Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -54,10 +54,10 @@ jobs:
python: ["3.11", "3.12", "3.13", "3.14"]
env:
# WIRELOG_VERSION here is the exact wirelog ref CI builds against.
# The default is pinned to the wirelog v0.62.0 release commit;
# The default is pinned to the wirelog v0.70.0 release commit;
# override the repository variable to test another ref before
# updating this fallback.
WIRELOG_VERSION: ${{ vars.WIRELOG_VERSION || '39a57cf3c4cdf02f97df0e951fe8ecea7a831e2c' }}
WIRELOG_VERSION: ${{ vars.WIRELOG_VERSION || 'c353350232c35356b34085abf5780a2fcb81e80f' }}
# `runner.temp` is NOT available in job-level `env:` (only in
# step-level contexts) — using it here caused the whole workflow
# to fail at startup (#114). `github.workspace` IS resolvable at
Expand Down
12 changes: 11 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,15 @@ wirelog floor and a validated wirelog ref (see

## [Unreleased]

## [1.1.2] - 2026-09-22

### Changed
- The pin for bundled and validated wirelog builds
moves from `v0.62.0` to `v0.70.0` at peeled SHA
`c353350232c35356b34085abf5780a2fcb81e80f`.
- The minimum compatible runtime wirelog version remains `0.52.0`.
This is a bundled-engine refresh; the PyreWire public API is unchanged.

## [1.1.1] - 2026-09-12

### Added
Expand Down Expand Up @@ -338,7 +347,8 @@ runtime wirelog version remaining `0.44.0`.
wirelog#852. They are available in the later [1.0.0] line, whose
validated wirelog ref is v0.50.0. Tracked in wirelog#859.

[Unreleased]: https://github.com/semantic-reasoning/PyreWire/compare/v1.1.1...HEAD
[Unreleased]: https://github.com/semantic-reasoning/PyreWire/compare/v1.1.2...HEAD
[1.1.2]: https://github.com/semantic-reasoning/PyreWire/compare/v1.1.1...v1.1.2
[1.1.1]: https://github.com/semantic-reasoning/PyreWire/compare/v1.0.6...v1.1.1
[1.0.6]: https://github.com/semantic-reasoning/PyreWire/compare/v1.0.5...v1.0.6
[1.0.5]: https://github.com/semantic-reasoning/PyreWire/compare/v1.0.4...v1.0.5
Expand Down
16 changes: 8 additions & 8 deletions docs/release-candidate-checklist.md
Original file line number Diff line number Diff line change
@@ -1,17 +1,17 @@
# v1.1.1 release candidate checklist
# v1.1.2 release candidate checklist

The v1.1.1 tag must not be cut until every gate below passes on the exact release commit.
The v1.1.2 tag must not be cut until every gate below passes on the exact release commit.
Freeze the release commit first:

```bash
git rev-parse HEAD
```

Record that SHA in the release issue or release PR. The `v1.1.1` tag must point to that exact SHA before any publication step. If any gate fails, do not tag or publish; open or link a GitHub issue, PR, or follow-up task that captures the failure before retrying.
Record that SHA in the release issue or release PR. The `v1.1.2` tag must point to that exact SHA before any publication step. If any gate fails, do not tag or publish; open or link a GitHub issue, PR, or follow-up task that captures the failure before retrying.

| Gate | Owner | Verification | Required evidence | Failure action |
| --- | --- | --- | --- | --- |
| Release commit freeze | Release manager | Command: `git rev-parse HEAD`; manual verification that `v1.1.1` will be created at that SHA. | Recorded release commit SHA and confirmation that the `v1.1.1` tag points to the same SHA. | Link a GitHub issue, PR, or follow-up task and restart the checklist from the corrected commit. |
| Release commit freeze | Release manager | Command: `git rev-parse HEAD`; manual verification that `v1.1.2` will be created at that SHA. | Recorded release commit SHA and confirmation that the `v1.1.2` tag points to the same SHA. | Link a GitHub issue, PR, or follow-up task and restart the checklist from the corrected commit. |
| Formatting | Release manager | Command: `black --check .`; command: `isort --check-only .`. | Passing command logs from the frozen release commit. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Lint and typing | Release manager | Command: `flake8 .`; command: `mypy src/pyrewire`. | Passing command logs from the frozen release commit. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Test suite | Release manager | Command: `pytest -q`. | Passing pytest log from the frozen release commit. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
Expand All @@ -24,12 +24,12 @@ Record that SHA in the release issue or release PR. The `v1.1.1` tag must point
| Dependabot coverage | Release manager | Manual verification of `.github/dependabot.yml`: Dependabot is configured for both `github-actions` and `pip` at `/` on a regular schedule. | Linked review note referencing the merged `.github/dependabot.yml` and both ecosystems. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Release workflow dry run review | Release manager | Manual verification of `.github/workflows/release.yml`: it builds wheels, runs dynamic-link verification, performs clean install tests, verifies release-local wheels and sdist artifacts before publish, uses trusted publishing via OIDC, keeps least-privilege top-level permissions, restricts `id-token: write` to the publish jobs, separates TestPyPI and production PyPI trusted publishing into explicit `testpypi` and `pypi` GitHub environments, and publishes production only after tag-triggered gates pass. Do not actually tag or publish production during RC validation. | Linked review note confirming the tag-triggered `release.yml` gates, least-privilege/OIDC scope, separate publish environments, and no pre-tag production publish occurred. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| TestPyPI dry run evidence | Release manager + Packaging owner | Manual verification: on the frozen RC commit, manually dispatch `.github/workflows/release.yml` with `publish-testpypi: true` and complete a TestPyPI end-to-end dry run before any production tag push. Use install command shape: `python -m pip install --index-url https://test.pypi.org/simple/ --extra-index-url https://pypi.org/simple pyrewire==<candidate-version>`. | Frozen commit SHA, successful `release.yml` workflow run URL, TestPyPI project/version URL, artifact filenames and candidate version, SHA256 hashes, successful TestPyPI upload logs, clean install command logs/results for Linux/macOS/Windows supported Python versions, import smoke output for `pyrewire.__version__` and `pyrewire.wirelog_version()`, confirmation wheel install uses bundled `libwirelog` with no system `libwirelog`, and documented sdist behavior if any sdist install behavior is intentional. Production PyPI release remains gated on this dry-run evidence. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Artifact attestation verification | Release manager | Workflow: `.github/workflows/release.yml` publish jobs generate release artifact attestations using `actions/attest@v4`. For tagged release artifacts, command: `gh attestation verify <artifact> -R semantic-reasoning/PyreWire --signer-workflow semantic-reasoning/PyreWire/.github/workflows/release.yml --source-ref refs/tags/v1.1.1` for every release wheel (`dist/pyrewire-*.whl`) and the sdist (`dist/pyrewire-*.tar.gz`). For RC/frozen-commit validation before the final tag exists, also verify with `--source-digest <frozen-sha>`. Repo-only `-R` verification alone is not sufficient for this gate. | Successful `release.yml` run URL, release tag or frozen RC commit SHA, artifact filenames, SHA256 hashes for each wheel/sdist, and successful `gh attestation verify` output showing enforced signer workflow and source identity (`--source-ref refs/tags/v1.1.1` or `--source-digest <frozen-sha>`) for each verified artifact. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Artifact attestation verification | Release manager | Workflow: `.github/workflows/release.yml` publish jobs generate release artifact attestations using `actions/attest@v4`. For tagged release artifacts, command: `gh attestation verify <artifact> -R semantic-reasoning/PyreWire --signer-workflow semantic-reasoning/PyreWire/.github/workflows/release.yml --source-ref refs/tags/v1.1.2` for every release wheel (`dist/pyrewire-*.whl`) and the sdist (`dist/pyrewire-*.tar.gz`). For RC/frozen-commit validation before the final tag exists, also verify with `--source-digest <frozen-sha>`. Repo-only `-R` verification alone is not sufficient for this gate. | Successful `release.yml` run URL, release tag or frozen RC commit SHA, artifact filenames, SHA256 hashes for each wheel/sdist, and successful `gh attestation verify` output showing enforced signer workflow and source identity (`--source-ref refs/tags/v1.1.2` or `--source-digest <frozen-sha>`) for each verified artifact. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Wheel dynamic-link check | Packaging owner | Command: `python scripts/ci/check_dynamic_link.py wheelhouse/*.whl`. | Passing command log for the release wheel artifacts. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Clean wheel install | Bindings owner | Manual verification in a clean environment with no system `libwirelog`: install the candidate wheel, import `pyrewire`, confirm PyreWire version, confirm bundled wirelog version, and run integration tests. | Environment description, install command log, import/version log, wirelog version log, and integration test log. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Release notes and changelog | Release manager | Manual verification that the v1.1.1 changelog section is extractable and matches the GitHub Release body generated from `CHANGELOG.md`. | Extracted release notes artifact or command log plus reviewer confirmation. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Metadata, API, support, and security consistency | Release manager | Manual verification that package metadata, public API stability, support matrix, and security policy all describe the same v1.1.1 contract. | Linked review note covering `pyproject.toml`, API stability docs, support docs, and `SECURITY.md`. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Release notes and changelog | Release manager | Manual verification that the v1.1.2 changelog section is extractable and matches the GitHub Release body generated from `CHANGELOG.md`. | Extracted release notes artifact or command log plus reviewer confirmation. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |
| Metadata, API, support, and security consistency | Release manager | Manual verification that package metadata, public API stability, support matrix, and security policy all describe the same v1.1.2 contract. | Linked review note covering `pyproject.toml`, API stability docs, support docs, and `SECURITY.md`. | Link a GitHub issue, PR, or follow-up task before retrying or tagging. |

Attestation verification for this gate requires signer workflow and source identity constraints; repo-only verification is not treated as sufficient provenance evidence for PyreWire release artifacts.
This does not independently attest upstream wirelog builds. For bundled wirelog traceability, rely on the pinned wirelog v0.62.0 SHA `39a57cf3c4cdf02f97df0e951fe8ecea7a831e2c` in release configuration and docs, plus the wheel dynamic-link and clean-install gates above.
This does not independently attest upstream wirelog builds. For bundled wirelog traceability, rely on the pinned wirelog v0.70.0 SHA `c353350232c35356b34085abf5780a2fcb81e80f` in release configuration and docs, plus the wheel dynamic-link and clean-install gates above.
External blocker for the TestPyPI dry run gate: TestPyPI trusted publishing must be configured for the `.github/workflows/release.yml` workflow identity with GitHub environment `testpypi` before dry-run uploads can pass.
4 changes: 2 additions & 2 deletions docs/support.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,8 +19,8 @@ not need to install wirelog separately.
| macOS | `arm64` | `macos-15` | Apple Silicon only for v1; no macOS Intel or universal2 wheel is produced. |
| Windows | `win_amd64` / `AMD64` | `windows-2025-vs2026` | Built with MSVC and repaired with delvewheel. |

The bundled library is built from wirelog v0.62.0, using peeled SHA
`39a57cf3c4cdf02f97df0e951fe8ecea7a831e2c`.
The bundled library is built from wirelog v0.70.0, using peeled SHA
`c353350232c35356b34085abf5780a2fcb81e80f`.

## Source Distributions

Expand Down
3 changes: 2 additions & 1 deletion docs/versioning.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ release to publish; it is **not** tied to the wirelog change.
## Current development pin

The current development branch builds and validates against wirelog
`v0.62.0` at peeled SHA `39a57cf3c4cdf02f97df0e951fe8ecea7a831e2c`.
`v0.70.0` at peeled SHA `c353350232c35356b34085abf5780a2fcb81e80f`.
The minimum compatible runtime wirelog version remains `0.52.0`.

