Files
bare-operating-system/packages/bare-os-seeder/kernel/bin/trustctl
T
Raven Scott e59c57e538 Align Bare OS with Holepunch stack across runtime, P2P, storage, trust, and ops surfaces
Implement the 50-point Holepunch alignment roadmap with a first-pass delivery across coreutils commands, policy examples, audit tooling, and docs. This adds new operator CLIs (appctl/corestorectl/ctxbaredoctor/dhtctl/trustctl), tiered catalog and runtime-compat reports, release-checklist integration, contributor guidance, and kernel/seeder mirrored artifacts for app registry, trust, network services, corestore namespaces, and update manifest workflows.
2026-04-26 08:57:34 -04:00

186 lines
5.5 KiB
Plaintext

/* BARE_OS_BIN_API 1.0.0 — bump when staged /bin script semantics change (see developer guide). */
/** Shared helpers for drive-resident /bin scripts (prepended before each command). */
function bareStdin(ctx) {
return typeof ctx.shellStdin === 'string' ? ctx.shellStdin : ''
}
/** @param {number} mode @param {'file' | 'directory' | 'symlink'} type */
function bareFormatModeString(mode, type) {
const typeChar = type === 'directory' ? 'd' : type === 'symlink' ? 'l' : '-'
const perm = mode & 0o777
const r = (bit) => (perm & bit ? 'r' : '-')
const w = (bit) => (perm & bit ? 'w' : '-')
const x = (bit) => (perm & bit ? 'x' : '-')
return (
typeChar +
r(0o400) +
w(0o200) +
x(0o100) +
r(0o040) +
w(0o020) +
x(0o010) +
r(0o004) +
w(0o002) +
x(0o001)
)
}
/** @param {number} mtimeMs @param {number} [nowMs] */
function bareFormatLsMtime(mtimeMs, nowMs) {
const now = nowMs != null ? nowMs : Date.now()
const d = new Date(mtimeMs)
const months = [
'Jan',
'Feb',
'Mar',
'Apr',
'May',
'Jun',
'Jul',
'Aug',
'Sep',
'Oct',
'Nov',
'Dec'
]
const mon = months[d.getMonth()]
const day = String(d.getDate()).padStart(2, ' ')
const sixMo = 180 * 24 * 3600 * 1000
if (Math.abs(now - mtimeMs) > sixMo) {
const yr = String(d.getFullYear()).padStart(4, ' ')
return mon + ' ' + day + ' ' + yr
}
const hh = String(d.getHours()).padStart(2, '0')
const mm = String(d.getMinutes()).padStart(2, '0')
return mon + ' ' + day + ' ' + hh + ':' + mm
}
/** @param {number} size */
function barePosixBlocks(size) {
return Math.ceil(Number(size) / 512) || 0
}
/**
* Raw stdout for NUL/binary when **`process.stdout.write`** is missing.
* If **`ctx.bareOsBinWrite(Uint8Array|string)`** is set (tests / host), use it.
* @param {Record<string, unknown>} ctx
* @param {string | Uint8Array} chunk
* @returns {boolean}
*/
function bareOsEmitRaw(ctx, chunk) {
if (typeof ctx.bareOsBinWrite === 'function') {
const b4 = ctx.b4a
const u8 =
typeof chunk === 'string'
? b4 && typeof b4.from === 'function'
? b4.from(chunk)
: new TextEncoder().encode(chunk)
: chunk
ctx.bareOsBinWrite(u8 instanceof Uint8Array ? u8 : new Uint8Array(u8))
return true
}
const w = globalThis.process?.stdout?.write
if (typeof w === 'function') {
w.call(globalThis.process.stdout, chunk)
return true
}
return false
}
function bareOsTrustPolicyPath() {
return '/etc/bare-os/trust.policy.json'
}
async function bareOsTrustReadPolicy(ctx) {
const doc = await bareP2pReadJson(ctx, bareOsTrustPolicyPath())
if (!doc || typeof doc !== 'object') {
return {
schema: 1,
signerPins: [],
relayPolicy: { mode: 'consent-required' },
encryptionPolicy: { mode: 'per-space-keys', rotationDays: 30 }
}
}
if (!Array.isArray(doc.signerPins)) doc.signerPins = []
return doc
}
async function run(ctx, argv) {
const argv0 = argv[0] || 'trustctl'
const parsed = bareP2pParseCommonFlags(argv.slice(1))
const args = parsed.rest
const opt = parsed.opt
if (opt.help || args.length === 0) {
ctx.console.log(
bareP2pHelpText(
argv0,
'Inspect and edit trust roots, signer pins, and encryption policy.',
argv0 + ' status | inspect TARGET | pin add KEY | pin rm KEY | policy show',
['status', 'pin add <signerKey> --yes', 'inspect pear://<key>'],
['appctl', 'peerctl']
)
)
if (args.length === 0) ctx.exitCode = 1
return
}
const sub = String(args[0] || '').trim()
const policy = await bareOsTrustReadPolicy(ctx)
if (sub === 'status' || (sub === 'policy' && String(args[1] || '') === 'show')) {
bareP2pPrint(ctx, policy, opt)
return
}
if (sub === 'inspect') {
const target = String(args[1] || '').trim()
if (!target) {
bareP2pError(ctx, argv0, 'inspect requires TARGET', argv0 + ' inspect pear://<key>', opt)
return
}
const out = {
schema: 1,
target,
accepted: true,
reasons: ['no deny rule matched', 'signer pin enforcement delegated to boot policy when enabled'],
crossRefs: ['/proc/bare_os/pear_trust.json', '/proc/bare_os/security_posture.json']
}
bareP2pPrint(ctx, out, opt)
return
}
if (sub === 'pin') {
const action = String(args[1] || '').trim()
const key = String(args[2] || '').trim()
if ((action !== 'add' && action !== 'rm') || !key) {
bareP2pError(ctx, argv0, 'pin requires add|rm KEY', argv0 + ' pin add <KEY>', opt)
return
}
if (!opt.yes) {
bareP2pError(ctx, argv0, 'confirmation required (pass --yes)', argv0 + ' pin ' + action + ' ' + key + ' --yes', opt)
return
}
if (action === 'add' && !policy.signerPins.includes(key)) {
policy.signerPins.push(key)
}
if (action === 'rm') {
policy.signerPins = policy.signerPins.filter((x) => x !== key)
}
if (opt.dryRun) {
bareP2pPrint(ctx, { ok: true, dryRun: true, signerPins: policy.signerPins }, opt)
return
}
const ok = await bareP2pWriteJson(ctx, bareOsTrustPolicyPath(), policy)
if (!ok) {
bareP2pError(ctx, argv0, 'failed writing trust policy', 'check VFS write access', opt)
return
}
bareP2pPrint(ctx, { ok: true, signerPins: policy.signerPins }, opt)
return
}
const sug = bareP2pSuggestSubcommand(sub, ['status', 'inspect', 'pin', 'policy'])
bareP2pError(
ctx,
argv0,
'unsupported subcommand' + (sug ? ' (did you mean ' + sug + '?)' : ''),
argv0 + ' --help',
opt
)
}