Repository navigation
P2p: mapping inputs reach the CLI as temporary files (#6), and release 0.1.1 - #7
Merged
Merged
Conversation
Red at this commit, against 7513583's package code: a served bundle over 2 MiB fails verify, and an input mapping over 2 MiB fails sign, with UsageError (--input - cannot be read: EAGAIN); every mapping input reaches the CLI as --input - on a pipe (#6, npstorey/typedstandards#138). The spawned fixture now records each input file's bytes as the child starts, so the D9 tests read the document the CLI received from its --input file, and the run-time guard checks those files for the seed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012qX8dRbkzJr3B24DbHS3wM Signed-off-by: Nathan Storey <npstorey@users.noreply.github.com>
sign, withdraw, attest and verify wrote a mapping input to the CLI's standard input (--input -). CLI 0.2.0 reads it with readFileSync(0), which fails with EAGAIN once the document is larger than a pipe buffer holds, so verify failed on every large served bundle (the D9 workaround turns a bundle path into a mapping). Each mapping is now written to a temporary file, as view already did, removed when the call returns or raises; the child's standard input is the null device. verify still drops only a bundle's top-level trustRegistry. Fixes #6; the CLI side is npstorey/typedstandards#138. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012qX8dRbkzJr3B24DbHS3wM Signed-off-by: Nathan Storey <npstorey@users.noreply.github.com>
… worktree pushes Three corrections the last orchestrator proposed in its closeout (typedstandards#135, G0 D17 = A): - publishing names scripts/publish.sh and its dry-run, live and read-back modes; - the orchestrator pushes the rollback tags, or hands them to the owner in the merge script; - a branch that adds or changes .gitleaks.toml is pushed from its own worktree, because gitleaks reads that file from the directory it runs in. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012qX8dRbkzJr3B24DbHS3wM Signed-off-by: Nathan Storey <npstorey@users.noreply.github.com>
The version moves to 0.1.1 and the Unreleased entry is dated 2026-10-05, the publish day the owner named (typedstandards#135, G0 D14 = A). uv.lock is unchanged: the package's version is dynamic and its editable entry carries none. The CLI pin stays 0.2.0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012qX8dRbkzJr3B24DbHS3wM Signed-off-by: Nathan Storey <npstorey@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PRODUCE-PY P2p: mapping inputs reach the CLI as temporary files, and release 0.1.1
Part of npstorey/typedstandards#135. G0 record: 5985856524, cards D14 = A and D17 = A. Fixes #6.
Head:
19eb4544de67ad3dda92def86fb153018118bfc4. Base:main7513583.Why
0.1.0's
verifyremoves a served bundle's top-leveltrustRegistry(D9, npstorey/typedstandards#136)and sends the result to the CLI on standard input. CLI 0.2.0 reads
--input -withreadFileSync(0), which fails withEAGAINonce the document is larger than a pipe buffer holds(npstorey/typedstandards#138). So any served bundle above that size failed with
UsageError(exit 2). A bundle that signs a notebook inline is above it. The same applied to any large mapping
given to
sign,withdraworattest.Commits
7c1d8f0src/is identical to7513583b956475runalways gives the childstdin=DEVNULL; README transport sentences;CHANGELOGentrycb7ca9aCLAUDE.md: namesscripts/publish.shand its modes; says who pushes the rollback tags; says a branch that changes.gitleaks.tomlis pushed from its own worktree (D17)19eb454__version__0.1.1,CHANGELOGdated 2026-10-05 (the publish day the owner named);uv.lockunchanged (the version is dynamic)Blast zone:
_commands.py,_cli.py,tests/, the README's transport sentences,CHANGELOG.md,CLAUDE.mdand__version__.uv.lock,.github/,scripts/,package*.json, the vendoredCLI and
tests/fixtures/are untouched.Acceptance: red, then green
Red at
7c1d8f0. Driven by the impl and reproduced by the ORCH in a separate worktree on macOS,Node 24.21.0, Python 3.12. The impl also reproduced it in a Debian bookworm container on Node
24.21.0. Result:
8 failed, 4 passed. Every failure is at the EAGAIN error or at its assertion:Green at
b956475and again at19eb454:UTF-8 file over 2 MiB inline under a fresh seed, runs
view, and inlines atrustRegistryinhost-core's shape.
sign,withdraw,attestandverifygiven mappings,--inputnames a file, the child's stdin isDEVNULL, and the file is gone after the call. Itis also gone when the CLI exits 2, or exits 1 for
verify.trustRegistry, with key order kept andthe caller's mapping unchanged.
test_the_cli_itself_refuses_the_keyis unchanged and passes.hashlib, a seed read andenv=(the impl'smutation run: 5 failed). One check was added: the run-time guard now also fails if the seed
appears in an input file.
243 passed(238 on main plus 5).ruff checkandruff format --checkare clean. The wheel job (clean clone,uv build, wheel ina fresh environment,
smoke_wheel.py) passed.Release dry run
DRY_RUN=1 RELEASE_REF=HEAD scripts/publish.shfrom a clean clone of19eb454. It built andchecked both files, smoke-tested the wheel (
typedstandards 0.1.1,CLI_VERSION 0.2.0, 232vendored files), and ran
uv publish --dry-run. PyPI still answers 404 for 0.1.1.The owner reruns the dry run from a clean checkout of
mainat the merge commit, then publisheson 2026-10-05.
publish.shrefuses the live run on any other local date.gitleaks, sign-off, signatures
Fixtures
None added or changed. The large bundle is built at test time from a fresh random seed. The pinned
first-note.bundle.jsoncheck (cb11d2a2…) is unchanged.Model
The impl ran on Opus 5.5: every turn in its metadata reads
claude-opus-5-5, at its agent file'seffort: high. The ORCH, Opus 5.5 at xhigh, wrotecb7ca9aand19eb454.Flagged, not fixed
tests/guards.pyseed_referencesmisses a name built with+. Only the run-time guard catches it. Out of scope here; for the cold read.pin moves to a CLI that fixes cli: --input - fails with EAGAIN on a large piped input (readFileSync(0)) typedstandards#138.
🤖 Generated with Claude Code
https://claude.ai/code/session_012qX8dRbkzJr3B24DbHS3wM