## Compatibility table
Expand All @@ -68,6 +68,7 @@ The minimum compatible runtime wirelog version remains `0.52.0`.
| `1.0.5` | `0.52.0` | `9f80877c82564cb92ea45bd6fffc2d681b0e13de` | Validated against wirelog `v0.54.0` (peeled tag SHA); runtime minimum remains `0.52.0`. Bundled engine bumped to v0.54.0 to pick up the wirelog#955 semijoin layout fix (#180); the public C header change is additive and the SONAME is unchanged. |
| `1.0.6` | `0.52.0` | `300f3e5150095c85331b561f1f42d99c27b4746f` | Validated against wirelog `v0.60.0` (peeled tag SHA); runtime minimum remains `0.52.0`. Bundled engine bumped to v0.60.0; the exported ABI is additive (19 new symbols, none removed) and the SONAME is unchanged. wirelog#1021 refuses a recursive `min()`/`max()` that shares an SCC with another relation - an engine-level compatibility break that reaches any program PyreWire runs. |
| `1.1.1` | `0.52.0` | `39a57cf3c4cdf02f97df0e951fe8ecea7a831e2c` | Validated against wirelog `v0.62.0` (peeled tag SHA); runtime minimum remains `0.52.0`. Typed Session methods require `0.60.0` or newer. Includes the arithmetic precedence change from wirelog `0.61.0`; expressions may produce different results (see changelog). |
| `1.1.2` | `0.52.0` | `c353350232c35356b34085abf5780a2fcb81e80f` | Validated against wirelog `v0.70.0` (peeled tag SHA); runtime minimum remains `0.52.0`. Bundled-engine refresh; the PyreWire public API is unchanged. |

The table grows with every release; the source of truth is the
[CHANGELOG](https://github.com/semantic-reasoning/PyreWire/blob/main/CHANGELOG.md).
10 changes: 5 additions & 5 deletions pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta"

[project]
name = "pyrewire"
version = "1.1.1"
version = "1.1.2"
description = "Python wrapper for wirelog - declarative dataflow analysis"
readme = "README.md"
requires-python = ">=3.11"
Expand Down Expand Up @@ -74,7 +74,7 @@ test-requires = ["pytest", "pytest-cov"]
before-build = "python {project}/scripts/bundle_libwirelog.py"
# Pin the wirelog source ref here too so the environment matches the
# `WIRELOG_VERSION` used by the test-matrix workflow.
environment = { WIRELOG_VERSION = "39a57cf3c4cdf02f97df0e951fe8ecea7a831e2c" }
environment = { WIRELOG_VERSION = "c353350232c35356b34085abf5780a2fcb81e80f" }

[tool.cibuildwheel.linux]
manylinux-x86_64-image = "manylinux_2_28"
Expand All @@ -83,7 +83,7 @@ before-all = """
pip install meson && \
WIRELOG_PREFIX=/wirelog-install bash {project}/scripts/build_wirelog.sh
"""
environment = { WIRELOG_VERSION = "39a57cf3c4cdf02f97df0e951fe8ecea7a831e2c", WIRELOG_PREFIX = "/wirelog-install", WIRELOG_LIB = "/wirelog-install/lib/libwirelog.so.1", LD_LIBRARY_PATH = "/wirelog-install/lib" }
environment = { WIRELOG_VERSION = "c353350232c35356b34085abf5780a2fcb81e80f", WIRELOG_PREFIX = "/wirelog-install", WIRELOG_LIB = "/wirelog-install/lib/libwirelog.so.1", LD_LIBRARY_PATH = "/wirelog-install/lib" }
# `auditwheel` bundles libwirelog.so.1 into the wheel and patches the
# RPATH (#31). Without this every wheel would ship as a manylinux
# wheel that immediately fails at import time on systems without the
Expand All @@ -96,15 +96,15 @@ before-all = """
brew install ninja meson pkg-config && \
WIRELOG_PREFIX=$HOME/wirelog-install bash {project}/scripts/build_wirelog.sh
"""
environment = { WIRELOG_VERSION = "39a57cf3c4cdf02f97df0e951fe8ecea7a831e2c", WIRELOG_PREFIX = "$HOME/wirelog-install", WIRELOG_LIB = "$HOME/wirelog-install/lib/libwirelog.1.dylib", DYLD_LIBRARY_PATH = "$HOME/wirelog-install/lib" }
environment = { WIRELOG_VERSION = "c353350232c35356b34085abf5780a2fcb81e80f", WIRELOG_PREFIX = "$HOME/wirelog-install", WIRELOG_LIB = "$HOME/wirelog-install/lib/libwirelog.1.dylib", DYLD_LIBRARY_PATH = "$HOME/wirelog-install/lib" }
# `delocate` is macOS's auditwheel equivalent — copies the dylib into
# the wheel and rewrites install names so the bundled copy wins.
repair-wheel-command = "DYLD_LIBRARY_PATH=$HOME/wirelog-install/lib delocate-wheel --require-archs {delocate_archs} -w {dest_dir} -v {wheel}"

