/* BARE_OS_BIN_API 1.0.0 — bump when staged /bin script semantics change (see developer guide). */ /** Shared helpers for drive-resident /bin scripts (prepended before each command). */ function bareStdin(ctx) { return typeof ctx.shellStdin === 'string' ? ctx.shellStdin : '' } /** @param {number} mode @param {'file' | 'directory' | 'symlink'} type */ function bareFormatModeString(mode, type) { const typeChar = type === 'directory' ? 'd' : type === 'symlink' ? 'l' : '-' const perm = mode & 0o777 const r = (bit) => (perm & bit ? 'r' : '-') const w = (bit) => (perm & bit ? 'w' : '-') const x = (bit) => (perm & bit ? 'x' : '-') return ( typeChar + r(0o400) + w(0o200) + x(0o100) + r(0o040) + w(0o020) + x(0o010) + r(0o004) + w(0o002) + x(0o001) ) } /** @param {number} mtimeMs @param {number} [nowMs] */ function bareFormatLsMtime(mtimeMs, nowMs) { const now = nowMs != null ? nowMs : Date.now() const d = new Date(mtimeMs) const months = [ 'Jan', 'Feb', 'Mar', 'Apr', 'May', 'Jun', 'Jul', 'Aug', 'Sep', 'Oct', 'Nov', 'Dec' ] const mon = months[d.getMonth()] const day = String(d.getDate()).padStart(2, ' ') const sixMo = 180 * 24 * 3600 * 1000 if (Math.abs(now - mtimeMs) > sixMo) { const yr = String(d.getFullYear()).padStart(4, ' ') return mon + ' ' + day + ' ' + yr } const hh = String(d.getHours()).padStart(2, '0') const mm = String(d.getMinutes()).padStart(2, '0') return mon + ' ' + day + ' ' + hh + ':' + mm } /** @param {number} size */ function barePosixBlocks(size) { return Math.ceil(Number(size) / 512) || 0 } /** * Raw stdout for NUL/binary when **`process.stdout.write`** is missing. * If **`ctx.bareOsBinWrite(Uint8Array|string)`** is set (tests / host), use it. * @param {Record} ctx * @param {string | Uint8Array} chunk * @returns {boolean} */ function bareOsEmitRaw(ctx, chunk) { if (typeof ctx.bareOsBinWrite === 'function') { const b4 = ctx.b4a const u8 = typeof chunk === 'string' ? b4 && typeof b4.from === 'function' ? b4.from(chunk) : new TextEncoder().encode(chunk) : chunk ctx.bareOsBinWrite(u8 instanceof Uint8Array ? u8 : new Uint8Array(u8)) return true } const w = globalThis.process?.stdout?.write if (typeof w === 'function') { w.call(globalThis.process.stdout, chunk) return true } return false } /** Session env map (`vfs.env`, then `ctx.env`). Never throws. */ function bareOsEnv(ctx) { const v = ctx && ctx.vfs && ctx.vfs.env if (v && typeof v === 'object') return v const e = ctx && ctx.env if (e && typeof e === 'object') return e return {} } /** * Strict POSIX-ish decimal integer (no octal, no exponent, no empty). * @param {unknown} s * @returns {number} */ function bareOsParseDecInt(s) { const t = String(s == null ? '' : s).trim() if (!/^[+-]?(?:0|[1-9][0-9]*)$/.test(t)) return NaN const n = Number.parseInt(t, 10) return Number.isSafeInteger(n) ? n : NaN } /** @param {unknown} s */ function bareOsParseNonNegInt(s) { const n = bareOsParseDecInt(s) return n >= 0 ? n : NaN } /** * @param {Record} ctx * @param {string} name * @param {number} fallback * @param {number} [min] * @param {number} [max] */ function bareOsEnvInt(ctx, name, fallback, min, max) { const raw = bareOsEnv(ctx)[name] if (raw == null || raw === '') return fallback const n = Number.parseInt(String(raw), 10) if (!Number.isFinite(n)) return fallback let v = n if (min != null && v < min) v = min if (max != null && v > max) v = max return v } /** * @param {Record} ctx * @param {string} msg * @param {number} [code] */ function bareOsFail(ctx, msg, code) { if (msg) ctx.console.error(msg) ctx.exitCode = code == null ? 