Skip to content

release: combine Core 2.0.1 security and lifecycle changes - #115

Merged
Brian Krabach (bkrabach) merged 7 commits into
mainfrom
fix/pyo3-security-20260923
Sep 23, 2026
Merged

Brian Krabach (bkrabach) merged 7 commits into
mainfrom
fix/pyo3-security-20260923

Conversation

@bkrabach

@bkrabach Brian Krabach (bkrabach) commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

Core 2.0.1 combined release candidate

What changed

This is the single integration PR for Core 2.0.1.

  • Remediates the PyO3 dependency family with pyo3 0.29.2, pyo3-async-runtimes 0.29.0, and pyo3-log 0.13.4.
  • Incorporates the lifecycle ownership and cleanup work from #114.
  • Incorporates the reviewed pinned Actions updates from #113.
  • Preserves abi3-py311, multiple-pymethods, and generate-import-lib compatibility, and keeps Foundation as the maintained CLI-smoke default while retaining configurable provider and literal-safe arguments.

Why

The release ships the patched native dependency graph and the related lifecycle contract work together, so consumers receive one qualified Core version rather than a split release sequence.

Exact source and completed verification

All release evidence below is for the exact combined candidate 0f5181ec774ad04e97035c5ac8e66d0344a5e613.

  • Local qualification passed on Python 3.11, 3.12, and 3.13: 1,164 passed, 1 skipped per interpreter; 14 maintained smoke fixtures; 17 native-qualification helper checks; and 10 repeated cancellation checks.
  • Rust qualification passed: 491 unit tests, 13 integration tests, and 19 doc tests, with locked check, clippy, format, and lock validation passing.
  • Official native qualification passed in Build Wheels run 35899811841: six native builds, all 18 normal-GIL CPython 3.11/3.12/3.13 qualification cells, and release-evidence aggregation. The validated archive covered six build receipts, 18 reports, and 31 checksum entries.
  • Exact-head Rust Core CI and Proto Sync Check both passed; CLA policy is green.
  • A real maintained Foundation CLI smoke, an independent Python 3.13 recipe execution, and the paired lifecycle harness passed. The paired harness completed 19/19 assertions, including a real terminal HTTP 202 before client close and exact graph-node validation.
  • The host/Core boundary qualification passed: normal shutdown and cooperative handoff preserve their strict ordering checks, bounded cleanup passed 10/10 attempts, and 35 related app-CLI tests passed.

The earlier reused host harness had asserted an ordering that the immediate-retry lifecycle contract does not promise: cancellation-handler exit before resource closure. The corrected harness checks the actual contract—one resource close, eventual handler exit, and no terminal replay—while preserving strict normal-shutdown and handoff checks. This was a harness-only correction; no Core source changed because of it.

The official qualification was a manual-dispatch evidence run, so its publish jobs were intentionally skipped. The tag workflow reruns the six-build/18-cell qualification for the tag SHA, creates and attaches the draft release evidence before PyPI publication, and publishes the GitHub release only after PyPI succeeds.

Compatibility and breaking changes

No intended public API or breaking-change release is introduced. The lifecycle contract remains authoritative: session:end is attempted at most once per initialized lifetime; cancellation may interrupt delivery, and the host owns cleanup completion. Free-threaded CPython remains outside the qualified matrix.

Attribution and review history

PRs #113 and #114 remain open and unchanged for their own attribution and review records. CI #127 and production runtime changes are out of scope.

Release disposition

The combined release is complete and published from the exact merged source:

The pre-merge qualification labels and run links above remain historical evidence for the candidate. Release provenance is the tag workflow and its receipts, all tied to the merged SHA above. PR #114 is now closed as incorporated here, not separately merged; PR #113 was already closed by Dependabot after main contained the pinned Action versions. No branch was deleted. CI #127 and production runtime changes remain out of scope.

The broader eager coroutine wrapper gap remains an unstarted follow-up documented in the historical PR #114 record; it is not claimed resolved by this release.

Generated with Amplifier

Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
Generated with Amplifier

Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
@bkrabach

Copy link
Copy Markdown
Collaborator Author

Official qualification has been dispatched from the security branch as a workflow_dispatch run:

The branch dispatch keeps all release-only paths skipped: no tag was created, no draft release was created or modified, no PyPI publication runs, and no final release publication runs. This is qualification only; the PR remains draft and official matrix evidence is pending.

Additional local evidence carried into this candidate:

  • The committed build-receipt/installed-wheel verification path passed on native Linux ARM64/Python 3.13 with the exact committed source and wheel hash.
  • Qualification helper: 17 passed.
  • Synthetic release-evidence aggregation: all six build receipts and 18 qualification cells accepted; missing-receipt, wrong-source, and wrong-hash cases fail closed.
  • Prior installed-wheel suites passed on Python 3.11, 3.12, and 3.13: 1135 passed, 1 skipped, 2 deprecation warnings per interpreter; targeted callback/conversion/session-lifecycle/cancellation coverage and the Rust gates also passed.

Source/lineage note: the Actions update represented by PR #113 is superseded by the pinned Actions revisions included in this security branch, but those pins are not merged to main yet. This PR remains distinct from #114 and no alerts, tags, releases, or production state were modified.

Generated with Amplifier\n\nCo-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
@bkrabach

Copy link
Copy Markdown
Collaborator Author

Qualification update for exact head 846ea25490d541661838d8cbb3788d259bfbf1f9:

  • Follow-up commit 846ea25490d541661838d8cbb3788d259bfbf1f9 updates only scripts/e2e-smoke-test.sh to run the smoke session with --bundle foundation, which supplies the required recipes:recipe-author agent. bash -n and git diff --check pass.
  • Historical evidence from 0a4efc081d7ce8e5dbbde7150b9be27ce9c89674 remains historical only: all six builds, all 18 native qualification cells, and the real Python 3.13 LLM smoke passed there. The maintained smoke script's prior failure was the missing explicit bundle/catalog path; no new runtime or library dependency changes were made.
  • Fresh qualification is pending for this new head. Build Wheels dispatch: https://github.com/microsoft/amplifier-core/actions/runs/35892517470 (queued at snapshot time).
  • Initial exact-head CI snapshot also showed Rust Core CI https://github.com/microsoft/amplifier-core/actions/runs/35892475899 and Proto Sync Check https://github.com/microsoft/amplifier-core/actions/runs/35892475939, both in progress. No prior-head evidence is being carried forward as new-head proof.

The DTU receipt checkout core-pyo3-security-20260923 was fetched from GitHub and detached at this exact head; tracked files are clean and only the pre-existing ignored cache/dist paths remain.

(cherry picked from commit 3654f7d)

Generated with Amplifier

Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
(cherry picked from commit 3e9cc37)

Generated with Amplifier

Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
Generated with Amplifier

Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
(cherry picked from commit 1e3ef7c)

Generated with Amplifier

Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
Generated with Amplifier\n\nCo-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
@bkrabach Brian Krabach (bkrabach) changed the title fix: remediate PyO3 security advisories and qualify native artifacts release: combine Core 2.0.1 security and lifecycle changes Sep 23, 2026
@bkrabach
Brian Krabach (bkrabach) merged commit 6ed2885 into main Sep 23, 2026
35 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants