Skip to content

Verify every TUI PyPI wheel after upload - #10268

Closed
lawrencecchen wants to merge 4 commits into
verify-tui-10214-docs-integrationfrom
audit-tui-postpublish-manifest-p2
Closed

lawrencecchen wants to merge 4 commits into
verify-tui-10214-docs-integrationfrom
audit-tui-postpublish-manifest-p2

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Aug 17, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The stable TUI PyPI publisher preflights each of the six immutable wheels, but after gh-action-pypi-publish it did not verify that every wheel was visible with the exact build bytes. A successful upload could therefore leave a partial or mismatched registry state unreported.

The publisher now performs a bounded post-upload reconciliation for all six local wheels. It uses PyPI JSON digests.sha256 through the existing registry reconciler, passes the complete six-wheel allowed set, waits up to 120 seconds for propagation, and requires MATCH. Any missing, unexpected, yanked, or mismatched file fails the job. The step never republishes.

The npm path is unchanged. It already uses exact post-write reconciliation for all five packages.

This PR is dependent on the cumulative P2/docs head in #10266. Source patch IDs are b193150277 and 7c8e413073; cherry-picked heads here are 748ba71b24 and 8caef33f84.

Regression sequence

  • 748ba71b24 adds the failing workflow contract.
  • 8caef33f84 adds the post-upload six-wheel check.

Verification

  • actionlint .github/workflows/tui-publish-pypi.yml .github/workflows/tui-publish-npm.yml
  • python3 -m pytest -q tests/test_tui_publish_workflow_security.py (69 passed)
  • python3 -m unittest cmux-tui/bindings/tests/test_reconcile_registry_artifact.py -q (58 passed)
  • python3 -m pytest -q tests/test_tui_package_contract.py tests/test_tui_npm_package_artifact.py (9 passed)
  • git diff --check

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Verifies every TUI PyPI wheel after upload across release and nightly publishers so the registry exactly matches the built artifacts. Previously the jobs published without post-upload reconciliation; now each checks all six wheels and fails on any mismatch.

  • Adds post-upload verification in tui-publish-pypi.yml and cmux-tui-nightly.yml, validating all six cmux wheels via PyPI JSON digests.sha256, passing the full allowed set, waiting up to 120 seconds, and requiring a match.
  • Fails the workflow on any missing, unexpected, yanked, or mismatched wheel; never republishes.
  • Keeps the npm publisher unchanged.
  • Extends tests to require step names, order (publish before verify; nightly after policy), version wiring, and verification arguments in both workflows.

Written for commit 31896f1. Summary will update on new commits.

Review in cubic

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Aug 17, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: cc9a9ed7-147f-4579-8ce6-d27721ba7889

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lawrencecchen

Copy link
Copy Markdown
Contributor Author

Closing as superseded by merged PR #11740 (author Lawrence Chen). Current main uses the shared PyPI upload verification helper and exact digest matching for all six wheels. This head is stale and conflicts; its old checks are not current-head evidence.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant