Files
bare-operating-system/packages/bare-os-coreutils
Raven Scott d286ce19b5 chore(plan): cancel end-to-end seeder-to-booter smoke harness task
test(protocol): add deterministic MBR failover-key coverage
docs(protocol): align package-bare-os-protocol version to 0.9.1
test(booter): add MBR corruption and wrong-topic smoke fixtures
test(peer-seed): add strict pre-MBR bare_os.capabilities negotiation check
feat(seeder): validate BARE_OS_SEED_REQUIRE_MBR_LABELS
feat(seeder): validate BARE_OS_SEED_CAPABILITY_ATTESTATION_JSON schema
docs(boot-policy): add requireProtocolPackageMin 0.9.1 example
test(kernel): cover boot.policy denySeedRpcMethods behavior
test(protocol): add app/cap/chat/meshdrop channel compatibility fixture
test(swarm-disk): cover duplicate Protomux channel null-return path
test(protocol): add 11-word kernelCapabilityWords round-trip fixture
docs(schema): add mbr-layout schema and validate seeder examples
test(protocol): add topicKey() golden hash fixture
docs(trust): document block-0 trust assumptions in boot docs
feat(seeder): add discovery.flushed readiness logging
feat(booter): record peer discovery timings in boot-perf.json
feat(integration): add local testnet mode to integration lab smoke
test(booter): add Hyperswarm connection-budget env regression coverage
test(booter): add swarm plus Corestore suspend/resume integration coverage
feat(booter): mirror swarm ban events into host audit logs
feat(booter): add direct-peer boot via BARE_OS_BOOT_JOIN_PEER_HEX
feat(seeder): pass BARE_OS_SEED_MAX_PEERS to Hyperswarm
feat(seeder): log drive.version and discoveryKey at startup
test(booter): add Hyperdrive.checkout read-only boot probe coverage
feat(booter): prefetch /boot/init.js before kernel handoff
feat(booter): add optional /bin warm replication via downloadDiff
feat(seeder): add manifestPaths SHA-256 generation in stage-kernel-tree
test(peer-seed): cover helper-served block-0 after seeder exit
feat(protocol): add Protomux cork batching for initial channel sends
test(boot-graph): compare kernel/init labels with booter graph proc
docs(boot-policy): add v9-v11 schema examples
feat(release): add requireInitJsSha256 fixture generation step
test(vfs): add BARE_OS_VFS_SYSTEM_RO_ALIAS coverage
test(vfs): strengthen system-drive write-deny path coverage
feat(identity): add personal-drive namespace export/import docs and tests
test(booter): add guest-to-login warm cache invalidation regression
test(vfs): add guest deny coverage for /.bare sensitive paths
test(coreutils): add cross-drive mv failure injection coverage
test(vfs): add .bareos_empty round-trip coverage across mkdir/rmdir/cp/git-fs
test(vfs): add /dev/shm quota enforcement coverage
test(proc): add /proc/bare_os/index.json sortedness and schema checks
test(vfs): add warm read cache invalidation on replication growth
docs(ctx): document bareOsInvalidateWarmReadCaches(reason)
test(kernel): add BARE_OS_BOOT_DRY_RUN behavior coverage
docs(posix): add dashboard rows for all COREUTILS_COMMANDS
feat(curl): expand -w variables beyond http_code/url_effective/size_download
feat(wget): mark -N timestamping as explicit unsupported error
feat(curl): plumb mutual TLS cert/key intent to ctx.httpFetch metadata
feat(shuf): add deterministic seed mode via BARE_OS_SHUF_SEED
docs(sort): document -M month-sort as unsupported
