NeoGraph 0.13.0 Linux — corresponding LGPL library-only source
Prepared 2026-10-05; source packaging, not runtime or legal-compliance certification.

1. DELIVERY, SOURCES AND EXACT PACKAGING MODIFICATIONS

This asset supplies preferred-modification source for the actual dynamically bundled keyutils-libs1.6.3-1.el9 and libxcrypt4.4.18-3.el9 libraries on x86_64 and aarch64. The chosen source-delivery route is to accompany corresponding Linux binaries with this actual source asset at the same designated GitHub release download location, under LGPL2.1 section4. Publisher attachment and prominent download link are required before distribution; no nonexistent release URL or future-fulfillment offer is asserted.

Sources were extracted from matching authoritative AlmaLinux SRPMs:
https://repo.almalinux.org/vault/9.8/BaseOS/Source/Packages/keyutils-1.6.3-1.el9.src.rpm
 SHA256 a133ed9e7dea39fda653cbee80a35a9cf389eb91c2c95f52c59d1ad6f457010b
https://repo.almalinux.org/vault/9.8/BaseOS/Source/Packages/libxcrypt-4.4.18-3.el9.src.rpm
 SHA256 504d77aa6c8d96f0100947067b73b9b9c617a978bfd3af10b3ddba0106cf4703
Upstream payload source SHA256:
 keyutils1.6.3 tar.gz a61d5706136ae4c05bd48f86186bcfdbd88dd8bd5107e3e195c924cfc1b39bb4
 libxcrypt4.4.18 tar.gz 3801f0263a8596b15ec466343fc1fdc4ad4ec7416c51e038a3528fd47f3be01a
The exact libxcrypt downstream LTO patch SHA256 is64bc629722a985cea146d6a74b808f0d8f3f3295f8fa090830cb7aedd953cd56. Complete source/patch/spec digests, matching binary/source XML fragments, repomd-linked primary checksums and actual binary-RPM SourceRPM mapping are retained in provenance. The full unrelated repository snapshots/original containers are NOT distributed in this asset. The extracted fragments are bounded evidence, not a claim of RPM signature authentication. No RPM signature verification or byte-identical RPM reproduction is claimed.

The delivered source profile is intentionally library-only, not an unchanged upstream project tarball. Every libxcrypt lib/ implementation, header, data table, version map, interface template and generator input remains byte-identical to the verified source payload before applying the supplied distro patch. All keyutils shared-library code/interfaces/version script, upstream version specification and pkgconfig input remain byte-identical. No library module, hash method or ABI has been omitted.

libxcrypt LICENSING126–135 explicitly identifies unknown holders/no license statements for unrelated tests that do not contribute to the installed library/headers. Nine named files actually exist in this version and have no embedded redistribution grant: test/{alg-des.c,alg-md4.c,alg-md5.c,alg-sha256.c,alg-sha512.c,des-cases.h,des-obsolete.c,des-obsolete_r.c,gensalt.c}. The delivered profile omits the entire unrelated test directory (including licensed tests), optional CI/coverage wrappers and other nonlibrary release-maintenance files. Original libxcrypt tar/SRPM containers are excluded because they contain the omitted files again. This is not an assertion that the library's overall LGPL terms license the separately identified unknown-grant tests.

The keyutils profile retains everything used by its shared-library link rule: keyutils.c/keyutils.h -> keyutils.os plus version.lds, Makefile, upstream keyutils.spec and pkgconfig input. It omits the unrelated command-line utilities, tests, configuration and manual-page tree. Original project license texts are preserved. The original distro specification is retained separately for provenance, without asserting that this subset is a runnable whole-utility RPM source package.

Only three delivered build-control files change: keyutils Makefile, libxcrypt Makefile.am and configure.ac. Each carries a dated source-packaging modification notice. The exact original copies and reproducible unified diff are in packaging/original-build-controls and packaging/library-only-source-packaging.patch. The keyutils controls retain original library/static/shared/version/header/pkgconfig build/install rules, removing unrelated tools/tests/RPM/Git rules. Libxcrypt controls retain all library/module/generator/header/version/install/man/pkgconfig rules, including the conditional lib/crypt-des-obsolete.c inclusion, while removing test targets and test-only Valgrind/Python configuration. The build recipe therefore does not pass the removed --disable-valgrind test option. The exact downstream RPM specifications and original LTO patch remain unchanged in packaging.

SOURCE-PACKAGING-SCOPE.json lists every preserved library input, every excluded original member/hash and all original/modified build-control hashes. Library-only packaging changes are already applied to sources/. DO NOT apply library-only-source-packaging.patch again there. To reconstruct those control changes independently:
  cp -a packaging/original-build-controls /absolute/new-controls-copy
  patch -p1 -d /absolute/new-controls-copy < packaging/library-only-source-packaging.patch
The downstream LTO patch is supplied separately, unapplied in delivered lib/ source; build-shared.sh applies it exactly once before bootstrapping. Optional qualification-marker patches are not part of any shipped binary.

2. LICENSE SELECTION AND RECIPIENT RIGHTS

keyutils.c/.h grant LGPL version2 or any later version. This distribution selects LGPL2.1 under that later-version option; upstream LICENCE.LGPL itself is2.1. Original notices/grants remain unchanged and recipients retain their original options. Libxcrypt LICENSING explicitly grants overall LGPL2.1-or-later; actual library headers confirm this, with retained BSD0/2/3/public-domain or fallback terms in their file scopes. Original LICENSING/AUTHORS/COPYING.LIB and per-library-file notices are retained verbatim; their references to omitted tests describe the original project, not included files. The matching historical GOST original-project BSD2 license is included with immutable source URL/hash and derivation evidence. GPL3/Autoconf-exception build-macro texts are retained; the exception is a complete standardized SPDX copy because the GNU primary page was unreachable. Do not infer GPL-only wheel code from source-only build macros or broad RPM labels.

You may modify this work for your own use and reverse engineer it for debugging modifications to these libraries, as LGPL2.1 section6 requires; these instructions add no contrary restriction. Preserve notices/disclaimers and mark modified files with changes/dates on redistribution. Full original license terms govern, not this summary. The intended combined-work mechanism is LGPL2.1 section6(b), contingent on actual interface-compatible replacement qualification. If that mechanism cannot be established, this asset alone does not supply any application-source/object/relink fallback required under another route; do not claim that the NeoGraph sdist alone supplies one.

3. REBUILD ON THE MATCHING NATIVE ARCHITECTURE

Use native x86_64 or aarch64 Linux with glibc2.34, e.g. the corresponding prepared AlmaLinux9/manylinux_2_34 environment. Required normal tools/headers: C compiler, GNU binutils, glibc/kernel headers, shell, GNU make, patch; libxcrypt additionally Autoconf>=2.69, Automake>=1.14, libtool>=2.4.6, pkg-config>=0.29, and a COMPLETE Perl>=5.14 installation with its standard core modules. On compatible EL9/AlmaLinux9, the matching source specification explicitly requires the package perl-core (packaging/libxcrypt-4.4.18-3.el9.spec line179), not merely a minimal interpreter. Python3/patchelf/readelf support replacement qualification. Use an already-prepared disposable environment; no host installation or privilege change is part of the recipe. Exact historical compiler/container/RPM-macro timestamps were not recovered.

The library generators directly require the core open pragma (open.pm), warnings, utf8, if/re, FindBin, Cwd, File::Spec::Functions, POSIX, Exporter and Class::Struct, together with their normal Perl core dependencies. No third-party CPAN module is requested. A minimal manylinux Perl can pass the interpreter/version probe but fail configure when expand-selected-hashes imports open.pm; the later "bad value all" message is then a downstream failure, not evidence that --enable-hashes=all is unsupported. Supply the complete EL9 perl-core dependency set in the isolated build environment, retain --enable-hashes=all and the unchanged source/build controls, and retry the failed configure/build step. An optional prerequisite check for the parent/recipient, not run by the preparer, is:
  perl -e 'use v5.14; use warnings; use utf8; use open qw(:std :utf8); use if 0, "warnings"; use re; use FindBin (); use Cwd (); use File::Spec::Functions (); use POSIX (); use Exporter (); use Class::Struct (); print "Perl core prerequisites present\n";'

  sha256sum -c SHA256SUMS
  sh build-shared.sh /absolute/new-native-work

The script copies the delivered preferred source into the new work directory, applies the original libxcrypt LTO patch, bootstraps libxcrypt and builds native libkeyutils.so.1.10 and libcrypt.so.2.0.0 into WORK/output. It preserves all hashes and selects the actual libcrypt.so.2 new API (--enable-hashes=all --enable-obsolete-api=no --enable-obsolete-api-enosys=no). The 2026-10-05 recipe revision restores -fstack-protector-strong in both libraries while retaining RELRO/NOW. The actual original ARM DSOs import __stack_chk_guard from the loader; the prior unprotected build omitted that guard and loader dependency. Ordinary native compiler/libc linking must restore the exact ordered dependency naturally; artificial loader linking or a weaker comparison is not permitted. Actual ARM/x64 proof remains required. These compatible-library flags do not assert reproduction of every historical RPM macro. It does not install to /usr. Parent/recipient can modify these preferred source files in a separate source copy before invoking the recipe. No unknown test code needs acquisition to build the library profile. Historical full RPM specifications include whole-project utilities/tests; they are provenance/build-input references, not the executable filtered-profile recipe.

