feat(boot,vfs,security): expand kernel boot contract, VFS snapshots, and ctx surfaces

- Kernel: strict capability contract merge, junit selftest, startup class, cold boot
  budget warning, boot txn schema v1, rc/kernel.ext resolution traces, richer
  bareOsPublishBootReady (steps/bootSteps, FSM sketch)
- Booter: warm reboot extra cycles, boot provenance on boot.json, step mirroring,
  corestore/swarm suspend-resume hooks, swarm connection manager sketch, event bus
  + optional NDJSON, security_posture proc schema v2, key handle TTL/scopes
- VFS: snapshot path class + BARE_OS_VFS_SNAPSHOTS checkout views, policy metrics,
  batch put + diff helpers, watch consistency hint, quotas vfsQuota fields
- Protocol: BARE_OS_PROTOMUX_CORK_HINT_VERSION via channel exports
- Initd: BARE_INITD_UNIT_STATES; shell: tokenizer module split
- Extensions: capability conflict detector in kernel-extension-resolver
- Docs/scripts: reference index map, observability event bus, dry-run vs rollback
  table, benchmark trend + integration-lab smoke, scripts README
- Tests: /proc listing + pseudo path caps for snapshots and security_posture
This commit is contained in:
Raven Scott
2026-04-04 17:24:48 -04:00
parent 9dcfaa8b1d
commit a485ce98d3
51 changed files with 7297 additions and 446 deletions
+26
View File
@@ -0,0 +1,26 @@
/** Boot transaction journal row state (resume / audit). */
const BARE_OS_BOOT_TXN_STATE = Object.freeze({
STAGE_COMMITTED: 'stage_committed'
})
/**
* @param {Record<string, unknown>} ctx
* @param {Record<string, unknown>} ev
*/
async function invokeCtxBootHooks(ctx, ev) {
const label = String(
ev.phase !== undefined && ev.phase !== null
? ev.phase
: ev.step !== undefined && ev.step !== null
? ev.step
: ''
)
const merged = { ...ev, phase: label, step: label }
if (typeof ctx.bareOsInvokeBootStepHooks === 'function') {
await ctx.bareOsInvokeBootStepHooks(merged)
return
}
if (typeof ctx.bareOsInvokeBootPhaseHooks === 'function') {
await ctx.bareOsInvokeBootPhaseHooks(merged)
}
}