feat(grep): add explicit -E and -G mode handling
test(sed): add Open Group Issue 7 golden fixtures
test(awk): add getline VFS regressions for missing/repeat/boundary cases
test(shell): add non-interactive here-doc coverage
test(shell): add trap delivery coverage for synthetic PIDs/job IDs
test(shell): add set -e compound-body behavior coverage
docs(shell): strengthen read builtin opt-in guidance
test(env): add Bare-runtime coverage for -S and --env-file
docs(man): add examples for pathcap-verify pkg-swarm-index corestorectl
test(identity): add account/vault backup-restore smoke coverage
feat(audit): add tamper detection verification for audit chain rows
test(peer-admission): cover strict empty allowlist deny behavior
test(peer-admission): add denylist precedence over allowlist coverage
test(peer-admission): add BARE_OS_PEER_REQUIRE_CAPS_JSON metadata checks
docs(identity): add trusted-key rotation example for path capabilities
feat(schema): tighten extensionSignerPinsV2-V4 hash validation
test(delegate): add allowlist negative cases for curl/wget/git/hrpc/systemctl
test(proc): extend /proc/self/environ redaction key coverage
docs(security): add peer-assisted block-0 mirroring threat-model notes
feat(bench): add boot budget trend output from real booter phases
test(baretop): align fixture coverage with /proc snapshot key set
test(metrics): validate /proc/bare_os/metrics.prom OpenMetrics shape
docs(ops): add structured seeder NDJSON examples
test(replication): add live stall-hint coverage for no_peers/length_unavailable/ok
docs(release): add corestore-snapshot workflow to checklist
docs(ops): add mirror-drive experiment utility to maintainer workflow
test(booter): add monitor progress coverage for replication live sketch
feat(seeder): validate DHT bootstrap address class JSON inputs
docs(network): add HYPERSWARM_BOOTSTRAP testnet operator guidance
chore(root): add deterministic test:integration script
docs(ci): add local CI runbook for no-.github environments
docs(release): add npm run test:bare after npm test
feat(verify): add protocol docs/package version parity checker
feat(verify): enforce feature-roadmap canonical path consistency
feat(lockfile-drift): add tier-1 strict fail option for mismatches
docs(lockfile-drift): add udx-native and blind-peering upgrade workflow notes
docs(cli-parity): add bare-fetch upstream issue tracking row
feat(bundle-health): generate per-tier bundle size regression thresholds
feat(doc-contracts): verify handbook references to current proc schema versions
feat(pretest): add validate-mermaid-syntax gate
feat(probe): add bare-runtime top-25 critical command lane
docs(protocol): update capability-word prose from bits..bits5 to current words
docs(two-drive): document /tmp /var/log and account-prefix routing
docs(security): add concise boot trust model page and links
docs(dev-guide): add P2P lab cookbook section
docs(dev-guide): add how-to for adding seed RPCs
docs(dev-guide): add how-to for adding /proc/bare_os nodes
docs(dev-guide): add /bin utility checklist for man/posix/build/parity/tests
docs(user-manual): add short What BareOS is not section
2026-04-26 22:28:21 -04:00
..
2026-04-03 23:04:42 -04:00
2026-04-26 15:49:55 -04:00
2026-04-26 06:19:47 -04:00
2026-04-26 16:24:57 -04:00
2026-04-25 23:18:44 -04:00
2026-04-26 16:24:57 -04:00

