From 918709ea730a44844c00c82f400ede4ad5912e2f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Eren=20Ar=C4=B1?= Date: Sat, 19 Sep 2026 20:00:36 +0300 Subject: [PATCH 01/11] research: record published scholarly release v1 --- research/ROADMAP.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/research/ROADMAP.md b/research/ROADMAP.md index 9fadf95..e620b74 100644 --- a/research/ROADMAP.md +++ b/research/ROADMAP.md @@ -46,8 +46,9 @@ - [x] Define the pilot v1 archival/DOI policy and third-party binary boundary. - [x] Generate and verify the final machine-readable archival manifest from the pinned pilot, repeat, and materialization artifacts; bind it with a compact repository lock and fail-closed redistribution checks. -- [ ] Create a research-tagged release after repeat stability and final figures - are frozen. +- [x] Create a research-tagged release after repeat stability and final figures + are frozen. Published `research-v1` / **BPFCompat Research Dataset v1** + from commit `141c491bd1508600338e7bc27abbc5a117eb7508`. - [ ] Archive the release/dataset in a DOI-granting repository such as Zenodo. - [ ] Add the DOI to `CITATION.cff` and the README only after it exists. - [ ] Preserve exact code/data versions used for any manuscript. From 9ee4d590d598965db464b201d412459200ea7618 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Eren=20Ar=C4=B1?= Date: Sat, 19 Sep 2026 20:00:39 +0300 Subject: [PATCH 02/11] research: bind published research-v1 release --- research/ARCHIVAL.md | 29 +++++++++++++++++++++++++++++ 1 file changed, 29 insertions(+) diff --git a/research/ARCHIVAL.md b/research/ARCHIVAL.md index d1a5960..dc654fe 100644 --- a/research/ARCHIVAL.md +++ b/research/ARCHIVAL.md @@ -107,6 +107,35 @@ reproducibility slice, and permitted materialized inputs. The compiled cilium/ebpf loader and Falco `scap-open` remain physically absent and are represented only by `exclude-rebuildable` identity/contract records. +## Published research release + +The immutable research publication point for pilot v1 is: + +- annotated tag: `research-v1` +- tag target commit: + `141c491bd1508600338e7bc27abbc5a117eb7508` +- GitHub release: **BPFCompat Research Dataset v1** +- GitHub release ID: `392145710` +- published: `2026-09-19T16:58:52Z` + +Published assets and GitHub-reported SHA-256 digests: + +| Asset | Size | SHA-256 | +| --- | ---: | --- | +| `archive-manifest.json` | 458,992 B | `6ed6d38d57db57e75964829278a62c7bb4a12cd8fc5db97baebb05a1fdd5e927` | +| `archive-lock.json` | 1,506 B | `44e0ebe3d32c2c388002a4f44e5d0bf9a476a20ee702c137471a6be89235ddf3` | +| `bpfcompat-research-v1-payload.zip` | 12,899,271 B | `143a8e8a93e43aebbacfd73465a659ca4cb055db7a576960c9d50ed9bc90a817` | +| `RELEASE-CHECKSUMS.txt` | 272 B | `bc96087d78bdd8419189b2e51927f3e5c2908dad81155313663af3f29125fdd9` | + +The scholarly release workflow rebuilt the archive from the three pinned source +Actions artifacts, verified the committed archive lock, generated GitHub +provenance attestations for all four release files, created the annotated tag, +published the release, and then verified the final tag target and asset set. + +The tag is annotated but not GPG-signed; integrity for the release assets is +provided by the committed archive lock, release checksums, GitHub-reported asset +digests, and GitHub build-provenance attestations. + ## Release gates A research-tagged release and DOI should not be created until all of the From 0242949ca73714b3af1a59b18145cc710c8d1f9b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Eren=20Ar=C4=B1?= Date: Sat, 19 Sep 2026 20:00:41 +0300 Subject: [PATCH 03/11] research: expose Zenodo deposit checklist --- research/README.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/research/README.md b/research/README.md index 7af942b..0e9dd57 100644 --- a/research/README.md +++ b/research/README.md @@ -52,6 +52,8 @@ Publication-facing material is kept explicit and evidence-bounded: tables, and an input/output SHA-256 manifest enforced by CI; - [archive/v1/](archive/v1/) — frozen archive policy, compact archive lock, and the inputs used to regenerate the release-shaped DOI payload; +- [archive/v1/ZENODO.md](archive/v1/ZENODO.md) — exact manual Zenodo deposit + metadata and release-asset checklist for the DOI record; - [ROADMAP.md](ROADMAP.md) — remaining archival, DOI, and external academic-use gates. From 6611b8f7f2585efb614e443405dac5178af90d99 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Eren=20Ar=C4=B1?