Pin Jerboa v0.13.2 for core API gate #7

Closed
ober wants to merge 2 commits from chore/jerboa-v0.13.2-pin into master
Owner

Summary

  • Pin jerboa-db to the published Jerboa v0.13.2 release and select that release in clean checkouts, without adjacent source-tree fallbacks.
  • Keep the fail-closed support/core-api-check.ss and transport security gate intact.
  • Advance VERSION from 0.1.4 to 0.1.5 and update stale release-blocker documentation.

Verification

  • v0.13.2^{} resolves to Jerboa commit 2604e79232f31f5efd721b73b669fce10ebf0c66.
  • The published macOS arm64 artifact reports jerboa 0.13.2; make ensure-jerboa-core-api passes with it, including from an empty project-local tool directory.
  • make verify and sh .forgejo/ci-required.sh pass on macOS: 73 core, 7 migration, 5 backup security, 24 authenticated transport, and 7 TLS transport tests, plus TLS admission, import, security, and native audit checks.
  • sh .forgejo/require-version-bump.sh origin/master HEAD passes (VERSION 0.1.5 is valid).
  • This repository has no standalone binary target; the required CI script runs make verify and reports that condition explicitly. The macOS runner skips the Linux-only server security test by design. FreeBSD CI must independently pass the required gate.
## Summary - Pin jerboa-db to the published Jerboa v0.13.2 release and select that release in clean checkouts, without adjacent source-tree fallbacks. - Keep the fail-closed `support/core-api-check.ss` and transport security gate intact. - Advance `VERSION` from 0.1.4 to 0.1.5 and update stale release-blocker documentation. ## Verification - `v0.13.2^{}` resolves to Jerboa commit `2604e79232f31f5efd721b73b669fce10ebf0c66`. - The published macOS arm64 artifact reports `jerboa 0.13.2`; `make ensure-jerboa-core-api` passes with it, including from an empty project-local tool directory. - `make verify` and `sh .forgejo/ci-required.sh` pass on macOS: 73 core, 7 migration, 5 backup security, 24 authenticated transport, and 7 TLS transport tests, plus TLS admission, import, security, and native audit checks. - `sh .forgejo/require-version-bump.sh origin/master HEAD` passes (`VERSION 0.1.5 is valid`). - This repository has no standalone binary target; the required CI script runs `make verify` and reports that condition explicitly. The macOS runner skips the Linux-only server security test by design. FreeBSD CI must independently pass the required gate.
Pin Jerboa v0.13.2 for core API gate
Some checks failed
version-policy / required (pull_request) Successful in 3m42s
required-ci / required (pull_request) Failing after 5m13s
ac0f489b7c
Author
Owner

Withdrawing this pin: the published Jerboa v0.13.2 artifact passes support/core-api-check.ss, but the required FreeBSD transport gate is not reliable.

Reproduction on canonical FreeBSD amd64 (biggus), from commit ac0f489:

  • sh .forgejo/ci-required.sh failed twice. Core API, security, import, 73/73 core, 7/7 migration, 5/5 backup security, and 8/8 server security passed. tests/test-transport.ss ended 16/24, with no leader elected within 10 seconds and eight dependent assertions failing.
  • JERBOA_DB_TRANSPORT_BASE_PORT=45000 JERBOA_DB_TRANSPORT_TRACE=1 gmake test-transport also ended 16/24. Both listeners bound and authenticated request-vote/vote-response frames moved in both directions. Repeated simultaneous elections continued past the 10-second limit; there was no connect, decode, or authentication error. This rules out contention on the default port as the cause of these runs.
  • The published v0.13.1 artifact passes the same core API probe and contains the same lib/std/raft.ss. Its transport test passed 24/24 once on alternate port 45100, then failed 16/24 on the default port 42407. This is a timing-dependent Raft liveness defect shared by both releases, not a v0.13.2 API omission.

A jerboa-db test-only startup delay or longer timeout would hide the failing simultaneous-election path. No safe scoped change to the transport adapter was established. The pin should wait for a reviewed Jerboa Raft election fix and a repeated passing FreeBSD CI run; the transport gate must remain enabled.

Withdrawing this pin: the published Jerboa v0.13.2 artifact passes `support/core-api-check.ss`, but the required FreeBSD transport gate is not reliable. Reproduction on canonical FreeBSD amd64 (`biggus`), from commit `ac0f489`: - `sh .forgejo/ci-required.sh` failed twice. Core API, security, import, 73/73 core, 7/7 migration, 5/5 backup security, and 8/8 server security passed. `tests/test-transport.ss` ended 16/24, with no leader elected within 10 seconds and eight dependent assertions failing. - `JERBOA_DB_TRANSPORT_BASE_PORT=45000 JERBOA_DB_TRANSPORT_TRACE=1 gmake test-transport` also ended 16/24. Both listeners bound and authenticated request-vote/vote-response frames moved in both directions. Repeated simultaneous elections continued past the 10-second limit; there was no connect, decode, or authentication error. This rules out contention on the default port as the cause of these runs. - The published v0.13.1 artifact passes the same core API probe and contains the same `lib/std/raft.ss`. Its transport test passed 24/24 once on alternate port 45100, then failed 16/24 on the default port 42407. This is a timing-dependent Raft liveness defect shared by both releases, not a v0.13.2 API omission. A jerboa-db test-only startup delay or longer timeout would hide the failing simultaneous-election path. No safe scoped change to the transport adapter was established. The pin should wait for a reviewed Jerboa Raft election fix and a repeated passing FreeBSD CI run; the transport gate must remain enabled.
Revert "Pin Jerboa v0.13.2 for core API gate"
Some checks failed
version-policy / required (pull_request) Failing after 3m42s
required-ci / required (pull_request) Failing after 3m42s
3b18725529
This reverts commit ac0f489b7c.
ober closed this pull request 2026-09-25 00:45:47 -04:00
Some checks failed
version-policy / required (pull_request) Failing after 3m42s
Required
Details
required-ci / required (pull_request) Failing after 3m42s
Required
Details

Pull request closed

Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ober/jerboa-db!7
No description provided.