POSIX Issue 7 coverage hints for /bin utilities. Omitted command names are not yet profiled here.",
"commandIndex": [
{
@@ -1,9 +1,9 @@
{
"schemaVersion": 11,
"ctxApiVersion": "1.53.0",
"ctxApiVersion": "1.54.0",
"posixProfile": {
"id": "bare-os-posix-like",
"version": "1.0.18"
"version": "1.0.19"
},
"ops": ["readFile", "writeFile", "socket"],
"opsDetail": [
@@ -33,7 +33,12 @@
"namesCsv": "open,close,read,write,readv,writev,getsockopt,setsockopt,lseek,nanosleep,clock_gettime,pipe,dup,dup2,fcntl,poll,select,umask,socket,bind,listen,accept,connect,send,recv,recvfrom,sendmsg,recvmsg,shutdown"
},
"socketMsgSurface": {
"schema": 4,
"schema": 6,
"iovecSemantics": {
"sendmsg": "bounded_flatten_all_iovs_into_single_wire_payload",
"recvmsg": "first_iov_primary_datagram_buffer_partial_ok_remainder_truncated",
"susv4Refs": ["XSH/sendmsg", "XSH/recvmsg"]
},
"ancillaryControl": {
"supported": false,
"errno": "ENOTSUP",
@@ -51,7 +56,11 @@
"syscallResultField": "scmRightsLocalDup"
},
"sendmsg": { "bridgePartial": true, "defaultErrno": "ENOTSUP" },
"recvmsg": { "bridgePartial": true, "defaultErrno": "ENOTSUP" }
"recvmsg": {
"bridgePartial": true,
"defaultErrno": "ENOTSUP",
"susv4Refs": ["XSH/recvmsg"]
}
},
"errnoHints": {
"ENOENT": 2,
@@ -60,7 +69,7 @@
"fdModel": {
"schema": 1,
"stdio": [0, 1, 2],
"processTableSchema": 8
"processTableSchema": 9
},
"signalModel": {
"schema": 1,
@@ -7,12 +7,6 @@
"b4a"
]
},
{
"path": "/lib/bare/bundles/compactEncoding.js",
"keys": [
"compactEncoding"
]
},
{
"path": "/lib/bare/bundles/safetyCatch.js",
"keys": [
@@ -26,9 +20,9 @@
]
},
{
"path": "/lib/bare/bundles/protomux.js",
"path": "/lib/bare/bundles/compactEncoding.js",
"keys": [
"protomux"
"compactEncoding"
]
},
{
@@ -38,9 +32,9 @@
]
},
{
"path": "/lib/bare/bundles/barePath.js",
"path": "/lib/bare/bundles/protomux.js",
"keys": [
"barePath"
"protomux"
]
},
{
@@ -49,6 +43,12 @@
"bareEncoding"
]
},
{
"path": "/lib/bare/bundles/barePath.js",
"keys": [
"barePath"
]
},
{
"path": "/lib/bare/bundles/bareEvents.js",
"keys": [
@@ -61,6 +61,12 @@
"bareAbort"
]
},
{
"path": "/lib/bare/bundles/bareReadline.js",
"keys": [
"bareReadline"
]
},
{
"path": "/lib/bare/bundles/bareAbortController.js",
"keys": [
@@ -73,12 +79,6 @@
"bareAnsiEscapes"
]
},
{
"path": "/lib/bare/bundles/bareReadline.js",
"keys": [
"bareReadline"
]
},
{
"path": "/lib/bare/bundles/bareAddonResolve.js",
"keys": [
@@ -86,9 +86,9 @@
]
},
{
"path": "/lib/bare/bundles/bareCrypto.js",
"path": "/lib/bare/bundles/fetch.js",
"keys": [
"bareCrypto"
"fetch"
]
},
{
@@ -104,9 +104,9 @@
]
},
{
"path": "/lib/bare/bundles/bareAssert.js",
"path": "/lib/bare/bundles/bareCrypto.js",
"keys": [
"bareAssert"
"bareCrypto"
]
},
{
@@ -116,9 +116,9 @@
]
},
{
"path": "/lib/bare/bundles/bareAtomics.js",
"path": "/lib/bare/bundles/bareAssert.js",
"keys": [
"bareAtomics"
"bareAssert"
]
},
{
@@ -128,9 +128,15 @@
]
},
{
"path": "/lib/bare/bundles/fetch.js",
"path": "/lib/bare/bundles/bareAtomics.js",
"keys": [
"fetch"
"bareAtomics"
]
},
{
"path": "/lib/bare/bundles/bareBundle.js",
"keys": [
"bareBundle"
]
},
{
@@ -152,9 +158,9 @@
]
},
{
"path": "/lib/bare/bundles/bareBundle.js",
"path": "/lib/bare/bundles/bareBoot.js",
"keys": [
"bareBundle"
"bareBoot"
]
},
{
@@ -170,9 +176,9 @@
]
},
{
"path": "/lib/bare/bundles/bareBoot.js",
"path": "/lib/bare/bundles/bareDebugLog.js",
"keys": [
"bareBoot"
"bareDebugLog"
]
},
{
@@ -181,30 +187,24 @@
"bareBundleId"
]
},
{
"path": "/lib/bare/bundles/bareDaemon.js",
"keys": [
"bareDaemon"
]
},
{
"path": "/lib/bare/bundles/bareChannel.js",
"keys": [
"bareChannel"
]
},
{
"path": "/lib/bare/bundles/bareDebugLog.js",
"keys": [
"bareDebugLog"
]
},
{
"path": "/lib/bare/bundles/bareDelta.js",
"keys": [
"bareDelta"
]
},
{
"path": "/lib/bare/bundles/bareDaemon.js",
"keys": [
"bareDaemon"
]
},
{
"path": "/lib/bare/bundles/bareDiagnosticsChannel.js",
"keys": [
@@ -224,15 +224,15 @@
]
},
{
"path": "/lib/bare/bundles/bareExif.js",
"path": "/lib/bare/bundles/bareCov.js",
"keys": [
"bareExif"
"bareCov"
]
},
{
"path": "/lib/bare/bundles/bareFfmpeg.js",
"path": "/lib/bare/bundles/bareExif.js",
"keys": [
"bareFfmpeg"
"bareExif"
]
},
{
@@ -242,9 +242,15 @@
]
},
{
"path": "/lib/bare/bundles/bareCov.js",
"path": "/lib/bare/bundles/bareFfmpeg.js",
"keys": [
"bareCov"
"bareFfmpeg"
]
},
{
"path": "/lib/bare/bundles/bareFormData.js",
"keys": [
"bareFormData"
]
},
{
@@ -259,42 +265,12 @@
"bareFormat"
]
},
{
"path": "/lib/bare/bundles/bareFormData.js",
"keys": [
"bareFormData"
]
},
{
"path": "/lib/bare/bundles/bareFileLogger.js",
"keys": [
"bareFileLogger"
]
},
{
"path": "/lib/bare/bundles/bareFs.js",
"keys": [
"bareFs"
]
},
{
"path": "/lib/bare/bundles/bareGif.js",
"keys": [
"bareGif"
]
},
{
"path": "/lib/bare/bundles/bareHrtime.js",
"keys": [
"bareHrtime"
]
},
{
"path": "/lib/bare/bundles/bareGtk.js",
"keys": [
"bareGtk"
]
},
{
"path": "/lib/bare/bundles/bareHeif.js",
"keys": [
@@ -302,15 +278,33 @@
]
},
{
"path": "/lib/bare/bundles/bareHttpParser.js",
"path": "/lib/bare/bundles/bareFileLogger.js",
"keys": [
"bareHttpParser"
"bareFileLogger"
]
},
{
"path": "/lib/bare/bundles/bareImageResample.js",
"path": "/lib/bare/bundles/bareGtk.js",
"keys": [
"bareImageResample"
"bareGtk"
]
},
{
"path": "/lib/bare/bundles/bareHrtime.js",
"keys": [
"bareHrtime"
]
},
{
"path": "/lib/bare/bundles/bareFs.js",
"keys": [
"bareFs"
]
},
{
"path": "/lib/bare/bundles/bareHttpParser.js",
"keys": [
"bareHttpParser"
]
},
{
@@ -319,24 +313,30 @@
"bareIco"
]
},
{
"path": "/lib/bare/bundles/bareImageResample.js",
"keys": [
"bareImageResample"
]
},
{
"path": "/lib/bare/bundles/bareHttp1.js",
"keys": [
"bareHttp1"
]
},
{
"path": "/lib/bare/bundles/bareInspect.js",
"keys": [
"bareInspect"
]
},
{
"path": "/lib/bare/bundles/bareHttps.js",
"keys": [
"bareHttps"
]
},
{
"path": "/lib/bare/bundles/bareInspect.js",
"keys": [
"bareInspect"
]
},
{
"path": "/lib/bare/bundles/bareJpeg.js",
"keys": [
@@ -361,12 +361,6 @@
"bareLief"
]
},
{
"path": "/lib/bare/bundles/bareLogger.js",
"keys": [
"bareLogger"
]
},
{
"path": "/lib/bare/bundles/bareInspector.js",
"keys": [
@@ -374,9 +368,9 @@
]
},
{
"path": "/lib/bare/bundles/bareLink.js",
"path": "/lib/bare/bundles/bareLogger.js",
"keys": [
"bareLink"
"bareLogger"
]
},
{
@@ -386,15 +380,9 @@
]
},
{
"path": "/lib/bare/bundles/bareModule.js",
"path": "/lib/bare/bundles/bareLink.js",
"keys": [
"bareModule"
]
},
{
"path": "/lib/bare/bundles/bareModuleResolve.js",
"keys": [
"bareModuleResolve"
"bareLink"
]
},
{
@@ -404,9 +392,15 @@
]
},
{
"path": "/lib/bare/bundles/bareNdk.js",
"path": "/lib/bare/bundles/bareModuleResolve.js",
"keys": [
"bareNdk"
"bareModuleResolve"
]
},
{
"path": "/lib/bare/bundles/bareModule.js",
"keys": [
"bareModule"
]
},
{
@@ -416,21 +410,9 @@
]
},
{
"path": "/lib/bare/bundles/bareNative.js",
"path": "/lib/bare/bundles/bareNdk.js",
"keys": [
"bareNative"
]
},
{
"path": "/lib/bare/bundles/bareMedia.js",
"keys": [
"bareMedia"
]
},
{
"path": "/lib/bare/bundles/bareNet.js",
"keys": [
"bareNet"
"bareNdk"
]
},
{
@@ -439,42 +421,72 @@
"bareNodeFetch"
]
},
{
"path": "/lib/bare/bundles/bareOs.js",
"keys": [
"bareOs"
]
},
{
"path": "/lib/bare/bundles/bareOpen.js",
"keys": [
"bareOpen"
]
},
{
"path": "/lib/bare/bundles/bareNet.js",
"keys": [
"bareNet"
]
},
{
"path": "/lib/bare/bundles/bareMedia.js",
"keys": [
"bareMedia"
]
},
{
"path": "/lib/bare/bundles/bareNative.js",
"keys": [
"bareNative"
]
},
{
"path": "/lib/bare/bundles/bareOs.js",
"keys": [
"bareOs"
]
},
{
"path": "/lib/bare/bundles/barePack.js",
"keys": [
"barePack"
]
},
{
"path": "/lib/bare/bundles/barePackDrive.js",
"keys": [
"barePackDrive"
]
},
{
"path": "/lib/bare/bundles/barePerformance.js",
"keys": [
"barePerformance"
]
},
{
"path": "/lib/bare/bundles/bareNodeRuntime.js",
"keys": [
"bareNodeRuntime"
]
},
{
"path": "/lib/bare/bundles/barePackDrive.js",
"keys": [
"barePackDrive"
]
},
{
"path": "/lib/bare/bundles/barePng.js",
"keys": [
"barePng"
]
},
{
"path": "/lib/bare/bundles/bareDev.js",
"keys": [
"bareDev"
]
},
{
"path": "/lib/bare/bundles/barePipe.js",
"keys": [
@@ -487,30 +499,6 @@
"barePrebuild"
]
},
{
"path": "/lib/bare/bundles/bareNodeRuntime.js",
"keys": [
"bareNodeRuntime"
]
},
{
"path": "/lib/bare/bundles/bareProcess.js",
"keys": [
"bareProcess"
]
},
{
"path": "/lib/bare/bundles/bareQuerystring.js",
"keys": [
"bareQuerystring"
]
},
{
"path": "/lib/bare/bundles/bareDev.js",
"keys": [
"bareDev"
]
},
{
"path": "/lib/bare/bundles/barePunycode.js",
"keys": [
@@ -529,12 +517,6 @@
"bareQueueMicrotask"
]
},
{
"path": "/lib/bare/bundles/bareRuntime.js",
"keys": [
"bareRuntime"
]
},
{
"path": "/lib/bare/bundles/barePromClient.js",
"keys": [
@@ -542,15 +524,21 @@
]
},
{
"path": "/lib/bare/bundles/bareRpc.js",
"path": "/lib/bare/bundles/bareQuerystring.js",
"keys": [
"bareRpc"
"bareQuerystring"
]
},
{
"path": "/lib/bare/bundles/bareRepl.js",
"path": "/lib/bare/bundles/bareRuntime.js",
"keys": [
"bareRepl"
"bareRuntime"
]
},
{
"path": "/lib/bare/bundles/bareProcess.js",
"keys": [
"bareProcess"
]
},
{
@@ -560,15 +548,15 @@
]
},
{
"path": "/lib/bare/bundles/bareSemver.js",
"path": "/lib/bare/bundles/bareRpc.js",
"keys": [
"bareSemver"
"bareRpc"
]
},
{
"path": "/lib/bare/bundles/bareRun.js",