4. ACTUAL WHEEL REPAIR/REPLACEMENT ROUTE

WHEEL-REPLACEMENT-MAP.json contains exact old f237a6b7 cohort facts for CPython3.9–3.13 on both architectures; final rebuilt release artifacts require a fresh version/ABI check. Observed repaired basenames and SONAMEs are identical:
 x86_64: libkeyutils-81e5c457.so.1.10, libcrypt-1e9ce68f.so.2.0.0
 aarch64: libkeyutils-87f4912d.so.1.10, libcrypt-8056e6c7.so.2.0.0
Original SONAMEs were libkeyutils.so.1 and libcrypt.so.2. The name hash-prefix is the original ELF SHA256 first8; original/repaired .text/.rodata/symbol-version/build-ID sections and versioned exports match. Actual consumers use mangled DT_NEEDED and DT_RPATH=$ORIGIN. Auditwheel6.8.2 was observed, but its exact historical invocation/dependency environment was not recovered.

libkrb5 needs keyutils symbols @KEYUTILS_0.3 plus keyctl_set_timeout@KEYUTILS_1.0 and keyctl_get_persistent@KEYUTILS_1.5. Libcrypt preserves exports crypt/crypt_r/crypt_rn/crypt_ra/crypt_gensalt/crypt_gensalt_rn/crypt_gensalt_ra@XCRYPT_2.0, crypt_checksalt@XCRYPT_4.3 and crypt_preferred_method@XCRYPT_4.4. The mapping records original versioned-export projections, consumer requirements, original/repaired SHA256, ELF architecture and system DT_NEEDED; it is not a complete unversioned ABI inventory. Replacement additionally compares every defined public versioned/unversioned/weak/data export name against the actual installed original. Retain real ELF type/binding/visibility/nonmarker data-layout review and consumer proof; public-name equality alone is not full ABI equivalence. Neither LGPL DSO needs another bundled foreign DSO. Do not disable symbol versioning or substitute libcrypt.so.1.

Stop all processes using a writable disposable wheel installation, then:
  SITE=$(python -c 'import sysconfig; print(sysconfig.get_path("platlib"))')
  LIBS="$SITE/neograph_engine.libs"
  python replace-libraries.py "$LIBS" /absolute/new-native-work/output

The utility derives this installation's actual repaired basenames/SONAMEs, checks architecture, exact complete public export names, expected build SONAME, ordered system dependencies and GLIBC<=2.34, stages each rebuilt library, patches the original repaired SONAME and DT_RPATH=$ORIGIN with patchelf, saves .before-replacement backups and replaces the exact file in neograph_engine.libs. Consumer mangled DT_NEEDED remain unchanged. Start a NEW process. Arbitrary LD_LIBRARY_PATH/unmangled system libraries or an already-loaded process are not proof. Modified installed bytes can differ from publisher wheel RECORD digests; retain originals and restore/reinstall afterward instead of altering publisher checksums.

5. PARENT QUALIFICATION — NOT EXECUTED BY SOURCE PREPARER

On both native architectures, for every final installed CPython wheel with its normal dependencies:
  SOURCE_ASSET=/absolute/unpacked/neograph-0.13.0-linux-lgpl-library-only-source
  SITE=$(python -c 'import sysconfig; print(sysconfig.get_path("platlib"))')
  LIBS="$SITE/neograph_engine.libs"
  env -u LD_LIBRARY_PATH -u LD_PRELOAD python "$SOURCE_ASSET/qualification/replacement-smoke.py" "$LIBS" baseline /absolute/baseline.json
  sh "$SOURCE_ASSET/build-shared.sh" /absolute/new-marked-native-work --qualification-markers
  python "$SOURCE_ASSET/replace-libraries.py" "$LIBS" /absolute/new-marked-native-work/output
  env -u LD_LIBRARY_PATH -u LD_PRELOAD python "$SOURCE_ASSET/qualification/replacement-smoke.py" "$LIBS" modified /absolute/modified.json /absolute/baseline.json

Capture stdout AND stderr. Require NEOGRAPH-LGPL-LIBXCRYPT-REPLACEMENT constructor stderr, NEOGRAPH-LGPL-REPLACEMENT in the existing keyutils_version_string symbol, unchanged baseline crypt hash/invalid-key result/errno, successful krb5_init_context/free_context, and exact installed neograph_engine.libs mappings. Engine import occurs first; real library APIs and a real dependent Kerberos API are exercised. Optional diagnostic patches are dated, interface-preserving source modifications for qualification only. Run publisher installed-wheel smoke/features with replacements in place as well. Stop processes and restore backups afterward.

Before publication parent must inspect omitted-member/build boundaries, actually bootstrap/build this filtered profile on both architectures, compare full versioned ABI and glibc floor, and exercise actual modified-library replacement. Recheck exact final artifact source versions/SONAMEs/basenames and all platform-specific source obligations. Prominent binary library notices and actual source-asset attachment/link must accompany distribution. Static source/digest preservation is proven; runtime suitability, complete legal clearance and whole-product safety are NOT asserted. This asset is distinct from the privately withheld original-container candidate and must be uploaded only by explicit final filename/digest, never a broad archive glob.