= Date: Sat, 19 Sep 2026 20:00:43 +0300 Subject: [PATCH 04/11] research: add exact Zenodo v1 deposit plan --- research/archive/v1/ZENODO.md | 112 ++++++++++++++++++++++++++++++++++ 1 file changed, 112 insertions(+) create mode 100644 research/archive/v1/ZENODO.md diff --git a/research/archive/v1/ZENODO.md b/research/archive/v1/ZENODO.md new file mode 100644 index 0000000..2b210ef --- /dev/null +++ b/research/archive/v1/ZENODO.md @@ -0,0 +1,112 @@ +# Zenodo deposit plan — BPFCompat Research Dataset v1 + +This file is the operator checklist for creating the DOI-bearing archival record +for the already-published GitHub research release. + +Do not publish a Zenodo record with placeholder or guessed identifiers. Reserve +or mint the DOI in Zenodo first, then update repository citation metadata in a +separate commit. + +## Source release + +- GitHub tag: `research-v1` +- release title: **BPFCompat Research Dataset v1** +- release commit: + `141c491bd1508600338e7bc27abbc5a117eb7508` +- GitHub release: + `https://github.com/Kernel-Guard/bpfcompat/releases/tag/research-v1` + +## Recommended deposit mode + +Use a **manual Zenodo upload** for the v1 research dataset. + +Reason: the GitHub release already exists, while Zenodo's GitHub integration +automatically ingests new releases only after the repository is enabled. The +research object is also a mixed evidence/data/reproducibility bundle rather than +only a software source release. + +## Files + +Upload these four files from the GitHub release without modification: + +| File | Size | SHA-256 | +| --- | ---: | --- | +| `archive-manifest.json` | 458,992 B | `6ed6d38d57db57e75964829278a62c7bb4a12cd8fc5db97baebb05a1fdd5e927` | +| `archive-lock.json` | 1,506 B | `44e0ebe3d32c2c388002a4f44e5d0bf9a476a20ee702c137471a6be89235ddf3` | +| `bpfcompat-research-v1-payload.zip` | 12,899,271 B | `143a8e8a93e43aebbacfd73465a659ca4cb055db7a576960c9d50ed9bc90a817` | +| `RELEASE-CHECKSUMS.txt` | 272 B | `bc96087d78bdd8419189b2e51927f3e5c2908dad81155313663af3f29125fdd9` | + +Verify the downloaded files against `RELEASE-CHECKSUMS.txt` before upload. + +## Zenodo metadata + +Use these values unless the Zenodo UI requires an equivalent normalized form. + +- **Resource type:** Dataset +- **Title:** BPFCompat Research Dataset v1: Empirical eBPF Compatibility Across Linux Vendor Kernels +- **Publication date:** 2026-09-19 +- **Creator:** Eren Arı +- **Version:** research-v1 +- **Language:** English +- **Visibility:** Public +- **Licenses:** Apache-2.0 and MIT +- **Keywords:** + - eBPF + - BPF + - Linux kernel + - compatibility + - vendor kernels + - libbpf + - BTF + - CO-RE + - reproducibility + - systems research + +Suggested description: + +> BPFCompat Research Dataset v1 is a frozen reproducibility package for an +> empirical pilot study of compiled eBPF artifact compatibility across Linux +> vendor kernels and loader paths. The canonical pilot contains 70/70 planned +> executions: 50 compatible, 13 incompatible, and 7 inconclusive. A bounded +> post-collection stability sample contains 21/21 same-exact-environment +> observations with no observed environment drift or same-environment verdict +> instability. The archive includes normalized evidence, deterministic +> RQ1–RQ4 analysis inputs/outputs, generated paper figures/tables, provenance, +> exact environment identities, and permitted materialized study inputs. +> Third-party compiled loader binaries whose complete redistribution notice set +> was not established are excluded and represented by hashes, source revisions, +> validation-contract identities, notices, and rebuild provenance. This release +> is a reproducibility archive of pilot evidence and is not a claim of peer +> review, population representativeness, institutional approval, or +> endorsement. + +### DOI field + +Select **No** for "Do you already have a DOI for this upload?" and use +**Get a DOI