"path": "/lib/bare/bundles/bareSemver.js",
"keys": [
"bareRun"
"bareSemver"
]
},
{
@@ -578,9 +566,9 @@
]
},
{
"path": "/lib/bare/bundles/bareStringDecoder.js",
"path": "/lib/bare/bundles/bareRun.js",
"keys": [
"bareStringDecoder"
"bareRun"
]
},
{
@@ -590,9 +578,15 @@
]
},
{
"path": "/lib/bare/bundles/bareStream.js",
"path": "/lib/bare/bundles/bareStringDecoder.js",
"keys": [
"bareStream"
"bareStringDecoder"
]
},
{
"path": "/lib/bare/bundles/bareRepl.js",
"keys": [
"bareRepl"
]
},
{
@@ -602,15 +596,15 @@
]
},
{
"path": "/lib/bare/bundles/bareStdio.js",
"path": "/lib/bare/bundles/bareStream.js",
"keys": [
"bareStdio"
"bareStream"
]
},
{
"path": "/lib/bare/bundles/bareStructuredClone.js",
"path": "/lib/bare/bundles/bareStdio.js",
"keys": [
"bareStructuredClone"
"bareStdio"
]
},
{
@@ -620,9 +614,9 @@
]
},
{
"path": "/lib/bare/bundles/bareTap.js",
"path": "/lib/bare/bundles/bareStructuredClone.js",
"keys": [
"bareTap"
"bareStructuredClone"
]
},
{
@@ -631,6 +625,12 @@
"bareSystemLogger"
]
},
{
"path": "/lib/bare/bundles/bareTap.js",
"keys": [
"bareTap"
]
},
{
"path": "/lib/bare/bundles/bareSubprocess.js",
"keys": [
@@ -643,30 +643,30 @@
"bareTiff"
]
},
{
"path": "/lib/bare/bundles/bareTimers.js",
"keys": [
"bareTimers"
]
},
{
"path": "/lib/bare/bundles/bareThread.js",
"keys": [
"bareThread"
]
},
{
"path": "/lib/bare/bundles/bareTpl.js",
"keys": [
"bareTpl"
]
},
{
"path": "/lib/bare/bundles/bareTcp.js",
"keys": [
"bareTcp"
]
},
{
"path": "/lib/bare/bundles/bareTimers.js",
"keys": [
"bareTimers"
]
},
{
"path": "/lib/bare/bundles/bareTpl.js",
"keys": [
"bareTpl"
]
},
{
"path": "/lib/bare/bundles/bareType.js",
"keys": [
@@ -685,18 +685,18 @@
"bareUiKit"
]
},
{
"path": "/lib/bare/bundles/bareTty.js",
"keys": [
"bareTty"
]
},
{
"path": "/lib/bare/bundles/bareUnpack.js",
"keys": [
"bareUnpack"
]
},
{
"path": "/lib/bare/bundles/bareTty.js",
"keys": [
"bareTty"
]
},
{
"path": "/lib/bare/bundles/bareV8.js",
"keys": [
@@ -709,18 +709,18 @@
"bareVm"
]
},
{
"path": "/lib/bare/bundles/bareWalkHandles.js",
"keys": [
"bareWalkHandles"
]
},
{
"path": "/lib/bare/bundles/bareUnionBundle.js",
"keys": [
"bareUnionBundle"
]
},
{
"path": "/lib/bare/bundles/bareWalkHandles.js",
"keys": [
"bareWalkHandles"
]
},
{
"path": "/lib/bare/bundles/bareWebKit.js",
"keys": [
@@ -728,9 +728,9 @@
]
},
{
"path": "/lib/bare/bundles/bareWebp.js",
"path": "/lib/bare/bundles/bareWebKitGtk.js",
"keys": [
"bareWebp"
"bareWebKitGtk"
]
},
{
@@ -739,18 +739,18 @@
"bareV8ToIstanbul"
]
},
{
"path": "/lib/bare/bundles/bareWebKitGtk.js",
"keys": [
"bareWebKitGtk"
]
},
{
"path": "/lib/bare/bundles/bareUtils.js",
"keys": [
"bareUtils"
]
},
{
"path": "/lib/bare/bundles/bareWebp.js",
"keys": [
"bareWebp"
]
},
{
"path": "/lib/bare/bundles/bareWhich.js",
"keys": [
@@ -769,18 +769,18 @@
"bareXdiff"
]
},
{
"path": "/lib/bare/bundles/bareZmq.js",
"keys": [
"bareZmq"
]
},
{
"path": "/lib/bare/bundles/bareZlib.js",
"keys": [
"bareZlib"
]
},
{
"path": "/lib/bare/bundles/bareZmq.js",
"keys": [
"bareZmq"
]
},
{
"path": "/lib/bare/bundles/bareWs.js",
