Skip to content

Iteration 41: align parent source pins with base, CTP and Gateway - #13

Draft
cloudQuant wants to merge 11 commits into
devfrom
codex/iteration41-sdk-pin-closure
Draft

cloudQuant wants to merge 11 commits into
devfrom
codex/iteration41-sdk-pin-closure

Conversation

@cloudQuant

@cloudQuant cloudQuant commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Scope

Align the parent bt_api_py pointers with reviewed base 0.15.5, CTP 2.0.3, and Gateway source commits. The Gateway gitlink now points to bf51a9bc from Gateway source PR #1, whose offline PR CI passed. The original dirty parent checkout is excluded.

Bootstrap the parent quality, docs, and compatibility CI jobs from the exact base source gitlink. The helper verifies the parent gitlink, canonical origin, source metadata, local wheel identity and SHA-256, and the installed PEP 610 direct_url hash. Git/build/install subprocesses receive a restricted environment; the Codecov token is scoped to its upload step.

Local verification

  • Independent source-pin QA: 16 targeted tests passed, Ruff/format checks passed, workflow YAML and package TOML parsed, and diff check passed.
  • In a clean Python 3.11 venv, the pinned base source built and installed as a wheel; its receipt matched the installed PEP 610 wheel hash, and pip check passed. Fake CI tokens, private index and PYTHONPATH values did not reach the build/install child processes.
  • Gateway source: 69 offline tests and Ruff passed; its sdist and wheel both include the same MIT LICENSE bytes.
  • Earlier isolated source/payload review covered base and CTP local wheel builds, without importing the CTP native extension or contacting a provider.

Remaining gates

The full-suite core-reference job still requests bt_api_ctp >=2.0.3 from the package index. The checked-out CTP submodule is not automatically installed, and public PyPI currently has 2.0.2. A pinned local CTP wheel/install path or an accepted release is still needed; CI is not expected to be fully green. The CTP source includes a native extension and bundled provider binaries, so source pinning alone does not accept its native artifact.

G4 still needs native binary provenance, a complete installed dependency chain, and real native lifecycle acceptance. Gateway source has no deployed authenticated AccountActor or account-wide writer fence. No managed CTP write route is enabled; no real SimNow login, order, cancel, or 33-case PASS is claimed. This remains a draft PR.

@cloudQuant cloudQuant added the risk:r3 发布/安全/供应链风险 label Sep 28, 2026
@cloudQuant cloudQuant changed the title Iteration 41: align parent SDK pins with reviewed base and CTP Iteration 41: align parent source pins with base, CTP and Gateway Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

risk:r3 发布/安全/供应链风险

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants