Fix deterministic compilation with scoped gensym identities #98

Merged
ober merged 1 commit from fix/issue-97-deterministic-compilation into master 2026-09-25 13:54:27 -04:00
Owner

Fresh compiler processes can serialize different FASL bytes because private gensym session identities vary. Add the explicit JERBOA_BUILD_GENSYM_NAMESPACE build mode to the bundled runtime, validating a 64-character lowercase SHA-256 namespace. Ordinary runtime behavior stays unchanged when it is unset. The documented manifest policy separates independent artifacts and compiler roles while preserving dependent identities.

Fixes #97.

The packaged-runtime regression covers the unpatched negative control, repeated raw FASL equality, independent/shared and mutually dependent identities, malformed inputs, ordinary runtime uniqueness, and actual jsqlite/cache compilation and loading. It runs from required CI. Version advances to 0.13.3.

Validation on macOS arm64:

  • Fresh copied self-contained package with isolated home/cache: all regression assertions pass; installed unpatched 0.13.2 reproduces both minimal and jsqlite/cache variance.
  • Secmon qualification with diagnostic hooks removed and its separate Chez installation unavailable: all five binary raw hashes match; binary smoke, hostile native-loader security, and mux telemetry pass.
  • Required local suites, including native parity, all 23 Wasm cases in Chromium/Firefox/WebKit, and 1,011 Wasm-GC assertions pass. Upstream two-build binary/program-image bytes match. Release-evidence assembly, Kotlin conformance, final package regression, and binary smoke pass.

The full verification exposed existing gate defects repaired here: release/debug wrapper lookup, typed binary version/loader context, JSON sentinel exhaustiveness, masked command failures, and macOS recursive evidence copying. Verification resumed at evidence assembly after the copy fix; completed suites were retained. Local native-link tests use pinned Rust 1.94.1 with CARGO_PROFILE_RELEASE_STRIP=none to avoid this host's Apple linker rejection of stripped dylibs. No browser bypass was used.

See docs/deterministic-compilation.md for the required namespace policy and docs/issue97-verification.md for scope and evidence. The downstream adapter is qualification evidence, not a secmon release or lock update. Original reports, final binaries, logs, and the consumer patch are preserved locally for review.

Fresh compiler processes can serialize different FASL bytes because private gensym session identities vary. Add the explicit `JERBOA_BUILD_GENSYM_NAMESPACE` build mode to the bundled runtime, validating a 64-character lowercase SHA-256 namespace. Ordinary runtime behavior stays unchanged when it is unset. The documented manifest policy separates independent artifacts and compiler roles while preserving dependent identities. Fixes https://git.jerboa.sh/ober/jerboa/issues/97. The packaged-runtime regression covers the unpatched negative control, repeated raw FASL equality, independent/shared and mutually dependent identities, malformed inputs, ordinary runtime uniqueness, and actual `jsqlite/cache` compilation and loading. It runs from required CI. Version advances to 0.13.3. Validation on macOS arm64: - Fresh copied self-contained package with isolated home/cache: all regression assertions pass; installed unpatched 0.13.2 reproduces both minimal and jsqlite/cache variance. - Secmon qualification with diagnostic hooks removed and its separate Chez installation unavailable: all five binary raw hashes match; binary smoke, hostile native-loader security, and mux telemetry pass. - Required local suites, including native parity, all 23 Wasm cases in Chromium/Firefox/WebKit, and 1,011 Wasm-GC assertions pass. Upstream two-build binary/program-image bytes match. Release-evidence assembly, Kotlin conformance, final package regression, and binary smoke pass. The full verification exposed existing gate defects repaired here: release/debug wrapper lookup, typed binary version/loader context, JSON sentinel exhaustiveness, masked command failures, and macOS recursive evidence copying. Verification resumed at evidence assembly after the copy fix; completed suites were retained. Local native-link tests use pinned Rust 1.94.1 with `CARGO_PROFILE_RELEASE_STRIP=none` to avoid this host's Apple linker rejection of stripped dylibs. No browser bypass was used. See `docs/deterministic-compilation.md` for the required namespace policy and `docs/issue97-verification.md` for scope and evidence. The downstream adapter is qualification evidence, not a secmon release or lock update. Original reports, final binaries, logs, and the consumer patch are preserved locally for review.
Fix compiler reproducibility with scoped gensym build identities
All checks were successful
required-ci / gerbil-compat (pull_request) Successful in 4m1s
version-policy / required (pull_request) Successful in 5m20s
dtrace / freebsd-usdt (pull_request) Successful in 14m32s
freebsd-required / required (pull_request) Successful in 16m14s
required-ci / required (pull_request) Successful in 17m44s
b7a90941dd
ober scheduled this pull request to auto merge when all checks succeed 2026-09-25 13:54:15 -04:00
ober merged commit a4c5e0960c into master 2026-09-25 13:54:27 -04:00
ober referenced this pull request from a commit 2026-09-25 13:54:28 -04:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ober/jerboa!98
No description provided.