Updates to MD
This commit is contained in:
@@ -33,15 +33,15 @@ Bare OS advertises optional booter and seed-channel capabilities as a versioned
|
||||
|
||||
9. **Sixth capability word (`bits6`)** — **`BARE_OS_KERNEL_FEATURES_STOCK_WORD_REPLICATION_OPERATOR_SURFACE`** and **`BARE_OS_FEATURE6_*`** group extended seed RPCs (replication plan, DHT bootstrap hints, compact ping, …), advisory replication JSON v2 fields, **`/proc/bare_os/*.json`** operator metrics, boot policy v6 (**`requireKernelCapabilitiesReplicationOperatorSurface`**, **`requireBooterSemver`**, **`requireCtxApiMin`**, extension deny/hash pins, offline LKG strict integrity), kernel extension registry schema v3 with dependency edges, Pear/Bare bridge **`ctx`** hooks, strict **`/proc/bare_os`** alias completeness (**`FEATURE6_STRICT_PROC_ALIAS`** + **`BARE_OS_PROC_ALIAS_STRICT`**), VFS/POSIX/initd/timer extensions, worker/sandbox/net-policy surfaces, telemetry NDJSON v5 / OTel schema v3 / audit v3, and CI (**`verify-kernel-capabilities-word-6.mjs`**, Pear static **`node:`** import scan). Seed JSON and **`/proc/bare_os_features`** include **`bits6`**. **`BARE_OS_SEED_CAP_STRICT`** may require **`bits6`** when the stock sixth word is non-zero.
|
||||
|
||||
10. **Seventh capability word (`bits7`)** — **`BARE_OS_KERNEL_FEATURES_STOCK_WORD_PEAR_CORESTORE_HRPC`** and **`BARE_OS_FEATURE7_*`** add another full 32-bit word. **Word 6 bits 16–31** remain reserved for future sixth-word–scoped features; new coarse groups use **`bits7`** instead (seed RPC surface, proc JSON, boot policy v7, extension registry v4, Pear/Bare bridge stubs, VFS/env/git policy docs, initd/subprocess, worker/net, telemetry v6/OTel v4/audit v4, CI **`verify-kernel-capabilities-word-7.mjs`**). Seed JSON and **`/proc/bare_os_features`** include **`bits7`**. **`BARE_OS_SEED_CAP_STRICT`** may require **`bits7`** when the stock seventh word is non-zero.
|
||||
10. **Seventh capability word (`bits7`)** — **`BARE_OS_KERNEL_FEATURES_STOCK_WORD_PEAR_CORESTORE_HRPC`** and `**BARE_OS_FEATURE7_***` add another full 32-bit word. **Word 6 bits 16–31** remain reserved for future sixth-word–scoped features; new coarse groups use **`bits7`** instead (seed RPC surface, proc JSON, boot policy v7, extension registry v4, Pear/Bare bridge stubs, VFS/env/git policy docs, initd/subprocess, worker/net, telemetry v6/OTel v4/audit v4, CI **`verify-kernel-capabilities-word-7.mjs`**). Seed JSON and **`/proc/bare_os_features`** include **`bits7`**. **`BARE_OS_SEED_CAP_STRICT`** may require **`bits7`** when the stock seventh word is non-zero.
|
||||
|
||||
11. **Eighth capability word (`bits8`)** — **`BARE_OS_KERNEL_FEATURES_STOCK_WORD_BARE_RUNTIME_PROTO_MUX`** and **`BARE_OS_FEATURE8_*`** add the eighth 32-bit word. **Word 7 high bits** remain reserved for future seventh-word–scoped features; **`bits8`** carries seed RPCs, **`/proc`** JSON, boot policy v8 (**`requireKernelCapabilitiesBareRuntimeProtoMux`**, **`requireBareRuntimeMin`**, **`denySeedRpcMethods`**, **`maxProtomuxChannelNameLength`**), extension registry v5 (**`compatPearBundleId`**), Pear/Bare structured-clone / protomux alias stubs, VFS/shell/git/curl parity, initd/subprocess/resume limits, worker **`ioproc:*`** / sandbox queue / delegate placeholders, HTTP/proxy/DNS/rocksdb proc hints, telemetry NDJSON v7 / OTel v5 / audit v5, and CI **`verify-kernel-capabilities-word-8.mjs`**. Seed JSON and **`/proc/bare_os_features`** include **`bits8`**. **`BARE_OS_SEED_CAP_STRICT`** requires **`bits8`** to cover the stock eighth word when it is non-zero.
|
||||
11. **Eighth capability word (`bits8`)** — **`BARE_OS_KERNEL_FEATURES_STOCK_WORD_BARE_RUNTIME_PROTO_MUX`** and `**BARE_OS_FEATURE8_***` add the eighth 32-bit word. **Word 7 high bits** remain reserved for future seventh-word–scoped features; **`bits8`** carries seed RPCs, **`/proc`** JSON, boot policy v8 (**`requireKernelCapabilitiesBareRuntimeProtoMux`**, **`requireBareRuntimeMin`**, **`denySeedRpcMethods`**, **`maxProtomuxChannelNameLength`**), extension registry v5 (**`compatPearBundleId`**), Pear/Bare structured-clone / protomux alias stubs, VFS/shell/git/curl parity, initd/subprocess/resume limits, worker **`ioproc:*`** / sandbox queue / delegate placeholders, HTTP/proxy/DNS/rocksdb proc hints, telemetry NDJSON v7 / OTel v5 / audit v5, and CI **`verify-kernel-capabilities-word-8.mjs`**. Seed JSON and **`/proc/bare_os_features`** include **`bits8`**. **`BARE_OS_SEED_CAP_STRICT`** requires **`bits8`** to cover the stock eighth word when it is non-zero.
|
||||
|
||||
12. **Ninth capability word (`bits9`)** — **`BARE_OS_KERNEL_FEATURES_STOCK_WORD_BARE_MODULE_CRYPTO_STAGING`** and **`BARE_OS_FEATURE9_*`** add the ninth 32-bit word. **Word 8 high bits** remain reserved for future eighth-word–scoped features; **`bits9`** carries Holepunch-aligned seed RPCs, **`/proc`** (bare-module, bare-crypto, pear-stage, …), boot policy v9 (**`requireKernelCapabilitiesBareModuleCryptoStaging`**, **`requirePearRuntimeRange`**, **`requireBareCryptoMin`**, **`denyBareModuleSpecifierPatterns`**, …), extension registry schema 6 surface, Pear/Bare bridge **`ctx`**, worker **`mediaproc:*`**, telemetry NDJSON schema 8 / OTel schema 6 / audit schema 6, and CI **`verify-kernel-capabilities-word-9.mjs`**. Seed JSON and **`/proc/bare_os_features`** include **`bits9`**. **`BARE_OS_SEED_CAP_STRICT`** requires **`bits9`** to cover the stock ninth word when it is non-zero.
|
||||
12. **Ninth capability word (`bits9`)** — **`BARE_OS_KERNEL_FEATURES_STOCK_WORD_BARE_MODULE_CRYPTO_STAGING`** and `**BARE_OS_FEATURE9_***` add the ninth 32-bit word. **Word 8 high bits** remain reserved for future eighth-word–scoped features; **`bits9`** carries Holepunch-aligned seed RPCs, **`/proc`** (bare-module, bare-crypto, pear-stage, …), boot policy v9 (**`requireKernelCapabilitiesBareModuleCryptoStaging`**, **`requirePearRuntimeRange`**, **`requireBareCryptoMin`**, **`denyBareModuleSpecifierPatterns`**, …), extension registry schema 6 surface, Pear/Bare bridge **`ctx`**, worker **`mediaproc:*`**, telemetry NDJSON schema 8 / OTel schema 6 / audit schema 6, and CI **`verify-kernel-capabilities-word-9.mjs`**. Seed JSON and **`/proc/bare_os_features`** include **`bits9`**. **`BARE_OS_SEED_CAP_STRICT`** requires **`bits9`** to cover the stock ninth word when it is non-zero.
