/* BARE_OS_BIN_API 1.0.0 — bump when staged /bin script semantics change (see developer guide). */ /** Shared helpers for drive-resident /bin scripts (prepended before each command). */ function bareStdin(ctx) { return typeof ctx.shellStdin === 'string' ? ctx.shellStdin : '' } /** @param {number} mode @param {'file' | 'directory' | 'symlink'} type */ function bareFormatModeString(mode, type) { const typeChar = type === 'directory' ? 'd' : type === 'symlink' ? 'l' : '-' const perm = mode & 0o777 const r = (bit) => (perm & bit ? 'r' : '-') const w = (bit) => (perm & bit ? 'w' : '-') const x = (bit) => (perm & bit ? 'x' : '-') return ( typeChar + r(0o400) + w(0o200) + x(0o100) + r(0o040) + w(0o020) + x(0o010) + r(0o004) + w(0o002) + x(0o001) ) } /** @param {number} mtimeMs @param {number} [nowMs] */ function bareFormatLsMtime(mtimeMs, nowMs) { const now = nowMs != null ? nowMs : Date.now() const d = new Date(mtimeMs) const months = [ 'Jan', 'Feb', 'Mar', 'Apr', 'May', 'Jun', 'Jul', 'Aug', 'Sep', 'Oct', 'Nov', 'Dec' ] const mon = months[d.getMonth()] const day = String(d.getDate()).padStart(2, ' ') const sixMo = 180 * 24 * 3600 * 1000 if (Math.abs(now - mtimeMs) > sixMo) { const yr = String(d.getFullYear()).padStart(4, ' ') return mon + ' ' + day + ' ' + yr } const hh = String(d.getHours()).padStart(2, '0') const mm = String(d.getMinutes()).padStart(2, '0') return mon + ' ' + day + ' ' + hh + ':' + mm } /** @param {number} size */ function barePosixBlocks(size) { return Math.ceil(Number(size) / 512) || 0 } /** * Raw stdout for NUL/binary when **`process.stdout.write`** is missing. * If **`ctx.bareOsBinWrite(Uint8Array|string)`** is set (tests / host), use it. * @param {Record} ctx * @param {string | Uint8Array} chunk * @returns {boolean} */ function bareOsEmitRaw(ctx, chunk) { if (typeof ctx.bareOsBinWrite === 'function') { const b4 = ctx.b4a const u8 = typeof chunk === 'string' ? b4 && typeof b4.from === 'function' ? b4.from(chunk) : new TextEncoder().encode(chunk) : chunk ctx.bareOsBinWrite(u8 instanceof Uint8Array ? u8 : new Uint8Array(u8)) return true } const w = globalThis.process?.stdout?.write if (typeof w === 'function') { w.call(globalThis.process.stdout, chunk) return true } return false } async function readProcJson(ctx, p) { const vfs = ctx.vfs if (!vfs || typeof vfs.readFile !== 'function') return null try { const buf = await vfs.readFile(p) const t = ctx.b4a ? ctx.b4a.toString(buf) : String(buf) const j = JSON.parse(t.trim()) return j && typeof j === 'object' ? j : null } catch { return null } } async function run(ctx, argv) { let json = false for (let i = 1; i < argv.length; i++) { if (argv[i] === '--json') json = true } const features = await readProcJson(ctx, '/proc/bare_os/features') const caps = await readProcJson(ctx, '/proc/bare_os/capabilities.json') const program = await readProcJson(ctx, '/proc/bare_os/kernel_program.json') const polOn = ctx.env?.BARE_OS_BOOT_POLICY === '1' || ctx.env?.BARE_OS_BOOT_POLICY === 'true' const ok = !!(features && caps && program) const out = { schema: 1, ok, bootPolicyEnabled: polOn, ctxApiVersion: String(ctx.bareOsCtxApiVersion || ''), programProcSchema: program && typeof program.schema === 'number' ? program.schema : null, note: 'kernel-preflight: non-secret proc presence only; extend with policy file checks on trusted images.' } if (json) { ctx.console.log(JSON.stringify(out, null, 2)) } else { ctx.console.log(ok ? 'kernel-preflight: ok' : 'kernel-preflight: missing proc nodes') } if (!ok) ctx.exitCode = 1 }