| 1 | # Compiled-host runtime inputs |
| 2 | |
| 3 | This is a release preparation contract, not runtime authority or a publication |
| 4 | approval. The runtime remains optional and Node remains the Core default. |
| 5 | |
| 6 | The exact local Bun observed during this packet is **1.4.0+34cbb9a40**, executable |
| 7 | SHA-256 `539598c775882420b9d8deb7dc14d845f20f7d26f5600c50ab067dde6ac3f3bf`. Its |
| 8 | full source revision is `34cbb9a40b4bd1bd767d134a7065e66c2432a676`, with WebKit |
| 9 | revision `0f966e81b78c84bb23213e391bc679c4ef83e56b`. This is one observed macOS |
| 10 | ARM64 binary, not qualification for other architectures or libc families. |
| 11 | |
| 12 | The [matching Bun license](https://raw.githubusercontent.com/oven-sh/bun/34cbb9a40b4bd1bd767d134a7065e66c2432a676/LICENSE.md) |
| 13 | identifies statically linked JavaScriptCore/WebCore under LGPL2 and TinyCC under |
| 14 | LGPL2.1. It provides the Bun/WebKit source rebuild path. Delivery must retain |
| 15 | the corresponding copyright/license texts and provide the exact matching |
| 16 | source, patches, build/relink recipe and application object/source inputs |
| 17 | needed to modify and relink the LGPL components. URLs or a single MIT label do |
| 18 | not constitute that payload. |
| 19 | |
| 20 | `stage-compiled-host.mjs` requires a reviewed JSON closure file with schema1, |
| 21 | exact `runtime_version`, full `runtime_revision`, `runtime_sha256`, full |
| 22 | `webkit_revision`, actual `libc` (`glibc`, `musl`, or `none`), current |
| 23 | `bundle_sha256` and `source_commit`; `notices`, `notices_sha256`, `relink_source`, |
| 24 | `source_sha256`; `license_closure: "complete"` and |
| 25 | `corresponding_source: "complete"`. Every named component must have an actual |
| 26 | `notice_components[name]: {file, sha256}` text included byte-for-byte in the |
| 27 | combined notices, including linked libraries, embedded polyfills and Rust |
| 28 | dependencies. Paths resolve only from this explicitly supplied local closure |
| 29 | file. The required notice inventory is enforced in the stager; the complete |
| 30 | per-platform component inventory must also be reviewed. |
| 31 | |
| 32 | The source `.tar.gz` must include `source_inputs` entries for `bun`, `webkit`, |
| 33 | `tinycc`, and `relink-recipe`, each naming its contained `root`; Bun and WebKit |
| 34 | entries also carry the exact corresponding revision. This inventory and hash |
| 35 | check detects missing/mixed inputs. Review of the complete reproduction and |
| 36 | relink recipe remains necessary: flags and archive member names alone do not |
| 37 | prove source sufficiency. Do not mark incomplete inputs complete. |
| 38 | |
| 39 | Exact corresponding Bun and TinyCC source archives are available from the |
| 40 | [matching Bun commit](https://codeload.github.com/oven-sh/bun/tar.gz/34cbb9a40b4bd1bd767d134a7065e66c2432a676) |
| 41 | and [matching TinyCC fork commit](https://codeload.github.com/oven-sh/tinycc/tar.gz/05f0fafaa3be31e31d7b4b5c17dc60f62c991171). |
| 42 | The Bun archive includes its exact TinyCC patch and build scripts. Matching |
| 43 | libwebp notice texts are available from Google's primary |
| 44 | [exact commit](https://chromium.googlesource.com/webm/libwebp/+/b7e29b9d75bd31422b00c2a446d49d7af06c328d/COPYING). |
| 45 | Earlier GitHub mirror 404 observations do not establish a source/notice absence. |
| 46 | |
| 47 | The matching WebKit release is |
| 48 | [`autobuild-0f966…`](https://github.com/oven-sh/WebKit/releases/tag/autobuild-0f966e81b78c84bb23213e391bc679c4ef83e56b). |
| 49 | Its 42 observed assets are ABI-specific prebuilts according to the pinned build |
| 50 | contract; no full source/relink archive was found among them. The generated |
| 51 | exact-source archive request returned HTTP 422 during the takeover. A full exact |
| 52 | fork source snapshot, generated-header/build inputs, complete copyright/license |
| 53 | texts for embedded components/polyfills/Rust dependencies, and a reviewed |
| 54 | rebuild/relink recipe are still required. API tree results were truncated and |
| 55 | must not be labeled a complete source inventory. No delivery-qualified closure |
| 56 | has been produced by these downloads. |
| 57 | |
| 58 | The exact build source also includes static SQLite on Linux/Windows, while macOS |
| 59 | loads system SQLite. Its in-tree source/public-domain dedication must be |
| 60 | accounted for in a complete per-platform component inventory. The stager's |
| 61 | required notice list is a minimum guard; full inventory and source sufficiency |
| 62 | remain reviewed input obligations, never conclusions from flags alone. |
| 63 | |
| 64 | The release workflow is explicitly opt-in and fails when those local reviewed |
| 65 | inputs or exact-source Native proof are absent. The compiled image is copied |
| 66 | from the already tested CI artifact, never rebuilt after Native containment |
| 67 | proof. Five direct-image protocol cases apply on every supported OS; macOS |
| 68 | adds a sixth reexec/jetsam case. These cases require zero failures and zero |
| 69 | skips and cannot substitute for the same exact compiled image's actual Rust |
| 70 | Native containment and memory enforcement or license/source closure. |
| 71 | |
| 72 | The official Bun 1.4.0 release has Android and musl runtime assets. Android is |
| 73 | **not a qualified Codewhale compiled-host delivery target** in this contract; |
| 74 | that is an evidence boundary, not a claim that upstream has no Android binary. |
| 75 | The existing static musl CLI remains available, while a musl runtime needs its |
| 76 | own exact-image Native receipt and complete source/notice closure. GNU runner |
| 77 | proof does not transfer. No additional delivery targets are enabled here. |
| 78 | |
| 79 | Delivery probes the actual selected Bun process and the actual compiled image |
| 80 | for platform/architecture. Both must equal the native runner and the exact-image |
| 81 | Native receipt; an emulated x64 Bun on ARM cannot be labeled ARM. Windows now |
| 82 | requires all nine current Native cases, including compiled-image containment |
| 83 | and memory enforcement plus seven LPAC cases. Linux/macOS require their two |
| 84 | compiled-image Rust cases, independently of the direct-image protocol cases. |
| 85 | This does not claim any of those remote cases ran locally. |
| 86 |