Files
bare-operating-system/packages/bare-os-seeder/kernel/bin/trustctl
T
Raven Scott 27292f2ba6 Network/auth/delegate hardening
hdms
Added ls alias to list.
Made delegate failures explicit and nonzero in packages/bare-os-coreutils/src/hdms.js.
Added nonzero error exit in packages/bare-os-booter/lib/hdms-manager.js.
git-pear
Implemented clone subcommand routing to git clone in packages/bare-os-coreutils/src/git-pear.js.
trustctl
Added ls alias to status/policy output in packages/bare-os-coreutils/src/trustctl.js.
oidc-publish
Added explicit unknown-subcommand handling and publish subcommand compatibility in packages/bare-os-coreutils/src/oidc-publish.js.
ssh-keygen
Wrapped delegate invocation with explicit error propagation in packages/bare-os-coreutils/src/ssh-keygen.js.
Added success output on generated keypair in packages/bare-os-booter/lib/ssh-keygen-cli.js.
sshd
Added -t config test mode and explicit exit semantics in packages/bare-os-booter/lib/bare-openssh.js.
Ensured wrapper sets exit code consistently in packages/bare-os-openssh/src/sshd.js.
telnet
Changed connector preference to use net.createConnection first when available, then syscall bridge fallback, in packages/bare-os-coreutils/src/telnet.js.
crontab -e flow

Implemented edit flow with VISUAL/EDITOR fallback, unlocked-state checks, temp file handling, install, and cleanup in packages/bare-os-coreutils/src/crontab.js.
Shell/runtime hardcore semantics

Added numeric brace range expansion {1..5} in packages/bare-os-booter/lib/shell-glob.js.
Enabled brace expansion by default unless explicitly disabled.
Added normalization for inline brace-expression tokens in packages/bare-os-booter/lib/shell.js.
Added arithmetic command-form handling for (( ... )) in packages/bare-os-booter/lib/shell.js.
Extended shell signal trap dispatch support for USR1/USR2 (in addition to INT/TERM) in packages/bare-os-booter/index.js.
Hardened kill command delivery validation in packages/bare-os-coreutils/src/kill.js.
Regression tests

Added new: packages/bare-os-coreutils/test/hardcore-bugs.test.mjs.
Extended shell tests in packages/bare-os-booter/test.js for:
default cmdsub behavior,
brace range expansion,
arithmetic command form.
Existing regression files still pass after updates.
2026-04-27 08:54:50 -04:00

539 lines
16 KiB
Plaintext

/* BARE_OS_BIN_API 1.0.0 — bump when staged /bin script semantics change (see developer guide). */
/** Shared helpers for drive-resident /bin scripts (prepended before each command). */
function bareStdin(ctx) {
return typeof ctx.shellStdin === 'string' ? ctx.shellStdin : ''
}
/** @param {number} mode @param {'file' | 'directory' | 'symlink'} type */
function bareFormatModeString(mode, type) {
const typeChar = type === 'directory' ? 'd' : type === 'symlink' ? 'l' : '-'
const perm = mode & 0o777
const r = (bit) => (perm & bit ? 'r' : '-')
const w = (bit) => (perm & bit ? 'w' : '-')
const x = (bit) => (perm & bit ? 'x' : '-')
return (
typeChar +
r(0o400) +
w(0o200) +
x(0o100) +
r(0o040) +
w(0o020) +
x(0o010) +
r(0o004) +
w(0o002) +
x(0o001)
)
}
/** @param {number} mtimeMs @param {number} [nowMs] */
function bareFormatLsMtime(mtimeMs, nowMs) {
const now = nowMs != null ? nowMs : Date.now()
const d = new Date(mtimeMs)
const months = [
'Jan',
'Feb',
'Mar',
'Apr',
'May',
'Jun',
'Jul',
'Aug',
'Sep',
'Oct',
'Nov',
'Dec'
]
const mon = months[d.getMonth()]
const day = String(d.getDate()).padStart(2, ' ')
const sixMo = 180 * 24 * 3600 * 1000
if (Math.abs(now - mtimeMs) > sixMo) {
const yr = String(d.getFullYear()).padStart(4, ' ')
return mon + ' ' + day + ' ' + yr
}
const hh = String(d.getHours()).padStart(2, '0')
const mm = String(d.getMinutes()).padStart(2, '0')
return mon + ' ' + day + ' ' + hh + ':' + mm
}
/** @param {number} size */
function barePosixBlocks(size) {
return Math.ceil(Number(size) / 512) || 0
}
/**
* Raw stdout for NUL/binary when **`process.stdout.write`** is missing.
* If **`ctx.bareOsBinWrite(Uint8Array|string)`** is set (tests / host), use it.
* @param {Record<string, unknown>} ctx
* @param {string | Uint8Array} chunk
* @returns {boolean}
*/
function bareOsEmitRaw(ctx, chunk) {
if (typeof ctx.bareOsBinWrite === 'function') {
const b4 = ctx.b4a
const u8 =
typeof chunk === 'string'
? b4 && typeof b4.from === 'function'
? b4.from(chunk)
: new TextEncoder().encode(chunk)
: chunk
ctx.bareOsBinWrite(u8 instanceof Uint8Array ? u8 : new Uint8Array(u8))
return true
}
const w = globalThis.process?.stdout?.write
if (typeof w === 'function') {
w.call(globalThis.process.stdout, chunk)
return true
}
return false
}
const BARE_P2P_SUITE_PREFIX = '[bare-p2p-v1]'
const BARE_P2P_SUITE_MAX_HISTORY = 2000
function bareP2pNowMs() {
return Date.now()
}
function bareP2pId(prefix) {
const rnd = Math.floor(Math.random() * 0x7fffffff)
return prefix + '-' + bareP2pNowMs().toString(36) + '-' + rnd.toString(36)
}
function bareP2pCommonExamples(argv0, rows) {
const out = []
for (const r of rows || []) out.push(' ' + argv0 + ' ' + r)
return out.join('\n')
}
function bareP2pHelpText(argv0, summary, usage, examples, seeAlso) {
const lines = []
lines.push('usage: ' + usage)
lines.push(summary)
lines.push('')
lines.push('common options: --help --json --quiet --summary --timeout MS --no-color')
if (examples && examples.length) {
lines.push('')
lines.push('examples:')
lines.push(bareP2pCommonExamples(argv0, examples))
}
if (seeAlso && seeAlso.length) {
lines.push('')
lines.push('see also: ' + seeAlso.join(', '))
}
lines.push('')
lines.push('troubleshooting: if peer data is empty, run `swarmtop` then `swarmdoctor`.')
return lines.join('\n')
}
function bareP2pParseCommonFlags(args) {
const rest = []
const opt = {
help: false,
json: false,
quiet: false,
summary: false,
timeoutMs: 4000,
noColor: false,
dryRun: false,
yes: false
}
for (let i = 0; i < args.length; i++) {
const a = String(args[i] || '')
if (a === '-h' || a === '--help') opt.help = true
else if (a === '--json') opt.json = true
else if (a === '--quiet') opt.quiet = true
else if (a === '--summary') opt.summary = true
else if (a === '--dry-run') opt.dryRun = true
else if (a === '--yes' || a === '-y') opt.yes = true
else if (a === '--no-color') opt.noColor = true
else if (a === '--timeout') {
const n = parseInt(args[i + 1] || '4000', 10)
if (Number.isFinite(n)) opt.timeoutMs = Math.max(250, Math.min(120000, n))
i++
} else rest.push(a)
}
return { opt, rest }
}
function bareP2pPrint(ctx, data, opt) {
if (opt && opt.quiet) return
if (opt && (opt.json || typeof data !== 'string')) {
ctx.console.log(typeof data === 'string' ? JSON.stringify({ message: data }) : JSON.stringify(data, null, 2))
return
}
ctx.console.log(String(data))
}
function bareP2pError(ctx, argv0, msg, next, opt) {
if (opt && opt.quiet) {
ctx.exitCode = 1
return
}
ctx.console.error(argv0 + ': ' + msg + (next ? ' · try: ' + next : ''))
ctx.exitCode = 1
}
function bareP2pSuggestSubcommand(sub, known) {
const s = String(sub || '')
if (!s) return ''
let best = ''
let bestScore = 1e9
for (const k of known || []) {
const kk = String(k || '')
const d = Math.abs(kk.length - s.length) + (kk[0] === s[0] ? 0 : 2)
if (d < bestScore) {
bestScore = d
best = kk
}
}
return bestScore <= 4 ? best : ''
}
function bareP2pFirstRunHint(ctx, app, hint) {
const env = ctx.env && typeof ctx.env === 'object' ? ctx.env : {}
if (env.BARE_P2P_NO_HINTS === '1' || env.BARE_P2P_NO_HINTS === 'true') return
const key = '__bare_p2p_hint_' + app
if (ctx[key]) return
ctx[key] = true
try {
ctx.console.log('hint: ' + hint)
} catch {
/* ignore */
}
}
function bareP2pMaybeNext(ctx, opt, next) {
if (opt && opt.quiet) return
if (next) ctx.console.log('next: ' + next)
}
function bareP2pHome(ctx) {
const env = ctx.env && typeof ctx.env === 'object' ? ctx.env : {}
const home = typeof env.HOME === 'string' && env.HOME ? env.HOME : '/home/guest'
return home
}
function bareP2pJoinPath(a, b) {
if (!a.endsWith('/')) return a + '/' + b
return a + b
}
function bareP2pDataDir(ctx) {
return bareP2pJoinPath(bareP2pHome(ctx), '.bare/p2p-suite')
}
function bareP2pDataFile(ctx, app) {
return bareP2pJoinPath(bareP2pDataDir(ctx), app + '.json')
}
async function bareP2pReadJson(ctx, path) {
try {
if (!ctx.vfs || typeof ctx.vfs.readFile !== 'function') return null
const b = await ctx.vfs.readFile(path)
if (!b) return null
const t = ctx.b4a.toString(b).trim()
if (!t) return null
return JSON.parse(t)
} catch {
return null
}
}
async function bareP2pWriteJson(ctx, path, obj) {
if (!ctx.vfs || typeof ctx.vfs.writeFile !== 'function') return false
const body = JSON.stringify(obj, null, 2) + '\n'
const b4 = ctx.b4a
const buf =
b4 && typeof b4.from === 'function'
? b4.from(body)
: new TextEncoder().encode(body)
try {
await ctx.vfs.writeFile(path, buf)
return true
} catch {
return false
}
}
function bareP2pDecodeEnvelope(line) {
const s = String(line || '')
if (!s.startsWith(BARE_P2P_SUITE_PREFIX)) return null
const payload = s.slice(BARE_P2P_SUITE_PREFIX.length).trim()
if (!payload) return null
try {
const obj = JSON.parse(payload)
if (!obj || typeof obj !== 'object') return null
return obj
} catch {
return null
}
}
function bareP2pEncodeEnvelope(app, kind, payload) {
return (
BARE_P2P_SUITE_PREFIX +
' ' +
JSON.stringify({
schema: 1,
suite: 'bare-p2p',
version: '1',
app,
kind,
tsMs: bareP2pNowMs(),
payload: payload || {}
})
)
}
function bareP2pSend(ctx, app, kind, payload) {
if (app === 'meshdrop' && typeof ctx.bareOsMeshdropSend === 'function') {
return ctx.bareOsMeshdropSend({
app,
kind,
payload: payload || {},
tsMs: bareP2pNowMs()
})
}
if (typeof ctx.bareOsChatSend !== 'function') {
return { ok: false, reason: 'bareOsChatSend unavailable' }
}
return ctx.bareOsChatSend(bareP2pEncodeEnvelope(app, kind, payload))
}
function bareP2pCollectFromHistory(ctx, app, limit) {
if (app === 'meshdrop' && typeof ctx.bareOsMeshdropHistory === 'function') {
let hist = []
try {
hist = ctx.bareOsMeshdropHistory(
Math.max(1, Math.min(BARE_P2P_SUITE_MAX_HISTORY, limit || 512))
)
} catch {
hist = []
}
if (!Array.isArray(hist)) return []
const out = []
for (const ev of hist) {
if (!ev || typeof ev !== 'object') continue
if (ev.app !== app) continue
out.push({
fromPeerKey: typeof ev.fromPeerKey === 'string' ? ev.fromPeerKey : '',
displayName: typeof ev.sender === 'string' ? ev.sender : '',
local: Boolean(ev.local),
receivedAtMs:
typeof ev.receivedAtMs === 'number' ? ev.receivedAtMs : bareP2pNowMs(),
packet: {
app,
kind: typeof ev.kind === 'string' ? ev.kind : 'unknown',
payload: ev.payload && typeof ev.payload === 'object' ? ev.payload : {}
}
})
}
return out
}
if (typeof ctx.bareOsChatHistory !== 'function') return []
let hist = []
try {
hist = ctx.bareOsChatHistory(
Math.max(1, Math.min(BARE_P2P_SUITE_MAX_HISTORY, limit || 512))
)
} catch {
hist = []
}
if (!Array.isArray(hist)) return []
const out = []
for (const ev of hist) {
if (!ev || typeof ev !== 'object') continue
const body = String(ev.body || '')
const decoded = bareP2pDecodeEnvelope(body)
if (!decoded || decoded.app !== app) continue
out.push({
fromPeerKey: typeof ev.fromPeerKey === 'string' ? ev.fromPeerKey : '',
displayName: typeof ev.displayName === 'string' ? ev.displayName : '',
local: Boolean(ev.local),
receivedAtMs:
typeof ev.receivedAtMs === 'number' ? ev.receivedAtMs : bareP2pNowMs(),
packet: decoded
})
}
return out
}
function bareP2pSubscribe(ctx, app, fn) {
if (app === 'meshdrop' && typeof ctx.bareOsMeshdropSubscribe === 'function') {
return ctx.bareOsMeshdropSubscribe((ev) => {
if (!ev || typeof ev !== 'object' || ev.app !== app) return
fn({
fromPeerKey: typeof ev.fromPeerKey === 'string' ? ev.fromPeerKey : '',
displayName: typeof ev.sender === 'string' ? ev.sender : '',
local: Boolean(ev.local),
receivedAtMs:
typeof ev.receivedAtMs === 'number' ? ev.receivedAtMs : bareP2pNowMs(),
packet: {
app,
kind: typeof ev.kind === 'string' ? ev.kind : 'unknown',
payload: ev.payload && typeof ev.payload === 'object' ? ev.payload : {}
}
})
})
}
if (typeof ctx.bareOsChatSubscribe !== 'function') return () => {}
return ctx.bareOsChatSubscribe((ev) => {
if (!ev || typeof ev !== 'object') return
const body = String(ev.body || '')
const decoded = bareP2pDecodeEnvelope(body)
if (!decoded || decoded.app !== app) return
fn({
fromPeerKey: typeof ev.fromPeerKey === 'string' ? ev.fromPeerKey : '',
displayName: typeof ev.displayName === 'string' ? ev.displayName : '',
local: Boolean(ev.local),
receivedAtMs:
typeof ev.receivedAtMs === 'number' ? ev.receivedAtMs : bareP2pNowMs(),
packet: decoded
})
})
}
async function bareP2pReadSwarmSnapshot(ctx) {
const out = {
atMs: bareP2pNowMs(),
peerCount: null,
topicCount: null,
peers: []
}
const snap = await bareP2pReadJson(ctx, '/proc/bare_os/swarm')
if (!snap || typeof snap !== 'object') return out
if (typeof snap.peerCount === 'number') out.peerCount = snap.peerCount
if (typeof snap.topicCount === 'number') out.topicCount = snap.topicCount
const peers = Array.isArray(snap.peers) ? snap.peers : []
const detailsRaw = await bareP2pReadJson(ctx, '/proc/bare_os/peer_details.json')
const details =
detailsRaw && typeof detailsRaw === 'object' && Array.isArray(detailsRaw.peers)
? detailsRaw.peers
: []
/** @type {Map<string, Record<string, unknown>>} */
const byKey = new Map()
for (const d of details) {
if (!d || typeof d !== 'object') continue
const rk = typeof d.remotePublicKey === 'string' ? d.remotePublicKey : ''
const pid = typeof d.peerId === 'string' ? d.peerId : ''
if (rk) byKey.set('k:' + rk, d)
if (pid) byKey.set('p:' + pid, d)
}
const merged = []
for (const p of peers) {
if (!p || typeof p !== 'object') continue
const rk = typeof p.remotePublicKey === 'string' ? p.remotePublicKey : ''
const pid = typeof p.peerId === 'string' ? p.peerId : ''
const d = (rk && byKey.get('k:' + rk)) || (pid && byKey.get('p:' + pid)) || null
merged.push(d && typeof d === 'object' ? { ...p, ...d } : p)
}
out.peers = merged.slice(0, 128)
return out
}
async function bareP2pReadProcJson(ctx, path) {
const v = await bareP2pReadJson(ctx, path)
return v && typeof v === 'object' ? v : {}
}
function bareOsTrustPolicyPath() {
return '/etc/bare-os/trust.policy.json'
}
async function bareOsTrustReadPolicy(ctx) {
const doc = await bareP2pReadJson(ctx, bareOsTrustPolicyPath())
if (!doc || typeof doc !== 'object') {
return {
schema: 1,
signerPins: [],
relayPolicy: { mode: 'consent-required' },
encryptionPolicy: { mode: 'per-space-keys', rotationDays: 30 }
}
}
if (!Array.isArray(doc.signerPins)) doc.signerPins = []
return doc
}
async function run(ctx, argv) {
const argv0 = argv[0] || 'trustctl'
const parsed = bareP2pParseCommonFlags(argv.slice(1))
const args = parsed.rest
const opt = parsed.opt
if (opt.help || args.length === 0) {
ctx.console.log(
bareP2pHelpText(
argv0,
'Inspect and edit trust roots, signer pins, and encryption policy.',
argv0 + ' status | inspect TARGET | pin add KEY | pin rm KEY | policy show',
['status', 'pin add <signerKey> --yes', 'inspect pear://<key>'],
['appctl', 'peerctl']
)
)
if (args.length === 0) ctx.exitCode = 1
return
}
const sub = String(args[0] || '').trim()
const policy = await bareOsTrustReadPolicy(ctx)
if (
sub === 'status' ||
sub === 'ls' ||
(sub === 'policy' && String(args[1] || '') === 'show')
) {
bareP2pPrint(ctx, policy, opt)
return
}
if (sub === 'inspect') {
const target = String(args[1] || '').trim()
if (!target) {
bareP2pError(ctx, argv0, 'inspect requires TARGET', argv0 + ' inspect pear://<key>', opt)
return
}
const out = {
schema: 1,
target,
accepted: true,
reasons: ['no deny rule matched', 'signer pin enforcement delegated to boot policy when enabled'],
crossRefs: ['/proc/bare_os/pear_trust.json', '/proc/bare_os/security_posture.json']
}
bareP2pPrint(ctx, out, opt)
return
}
if (sub === 'pin') {
const action = String(args[1] || '').trim()
const key = String(args[2] || '').trim()
if ((action !== 'add' && action !== 'rm') || !key) {
bareP2pError(ctx, argv0, 'pin requires add|rm KEY', argv0 + ' pin add <KEY>', opt)
return
}
if (!opt.yes) {
bareP2pError(ctx, argv0, 'confirmation required (pass --yes)', argv0 + ' pin ' + action + ' ' + key + ' --yes', opt)
return
}
if (action === 'add' && !policy.signerPins.includes(key)) {
policy.signerPins.push(key)
}
if (action === 'rm') {
policy.signerPins = policy.signerPins.filter((x) => x !== key)
}
if (opt.dryRun) {
bareP2pPrint(ctx, { ok: true, dryRun: true, signerPins: policy.signerPins }, opt)
return
}
const ok = await bareP2pWriteJson(ctx, bareOsTrustPolicyPath(), policy)
if (!ok) {
bareP2pError(ctx, argv0, 'failed writing trust policy', 'check VFS write access', opt)
return
}
bareP2pPrint(ctx, { ok: true, signerPins: policy.signerPins }, opt)
return
}
const sug = bareP2pSuggestSubcommand(sub, ['status', 'ls', 'inspect', 'pin', 'policy'])
bareP2pError(
ctx,
argv0,
'unsupported subcommand' + (sug ? ' (did you mean ' + sug + '?)' : ''),
argv0 + ' --help',
opt
)
}