Repository navigation
Verify every TUI PyPI wheel after upload - #10268
lawrencecchen wants to merge 4 commits into
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Closing as superseded by merged PR #11740 (author Lawrence Chen). Current main uses the shared PyPI upload verification helper and exact digest matching for all six wheels. This head is stale and conflicts; its old checks are not current-head evidence. |
Summary
The stable TUI PyPI publisher preflights each of the six immutable wheels, but after
gh-action-pypi-publishit did not verify that every wheel was visible with the exact build bytes. A successful upload could therefore leave a partial or mismatched registry state unreported.The publisher now performs a bounded post-upload reconciliation for all six local wheels. It uses PyPI JSON
digests.sha256through the existing registry reconciler, passes the complete six-wheel allowed set, waits up to 120 seconds for propagation, and requiresMATCH. Any missing, unexpected, yanked, or mismatched file fails the job. The step never republishes.The npm path is unchanged. It already uses exact post-write reconciliation for all five packages.
This PR is dependent on the cumulative P2/docs head in #10266. Source patch IDs are
b193150277and7c8e413073; cherry-picked heads here are748ba71b24and8caef33f84.Regression sequence
748ba71b24adds the failing workflow contract.8caef33f84adds the post-upload six-wheel check.Verification
actionlint .github/workflows/tui-publish-pypi.yml .github/workflows/tui-publish-npm.ymlpython3 -m pytest -q tests/test_tui_publish_workflow_security.py(69 passed)python3 -m unittest cmux-tui/bindings/tests/test_reconcile_registry_artifact.py -q(58 passed)python3 -m pytest -q tests/test_tui_package_contract.py tests/test_tui_npm_package_artifact.py(9 passed)git diff --checkNeed help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Verifies every TUI PyPI wheel after upload across release and nightly publishers so the registry exactly matches the built artifacts. Previously the jobs published without post-upload reconciliation; now each checks all six wheels and fails on any mismatch.
tui-publish-pypi.ymlandcmux-tui-nightly.yml, validating all sixcmuxwheels via PyPI JSONdigests.sha256, passing the full allowed set, waiting up to 120 seconds, and requiring a match.Written for commit 31896f1. Summary will update on new commits.