Files
bare-operating-system/docs/schemas/boot.policy.schema.json
T
Raven Scott d286ce19b5 chore(plan): cancel end-to-end seeder-to-booter smoke harness task
test(protocol): add deterministic MBR failover-key coverage
docs(protocol): align package-bare-os-protocol version to 0.9.1
test(booter): add MBR corruption and wrong-topic smoke fixtures
test(peer-seed): add strict pre-MBR bare_os.capabilities negotiation check
feat(seeder): validate BARE_OS_SEED_REQUIRE_MBR_LABELS
feat(seeder): validate BARE_OS_SEED_CAPABILITY_ATTESTATION_JSON schema
docs(boot-policy): add requireProtocolPackageMin 0.9.1 example
test(kernel): cover boot.policy denySeedRpcMethods behavior
test(protocol): add app/cap/chat/meshdrop channel compatibility fixture
test(swarm-disk): cover duplicate Protomux channel null-return path
test(protocol): add 11-word kernelCapabilityWords round-trip fixture
docs(schema): add mbr-layout schema and validate seeder examples
test(protocol): add topicKey() golden hash fixture
docs(trust): document block-0 trust assumptions in boot docs
feat(seeder): add discovery.flushed readiness logging
feat(booter): record peer discovery timings in boot-perf.json
feat(integration): add local testnet mode to integration lab smoke
test(booter): add Hyperswarm connection-budget env regression coverage
test(booter): add swarm plus Corestore suspend/resume integration coverage
feat(booter): mirror swarm ban events into host audit logs
feat(booter): add direct-peer boot via BARE_OS_BOOT_JOIN_PEER_HEX
feat(seeder): pass BARE_OS_SEED_MAX_PEERS to Hyperswarm
feat(seeder): log drive.version and discoveryKey at startup
test(booter): add Hyperdrive.checkout read-only boot probe coverage
feat(booter): prefetch /boot/init.js before kernel handoff
feat(booter): add optional /bin warm replication via downloadDiff
feat(seeder): add manifestPaths SHA-256 generation in stage-kernel-tree
test(peer-seed): cover helper-served block-0 after seeder exit
feat(protocol): add Protomux cork batching for initial channel sends
test(boot-graph): compare kernel/init labels with booter graph proc
docs(boot-policy): add v9-v11 schema examples
feat(release): add requireInitJsSha256 fixture generation step
test(vfs): add BARE_OS_VFS_SYSTEM_RO_ALIAS coverage
test(vfs): strengthen system-drive write-deny path coverage
feat(identity): add personal-drive namespace export/import docs and tests
test(booter): add guest-to-login warm cache invalidation regression
test(vfs): add guest deny coverage for /.bare sensitive paths
test(coreutils): add cross-drive mv failure injection coverage
test(vfs): add .bareos_empty round-trip coverage across mkdir/rmdir/cp/git-fs
test(vfs): add /dev/shm quota enforcement coverage
test(proc): add /proc/bare_os/index.json sortedness and schema checks
test(vfs): add warm read cache invalidation on replication growth
docs(ctx): document bareOsInvalidateWarmReadCaches(reason)
test(kernel): add BARE_OS_BOOT_DRY_RUN behavior coverage
docs(posix): add dashboard rows for all COREUTILS_COMMANDS
feat(curl): expand -w variables beyond http_code/url_effective/size_download
feat(wget): mark -N timestamping as explicit unsupported error
feat(curl): plumb mutual TLS cert/key intent to ctx.httpFetch metadata
feat(shuf): add deterministic seed mode via BARE_OS_SHUF_SEED
docs(sort): document -M month-sort as unsupported
feat(grep): add explicit -E and -G mode handling
test(sed): add Open Group Issue 7 golden fixtures
test(awk): add getline VFS regressions for missing/repeat/boundary cases
test(shell): add non-interactive here-doc coverage
test(shell): add trap delivery coverage for synthetic PIDs/job IDs
test(shell): add set -e compound-body behavior coverage
docs(shell): strengthen read builtin opt-in guidance
test(env): add Bare-runtime coverage for -S and --env-file
docs(man): add examples for pathcap-verify pkg-swarm-index corestorectl
test(identity): add account/vault backup-restore smoke coverage
feat(audit): add tamper detection verification for audit chain rows
test(peer-admission): cover strict empty allowlist deny behavior
test(peer-admission): add denylist precedence over allowlist coverage
test(peer-admission): add BARE_OS_PEER_REQUIRE_CAPS_JSON metadata checks
docs(identity): add trusted-key rotation example for path capabilities
feat(schema): tighten extensionSignerPinsV2-V4 hash validation
test(delegate): add allowlist negative cases for curl/wget/git/hrpc/systemctl
test(proc): extend /proc/self/environ redaction key coverage
docs(security): add peer-assisted block-0 mirroring threat-model notes
feat(bench): add boot budget trend output from real booter phases
test(baretop): align fixture coverage with /proc snapshot key set
test(metrics): validate /proc/bare_os/metrics.prom OpenMetrics shape
docs(ops): add structured seeder NDJSON examples
test(replication): add live stall-hint coverage for no_peers/length_unavailable/ok
docs(release): add corestore-snapshot workflow to checklist
docs(ops): add mirror-drive experiment utility to maintainer workflow
test(booter): add monitor progress coverage for replication live sketch
feat(seeder): validate DHT bootstrap address class JSON inputs
docs(network): add HYPERSWARM_BOOTSTRAP testnet operator guidance
chore(root): add deterministic test:integration script
docs(ci): add local CI runbook for no-.github environments
docs(release): add npm run test:bare after npm test
feat(verify): add protocol docs/package version parity checker
feat(verify): enforce feature-roadmap canonical path consistency
feat(lockfile-drift): add tier-1 strict fail option for mismatches
docs(lockfile-drift): add udx-native and blind-peering upgrade workflow notes
docs(cli-parity): add bare-fetch upstream issue tracking row
feat(bundle-health): generate per-tier bundle size regression thresholds
feat(doc-contracts): verify handbook references to current proc schema versions
feat(pretest): add validate-mermaid-syntax gate
feat(probe): add bare-runtime top-25 critical command lane
docs(protocol): update capability-word prose from bits..bits5 to current words
docs(two-drive): document /tmp /var/log and account-prefix routing
docs(security): add concise boot trust model page and links
docs(dev-guide): add P2P lab cookbook section
docs(dev-guide): add how-to for adding seed RPCs
docs(dev-guide): add how-to for adding /proc/bare_os nodes
docs(dev-guide): add /bin utility checklist for man/posix/build/parity/tests
docs(user-manual): add short What BareOS is not section
2026-04-26 22:28:21 -04:00

283 lines
11 KiB
JSON

{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://bare-os.dev/schemas/boot.policy.schema.json",
"title": "Bare OS boot.policy.json (subset)",
"type": "object",
"additionalProperties": true,
"properties": {
"skipBootStages": {
"type": "array",
"items": { "type": "string" },
"description": "Boot stages to skip (canonical); merged with legacy skipPhases"
},
"denyBootStages": {
"type": "array",
"items": { "type": "string" },
"description": "Boot stages denied like skip list (canonical); merged with legacy denyBootPhases"
},
"skipPhases": {
"type": "array",
"items": { "type": "string" },
"description": "Deprecated alias of skipBootStages (still honored; prefer skipBootStages)"
},
"denyBootPhases": {
"type": "array",
"items": { "type": "string" },
"description": "Deprecated alias of denyBootStages (still honored; prefer denyBootStages)"
},
"minKernelCapabilitiesPrimary": { "type": "integer", "minimum": 0 },
"requireSeedCaps": { "type": "integer", "minimum": 0 },
"requireKernelCapabilitiesExtendedSeedingPlatform": { "type": "integer", "minimum": 0 },
"requireKernelCapabilitiesRlimitsDelegatesShell": { "type": "integer", "minimum": 0 },
"requireKernelCapabilitiesOfflineNetExtensions": { "type": "integer", "minimum": 0 },
"requireKernelCapabilitiesHostTransportDelegates": { "type": "integer", "minimum": 0 },
"requireKernelCapabilitiesReplicationOperatorSurface": { "type": "integer", "minimum": 0 },
"requireKernelCapabilitiesPearCorestoreHrpc": { "type": "integer", "minimum": 0 },
"requireKernelCapabilitiesBareRuntimeProtoMux": { "type": "integer", "minimum": 0 },
"requireKernelCapabilitiesBareModuleCryptoStaging": { "type": "integer", "minimum": 0 },
"requireKernelCapabilitiesPearInspectLoggerTls": { "type": "integer", "minimum": 0 },
