sh, diff/patch, sort, printf, find, test, getfacl/setfacl/xattr), expanded /proc and metrics (process table, syscalls, replication, net, security posture, worker budget, swarm/replication hints), initd DAG supervision metadata and richer restart journal telemetry, synthetic process groups via IPC (assignProcessGroup/signalProcessGroup) mirrored into process_table, optional kernel.ext.d incremental hot reload (BARE_OS_KERNEL_EXT_D_HOT_RELOAD) with reload audit NDJSON, features proc for hyperblobs dedup and systemd subset documentation, vault threat model doc plus posture fields for AEAD, Pear enclave pointer, account rotation continuity, and Ed25519 consistency across boot manifest / extensions / replication. Adds or extends tests and keeps kernel/ and packages/bare-os-seeder/kernel/ in parity; guest init is bundled from kernel/lib/init/init-main.js via bundle-kernel-init.
171 lines
4.5 KiB
Plaintext
171 lines
4.5 KiB
Plaintext
/* BARE_OS_BIN_API 1.0.0 — bump when staged /bin script semantics change (see developer guide). */
|
|
/** Shared helpers for drive-resident /bin scripts (prepended before each command). */
|
|
function bareStdin(ctx) {
|
|
return typeof ctx.shellStdin === 'string' ? ctx.shellStdin : ''
|
|
}
|
|
|
|
/** @param {number} mode @param {'file' | 'directory' | 'symlink'} type */
|
|
function bareFormatModeString(mode, type) {
|
|
const typeChar = type === 'directory' ? 'd' : type === 'symlink' ? 'l' : '-'
|
|
const perm = mode & 0o777
|
|
const r = (bit) => (perm & bit ? 'r' : '-')
|
|
const w = (bit) => (perm & bit ? 'w' : '-')
|
|
const x = (bit) => (perm & bit ? 'x' : '-')
|
|
return (
|
|
typeChar +
|
|
r(0o400) +
|
|
w(0o200) +
|
|
x(0o100) +
|
|
r(0o040) +
|
|
w(0o020) +
|
|
x(0o010) +
|
|
r(0o004) +
|
|
w(0o002) +
|
|
x(0o001)
|
|
)
|
|
}
|
|
|
|
/** @param {number} mtimeMs @param {number} [nowMs] */
|
|
function bareFormatLsMtime(mtimeMs, nowMs) {
|
|
const now = nowMs != null ? nowMs : Date.now()
|
|
const d = new Date(mtimeMs)
|
|
const months = [
|
|
'Jan',
|
|
'Feb',
|
|
'Mar',
|
|
'Apr',
|
|
'May',
|
|
'Jun',
|
|
'Jul',
|
|
'Aug',
|
|
'Sep',
|
|
'Oct',
|
|
'Nov',
|
|
'Dec'
|
|
]
|
|
const mon = months[d.getMonth()]
|
|
const day = String(d.getDate()).padStart(2, ' ')
|
|
const sixMo = 180 * 24 * 3600 * 1000
|
|
if (Math.abs(now - mtimeMs) > sixMo) {
|
|
const yr = String(d.getFullYear()).padStart(4, ' ')
|
|
return mon + ' ' + day + ' ' + yr
|
|
}
|
|
const hh = String(d.getHours()).padStart(2, '0')
|
|
const mm = String(d.getMinutes()).padStart(2, '0')
|
|
return mon + ' ' + day + ' ' + hh + ':' + mm
|
|
}
|
|
|
|
/** @param {number} size */
|
|
function barePosixBlocks(size) {
|
|
return Math.ceil(Number(size) / 512) || 0
|
|
}
|
|
|
|
/**
|
|
* Raw stdout for NUL/binary when **`process.stdout.write`** is missing.
|
|
* If **`ctx.bareOsBinWrite(Uint8Array|string)`** is set (tests / host), use it.
|
|
* @param {Record<string, unknown>} ctx
|
|
* @param {string | Uint8Array} chunk
|
|
* @returns {boolean}
|
|
*/
|
|
function bareOsEmitRaw(ctx, chunk) {
|
|
if (typeof ctx.bareOsBinWrite === 'function') {
|
|
const b4 = ctx.b4a
|
|
const u8 =
|
|
typeof chunk === 'string'
|
|
? b4 && typeof b4.from === 'function'
|
|
? b4.from(chunk)
|
|
: new TextEncoder().encode(chunk)
|
|
: chunk
|
|
ctx.bareOsBinWrite(u8 instanceof Uint8Array ? u8 : new Uint8Array(u8))
|
|
return true
|
|
}
|
|
const w = globalThis.process?.stdout?.write
|
|
if (typeof w === 'function') {
|
|
w.call(globalThis.process.stdout, chunk)
|
|
return true
|
|
}
|
|
return false
|
|
}
|
|
|
|
/**
|
|
* getfacl — show POSIX-style ACL text for a VFS path.
|
|
* When PATH.bare_acl exists, prints that file; otherwise synthesizes user/group/other
|
|
* triples from the path mode bits (see setfacl / handbook).
|
|
*/
|
|
|
|
/**
|
|
* @param {number} mode
|
|
* @param {number} shift
|
|
*/
|
|
function tripleFromMode(mode, shift) {
|
|
const b = (mode >> shift) & 7
|
|
const r = b & 4 ? 'r' : '-'
|
|
const w = b & 2 ? 'w' : '-'
|
|
const x = b & 1 ? 'x' : '-'
|
|
return r + w + x
|
|
}
|
|
|
|
async function run(ctx, argv) {
|
|
let compact = false
|
|
/** @type {string[]} */
|
|
const files = []
|
|
for (let i = 1; i < argv.length; i++) {
|
|
const a = argv[i]
|
|
if (a === '-c' || a === '--compact') {
|
|
compact = true
|
|
continue
|
|
}
|
|
if (a === '--help' || a === '-h') {
|
|
ctx.console.log('usage: getfacl [-c] FILE')
|
|
return
|
|
}
|
|
if (a.startsWith('-')) {
|
|
ctx.console.error('getfacl: unsupported option ' + a)
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
files.push(a)
|
|
}
|
|
if (files.length !== 1) {
|
|
ctx.console.error('usage: getfacl [-c] FILE')
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
const path = files[0]
|
|
const side = path + '.bare_acl'
|
|
try {
|
|
const st = await ctx.vfs.stat(path)
|
|
if (!st) {
|
|
ctx.console.error('getfacl: ' + path + ': No such file')
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
const raw = await ctx.vfs.readFile(side)
|
|
if (raw && raw.byteLength) {
|
|
const text = ctx.b4a.toString(raw)
|
|
ctx.console.log(text.replace(/\n$/, ''))
|
|
return
|
|
}
|
|
const mode = (st.mode || 0) & 0o777
|
|
const u = tripleFromMode(mode, 6)
|
|
const g = tripleFromMode(mode, 3)
|
|
const o = tripleFromMode(mode, 0)
|
|
const lines = compact
|
|
? ['user::' + u, 'group::' + g, 'other::' + o]
|
|
: [
|
|
'# file: ' + path,
|
|
'# owner: synthetic',
|
|
'# group: synthetic',
|
|
'user::' + u,
|
|
'group::' + g,
|
|
'other::' + o
|
|
]
|
|
ctx.console.log(lines.join('\n'))
|
|
} catch (e) {
|
|
ctx.console.error(
|
|
'getfacl: ' + path + ': ' + (e && e.message ? e.message : String(e))
|
|
)
|
|
ctx.exitCode = 1
|
|
}
|
|
}
|