/* BARE_OS_BIN_API 1.0.0 — bump when staged /bin script semantics change (see developer guide). */ /** Shared helpers for drive-resident /bin scripts (prepended before each command). */ function bareStdin(ctx) { return typeof ctx.shellStdin === 'string' ? ctx.shellStdin : '' } /** @param {number} mode @param {'file' | 'directory' | 'symlink'} type */ function bareFormatModeString(mode, type) { const typeChar = type === 'directory' ? 'd' : type === 'symlink' ? 'l' : '-' const perm = mode & 0o777 const r = (bit) => (perm & bit ? 'r' : '-') const w = (bit) => (perm & bit ? 'w' : '-') const x = (bit) => (perm & bit ? 'x' : '-') return ( typeChar + r(0o400) + w(0o200) + x(0o100) + r(0o040) + w(0o020) + x(0o010) + r(0o004) + w(0o002) + x(0o001) ) } /** @param {number} mtimeMs @param {number} [nowMs] */ function bareFormatLsMtime(mtimeMs, nowMs) { const now = nowMs != null ? nowMs : Date.now() const d = new Date(mtimeMs) const months = [ 'Jan', 'Feb', 'Mar', 'Apr', 'May', 'Jun', 'Jul', 'Aug', 'Sep', 'Oct', 'Nov', 'Dec' ] const mon = months[d.getMonth()] const day = String(d.getDate()).padStart(2, ' ') const sixMo = 180 * 24 * 3600 * 1000 if (Math.abs(now - mtimeMs) > sixMo) { const yr = String(d.getFullYear()).padStart(4, ' ') return mon + ' ' + day + ' ' + yr } const hh = String(d.getHours()).padStart(2, '0') const mm = String(d.getMinutes()).padStart(2, '0') return mon + ' ' + day + ' ' + hh + ':' + mm } /** @param {number} size */ function barePosixBlocks(size) { return Math.ceil(Number(size) / 512) || 0 } /** * Raw stdout for NUL/binary when **`process.stdout.write`** is missing. * If **`ctx.bareOsBinWrite(Uint8Array|string)`** is set (tests / host), use it. * @param {Record} ctx * @param {string | Uint8Array} chunk * @returns {boolean} */ function bareOsEmitRaw(ctx, chunk) { if (typeof ctx.bareOsBinWrite === 'function') { const b4 = ctx.b4a const u8 = typeof chunk === 'string' ? b4 && typeof b4.from === 'function' ? b4.from(chunk) : new TextEncoder().encode(chunk) : chunk ctx.bareOsBinWrite(u8 instanceof Uint8Array ? u8 : new Uint8Array(u8)) return true } const w = globalThis.process?.stdout?.write if (typeof w === 'function') { w.call(globalThis.process.stdout, chunk) return true } return false } /** * Verify a path-capability envelope (JSON) using ctx.bareOsVerifyPathCapabilityEnvelope * or bareOsVerifyPathCapabilityEnvelopeTrusted when --trusted (issuer pubkey allowlist on host). * Usage: pathcap-verify FILE.json (or stdin JSON when FILE is -) */ async function run(ctx, argv) { let path = '' let trusted = false for (let i = 1; i < argv.length; i++) { const a = argv[i] if (a === '--help' || a === '-h') { ctx.console.log( 'usage: pathcap-verify [--trusted] FILE.json\n pathcap-verify - (read envelope JSON from stdin)\n --trusted uses ctx.bareOsVerifyPathCapabilityEnvelopeTrusted + BARE_OS_PATH_CAPABILITY_TRUSTED_PUBKEYS_HEX' ) return } if (a === '--trusted') { trusted = true continue } if (!a.startsWith('-')) { path = a break } ctx.console.error('pathcap-verify: unknown option ' + a) ctx.exitCode = 1 return } if (!path) { ctx.console.error( 'usage: pathcap-verify FILE.json\n pathcap-verify -' ) ctx.exitCode = 1 return } const verifyFn = trusted ? ctx.bareOsVerifyPathCapabilityEnvelopeTrusted : ctx.bareOsVerifyPathCapabilityEnvelope if (typeof verifyFn !== 'function') { ctx.console.error( 'pathcap-verify: ctx.' + (trusted ? 'bareOsVerifyPathCapabilityEnvelopeTrusted' : 'bareOsVerifyPathCapabilityEnvelope') + ' missing' ) ctx.exitCode = 1 return } let text = '' try { if (path === '-') { text = String(ctx.shellStdin || '') } else { const buf = await ctx.vfs.readFile(path) if (!buf || !buf.byteLength) { ctx.console.error('pathcap-verify: empty or missing: ' + path) ctx.exitCode = 1 return } text = ctx.b4a.toString(buf) } } catch (e) { ctx.console.error( 'pathcap-verify: read failed: ' + ((e && e.message) || String(e)) ) ctx.exitCode = 1 return } let env try { env = JSON.parse(text) } catch { ctx.console.error('pathcap-verify: invalid JSON') ctx.exitCode = 1 return } const r = verifyFn(env) if (r.ok) { ctx.console.log( 'ok prefix=' + r.payload.prefix + ' ops=' + r.payload.ops.join(',') ) return } ctx.console.error('pathcap-verify: FAIL ' + r.reason) if (trusted) { ctx.console.error( 'pathcap-verify: hint: extend BARE_OS_PATH_CAPABILITY_TRUSTED_PUBKEYS_HEX with the issuer Ed25519 pubkey (64 hex) when the envelope is otherwise well-formed.' ) } ctx.exitCode = 1 }