Skip to content

Fix v0.11.1 installation and OCR qualification - #216

Merged
xeonvs merged 1 commit into
mainfrom
codex/v0.11.1-install-qualification
Sep 23, 2026
Merged

xeonvs merged 1 commit into
mainfrom
codex/v0.11.1-install-qualification

Conversation

@xeonvs

@xeonvs xeonvs commented Sep 23, 2026

Copy link
Copy Markdown
Owner

Problem and result

The official GitLab example for toolkit 0.11.x installs only a wheel with --no-deps, leaving MCP and other runtime dependencies absent on clean Python. Issue #214 tracks the fix. The recipe now verifies a release runtime-requirements.txt asset against SHA256SUMS, installs its binary dependencies with hashes, then installs the verified toolkit wheel and runs pip check. Build, development, and stable registry checks exercise a real installed MCP gateway/schema exchange; a clean wheel-only negative control fails as expected.

The stable release workflow binds the runtime lock to provenance, checksums, receipt v2, draft recovery, and immutable asset readback while keeping PyPI/TestPyPI limited to wheel and sdist. The OCR qualification workflow installs frozen dependencies before probing, records a closed status even if setup fails, and preserves historical evidence through OCR 1.12.7 while checking the 1.12.8+ F# and exclusion contracts. Scheduled qualification pauses indefinitely from 2026-10-01 UTC; manual dispatch remains available.

The engineering workflow layer adopts 0.9.8 instruction routes, archive state, and optional GPT-6 utility/explorer/reviewer profiles. The repository's public-content and Gitleaks gates remain active.

Validation

  • Focused qualification, receipt, installation-contract, and documentation tests passed; the clean wheel-only negative test failed its functional probe as required.
  • The full local quality run reached the suite with one outdated static workflow-order assertion; that assertion was corrected and its owning module passed. Protected CI is the final complete gate for this head.
  • Instruction contract v3, plan/archive checks, Ruff, git diff --check, staged/tree/history Gitleaks, and commit-signature verification passed.

This PR prepares the feature; stable v0.11.1 publication follows the separate protected release PR and its registry/asset gates.

@xeonvs
xeonvs marked this pull request as ready for review September 23, 2026 07:21
@xeonvs
xeonvs merged commit 0b589f0 into main Sep 23, 2026
13 checks passed
@xeonvs
xeonvs deleted the codex/v0.11.1-install-qualification branch September 23, 2026 07:21
@xeonvs xeonvs mentioned this pull request Sep 23, 2026
xeonvs added a commit that referenced this pull request Sep 23, 2026
## Release preparation

Authorize stable v0.11.1 from the reviewed feature and OCR promotion
merges. This PR advances the stable marker to 0.11.1 and the next
development line to 0.12.0, binds the sorted milestone issues 214, 217,
and 218, renders Towncrier, pins the public example to toolkit 0.11.1
with OCR 1.12.9, and archives the repository-complete plan with external
delivery pending.

The official installation now receives the hash-locked runtime
dependency asset before the verified toolkit wheel; the stable workflow
will publish and verify that asset with its receipt.

Tracked milestone: v0.11.1 (#214, #217, #218). The Release workflow owns
their final closure after immutable receipt readback.

## Validation

- Feature PR #216 and OCR promotion PR #219 passed exact-head CI and
merged; both development TestPyPI workflows completed successfully.
- Hosted OCR qualification run 35831453766 established adjacent
1.12.8–1.12.9 compatibility, with source review for the F# Rules and
selection change.
- Local release/docs tests, full `scripts/quality.sh check`, release
notes rendering, formatter, signed commit, and staged/tree/history
Gitleaks passed.

Stable registries, immutable GitHub Release, receipt readback, and
external reconciliation remain post-merge gates.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant