- Add createBareOsDiskOsBridge for Hyperdrive searchLocal + whitelisted bare_os.* execRpc; wire disk.os after initd - Expose ctx.bareOsRunSystemctlCli; route /bin/systemctl and journalctl through it (sync seeder kernel/bin) - Implement ssh-keygen passphrase envelope (bareOsKeySchema 2, PBKDF2 + ChaCha20-Poly1305); add warc and archive delegates - Extend basenc (--base32/--base64); improve hostid/users session UX - Introduce bare-os-boot-phases, bare-os-errors; CI boot-step alignment - Bump BARE_OS_CTX_API_VERSION to 1.28.0; update ctx d.ts and verifiers - Add KERNEL_CONTRACT, OTA_AND_BUNDLES, PLACEHOLDER_BASELINE; handbook disk.os + security hooks; reference docs and CHANGELOG
349 lines
8.9 KiB
Plaintext
349 lines
8.9 KiB
Plaintext
/* BARE_OS_BIN_API 1.0.0 — bump when staged /bin script semantics change (see developer guide). */
|
|
/** Shared helpers for drive-resident /bin scripts (prepended before each command). */
|
|
function bareStdin(ctx) {
|
|
return typeof ctx.shellStdin === 'string' ? ctx.shellStdin : ''
|
|
}
|
|
|
|
/** @param {number} mode @param {'file' | 'directory' | 'symlink'} type */
|
|
function bareFormatModeString(mode, type) {
|
|
const typeChar = type === 'directory' ? 'd' : type === 'symlink' ? 'l' : '-'
|
|
const perm = mode & 0o777
|
|
const r = (bit) => (perm & bit ? 'r' : '-')
|
|
const w = (bit) => (perm & bit ? 'w' : '-')
|
|
const x = (bit) => (perm & bit ? 'x' : '-')
|
|
return (
|
|
typeChar +
|
|
r(0o400) +
|
|
w(0o200) +
|
|
x(0o100) +
|
|
r(0o040) +
|
|
w(0o020) +
|
|
x(0o010) +
|
|
r(0o004) +
|
|
w(0o002) +
|
|
x(0o001)
|
|
)
|
|
}
|
|
|
|
/** @param {number} mtimeMs @param {number} [nowMs] */
|
|
function bareFormatLsMtime(mtimeMs, nowMs) {
|
|
const now = nowMs != null ? nowMs : Date.now()
|
|
const d = new Date(mtimeMs)
|
|
const months = [
|
|
'Jan',
|
|
'Feb',
|
|
'Mar',
|
|
'Apr',
|
|
'May',
|
|
'Jun',
|
|
'Jul',
|
|
'Aug',
|
|
'Sep',
|
|
'Oct',
|
|
'Nov',
|
|
'Dec'
|
|
]
|
|
const mon = months[d.getMonth()]
|
|
const day = String(d.getDate()).padStart(2, ' ')
|
|
const sixMo = 180 * 24 * 3600 * 1000
|
|
if (Math.abs(now - mtimeMs) > sixMo) {
|
|
const yr = String(d.getFullYear()).padStart(4, ' ')
|
|
return mon + ' ' + day + ' ' + yr
|
|
}
|
|
const hh = String(d.getHours()).padStart(2, '0')
|
|
const mm = String(d.getMinutes()).padStart(2, '0')
|
|
return mon + ' ' + day + ' ' + hh + ':' + mm
|
|
}
|
|
|
|
/** @param {number} size */
|
|
function barePosixBlocks(size) {
|
|
return Math.ceil(Number(size) / 512) || 0
|
|
}
|
|
|
|
/**
|
|
* Raw stdout for NUL/binary when **`process.stdout.write`** is missing.
|
|
* If **`ctx.bareOsBinWrite(Uint8Array|string)`** is set (tests / host), use it.
