feat: complete 20-track kernel roadmap (P2P ops, POSIX, HRPC, CI, docs)

- Add optional Holepunch clone lag gate (holepunch-freshness-gate.json,
  verify-holepunch-clone-freshness.mjs) and wire into pretest/docs.
- Extend stock ctx.bareOsHrpcRequest with disk.os replication routes;
  bump hrpc_allowlist_sketch proc to schema 2 with stockRoutes list.
- Security posture: blindRelayAudit; hyper_multisig_trust_pointer schema 2
  + vault multisig continuity env; login/unlock audit hook.
- Syscalls schema 9 alignment (JSON schema, compatibility matrix, conformance
  matrix clock_gettime); boot budget telemetry schema 2 in metrics_live.
- Coreutils hostname -s/--short man/options; rebuild kernel bins/man.
- POSIX + P2P dashboard section in docs/README; handbook/DOCUMENTATION/
  release-checklist/OTA/KERNEL_CONTRACT/PEAR-RUN and related reference updates.
- verify-boot-policy-extension-signer-pins: scan kernel init fragments.

Note: vendor drift section removed from kernel/lib/bare/README.md (intentional).
This commit is contained in:
Raven Scott
2026-04-05 14:17:20 -04:00
parent c15e8fa5be
commit 8bde745191
87 changed files with 7385 additions and 6725 deletions
+2 -2
View File
@@ -183,10 +183,10 @@ const CONF = {
_PC_2_SYMLINKS: '1',
/** Comma-separated `ctx.bareOsSyscall` op names implemented in stock booter. */
BARE_OS_SYSCALL_OPS:
'accept,access,bind,chdir,chmod,connect,exists,fcntl,fdatasync,fsync,ftruncate,getcwd,getsockopt,kill,link,listen,lstat,mkdir,mount,mq_open,mq_receive,mq_send,nanosleep,pathconf,posixPoll,readFile,readdir,readlink,readv,recv,recvfrom,recvmsg,rename,rmdir,select,send,sendmsg,setsockopt,shutdown,socket,stat,symlink,truncate,umask,umount,unlink,utimes,writeFile,writev',
'accept,access,bind,chdir,chmod,clock_gettime,connect,exists,fcntl,fdatasync,fsync,ftruncate,getcwd,getsockopt,kill,link,listen,lstat,mkdir,mount,mq_open,mq_receive,mq_send,nanosleep,pathconf,posixPoll,readFile,readdir,readlink,readv,recv,recvfrom,recvmsg,rename,rmdir,select,send,sendmsg,setsockopt,shutdown,socket,stat,symlink,truncate,umask,umount,unlink,utimes,writeFile,writev',
/** POSIX.1 XSH-style names documented in `/proc/bare_os/syscalls.json` opsDetail (socket family are syscall probes returning ENOSYS-shaped results). */
BARE_OS_POSIX_XSH_OPS:
'open,close,read,write,lseek,nanosleep,pipe,dup,dup2,fcntl,poll,select,umask,socket,bind,listen,accept,connect,send,recv,recvfrom,sendmsg,recvmsg,shutdown',
'open,close,read,write,lseek,nanosleep,clock_gettime,pipe,dup,dup2,fcntl,poll,select,umask,socket,bind,listen,accept,connect,send,recv,recvfrom,sendmsg,recvmsg,shutdown',
/** Encodings accepted by `/bin/iconv` (subset; case-insensitive names). */
BARE_OS_ICONV_ENCODINGS: 'UTF-8,ISO-8859-1,UTF-16LE,UTF-16BE',
/** Synthetic process table JSON path (logical VFS). */
+13 -1
View File
@@ -88,10 +88,22 @@ function bareOsEmitRaw(ctx, chunk) {
}
async function run(ctx, argv) {
const h =
let h =
globalThis.process?.env?.HOSTNAME ||
globalThis.process?.env?.COMPUTERNAME ||
ctx.vfs.env.HOSTNAME ||
'bare-os'
h = String(h)
let shortOnly = false
for (let i = 1; i < argv.length; i++) {
const a = String(argv[i] || '')
if (a === '-s' || a === '--short') shortOnly = true
else if (a === '-f' || a === '--fqdn') shortOnly = false
else if (a === '--') break
}
if (shortOnly) {
const dot = h.indexOf('.')
if (dot > 0) h = h.slice(0, dot)
}
ctx.console.log(h)
}