- HRPC: bare_os.pkg_index_get, route table schema 3; pkg-swarm-index list/get; pathcap-verify --trusted - POSIX: profile 1.0.17, ctx API 1.53.0, syscalls.json schema 11 + susv4Refs; JSON schemas + matrix/dashboard - Feature bits: BARE_OS_KERNEL_FEATURE_BITS_DOC 16; contract + verify scripts; ctx.d.ts + gen helper sync - Ops: BARE_OS_HOLEPUNCH_DRIFT_TIER1 + tier1Repos; mktemp avoids false XXX marker; /proc boot_budget_summary test list - Docs: contract spine, env appendix, handbook, compatibility matrix, boot budget schema, vault threat model notes Covers bare-os P2P roadmap items 1–20 where implemented in-tree; kernel/lib/bare/README left minimal per maintainer edit.
177 lines
4.7 KiB
Plaintext
177 lines
4.7 KiB
Plaintext
/* BARE_OS_BIN_API 1.0.0 — bump when staged /bin script semantics change (see developer guide). */
|
|
/** Shared helpers for drive-resident /bin scripts (prepended before each command). */
|
|
function bareStdin(ctx) {
|
|
return typeof ctx.shellStdin === 'string' ? ctx.shellStdin : ''
|
|
}
|
|
|
|
/** @param {number} mode @param {'file' | 'directory' | 'symlink'} type */
|
|
function bareFormatModeString(mode, type) {
|
|
const typeChar = type === 'directory' ? 'd' : type === 'symlink' ? 'l' : '-'
|
|
const perm = mode & 0o777
|
|
const r = (bit) => (perm & bit ? 'r' : '-')
|
|
const w = (bit) => (perm & bit ? 'w' : '-')
|
|
const x = (bit) => (perm & bit ? 'x' : '-')
|
|
return (
|
|
typeChar +
|
|
r(0o400) +
|
|
w(0o200) +
|
|
x(0o100) +
|
|
r(0o040) +
|
|
w(0o020) +
|
|
x(0o010) +
|
|
r(0o004) +
|
|
w(0o002) +
|
|
x(0o001)
|
|
)
|
|
}
|
|
|
|
/** @param {number} mtimeMs @param {number} [nowMs] */
|
|
function bareFormatLsMtime(mtimeMs, nowMs) {
|
|
const now = nowMs != null ? nowMs : Date.now()
|
|
const d = new Date(mtimeMs)
|
|
const months = [
|
|
'Jan',
|
|
'Feb',
|
|
'Mar',
|
|
'Apr',
|
|
'May',
|
|
'Jun',
|
|
'Jul',
|
|
'Aug',
|
|
'Sep',
|
|
'Oct',
|
|
'Nov',
|
|
'Dec'
|
|
]
|
|
const mon = months[d.getMonth()]
|
|
const day = String(d.getDate()).padStart(2, ' ')
|
|
const sixMo = 180 * 24 * 3600 * 1000
|
|
if (Math.abs(now - mtimeMs) > sixMo) {
|
|
const yr = String(d.getFullYear()).padStart(4, ' ')
|
|
return mon + ' ' + day + ' ' + yr
|
|
}
|
|
const hh = String(d.getHours()).padStart(2, '0')
|
|
const mm = String(d.getMinutes()).padStart(2, '0')
|
|
return mon + ' ' + day + ' ' + hh + ':' + mm
|
|
}
|
|
|
|
/** @param {number} size */
|
|
function barePosixBlocks(size) {
|
|
return Math.ceil(Number(size) / 512) || 0
|
|
}
|
|
|
|
/**
|
|
* Raw stdout for NUL/binary when **`process.stdout.write`** is missing.
|
|
* If **`ctx.bareOsBinWrite(Uint8Array|string)`** is set (tests / host), use it.
|
|
* @param {Record<string, unknown>} ctx
|
|
* @param {string | Uint8Array} chunk
|
|
* @returns {boolean}
|
|
*/
|
|
function bareOsEmitRaw(ctx, chunk) {
|
|
if (typeof ctx.bareOsBinWrite === 'function') {
|
|
const b4 = ctx.b4a
|
|
const u8 =
|
|
typeof chunk === 'string'
|
|
? b4 && typeof b4.from === 'function'
|
|
? b4.from(chunk)
|
|
: new TextEncoder().encode(chunk)
|
|
: chunk
|
|
ctx.bareOsBinWrite(u8 instanceof Uint8Array ? u8 : new Uint8Array(u8))
|
|
return true
|
|
}
|
|
const w = globalThis.process?.stdout?.write
|
|
if (typeof w === 'function') {
|
|
w.call(globalThis.process.stdout, chunk)
|
|
return true
|
|
}
|
|
return false
|
|
}
|
|
|
|
/**
|
|
* Verify a path-capability envelope (JSON) using ctx.bareOsVerifyPathCapabilityEnvelope
|
|
* or bareOsVerifyPathCapabilityEnvelopeTrusted when --trusted (issuer pubkey allowlist on host).
|
|
* Usage: pathcap-verify FILE.json (or stdin JSON when FILE is -)
|
|
*/
|
|
async function run(ctx, argv) {
|
|
let path = ''
|
|
let trusted = false
|
|
for (let i = 1; i < argv.length; i++) {
|
|
const a = argv[i]
|
|
if (a === '--help' || a === '-h') {
|
|
ctx.console.log(
|
|
'usage: pathcap-verify [--trusted] FILE.json\n pathcap-verify - (read envelope JSON from stdin)\n --trusted uses ctx.bareOsVerifyPathCapabilityEnvelopeTrusted + BARE_OS_PATH_CAPABILITY_TRUSTED_PUBKEYS_HEX'
|
|
)
|
|
return
|
|
}
|
|
if (a === '--trusted') {
|
|
trusted = true
|
|
continue
|
|
}
|
|
if (!a.startsWith('-')) {
|
|
path = a
|
|
break
|
|
}
|
|
ctx.console.error('pathcap-verify: unknown option ' + a)
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
if (!path) {
|
|
ctx.console.error(
|
|
'usage: pathcap-verify FILE.json\n pathcap-verify -'
|
|
)
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
const verifyFn = trusted
|
|
? ctx.bareOsVerifyPathCapabilityEnvelopeTrusted
|
|
: ctx.bareOsVerifyPathCapabilityEnvelope
|
|
if (typeof verifyFn !== 'function') {
|
|
ctx.console.error(
|
|
'pathcap-verify: ctx.' +
|
|
(trusted
|
|
? 'bareOsVerifyPathCapabilityEnvelopeTrusted'
|
|
: 'bareOsVerifyPathCapabilityEnvelope') +
|
|
' missing'
|
|
)
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
let text = ''
|
|
try {
|
|
if (path === '-') {
|
|
text = String(ctx.shellStdin || '')
|
|
} else {
|
|
const buf = await ctx.vfs.readFile(path)
|
|
if (!buf || !buf.byteLength) {
|
|
ctx.console.error('pathcap-verify: empty or missing: ' + path)
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
text = ctx.b4a.toString(buf)
|
|
}
|
|
} catch (e) {
|
|
ctx.console.error(
|
|
'pathcap-verify: read failed: ' + ((e && e.message) || String(e))
|
|
)
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
let env
|
|
try {
|
|
env = JSON.parse(text)
|
|
} catch {
|
|
ctx.console.error('pathcap-verify: invalid JSON')
|
|
ctx.exitCode = 1
|
|
return
|
|
}
|
|
const r = verifyFn(env)
|
|
if (r.ok) {
|
|
ctx.console.log(
|
|
'ok prefix=' + r.payload.prefix + ' ops=' + r.payload.ops.join(',')
|
|
)
|
|
return
|
|
}
|
|
ctx.console.error('pathcap-verify: FAIL ' + r.reason)
|
|
ctx.exitCode = 1
|
|
}
|