|
|
* @param {Record<string, unknown>} ctx
|
|
* @param {string | Uint8Array} chunk
|
|
* @returns {boolean}
|
|
*/
|
|
function bareOsEmitRaw(ctx, chunk) {
|
|
if (typeof ctx.bareOsBinWrite === 'function') {
|
|
const b4 = ctx.b4a
|
|
const u8 =
|
|
typeof chunk === 'string'
|
|
? b4 && typeof b4.from === 'function'
|
|
? b4.from(chunk)
|
|
: new TextEncoder().encode(chunk)
|
|
: chunk
|
|
ctx.bareOsBinWrite(u8 instanceof Uint8Array ? u8 : new Uint8Array(u8))
|
|
return true
|
|
}
|
|
const w = globalThis.process?.stdout?.write
|
|
if (typeof w === 'function') {
|
|
w.call(globalThis.process.stdout, chunk)
|
|
return true
|
|
}
|
|
return false
|
|
}
|
|
|
|
const B32 = 'ABCDEFGHIJKLMNOPQRSTUVWXYZ234567'
|
|
|
|
function bareHexEncode(u8) {
|
|
let s = ''
|
|
for (let i = 0; i < u8.length; i++) {
|
|
s += u8[i].toString(16).padStart(2, '0')
|
|
}
|
|
return s
|
|
}
|
|
|
|
function bareHexDecode(s) {
|
|
const t = String(s).replace(/\s+/g, '')
|
|
if (t.length % 2 !== 0) throw new Error('odd hex length')
|
|
const out = new Uint8Array(t.length / 2)
|
|
for (let i = 0; i < out.length; i++) {
|
|
out[i] = parseInt(t.slice(i * 2, i * 2 + 2), 16)
|
|
if (!Number.isFinite(out[i])) throw new Error('invalid hex')
|
|
}
|
|
return out
|
|
}
|
|
|
|
function bareB32EncodeBytes(u8) {
|
|
let out = ''
|
|
let i = 0
|
|
let buf = 0
|
|
let bits = 0
|
|
for (; i < u8.length; i++) {
|
|
buf = (buf << 8) | u8[i]
|
|
bits += 8
|
|
while (bits >= 5) {
|
|
bits -= 5
|
|
out += B32[(buf >> bits) & 31]
|
|
}
|
|
}
|
|
if (bits > 0) out += B32[(buf << (5 - bits)) & 31]
|
|
while (out.length % 8 !== 0) out += '='
|
|
return out
|
|
}
|
|
|
|
function bareB32DecodeToU8(s) {
|
|
const t = String(s).replace(/\s+/g, '').replace(/=+$/, '')
|
|
let buf = 0
|
|
let bits = 0
|
|
const bytes = []
|
|
for (let i = 0; i < t.length; i++) {
|
|
const c = t[i]
|
|
const v = B32.indexOf(c)
|
|
if (v < 0) throw new Error('invalid base32 character')
|
|
buf = (buf << 5) | v
|
|
bits += 5
|
|
if (bits >= 8) {
|
|
bits -= 8
|
|
bytes.push((buf >> bits) & 255)
|
|
}
|
|
}
|
|
return new Uint8Array(bytes)
|
|
}
|
|
|
|
function bareB64EncodeBytes(u8) {
|
|
const B =
|
|
'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/'
|
|
let out = ''
|
|
let i = 0
|
|
for (; i + 2 < u8.length; i += 3) {
|
|
const n = (u8[i] << 16) | (u8[i + 1] << 8) | u8[i + 2]
|
|
out += B[(n >> 18) & 63] + B[(n >> 12) & 63] + B[(n >> 6) & 63] + B[n & 63]
|
|
}
|
|
const rest = u8.length - i
|
|
if (rest === 1) {
|
|
const n = u8[i] << 16
|
|
out += B[(n >> 18) & 63] + B[(n >> 12) & 63] + '=='
|
|
} else if (rest === 2) {
|
|
const n = (u8[i] << 16) | (u8[i + 1] << 8)
|
|
out += B[(n >> 18) & 63] + B[(n >> 12) & 63] + B[(n >> 6) & 63] + '='
|
|
}
|
|
return out
|
|
}
|
|
|
|
function bareB64DecodeToU8(s) {
|
|
const t = String(s).replace(/\s+/g, '')
|
|
if (typeof globalThis.Buffer !== 'undefined') {
|
|
return new Uint8Array(globalThis.Buffer.from(t, 'base64'))
|
|
}
|
|
if (typeof globalThis.atob === 'function') {
|
|
const bin = globalThis.atob(t)
|
|
const out = new Uint8Array(bin.length)
|
|
for (let i = 0; i < bin.length; i++) out[i] = bin.charCodeAt(i) & 255
|
|
return out
|
|
}
|
|
throw new Error('base64 decode requires Buffer or atob')
|
|
}
|
|
|
|
async function run(ctx, argv) {
|
|
let decode = false
|
|
let base16 = false
|
|
let base32 = false
|
|
let base64 = false
|
|
let wrap = 0
|
|
const paths = []
|
|
for (let i = 1; i < argv.length; i++) {
|
|
const a = argv[i]
|
|
if (a === '-h' || a === '--help') {
|
|
ctx.console.log(
|
|
'usage: basenc [--base16 | --base32 | --base64] [-d] [-w COLS] [FILE]\n' +
|
|
' --base16 hex (default when no base flag)\n' +