"keys": [
@@ -1595,8 +1595,8 @@
],
"bundleProvenance": {
"schemaVersion": 1,
"generatedAt": "2026-04-06T03:01:17.869Z",
"gitCommit": "8f61d0bea8efc674a1063df176d7383a09f85b46",
"generatedAt": "2026-04-06T03:12:51.812Z",
"gitCommit": "071edccfb3f074d3ee00c901d5df2a514063815d",
"nodeVersion": "v22.22.0",
"bundleTier": "all",
"normativeManifest": "packages/bare-os-booter/lib/bare-module-manifest.json",
@@ -1,6 +1,6 @@
{
"schema": 1,
"atMs": 1775444477009,
"atMs": 1775445170834,
"commands": [
"arch",
"awk",
@@ -19,3 +19,5 @@ Staged paths: **`/lib/init/init-main.js`**, **`/lib/init/fragments/*`**, and bun
| Interactive loop | readline / REPL after boot stages | `init-main.js` |
After editing any fragment or `init-main.js`, run `node scripts/bundle-kernel-init.mjs` and sync the seeder tree (`rsync -a --delete kernel/ packages/bare-os-seeder/kernel/`). CI: `verify-init-bundle-recipe.mjs`, `verify-kernel-seeder-parity.mjs`, `verify-runtime-no-incomplete-markers.mjs`.
**Boot footprint:** keep heavy optional paths (for example deep selftest or auxiliary REPL wiring) behind **boot policy** / env gates inside existing fragments rather than adding new concatenation slots unless `verify-init-bundle-recipe.mjs` is updated—this preserves a single `/boot/init.js` artifact while allowing cold-boot skipping of gated sections.
File diff suppressed because one or more lines are too long
+1
View File
@@ -4,6 +4,7 @@
* look like incomplete implementations (complements verify-bundle-markers.mjs). Allowlist entries
* carry rationale. This is **not** the same gate as verify-runtime-no-incomplete-markers.mjs, which
* applies only to first-party kernel + booter sources see developer-guide/node-to-bare-modules.md.
* HTTP stacks may retain **`bareOsHttp501Factory("Method not implemented")`** patterns after `sanitize-bare-bundles.mjs`; those are **501 factories**, not kernel TODOs do not add them to the throw allowlist unless upstream reintroduces raw abstract throws.
*
* Matches: throw new Error("…"), cb(new Error("…")), emit("error", new Error("…")), etc.
*/
+27
View File
@@ -161,6 +161,33 @@ function main() {
)
process.exit(1)
}
const writeReport =
process.env.BARE_OS_HOLEPUNCH_DRIFT_WRITE_REPORT === '1' ||
process.env.BARE_OS_HOLEPUNCH_DRIFT_WRITE_REPORT === 'true'
if (writeReport) {
const outMd = path.join(root, 'docs/audit/holepunch-drift-last-run.md')
const lines = [
'# Holepunch clone drift (last verify)',
'',
`Generated: ${new Date().toISOString()}`,
'',
'All listed clones were at or ahead of `origin/main` when this file was written.',
'',
`Mode: ${tier1 ? 'tier1Repos[]' : 'repos[]'}`,
'',
'Repos checked:',
...repos.map((n) => `- ${n}`),
'',
'Re-run: `BARE_OS_HOLEPUNCH_DRIFT_WRITE_REPORT=1 npm run pretest` (or run this script directly after `git fetch`).',
''
]
try {
fs.mkdirSync(path.dirname(outMd), { recursive: true })
fs.writeFileSync(outMd, lines.join('\n'), 'utf8')
} catch (e) {
console.warn('verify-holepunch-clone-drift: could not write report', e)
}
}
console.log('verify-holepunch-clone-drift: OK')
}