Skip to content

build(sdk): prepare verified runtime artifact pin updates - #223

Merged
abonneth merged 9 commits into
charlie/placement-python-sdkfrom
charlie/placement-sdk-pins
Oct 2, 2026
Merged

abonneth merged 9 commits into
charlie/placement-python-sdkfrom
charlie/placement-sdk-pins

Conversation

@cm2435-hcomp

@cm2435-hcomp cm2435-hcomp commented Sep 30, 2026 •

Copy link
Copy Markdown

What

Prepare the SDK-owned runtime artifact pin updater. Validate the manifest and hashes before changing the version; retain the legacy CLI publication target until its migration ships. No candidate hashes become public defaults in this change.

Why

Artifact versions and checksums should have one validated handoff into the SDK; partial updates or premature removal of CLI ownership can break consumers.

How

Validate artifact metadata and hashes before rewriting the runtime manifest; keep the existing CLI release target until its migration ships.

Validation and dependencies

P5c, based on #222. After P5a produces a reviewed immutable release, use this helper to update the actual SDK pin; SDK/CLI publication remains gated on compatible released dependencies.

Validation: both updater regression tests pass (valid updates and rejection without partial writes). No runtime publication is performed.

Stack navigation: P1 contract → P2 runtime; P3 generation + P4 SDK; P5 checks: runtime, generation, SDK pins; P6 CLI. P7 duplicate pin cleanup follows only after P6 ships. HoloWork integration is subsequent work.

Review guide: intent, architecture, service tradeoffs and merge order.


Note

Low Risk
Release-time maintenance tooling and docs only; pinned version and digests in the manifest are unchanged until someone runs the script.

Overview
Adds scripts/bump_runtime.py, a stdlib-only maintainer tool that rewrites PINNED_RUNTIME_VERSION and every published platform’s sha256 in manifest.py in one atomic edit. It rejects partial bumps (unknown platforms, missing shas, or ambiguous literals) so a version bump cannot leave stale digests on new CDN URLs.

Documents the workflow in README (“Runtime release maintenance”): run after a verified release with --version and --sha PLATFORM=SHA256 for each platform in the manifest; schema generation does not touch the pin; legacy CLI pin PRs stay until SDK/CLI migration ships.

manifest.py only updates its module docstring to point at the script. tests/test_bump_runtime.py covers successful full updates and failure with no file write when shas are incomplete.

Reviewed by Cursor Bugbot for commit ee14299. Bugbot is set up for automated code reviews on this repo. Configure here.

@cm2435-hcomp

Copy link
Copy Markdown
Author

bugbot run

@cm2435-hcomp

Copy link
Copy Markdown
Author

bugbot run

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit cb86d87. Configure here.

@abonneth

abonneth commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Pushed directly (as agreed):

Tests: 230 passed, 12 skipped.

@abonneth
abonneth merged commit ee14299 into charlie/placement-python-sdk Oct 2, 2026
3 checks passed
@abonneth
abonneth deleted the charlie/placement-sdk-pins branch October 2, 2026 12:33
@abonneth

abonneth commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Folded into #222 (fast-forward, same commits) to simplify the stack.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants