build(sdk): prepare verified runtime artifact pin updates - #223
Merged
abonneth merged 9 commits intoOct 2, 2026
Merged
Conversation
This was referenced Sep 30, 2026
cm2435-hcomp
marked this pull request as ready for review
September 30, 2026 15:23
Author
|
bugbot run |
Author
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit cb86d87. Configure here.
…to charlie/placement-sdk-pins # Conflicts: # src/hai_agents_local/runtime/manifest.py
Collaborator
|
Pushed directly (as agreed):
Tests: 230 passed, 12 skipped. |
…to charlie/placement-sdk-pins
…to charlie/placement-sdk-pins
abonneth
approved these changes
Oct 2, 2026
Collaborator
|
Folded into #222 (fast-forward, same commits) to simplify the stack. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Prepare the SDK-owned runtime artifact pin updater. Validate the manifest and hashes before changing the version; retain the legacy CLI publication target until its migration ships. No candidate hashes become public defaults in this change.
Why
Artifact versions and checksums should have one validated handoff into the SDK; partial updates or premature removal of CLI ownership can break consumers.
How
Validate artifact metadata and hashes before rewriting the runtime manifest; keep the existing CLI release target until its migration ships.
Validation and dependencies
P5c, based on #222. After P5a produces a reviewed immutable release, use this helper to update the actual SDK pin; SDK/CLI publication remains gated on compatible released dependencies.
Validation: both updater regression tests pass (valid updates and rejection without partial writes). No runtime publication is performed.
Stack navigation: P1 contract → P2 runtime; P3 generation + P4 SDK; P5 checks: runtime, generation, SDK pins; P6 CLI. P7 duplicate pin cleanup follows only after P6 ships. HoloWork integration is subsequent work.
Review guide: intent, architecture, service tradeoffs and merge order.
Note
Low Risk
Release-time maintenance tooling and docs only; pinned version and digests in the manifest are unchanged until someone runs the script.
Overview
Adds
scripts/bump_runtime.py, a stdlib-only maintainer tool that rewritesPINNED_RUNTIME_VERSIONand every published platform’s sha256 inmanifest.pyin one atomic edit. It rejects partial bumps (unknown platforms, missing shas, or ambiguous literals) so a version bump cannot leave stale digests on new CDN URLs.Documents the workflow in README (“Runtime release maintenance”): run after a verified release with
--versionand--sha PLATFORM=SHA256for each platform in the manifest; schema generation does not touch the pin; legacy CLI pin PRs stay until SDK/CLI migration ships.manifest.pyonly updates its module docstring to point at the script.tests/test_bump_runtime.pycovers successful full updates and failure with no file write when shas are incomplete.Reviewed by Cursor Bugbot for commit ee14299. Bugbot is set up for automated code reviews on this repo. Configure here.