1 : code } /** @param {unknown} e */ function bareOsIsNotFoundErr(e) { const code = e && typeof e === 'object' ? e.code : '' if (code === 'ENOENT') return true const msg = String((e && e.message) || e || '') return /ENOENT|No such file|not found/i.test(msg) } /** * @param {Record} ctx * @param {unknown} buf * @returns {Uint8Array} */ function bareOsToU8(ctx, buf) { if (!buf) return new Uint8Array(0) if (buf instanceof Uint8Array) return buf if (ctx && ctx.b4a && typeof ctx.b4a.from === 'function') return ctx.b4a.from(buf) return new Uint8Array(buf) } /** @param {string} dir @param {string} name */ function bareOsJoinPath(dir, name) { const d = String(dir || '').replace(/\/+$/, '') const n = String(name || '').replace(/^\/+/, '') if (!d || d === '/') return '/' + n return d + '/' + n } /** @param {string} p */ function bareOsBaseName(p) { const t = String(p || '').replace(/\/+$/, '') if (!t || t === '/') return t === '/' ? '/' : '' const i = t.lastIndexOf('/') return i < 0 ? t : t.slice(i + 1) || t } /** @param {string} p */ function bareOsParentDir(p) { const t = String(p || '').replace(/\/+$/, '') || '/' if (t === '/') return '/' const i = t.lastIndexOf('/') return i <= 0 ? '/' : t.slice(0, i) || '/' } /** @param {string} p */ function bareOsNormPath(p) { return String(p || '').replace(/\/+$/, '') || '/' } /** * @param {Record} ctx * @param {string} p */ function bareOsResolvePath(ctx, p) { if (ctx && ctx.vfs && typeof ctx.vfs.resolveLogical === 'function') { try { return String(ctx.vfs.resolveLogical(p) || p) } catch { /* fall through */ } } return String(p || '') } /** * True when dest is src or lives under src (self-copy / self-move). * @param {Record} ctx * @param {string} src * @param {string} dest */ function bareOsDestInsideSrc(ctx, src, dest) { const s = bareOsNormPath(bareOsResolvePath(ctx, src)) const d = bareOsNormPath(bareOsResolvePath(ctx, dest)) if (s === d) return true if (s === '/') return d !== '/' return d === s || d.startsWith(s + '/') } const BARE_OS_B64_ALPH = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' /** @param {Uint8Array} u8 */ function bareOsB64Encode(u8) { let out = '' let i = 0 for (; i + 2 < u8.length; i += 3) { const n = (u8[i] << 16) | (u8[i + 1] << 8) | u8[i + 2] out += BARE_OS_B64_ALPH[(n >> 18) & 63] + BARE_OS_B64_ALPH[(n >> 12) & 63] + BARE_OS_B64_ALPH[(n >> 6) & 63] + BARE_OS_B64_ALPH[n & 63] } const rest = u8.length - i if (rest === 1) { const n = u8[i] << 16 out += BARE_OS_B64_ALPH[(n >> 18) & 63] + BARE_OS_B64_ALPH[(n >> 12) & 63] + '==' } else if (rest === 2) { const n = (u8[i] << 16) | (u8[i + 1] << 8) out += BARE_OS_B64_ALPH[(n >> 18) & 63] + BARE_OS_B64_ALPH[(n >> 12) & 63] + BARE_OS_B64_ALPH[(n >> 6) & 63] + '=' } return out } /** * RFC 4648 Base64 decode (also accepts URL-safe alphabet). Rejects junk. * @param {string} s * @returns {Uint8Array} */ function bareOsB64Decode(s) { const t = String(s).replace(/\s+/g, '') if (!t) return new Uint8Array(0) if (t.length % 4 === 1) throw new Error('invalid base64 length') let pad = 0 if (t.endsWith('==')) pad = 2 else if (t.endsWith('=')) pad = 1 const body = pad ? t.slice(0, t.length - pad) : t const bytes = [] let buf = 0 let bits = 0 for (let i = 0; i < body.length; i++) { const c = body[i] let v = BARE_OS_B64_ALPH.indexOf(c) if (v < 0) { if (c === '-') v = 62 else if (c === '_') v = 63 else throw new Error('invalid base64 character') } buf = (buf << 6) | v bits += 6 if (bits >= 8) { bits -= 8 bytes.push((buf >> bits) & 255) } } if (pad) { const want = Math.floor((body.length * 6) / 8) if (bytes.length > want) bytes.length = want } return new Uint8Array(bytes) } /** * @param {string} s * @returns {Uint8Array} */ function bareOsHexDecode(s) { const t = String(s).replace(/\s+/g, '') if (t.length % 2 !== 0) throw new Error('odd hex length') const out = new Uint8Array(t.length / 2) for (let i = 0; i < out.length; i++) { const pair = t.slice(i * 2, i * 2 + 2) if (!/^[0-9a-fA-F]{2}$/.test(pair)) throw new Error('invalid hex') out[i] = Number.parseInt(pair, 16) } return out } /** @param {Uint8Array} u8 */ function bareOsHexEncode(u8) { let s = '' for (let i = 0; i < u8.length; i++) s += u8[i].toString(16).padStart(2, '0') return s } /** * Shared GNU-style checksum FILE / stdin loop used by *sum commands. * @param {Record} ctx * @param {string[]} argv * @param {{ * cmd: string, * help?: string, * digest: (u8: Uint8Array) => string | Promise * }} opts */ async function bareChecksumRun(ctx, argv, opts) { const cmd = String(opts.cmd || 'checksum') const help = opts.help || 'usage: ' + cmd + ' [FILE]...