Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 19 additions & 2 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,14 +8,30 @@ wirelog floor and a validated wirelog ref (see

## [Unreleased]

## [1.1.1] - 2026-09-12

### Added
- Typed rows on `Session`: `insert_typed`, `remove_typed`,
`snapshot_typed`, `step_typed`, and `set_typed_delta_callback`
preserve FLOAT values across the Python/C boundary. `TypedRowError`
and `TypedErrorCode` expose engine validation diagnostics.
These methods require wirelog >= `0.60.0`; on older supported engines
(including `0.52.0`) they raise `WirelogVersionError` while the
existing APIs remain available.

### Changed
- The current development pin for bundled and validated wirelog builds
- The pin for bundled and validated wirelog builds
moves from `v0.60.0` to `v0.62.0` at peeled SHA
`39a57cf3c4cdf02f97df0e951fe8ecea7a831e2c`.
- The minimum compatible runtime wirelog version remains `0.52.0`.
wirelog 0.62.0 adds `wirelog_program_get_plan_error` relative to
0.60.0, and the library SONAME is unchanged, so no PyreWire code
stops supporting `0.52.0`.
- **Arithmetic precedence changes with wirelog `0.61.0` and newer**:
`A + B * C` now means `A + (B * C)`, so `2 + 3 * 4` produces
`14` instead of `22`. The bundled `0.62.0` engine includes this change;
existing programs may produce different results. Add explicit
parentheses to preserve an intended evaluation order.

## [1.0.6] - 2026-09-05

Expand Down Expand Up @@ -322,7 +338,8 @@ runtime wirelog version remaining `0.44.0`.
wirelog#852. They are available in the later [1.0.0] line, whose
validated wirelog ref is v0.50.0. Tracked in wirelog#859.

[Unreleased]: https://github.com/semantic-reasoning/PyreWire/compare/v1.0.6...HEAD
[Unreleased]: https://github.com/semantic-reasoning/PyreWire/compare/v1.1.1...HEAD
[1.1.1]: https://github.com/semantic-reasoning/PyreWire/compare/v1.0.6...v1.1.1
[1.0.6]: https://github.com/semantic-reasoning/PyreWire/compare/v1.0.5...v1.0.6
[1.0.5]: https://github.com/semantic-reasoning/PyreWire/compare/v1.0.4...v1.0.5
[1.0.4]: https://github.com/semantic-reasoning/PyreWire/compare/v1.0.3...v1.0.4
Expand Down
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,10 +20,10 @@ pip install pyrewire

**Requirements:** CPython 3.11, 3.12, 3.13, or 3.14.

See the [support matrix](docs/support.md) for v1.0 wheel targets and
See the [support matrix](docs/support.md) for v1 wheel targets and
source-install requirements, including supported OS/architecture
combinations and `libwirelog` handling. The
[API stability policy](docs/api-stability.md) defines the v1.0 stable
[API stability policy](docs/api-stability.md) defines the v1 stable
public import boundary and deprecation policy.

## Quick Start
Expand Down
1 change: 1 addition & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@

| Version | Supported |
|---------|-----------|
| v1.1.x | ✓ |
| v1.0.x | ✓ |
| < v1.0 | ✗ |

Expand Down
4 changes: 2 additions & 2 deletions docs/api-stability.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# API stability

PyreWire v1.0 treats `pyrewire.__all__` as the stable public import boundary.
PyreWire v1 treats `pyrewire.__all__` as the stable public import boundary.
Names listed there are the supported surface for
`from pyrewire import ...` imports and are covered by the v1 API
compatibility and deprecation policy.
Expand Down Expand Up @@ -118,4 +118,4 @@ and the affected API.
Minor releases may add compatible public API surface, including new APIs,
optional parameters, enum members, and exception subclasses. Code
that handles PyreWire enums or exception hierarchies should therefore
avoid assuming that the v1.0 set is permanently exhaustive.
avoid assuming that the v1 set is permanently exhaustive.
2 changes: 1 addition & 1 deletion docs/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ The wheel bundles `libwirelog`; no system install required.
- [Quickstart](quickstart.md) — a six-line example you can paste.
- [Versioning](versioning.md) — PyreWire and wirelog version
independently.
- [API stability](api-stability.md) — the v1.0 public API boundary and
- [API stability](api-stability.md) — the v1 public API boundary and
deprecation policy.
- [Reference](reference/sessions.md) — auto-generated from the
public-API docstrings.
16 changes: 8 additions & 8 deletions docs/release-candidate-checklist.md
Original file line number Diff line number Diff line change
@@ -1,17 +1,17 @@
# v1.0.0 release candidate checklist
# v1.1.1 release candidate checklist

The v1.0.0 tag must not be cut until every gate below passes on the exact release commit.
The v1.1.1 tag must not be cut until every gate below passes on the exact release commit.
Freeze the release commit first:

```bash
git rev-parse HEAD
```

Record that SHA in the release issue or release PR. The `v1.0.0` tag must point to that exact SHA before any publication step. If any gate fails, do not tag or publish; open or link a GitHub issue, PR, or follow-up task that captures the failure before retrying.
Record that SHA in the release issue or release PR. The `v1.1.1` tag must point to that exact SHA before any publication step. If any gate fails, do not tag or publish; open or link a GitHub issue, PR, or follow-up task that captures the failure before retrying.

| Gate | Owner | Verification | Required evidence | Failure action |
| --- | --- | --- | --- | --- |
| Release commit freeze | Release manager | Command: `git rev-parse HEAD`; manual verification that `v1.0.0` will be created at that SHA. | Recorded release commit SHA and confirmation that the `v1.0.0` tag points to the same SHA. | Link a GitHub issue, PR, or follow-up task and restart the checklist from the corrected commit. |
| Release commit freeze | Release manager | Command: `git rev-parse HEAD`; manual verification that `v1.1.1` will be created at that SHA. | Recorded release commit SHA and confirmation that the `v1.1.1` tag points to the same SHA. | Link a GitHub issue, PR, or follow-up task and restart the checklist from the corrected commit. |
| Formatting | Release manager | Command: `black --check .`; command: `isort --check-only .`. | Passing command logs from the frozen release commit. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Lint and typing | Release manager | Command: `flake8 .`; command: `mypy src/pyrewire`. | Passing command logs from the frozen release commit. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Test suite | Release manager | Command: `pytest -q`. | Passing pytest log from the frozen release commit. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
Expand All @@ -24,12 +24,12 @@ Record that SHA in the release issue or release PR. The `v1.0.0` tag must point
| Dependabot coverage | Release manager | Manual verification of `.github/dependabot.yml`: Dependabot is configured for both `github-actions` and `pip` at `/` on a regular schedule. | Linked review note referencing the merged `.github/dependabot.yml` and both ecosystems. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Release workflow dry run review | Release manager | Manual verification of `.github/workflows/release.yml`: it builds wheels, runs dynamic-link verification, performs clean install tests, verifies release-local wheels and sdist artifacts before publish, uses trusted publishing via OIDC, keeps least-privilege top-level permissions, restricts `id-token: write` to the publish jobs, separates TestPyPI and production PyPI trusted publishing into explicit `testpypi` and `pypi` GitHub environments, and publishes production only after tag-triggered gates pass. Do not actually tag or publish production during RC validation. | Linked review note confirming the tag-triggered `release.yml` gates, least-privilege/OIDC scope, separate publish environments, and no pre-tag production publish occurred. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| TestPyPI dry run evidence | Release manager + Packaging owner | Manual verification: on the frozen RC commit, manually dispatch `.github/workflows/release.yml` with `publish-testpypi: true` and complete a TestPyPI end-to-end dry run before any production tag push. Use install command shape: `python -m pip install --index-url https://test.pypi.org/simple/ --extra-index-url https://pypi.org/simple pyrewire==<candidate-version>`. | Frozen commit SHA, successful `release.yml` workflow run URL, TestPyPI project/version URL, artifact filenames and candidate version, SHA256 hashes, successful TestPyPI upload logs, clean install command logs/results for Linux/macOS/Windows supported Python versions, import smoke output for `pyrewire.