"requireKernelCapabilitiesHypercorePackHrpcLifecycle": {
"type": "integer",
"minimum": 0,
"description": "Mask checked against ctx.bareOsAdvertisedKernelCapabilityWords.hypercorePackHrpcLifecycle (capability word 11)"
},
"requireBareBootMin": {
"type": "string",
"description": "Minimum bare-boot semver vs BARE_OS_BARE_BOOT_VERSION"
},
"denyBareRpcMethodPatterns": {
"type": "array",
"items": { "type": "string" },
"description": "Regex/pattern strings merged to BARE_OS_BOOT_POLICY_DENY_BARE_RPC_PATTERNS_JSON"
},
"maxPearInspectDepth": {
"type": "integer",
"minimum": 0,
"maximum": 64
},
"maxHrpcAllowlistDepth": {
"type": "integer",
"minimum": 0,
"maximum": 64,
"description": "Cap nested HRPC allowlist probe depth; merged to BARE_OS_BOOT_POLICY_MAX_HRPC_ALLOWLIST_DEPTH"
},
"requireBareLoggerMin": {
"type": "string",
"description": "Minimum bare-logger API class vs BARE_OS_BARE_LOGGER_VERSION"
},
"denyAutobaseDiscoveryChannels": {
"type": "array",
"items": { "type": "string" }
},
"requireBareTlsMin": {
"type": "string",
"description": "Minimum bare-tls semver vs BARE_OS_BARE_TLS_VERSION"
},
"requireBarePackMin": {
"type": "string",
"description": "Minimum bare-pack semver vs BARE_OS_BARE_PACK_VERSION (host-supplied)"
},
"requireBareAddonPolicyMin": {
"type": "string",
"description": "Minimum bare-addon policy semver vs BARE_OS_BARE_ADDON_POLICY_VERSION (host-supplied sketch)"
},
"extensionSignerPinsV3": {
"type": "object",
"additionalProperties": { "type": "string", "pattern": "^[a-f0-9]{64}$" }
},
"extensionSignerPinsV4": {
"type": "object",
"additionalProperties": { "type": "string", "pattern": "^[a-f0-9]{64}$" },
"description": "Optional fourth extension signer pin map (capability word 11); merged to BARE_OS_BOOT_POLICY_EXTENSION_SIGNER_PINS_V4_JSON"
},
"offlineLkgRequirePearStamp": {
"type": "boolean",
"description": "When true, sets BARE_OS_OFFLINE_LKG_REQUIRE_PEAR_STAMP=1 for host/offline stamp class hints"
},
"offlineLkgRequireHypercorePackHrpcLifecycle": {
"type": "boolean",
"description": "When true, sets BARE_OS_OFFLINE_LKG_REQUIRE_HYPERCORE_PACK_HRPC_LIFECYCLE=1 for strict offline bits11 class hints"
},
"bootStagesRequireLifecycleMinSchema": {
"type": "integer",
"minimum": 0,
"description": "When > 0, fail strict boot when BARE_OS_LIFECYCLE_SCHEMA_VERSION < this value; **0** disables. Canonical; merged with bootPhasesRequireLifecycleMinSchema (max wins)"
},
"bootPhasesRequireLifecycleMinSchema": {
"type": "integer",
"minimum": 0,
"description": "Deprecated alias of bootStagesRequireLifecycleMinSchema"
},
"requirePearRuntimeRange": {
"type": "object",
"additionalProperties": false,
"properties": {
"min": { "type": "string" },
"max": { "type": "string" }
}
},
"denyBareModuleSpecifierPatterns": {
"type": "array",
"items": { "type": "string" }
},
"requireBareCryptoMin": {
"type": "string",
"description": "Minimum bare-crypto semver vs BARE_OS_BARE_CRYPTO_VERSION"
},
"denyKernelSyscalls": {
"type": "array",
"items": { "type": "string" }
},
"requirePearIpcMin": {
"type": "string",
"description": "Minimum pear-ipc package semver vs BARE_OS_PEAR_IPC_PACKAGE_VERSION"
},
"extensionSignerPinsV2": {
"type": "object",
"additionalProperties": { "type": "string", "pattern": "^[a-f0-9]{64}$" }
},
"offlineLkgManifestMaxAgeSec": {
"type": "integer",
"minimum": 0
},
"bootStagesRequireProcIndexMinSchema": {
"type": "integer",
"minimum": 1,
"description": "Fail strict boot when /proc/bare_os/index.json schema < this value (canonical; max with bootPhasesRequireProcIndexMinSchema)"
},
"bootPhasesRequireProcIndexMinSchema": {
"type": "integer",
"minimum": 1,
"description": "Deprecated alias of bootStagesRequireProcIndexMinSchema"
},
"requireBareRuntimeMin": {
"type": "string",
"description": "Minimum Bare runtime semver; compared to ctx.bareOsBareRuntimeVersion / BARE_OS_BARE_RUNTIME_VERSION"
},
"denySeedRpcMethods": {
"type": "array",
"items": { "type": "string" },
"description": "Seed RPC short names to skip at booter handshake; merged to BARE_OS_BOOT_POLICY_DENY_SEED_RPC_METHODS"
},
"maxProtomuxChannelNameLength": {
"type": "integer",
"minimum": 8,
"maximum": 512,
