Prepare v0.28.2: Python receiver fix and historical acceptance #266

Merged
buildagent merged 7 commits from fix/246-shadowed-imports into master 2026-09-11 22:03:40 +02:00
Member

The two Django user.email references reported in #246 stop binding to an unrelated test app's User.email. A local value rebinding previously discarded the imported type's origin. The resolver now retains that origin as a rejection filter after member uniqueness has been decided, preserving ambiguity instead of manufacturing a new target. Schema 68 re-decides existing Python bindings and advances their committed content identity.

This EBF also completes #263's separate historical acceptance work: the four-crate membership fixture detects the actual M5 mutation, and the occurrence-level source audit reconstructs all 379 historical losses as 301 false bindings removed and 78 correct coverage losses. All nine apps.ready sites are adjudicated. The four locally derived false bindings still present are explicitly recorded; this change does not claim to repair them. The 47 Flask url_for module targets and Ruby/PHP controls are preserved.

The workspace version and pinned installation examples advance to v0.28.2. Independent plugin package versions are unchanged. This addresses #246 and #263; issue closure follows published-artifact verification. #250's untyped storage.request.COOKIES chain remains separate.

Validation:

  • Full nine-repository comparison: identical reference populations; exactly two Django rule-60 false bindings removed; every other target and rule unchanged. All 17 required #199 controls and two additional ContentType controls retain their exact targets. Occurrence-level records and source hashes are in _prdoc/records/issue-246-adjudication.{json,md}.
  • Actual Flask/Django schema-67 upgrades equal fresh schema-68 reference projections without reparsing or replacing symbol/contribution rows.
  • Python import tests 11/11, package-identity tests 8/8. Actual intended-test mutations cover decision filtering, positive preservation, ambiguity, migration and membership isolation; bytes were restored and revalidated.
  • Daemon precision 7/7 across 30 declared decoy sites in 88 files, with populations printed and zero corpus repositories. Removing the decision filter produces one declared Python phantom and fails its intended gate; restoration passes.
  • Tier-1 cost and resolver-stage gates pass unchanged. The separate tier-3 record updates exactly four counters by -2, explained by the two adjudicated false bindings; normal verification then passes 5/5. The protected tier-1 structural baseline and tolerance limits do not change.
  • Local required checks completed: fmt, workspace/all-target Clippy, workspace tests with both initially failing targets re-run successfully, daemon transport suite, tier-1 structural corpus 6/6, and private-item rustdoc with warnings denied. Doctor correctly rejected a nearly full disk; reclaiming completed compiler caches restored the crash matrix (6/6). The package-lifecycle record was separately re-measured: all ten states and seven controls reproduce, with only schema 67 -> 68 recorded as conditions_only; normal full target verification passes 7/7.
  • All nine per-statement cost attribution runs pass. The new filter accounts for 0.052% of measured Django SQLite opcodes. Remote CI is required before merge.

The #263 historical comparison uses the actual 05a3816 and cbbdc04 binaries at pinned heads and is not inferred from this EBF's Python comparison. Its full independent evidence is in _prdoc/records/issue-263-historical-adjudication.{json,md}.

The first corpus CI run caught a remaining schema-67 condition in the separate Ruby package cost record. Three isolated schema-68 surveys and package statement attribution passed within the old bands. The existing writer recorded a fresh run (26,431,549 VM steps; wall ratio 132%), and normal full-target verification passed 4/4. Only that measurement record and its evidence changed; no runtime code, tolerances or protected corpus baseline changed.

The two Django `user.email` references reported in #246 stop binding to an unrelated test app's `User.email`. A local value rebinding previously discarded the imported type's origin. The resolver now retains that origin as a rejection filter after member uniqueness has been decided, preserving ambiguity instead of manufacturing a new target. Schema 68 re-decides existing Python bindings and advances their committed content identity. This EBF also completes #263's separate historical acceptance work: the four-crate membership fixture detects the actual M5 mutation, and the occurrence-level source audit reconstructs all 379 historical losses as 301 false bindings removed and 78 correct coverage losses. All nine `apps.ready` sites are adjudicated. The four locally derived false bindings still present are explicitly recorded; this change does not claim to repair them. The 47 Flask `url_for` module targets and Ruby/PHP controls are preserved. The workspace version and pinned installation examples advance to v0.28.2. Independent plugin package versions are unchanged. This addresses #246 and #263; issue closure follows published-artifact verification. #250's untyped `storage.request.COOKIES` chain remains separate. Validation: - Full nine-repository comparison: identical reference populations; exactly two Django rule-60 false bindings removed; every other target and rule unchanged. All 17 required #199 controls and two additional ContentType controls retain their exact targets. Occurrence-level records and source hashes are in `_prdoc/records/issue-246-adjudication.{json,md}`. - Actual Flask/Django schema-67 upgrades equal fresh schema-68 reference projections without reparsing or replacing symbol/contribution rows. - Python import tests 11/11, package-identity tests 8/8. Actual intended-test mutations cover decision filtering, positive preservation, ambiguity, migration and membership isolation; bytes were restored and revalidated. - Daemon precision 7/7 across 30 declared decoy sites in 88 files, with populations printed and zero corpus repositories. Removing the decision filter produces one declared Python phantom and fails its intended gate; restoration passes. - Tier-1 cost and resolver-stage gates pass unchanged. The separate tier-3 record updates exactly four counters by -2, explained by the two adjudicated false bindings; normal verification then passes 5/5. The protected tier-1 structural baseline and tolerance limits do not change. - Local required checks completed: fmt, workspace/all-target Clippy, workspace tests with both initially failing targets re-run successfully, daemon transport suite, tier-1 structural corpus 6/6, and private-item rustdoc with warnings denied. Doctor correctly rejected a nearly full disk; reclaiming completed compiler caches restored the crash matrix (6/6). The package-lifecycle record was separately re-measured: all ten states and seven controls reproduce, with only schema 67 -> 68 recorded as conditions_only; normal full target verification passes 7/7. - All nine per-statement cost attribution runs pass. The new filter accounts for 0.052% of measured Django SQLite opcodes. Remote CI is required before merge. The #263 historical comparison uses the actual `05a3816` and `cbbdc04` binaries at pinned heads and is not inferred from this EBF's Python comparison. Its full independent evidence is in `_prdoc/records/issue-263-historical-adjudication.{json,md}`. The first corpus CI run caught a remaining schema-67 condition in the separate Ruby package cost record. Three isolated schema-68 surveys and package statement attribution passed within the old bands. The existing writer recorded a fresh run (26,431,549 VM steps; wall ratio 132%), and normal full-target verification passed 4/4. Only that measurement record and its evidence changed; no runtime code, tolerances or protected corpus baseline changed.
test: record released-binary census and schema 68 measurements
Some checks failed
CI / cargo fmt (pull_request) Successful in 50s
CI / OSS corpus tier-3 scale (nightly) (pull_request) Has been skipped
CI / Grammar rebuild from source (nightly) (pull_request) Has been skipped
CI / cargo doc (intra-doc links) (pull_request) Successful in 6m13s
CI / cargo test (abi, 32-bit + wasm32) (pull_request) Successful in 6m52s
CI / cargo check (MSRV 1.98) (pull_request) Successful in 7m31s
CI / cargo deny (pull_request) Successful in 8m5s
CI / cargo clippy (pull_request) Successful in 8m15s
CI / cargo check (windows-gnu) (pull_request) Successful in 8m33s
CI / OSS corpus (tier 1) (pull_request) Failing after 34m40s
CI / cargo test (pull_request) Successful in 32m5s
CI / Plugin path cost + pool throughput (nightly) (pull_request) Has been cancelled
CI / cargo test (daemon transport) (pull_request) Has been cancelled
CI (Windows) / fmt + clippy + build + test (windows) (pull_request) Has been cancelled
9de09db9ab
buildagent changed title from Prepare v0.28.2: fix #246 and complete #263 acceptance to Prepare v0.28.2: Python receiver fix and historical acceptance 2026-09-11 20:56:21 +02:00
test: remeasure Ruby package cost under schema 68
All checks were successful
CI / cargo doc (intra-doc links) (pull_request) Successful in 6m22s
CI / cargo test (abi, 32-bit + wasm32) (pull_request) Successful in 6m25s
CI / cargo check (MSRV 1.98) (pull_request) Successful in 7m6s
CI / cargo deny (pull_request) Successful in 7m14s
CI / cargo clippy (pull_request) Successful in 7m31s
CI / cargo check (windows-gnu) (pull_request) Successful in 7m40s
CI / OSS corpus (tier 1) (pull_request) Successful in 33m9s
CI / cargo test (pull_request) Successful in 31m39s
CI / cargo test (daemon transport) (pull_request) Successful in 8m6s
CI / Plugin path cost + pool throughput (nightly) (pull_request) Has been skipped
CI (Windows) / fmt + clippy + build + test (windows) (pull_request) Successful in 52m44s
Release Build / Generate Version (push) Successful in 30s
Release Build / Required CI green (push) Successful in 1m5s
Release Build / Build linux-aarch64 (push) Successful in 14m20s
Release Build / Build linux-x86_64 (push) Successful in 17m33s
Release Build / Build linux-x86_64-musl (push) Successful in 17m46s
Release Build / Pack the Ruby language package (push) Successful in 59s
Release Build / Pack the XAML reference package (push) Successful in 52s
Release Build / Pack the TimeLine package (push) Successful in 1m11s
Release Build / Build windows-x86_64 (push) Successful in 21m9s
Release Build / Windows archive smoke (msvc) (push) Successful in 8s
Release Build / Create Forgejo Release (push) Successful in 4m24s
CI / OSS corpus tier-3 scale (nightly) (pull_request) Has been skipped
CI / Grammar rebuild from source (nightly) (pull_request) Has been skipped
CI / cargo fmt (pull_request) Successful in 49s
76e8967c12
Author
Member

Released and independently verified as v0.28.2. Release run 760 passed all 11 jobs; PR and merged-master Linux/Windows CI also passed every required job.

Public downloads passed checksum, pinned installer, installed-byte, four-executable build identity, worker smoke and both MCP transport checks. The public CLI reproduces all nine final corpus projections. Upgrading published-v0.28.1 Flask/Django databases matches fresh v0.28.2 projections. The #246 MCP regression yields wrong-target count 0 and positive-control count 1 in both transports. Registry checksum pairs also pass, and its four Linux executable hashes match the public release byte for byte.

The first publication attempt was correctly stopped because my initial git tag -F command stripped Markdown headings. I corrected only the unpublished tag annotation with --cleanup=verbatim and a lease-protected push, retaining the exact tested commit 76e8967c128327b7d32a2d12c9a609ae293d01a5. The full release retry passed; no source or baseline changes were needed. The corrected annotation matches the reviewed notes byte for byte.

#246 and #263 are now closed with release evidence. #250 remains open for its untyped receiver chain. Local master is updated to merge ce2b0401a24014721080efc7440e6051f8d31d2f and clean.

Released and independently verified as [v0.28.2](https://git.h-dv.de/h-dv/code-index/releases/tag/v0.28.2). [Release run 760](https://git.h-dv.de/h-dv/code-index/actions/runs/760) passed all 11 jobs; PR and merged-master Linux/Windows CI also passed every required job. Public downloads passed checksum, pinned installer, installed-byte, four-executable build identity, worker smoke and both MCP transport checks. The public CLI reproduces all nine final corpus projections. Upgrading published-v0.28.1 Flask/Django databases matches fresh v0.28.2 projections. The #246 MCP regression yields wrong-target count 0 and positive-control count 1 in both transports. Registry checksum pairs also pass, and its four Linux executable hashes match the public release byte for byte. The first publication attempt was correctly stopped because my initial `git tag -F` command stripped Markdown headings. I corrected only the unpublished tag annotation with `--cleanup=verbatim` and a lease-protected push, retaining the exact tested commit `76e8967c128327b7d32a2d12c9a609ae293d01a5`. The full release retry passed; no source or baseline changes were needed. The corrected annotation matches the reviewed notes byte for byte. #246 and #263 are now closed with release evidence. #250 remains open for its untyped receiver chain. Local master is updated to merge `ce2b0401a24014721080efc7440e6051f8d31d2f` and clean.
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
h-dv/code-index!266
No description provided.