T00: fix pinned Jerboa runtime bootstrap #3

Merged
ober merged 2 commits from fix/astra-improv-t00 into main 2026-09-10 13:16:59 -04:00
Owner

T00 from /Users/user/jerboa-review-20260909/astra-improv.md.

Changes:

  • Add scripts/fetch-jerboa.sh to read generator_runtime from dependencies.lock.json with JSON parsing, clone/fetch vendor/jerboa, verify commit and tree, initialize submodules, reject dirty/mismatched dependency state, and publish a completed typed runtime cache under .tools/jerboa-runtime-cache.
  • Remove sibling ../jerboa defaults from generator execution and supply-chain/release paths.
  • Make scripts/run-jandroid.sh use the pinned runtime cache, keep --help/--version cheap, and explicitly enable unsafe prelude for the trusted generator/secure-output FFI path.
  • Add make bootstrap-runtime, make t00-contract, make binary, and make binary-smoke; wire the T00 contract into make test/make verify.
  • Broaden raw Kotlin source scanning across first-party specs while preserving the dedicated adversarial fixture.
  • Split CI into host-required and Android SDK compile jobs, both bootstrapping the pinned runtime.
  • Sync VERSION and jpkg.sexp to 0.1.4 and update README bootstrap/raw-source policy docs.

Local verification on macOS:

  • sh -n scripts/fetch-jerboa.sh scripts/run-jandroid.sh scripts/check-no-raw-kotlin.sh scripts/verify-supply-chain.sh scripts/release-evidence.sh tests/t00-contract-test.sh
  • tests/t00-contract-test.sh
  • scripts/verify-supply-chain.sh
  • scripts/fetch-jerboa.sh
  • make verify
  • make binary
  • make binary-smoke
  • scripts/run-jandroid.sh --version
  • scripts/run-jandroid.sh --help
  • git diff --check

Local Android compile limitation:

  • make ssd-compile generated the SSD project, then scripts/verify-android-sdk.sh stopped because this machine has no configured Android SDK (ANDROID_SDK_ROOT or ANDROID_HOME is required outside Make, and the earlier Make invocation lacked platforms/android-35/source.properties). The new CI Android job is intended to run this on an SDK-capable runner.

Not complete for the full review:

  • This PR implements the first required Android bootstrap PR (T00). T01-T17 still require substantial upstream Jerboa compiler work and later Android integration.
T00 from `/Users/user/jerboa-review-20260909/astra-improv.md`. Changes: - Add `scripts/fetch-jerboa.sh` to read `generator_runtime` from `dependencies.lock.json` with JSON parsing, clone/fetch `vendor/jerboa`, verify commit and tree, initialize submodules, reject dirty/mismatched dependency state, and publish a completed typed runtime cache under `.tools/jerboa-runtime-cache`. - Remove sibling `../jerboa` defaults from generator execution and supply-chain/release paths. - Make `scripts/run-jandroid.sh` use the pinned runtime cache, keep `--help`/`--version` cheap, and explicitly enable unsafe prelude for the trusted generator/secure-output FFI path. - Add `make bootstrap-runtime`, `make t00-contract`, `make binary`, and `make binary-smoke`; wire the T00 contract into `make test`/`make verify`. - Broaden raw Kotlin source scanning across first-party specs while preserving the dedicated adversarial fixture. - Split CI into host-required and Android SDK compile jobs, both bootstrapping the pinned runtime. - Sync `VERSION` and `jpkg.sexp` to `0.1.4` and update README bootstrap/raw-source policy docs. Local verification on macOS: - `sh -n scripts/fetch-jerboa.sh scripts/run-jandroid.sh scripts/check-no-raw-kotlin.sh scripts/verify-supply-chain.sh scripts/release-evidence.sh tests/t00-contract-test.sh` - `tests/t00-contract-test.sh` - `scripts/verify-supply-chain.sh` - `scripts/fetch-jerboa.sh` - `make verify` - `make binary` - `make binary-smoke` - `scripts/run-jandroid.sh --version` - `scripts/run-jandroid.sh --help` - `git diff --check` Local Android compile limitation: - `make ssd-compile` generated the SSD project, then `scripts/verify-android-sdk.sh` stopped because this machine has no configured Android SDK (`ANDROID_SDK_ROOT or ANDROID_HOME is required` outside Make, and the earlier Make invocation lacked `platforms/android-35/source.properties`). The new CI Android job is intended to run this on an SDK-capable runner. Not complete for the full review: - This PR implements the first required Android bootstrap PR (T00). T01-T17 still require substantial upstream Jerboa compiler work and later Android integration.
Fix pinned Jerboa runtime bootstrap
Some checks failed
version-policy / required (pull_request) Successful in 3m48s
required-ci / host-required (pull_request) Failing after 5m27s
required-ci / android-sdk (pull_request) Failing after 7m5s
59b203e2ac
Adjust CI gates for available runners
All checks were successful
version-policy / required (pull_request) Successful in 3m50s
required-ci / host-required (pull_request) Successful in 3m57s
required-ci / android-sdk (pull_request) Successful in 6m32s
c648baa008
ober scheduled this pull request to auto merge when all checks succeed 2026-09-10 13:16:46 -04:00
ober merged commit 0f2bb6b0c4 into main 2026-09-10 13:16:59 -04:00
ober referenced this pull request from a commit 2026-09-10 13:16:59 -04:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ober/jerboa-android!3
No description provided.