|
||||
|
||||
13. **Tenth capability word (`bits10`)** — **`BARE_OS_KERNEL_FEATURES_STOCK_WORD_PEAR_INSPECT_LOGGER_TLS`** and **`BARE_OS_FEATURE10_*`** add the tenth 32-bit word. **Word 9 high bits** remain reserved for future ninth-word–scoped features; **`bits10`** carries additional seed RPCs, replication JSON adjuncts (bundle tier, autobase-discovery hint, token bucket v4, staging schema 7, peer firewall v5, compact ping v4, ready guard v4, mirror compaction v5, blind relay v3), **`/proc`** JSON (**`bare-os-proc-pear-inspect-logger-tls.js`**), **`bare_os_proc_index`** schema **6**, boot policy v10 (**`requireKernelCapabilitiesPearInspectLoggerTls`**, **`requireBareBootMin`**, **`denyBareRpcMethodPatterns`**, **`extensionSignerPinsV3`**, **`bootPhasesRequireLifecycleMinSchema`**, …), extension registry schema **7**, Pear/Bare bridge **`ctx`**, worker **`sysproc:*`**, telemetry NDJSON schema **9** / OTel **7** / audit **7**, and CI **`verify-kernel-capabilities-word-10.mjs`**. Seed JSON and **`/proc/bare_os_features`** include **`bits10`**. **`BARE_OS_SEED_CAP_STRICT`** requires **`bits10`** to cover the stock tenth word when it is non-zero (same pattern as **`bits9`**).
|
||||
13. **Tenth capability word (`bits10`)** — **`BARE_OS_KERNEL_FEATURES_STOCK_WORD_PEAR_INSPECT_LOGGER_TLS`** and `**BARE_OS_FEATURE10_***` add the tenth 32-bit word. **Word 9 high bits** remain reserved for future ninth-word–scoped features; **`bits10`** carries additional seed RPCs, replication JSON adjuncts (bundle tier, autobase-discovery hint, token bucket v4, staging schema 7, peer firewall v5, compact ping v4, ready guard v4, mirror compaction v5, blind relay v3), **`/proc`** JSON (**`bare-os-proc-pear-inspect-logger-tls.js`**), **`bare_os_proc_index`** schema **6**, boot policy v10 (**`requireKernelCapabilitiesPearInspectLoggerTls`**, **`requireBareBootMin`**, **`denyBareRpcMethodPatterns`**, **`extensionSignerPinsV3`**, **`bootPhasesRequireLifecycleMinSchema`**, …), extension registry schema **7**, Pear/Bare bridge **`ctx`**, worker `**sysproc:***`, telemetry NDJSON schema **9** / OTel **7** / audit **7**, and CI **`verify-kernel-capabilities-word-10.mjs`**. Seed JSON and **`/proc/bare_os_features`** include **`bits10`**. **`BARE_OS_SEED_CAP_STRICT`** requires **`bits10`** to cover the stock tenth word when it is non-zero (same pattern as **`bits9`**).
|
||||
|
||||
14. **Eleventh capability word (`hypercorePackHrpcLifecycle`)** — **`BARE_OS_KERNEL_FEATURES_STOCK_WORD_HYPERCORE_PACK_HRPC_LIFECYCLE`** and **`BARE_OS_FEATURE11_*`** add the eleventh 32-bit word. **`BARE_OS_KERNEL_FEATURE_BITS_DOC`** is **16** after the optional Protomux cap-channel bit (**`BARE_OS_FEATURE8_PROTOMUX_CAP_CHANNEL`**) and related proc/HRPC documentation bump (no legacy bit renumbering). This word groups protocol **`0.9.0`** (wire v2 **`kernelCapabilityWords`**), twenty seed RPC methods (replicate budget, drive graph, protomux backpressure, Pear matrix, bundle preload, … through mirror compaction v6), **`bare-os-proc-hypercore-pack-hrpc-lifecycle.js`** with twenty **`/proc/bare_os/*.json`** surfaces, **`bare_os_proc_index`** schema **7**, boot policy v11 (**`requireKernelCapabilitiesHypercorePackHrpcLifecycle`**, **`extensionSignerPinsV4`**, **`requireBarePackMin`**, **`requireBareAddonPolicyMin`**, **`maxHrpcAllowlistDepth`**, **`offlineLkgRequireHypercorePackHrpcLifecycle`**, merged **`denySeedRpcMethods`**), extension registry **`/proc`** payload schema **8**, **`ctx`** API **1.22.0** (**`bareOsAdvertisedKernelCapabilityWords`** / **`bareOsSeedKernelCapabilityWords`**), worker patterns **`cryptoproc:*`** / **`indexerproc:*`**, telemetry NDJSON **10** / OTel `**otlSchemaVersion` 8** / audit **8**, and CI **`verify-kernel-capabilities-word-11.mjs`**. Seed JSON and **`/proc/bare_os_features`** include **`kernelCapabilityWords.hypercorePackHrpcLifecycle`**. **`BARE_OS_SEED_CAP_STRICT`** requires that key to cover the stock eleventh word when it is non-zero.
|
||||
14. **Eleventh capability word (`hypercorePackHrpcLifecycle`)** — **`BARE_OS_KERNEL_FEATURES_STOCK_WORD_HYPERCORE_PACK_HRPC_LIFECYCLE`** and **`BARE_OS_FEATURE11_*`** add the eleventh 32-bit word. **`BARE_OS_KERNEL_FEATURE_BITS_DOC`** is **16** after the optional Protomux cap-channel bit (**`BARE_OS_FEATURE8_PROTOMUX_CAP_CHANNEL`**) and related proc/HRPC documentation bump (no legacy bit renumbering). This word groups protocol **`0.9.0`** (wire v2 **`kernelCapabilityWords`**), twenty seed RPC methods (replicate budget, drive graph, protomux backpressure, Pear matrix, bundle preload, … through mirror compaction v6), **`bare-os-proc-hypercore-pack-hrpc-lifecycle.js`** with twenty **`/proc/bare_os/*.json`** surfaces, **`bare_os_proc_index`** schema **7**, boot policy v11 (**`requireKernelCapabilitiesHypercorePackHrpcLifecycle`**, **`extensionSignerPinsV4`**, **`requireBarePackMin`**, **`requireBareAddonPolicyMin`**, **`maxHrpcAllowlistDepth`**, **`offlineLkgRequireHypercorePackHrpcLifecycle`**, merged **`denySeedRpcMethods`**), extension registry **`/proc`** payload schema **8**, **`ctx`** API **1.22.0** (**`bareOsAdvertisedKernelCapabilityWords`** / **`bareOsSeedKernelCapabilityWords`**), worker patterns `**cryptoproc:***` / `**indexerproc:*`**, telemetry NDJSON **10** / OTel `**otlSchemaVersion` 8** / audit **8**, and CI **`verify-kernel-capabilities-word-11.mjs`**. Seed JSON and **`/proc/bare_os_features`** include **`kernelCapabilityWords.hypercorePackHrpcLifecycle`**. **`BARE_OS_SEED_CAP_STRICT`** requires that key to cover the stock eleventh word when it is non-zero.
|
||||
|
||||
**Deprecation (unused bits):** once a bit is published in this ADR and **`kernel-capabilities-index.md`**, its numeric position is **stable**; if a feature is removed from the stock booter, the bit stays reserved (document as “unused / reserved”) until a major governance revision. **`BARE_OS_KERNEL_FEATURE_BITS_DOC`** bumps when semantics or this policy changes.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user