From 76e26e6dc50005b252143496c244e792b1db3042 Mon Sep 17 00:00:00 2001 From: Jer Miller Date: Mon, 27 Jul 2026 00:47:11 -0600 Subject: [PATCH] refactor(packaging): derive helper wheel tags instead of restating them Audit found the helper's platform tags hardcoded in four release paths rather than imported from solstone/think/probe.py, where criterion 5 requires them to be declared exactly once. The drift this prevents is concrete: if the measured floor moves and probe.py is updated, a literal selector keeps matching the OLD filename. The release path then silently selects nothing, or the wrong artifact, and proves nothing while reporting success -- the same silent-wrong-answer shape the wheel's own tag discipline exists to prevent. Product selectors now derive from SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS: release_install_smoke.py, release_build_host.py, release_candidate_driver.py, and the Makefile's macOS helper lane. The Makefile derives via a $(shell) import, which works precisely because probe.py is stdlib-only and needs no venv. Pre-existing root/core literals are left alone; they predate this lode. Left as literals deliberately, because they are not tag declarations: maturin `--compatibility manylinux_2_27` build arguments and the lane validator's expected token tuples, which are build inputs rather than selectors; and the upstream `onnxruntime-1.25.0-...whl` filenames in the staging script's digest-pinned provenance table, which identify exact third-party bytes. The constants test no longer pins tag literals. Comparing a tag against the string the code just produced passes whether or not the tag is honest. It now asserts the properties that can actually fail: that the dict cannot drift from its derivation function, that the Linux helper tags are NOT equal to the core's (copying them is the specific defect this coverage set exists to prevent, since the core is static musl with no glibc floor), and that the parsed floor is at least the measured 2.27. Both mutations were verified to fail the test before landing. Fixture writers and their selectors derive together, so neither can drift from the other. make ci: 15539 passed, 17 skipped. Co-Authored-By: Claude Opus 5 (1M context) --- Makefile | 11 ++++-- scripts/release_build_host.py | 10 ++++- scripts/release_candidate_driver.py | 9 ++++- scripts/release_install_smoke.py | 13 ++++++- tests/helpers/release_candidate_fixtures.py | 19 +++++++--- tests/helpers/release_wheel_fixtures.py | 12 +++++- tests/test_release_install_smoke.py | 2 +- tests/test_solstone_core_platforms.py | 41 ++++++++++++++++++--- 8 files changed, 99 insertions(+), 18 deletions(-) diff --git a/Makefile b/Makefile index 2246d4c6d..5e914cc2a 100644 --- a/Makefile +++ b/Makefile @@ -33,6 +33,11 @@ REQUIRE_RUSTUP := command -v rustup >/dev/null 2>&1 || { echo "rustup is require # are therefore the checked-in developer path for the helper's GLIBC_2.27 floor. SPEAKERS_ANALYZE_LINUX_X86_64_MATURIN_ARGS := --locked --zig --compatibility manylinux_2_27 --auditwheel skip --target x86_64-unknown-linux-gnu SPEAKERS_ANALYZE_LINUX_AARCH64_MATURIN_ARGS := --locked --zig --compatibility manylinux_2_27 --auditwheel skip --target aarch64-unknown-linux-gnu +# Derived, never written out: the helper's declared coverage lives in +# solstone/think/probe.py, which is stdlib-only precisely so it imports here +# without a venv. A literal would keep globbing the old filename if the +# measured macOS minimum ever moves. +SPEAKERS_ANALYZE_MACOS_TAG := $(shell PYTHONPATH=. python3 -c 'from solstone.think.probe import SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS as t; print(t["darwin", "arm64"])') # Pick the GPU (CUDA) journal runtime only on x86_64 NVIDIA hosts. The # CUDA bundle resolves