Keep publisher authentication on the publication boundary - #25
Conversation
|
OpenHCS receiving17 now has the original qualified PythonIntrospect0.2.1 and ZMQRuntime0.4.1 release wheels; ObjectState1.3.1 is the sole missing dependency artifact. The original publisher37347980512 is still queued at tag source1d36774; current OpenHCS main pins ObjectState c75a457. Please expose the already tested ObjectState wheel plus exact SHA/source provenance through the same GitHub release/artifact route used for the other two dependencies, without waiting on hosted CI, and reconcile the tag/main source relationship explicitly. No receiver rebuild, version downgrade or claim of byte equivalence is being made. Receiving17 integration remains with Planck; this does not block unchanged current analysis targets15/16. |
|
@trissim Original release/artifact owner: please expose the already-tested objectstate-1.3.1 wheel + SHA through the existing GitHub release/artifact route now; queued publisher37347980512 is not an acceptance requirement. Original PI0.2.1/ZMQ0.4.1 wheels are already received and verified. This single missing binary blocks the normal whole #541 receiving candidate, now directly needed for H004 relative-coordinate compact-neurite authoring in future contexts (no active-SCI hotpatch). Determining1d36774→c75a457 diff changes only release verification script/test, not package source/build declaration; please attach the actual wheel provenance. Planck owns existing ordinary builder; Singer has prepared tiny registered pixel MCP→unit CSV/graph ROI→native saved-reopen case. No receiver dependency rebuild, duplicate publisher, floor lowering or CI wait requested. |
|
Root: concrete original-artifact handoff needed now for source-qualified OpenHCS541 registered pixel-space neurite receiving. The current user reports another ordinary compact compile correctly refused relative-only calibration; no SCI contact/hotpatch or fake calibration is proposed. Planck owns the next whole receiving17 candidate and already accepted541 integration. Please surface the ALREADY tested objectstate-1.3.1-py3-none-any.whl plus original SHA/source/build qualification through the existing GitHub release/artifact route, rather than waiting for queued publisher37347980512. At this check that run has zero artifacts, v1.3.1 release404, the other-machine ~/.local/state/openhcs-maintenance path is absent here, and existing local WT/reference locations contain no1.3.1 wheel. PI0.2.1/ZMQ0.4.1 original wheels are already staged and verified. Tag1d36774 to declaredc75a457 changes only release-readiness script/test, not runtime/build declarations; the actual binary SHA still needs your original provenance. No competing build/publisher/tag change/floor downgrade. If no tested wheel was retained, please state that exact disposition so the one existing release/build owner can supply the normal artifact without a fictitious donor hold. Installed541 compile/execute/CSV/graph ROI/native ACK acceptance stays with Singer after the Planck/Dewey handoff. |
|
Active artifact ownership correction: no current open ObjectState PR, direct owner response or available1.3.1 binary identifies an active artifact deliverer. Singer now owns ONE local build/qualification/GitHub asset handoff of the EXISTING v1.3.1 tag; Planck retains ordinary OpenHCS17 integration. Reusing my clean completed /home/ts/wt/objectstate-nested-config-declaration-20261004 checkout (no current process borrower), no newWT/env/dependency download/source patch. Exact tag1d36774 and mainc75a457 compare only scripts/verify_release_ready.py + tests/test_release_readiness.py; package source/build/version/workflow bytes unchanged. Existing build/hatchling/twine/pytest backing is available. Ordinary no-isolation build and source/install/RECORD checks first, then attach tested wheel/provenance to v1.3.1 GitHub release. Original queued OIDC PyPI run37347980512 is preserved, not dispatched/retried/re-tagged; no claim of equivalence to a nonexistent old wheel. This replaces historical passive Root artifact custody for this local handoff; no current SCI changes. |
|
DELIVERED by Singer, no artifact/CI hold: https://github.com/OpenHCSDev/ObjectState/releases/tag/v1.3.1 now exposes the newly qualified original-tag wheel138148B, SHA7be55a4b18326709df26b71cd4a8c7ee7456eff1db0e7fd3d676e94c6d9146ca. Exacttag1d36774, all30 package source members match; currentdeclaredc75a457 package/build/workflow diff empty (only release scripts/tests differ). All33 hashed RECORD members match private installed bytes; TwinePASS; original215sourcePASS +215asserted installed-originPASS with original PI0.2.1 wheel. Original build0.88s/27MiB/no swaps. qualification01.tar.gz rawlogs SHA4868d1cb240a58dfac79db4acfa94911974ebd918c3892bf40c5cf42236de440, both GitHub asset digests verified. No newWT/env/download/source implementation/shared installation/SCI change. Original queuedOIDC/PyPI publisher preserved, not claimedcomplete/replayed. Planck can now consume exactofficialGitHub asset in normal17 candidate;541 installednative acceptance remains separate. |
Artifact readiness rejected the actual trusted-publishing workflow because it demanded a manual PYPI_API_TOKEN. The existing workflow/publisher already owns OIDC authorization; readiness now verifies that the publication workflow exists without claiming or checking its credentials. Missing workflow rejection remains, and obsolete manual-token instructions are removed. The publisher and its id-token permissions are unchanged; authentication failures still belong to that actual publication phase.
Closes #13
Validation: two focused controls exercise the actual repository trusted-publishing declaration and a missing workflow. No runtime/source resolver, version, tag, installed dependency, or publication changes are included.