Adopt Jerboa 0.13.3 and qualify reproducible Conduit telemetry #8

Merged
ober merged 2 commits from feature/jerboa-0133-adoption-20260925 into main 2026-09-25 16:43:05 -04:00
Owner

Summary

  • Adopt packaged Jerboa 0.13.3 and its supported deterministic-compilation namespaces, with distinct output/parent/child identities and stable source manifests.
  • Use the self-contained fresh runtime and bundled linker inputs. Remove the separate Chez/main.o requirement and upstream compiler rebuild. Keep consumer source/object paths separate from runtime extraction; clear compiler namespaces for metadata queries.
  • Resolve secure-key libc symbols through the trusted loader; use reproducible macOS linking without constant UUID rewriting.
  • Accept jsshd sequence-bound authenticated telemetry while retaining the existing framing path; reject wrong keys and tampering.
  • Add bounded same-event Conduit/private-to-legacy storage and real detector parity checks and evidence.
  • Advance VERSION and package manifest to 0.1.6.

Verification

  • Full make verify: security, generated Rust tests, Scheme checks and dependency audit.
  • Two complete release builds: all five binaries match byte-for-byte; typed lock/staticlib, release inputs and source manifest all match (status=match). Evidence directory: dist/reproducibility-jerboa-0133-isolated.
  • make binary-smoke: code-signature validation and all five binaries pass.
  • Post-build make security: hostile-loader regression and secret scan pass.
  • Telemetry tests reject wrong key and modified header, nonce sequence, ciphertext and tag.
  • Same-event fixture: two matching private/projected legacy rows produce one identical daemon alert; deliberately changing legacy severity fails.
  • Installed Jerboa remains usable after the builds. No separate compiler build tree was required.

This addresses downstream adoption of ober/jerboa#97.
See evidence/jerboa-0133-qualification-2026-09-25.md and
evidence/conduit-telemetry-parity-2026-09-25.md for scope and limits.
This is not production cutover or live legacy-receiver parity evidence.

## Summary - Adopt packaged Jerboa 0.13.3 and its supported deterministic-compilation namespaces, with distinct output/parent/child identities and stable source manifests. - Use the self-contained fresh runtime and bundled linker inputs. Remove the separate Chez/main.o requirement and upstream compiler rebuild. Keep consumer source/object paths separate from runtime extraction; clear compiler namespaces for metadata queries. - Resolve secure-key libc symbols through the trusted loader; use reproducible macOS linking without constant UUID rewriting. - Accept jsshd sequence-bound authenticated telemetry while retaining the existing framing path; reject wrong keys and tampering. - Add bounded same-event Conduit/private-to-legacy storage and real detector parity checks and evidence. - Advance VERSION and package manifest to 0.1.6. ## Verification - Full `make verify`: security, generated Rust tests, Scheme checks and dependency audit. - Two complete release builds: all five binaries match byte-for-byte; typed lock/staticlib, release inputs and source manifest all match (`status=match`). Evidence directory: `dist/reproducibility-jerboa-0133-isolated`. - `make binary-smoke`: code-signature validation and all five binaries pass. - Post-build `make security`: hostile-loader regression and secret scan pass. - Telemetry tests reject wrong key and modified header, nonce sequence, ciphertext and tag. - Same-event fixture: two matching private/projected legacy rows produce one identical daemon alert; deliberately changing legacy severity fails. - Installed Jerboa remains usable after the builds. No separate compiler build tree was required. This addresses downstream adoption of https://git.jerboa.sh/ober/jerboa/issues/97. See `evidence/jerboa-0133-qualification-2026-09-25.md` and `evidence/conduit-telemetry-parity-2026-09-25.md` for scope and limits. This is not production cutover or live legacy-receiver parity evidence.
Adopt Jerboa 0.13.3 reproducible compiler and qualify Conduit telemetry
Some checks failed
version-policy / required (pull_request) Successful in 3m43s
required-ci / required (pull_request) Failing after 4m28s
3fc0094c46
ober scheduled this pull request to auto merge when all checks succeed 2026-09-25 16:17:48 -04:00
Fix Jerboa runtime libdirs for FreeBSD CI
All checks were successful
version-policy / required (pull_request) Successful in 3m43s
required-ci / required (pull_request) Successful in 11m30s
b5848b16a2
ober scheduled this pull request to auto merge when all checks succeed 2026-09-25 16:42:48 -04:00
ober merged commit 45f65d5070 into main 2026-09-25 16:43:05 -04:00
ober referenced this pull request from a commit 2026-09-25 16:43:06 -04:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ober/jerboa-secmon!8
No description provided.