onnxruntime-gpu, which ships NO aarch64 wheel on PyPI, so # an aarch64 NVIDIA host (e.g. DGX Spark / GB10) that auto-selected `cuda` would @@ -396,12 +401,12 @@ wheel-macos: parakeet-helper SOURCE_COMMIT=$$(git rev-parse HEAD); \ CORE_LOCK_SHA256=$$(shasum -a 256 core/Cargo.lock | awk '{print $$1}'); \ python3 -m scripts.record_macos_native_wheel --role core --wheel "$$CORE_MAC_WHEEL" --signing-facts "$$CORE_FACTS" --source-commit "$$SOURCE_COMMIT" --core-lock-sha256 "$$CORE_LOCK_SHA256" --out dist/macos-native-core.json - @echo "==> staging macosx_14_0_arm64 solstone-core-speakers-analyze runtime" + @echo "==> staging $(SPEAKERS_ANALYZE_MACOS_TAG) solstone-core-speakers-analyze runtime" python3 scripts/stage_speakers_analyze_runtime.py --target macos-arm64 - @echo "==> building macosx_14_0_arm64 solstone-core-speakers-analyze wheel" + @echo "==> building $(SPEAKERS_ANALYZE_MACOS_TAG) solstone-core-speakers-analyze wheel" MACOSX_DEPLOYMENT_TARGET=14.0 MATURIN_PEP517_ARGS="--locked --target aarch64-apple-darwin" $(UV) build --package solstone-core-speakers-analyze --wheel @echo "==> signing and notarizing solstone-core-speakers-analyze and bundled ONNX Runtime dylib" - @SPEAKERS_MAC_WHEEL=$$(ls dist/solstone_core_speakers_analyze-*-macosx_14_0_arm64.whl); \ + @SPEAKERS_MAC_WHEEL=$$(ls dist/solstone_core_speakers_analyze-*-$(SPEAKERS_ANALYZE_MACOS_TAG).whl); \ SPEAKERS_FACTS=$$(mktemp); \ SPEAKERS_TMP=$$(mktemp -d); \ trap 'rm -rf "$$SPEAKERS_TMP" "$$SPEAKERS_FACTS"' EXIT; \ diff --git a/scripts/release_build_host.py b/scripts/release_build_host.py index d34d2c30d..62635a2b3 100644 --- a/scripts/release_build_host.py +++ b/scripts/release_build_host.py @@ -26,6 +26,14 @@ from scripts.check_rust_release_manifest import ( ) from scripts.release_digest import file_sha256_size from scripts.release_public_evidence import validate_public_evidence_tree +from solstone.think.probe import SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS + +# Derived, never restated: the helper's declared coverage lives in +# solstone/think/probe.py. A literal here would keep selecting the old +# filename if the measured floor ever moves. +SPEAKERS_ANALYZE_MACOS_TAG = SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS[ + ("darwin", "arm64") +] Runner = Callable[..., subprocess.CompletedProcess[str]] IdFactory = Callable[[], str] @@ -531,7 +539,7 @@ def _expected_macos_wheel_names() -> tuple[str, str, str]: item for item in expected_wheels if item.startswith("solstone_core_speakers_analyze-") - and "macosx_14_0_arm64" in item + and SPEAKERS_ANALYZE_MACOS_TAG in item ) return expected_root, expected_core, expected_speakers_analyze diff --git a/scripts/release_candidate_driver.py b/scripts/release_candidate_driver.py index 7c752b4d9..a4f2d4885 100644 --- a/scripts/release_candidate_driver.py +++ b/scripts/release_candidate_driver.py @@ -96,6 +96,7 @@ from scripts.release_tool_pins import ( RUSTC_RELEASE_PIN, fixture_lane_tool_evidence, ) +from solstone.think.probe import SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS Runner = Callable[..., subprocess.CompletedProcess[str]] @@ -118,6 +119,12 @@ SPEAKERS_ANALYZE_AARCH64_MATURIN_ARGS = ( "--locked --zig --compatibility manylinux_2_27 --auditwheel skip " "--target aarch64-unknown-linux-gnu" ) +# Derived, never restated: the helper's declared coverage lives in +# solstone/think/probe.py. A literal here would keep selecting the old +# filename if the measured floor ever moves. +SPEAKERS_ANALYZE_MACOS_TAG = SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS[ + ("darwin", "arm64") +] ROOT_WORKSPACE_PACKAGE = "solstone" MODELS_WORKSPACE_PACKAGE = "solstone-journal-models" CORE_WORKSPACE_PACKAGE = "solstone-core" @@ -1163,7 +1170,7 @@ def _macos_wheel_role(path: Path) -> str | None: item for item in expected_wheels if item.startswith("solstone_core_speakers_analyze-") - and "macosx_14_0_arm64" in item + and SPEAKERS_ANALYZE_MACOS_TAG in item ) if name == expected_core: return "core" diff --git a/scripts/release_install_smoke.py b/scripts/release_install_smoke.py index 3b8e60989..c461d2648 100644 --- a/scripts/release_install_smoke.py +++ b/scripts/release_install_smoke.py @@ -36,6 +36,14 @@ from scripts.check_wheel_contents import ( ) from scripts.release_digest import file_sha256_size from scripts.release_public_evidence import validate_public_evidence_tree +from solstone.think.probe import SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS + +# Derived, never restated: the helper's declared coverage lives in +# solstone/think/probe.py. A literal here would keep selecting the old +# filename if the measured floor ever moves, silently proving nothing. +SPEAKERS_ANALYZE_LINUX_X86_64_TAG = SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS[ + ("linux", "x86_64") +] PROOF_TARGETS: tuple[str, ...] = ( "linux-x86_64-musl", @@ -253,7 +261,10 @@ def _select_names_for_target(target: str, names: Sequence[str]) -> tuple[str, .. if not name.endswith(".whl"): continue if name.startswith("solstone_core_speakers_analyze-"): - if target == "linux-x86_64-musl" and "manylinux_2_27_x86_64" in name: + if ( + target == "linux-x86_64-musl" + and SPEAKERS_ANALYZE_LINUX_X86_64_TAG in name + ): selected.append(name) continue if name.startswith("solstone_core-"): diff --git a/tests/helpers/release_candidate_fixtures.py b/tests/helpers/release_candidate_fixtures.py index f2b1ca0c7..434d83452 100644 --- a/tests/helpers/release_candidate_fixtures.py +++ b/tests/helpers/release_candidate_fixtures.py @@ -43,6 +43,13 @@ from scripts.release_install_smoke import ( target_install_paths_from_ledger, write_install_proof, ) +from solstone.think.probe import ( + SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS, +) + +SPEAKERS_ANALYZE_LINUX_X86_64_TAG = SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS[ + ("linux", "x86_64") +] from tests.helpers.release_wheel_fixtures import ( ROOT_LAUNCHER_BYTES, minimal_elf, @@ -187,10 +194,12 @@ def _write_linux_core_wheels(dist_dir: Path) -> None: def _write_linux_speakers_analyze_wheels(dist_dir: Path) -> None: - for tag, machine in ( - ("manylinux_2_27_x86_64", "x86_64"), - ("manylinux_2_27_aarch64", "aarch64"), - ): + # Derived from probe so these fixtures keep matching what the release code + # selects; a literal here would drift silently if the measured floor moved. + for platform_tuple, tag in SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS.items(): + system, machine = platform_tuple + if system != "linux": + continue write_speakers_analyze_wheel( dist_dir, tag=tag, @@ -435,7 +444,7 @@ def _proof_observation( path for path in install_paths if path.name.startswith("solstone_core_speakers_analyze-") - and "manylinux_2_27_x86_64" in path.name + and SPEAKERS_ANALYZE_LINUX_X86_64_TAG in path.name ] if helper_wheels: with zipfile.ZipFile(helper_wheels[0]) as wheel: diff --git a/tests/helpers/release_wheel_fixtures.py b/tests/helpers/release_wheel_fixtures.py index b897c372d..8b033588a 100644 --- a/tests/helpers/release_wheel_fixtures.py +++ b/tests/helpers/release_wheel_fixtures.py @@ -13,6 +13,16 @@ from collections.abc import Mapping, Sequence from pathlib import Path import scripts.check_wheel_contents as checker +from solstone.think.probe import ( + SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS, +) + +# Derived rather than written out: the fixture's default tag should track +# the helper's declared coverage. Callers still pass deliberately wrong +# tags for negative tests. +SPEAKERS_ANALYZE_DEFAULT_TAG = SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS[ + ("linux", "x86_64") +] ELF_HEADER_SIZE = 64 ELF_PROGRAM_HEADER_SIZE = 56 @@ -221,7 +231,7 @@ def write_core_wheel( def write_speakers_analyze_wheel( path: Path, *, - tag: str = "manylinux_2_27_x86_64", + tag: str = SPEAKERS_ANALYZE_DEFAULT_TAG, version: str = "1.2.3", binary: bytes | None = None, library: bytes = b"fixture libonnxruntime.so.1 GLIBC_2.27\n", diff --git a/tests/test_release_install_smoke.py b/tests/test_release_install_smoke.py index f21ee203c..9f1f08382 100644 --- a/tests/test_release_install_smoke.py +++ b/tests/test_release_install_smoke.py @@ -181,7 +181,7 @@ def _observation( path for path in install_paths if path.name.startswith("solstone_core_speakers_analyze-") - and "manylinux_2_27_x86_64" in path.name + and smoke.SPEAKERS_ANALYZE_LINUX_X86_64_TAG in path.name ] helper_bytes = b"" if helper_wheels: diff --git a/tests/test_solstone_core_platforms.py b/tests/test_solstone_core_platforms.py index 09d5c33d6..d4596147a 100644 --- a/tests/test_solstone_core_platforms.py +++ b/tests/test_solstone_core_platforms.py @@ -13,6 +13,7 @@ import solstone.think.probe as probe from solstone.think.probe import ( SOLSTONE_CORE_COVERED_PLATFORMS, SOLSTONE_CORE_PLATFORM_MARKERS, + SOLSTONE_CORE_PLATFORM_TAGS, SOLSTONE_CORE_SPEAKERS_ANALYZE_COVERED_PLATFORMS, SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS, SOLSTONE_CORE_UNSUPPORTED_PLATFORM_MARKER, @@ -91,16 +92,46 @@ def test_core_pin_markers_match_probe_covered_platforms() -> None: def test_speakers_analyze_platform_tags_are_probe_declared_once() -> None: + # The covered-platform tuples ARE the declaration, so pinning them is the + # point of the test. The tags are not pinned as literals: a test that + # restates the string the code produced would pass whether or not the tag + # is honest. Assert the properties that would actually catch a defect. assert SOLSTONE_CORE_SPEAKERS_ANALYZE_COVERED_PLATFORMS == ( ("linux", "x86_64"), ("linux", "aarch64"), ("darwin", "arm64"), ) - assert SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS == { - ("linux", "x86_64"): "manylinux_2_27_x86_64", - ("linux", "aarch64"): "manylinux_2_27_aarch64", - ("darwin", "arm64"): "macosx_14_0_arm64", - } + + # The dict cannot drift from the derivation function it is built from. + assert set(SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS) == set( + SOLSTONE_CORE_SPEAKERS_ANALYZE_COVERED_PLATFORMS + ) + for platform_tuple, tag in SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS.items(): + assert tag == probe._solstone_core_speakers_analyze_platform_tag(platform_tuple) + + # Copying the core's Linux tag is the specific defect this coverage set + # exists to prevent: the core is static musl with no glibc floor, the + # helper dynamically links a glibc-only ONNX Runtime. + for platform_tuple in SOLSTONE_CORE_SPEAKERS_ANALYZE_COVERED_PLATFORMS: + system, _machine = platform_tuple + if system != "linux": + continue + assert ( + SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS[platform_tuple] + != SOLSTONE_CORE_PLATFORM_TAGS[platform_tuple] + ) + + # The Linux floor must not understate the measured GLIBC_2.27 requirement + # of the bundled ONNX Runtime library. Parsed, not string-compared, so a + # future floor rise stays green while a regression fails. + for platform_tuple, tag in SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_TAGS.items(): + system, machine = platform_tuple + if system != "linux": + continue + match = re.fullmatch(rf"manylinux_(\d+)_(\d+)_{re.escape(machine)}", tag) + assert match is not None, tag + assert (int(match.group(1)), int(match.group(2))) >= (2, 27) + assert not hasattr(probe, "SOLSTONE_CORE_SPEAKERS_ANALYZE_PLATFORM_MARKERS") assert not hasattr( probe, "SOLSTONE_CORE_SPEAKERS_ANALYZE_UNSUPPORTED_PLATFORM_MARKER" -- 2.51.2