feat(jdisk): ,jdisk encrypted S3 drive with //embed/-only state #31

Merged
ober merged 1 commit from feat/jdisk into main 2026-09-03 13:02:43 -04:00
Owner

Adds the jdisk feature: the vendored jdrive encrypted S3 drive CLI as a ,jdisk meta command whose profile state (config, scrypt+ChaCha20-Poly1305 key vault, generation marks) lives exclusively in the encrypted //embed/ store, and whose AWS credentials are read from //embed/aws/credentials and injected explicitly so they never enter the process environment.

Depends on ober/jerboa-drive#36 (state-I/O override + credentials parameter). vendor/ is fetched from main at build time, so required-ci here stays red until that PR merges — no action needed on this branch.

  • jerboa-src/src/jsh/jdisk.{ss,static}: lazy loader + WPO-safe static registration for jdrive's run-cli and the two parameter objects the hardened mode parameterizes per invocation; console-gated like ,pass, refused while locked
  • ffi-shim.c: jerboa-crypto OpenSSL-shim ABI compatibility layer over the Rust natives — real one-shot + incremental SHA-256 (SigV4, chunk checksums), HMAC, scrypt, AEAD bridge, rand, constant-time compare; cipher/ed25519 surface fails closed
  • vendor/build plumbing: jerboa-drive + jerboa-crypto transpile staging, libdirs in all four jerbuild configs, source-lock row, 27 shim symbols registered for static builds
  • features.def jdisk entry (requires embed + native lib); docs; VERSION 0.6.0
  • test/test-jdisk.sh: 14 assertions — locked refusal, init/profile-status/unlock-test round-trip through //embed/, named-profile isolation, wrong-password rejection, no plaintext ~/.jdrive (all green locally)

Local verification: make macos green, test-jdisk 14/14 PASS, make test green. test-pass.sh T2 failures reproduce on clean main (pre-existing).

Adds the `jdisk` feature: the vendored jdrive encrypted S3 drive CLI as a `,jdisk` meta command whose profile state (config, scrypt+ChaCha20-Poly1305 key vault, generation marks) lives exclusively in the encrypted `//embed/` store, and whose AWS credentials are read from `//embed/aws/credentials` and injected explicitly so they never enter the process environment. **Depends on ober/jerboa-drive#36** (state-I/O override + credentials parameter). `vendor/` is fetched from main at build time, so required-ci here stays red until that PR merges — no action needed on this branch. - `jerboa-src/src/jsh/jdisk.{ss,static}`: lazy loader + WPO-safe static registration for jdrive's run-cli and the two parameter objects the hardened mode parameterizes per invocation; console-gated like `,pass`, refused while locked - `ffi-shim.c`: jerboa-crypto OpenSSL-shim ABI compatibility layer over the Rust natives — real one-shot + incremental SHA-256 (SigV4, chunk checksums), HMAC, scrypt, AEAD bridge, rand, constant-time compare; cipher/ed25519 surface fails closed - vendor/build plumbing: jerboa-drive + jerboa-crypto transpile staging, libdirs in all four jerbuild configs, source-lock row, 27 shim symbols registered for static builds - features.def jdisk entry (requires embed + native lib); docs; VERSION 0.6.0 - test/test-jdisk.sh: 14 assertions — locked refusal, init/profile-status/unlock-test round-trip through //embed/, named-profile isolation, wrong-password rejection, no plaintext ~/.jdrive (all green locally) Local verification: `make macos` green, test-jdisk 14/14 PASS, `make test` green. test-pass.sh T2 failures reproduce on clean main (pre-existing).
feat(jdisk): add ,jdisk encrypted S3 drive with //embed/-only state
Some checks failed
required-ci / required (pull_request) Failing after 3m50s
version-policy / required (pull_request) Successful in 3m51s
2bea483a62
Add the jdisk feature: the vendored jdrive encrypted S3 drive CLI as a
,jdisk meta command whose profile state (config, scrypt+ChaCha20-Poly1305
key vault, generation marks) lives exclusively in the encrypted //embed/
store via jdrive's state-I/O override, and whose AWS credentials are read
from //embed/aws/credentials and injected explicitly so they never enter
the process environment.

- jerboa-src/src/jsh/jdisk.{ss,static}: lazy loader + WPO-safe static
  registration for jdrive's run-cli and the two parameter objects the
  hardened mode parameterizes per invocation (state-I/O override, AWS
  credentials tuple); console-gated like ,pass, refused while locked
- ffi-shim.c: jerboa-crypto OpenSSL-shim ABI compatibility layer over the
  Rust natives (full digest one-shot + incremental SHA-256 for SigV4 and
  chunk checksums, HMAC, scrypt, AEAD bridge, rand, constant-time
  compare, error surfacing; cipher/ed25519 surface fails closed)
- vendor/build plumbing: jerboa-drive + jerboa-crypto transpile staging,
  libdirs for all four jerbuild configs, source-lock row pinning the
  jerboa-drive PR, 27 shim symbols registered for static macOS builds
- features.def jdisk entry (requires embed + native lib; retains the
  jdrive closure via (jsh jdisk-static))
- docs + VERSION 0.6.0; test/test-jdisk.sh: 14 assertions covering locked
  refusal, init/profile-status/unlock-test round-trip through //embed/,
  named-profile isolation, wrong-password rejection, no plaintext ~/.jdrive
ober scheduled this pull request to auto merge when all checks succeed 2026-09-03 13:02:28 -04:00
ober merged commit 2f823608c3 into main 2026-09-03 13:02:43 -04:00
ober referenced this pull request from a commit 2026-09-03 13:02:44 -04:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ober/jerboa-shell-extras!31
No description provided.