now** if you want the version DOI before publishing. + +Record both identifiers after publication: + +- **Version DOI** — cite this for exact `research-v1` reproducibility. +- **Concept DOI** — use this only when intentionally referring to the evolving + BPFCompat research dataset across versions. + +## Mixed-license note + +The payload contains BPFCompat-owned Apache-2.0 material and permitted +third-party-derived MIT material. File-level provenance, redistribution status, +and retained notice paths are authoritative in `archive-manifest.json`. +The excluded cilium/ebpf and Falco loader binaries are not present in the +payload. + +## After Zenodo publication + +Do not alter the `research-v1` GitHub release. + +Create a new repository commit/PR that: + +1. records the Zenodo record URL, version DOI, and concept DOI; +2. marks the DOI roadmap gate complete; +3. adds the **version DOI** to `CITATION.cff` for exact v1 citation; +4. adds DOI links to the repository/research README; +5. preserves the GitHub tag/release/archive hashes unchanged. From 01daa00b156f3f6070bce855920b2d8c09b297ae Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Eren=20Ar=C4=B1?= Date: Sat, 19 Sep 2026 20:01:09 +0300 Subject: [PATCH 05/11] research: state no-mutation policy precisely --- research/ARCHIVAL.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/research/ARCHIVAL.md b/research/ARCHIVAL.md index dc654fe..396a86c 100644 --- a/research/ARCHIVAL.md +++ b/research/ARCHIVAL.md @@ -109,7 +109,7 @@ represented only by `exclude-rebuildable` identity/contract records. ## Published research release -The immutable research publication point for pilot v1 is: +The frozen research publication point for pilot v1 is: - annotated tag: `research-v1` - tag target commit: @@ -131,6 +131,10 @@ The scholarly release workflow rebuilt the archive from the three pinned source Actions artifacts, verified the committed archive lock, generated GitHub provenance attestations for all four release files, created the annotated tag, published the release, and then verified the final tag target and asset set. +The GitHub API does not mark this release object as immutable, so v1 relies on a +project no-mutation policy plus the annotated tag, committed lock, checksums, +asset digests, and attestations. Corrections must create a new research version +rather than rewriting the published v1 evidence. The tag is annotated but not GPG-signed; integrity for the release assets is provided by the committed archive lock, release checksums, GitHub-reported asset From 3109656f4ff3ee60b23225db3a50f75e295119e7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Eren=20Ar=C4=B1?= Date: Sat, 19 Sep 2026 20:02:10 +0300 Subject: [PATCH 06/11] research: preserve frozen v1 payload after release --- research/ROADMAP.md | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/research/ROADMAP.md b/research/ROADMAP.md index e620b74..9fadf95 100644 --- a/research/ROADMAP.md +++ b/research/ROADMAP.md @@ -46,9 +46,8 @@ - [x] Define the pilot v1 archival/DOI policy and third-party binary boundary. - [x] Generate and verify the final machine-readable archival manifest from the pinned pilot, repeat, and materialization artifacts; bind it with a compact repository lock and fail-closed redistribution checks. -- [x] Create a research-tagged release after repeat stability and final figures - are frozen. Published `research-v1` / **BPFCompat Research Dataset v1** - from commit `141c491bd1508600338e7bc27abbc5a117eb7508`. +- [ ] Create a research-tagged release after repeat stability and final figures + are frozen. - [ ] Archive the release/dataset in a DOI-granting repository such as Zenodo. - [ ] Add the DOI to `CITATION.cff` and the README only after it exists. - [ ] Preserve exact code/data versions used for any manuscript. From 7bfcdb9dbbfb2f33df7c4ecefc50ebf8b79bfb2a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Eren=20Ar=C4=B1?= Date: Sat, 19 Sep 2026 20:02:13 +0300 Subject: [PATCH 07/11] research: preserve frozen v1 payload after release --- research/ARCHIVAL.md | 33 --------------------------------- 1 file changed, 33 deletions(-) diff --git a/research/ARCHIVAL.md b/research/ARCHIVAL.md index 396a86c..d1a5960 100644 --- a/research/ARCHIVAL.md +++ b/research/ARCHIVAL.md @@ -107,39 +107,6 @@ reproducibility slice, and permitted materialized inputs. The compiled cilium/ebpf loader and Falco `scap-open` remain physically absent and are represented only by `exclude-rebuildable` identity/contract records. -## Published research release - -The frozen research publication point for pilot v1 is: - -- annotated tag: `research-v1` -- tag target commit: - `141c491bd1508600338e7bc27abbc5a117eb7508` -- GitHub release: **BPFCompat Research Dataset v1** -- GitHub release ID: `392145710` -- published: `2026-09-19T16:58:52Z` - -Published assets and GitHub-reported SHA-256 digests: - -| Asset | Size | SHA-256 | -| --- | ---: | --- | -| `archive-manifest.json` | 458,992 B | `6ed6d38d57db57e75964829278a62c7bb4a12cd8fc5db97baebb05a1fdd5e927` | -| `archive-lock.json` | 1,506 B | `44e0ebe3d32c2c388002a4f44e5d0bf9a476a20ee702c137471a6be89235ddf3` | -| `bpfcompat-research-v1-payload.zip` | 12,899,271 B | `143a8e8a93e43aebbacfd73465a659ca4cb055db7a576960c9d50ed9bc90a817` | -| `RELEASE-CHECKSUMS.txt` | 272 B | `bc96087d78bdd8419189b2e51927f3e5c2908dad81155313663af3f29125fdd9` | - -The scholarly release workflow rebuilt the archive from the three pinned source -Actions artifacts, verified the committed archive lock, generated GitHub -provenance attestations for all four release files, created the annotated tag, -published the release, and then verified the final tag target and asset set. -The GitHub API does not mark this release object as immutable, so v1 relies on a -project no-mutation policy plus the annotated tag, committed lock, checksums, -asset digests, and attestations. Corrections must create a new research version -rather than rewriting the published v1 evidence. - -The tag is annotated but not GPG-signed; integrity for the release assets is -provided by the committed archive lock, release checksums, GitHub-reported asset -digests, and GitHub build-provenance attestations. - ## Release gates A research-tagged release and DOI should not be created until all of the From dc479089d66dcaeda2ed62f51000d66688f093ab Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Eren=20Ar=C4=B1?= Date: Sat, 19 Sep 2026 20:02:17 +0300 Subject: [PATCH 08/11] research: preserve frozen v1 payload after release --- research/README.md | 2 -- 1 file changed, 2 deletions(-) diff --git a/research/README.md b/research/README.md index 0e9dd57..7af942b 100644 --- a/research/README.md +++ b/research/README.md @@ -52,8 +52,6 @@ Publication-facing material is kept explicit and evidence-bounded: tables, and an input/output SHA-256 manifest enforced by CI; - [archive/v1/](archive/v1/) — frozen archive policy, compact archive lock, and the inputs used to regenerate the release-shaped DOI payload; -- [archive/v1/ZENODO.md](archive/v1/ZENODO.md) — exact manual Zenodo deposit - metadata and release-asset checklist for the DOI record; - [ROADMAP.md](ROADMAP.md) — remaining archival, DOI, and external academic-use gates. From ee4354ad77cb423e5fa23cdece0354000fc5fab2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Eren=20Ar=C4=B1?= Date: Sat, 19 Sep 2026 20:02:20 +0300 Subject: [PATCH 09/11] research: keep post-release DOI notes outside frozen payload --- research/archive/v1/ZENODO.md | 112 ---------------------------------- 1 file changed, 112 deletions(-) delete mode 100644 research/archive/v1/ZENODO.md diff --git a/research/archive/v1/ZENODO.md b/research/archive/v1/ZENODO.md deleted file mode 100644 index 2b210ef..0000000 --- a/research/archive/v1/ZENODO.md +++ /dev/null @@ -1,112 +0,0 @@ -# Zenodo deposit plan — BPFCompat Research Dataset v1 - -This file is the operator checklist for creating the DOI-bearing archival record -for the already-published GitHub research release. - -Do not publish a Zenodo record with placeholder or guessed identifiers. Reserve -or mint the DOI in Zenodo first, then update repository citation metadata in a -separate commit. - -## Source release - -- GitHub tag: `research-v1` -- release title: **BPFCompat Research Dataset v1** -- release commit: - `141c491bd1508600338e7bc27abbc5a117eb7508` -- GitHub release: - `https://github.com/Kernel-Guard/bpfcompat/releases/tag/research-v1` - -## Recommended deposit mode - -Use a **manual Zenodo upload** for the v1 research dataset. - -Reason: the GitHub release already exists, while Zenodo's GitHub integration -automatically ingests new releases only after the repository is enabled. The -research object is also a mixed evidence/data/reproducibility bundle rather than -only a software source release. - -## Files - -Upload these four files from the GitHub release without modification: - -| File | Size | SHA-256 | -| --- | ---: | --- | -| `archive-manifest.json` | 458,992 B | `6ed6d38d57db57e75964829278a62c7bb4a12cd8fc5db97baebb05a1fdd5e927` | -| `archive-lock.json` | 1,506 B | `44e0ebe3d32c2c388002a4f44e5d0bf9a476a20ee702c137471a6be89235ddf3` | -| `bpfcompat-research-v1-payload.zip` | 12,899,271 B | `143a8e8a93e43aebbacfd73465a659ca4cb055db7a576960c9d50ed9bc90a817` | -| `RELEASE-CHECKSUMS.txt` | 272 B | `bc96087d78bdd8419189b2e51927f3e5c2908dad81155313663af3f29125fdd9` | - -Verify the downloaded files against `RELEASE-CHECKSUMS.txt` before upload. - -## Zenodo metadata - -Use these values unless the Zenodo UI requires an equivalent normalized form. - -- **Resource type:** Dataset -- **Title:** BPFCompat Research Dataset v1: Empirical eBPF Compatibility Across Linux Vendor Kernels -- **Publication date:** 2026-09-19 -- **Creator:** Eren Arı -- **Version:** research-v1 -- **Language:** English -- **Visibility:** Public -- **Licenses:** Apache-2.0 and MIT -- **Keywords:** - - eBPF - - BPF - - Linux kernel - - compatibility - - vendor kernels - - libbpf - - BTF - - CO-RE - - reproducibility - - systems research - -Suggested description: - -> BPFCompat Research Dataset v1 is a frozen reproducibility package for an -> empirical pilot study of compiled eBPF artifact compatibility across Linux -> vendor kernels and loader paths. The canonical pilot contains 70/70 planned -> executions: 50 compatible, 13 incompatible, and 7 inconclusive. A bounded -> post-collection stability sample contains 21/21 same-exact-environment -> observations with no observed environment drift or same-environment verdict -> instability. The archive includes normalized evidence, deterministic -> RQ1–RQ4 analysis inputs/outputs, generated paper figures/tables, provenance, -> exact environment identities, and permitted materialized study inputs. -> Third-party compiled loader binaries whose complete redistribution notice set -> was not established are excluded and represented by hashes, source revisions, -> validation-contract identities, notices, and rebuild provenance. This release -> is a reproducibility archive of pilot evidence and is not a claim of peer -> review, population representativeness, institutional approval, or -> endorsement. - -### DOI field - -Select **No** for "Do you already have a DOI for this upload?" and use -**Get a DOI now** if you want the version DOI before publishing. - -Record both identifiers after publication: - -- **Version DOI** — cite this for exact `research-v1` reproducibility. -- **Concept DOI** — use this only when intentionally referring to the evolving - BPFCompat research dataset across versions. - -## Mixed-license note - -The payload contains BPFCompat-owned Apache-2.0 material and permitted -third-party-derived MIT material. File-level provenance, redistribution status, -and retained notice paths are authoritative in `archive-manifest.json`. -The excluded cilium/ebpf and Falco loader binaries are not present in the -payload. - -## After Zenodo publication - -Do not alter the `research-v1` GitHub release. - -Create a new repository commit/PR that: - -1. records the Zenodo record URL, version DOI, and concept DOI; -2. marks the DOI roadmap gate complete; -3. adds the **version DOI** to `CITATION.cff` for exact v1 citation; -4. adds DOI links to the repository/research README; -5. preserves the GitHub tag/release/archive hashes unchanged. From 34957b3bb119592886026cc9a490f7cb1578499e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Eren=20Ar=C4=B1?= Date: Sat, 19 Sep 2026 20:02:39 +0300 Subject: [PATCH 10/11] docs: add post-release Zenodo deposit checklist --- docs/research-v1-zenodo.md | 125 +++++++++++++++++++++++++++++++++++++ 1 file changed, 125 insertions(+) create mode 100644 docs/research-v1-zenodo.md diff --git a/docs/research-v1-zenodo.md b/docs/research-v1-zenodo.md new file mode 100644 index 0000000..9d311d4 --- /dev/null +++ b/docs/research-v1-zenodo.md @@ -0,0 +1,125 @@ +# BPFCompat Research Dataset v1 — Zenodo deposit checklist + +This document records the **post-release** DOI workflow for the already-published +BPFCompat research dataset. It intentionally lives outside `research/**` so the +frozen `research-v1` archive payload and its committed archive lock remain +unchanged. + +## Current publication state + +- GitHub tag: `research-v1` +- tag type: annotated tag +- tag target commit: + `141c491bd1508600338e7bc27abbc5a117eb7508` +- GitHub release: **BPFCompat Research Dataset v1** +- GitHub release ID: `392145710` +- published: `2026-09-19T16:58:52Z` +- DOI: **not yet minted** + +The GitHub API does not mark the release object itself immutable. Project policy +for v1 is therefore **no mutation**: corrections must produce a new research +version instead of replacing published v1 evidence. + +## Release assets + +Upload the following release assets to Zenodo without modification. + +| File | Size | GitHub SHA-256 | +| --- | ---: | --- | +| `archive-manifest.json` | 458,992 B | `6ed6d38d57db57e75964829278a62c7bb4a12cd8fc5db97baebb05a1fdd5e927` | +| `archive-lock.json` | 1,506 B | `44e0ebe3d32c2c388002a4f44e5d0bf9a476a20ee702c137471a6be89235ddf3` | +| `bpfcompat-research-v1-payload.zip` | 12,899,271 B | `143a8e8a93e43aebbacfd73465a659ca4cb055db7a576960c9d50ed9bc90a817` | +| `RELEASE-CHECKSUMS.txt` | 272 B | `bc96087d78bdd8419189b2e51927f3e5c2908dad81155313663af3f29125fdd9` | + +The release workflow generated GitHub build-provenance attestations for all four +files before publishing the release. + +## Recommended Zenodo deposit mode + +Use a **manual Zenodo upload** for this research record. + +The `research-v1` GitHub release already exists, while Zenodo's GitHub +integration is intended to ingest releases after a repository is enabled. The +research object is also primarily a reproducibility dataset/evidence bundle, +with code included as supporting material. + +## Zenodo metadata + +Recommended values: + +- **Resource type:** Dataset +- **Title:** BPFCompat Research Dataset v1: Empirical eBPF Compatibility Across Linux Vendor Kernels +- **Publication date:** 2026-09-19 +- **Creator:** Eren Arı +- **Version:** research-v1 +- **Language:** English +- **Visibility:** Public +- **Licenses:** Apache-2.0 and MIT +- **Keywords:** + - eBPF + - BPF + - Linux kernel + - compatibility + - vendor kernels + - libbpf + - BTF + - CO-RE + - reproducibility + - systems research + +Suggested description: + +> BPFCompat Research Dataset v1 is a frozen reproducibility package for an +> empirical pilot study of compiled eBPF artifact compatibility across Linux +> vendor kernels and loader paths. The canonical pilot contains 70/70 planned +> executions: 50 compatible, 13 incompatible, and 7 inconclusive. A bounded +> post-collection stability sample contains 21/21 same-exact-environment +> observations with no observed environment drift or same-environment verdict +> instability. The archive includes normalized evidence, deterministic RQ1–RQ4 +> analysis inputs/outputs, generated paper figures/tables, provenance, exact +> environment identities, and permitted materialized study inputs. +> Third-party compiled loader binaries whose complete redistribution notice set +> was not established are excluded and represented by hashes, source revisions, +> validation-contract identities, notices, and rebuild provenance. This release +> is a reproducibility archive of pilot evidence and is not a claim of peer +> review, population representativeness, institutional approval, or +> endorsement. + +## DOI handling + +For the Zenodo DOI field: + +1. choose **No** for "Do you already have a DOI for this upload?"; +2. use **Get a DOI now** if the exact version DOI is needed before publication; +3. do not add the reserved/minted DOI to the frozen `research-v1` release; +4. after publication, record both: + - the **Version