|
|
' --base32 RFC 4648 Base32\n' +
|
|
' --base64 RFC 4648 Base64\n' +
|
|
' -d decode from text to raw bytes (stdout)\n' +
|
|
' -w COLS wrap encoded output (base64/base32 only; 0 = no wrap)'
|
|
)
|
|
ctx.exitCode = 0
|
|
return
|
|
}
|
|
if (a === '-d' || a === '--decode') {
|
|
decode = true
|
|
continue
|
|
}
|
|
if (a === '--base16') {
|
|
base16 = true
|
|
continue
|
|
}
|
|
if (a === '--base32') {
|
|
base32 = true
|
|
continue
|
|
}
|
|
if (a === '--base64') {
|
|
base64 = true
|
|
continue
|
|
}
|
|
if ((a === '-w' || a === '--wrap') && argv[i + 1]) {
|
|
wrap = Number.parseInt(argv[++i], 10)
|
|
if (!Number.isFinite(wrap) || wrap < 0) wrap = 0
|
|
continue
|
|
}
|
|
if (a.startsWith('-')) {
|
|
ctx.console.error('basenc: unsupported option ' + a)
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
paths.push(a)
|
|
}
|
|
|
|
const modeCount = (base16 ? 1 : 0) + (base32 ? 1 : 0) + (base64 ? 1 : 0)
|
|
if (modeCount > 1) {
|
|
ctx.console.error('basenc: specify at most one of --base16, --base32, --base64')
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
if (modeCount === 0) base16 = true
|
|
|
|
const b4 = ctx.b4a
|
|
let buf
|
|
if (!paths.length || paths[0] === '-') {
|
|
buf = b4.from(bareStdin(ctx))
|
|
} else {
|
|
const b = await ctx.vfs.readFile(paths[0])
|
|
if (!b) {
|
|
ctx.console.error('basenc: cannot read ' + paths[0])
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
buf = b instanceof Uint8Array ? b : new Uint8Array(b)
|
|
}
|
|
|
|
if (base16) {
|
|
if (decode) {
|
|
const text = b4.toString(buf)
|
|
let raw
|
|
try {
|
|
raw = bareHexDecode(text)
|
|
} catch (e) {
|
|
ctx.console.error('basenc: ' + (e.message || e))
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
if (!bareOsEmitRaw(ctx, raw)) {
|
|
ctx.console.error(
|
|
'basenc: decode output requires process.stdout.write or ctx.bareOsBinWrite'
|
|
)
|
|
ctx.exitCode = 1
|
|
}
|
|
return
|
|
}
|
|
ctx.console.log(bareHexEncode(buf))
|
|
return
|
|
}
|
|
|
|
if (base32) {
|
|
if (decode) {
|
|
const text = b4.toString(buf)
|
|
let raw
|
|
try {
|
|
raw = bareB32DecodeToU8(text)
|
|
} catch (e) {
|
|
ctx.console.error('basenc: ' + (e.message || e))
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
if (!bareOsEmitRaw(ctx, raw)) {
|
|
ctx.console.error(
|
|
'basenc: decode output requires process.stdout.write or ctx.bareOsBinWrite'
|
|
)
|
|
ctx.exitCode = 1
|
|
}
|
|
return
|
|
}
|
|
let enc = bareB32EncodeBytes(buf)
|
|
if (wrap > 0) {
|
|
const lines = []
|
|
for (let i = 0; i < enc.length; i += wrap) {
|
|
lines.push(enc.slice(i, i + wrap))
|
|
}
|
|
enc = lines.join('\n')
|
|
}
|
|
ctx.console.log(enc)
|
|
return
|
|
}
|
|
|
|
if (base64) {
|
|
if (decode) {
|
|
const text = new TextDecoder().decode(buf)
|
|
let raw
|
|
try {
|
|
raw = bareB64DecodeToU8(text)
|
|
} catch (e) {
|
|
ctx.console.error('basenc: ' + (e.message || e))
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
if (!bareOsEmitRaw(ctx, raw)) {
|
|
ctx.console.error(
|
|
'basenc: decode output requires process.stdout.write or ctx.bareOsBinWrite'
|
|
)
|
|
ctx.exitCode = 1
|
|
}
|
|
return
|
|
}
|
|
let enc
|
|
if (typeof globalThis.btoa === 'function') {
|
|
let s = ''
|
|
const step = 0x8000
|
|
for (let i = 0; i < buf.length; i += step) {
|
|
const chunk = buf.subarray(i, i + step)
|
|
s += String.fromCharCode.apply(null, chunk)
|
|
}
|
|
enc = globalThis.btoa(s)
|
|
} else {
|
|
enc = bareB64EncodeBytes(buf)
|
|
}
|
|
if (wrap > 0) {
|
|
const lines = []
|
|
for (let i = 0; i < enc.length; i += wrap) {
|
|
lines.push(enc.slice(i, i + wrap))
|
|
}
|
|
enc = lines.join('\n')
|
|
}
|
|
ctx.console.log(enc)
|
|
}
|
|
}
|