__version__` and `pyrewire.wirelog_version()`, confirmation wheel install uses bundled `libwirelog` with no system `libwirelog`, and documented sdist behavior if any sdist install behavior is intentional. Production PyPI release remains gated on this dry-run evidence. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Artifact attestation verification | Release manager | Workflow: `.github/workflows/release.yml` publish jobs generate release artifact attestations using `actions/attest@v4`. For tagged release artifacts, command: `gh attestation verify <artifact> -R semantic-reasoning/PyreWire --signer-workflow semantic-reasoning/PyreWire/.github/workflows/release.yml --source-ref refs/tags/v1.0.0` for every release wheel (`dist/pyrewire-*.whl`) and the sdist (`dist/pyrewire-*.tar.gz`). For RC/frozen-commit validation before the final tag exists, also verify with `--source-digest <frozen-sha>`. Repo-only `-R` verification alone is not sufficient for this gate. | Successful `release.yml` run URL, release tag or frozen RC commit SHA, artifact filenames, SHA256 hashes for each wheel/sdist, and successful `gh attestation verify` output showing enforced signer workflow and source identity (`--source-ref refs/tags/v1.0.0` or `--source-digest <frozen-sha>`) for each verified artifact. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Artifact attestation verification | Release manager | Workflow: `.github/workflows/release.yml` publish jobs generate release artifact attestations using `actions/attest@v4`. For tagged release artifacts, command: `gh attestation verify <artifact> -R semantic-reasoning/PyreWire --signer-workflow semantic-reasoning/PyreWire/.github/workflows/release.yml --source-ref refs/tags/v1.1.1` for every release wheel (`dist/pyrewire-*.whl`) and the sdist (`dist/pyrewire-*.tar.gz`). For RC/frozen-commit validation before the final tag exists, also verify with `--source-digest <frozen-sha>`. Repo-only `-R` verification alone is not sufficient for this gate. | Successful `release.yml` run URL, release tag or frozen RC commit SHA, artifact filenames, SHA256 hashes for each wheel/sdist, and successful `gh attestation verify` output showing enforced signer workflow and source identity (`--source-ref refs/tags/v1.1.1` or `--source-digest <frozen-sha>`) for each verified artifact. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Wheel dynamic-link check | Packaging owner | Command: `python scripts/ci/check_dynamic_link.py wheelhouse/*.whl`. | Passing command log for the release wheel artifacts. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Clean wheel install | Bindings owner | Manual verification in a clean environment with no system `libwirelog`: install the candidate wheel, import `pyrewire`, confirm PyreWire version, confirm bundled wirelog version, and run integration tests. | Environment description, install command log, import/version log, wirelog version log, and integration test log. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Release notes and changelog | Release manager | Manual verification that the v1.0.0 changelog section is extractable and matches the GitHub Release body generated from `CHANGELOG.md`. | Extracted release notes artifact or command log plus reviewer confirmation. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Metadata, API, support, and security consistency | Release manager | Manual verification that package metadata, public API stability, support matrix, and security policy all describe the same v1.0.0 contract. | Linked review note covering `pyproject.toml`, API stability docs, support docs, and `SECURITY.md`. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Release notes and changelog | Release manager | Manual verification that the v1.1.1 changelog section is extractable and matches the GitHub Release body generated from `CHANGELOG.md`. | Extracted release notes artifact or command log plus reviewer confirmation. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Metadata, API, support, and security consistency | Release manager | Manual verification that package metadata, public API stability, support matrix, and security policy all describe the same v1.1.1 contract. | Linked review note covering `pyproject.toml`, API stability docs, support docs, and `SECURITY.md`. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |

Attestation verification for this gate requires signer workflow and source identity constraints; repo-only verification is not treated as sufficient provenance evidence for PyreWire release artifacts.
This does not independently attest upstream wirelog builds. For bundled wirelog traceability, rely on the pinned wirelog v0.50.0 SHA `272edf3a24b25676f12c4b843d55510f5048dd2f` in release configuration and docs, plus the wheel dynamic-link and clean-install gates above.
This does not independently attest upstream wirelog builds. For bundled wirelog traceability, rely on the pinned wirelog v0.62.0 SHA `39a57cf3c4cdf02f97df0e951fe8ecea7a831e2c` in release configuration and docs, plus the wheel dynamic-link and clean-install gates above.
External blocker for the TestPyPI dry run gate: TestPyPI trusted publishing must be configured for the `.github/workflows/release.yml` workflow identity with GitHub environment `testpypi` before dry-run uploads can pass.
6 changes: 3 additions & 3 deletions docs/support.md
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
# Support Matrix

This page documents the supported PyreWire v1.0 installation targets.
This page documents the supported PyreWire v1 installation targets.
It is a release contract, not a list of every platform that might work
from source.

## Python

PyreWire v1.0 supports CPython 3.11, 3.12, 3.13, and 3.14.
PyreWire v1 supports CPython 3.11, 3.12, 3.13, and 3.14.

## Wheels

Expand All @@ -16,7 +16,7 @@ not need to install wirelog separately.
| Platform | Wheel target | Build and test runner | Notes |
| -------- | ------------ | --------------------- | ----- |
| Linux | `manylinux_2_28` `x86_64` | `ubuntu-24.04` | Built with cibuildwheel's manylinux container and repaired with auditwheel. |
| macOS | `arm64` | `macos-15` | Apple Silicon only for v1.0; no macOS Intel or universal2 wheel is produced. |
| macOS | `arm64` | `macos-15` | Apple Silicon only for v1; no macOS Intel or universal2 wheel is produced. |
| Windows | `win_amd64` / `AMD64` | `windows-2025-vs2026` | Built with MSVC and repaired with delvewheel. |

The bundled library is built from wirelog v0.62.0, using peeled SHA
Expand Down
1 change: 1 addition & 0 deletions docs/versioning.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,7 @@ The minimum compatible runtime wirelog version remains `0.52.0`.
| `1.0.4` | `0.52.0` | `668f82ad69c2bbfc8e8111839302adf1360f55da` | Validated against wirelog `v0.53.0` (peeled tag SHA); runtime minimum remains `0.52.0`. Bundled engine bumped to v0.53.0 with no public C header or SONAME change. |
| `1.0.5` | `0.52.0` | `9f80877c82564cb92ea45bd6fffc2d681b0e13de` | Validated against wirelog `v0.54.0` (peeled tag SHA); runtime minimum remains `0.52.0`. Bundled engine bumped to v0.54.0 to pick up the wirelog#955 semijoin layout fix (#180); the public C header change is additive and the SONAME is unchanged. |
| `1.0.6` | `0.52.0` | `300f3e5150095c85331b561f1f42d99c27b4746f` | Validated against wirelog `v0.60.0` (peeled tag SHA); runtime minimum remains `0.52.0`. Bundled engine bumped to v0.60.0; the exported ABI is additive (19 new symbols, none removed) and the SONAME is unchanged. wirelog#1021 refuses a recursive `min()`/`max()` that shares an SCC with another relation - an engine-level compatibility break that reaches any program PyreWire runs. |
| `1.1.1` | `0.52.0` | `39a57cf3c4cdf02f97df0e951fe8ecea7a831e2c` | Validated against wirelog `v0.62.0` (peeled tag SHA); runtime minimum remains `0.52.0`. Typed Session methods require `0.60.0` or newer. Includes the arithmetic precedence change from wirelog `0.61.0`; expressions may produce different results (see changelog). |

The table grows with every release; the source of truth is the
[CHANGELOG](https://github.com/semantic-reasoning/PyreWire/blob/main/CHANGELOG.md).
2 changes: 1 addition & 1 deletion pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta"

[project]
name = "pyrewire"
version = "1.0.6"
version = "1.1.1"
description = "Python wrapper for wirelog - declarative dataflow analysis"
readme = "README.md"
requires-python = ">=3.11"
Expand Down
2 changes: 1 addition & 1 deletion src/pyrewire/__init__.py
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# SPDX-License-Identifier: Apache-2.0 OR GPL-3.0-or-later
"""PyreWire - Python wrapper for wirelog declarative dataflow analysis."""

__version__ = "1.0.6"
__version__ = "1.1.1"
__author__ = "PyreWire Contributors"
__license__ = "Apache-2.0 OR GPL-3.0-or-later"

Expand Down
2 changes: 1 addition & 1 deletion tests/docs/test_api_stability_contract.py
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# SPDX-License-Identifier: Apache-2.0 OR GPL-3.0-or-later
"""Regression coverage for the documented v1.0 public API policy."""
"""Regression coverage for the documented v1 public API policy."""

from __future__ import annotations

Expand Down
12 changes: 6 additions & 6 deletions tests/docs/test_release_candidate_checklist.py
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# SPDX-License-Identifier: Apache-2.0 OR GPL-3.0-or-later
"""Regression coverage for the v1.0.0 release candidate checklist."""
"""Regression coverage for the v1.1.1 release candidate checklist."""

from __future__ import annotations

Expand Down Expand Up @@ -74,7 +74,7 @@ def test_release_commit_freeze_and_tag_gating_are_explicit():
text = _checklist()

assert "git rev-parse HEAD" in text
assert "The `v1.0.0` tag must point to that exact SHA" in text
assert "The `v1.1.1` tag must point to that exact SHA" in text
assert "must not be cut until every gate below passes on the exact release commit" in text
assert "do not tag or publish" in text

Expand Down Expand Up @@ -166,7 +166,7 @@ def test_testpypi_dry_run_gate_and_evidence_requirements_are_documented():
def test_release_notes_and_consistency_checks_are_documented():
text = _checklist()
for required in (
"v1.0.0 changelog section",
"v1.1.1 changelog section",
"GitHub Release body",
"CHANGELOG.md",
"package metadata",
Expand All @@ -186,7 +186,7 @@ def test_release_security_baseline_and_provenance_scope_are_documented():
"Dependabot is configured for both `github-actions` and `pip` at `/` on a regular schedule",
"gh attestation verify <artifact> -R semantic-reasoning/PyreWire",
"--signer-workflow semantic-reasoning/PyreWire/.github/workflows/release.yml",
"--source-ref refs/tags/v1.0.0",
"--source-ref refs/tags/v1.1.1",
"--source-digest <frozen-sha>",
"Repo-only `-R` verification alone is not sufficient for this gate",
"release.yml` run URL",
Expand All @@ -198,8 +198,8 @@ def test_release_security_baseline_and_provenance_scope_are_documented():
"requires signer workflow and source identity constraints",
"repo-only verification is not treated as sufficient provenance evidence",
"does not independently attest upstream wirelog builds",
"wirelog v0.50.0",
"272edf3a24b25676f12c4b843d55510f5048dd2f",
"wirelog v0.62.0",
"39a57cf3c4cdf02f97df0e951fe8ecea7a831e2c",
"wheel dynamic-link and clean-install gates",
):
assert required in text
Expand Down
3 changes: 2 additions & 1 deletion tests/docs/test_support_matrix.py
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# SPDX-License-Identifier: Apache-2.0 OR GPL-3.0-or-later
"""Regression coverage for the documented v1.0 support matrix."""
"""Regression coverage for the documented v1 support matrix."""

from __future__ import annotations

Expand Down Expand Up @@ -147,6 +147,7 @@ def test_support_documents_sdist_system_libwirelog_behavior():

def test_security_supported_versions_match_v1_contract():
security = _read("SECURITY.md")
assert "| v1.1.x | ✓ |" in security
assert "| v1.0.x | \u2713 |" in security
assert "| < v1.0 | \u2717 |" in security
assert "alpha" not in security.lower()
Expand Down
Loading