Files
bare-operating-system/packages/bare-os-seeder/kernel/bin/login
T
snxraven 3b0ada9a07
Release rolling / release (push) Successful in 25m40s
Condense commands (bot)
2026-08-23 14:11:27 -04:00

718 lines
20 KiB
Bash

/* BARE_OS_BIN_API 1.0.0 — bump when staged /bin script semantics change (see developer guide). */
/** Shared helpers for drive-resident /bin scripts (prepended before each command). */
function bareStdin(ctx) {
return typeof ctx.shellStdin === 'string' ? ctx.shellStdin : ''
}
/** @param {number} mode @param {'file' | 'directory' | 'symlink'} type */
function bareFormatModeString(mode, type) {
const typeChar = type === 'directory' ? 'd' : type === 'symlink' ? 'l' : '-'
const perm = mode & 0o777
const r = (bit) => (perm & bit ? 'r' : '-')
const w = (bit) => (perm & bit ? 'w' : '-')
const x = (bit) => (perm & bit ? 'x' : '-')
return (
typeChar +
r(0o400) +
w(0o200) +
x(0o100) +
r(0o040) +
w(0o020) +
x(0o010) +
r(0o004) +
w(0o002) +
x(0o001)
)
}
/** @param {number} mtimeMs @param {number} [nowMs] */
function bareFormatLsMtime(mtimeMs, nowMs) {
const now = nowMs != null ? nowMs : Date.now()
const d = new Date(mtimeMs)
const months = [
'Jan',
'Feb',
'Mar',
'Apr',
'May',
'Jun',
'Jul',
'Aug',
'Sep',
'Oct',
'Nov',
'Dec'
]
const mon = months[d.getMonth()]
const day = String(d.getDate()).padStart(2, ' ')
const sixMo = 180 * 24 * 3600 * 1000
if (Math.abs(now - mtimeMs) > sixMo) {
const yr = String(d.getFullYear()).padStart(4, ' ')
return mon + ' ' + day + ' ' + yr
}
const hh = String(d.getHours()).padStart(2, '0')
const mm = String(d.getMinutes()).padStart(2, '0')
return mon + ' ' + day + ' ' + hh + ':' + mm
}
/** @param {number} size */
function barePosixBlocks(size) {
return Math.ceil(Number(size) / 512) || 0
}
/**
* Raw stdout for NUL/binary when **`process.stdout.write`** is missing.
* If **`ctx.bareOsBinWrite(Uint8Array|string)`** is set (tests / host), use it.
* @param {Record<string, unknown>} ctx
* @param {string | Uint8Array} chunk
* @returns {boolean}
*/
function bareOsEmitRaw(ctx, chunk) {
if (typeof ctx.bareOsBinWrite === 'function') {
const b4 = ctx.b4a
const u8 =
typeof chunk === 'string'
? b4 && typeof b4.from === 'function'
? b4.from(chunk)
: new TextEncoder().encode(chunk)
: chunk
ctx.bareOsBinWrite(u8 instanceof Uint8Array ? u8 : new Uint8Array(u8))
return true
}
const w = globalThis.process?.stdout?.write
if (typeof w === 'function') {
w.call(globalThis.process.stdout, chunk)
return true
}
return false
}
/** Session env map (`vfs.env`, then `ctx.env`). Never throws. */
function bareOsEnv(ctx) {
const v = ctx && ctx.vfs && ctx.vfs.env
if (v && typeof v === 'object') return v
const e = ctx && ctx.env
if (e && typeof e === 'object') return e
return {}
}
/**
* Strict POSIX-ish decimal integer (no octal, no exponent, no empty).
* @param {unknown} s
* @returns {number}
*/
function bareOsParseDecInt(s) {
const t = String(s == null ? '' : s).trim()
if (!/^[+-]?(?:0|[1-9][0-9]*)$/.test(t)) return NaN
const n = Number.parseInt(t, 10)
return Number.isSafeInteger(n) ? n : NaN
}
/** @param {unknown} s */
function bareOsParseNonNegInt(s) {
const n = bareOsParseDecInt(s)
return n >= 0 ? n : NaN
}
/**
* @param {Record<string, unknown>} ctx
* @param {string} name
* @param {number} fallback
* @param {number} [min]
* @param {number} [max]
*/
function bareOsEnvInt(ctx, name, fallback, min, max) {
const raw = bareOsEnv(ctx)[name]
if (raw == null || raw === '') return fallback
const n = Number.parseInt(String(raw), 10)
if (!Number.isFinite(n)) return fallback
let v = n
if (min != null && v < min) v = min
if (max != null && v > max) v = max
return v
}
/**
* @param {Record<string, unknown>} ctx
* @param {string} msg
* @param {number} [code]
*/
function bareOsFail(ctx, msg, code) {
if (msg) ctx.console.error(msg)
ctx.exitCode = code == null ? 1 : code
}
/** @param {unknown} e */
function bareOsIsNotFoundErr(e) {
const code = e && typeof e === 'object' ? e.code : ''
if (code === 'ENOENT') return true
const msg = String((e && e.message) || e || '')
return /ENOENT|No such file|not found/i.test(msg)
}
/**
* @param {Record<string, unknown>} ctx
* @param {unknown} buf
* @returns {Uint8Array}
*/
function bareOsToU8(ctx, buf) {
if (!buf) return new Uint8Array(0)
if (buf instanceof Uint8Array) return buf
if (ctx && ctx.b4a && typeof ctx.b4a.from === 'function') return ctx.b4a.from(buf)
return new Uint8Array(buf)
}
/** @param {string} dir @param {string} name */
function bareOsJoinPath(dir, name) {
const d = String(dir || '').replace(/\/+$/, '')
const n = String(name || '').replace(/^\/+/, '')
if (!d || d === '/') return '/' + n
return d + '/' + n
}
/** @param {string} p */
function bareOsBaseName(p) {
const t = String(p || '').replace(/\/+$/, '')
if (!t || t === '/') return t === '/' ? '/' : ''
const i = t.lastIndexOf('/')
return i < 0 ? t : t.slice(i + 1) || t
}
/** @param {string} p */
function bareOsParentDir(p) {
const t = String(p || '').replace(/\/+$/, '') || '/'
if (t === '/') return '/'
const i = t.lastIndexOf('/')
return i <= 0 ? '/' : t.slice(0, i) || '/'
}
/** @param {string} p */
function bareOsNormPath(p) {
return String(p || '').replace(/\/+$/, '') || '/'
}
/**
* @param {Record<string, unknown>} ctx
* @param {string} p
*/
function bareOsResolvePath(ctx, p) {
if (ctx && ctx.vfs && typeof ctx.vfs.resolveLogical === 'function') {
try {
return String(ctx.vfs.resolveLogical(p) || p)
} catch {
/* fall through */
}
}
return String(p || '')
}
/**
* True when dest is src or lives under src (self-copy / self-move).
* @param {Record<string, unknown>} ctx
* @param {string} src
* @param {string} dest
*/
function bareOsDestInsideSrc(ctx, src, dest) {
const s = bareOsNormPath(bareOsResolvePath(ctx, src))
const d = bareOsNormPath(bareOsResolvePath(ctx, dest))
if (s === d) return true
if (s === '/') return d !== '/'
return d === s || d.startsWith(s + '/')
}
const BARE_OS_B64_ALPH =
'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/'
/** @param {Uint8Array} u8 */
function bareOsB64Encode(u8) {
let out = ''
let i = 0
for (; i + 2 < u8.length; i += 3) {
const n = (u8[i] << 16) | (u8[i + 1] << 8) | u8[i + 2]
out +=
BARE_OS_B64_ALPH[(n >> 18) & 63] +
BARE_OS_B64_ALPH[(n >> 12) & 63] +
BARE_OS_B64_ALPH[(n >> 6) & 63] +
BARE_OS_B64_ALPH[n & 63]
}
const rest = u8.length - i
if (rest === 1) {
const n = u8[i] << 16
out += BARE_OS_B64_ALPH[(n >> 18) & 63] + BARE_OS_B64_ALPH[(n >> 12) & 63] + '=='
} else if (rest === 2) {
const n = (u8[i] << 16) | (u8[i + 1] << 8)
out +=
BARE_OS_B64_ALPH[(n >> 18) & 63] +
BARE_OS_B64_ALPH[(n >> 12) & 63] +
BARE_OS_B64_ALPH[(n >> 6) & 63] +
'='
}
return out
}
/**
* RFC 4648 Base64 decode (also accepts URL-safe alphabet). Rejects junk.
* @param {string} s
* @returns {Uint8Array}
*/
function bareOsB64Decode(s) {
const t = String(s).replace(/\s+/g, '')
if (!t) return new Uint8Array(0)
if (t.length % 4 === 1) throw new Error('invalid base64 length')
let pad = 0
if (t.endsWith('==')) pad = 2
else if (t.endsWith('=')) pad = 1
const body = pad ? t.slice(0, t.length - pad) : t
const bytes = []
let buf = 0
let bits = 0
for (let i = 0; i < body.length; i++) {
const c = body[i]
let v = BARE_OS_B64_ALPH.indexOf(c)
if (v < 0) {
if (c === '-') v = 62
else if (c === '_') v = 63
else throw new Error('invalid base64 character')
}
buf = (buf << 6) | v
bits += 6
if (bits >= 8) {
bits -= 8
bytes.push((buf >> bits) & 255)
}
}
if (pad) {
const want = Math.floor((body.length * 6) / 8)
if (bytes.length > want) bytes.length = want
}
return new Uint8Array(bytes)
}
/**
* @param {string} s
* @returns {Uint8Array}
*/
function bareOsHexDecode(s) {
const t = String(s).replace(/\s+/g, '')
if (t.length % 2 !== 0) throw new Error('odd hex length')
const out = new Uint8Array(t.length / 2)
for (let i = 0; i < out.length; i++) {
const pair = t.slice(i * 2, i * 2 + 2)
if (!/^[0-9a-fA-F]{2}$/.test(pair)) throw new Error('invalid hex')
out[i] = Number.parseInt(pair, 16)
}
return out
}
/** @param {Uint8Array} u8 */
function bareOsHexEncode(u8) {
let s = ''
for (let i = 0; i < u8.length; i++) s += u8[i].toString(16).padStart(2, '0')
return s
}
/**
* Shared GNU-style checksum FILE / stdin loop used by *sum commands.
* @param {Record<string, unknown>} ctx
* @param {string[]} argv
* @param {{
* cmd: string,
* help?: string,
* digest: (u8: Uint8Array) => string | Promise<string>
* }} opts
*/
async function bareChecksumRun(ctx, argv, opts) {
const cmd = String(opts.cmd || 'checksum')
const help =
opts.help ||
'usage: ' +
cmd +
' [FILE]...\nWith no FILE, or when FILE is -, read standard input.'
const digest = opts.digest
const paths = []
for (let i = 1; i < argv.length; i++) {
const a = argv[i]
if (a === '-h' || a === '--help') {
ctx.console.log(help)
ctx.exitCode = 0
return
}
if (a.startsWith('-') && a !== '-') {
ctx.console.error(cmd + ': unsupported option ' + a)
ctx.exitCode = 1
return
}
paths.push(a)
}
const b4 = ctx.b4a
async function one(name, buf) {
const u8 = buf instanceof Uint8Array ? buf : new Uint8Array(buf)
try {
const hex = await digest(u8)
ctx.console.log(hex + ' ' + name)
} catch (e) {
ctx.console.error(cmd + ': ' + (e.message || e))
ctx.exitCode = 1
}
}
if (!paths.length || (paths.length === 1 && paths[0] === '-')) {
await one('-', b4.from(bareStdin(ctx)))
return
}
for (const p of paths) {
if (p === '-') {
await one('-', b4.from(bareStdin(ctx)))
continue
}
const b = await ctx.vfs.readFile(p)
if (!b) {
ctx.console.error(cmd + ': ' + p + ': No such file')
ctx.exitCode = 1
continue
}
await one(p, b)
}
}
/**
* WebCrypto hex digest; throws the same missing-subtle message as the old *sum files.
* @param {string} algo
* @param {string} missingMsg
* @returns {(u8: Uint8Array) => Promise<string>}
*/
function bareSubtleHexDigest(algo, missingMsg) {
return async function (u8) {
const subtle = globalThis.crypto?.subtle
if (!subtle || typeof subtle.digest !== 'function') {
throw new Error(missingMsg)
}
const hash = await subtle.digest(algo, u8)
return bareOsHexEncode(new Uint8Array(hash))
}
}
/**
* Owner/group name → uid/gid used by chown / chgrp.
* @param {string} spec
* @param {Record<string, string>} env
* @returns {number | null}
*/
function parseGroupSpec(spec, env) {
const s = String(spec).trim()
if (!s) return null
if (/^\d+$/.test(s)) {
const n = Number.parseInt(s, 10)
return Number.isFinite(n) ? n : null
}
const g = (env.GROUP || env.USER || 'guest').trim()
if (s === 'root') return 0
if (s === 'guest' || s === 'nobody') return 65534
if (g && s === g) {
const gid = Number.parseInt(String(env.GID ?? '65534'), 10)
return Number.isFinite(gid) ? gid : 65534
}
return null
}
/**
* User name / numeric uid used by chown.
* @param {string} spec
* @param {Record<string, string>} env
* @returns {{ uid: number | null, gid: number | null }}
*/
function parseIdSpec(spec, env) {
const s = String(spec).trim()
if (!s) return { uid: null, gid: null }
if (/^\d+$/.test(s)) {
const n = Number.parseInt(s, 10)
return { uid: Number.isFinite(n) ? n : null, gid: null }
}
const u = (env.USER || env.LOGNAME || '').trim()
if (s === 'root') return { uid: 0, gid: null }
if (s === 'guest' || s === 'nobody') return { uid: 65534, gid: null }
if (u && s === u) {
const uid = Number.parseInt(String(env.UID ?? '65534'), 10)
return { uid: Number.isFinite(uid) ? uid : 65534, gid: null }
}
return { uid: null, gid: null }
}
/**
* Plain-stream masked line input (same pattern as agent --config / bareAgentPromptSetupLine).
* Used by /bin/login so the Fish REPL is suspended and stdin/stdout are the TTY streams.
*/
/**
* @param {Record<string, unknown> | undefined} ctx
* @param {import('stream').Writable | undefined} out
* @param {string} s
*/
function bareLoginInteractiveWrite(ctx, out, s) {
const text =
ctx && ctx.bareOsPtyStdoutCrlf
? String(s).replace(/\r?\n/g, '\r\n')
: String(s)
if (out && typeof out.write === 'function') {
try {
out.write(text)
} catch {
/* ignore */
}
}
}
/**
* @param {import('stream').Readable} stdin
* @returns {Promise<string>}
*/
function bareLoginReadStreamLineOnce(stdin) {
return new Promise((resolve) => {
let acc = ''
/** @param {string | Uint8Array | Buffer} chunk */
function onData(chunk) {
let s = ''
if (typeof chunk === 'string') s = chunk
else if (chunk instanceof Uint8Array) s = new TextDecoder().decode(chunk)
else if (
typeof Buffer !== 'undefined' &&
typeof Buffer.isBuffer === 'function' &&
Buffer.isBuffer(chunk)
)
s = chunk.toString('utf8')
else s = String(chunk)
acc += s
const n = acc.indexOf('\n')
if (n >= 0) {
cleanup()
resolve(acc.slice(0, n).replace(/\r$/, ''))
}
}
function onEnd() {
cleanup()
resolve(acc.replace(/\r$/, ''))
}
function cleanup() {
stdin.removeListener('data', onData)
stdin.removeListener('end', onEnd)
stdin.removeListener('error', onEnd)
}
stdin.on('data', onData)
stdin.once('end', onEnd)
stdin.once('error', onEnd)
if (typeof stdin.resume === 'function') stdin.resume()
})
}
/**
* @param {Record<string, unknown>} ctx
* @param {import('stream').Readable} stdin
* @param {import('stream').Writable | undefined} stdout
* @returns {Promise<string>}
*/
function bareLoginReadMaskedLineOnce(ctx, stdin, stdout) {
const ttyIn = /** @type {{ setRawMode?: (v: boolean) => void, isTTY?: boolean }} */ (
stdin
)
if (!ttyIn || typeof ttyIn.setRawMode !== 'function' || !ttyIn.isTTY) {
return bareLoginReadStreamLineOnce(stdin)
}
return new Promise((resolve, reject) => {
/** @type {string[]} */
const chars = []
let done = false
/** @param {string | Uint8Array | Buffer} chunk */
function onData(chunk) {
if (done) return
let s = ''
if (typeof chunk === 'string') s = chunk
else if (chunk instanceof Uint8Array) s = new TextDecoder().decode(chunk)
else if (
typeof Buffer !== 'undefined' &&
typeof Buffer.isBuffer === 'function' &&
Buffer.isBuffer(chunk)
) {
s = chunk.toString('utf8')
} else s = String(chunk)
for (const ch of s) {
const code = ch.charCodeAt(0)
if (ch === '\r' || ch === '\n') {
finish(true)
return
}
if (ch === '\u0003') {
finish(false, new Error('interrupted'))
return
}
if (ch === '\u007f' || ch === '\b') {
if (chars.length) {
chars.pop()
bareLoginInteractiveWrite(ctx, stdout, '\b \b')
}
continue
}
if (code >= 32 && code !== 127) {
chars.push(ch)
bareLoginInteractiveWrite(ctx, stdout, '*')
}
}
}
/** @param {boolean} ok @param {Error} [err] */
function finish(ok, err) {
if (done) return
done = true
cleanup()
if (ok) resolve(chars.join(''))
else reject(err || new Error('masked_input_failed'))
}
function cleanup() {
stdin.removeListener('data', onData)
stdin.removeListener('end', onEnd)
stdin.removeListener('error', onErr)
try {
ttyIn.setRawMode(false)
} catch {
/* ignore */
}
bareLoginInteractiveWrite(ctx, stdout, '\n')
}
function onEnd() {
finish(true)
}
/** @param {unknown} e */
function onErr(e) {
const msg =
e && typeof e === 'object' && 'message' in e ? String(e.message) : String(e)
finish(false, new Error(msg))
}
try {
ttyIn.setRawMode(true)
} catch {
return resolve('')
}
stdin.on('data', onData)
stdin.once('end', onEnd)
stdin.once('error', onErr)
if (typeof stdin.resume === 'function') stdin.resume()
})
}
/**
* @param {Record<string, unknown>} ctx
* @param {string} prompt
* @returns {Promise<string>}
*/
async function bareLoginPromptMaskedLine(ctx, prompt) {
const stdin = /** @type {import('stream').Readable | undefined} */ (
ctx.replStdin || ctx.stdin
)
const stdout = /** @type {import('stream').Writable | undefined} */ (
ctx.replStdout || ctx.stdout
)
if (!stdin || typeof stdin.on !== 'function') {
throw new Error('login: stdin stream unavailable (need an interactive TTY)')
}
bareLoginInteractiveWrite(ctx, stdout, '\x1b[?25h\x1b[0m' + prompt)
return bareLoginReadMaskedLineOnce(ctx, stdin, stdout)
}
async function run(ctx, argv) {
const argv0 = argv[0] || 'login'
const args = argv.slice(1)
if (args.includes('-h') || args.includes('--help')) {
ctx.console.log(
'usage: ' +
argv0 +
' [--new]\n\n' +
'Unlock or register your identity. Run this command with no passphrase on the line;\n' +
'then type your passphrase at the prompt (hidden). A passphrase may be several words.\n' +
'Passphrases must not be given as command-line arguments (they would appear in shell history).\n\n' +
' --new register a new identity instead of unlocking an existing one.'
)
ctx.exitCode = 0
return
}
let createNew = false
if (args[0] === '--new') {
createNew = true
args.shift()
}
if (args.length > 0) {
ctx.console.error(
'login: passphrase must not be given on the command line (it would appear in shell history).'
)
ctx.console.error('Run: login' + (createNew ? ' --new' : ''))
ctx.console.error(
'Then type your passphrase at the prompt. It may be multiple words; typing is hidden.'
)
ctx.exitCode = 1
return
}
const reg = ctx.applyRegister
const unlock = ctx.applyUnlock
if (typeof reg !== 'function' || typeof unlock !== 'function') {
ctx.console.error('login: not supported in this environment')
ctx.exitCode = 1
return
}
const stdin = ctx.replStdin || ctx.stdin
const stdout = ctx.replStdout || ctx.stdout
const tty = /** @type {{ isTTY?: boolean }} */ (stdin)
if (
!stdin ||
typeof stdin.on !== 'function' ||
!tty.isTTY ||
!stdout ||
typeof stdout.write !== 'function'
) {
ctx.console.error(
'login: needs an interactive TTY (same as agent --config). Run from the shell prompt on a terminal.'
)
ctx.exitCode = 1
return
}
let suspended = false
try {
if (typeof ctx.suspendReplForSubprocess === 'function') {
ctx.suspendReplForSubprocess()
suspended = true
}
ctx.console.log(
createNew
? 'Creating a new identity. Choose a passphrase (multiple words allowed); typing is hidden.'
: 'Unlocking. Enter your passphrase (multiple words allowed); typing is hidden.'
)
let passphrase
try {
passphrase = await bareLoginPromptMaskedLine(
ctx,
createNew ? 'New passphrase: ' : 'Passphrase: '
)
} catch (e) {
ctx.console.error((e && e.message) || String(e))
ctx.exitCode = 1
return
}
if (!String(passphrase || '').trim()) {
ctx.console.error('login: empty passphrase')
ctx.exitCode = 1
return
}
try {
if (createNew) await reg.call(ctx, String(passphrase))
else await unlock.call(ctx, String(passphrase))
ctx.exitCode = 0
} catch (err) {
ctx.console.error(err?.message ?? String(err))
ctx.exitCode = 1
}
} finally {
if (suspended && typeof ctx.resumeReplAfterSubprocess === 'function') {
ctx.resumeReplAfterSubprocess()
}
}
}