fix: close kimi security acceptance gaps #12

Merged
ober merged 3 commits from fix/security-kimi-completion into main 2026-08-10 18:53:38 -04:00
Owner

Closes the remaining finish2-kimi3.md acceptance gaps.\n\nChanges:\n- Fix JMAP session accountCapabilities to include core/mail/vendor capabilities.\n- Add standard Email/query total and limit fields with unit, dispatcher, and golden fixture coverage.\n- Harden HTTP Content-Length parsing to strict decimal and fix streaming file-slice TLS writes.\n- Expand TLS renewal/SPKI pin rotation FreeBSD deployment docs.\n- Make make verify match Kimi acceptance by including e2e, audit, SBOM, and fuzz evidence.\n- Vendor the fuzz dependency closure and pin jsqlite fetch metadata.\n- Bump VERSION and synchronized package/app/native versions to 0.2.3.\n\nVerification:\n- jerboa_check_balance on all changed .ss files: OK.\n- jerboa_verify on changed production .ss files: OK.\n- jerboa_security_scan on lib/jjmap/session.ss, lib/jjmap/email.ss, lib/jjmap/http.ss, lib/jjmap/main.ss: no findings after documented CLI-only suppressions.\n- make test: PASS.\n- make verify: PASS, including security-gates, unit tests, Rust native tests, Android native tests, binary build, e2e, cargo audit, SBOM, and fuzz evidence.\n- env -i PATH=... ./jjmapd version: jjmapd 0.2.3.

Closes the remaining finish2-kimi3.md acceptance gaps.\n\nChanges:\n- Fix JMAP session accountCapabilities to include core/mail/vendor capabilities.\n- Add standard Email/query total and limit fields with unit, dispatcher, and golden fixture coverage.\n- Harden HTTP Content-Length parsing to strict decimal and fix streaming file-slice TLS writes.\n- Expand TLS renewal/SPKI pin rotation FreeBSD deployment docs.\n- Make make verify match Kimi acceptance by including e2e, audit, SBOM, and fuzz evidence.\n- Vendor the fuzz dependency closure and pin jsqlite fetch metadata.\n- Bump VERSION and synchronized package/app/native versions to 0.2.3.\n\nVerification:\n- jerboa_check_balance on all changed .ss files: OK.\n- jerboa_verify on changed production .ss files: OK.\n- jerboa_security_scan on lib/jjmap/session.ss, lib/jjmap/email.ss, lib/jjmap/http.ss, lib/jjmap/main.ss: no findings after documented CLI-only suppressions.\n- make test: PASS.\n- make verify: PASS, including security-gates, unit tests, Rust native tests, Android native tests, binary build, e2e, cargo audit, SBOM, and fuzz evidence.\n- env -i PATH=... ./jjmapd version: jjmapd 0.2.3.
fix: close kimi security acceptance gaps
Some checks failed
version-policy / required (pull_request) Successful in 5s
required-ci / required (pull_request) Failing after 1m4s
f3471a2337
fix: make security gates CI portable
Some checks failed
version-policy / required (pull_request) Successful in 5s
required-ci / required (pull_request) Failing after 6m3s
6f0035dab2
fix: avoid xxd in e2e smoke
All checks were successful
version-policy / required (pull_request) Successful in 7s
required-ci / required (pull_request) Successful in 8m10s
7ccd9f1898
ober scheduled this pull request to auto merge when all checks succeed 2026-08-10 18:53:25 -04:00
ober merged commit c8bea5f011 into main 2026-08-10 18:53:38 -04:00
ober referenced this pull request from a commit 2026-08-10 18:53:40 -04:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ober/jerboa-jmap!12
No description provided.