\nWith no FILE, or when FILE is -, read standard input.' const digest = opts.digest const paths = [] for (let i = 1; i < argv.length; i++) { const a = argv[i] if (a === '-h' || a === '--help') { ctx.console.log(help) ctx.exitCode = 0 return } if (a.startsWith('-') && a !== '-') { ctx.console.error(cmd + ': unsupported option ' + a) ctx.exitCode = 1 return } paths.push(a) } const b4 = ctx.b4a async function one(name, buf) { const u8 = buf instanceof Uint8Array ? buf : new Uint8Array(buf) try { const hex = await digest(u8) ctx.console.log(hex + ' ' + name) } catch (e) { ctx.console.error(cmd + ': ' + (e.message || e)) ctx.exitCode = 1 } } if (!paths.length || (paths.length === 1 && paths[0] === '-')) { await one('-', b4.from(bareStdin(ctx))) return } for (const p of paths) { if (p === '-') { await one('-', b4.from(bareStdin(ctx))) continue } const b = await ctx.vfs.readFile(p) if (!b) { ctx.console.error(cmd + ': ' + p + ': No such file') ctx.exitCode = 1 continue } await one(p, b) } } /** * WebCrypto hex digest; throws the same missing-subtle message as the old *sum files. * @param {string} algo * @param {string} missingMsg * @returns {(u8: Uint8Array) => Promise} */ function bareSubtleHexDigest(algo, missingMsg) { return async function (u8) { const subtle = globalThis.crypto?.subtle if (!subtle || typeof subtle.digest !== 'function') { throw new Error(missingMsg) } const hash = await subtle.digest(algo, u8) return bareOsHexEncode(new Uint8Array(hash)) } } /** * Owner/group name → uid/gid used by chown / chgrp. * @param {string} spec * @param {Record} env * @returns {number | null} */ function parseGroupSpec(spec, env) { const s = String(spec).trim() if (!s) return null if (/^\d+$/.test(s)) { const n = Number.parseInt(s, 10) return Number.isFinite(n) ? n : null } const g = (env.GROUP || env.USER || 'guest').trim() if (s === 'root') return 0 if (s === 'guest' || s === 'nobody') return 65534 if (g && s === g) { const gid = Number.parseInt(String(env.GID ?? '65534'), 10) return Number.isFinite(gid) ? gid : 65534 } return null } /** * User name / numeric uid used by chown. * @param {string} spec * @param {Record} env * @returns {{ uid: number | null, gid: number | null }} */ function parseIdSpec(spec, env) { const s = String(spec).trim() if (!s) return { uid: null, gid: null } if (/^\d+$/.test(s)) { const n = Number.parseInt(s, 10) return { uid: Number.isFinite(n) ? n : null, gid: null } } const u = (env.USER || env.LOGNAME || '').trim() if (s === 'root') return { uid: 0, gid: null } if (s === 'guest' || s === 'nobody') return { uid: 65534, gid: null } if (u && s === u) { const uid = Number.parseInt(String(env.UID ?? '65534'), 10) return { uid: Number.isFinite(uid) ? uid : 65534, gid: null } } return { uid: null, gid: null } } async function readProcJson(ctx, p) { const vfs = ctx.vfs if (!vfs || typeof vfs.readFile !== 'function') return null try { const buf = await vfs.readFile(p) const t = ctx.b4a ? ctx.b4a.toString(buf) : String(buf) const j = JSON.parse(t.trim()) return j && typeof j === 'object' ? j : null } catch { return null } } async function run(ctx, argv) { let json = false for (let i = 1; i < argv.length; i++) { if (argv[i] === '--json') json = true } const features = await readProcJson(ctx, '/proc/bare_os/features') const caps = await readProcJson(ctx, '/proc/bare_os/capabilities.json') const program = await readProcJson(ctx, '/proc/bare_os/kernel_program.json') const polOn = ctx.env?.BARE_OS_BOOT_POLICY === '1' || ctx.env?.BARE_OS_BOOT_POLICY === 'true' const ok = !!(features && caps && program) const out = { schema: 1, ok, bootPolicyEnabled: polOn, ctxApiVersion: String(ctx.bareOsCtxApiVersion || ''), programProcSchema: program && typeof program.schema === 'number' ? program.schema : null, note: 'kernel-preflight: non-secret proc presence only; extend with policy file checks on trusted images.' } if (json) { ctx.console.log(JSON.stringify(out, null, 2)) } else { ctx.console.log(ok ? 'kernel-preflight: ok' : 'kernel-preflight: missing proc nodes') } if (!ok) ctx.exitCode = 1 }