release: combine Core 2.0.1 security and lifecycle changes - #115
Conversation
Generated with Amplifier Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
Generated with Amplifier Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
|
Official qualification has been dispatched from the security branch as a
The branch dispatch keeps all release-only paths skipped: no tag was created, no draft release was created or modified, no PyPI publication runs, and no final release publication runs. This is qualification only; the PR remains draft and official matrix evidence is pending. Additional local evidence carried into this candidate:
Source/lineage note: the Actions update represented by PR #113 is superseded by the pinned Actions revisions included in this security branch, but those pins are not merged to |
Generated with Amplifier\n\nCo-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
|
Qualification update for exact head
The DTU receipt checkout |
(cherry picked from commit 3654f7d) Generated with Amplifier Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
(cherry picked from commit 3e9cc37) Generated with Amplifier Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
Generated with Amplifier Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com> (cherry picked from commit 1e3ef7c) Generated with Amplifier Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
Generated with Amplifier\n\nCo-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
Core 2.0.1 combined release candidate
What changed
This is the single integration PR for Core
2.0.1.pyo30.29.2,pyo3-async-runtimes0.29.0, andpyo3-log0.13.4.abi3-py311,multiple-pymethods, andgenerate-import-libcompatibility, and keeps Foundation as the maintained CLI-smoke default while retaining configurable provider and literal-safe arguments.Why
The release ships the patched native dependency graph and the related lifecycle contract work together, so consumers receive one qualified Core version rather than a split release sequence.
Exact source and completed verification
All release evidence below is for the exact combined candidate
0f5181ec774ad04e97035c5ac8e66d0344a5e613.1,164 passed, 1 skippedper interpreter; 14 maintained smoke fixtures; 17 native-qualification helper checks; and 10 repeated cancellation checks.202before client close and exact graph-node validation.The earlier reused host harness had asserted an ordering that the immediate-retry lifecycle contract does not promise: cancellation-handler exit before resource closure. The corrected harness checks the actual contract—one resource close, eventual handler exit, and no terminal replay—while preserving strict normal-shutdown and handoff checks. This was a harness-only correction; no Core source changed because of it.
The official qualification was a manual-dispatch evidence run, so its publish jobs were intentionally skipped. The tag workflow reruns the six-build/18-cell qualification for the tag SHA, creates and attaches the draft release evidence before PyPI publication, and publishes the GitHub release only after PyPI succeeds.
Compatibility and breaking changes
No intended public API or breaking-change release is introduced. The lifecycle contract remains authoritative:
session:endis attempted at most once per initialized lifetime; cancellation may interrupt delivery, and the host owns cleanup completion. Free-threaded CPython remains outside the qualified matrix.Attribution and review history
PRs #113 and #114 remain open and unchanged for their own attribution and review records. CI #127 and production runtime changes are out of scope.
Release disposition
The combined release is complete and published from the exact merged source:
6ed28858ebb4ce3ca3939f9be96dc091f25822cbv2.0.1amplifier-core==2.0.1The pre-merge qualification labels and run links above remain historical evidence for the candidate. Release provenance is the tag workflow and its receipts, all tied to the merged SHA above. PR #114 is now closed as incorporated here, not separately merged; PR #113 was already closed by Dependabot after main contained the pinned Action versions. No branch was deleted. CI #127 and production runtime changes remain out of scope.
The broader eager coroutine wrapper gap remains an unstarted follow-up documented in the historical PR #114 record; it is not claimed resolved by this release.