NDJSON audit + rate limit; env passthrough and handbook/appendix/docs - /proc/bare_os/security_posture.json schema 4: vaultCryptoPrimitives, bareCryptoReportedVersion, expanded peerAdmission - /proc/bare_os_features: pearIpcConservativeAdvertisement (names only) - Syscall select returns pollClock with timeout; coreutils test -u/-g/-k - Host env: BARE_OS_CTX_BARE_SUBPROCESS_SPAWN, BARE_OS_REPLICATION_PEER_PRIORITY_JSON, peer audit keys - Placeholder scan: rename expandCmdsubstEmbedded; sendmsg wording - Docs: vault threat model, preface Mermaid, protocol/changelog, posix matrix, holepunch clone audit refresh, developer-guide/kernel-program Wasm - ctx.d.ts + gen-ctx-client-helper; booter CHANGELOG maintenance notes
275 lines
9.3 KiB
Plaintext
275 lines
9.3 KiB
Plaintext
/* BARE_OS_BIN_API 1.0.0 — bump when staged /bin script semantics change (see developer guide). */
|
|
/** Shared helpers for drive-resident /bin scripts (prepended before each command). */
|
|
function bareStdin(ctx) {
|
|
return typeof ctx.shellStdin === 'string' ? ctx.shellStdin : ''
|
|
}
|
|
|
|
/** @param {number} mode @param {'file' | 'directory' | 'symlink'} type */
|
|
function bareFormatModeString(mode, type) {
|
|
const typeChar = type === 'directory' ? 'd' : type === 'symlink' ? 'l' : '-'
|
|
const perm = mode & 0o777
|
|
const r = (bit) => (perm & bit ? 'r' : '-')
|
|
const w = (bit) => (perm & bit ? 'w' : '-')
|
|
const x = (bit) => (perm & bit ? 'x' : '-')
|
|
return (
|
|
typeChar +
|
|
r(0o400) +
|
|
w(0o200) +
|
|
x(0o100) +
|
|
r(0o040) +
|
|
w(0o020) +
|
|
x(0o010) +
|
|
r(0o004) +
|
|
w(0o002) +
|
|
x(0o001)
|
|
)
|
|
}
|
|
|
|
/** @param {number} mtimeMs @param {number} [nowMs] */
|
|
function bareFormatLsMtime(mtimeMs, nowMs) {
|
|
const now = nowMs != null ? nowMs : Date.now()
|
|
const d = new Date(mtimeMs)
|
|
const months = [
|
|
'Jan',
|
|
'Feb',
|
|
'Mar',
|
|
'Apr',
|
|
'May',
|
|
'Jun',
|
|
'Jul',
|
|
'Aug',
|
|
'Sep',
|
|
'Oct',
|
|
'Nov',
|
|
'Dec'
|
|
]
|
|
const mon = months[d.getMonth()]
|
|
const day = String(d.getDate()).padStart(2, ' ')
|
|
const sixMo = 180 * 24 * 3600 * 1000
|
|
if (Math.abs(now - mtimeMs) > sixMo) {
|
|
const yr = String(d.getFullYear()).padStart(4, ' ')
|
|
return mon + ' ' + day + ' ' + yr
|
|
}
|
|
const hh = String(d.getHours()).padStart(2, '0')
|
|
const mm = String(d.getMinutes()).padStart(2, '0')
|
|
return mon + ' ' + day + ' ' + hh + ':' + mm
|
|
}
|
|
|
|
/** @param {number} size */
|
|
function barePosixBlocks(size) {
|
|
return Math.ceil(Number(size) / 512) || 0
|
|
}
|
|
|
|
/**
|
|
* Raw stdout for NUL/binary when **`process.stdout.write`** is missing.
|
|
* If **`ctx.bareOsBinWrite(Uint8Array|string)`** is set (tests / host), use it.
|
|
* @param {Record<string, unknown>} ctx
|
|
* @param {string | Uint8Array} chunk
|
|
* @returns {boolean}
|
|
*/
|
|
function bareOsEmitRaw(ctx, chunk) {
|
|
if (typeof ctx.bareOsBinWrite === 'function') {
|
|
const b4 = ctx.b4a
|
|
const u8 =
|
|
typeof chunk === 'string'
|
|
? b4 && typeof b4.from === 'function'
|
|
? b4.from(chunk)
|
|
: new TextEncoder().encode(chunk)
|
|
: chunk
|
|
ctx.bareOsBinWrite(u8 instanceof Uint8Array ? u8 : new Uint8Array(u8))
|
|
return true
|
|
}
|
|
const w = globalThis.process?.stdout?.write
|
|
if (typeof w === 'function') {
|
|
w.call(globalThis.process.stdout, chunk)
|
|
return true
|
|
}
|
|
return false
|
|
}
|
|
|
|
/**
|
|
* Subset of POSIX.1-2017 getconf — fixed values for Bare OS (no host sysconf).
|
|
* Unknown names exit with status 1 (matches common getconf for invalid var).
|
|
* Live pathconf: **`getconf NAME /absolute/path`** delegates to **`ctx.bareOsPathconf`** when set.
|
|
*/
|
|
|
|
const CONF = {
|
|
PATH_MAX: '4096',
|
|
NAME_MAX: '255',
|
|
/** POSIX minimum for ARG_MAX; Bare uses a conservative cap for runBinCommand argv. */
|
|
_POSIX_ARG_MAX: '4096',
|
|
ARG_MAX: '262144',
|
|
LINE_MAX: '2048',
|
|
/** POSIX.1-2008 */
|
|
_POSIX_VERSION: '200809',
|
|
_POSIX2_VERSION: '200809',
|
|
NGROUPS_MAX: '32',
|
|
OPEN_MAX: '256',
|
|
STREAM_MAX: '256',
|
|
TZNAME_MAX: '32',
|
|
_POSIX_CHOWN_RESTRICTED: '1',
|
|
_POSIX_NO_TRUNC: '1',
|
|
_POSIX_VDISABLE: '0',
|
|
_POSIX_JOB_CONTROL: '0',
|
|
_POSIX_SAVED_IDS: '0',
|
|
/** Named segments under `/dev/shm` (in-memory; not a host shm_open). */
|
|
_POSIX_SHARED_MEMORY_OBJECTS: '1',
|
|
_POSIX_MESSAGE_PASSING: '1',
|
|
_POSIX_ASYNCHRONOUS_IO: '0',
|
|
/** Bare shell line length (reasonable REPL limit, not a hard kernel cap). */
|
|
BARE_OS_INPUT_LINE_MAX: '8192',
|
|
/** Defaults for simulated pipelines (override with BARE_OS_PIPELINE_* env); see handbook §3. */
|
|
BARE_OS_PIPELINE_MAX_STAGES: '32',
|
|
BARE_OS_PIPELINE_MAX_BYTES: '2097152',
|
|
BARE_OS_PIPELINE_MAX_LINES: '50000',
|
|
/** Default cap for find -exec/-ok invocations per run (override with env). */
|
|
BARE_OS_FIND_EXEC_MAX: '64',
|
|
/** Max lines `yes` prints before stopping (override with BARE_OS_YES_MAX_LINES). */
|
|
BARE_OS_YES_MAX_LINES: '100000',
|
|
/** Max input lines `shuf` will hold in memory (override with BARE_OS_SHUF_MAX_LINES). */
|
|
BARE_OS_SHUF_MAX_LINES: '50000',
|
|
/** Max output chunk files `split` may create (override with BARE_OS_SPLIT_MAX_FILES). */
|
|
BARE_OS_SPLIT_MAX_FILES: '10000',
|
|
_POSIX_THREAD_ATTR_STACKSIZE: '65536',
|
|
_SC_PAGESIZE: '4096',
|
|
_SC_PAGE_SIZE: '4096',
|
|
_SC_OPEN_MAX: '256',
|
|
_SC_STREAM_MAX: '256',
|
|
_SC_CHILD_MAX: '0',
|
|
_SC_CLK_TCK: '100',
|
|
_SC_PHYS_PAGES: '524288',
|
|
_SC_AVPHYS_PAGES: '262144',
|
|
_SC_ARG_MAX: '262144',
|
|
_SC_NPROCESSORS_CONF: '4',
|
|
/** Online processors (static default; live override via `ctx.bareOsGetconfSysconf` + `BARE_OS_NPROC`). */
|
|
_SC_NPROCESSORS_ONLN: '4',
|
|
_SC_HOST_NAME_MAX: '255',
|
|
_POSIX_HOST_NAME_MAX: '255',
|
|
_SC_MONOTONIC_CLOCK: '1',
|
|
_SC_ATEXIT_MAX: '32',
|
|
_SC_LINE_MAX: '2048',
|
|
_SC_BC_BASE_MAX: '99',
|
|
_SC_BC_DIM_MAX: '2048',
|
|
_SC_BC_SCALE_MAX: '99',
|
|
_SC_SYMLOOP_MAX: '32',
|
|
_SC_IOV_MAX: '1024',
|
|
_SC_UIO_MAXIOV: '1024',
|
|
_SC_THREAD_DESTRUCTOR_ITERATIONS: '4',
|
|
_SC_TTY_NAME_MAX: '32',
|
|
_SC_LOGIN_NAME_MAX: '256',
|
|
_PC_PATH_MAX: '4096',
|
|
_PC_NAME_MAX: '255',
|
|
_PC_CHOWN_RESTRICTED: '1',
|
|
_PC_NO_TRUNC: '1',
|
|
_PC_FILESIZEBITS: '64',
|
|
_PC_LINK_MAX: '1',
|
|
_PC_MAX_CANON: '255',
|
|
_PC_MAX_INPUT: '512',
|
|
_PC_PIPE_BUF: '4096',
|
|
_PC_2_SYMLINKS: '1',
|
|
/** Comma-separated `ctx.bareOsSyscall` op names implemented in stock booter. */
|
|
BARE_OS_SYSCALL_OPS:
|
|
'accept,access,bind,chdir,chmod,connect,exists,fcntl,fdatasync,fsync,ftruncate,getcwd,getsockopt,kill,link,listen,lstat,mkdir,mount,mq_open,mq_receive,mq_send,nanosleep,pathconf,posixPoll,readFile,readdir,readlink,readv,recv,recvfrom,recvmsg,rename,rmdir,select,send,sendmsg,setsockopt,shutdown,socket,stat,symlink,truncate,umask,umount,unlink,utimes,writeFile,writev',
|
|
/** POSIX.1 XSH-style names documented in `/proc/bare_os/syscalls.json` opsDetail (socket family are syscall probes returning ENOSYS-shaped results). */
|
|
BARE_OS_POSIX_XSH_OPS:
|
|
'open,close,read,write,lseek,nanosleep,pipe,dup,dup2,fcntl,poll,select,umask,socket,bind,listen,accept,connect,send,recv,recvfrom,sendmsg,recvmsg,shutdown',
|
|
/** Encodings accepted by `/bin/iconv` (subset; case-insensitive names). */
|
|
BARE_OS_ICONV_ENCODINGS: 'UTF-8,ISO-8859-1,UTF-16LE,UTF-16BE',
|
|
/** Synthetic process table JSON path (logical VFS). */
|
|
BARE_OS_PROC_PROCESS_TABLE: '/proc/bare_os/process_table.json',
|
|
/** Sidecar suffix for synthetic POSIX ACL text (`getfacl` / `setfacl`). */
|
|
BARE_OS_ACL_SIDECAR_SUFFIX: '.bare_acl',
|
|
/** Sidecar suffix for extended-attribute JSON (`xattr`). */
|
|
BARE_OS_XATTR_SIDECAR_SUFFIX: '.bare_xattr.json',
|
|
/** Incremental kernel.ext.d reload after boot (`ctx.bareOsReloadKernelExtDropinsSafe`); 0/1 hint only. */
|
|
BARE_OS_KERNEL_EXT_D_HOT_RELOAD: '0',
|
|
/** Operator hint for hyperblob-style dedup in host pipelines; guest VFS does not enable automatically. */
|
|
BARE_OS_VFS_HYPERBLOBS_DEDUP: '0',
|
|
/** This binary: fixed catalog. Use `getconf NAME /path` + `ctx.bareOsPathconf` for live pathconf. */
|
|
BARE_OS_GETCONF_SOURCE: 'static_catalog',
|
|
/** Guest session denies read/write/unlink/chmod on sealed `/.bare/account` and `/.bare/vault/**` unless BARE_OS_GUEST_BARE_READ_ALL=1. */
|
|
BARE_OS_GUEST_SENSITIVE_BARE_DENY: '1',
|
|
/** Optional `/.bare-os/acct/…` segment before `home/` and `tmp/` (BARE_OS_PERSONAL_ACCT_PREFIX). */
|
|
BARE_OS_PERSONAL_ACCT_PREFIX_FEATURE: '1',
|
|
/** Legacy flat-root → `/.bare-os/home/<seg>/` migration state file on the personal drive. */
|
|
BARE_OS_PERSONAL_ROOT_MIGRATION_STATE: '/.bare-os/migration/legacy-root-v1.json',
|
|
/** Replication hook counter: vfs.replication_warm_full_invalidate (metrics / kernelCounters). */
|
|
BARE_OS_REPLICATION_WARM_FULL_INVALIDATE_METRIC: 'vfs.replication_warm_full_invalidate'
|
|
}
|
|
|
|
async function run(ctx, argv) {
|
|
const args = argv.slice(1).filter((a) => a !== '--')
|
|
let dumpAll = false
|
|
/** @type {string[]} */
|
|
const positional = []
|
|
for (const a of args) {
|
|
if (a === '-a') dumpAll = true
|
|
else if (!a.startsWith('-')) positional.push(a)
|
|
else {
|
|
ctx.console.error('getconf: unknown option: ' + a)
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
}
|
|
|
|
if (dumpAll) {
|
|
for (const k of Object.keys(CONF).sort()) {
|
|
ctx.console.log(k + '\n' + CONF[k])
|
|
}
|
|
ctx.exitCode = 0
|
|
return
|
|
}
|
|
|
|
if (positional.length === 2) {
|
|
const varName = positional[0]
|
|
const pathSpec = positional[1]
|
|
if (
|
|
typeof ctx.bareOsPathconf === 'function' &&
|
|
pathSpec.startsWith('/')
|
|
) {
|
|
try {
|
|
const v = ctx.bareOsPathconf(pathSpec, varName)
|
|
ctx.console.log(String(v))
|
|
ctx.exitCode = 0
|
|
return
|
|
} catch (e) {
|
|
ctx.console.error('getconf: ' + (e?.message || String(e)))
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
}
|
|
}
|
|
|
|
if (positional.length !== 1) {
|
|
ctx.console.error('usage: getconf [-a] system_var [path_for_pathconf]')
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
|
|
const name = positional[0]
|
|
|
|
if (typeof ctx.bareOsGetconfSysconf === 'function') {
|
|
try {
|
|
const dyn = ctx.bareOsGetconfSysconf(name)
|
|
if (dyn != null && dyn !== '') {
|
|
ctx.console.log(String(dyn))
|
|
ctx.exitCode = 0
|
|
return
|
|
}
|
|
} catch (e) {
|
|
ctx.console.error('getconf: ' + (e?.message || String(e)))
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
}
|
|
|
|
if (Object.prototype.hasOwnProperty.call(CONF, name)) {
|
|
ctx.console.log(CONF[name])
|
|
ctx.exitCode = 0
|
|
return
|
|
}
|
|
|
|
ctx.console.error('getconf: ' + name + ': unknown variable')
|
|
ctx.exitCode = 1
|
|
}
|