feat(booter): POSIX/P2P kernel roadmap — sockets, disk.os, VFS, docs

- Bump bareOsCtxApiVersion to 1.46.0 and POSIX profile 1.0.10; sync
  syscalls example, process table, compatibility matrix, CHANGELOGs.
- Socket FD bridge: passive SOCK_DGRAM bind/connect/send path, poll
  readiness; bareOsPosixPoll monotonic timeouts via bare-hrtime.
- disk.os: replication_operator_sketch schema 2; cap-gated
  replication_operator_intent + audit; enrich protomux proc JSON.
- VFS: route /.bare/** to personal drive; optional
  BARE_OS_PERSONAL_VAULT_INDEX_CACHE_MS readdir TTL cache.
- Boot policy: p2pAdmission (peerAllowlistHex, hyperswarmBootstrap) in
  schema + kernel init merge into ctx.env when unset.
- Coreutils/booter getconf: expand _SC_* coverage; shell wait -n under
  BARE_OS_SHELL_POSIX_MODE; seeder multisig verify → security_posture.
- Tests: vfs /.bare routing; test.bare-smoke + test:bare; bench schema 2.
- Docs: syscall-socket-contract, handbook/env/kernel-extensions,
  holepunch drift pretest note, vault threat model multisig section.
- Drop hyperbee from bare-os-booter package.json dependencies (if that
  change is part of this commit).
This commit is contained in:
Raven Scott
2026-04-05 01:46:17 -04:00
parent 15209b4837
commit ebee9576c8
62 changed files with 1235 additions and 547 deletions
+12
View File
@@ -687,6 +687,18 @@ async function applyBootPolicyFile(ctx) {
)
}
}
if (pol.p2pAdmission && typeof pol.p2pAdmission === 'object' && ctx.env) {
const p2p = /** @type {Record<string, unknown>} */ (pol.p2pAdmission)
const allow = typeof p2p.peerAllowlistHex === 'string' ? p2p.peerAllowlistHex.trim() : ''
if (allow && !String(ctx.env.BARE_OS_PEER_ALLOWLIST_HEX || '').trim()) {
ctx.env.BARE_OS_PEER_ALLOWLIST_HEX = allow
}
const boot =
typeof p2p.hyperswarmBootstrap === 'string' ? p2p.hyperswarmBootstrap.trim() : ''
if (boot && !String(ctx.env.HYPERSWARM_BOOTSTRAP || '').trim()) {
ctx.env.HYPERSWARM_BOOTSTRAP = boot
}
}
if (
typeof pol.minKernelCapabilitiesPrimary === 'number' &&
pol.minKernelCapabilitiesPrimary > 0