Files
bare-operating-system/packages/bare-os-seeder/kernel/lib/bare
Raven Scott 27292f2ba6 Network/auth/delegate hardening
hdms
Added ls alias to list.
Made delegate failures explicit and nonzero in packages/bare-os-coreutils/src/hdms.js.
Added nonzero error exit in packages/bare-os-booter/lib/hdms-manager.js.
git-pear
Implemented clone subcommand routing to git clone in packages/bare-os-coreutils/src/git-pear.js.
trustctl
Added ls alias to status/policy output in packages/bare-os-coreutils/src/trustctl.js.
oidc-publish
Added explicit unknown-subcommand handling and publish subcommand compatibility in packages/bare-os-coreutils/src/oidc-publish.js.
ssh-keygen
Wrapped delegate invocation with explicit error propagation in packages/bare-os-coreutils/src/ssh-keygen.js.
Added success output on generated keypair in packages/bare-os-booter/lib/ssh-keygen-cli.js.
sshd
Added -t config test mode and explicit exit semantics in packages/bare-os-booter/lib/bare-openssh.js.
Ensured wrapper sets exit code consistently in packages/bare-os-openssh/src/sshd.js.
telnet
Changed connector preference to use net.createConnection first when available, then syscall bridge fallback, in packages/bare-os-coreutils/src/telnet.js.
crontab -e flow

Implemented edit flow with VISUAL/EDITOR fallback, unlocked-state checks, temp file handling, install, and cleanup in packages/bare-os-coreutils/src/crontab.js.
Shell/runtime hardcore semantics

Added numeric brace range expansion {1..5} in packages/bare-os-booter/lib/shell-glob.js.
Enabled brace expansion by default unless explicitly disabled.
Added normalization for inline brace-expression tokens in packages/bare-os-booter/lib/shell.js.
Added arithmetic command-form handling for (( ... )) in packages/bare-os-booter/lib/shell.js.
Extended shell signal trap dispatch support for USR1/USR2 (in addition to INT/TERM) in packages/bare-os-booter/index.js.
Hardened kill command delivery validation in packages/bare-os-coreutils/src/kill.js.
Regression tests

Added new: packages/bare-os-coreutils/test/hardcore-bugs.test.mjs.
Extended shell tests in packages/bare-os-booter/test.js for:
default cmdsub behavior,
brace range expansion,
arithmetic command form.
Existing regression files still pass after updates.
2026-04-27 08:54:50 -04:00
..
2026-04-24 08:39:22 -04:00
2026-04-03 23:21:30 -04:00
2026-04-25 23:18:44 -04:00

/lib/bare (system image)

Self-contained ctx.bare support on the system Hyperdrive: Holepunch Bare packages bundled as IIFE scripts the booter can execute without a traditional Node module graph on the drive.

Documentation: Developer guide ch.12 · bare-os-bare-libs package README.


On this page


What gets staged

  • bare-module-manifest.json — Copy of the booter manifest (same keys and packages as host resolution). Tells the runtime which logical module names exist.
  • manifest.json — Drive loader index: bundles lists IIFE paths that assign into globalThis.__bare_os_stdlib__; bundleStats counts attempted bundles; bundleDiagnostics lists each bundles byte size (same data as docs/audit/bundle-health.json).
  • bundles/*.js — One esbuild IIFE per catalog entry. The bare-libs build is fail-fast (esbuild errors abort; no stub placeholders). Stale ***.js** left from older tiered builds are pruned on each successful build. Regenerate with npm run build -w bare-os-bare-libs (updates docs/audit/bundle-health.json).

At boot the booter runs drive bundles first, then (unless BARE_OS_BARE_HOST_IMPORTS=0) fills any missing keys via host import() so development iterations can patch a single package without re-seeding the entire drive.


Boot order: drive bundles vs host imports

  1. Seeded bundles win for keys they actually populate — they are part of the trusted image, same class as /bin.
  2. Host imports run only for keys still missing after bundle evaluation, keeping local checkout workflows fast.
  3. Disabling host imports (BARE_OS_BARE_HOST_IMPORTS=0) approximates production Pear behavior where only the drive contents exist.

Environment toggles

The authoritative list is in the environment appendix. Names that operators mention most often alongside /lib/bare:

  • BARE_OS_BARE_HOST_IMPORTS — Set to 0 / false to forbid host **import()** fallback (drive-only resolution).
  • Related Pear ctx.bare toggles and HTTP allow lists are documented in PEAR-RUN.md and the booter package reference.

Trust model

Trusted image only: executing these bundles is equivalent to running seeded /bin utilities. Do not copy arbitrary third-party IIFEs into kernel/lib/bare/bundles/ without reviewing them the same way you would review a new setuid binary on a Unix system.


Regenerating bundles

  1. Edit packages/bare-os-booter/lib/bare-module-manifest.json or bundle sources under packages/bare-os-bare-libs/ as needed.
  2. Run npm run build -w bare-os-bare-libs — output lands in kernel/lib/bare/ (and CI expects packages/bare-os-seeder/kernel/ to match kernel/ byte-for-byte afterward).
  3. Mirror kernel/ into packages/bare-os-seeder/kernel/ (same tree) so scripts/verify-kernel-seeder-parity.mjs passes — typically rsync -a --delete kernel/ packages/bare-os-seeder/kernel/ from the repo root after init/bundle changes.
  4. Re-run the seeder so peers replicate the updated system drive.

Order with coreutils: from repo root, prefer npm run build -w bare-os-coreutils && npm run build -w bare-os-bare-libs && npm run bundle:kernel before parity check (matches root pretest).


When builds fail

Esbuild prints the failing ctxKey and package. Fix bare-module-manifest.json, adjust build.mjs (plugins, platform), or mark the entry optional / bundle: false when host-only resolution is intended. npm run smoke:bare-manifest guards required imports listed in the manifest smoke list.

CI: scripts/verify-bundle-health.mjs checks docs/audit/bundle-health.json against on-disk sizes; scripts/verify-bundle-markers.mjs and scripts/verify-bundle-throws.mjs gate incomplete-looking substrings / Error messages. scripts/sanitize-bare-bundles.mjs (run from this build) normalizes known upstream HTTP helpers, stream-base-class messages, and ICO encode paths so docs/audit/bundle-marker-allowlist.json and docs/audit/bundle-throw-allowlist.json stay empty.


Note: This file is copied to kernel/lib/bare/README.md (and the vendored seeder tree) by bare-os-bare-libs build. Links are written for the kernel/lib/bare/ path; verify-doc-links skips this template path because its on-disk location differs.