DOI** for exact `research-v1` citation; + - the **Concept DOI** for the evolving dataset family. + +For reproducibility claims and the v1 manuscript, prefer the **Version DOI**. + +## Mixed-license note + +The archive contains BPFCompat-owned Apache-2.0 material and permitted +third-party-derived MIT material. File-level provenance, redistribution status, +and retained notice paths in `archive-manifest.json` are authoritative. + +The compiled cilium/ebpf project-loader binary and Falco `scap-open` binary are +not present in the DOI payload. + +## After Zenodo publication + +Create a new post-release repository PR, without rewriting the `research-v1` +tag or GitHub release, that: + +1. records the Zenodo record URL, Version DOI, and Concept DOI; +2. adds the Version DOI to `CITATION.cff`; +3. adds DOI links to the repository README and research-facing documentation; +4. records that the Zenodo/DOI archival gate is complete; +5. leaves the GitHub release asset hashes unchanged. + +## Frozen-v1 note + +The `research/**` tree is part of the archived v1 payload. Post-release +bookkeeping should therefore remain outside that frozen payload unless a new +research version and archive lock are intentionally created. From 98d506b944d7eb626d82fd8b2311630a6fe668aa Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Eren=20Ar=C4=B1?= Date: Sat, 19 Sep 2026 20:23:52 +0300 Subject: [PATCH 11/11] docs: harden Zenodo deposit integrity and duplicate checks --- docs/research-v1-zenodo.md | 38 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) diff --git a/docs/research-v1-zenodo.md b/docs/research-v1-zenodo.md index 9d311d4..0601686 100644 --- a/docs/research-v1-zenodo.md +++ b/docs/research-v1-zenodo.md @@ -34,6 +34,26 @@ Upload the following release assets to Zenodo without modification. The release workflow generated GitHub build-provenance attestations for all four files before publishing the release. +### Transfer-integrity gate + +Before uploading anything to Zenodo: + +1. download all four assets from the published `research-v1` GitHub release; +2. compute SHA-256 for each downloaded file; +3. compare every digest against the table above and + `RELEASE-CHECKSUMS.txt`; +4. stop the deposit if any filename, size, or SHA-256 differs. + +After the Zenodo record is published: + +1. download all four files from the published Zenodo record; +2. recompute SHA-256 for each file; +3. compare every digest against the same GitHub release values above; +4. keep the Zenodo/DOI archival gate open if any post-publication digest differs. + +The DOI record is considered an exact archival copy of `research-v1` only when +both the pre-upload and post-publication comparisons pass for all four files. + ## Recommended Zenodo deposit mode Use a **manual Zenodo upload** for this research record. @@ -43,6 +63,22 @@ integration is intended to ingest releases after a repository is enabled. The research object is also primarily a reproducibility dataset/evidence bundle, with code included as supporting material. +### Duplicate-record preflight + +Before creating the manual Zenodo record: + +1. search Zenodo for an existing record matching **BPFCompat Research Dataset + v1**, `research-v1`, or the GitHub release URL; +2. check the Zenodo GitHub integration state for + `Kernel-Guard/bpfcompat` and confirm that it has **not** already processed + the `research-v1` release; +3. proceed with the manual deposit only if both checks show that no Zenodo record + already represents this release. + +If an existing or automatically ingested record is found, do not create a second +manual record or DOI for the same `research-v1` publication. Reconcile and use +the existing record instead. + ## Zenodo metadata Recommended values: @@ -115,6 +151,8 @@ tag or GitHub release, that: 1. records the Zenodo record URL, Version DOI, and Concept DOI; 2. adds the Version DOI to `CITATION.cff`; 3. adds DOI links to the repository README and research-facing documentation; + a target under `research/**` is allowed only after creating a new research + version and archive lock; 4. records that the Zenodo/DOI archival gate is complete; 5. leaves the GitHub release asset hashes unchanged.