"description": "Cap merged to BARE_OS_BOOT_POLICY_MAX_PROTO_MUX_CHANNEL_NAME_LENGTH"
},
"requireInitJsSha256": { "type": "string", "minLength": 64, "maxLength": 64 },
"requireBooterSemver": {
"type": "string",
"description": "Minimum booter package semver (e.g. 0.1.0); compared to ctx.bareOsBooterPackageVersion"
},
"requireCtxApiMin": {
"type": "string",
"description": "Minimum ctx API semver (e.g. 1.16.0); compared to bareOsCtxApiVersion"
},
"requirePearRuntimeMin": {
"type": "string",
"description": "Minimum Pear runtime semver; compared to ctx.bareOsPearRuntimeVersion / BARE_OS_PEAR_RUNTIME_VERSION"
},
"requireProtocolPackageMin": {
"type": "string",
"description": "Minimum bare-os-protocol package semver; compared to ctx.bareOsProtocolPackageVersion"
},
"denyKernelExtensionIds": {
"type": "array",
"items": { "type": "string" }
},
"kernelExtensionHashPins": {
"type": "object",
"additionalProperties": { "type": "string", "pattern": "^[a-f0-9]{64}$" }
},
"offlineLkgIntegrityStrict": {
"type": "boolean",
"description": "When true with strict policy, offline LKG boot requires extra integrity checks (operator-defined via env on host)"
},
"maxExecLineDepth": { "type": "integer", "minimum": 1 },
"denyEnvKeys": { "type": "array", "items": { "type": "string" } },
"requireProcNodes": { "type": "array", "items": { "type": "string" } },
"allowedUnionPrefixes": { "type": "array", "items": { "type": "string" } },
"allowedPearIpcChannels": {
"type": "array",
"items": { "type": "string" }
},
"denyVfsPrefixes": { "type": "array", "items": { "type": "string" } },
"denyExecLineBuiltins": {
"type": "array",
"items": { "type": "string" }
},
"allowedCtxMethods": {
"type": "array",
"items": { "type": "string" }
},
"denyCtxMethodPrefixes": {
"type": "array",
"items": { "type": "string" },
"description": "Merged to BARE_OS_BOOT_POLICY_DENY_CTX_PREFIXES (comma-separated); ctx method names starting with any prefix are denied"
},
"maxKernelExtensionDepth": {
"type": "integer",
"minimum": 1,
"maximum": 32,
"description": "Maximum dependency depth for kernel.ext.d graph (strict policy fails when exceeded)"
},
"gitPartialClonePolicy": {
"type": "string",
"enum": ["deny", "allow", "prefer"],
"description": "Host-interpreted git partial clone stance; surfaced as BARE_OS_BOOT_POLICY_GIT_PARTIAL_CLONE"
},
"maxInitdRestartsPerUnit": {
"type": "integer",
"minimum": 1,
"maximum": 32
},
"policyFallbackPaths": {
"type": "array",
"items": { "type": "string" },
"description": "Additional /etc/bare-os/*.json files whose skipBootStages/denyBootStages (and legacy skipPhases/denyBootPhases) merge after the primary policy"
},
"requireBootBundleSha256Hex": {
"type": "string",
"description": "Compare to env BARE_OS_BOOT_BUNDLE_DIGEST_HEX (lowercase hex)"
},
"initdAdmission": {
"type": "object",
"additionalProperties": true,
"properties": {
"maxParallel": { "type": "integer", "minimum": 1, "maximum": 32 },
"memoryHintMb": { "type": "integer", "minimum": 1 },
"wallBudgetMsDefault": { "type": "integer", "minimum": 1 }
},
"description": "Merged to BARE_OS_INITD_* env hints for bare-initd"
},
"p2pAdmission": {
"type": "object",
"additionalProperties": true,
"properties": {
"peerAllowlistHex": {
"type": "array",
"items": { "type": "string" },
"description": "When ctx.env BARE_OS_PEER_ALLOWLIST_HEX is unset, merged as JSON string into that env (comma-separated hex public keys)"
},
"hyperswarmBootstrap": {
"type": "array",
"items": { "type": "string" },
"description": "When ctx.env BARE_OS_HYPERSWARM_BOOTSTRAP is unset, merged as JSON string into that env (comma-separated host:port)"
}
},
"description": "Optional P2P admission hints merged into ctx.env during boot when corresponding env vars are empty"
},
"extensionSignerPinsV5": {
"type": "object",
"additionalProperties": { "type": "string" },
"description": "Optional multi-signer pin map → BARE_OS_BOOT_POLICY_EXTENSION_SIGNER_PINS_V5_JSON"
},
"posixCapabilityHints": {
"type": "array",
"items": { "type": "string" },
"description": "Optional distributor catalog of POSIX-like surfaces (e.g. cooperative_fcntl_locks, socket_fd_bridge, dynamic_sysconf); informational for governance dashboards"
}
}
}