feat(boot,vfs,security): expand kernel boot contract, VFS snapshots, and ctx surfaces

- Kernel: strict capability contract merge, junit selftest, startup class, cold boot
  budget warning, boot txn schema v1, rc/kernel.ext resolution traces, richer
  bareOsPublishBootReady (steps/bootSteps, FSM sketch)
- Booter: warm reboot extra cycles, boot provenance on boot.json, step mirroring,
  corestore/swarm suspend-resume hooks, swarm connection manager sketch, event bus
  + optional NDJSON, security_posture proc schema v2, key handle TTL/scopes
- VFS: snapshot path class + BARE_OS_VFS_SNAPSHOTS checkout views, policy metrics,
  batch put + diff helpers, watch consistency hint, quotas vfsQuota fields
- Protocol: BARE_OS_PROTOMUX_CORK_HINT_VERSION via channel exports
- Initd: BARE_INITD_UNIT_STATES; shell: tokenizer module split
- Extensions: capability conflict detector in kernel-extension-resolver
- Docs/scripts: reference index map, observability event bus, dry-run vs rollback
  table, benchmark trend + integration-lab smoke, scripts README
- Tests: /proc listing + pseudo path caps for snapshots and security_posture
This commit is contained in:
Raven Scott
2026-04-04 17:24:48 -04:00
parent 9dcfaa8b1d
commit a485ce98d3
51 changed files with 7297 additions and 446 deletions
+2
View File
@@ -53,6 +53,8 @@ This project is **experimental research software**. APIs described here follow t
- **[Kernel program (governed expansion)](kernel-program.md)** — Governance, boot hooks, **`/proc/bare_os/kernel_program.json`**, Bare stack pointers, 200-item roadmap batches.
- **[Naming conventions](naming-conventions.md)** — First-party vs vendored trees, `ctx` / env / proc naming.
- **[Naming migrations](naming-migrations.md)** — Legacy aliases and deprecation windows for boot hooks and policy keys.
- **[Architecture decision records (ADRs)](adr/README.md)** — Contract decisions and templates.
- **[Kernel doctor / kernel-explain conventions](kernel-explain-and-doctor-conventions.md)** — Structured diagnostic output.
---