bare-os-coreutils

Build step, not a runtime library: validates and merges man/pages/*.json into kernel/share/man/man.json (see scripts/build-man-db.mjs), then concatenates lib/runtime.js, optional preamble chunks (see preamble in build.mjs — e.g. md5sumlib/md5.js, sed, awk, jq, man, lscolors, edit/nano TUI), then each **src/<command>.js**, and writes standalone scripts to:

  • kernel/bin/<command> — staged into the system Hyperdrive as /bin/*
  • packages/bare-os-seeder/kernel/bin/<command>vendored copy for Pear bundles (seeder has no sibling bare-os-coreutils at runtime)

When to use: run npm run build -w bare-os-coreutils whenever you change src/*.js, lib/commands.mjs, or man/pages/* so kernel/bin/* and man.json stay in sync before pretest or pear run.

Documentation: Concepts — POSIX · Developer guide — extending /bin · Coreutils reference · Handbook ch.9.

Command contract

Each src/*.js file must define:

async function run(ctx, argv) {
  /* ... */
}

No top-level import — commands are loaded by the booter via AsyncFunction for Bare/Pear compatibility. The concatenated prelude starts with /* BARE_OS_BIN_API … */** so scripts/verify-kernel-seeder-parity.mjs can verify staged **kernel/bin/*. Use ctx.vfs, ctx.console, ctx.b4a, ctx.drive, bareStdin(ctx) from the prelude where needed. Optional ctx.bareOsBinWrite(Uint8Array|string) captures raw bytes (e.g. NUL-terminated output) when process.stdout.write is absent (see bareOsEmitRaw in lib/runtime.js).

Build

From the monorepo root:

npm run build -w bare-os-coreutils

Or node packages/bare-os-coreutils/build.mjs.

CI / tests: root pretest runs this build so kernel/bin exists before workspace tests.

Commands (authoritative list)

Source of truth: lib/commands.mjsCOREUTILS_COMMANDS (imported by build.mjs and scripts/build-man-db.mjs). Each name must have **man/pages/<name>.json. 179 Tier-1 commands in the current tree (sshd**s /bin body is emitted by bare-os-openssh); root pretest runs verify-man-coverage.mjs against this list (do not hand-maintain a duplicate comma-separated inventory here—use lib/commands.mjs, ls /bin in the guest, or man -k).

edit is a full-screen TTY buffer editor (syntax highlighting, search, save). nano is built from the same src/edit.js with the same lib/edit-*.js preamble; /bin/nano exists for familiarity, and the stock shell alias **nanoedit** routes nano to that utility (see packages/bare-os-booter/lib/shell.js). Both require a real TTY (stdout.isTTY).

baretop is the stock top alias target: a multi-tab TTY dashboard over /proc/bare_os/* (session metrics, Pear, replication, initd, scrollable overview, process tree/sort, optional mouse, …). btop is the same bundle as /bin/baretop (short name); the stock shell alias **btopbaretop** matches **nanoedit**. The booter may expose ctx.bareOsReadBareTopSnapshot (optional { lite: true }) to batch-read the same mirrors baretop would vfs.readFile individually; the return value can include metricsLiveText so metrics_live.json need not be read twice. BARE_TOP_INCREMENTAL=2 enables experimental line-diff redraws; BARE_TOP_LAYOUT_AUTO=1 picks a wide split on large terminals. Rebuild kernel/bin/baretop and kernel/bin/btop with node packages/bare-os-coreutils/build.mjs after editing lib/baretop-snapshot.js, lib/baretop-ui-helpers.js, or lib/baretop-tui.js.

Baretop performance baseline

Run the repeatable baseline from repo root:

npm run perf:baretop -w bare-os-coreutils

or inside the package:

node ./test/baretop-perf-baseline.test.mjs

KPI envelope tracked in baseline lane:

  • fetchMs (snapshot fetch wall time): rolling p50 / p95
  • composeMs (frame compose cost): rolling p50 / p95
  • emitMs (terminal emit cost): rolling p50 / p95
  • emitBytes (bytes written/frame): rolling p50 / p95
  • droppedRefreshPct (draws skipped by UI throttling): rolling p50 / p95
  • startup-to-first-frame latency (start=...ms in profile footer)

Expected development-range targets (local machine, non-SSH):

  • composeMs p95 < 40ms on fixture runs
  • emitMs p95 < 10ms in synthetic tests
  • droppedRefreshPct p50 < 10% with default BARE_TOP_UI_MIN_MS=0

agent is the OpenAI-compatible HTTPS assistant (ReAct-style tools, TTY streaming). Preamble pulls in lib/agent-*.js, agent-workspace.js (~/.agent/workspace/*.md loader), agent-skills.js (compact skill index + read_skill), agent-web-fetch.js, agent-tools.js, agent-tui.js (see build.mjs preamble.agent). Config and secrets live under **~/.agent/** on the personal drive (man agent). Markdown soul files default from share/agent-workspace/ (also staged to kernel/share/agent-workspace/ on build). Outbound HTTPS uses ctx.httpFetch (same BARE_OS_HTTP_ALLOWLIST / BARE_OS_HTTP_DENYLIST as delegated curl / wget); the web_fetch tool needs every target host allowlisted alongside your API origin. Maintainer smoke under the Bare runtime: from repo root npm run smoke:agent-web-fetch:bare (scripts/smoke-agent-web-fetch-bare.mjs). chat is separate: swarm / Protomux text chat (lib/chat-tui.js preamble; man chat).

ls prepends bare-os-lscolors for LS_COLORS / dircolors parsing. dircolors and theme integrate with the booters bare-os-theme-presets.js (see docs/themes/README.md).

grep uses JavaScript RegExp (and -F fixed strings); POSIX/GNU-like subset (including -x, -m, -o among common flags). It is not PCRE- or GNU-bit-identical; use -F when literals must not be treated as regex.

sed / awk use large interpreters in lib/sed-engine.js and lib/awk-engine.js — capable, but not guaranteed to match every POSIX or GNU edge case; treat parity as best-effort.

curl and wget ship as /bin scripts (see src/curl.js, src/wget.js) so which, ls /bin, and parity checks see them; the booter delegates to Fetch-based clients in bare-os-booter first, and **ctx.bareOsRunCurlCli / ctx.bareOsRunWgetCli** run the same implementation if a script is executed directly. openssl, ssh-keygen, and tar use matching ctx.bareOsRun* hooks backed by openssl-cli.js, ssh-keygen-cli.js, and tar-cli.js in the booter.

mkfifo creates simulated named pipes under **/run/bare-os/ipc/<name>** (in-memory; see booter VFS). getconf and xargs implement a documented Bare-specific subset (see src/getconf.js, src/xargs.js).

Pipelines: the shell sets ctx.bareOsStdoutCaptured when a commands stdout is captured (pipe or **>** / **>>**). ls prints one name per line in short mode in that case (GNU-like), so **ls | grep** / sort / wc see one record per line.

GNU-style text / data utilities (bounded where needed): paste, split (BARE_OS_SPLIT_MAX_FILES), tac, rev, expand, unexpand, fold, fmt, comm, join, pr, yes (BARE_OS_YES_MAX_LINES), shuf (BARE_OS_SHUF_MAX_LINES), tsort, factor, expr, numfmt. Checksums / encodings: md5sum, sha1sum, sha256sum, sha512sum, sum, base32, basenc --base16. Files / stubs: truncate, unlink, install, df, sync, dir/vdir (delegate to ls), arch, groups, hostid, nproc, uptime, users, who.

Earlier parity / UX: tail -f (watch or poll; BARE_OS_TAIL_F_* env), **head/tail -c** and **+ line/byte offsets**, sort -n/-r/-u/-f/-k/-t, sort -c/-C (check), -s (stable), -o, wc -l/-w/-c, grep -A/-B/-C and --color, date +FORMAT (strftime-like subset), test integer compares and **-h/-L**, xargs -I, **find -iname/-print0**, du -h, **basename -a/-s**, dirname -z, cat -n/-A, env -i, **env -S / --env-file** (with **BARE_OS_ENV_DASH_S=1**), touch -a/-m/-d/-r, mkdir -m, grep -r, **cp/mv -L/-P**, readlink -f, rmdir -p, du -a/-L, **find -mtime/-newer/-prune/-empty/-delete** (gated), stat --format, uniq, realpath, base64, rm -d, cut -s, **tr [:class:]**, richer **od/nl/seq/pathchk/printf/time**, and bareOsBinWrite for captured NUL output in tests. Cap names for getconf include BARE_OS_FIND_EXEC_MAX, BARE_OS_YES_MAX_LINES, BARE_OS_SHUF_MAX_LINES, BARE_OS_SPLIT_MAX_FILES.

See handbook §6 — Kernel and /bin, handbook §9 — POSIX alignment, and handbook §10 — man and online help.

See also