- Rename scripts/gen-ctx-client-stub.mjs to gen-ctx-client-helper.mjs; update pretest, scripts README, and PLACEHOLDER_BASELINE. - Scan packages/bare-os-protocol/lib in verify-bare-imports.mjs; clarify scope in script header. - Document bundle health / marker allowlist workflow in bare-os-bare-libs README and quarterly upstream notes in docs/release-checklist.md. - Add ctx API release checklist to docs/reference/ctx-api-versioning.md. - Add shell param expansion V3 tests in bare-os-booter/test.js; add coreutils posix-test-int-compare.test.mjs and wire into bare-os-coreutils test script. - Sync conformance matrix, environment appendix, handbook ch.9, and add pathconf to docs/reference/posix-conformance-matrix.json for verify-compat-matrix.
bare-os-bare-libs
Builds trusted IIFE bundles from bare-module-manifest.json entries marked "bundle": true. Output:
kernel/lib/bare/bundles/<ctxKey>.jskernel/lib/bare/manifest.json(paths for the booter drive merge)- Mirrored under
packages/bare-os-seeder/kernel/lib/bare/for seeder parity
Documentation: Developer guide ch.12 — Bare modules · Kernel tree — lib/bare · docs/README — catalog.
Run from repo root:
npm run build -w bare-os-bare-libs
The booter loads these only when BARE_OS_BARE_MODULES is enabled and BARE_OS_BARE_DRIVE_BUNDLES is not disabled; see the developer guide.
Manifest rows may include optional tier (core default when omitted) and risk (low / medium / high) so distributors can filter bundles without reading upstream READMEs. The catalog sync scripts preserve unknown fields when merging from docs/bare-holepunch-catalog.json.
Bundle health, markers, and upstream closure
docs/audit/bundle-health.json— per-bundle byte sizes; regenerated bynpm run build -w bare-os-bare-libs. When a bundle’s size moves by more than roughly 10%, add a dated one-line note under Bundle health log below (or in the same PR description) so reviewers can tell intentional catalog bumps from accidents.scripts/verify-bundle-health.mjs— CI compares committed JSON to on-disk bundle sizes.scripts/verify-bundle-markers.mjs+docs/audit/bundle-marker-allowlist.json— gateTODO/NOT_IMPLEMENTEDsubstrings inside vendored IIFEs; shrink the allowlist when upgrading Holepunch packages removes markers.scripts/verify-bundle-throws.mjs+docs/audit/bundle-throw-allowlist.json— same forthrow new Error("not implemented")phrasing.
See docs/audit/PLACEHOLDER_BASELINE.md § P3 for policy: first-party kernel code stays marker-free via verify-runtime-no-incomplete-markers.mjs; bundle gaps close through version bumps, post-processing (rare), or allowlist shrink.
Bundle health log
| Date (UTC) | Note |
|---|---|
| Append a row when a bundle size change ≥ ~10% is intentional (catalog version, esbuild flags, or new upstream files). |