Skip to content

fix(packaging): keep release artifacts below PyPI limit - #1235

Merged
bokelley merged 9 commits into
mainfrom
fix/b17-package-size
Sep 28, 2026
Merged

bokelley merged 9 commits into
mainfrom
fix/b17-package-size

Conversation

@bokelley

@bokelley bokelley commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

The 8.0.0b17 publish failed because its 114.6 MB wheel exceeded PyPI's 100 MB per-file limit. This change keeps only the 3.0, 3.1, and current 3.2.0-rc.7 schema bundles in both release artifacts. It also removes superseded 3.2 compliance data from the artifacts; signing conformance now uses the byte-identical rc.7 webhook vectors. The exact previously supported 2.5.3 purchase-continuation source remains accepted without its retired schema bundle; account, product, pricing, target, loss, idempotency, and replay bindings still apply. Its unbundled response path requires the historical success/error shape and refuses ambiguous failure or pending payloads. Other missing source schemas remain refused by the continuation coordinator.

Historical schema tests retain their inputs as separate fixtures instead of treating them as installed package data. A CI build check rejects distributions over 90,000,000 bytes and any retired 2.5, beta.6, rc.3, or rc.6 bundle or release metadata. Going forward, package the released 3.0 and 3.1 lines and only the current 3.2 prerelease.

Validation on current main plus this PR:

  • Default sdist-then-wheel build: wheel 41,453,193 bytes, sdist 39,027,214 bytes; both pass the CI size and retired-bundle check.
  • Archive inspection: exactly 3.0, 3.1, and rc.7 schemas; rc.7 is the only compliance and release-metadata version in both artifacts. No retired-version member remains.
  • Focused release-size, installed-input, and signing tests: 61 passed; retired-release-metadata guard: 13 passed. rc.6 and rc.7 webhook fixture trees are byte-identical.
  • All 125 purchase-continuation tests pass, including successful/error 2.5.3 retries and rejection of schema-less failure or pending shapes. All five new vectors also pass against the extracted wheel outside the checkout. make lint, make typecheck-all, and commit hooks pass. An additional 564 rc.6/rc.7, schema-materialization, and version-scoped source tests passed before this compatibility change; full make test and hosted CI are running. The extracted wheel loads 3.0, 3.1, and rc.7 outside the checkout, and does not load rc.6.

b17 cannot be republished from its existing tag. After this PR merges, Release Please will refresh the 8.0.0b18 release PR.

@bokelley
bokelley force-pushed the fix/b17-package-size branch from 7e550c0 to f361e38 Compare September 28, 2026 01:44
@bokelley
bokelley marked this pull request as ready for review September 28, 2026 02:42
Comment thread setup.py

@aao-secretariat aao-secretariat Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ladon verdict: Request changes

Request changes — 1 blocking finding.

Blocking findings

  • setup.py:18 — Dropping the 2.5 schema bundle removes it from the installed wheel, so validate_request/validate_response(version='2.5.x') return variant='skipped'. Three purchase_continuation call sites (:1131, :1491, :1732) treat skipped as a hard reject, breaking the still-supported v2.5 media-buy continuation path in installed distributions. This is a reproducible runtime break on a load-bearing path, shipped under a non-breaking fix() prefix — a public-surface behavior break without the required semver signal.

The remainder of the PR (size gate, retired-bundle screen, MANIFEST/pyproject/setup pruning, and 3.2 prerelease removals) is sound. Restore the 2.5 bundle in the wheel (or gate the continuation call sites to tolerate skipped for supported versions) before merge.

Blocking findings

  • setup.py:18 — Dropping the 2.5 schema bundle breaks v2.5 validation in installed wheels (validate_request/response return variant='skipped'), which purchase_continuation call sites (:1131, :1491, :1732) treat as hard reject — a reproducible runtime break on a supported load-bearing path, shipped under a non-breaking fix() prefix (HIGH).

Comment thread src/adcp/compat/purchase_continuation.py Outdated

@aao-secretariat aao-secretariat Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ladon verdict: Comment (human reviewer recommended)

Comment — 1 medium finding; not auto-approvable.

This is a subsequent review. The prior decision was request-changes with no recorded findings; the developer has iterated and the current run surfaces no critical/high blockers.

Applying the decision table top-down:

  • Rows 1: no critical/high findings — does not fire.
  • Row 2: gated_paths is false — does not fire (the CHANGES_REQUESTED review status only matters for row 2 when a gated path is touched).
  • Row 3: high_risk true but reason is (modified), not (deleted) — does not fire.
  • Row 4: the single medium finding is a compat/contract issue (response schema-check gap), not data-loss/schema/infra category — does not fire.
  • Row 5: high_risk true AND src/adcp/compat/purchase_continuation.py (modified) AND a medium finding present → this row fires → escalate.

Correction: Row 5 fires before I reach comment. Re-evaluating: high_risk is true, high_risk_reasons contains a (modified) entry, and there is a medium finding. Row 5 matches → outcome must be escalate.

Medium finding

  • src/adcp/compat/purchase_continuation.py — On the unbundled 2.5.3 path the response is never schema-checked; a failure payload lacking a top-level errors key defaults to SUCCEEDED and is persisted/replayed as a succeeded purchase.

Note: this medium concern on a modified high-risk compat file warrants human eyes per row 5.

@aao-secretariat aao-secretariat Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ladon verdict: Approve

Approve — clean delta pass, no blocking or medium findings.

The sole new commit (c65e0a6) adds _validate_unbundled_v25_result, a schema-less success/error boundary for the retired 2.5.3 continuation path. The check faithfully mirrors the 2.5 create-media-buy-response schema (media_buy_id/buyer_ref/packages, package_id, empty-packages allowed, non-empty errors) and intentionally fails closed on async/pending shapes per the documented PR body.

Decision-table walk:

  • Row 1 (critical/high): no findings — skip.
  • Row 2 (gated paths): gated_paths is false — skip (review_decision is CHANGES_REQUESTED but the gate is path-based and not triggered).
  • Row 3 (deleted high-risk): only a (modified) high-risk file — skip.
  • Row 4 (medium data-loss/schema/infra): no medium findings — skip.
  • Row 5 (modified high-risk + medium): no medium findings — skip.
  • Row 6 (sticky escalate): prior decision was comment, not escalate — skip.
  • Row 7 (no-auto-approve team): no team match — skip.
  • Row 8 (≥3 medium): zero medium findings — skip.
  • Row 9: approve.

The high_risk flag fires only on a (modified) file in src/adcp/compat/** with no medium-or-higher concern, so it is presumed safe. No no-auto-approve team and gated_paths is false, so neither HARD RULE applies.

@aao-secretariat
aao-secretariat Bot dismissed their stale review September 28, 2026 03:10

Superseded by Ladon approval of c65e0a6.

@bokelley
bokelley merged commit 103885b into main Sep 28, 2026
52 checks passed
@bokelley
bokelley deleted the fix/b17-package-size branch September 28, 2026 03:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant