Raven Scott
e2b721d19f
complete shell 100-item plan across parser, execution, security, and docs
...
Implement the full BareOS shell roadmap end-to-end, including grammar/tokenization
diagnostics, expansion/runtime hardening, execution graph tooling, builtins/job-control
stability, policy/sandbox controls, and release/traceability documentation updates.
- Add shell grammar baseline and diagnostics primitives:
- introduce `docs/reference/shell-grammar.md` with lexer modes and EBNF contract
- add rich diagnostic tokenizer output (mode + span metadata) via `tokenizeBareShellLineDetailed`
- export structured parse snapshot helpers (`bareOsShellAstSnapshot`) and shell error kinds
- add determinism coverage for tokenizer and AST snapshot outputs
- Harden expansion semantics and guardrails:
- enforce expansion byte budgets (`BARE_OS_SHELL_EXPANSION_MAX_BYTES`)
- add expansion trace hooks (`BARE_OS_SHELL_EXPANSION_TRACE`) with stage-level rows
- add expansion recursion depth limits (`BARE_OS_SHELL_EXPANSION_MAX_DEPTH`)
- tighten POSIX-mode arithmetic invalid-token diagnostics
- preserve declared expansion ordering and document it in code/docs
- Extend redirection/pipeline execution model:
- add normalized redirection planner (`planShellRedirections`) independent of side effects
- add execution graph builder/debug surface (`buildShellExecutionGraph`)
- support `<<-` operator in tokenizer/parser paths
- add pipeline stage timeout safety (`BARE_OS_SHELL_PIPELINE_STAGE_TIMEOUT_MS`)
- keep pipefail/pipestatus behavior verified with integration tests
- Improve builtins and control-flow reliability:
- expand `read` builtin support:
- `-r` raw mode
- `-d` single-char delimiter
- `-t` timeout semantics
- refine wait/jobs semantics:
- stable `jobs -l` parseable format expectations
- synthetic pid mapping (`wait 410x`) and `wait all` support
- keep trap registration/listing behavior deterministic and test-covered
- add trap signal dispatch helper (`dispatchShellTrapSignal`) with normalization
- Add security and policy enforcement hooks:
- command deny/allow policy gates:
- `BARE_OS_SHELL_DENY_COMMANDS`
- `BARE_OS_SHELL_ALLOW_COMMANDS`
- sandbox mode (`BARE_OS_SHELL_SANDBOX`) to block external command execution
- redirect path safety guard (`BARE_OS_SHELL_REDIRECT_GUARD`) for pseudo-path/traversal risks
- emit structured shell audit event rows (`ctx.shellAuditEvents`) for start/error/finish
- Improve interactive UX resilience:
- add prompt-hook timeout protection in fish readline:
- `resolveShellPromptHookSegment`
- env control `BARE_OS_SHELL_PROMPT_HOOK_TIMEOUT_MS`
- ensure prompt segment resolution is non-blocking and safe on timeout/error
- Add reliability/performance artifacts and shell fast lane:
- add `scripts/bench-shell-phases.mjs` for shell microbench sanity checks
- add `scripts/gen-shell-reliability-report.mjs` and generate reliability JSON artifact
- add root scripts:
- `test:shell-fast`
- `bench:shell`
- `report:shell-reliability`
- Expand shell-focused docs and traceability:
- add:
- `docs/reference/shell-unsupported-behavior.md`
- `docs/reference/shell-troubleshooting.md`
- add contributor guides:
- `developer-guide/17-how-to-add-shell-builtin.md`
- `developer-guide/18-how-to-add-shell-grammar-feature.md`
- update indexes/traceability/release gate docs:
- `docs/reference/README.md`
- `docs/reference/posix-issue7-traceability.md`
- `docs/reference/environment-and-posix-appendix.md`
- `docs/release-checklist.md`
- `developer-guide/README.md`
- `scripts/README.md`
- Add and update shell regression tests in `packages/bare-os-booter/test.js` for:
- tokenizer spans/modes and deterministic output
- AST snapshot schema/shape
- redirection planner and execution graph behavior
- expansion trace and strict arithmetic paths
- `<<-` support
- pipeline stage timeout handling
- `read` delimiter/raw/timeout semantics
- jobs/wait parseability and selection semantics
- trap dispatch and normalization behavior
- policy/sandbox/redirect-guard/audit-event pathways
Validation:
- `npm run test -w bare-os-booter`
- `npm run test:shell-bracket -w bare-os-booter`
- `npm run test:shell-fast`
- `npm run report:shell-reliability`
2026-04-26 23:17:20 -04:00
Raven Scott
ef5a30fbef
TextEncoder Fix
2026-04-26 22:34:04 -04:00
Raven Scott
d286ce19b5
chore(plan): cancel end-to-end seeder-to-booter smoke harness task
...
test(protocol): add deterministic MBR failover-key coverage
docs(protocol): align package-bare-os-protocol version to 0.9.1
test(booter): add MBR corruption and wrong-topic smoke fixtures
test(peer-seed): add strict pre-MBR bare_os.capabilities negotiation check
feat(seeder): validate BARE_OS_SEED_REQUIRE_MBR_LABELS
feat(seeder): validate BARE_OS_SEED_CAPABILITY_ATTESTATION_JSON schema
docs(boot-policy): add requireProtocolPackageMin 0.9.1 example
test(kernel): cover boot.policy denySeedRpcMethods behavior
test(protocol): add app/cap/chat/meshdrop channel compatibility fixture
test(swarm-disk): cover duplicate Protomux channel null-return path
test(protocol): add 11-word kernelCapabilityWords round-trip fixture
docs(schema): add mbr-layout schema and validate seeder examples
test(protocol): add topicKey() golden hash fixture
docs(trust): document block-0 trust assumptions in boot docs
feat(seeder): add discovery.flushed readiness logging
feat(booter): record peer discovery timings in boot-perf.json
feat(integration): add local testnet mode to integration lab smoke
test(booter): add Hyperswarm connection-budget env regression coverage
test(booter): add swarm plus Corestore suspend/resume integration coverage
feat(booter): mirror swarm ban events into host audit logs
feat(booter): add direct-peer boot via BARE_OS_BOOT_JOIN_PEER_HEX
feat(seeder): pass BARE_OS_SEED_MAX_PEERS to Hyperswarm
feat(seeder): log drive.version and discoveryKey at startup
test(booter): add Hyperdrive.checkout read-only boot probe coverage
feat(booter): prefetch /boot/init.js before kernel handoff
feat(booter): add optional /bin warm replication via downloadDiff
feat(seeder): add manifestPaths SHA-256 generation in stage-kernel-tree
test(peer-seed): cover helper-served block-0 after seeder exit
feat(protocol): add Protomux cork batching for initial channel sends
test(boot-graph): compare kernel/init labels with booter graph proc
docs(boot-policy): add v9-v11 schema examples
feat(release): add requireInitJsSha256 fixture generation step
test(vfs): add BARE_OS_VFS_SYSTEM_RO_ALIAS coverage
test(vfs): strengthen system-drive write-deny path coverage
feat(identity): add personal-drive namespace export/import docs and tests
test(booter): add guest-to-login warm cache invalidation regression
test(vfs): add guest deny coverage for /.bare sensitive paths
test(coreutils): add cross-drive mv failure injection coverage
test(vfs): add .bareos_empty round-trip coverage across mkdir/rmdir/cp/git-fs
test(vfs): add /dev/shm quota enforcement coverage
test(proc): add /proc/bare_os/index.json sortedness and schema checks
test(vfs): add warm read cache invalidation on replication growth
docs(ctx): document bareOsInvalidateWarmReadCaches(reason)
test(kernel): add BARE_OS_BOOT_DRY_RUN behavior coverage
docs(posix): add dashboard rows for all COREUTILS_COMMANDS
feat(curl): expand -w variables beyond http_code/url_effective/size_download
feat(wget): mark -N timestamping as explicit unsupported error
feat(curl): plumb mutual TLS cert/key intent to ctx.httpFetch metadata
feat(shuf): add deterministic seed mode via BARE_OS_SHUF_SEED
docs(sort): document -M month-sort as unsupported
feat(grep): add explicit -E and -G mode handling
test(sed): add Open Group Issue 7 golden fixtures
test(awk): add getline VFS regressions for missing/repeat/boundary cases
test(shell): add non-interactive here-doc coverage
test(shell): add trap delivery coverage for synthetic PIDs/job IDs
test(shell): add set -e compound-body behavior coverage
docs(shell): strengthen read builtin opt-in guidance
test(env): add Bare-runtime coverage for -S and --env-file
docs(man): add examples for pathcap-verify pkg-swarm-index corestorectl
test(identity): add account/vault backup-restore smoke coverage
feat(audit): add tamper detection verification for audit chain rows
test(peer-admission): cover strict empty allowlist deny behavior
test(peer-admission): add denylist precedence over allowlist coverage
test(peer-admission): add BARE_OS_PEER_REQUIRE_CAPS_JSON metadata checks
docs(identity): add trusted-key rotation example for path capabilities
feat(schema): tighten extensionSignerPinsV2-V4 hash validation
test(delegate): add allowlist negative cases for curl/wget/git/hrpc/systemctl
test(proc): extend /proc/self/environ redaction key coverage
docs(security): add peer-assisted block-0 mirroring threat-model notes
feat(bench): add boot budget trend output from real booter phases
test(baretop): align fixture coverage with /proc snapshot key set
test(metrics): validate /proc/bare_os/metrics.prom OpenMetrics shape
docs(ops): add structured seeder NDJSON examples
test(replication): add live stall-hint coverage for no_peers/length_unavailable/ok
docs(release): add corestore-snapshot workflow to checklist
docs(ops): add mirror-drive experiment utility to maintainer workflow
test(booter): add monitor progress coverage for replication live sketch
feat(seeder): validate DHT bootstrap address class JSON inputs
docs(network): add HYPERSWARM_BOOTSTRAP testnet operator guidance
chore(root): add deterministic test:integration script
docs(ci): add local CI runbook for no-.github environments
docs(release): add npm run test:bare after npm test
feat(verify): add protocol docs/package version parity checker
feat(verify): enforce feature-roadmap canonical path consistency
feat(lockfile-drift): add tier-1 strict fail option for mismatches
docs(lockfile-drift): add udx-native and blind-peering upgrade workflow notes
docs(cli-parity): add bare-fetch upstream issue tracking row
feat(bundle-health): generate per-tier bundle size regression thresholds
feat(doc-contracts): verify handbook references to current proc schema versions
feat(pretest): add validate-mermaid-syntax gate
feat(probe): add bare-runtime top-25 critical command lane
docs(protocol): update capability-word prose from bits..bits5 to current words
docs(two-drive): document /tmp /var/log and account-prefix routing
docs(security): add concise boot trust model page and links
docs(dev-guide): add P2P lab cookbook section
docs(dev-guide): add how-to for adding seed RPCs
docs(dev-guide): add how-to for adding /proc/bare_os nodes
docs(dev-guide): add /bin utility checklist for man/posix/build/parity/tests
docs(user-manual): add short What BareOS is not section
2026-04-26 22:28:21 -04:00
Raven Scott
a553a4e4a7
further shell updates
2026-04-26 16:24:57 -04:00
Raven Scott
d3001aba9c
Updates
2026-04-26 16:12:58 -04:00
Raven Scott
2dc388ffd0
Updates
2026-04-26 15:49:55 -04:00
Raven Scott
4cdd1569af
sh: add POSIX-like -c support and complete shell subset gaps
...
Implement sh -c COMMAND [NAME [ARG...]] in /bin/sh, add shell function
declarations/invocation support, expand export semantics (NAME, NAME=value, -p),
and make until/loop-control behavior available by default. Add focused shell
tests and update sh man-page option docs.
2026-04-26 15:28:29 -04:00
Raven Scott
194fbd2c67
fix(swarmtop): expose and render full peer identity/details from proc surfaces
2026-04-26 08:02:37 -04:00
Raven Scott
8c3d5f8795
feat(p2p): introduce shared p2p transport/service stack and launch swarmtop, meshdrop, taskmesh, peernote, and hypershell-board
2026-04-26 07:48:55 -04:00
Raven Scott
b1736b7a7a
booter: apply 20-point Holepunch resilience and observability upgrades
...
add grouped retry orchestration, duplicate arbitration hardening, and transport-aware peer scoring
expand IPC with readiness gates, soft backpressure, request deadlines, batching, and method circuit-breakers
strengthen worker/control-plane lifecycle via idempotent termination, orphan detection, and liveness checkpoint helpers
improve lifecycle correctness with state-machine + transactional hook infrastructure and adaptive quiesce utilities
enrich operator surfaces/tests for degraded readiness, crash-safe telemetry patterns, and contract-level regressions
2026-04-26 07:22:31 -04:00
Raven Scott
dcf07fbaa0
booter: harden lifecycle and IPC; add richer swarm/process observability
...
add deterministic connection arbitration, reconnect gating, and localhost multi-address fallback
introduce IPC request/response correlation, soft backpressure thresholds, readiness waits, and batch sends
add lifecycle state machine + transactional suspend/resume hooks + replication quiesce helper
enrich process/job lifecycle phases and add close/crash journaling hooks
extend metrics live surface with degraded readiness and aggregate pressure views
2026-04-26 07:15:34 -04:00
Raven Scott
d95c135dd9
booter updates
2026-04-26 07:05:24 -04:00
Raven Scott
47da0b8531
normalize initd state modeling and stabilize synthetic initd PID mapping
...
add IPC backpressure/drop telemetry and jittered swarm retry tiers
harden socket bridge timeout/lifecycle handling and replace recv polling with readiness signaling
improve shell background child isolation and worker offload fallback/output diagnostics
add var-log fast append path to reduce read-concat-write amplification
2026-04-26 06:57:07 -04:00
Raven Scott
dfcd36dc58
/proc/bare_os/initd_readiness.json schema 2
2026-04-26 06:44:02 -04:00
Raven Scott
09f164b8de
Change how login works
2026-04-26 06:19:47 -04:00
Raven Scott
30e6cfc2ff
Updates
2026-04-26 05:48:11 -04:00
Raven Scott
95c60bb8bf
Clear pending ghost suggestions before writing the submit newline so inline hints do not appear in scrollback as typed input.
...
Add a regression test for submitting `ls` when history suggests `ls /bin`.
2026-04-25 03:30:56 -04:00
Raven Scott
9a41136aea
Login Security
2026-04-25 02:59:32 -04:00
Raven Scott
4846c534fd
feat(terminal): align clear and fish TTY with xterm.js scrollback behavior
...
Add terminal-escapes.js with a canonical clear sequence (home, CSI 3J/2J,
SGR reset) and use it for fish ^L and fish-tty-repro. Match /bin/clear in
coreutils with the same sequence and a sync comment. Harden fish-readline
for bracketed paste, SS3/legacy CSI arrows, focus CSI, and common ~ keys;
widen stripAnsi CSI matching. Add brittle and coreutils tests for the
sequence and paste/focus/^L behavior.
2026-04-25 02:00:44 -04:00
Raven Scott
845e28f290
HS Updates
2026-04-24 09:05:52 -04:00
Raven Scott
bdf4b02b82
HS Updates
2026-04-24 08:54:16 -04:00
Raven Scott
b060f368f4
HS Updates
2026-04-24 08:39:22 -04:00
Raven Scott
54626ef873
booter: synthesize seed capabilities so more peers mirror MBR block 0
...
After a successful swarm boot, fill seedCapabilityInfo with stock
kernelCapabilityWords when the pre-MBR capabilities RPC was skipped,
failed, or lacked words, so peer system seed eligibility passes and
localRAM can serve block 0. Add BARE_OS_PEER_SEED_SYNTHETIC_CAPABILITIES
(opt-out) and BARE_OS_PEER_SEED_ADVERTISE_IMAGE_TIP_ID; document tip
propagation in env appendix, users manual, and handbook. Extend peer
seed tests.
2026-04-24 01:14:35 -04:00
Raven Scott
595a7d5910
Peer Seed Default
2026-04-23 21:26:28 -04:00
Raven Scott
d744cfe104
Allow Verified Version Peers to help boots
2026-04-23 21:24:04 -04:00
Raven Scott
300f011f01
Remove logger
2026-04-23 20:49:38 -04:00
Raven Scott
80485468f0
feat(booter): ephemeral port fallback on EADDRINUSE
...
Retry listen(0)/bind(0) when the preferred port is taken, gated by
BARE_OS_BIND_FALLBACK (default on; set 0/false for strict bind).
- Add lib/bare-os-bind-fallback.js and use it from bare-os-www-initd and
bare-openssh (including privilege-path + holesail actual port).
- POSIX socket bridge in index.js: TCP listen and UDP bind fallbacks.
