Files
bare-operating-system/kernel/bin/pathcap-verify
T
Raven Scott 071edccfb3 Expand bounded awk/expr/test toward Issue 7; refresh man, profile 1.0.18,
posix matrix/dashboard, and syscalls/process_table schema alignment (v8).

Booter: replication_operator_sketch/corestore hints, HRPC allowlist tests,
Protomux cap channel 65536-byte bound + export, Wasm posix_profile_peek,
swarm-disk and security_posture docs.

Coreutils/kernel: pkg-swarm-index pathCapabilityEnvelopeVerify on get;
pathcap-verify --trusted failure hint; rebuild bins and sync seeder.

Docs: KERNEL_CONTRACT, kernel-extensions, capabilities index, environment
appendix (warm-cache tuning, cap channel, Wasm env), handbook observability,
vault threat model (multisig), developer-guide ctx/HRPC/Wasm, DOCUMENTATION
release-checklist note, release-checklist optional tier1 drift.

Changelog maintenance in bare-os-booter and bare-os-protocol.
2026-04-05 23:01:54 -04:00

182 lines
5.0 KiB
Plaintext

/* BARE_OS_BIN_API 1.0.0 — bump when staged /bin script semantics change (see developer guide). */
/** Shared helpers for drive-resident /bin scripts (prepended before each command). */
function bareStdin(ctx) {
return typeof ctx.shellStdin === 'string' ? ctx.shellStdin : ''
}
/** @param {number} mode @param {'file' | 'directory' | 'symlink'} type */
function bareFormatModeString(mode, type) {
const typeChar = type === 'directory' ? 'd' : type === 'symlink' ? 'l' : '-'
const perm = mode & 0o777
const r = (bit) => (perm & bit ? 'r' : '-')
const w = (bit) => (perm & bit ? 'w' : '-')
const x = (bit) => (perm & bit ? 'x' : '-')
return (
typeChar +
r(0o400) +
w(0o200) +
x(0o100) +
r(0o040) +
w(0o020) +
x(0o010) +
r(0o004) +
w(0o002) +
x(0o001)
)
}
/** @param {number} mtimeMs @param {number} [nowMs] */
function bareFormatLsMtime(mtimeMs, nowMs) {
const now = nowMs != null ? nowMs : Date.now()
const d = new Date(mtimeMs)
const months = [
'Jan',
'Feb',
'Mar',
'Apr',
'May',
'Jun',
'Jul',
'Aug',
'Sep',
'Oct',
'Nov',
'Dec'
]
const mon = months[d.getMonth()]
const day = String(d.getDate()).padStart(2, ' ')
const sixMo = 180 * 24 * 3600 * 1000
if (Math.abs(now - mtimeMs) > sixMo) {
const yr = String(d.getFullYear()).padStart(4, ' ')
return mon + ' ' + day + ' ' + yr
}
const hh = String(d.getHours()).padStart(2, '0')
const mm = String(d.getMinutes()).padStart(2, '0')
return mon + ' ' + day + ' ' + hh + ':' + mm
}
/** @param {number} size */
function barePosixBlocks(size) {
return Math.ceil(Number(size) / 512) || 0
}
/**
* Raw stdout for NUL/binary when **`process.stdout.write`** is missing.
* If **`ctx.bareOsBinWrite(Uint8Array|string)`** is set (tests / host), use it.
* @param {Record<string, unknown>} ctx
* @param {string | Uint8Array} chunk
* @returns {boolean}
*/
function bareOsEmitRaw(ctx, chunk) {
if (typeof ctx.bareOsBinWrite === 'function') {
const b4 = ctx.b4a
const u8 =
typeof chunk === 'string'
? b4 && typeof b4.from === 'function'
? b4.from(chunk)
: new TextEncoder().encode(chunk)
: chunk
ctx.bareOsBinWrite(u8 instanceof Uint8Array ? u8 : new Uint8Array(u8))
return true
}
const w = globalThis.process?.stdout?.write
if (typeof w === 'function') {
w.call(globalThis.process.stdout, chunk)
return true
}
return false
}
/**
* Verify a path-capability envelope (JSON) using ctx.bareOsVerifyPathCapabilityEnvelope
* or bareOsVerifyPathCapabilityEnvelopeTrusted when --trusted (issuer pubkey allowlist on host).
* Usage: pathcap-verify FILE.json (or stdin JSON when FILE is -)
*/
async function run(ctx, argv) {
let path = ''
let trusted = false
for (let i = 1; i < argv.length; i++) {
const a = argv[i]
if (a === '--help' || a === '-h') {
ctx.console.log(
'usage: pathcap-verify [--trusted] FILE.json\n pathcap-verify - (read envelope JSON from stdin)\n --trusted uses ctx.bareOsVerifyPathCapabilityEnvelopeTrusted + BARE_OS_PATH_CAPABILITY_TRUSTED_PUBKEYS_HEX'
)
return
}
if (a === '--trusted') {
trusted = true
continue
}
if (!a.startsWith('-')) {
path = a
break
}
ctx.console.error('pathcap-verify: unknown option ' + a)
ctx.exitCode = 1
return
}
if (!path) {
ctx.console.error(
'usage: pathcap-verify FILE.json\n pathcap-verify -'
)
ctx.exitCode = 1
return
}
const verifyFn = trusted
? ctx.bareOsVerifyPathCapabilityEnvelopeTrusted
: ctx.bareOsVerifyPathCapabilityEnvelope
if (typeof verifyFn !== 'function') {
ctx.console.error(
'pathcap-verify: ctx.' +
(trusted
? 'bareOsVerifyPathCapabilityEnvelopeTrusted'
: 'bareOsVerifyPathCapabilityEnvelope') +
' missing'
)
ctx.exitCode = 1
return
}
let text = ''
try {
if (path === '-') {
text = String(ctx.shellStdin || '')
} else {
const buf = await ctx.vfs.readFile(path)
if (!buf || !buf.byteLength) {
ctx.console.error('pathcap-verify: empty or missing: ' + path)
ctx.exitCode = 1
return
}
text = ctx.b4a.toString(buf)
}
} catch (e) {
ctx.console.error(
'pathcap-verify: read failed: ' + ((e && e.message) || String(e))
)
ctx.exitCode = 1
return
}
let env
try {
env = JSON.parse(text)
} catch {
ctx.console.error('pathcap-verify: invalid JSON')
ctx.exitCode = 1
return
}
const r = verifyFn(env)
if (r.ok) {
ctx.console.log(
'ok prefix=' + r.payload.prefix + ' ops=' + r.payload.ops.join(',')
)
return
}
ctx.console.error('pathcap-verify: FAIL ' + r.reason)
if (trusted) {
ctx.console.error(
'pathcap-verify: hint: extend BARE_OS_PATH_CAPABILITY_TRUSTED_PUBKEYS_HEX with the issuer Ed25519 pubkey (64 hex) when the envelope is otherwise well-formed.'
)
}
ctx.exitCode = 1
}