- bare-holesail + bare-holesail-managed: retry Holesail ready(); persist
resolved listen port in managed state when it changes.
- Add test.bare-os-bind-fallback.js.
2026-04-23 20:39:50 -04:00
Raven Scott
72a5f3f2b8
fix(booter): tolerate UTF-8 BOM in /lib/bare/bare-module-lock.json
2026-04-22 22:24:23 -04:00
Raven Scott
4fa8c14079
When the host leaves these unset, the booter now sets
...
BARE_OS_SHELL_STREAMING=1, BARE_OS_SHELL_STREAMING_MULT=2,
BARE_OS_PIPELINE_MAX_BYTES (512 MiB), and BARE_OS_PIPELINE_MAX_LINES
(2M) so the high-throughput ~512 MiB burst profile does not require
pre-launch exports.
Align getconf Tier-1 statics with those bases; note legacy rc.profile
exports; refresh handbook, environment appendix, cookbook, and
bare-os-booter CHANGELOG.
2026-04-22 22:09:58 -04:00
Raven Scott
32446dfdef
feat(booter): tune 1GiB-class hosts — pipeline ceilings, IPC/MQ, rlimits
...
Raise simulated pipeline absolute caps (defaults 512 MiB / 2 M lines) via
BARE_OS_PIPELINE_ABS_MAX_BYTES and BARE_OS_PIPELINE_ABS_MAX_LINES so large
BARE_OS_PIPELINE_MAX_* values take effect after streaming multiplier.
Copy missing host env into the guest (BARE_OS_IPC_MAX_CHANNELS, POSIX MQ
defaults, abs caps, BARE_OS_VFS_MAX_OPEN). Add aliases:
BARE_OS_STREAMING_MULTIPLIER → BARE_OS_SHELL_STREAMING_MULT,
BARE_OS_TIMER_BUDGET_MS → BARE_OS_EXEC_LINE_BUDGET_MS,
BARE_OS_TELEMETRY_OTEL=1 → default OTL JSONL path.
Extend POSIX mq_open defaults and maxmsg ceiling; mirror BARE_OS_VFS_MAX_OPEN
to RLIMIT_NOFILE in /proc/bare_os/rlimits.json.
Document the profile in the Pear cookbook and refresh pipeline limits in the
handbook; extend runtime caps env key list.
2026-04-22 21:54:42 -04:00
Raven Scott
ff9a1f8888
OpenSSH Holesail
2026-04-22 21:01:08 -04:00
Raven Scott
790c95105e
Remove Log Config
2026-04-22 20:54:49 -04:00
Raven Scott
23172a2616
Stabilize Keys on login
2026-04-22 20:48:16 -04:00
Raven Scott
638b1141e4
Updates
2026-04-22 20:40:39 -04:00
Raven Scott
dd1003e3ae
tests
2026-04-22 20:32:40 -04:00
Raven Scott
d562c78ebb
updates
2026-04-22 20:26:24 -04:00
Raven Scott
c1fb344784
seed
2026-04-22 20:18:19 -04:00
Raven Scott
835de02ae5
tests
2026-04-22 20:06:18 -04:00
Raven Scott
45a8a3fde6
Tests
2026-04-22 19:48:28 -04:00
Raven Scott
c8e6b3b6d4
Update
2026-04-22 19:42:52 -04:00
Raven Scott
24f1067330
Tests
2026-04-22 19:39:30 -04:00
Raven Scott
c5256b9a0e
Fixes
2026-04-22 19:31:00 -04:00
Raven Scott
59af2a3dbf
Attempt 3
2026-04-22 19:17:59 -04:00
Raven Scott
1371a15314
Attempt 2
2026-04-22 19:11:53 -04:00
Raven Scott
c4e60fd83e
HS Fixes
2026-04-22 18:57:40 -04:00
Raven Scott
bc22a0d63e
Attempts to normalized Agent output when using OpenSSH Server
2026-04-22 17:11:42 -04:00
Raven Scott
50f90320f7
Continue resolve for www server
2026-04-22 16:00:34 -04:00
Raven Scott
594c9d2279
web server service detect sub directory index.html
2026-04-22 15:54:32 -04:00
Raven Scott
faba92f8b1
More Mux Fixes
2026-04-22 06:38:52 -04:00
Raven Scott
e4f28533cf
changes - may reverse
2026-04-22 06:25:02 -04:00