[tool.cibuildwheel.windows]
archs = ["AMD64"]
before-all = "powershell {project}\\scripts\\build_wirelog.ps1"
environment = { WIRELOG_VERSION = "39a57cf3c4cdf02f97df0e951fe8ecea7a831e2c", WIRELOG_PREFIX = "C:/wirelog-install", WIRELOG_LIB = "C:/wirelog-install/bin/wirelog-1.dll" }
environment = { WIRELOG_VERSION = "c353350232c35356b34085abf5780a2fcb81e80f", WIRELOG_PREFIX = "C:/wirelog-install", WIRELOG_LIB = "C:/wirelog-install/bin/wirelog-1.dll" }
# `delvewheel` is the Windows analogue. The bundled DLL ends up in
# `pyrewire/_lib/` and the loader (#2) finds it ahead of system paths.
repair-wheel-command = "pip install delvewheel && delvewheel repair -w {dest_dir} --no-mangle-all --add-path C:/wirelog-install/bin {wheel}"
Expand Down
2 changes: 1 addition & 1 deletion src/pyrewire/__init__.py
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# SPDX-License-Identifier: Apache-2.0 OR GPL-3.0-or-later
"""PyreWire - Python wrapper for wirelog declarative dataflow analysis."""

__version__ = "1.1.1"
__version__ = "1.1.2"
__author__ = "PyreWire Contributors"
__license__ = "Apache-2.0 OR GPL-3.0-or-later"

Expand Down
21 changes: 20 additions & 1 deletion tests/data/wirelog_abi.txt
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,17 @@ wirelog_error_string
wirelog_evaluate
wirelog_executor_create
wirelog_executor_free
wirelog_extension_last_error
wirelog_extension_register
wirelog_extension_registry_create
wirelog_extension_registry_destroy
wirelog_extension_snapshot_acquire
wirelog_extension_snapshot_find
wirelog_extension_snapshot_pin
wirelog_extension_snapshot_release
wirelog_extension_snapshot_retain
wirelog_extension_snapshot_unpin
wirelog_extension_unregister
wirelog_io_ctx_col_type
wirelog_io_ctx_intern_string
wirelog_io_ctx_num_cols
Expand All @@ -44,34 +55,42 @@ wirelog_load_facts_from_csv
wirelog_load_input_files
wirelog_optimize
wirelog_optimize_apply_pass
wirelog_optimize_with_config
wirelog_optimizer_cost_estimate
wirelog_optimizer_debug
wirelog_optimizer_debug_print
wirelog_optimizer_get_default_config
wirelog_optimizer_get_stats
wirelog_optimize_with_config
wirelog_parse
wirelog_parse_string
wirelog_parse_with_error_info
wirelog_program_free
wirelog_program_get_facts
wirelog_program_get_intern
wirelog_program_get_plan_error
wirelog_program_get_relation_ir
wirelog_program_get_rule_count
wirelog_program_get_schema
wirelog_program_get_stratum
wirelog_program_get_stratum_count
wirelog_program_is_stratified
wirelog_program_relation_has_input
wirelog_result_free
wirelog_result_get_relation
wirelog_result_relation_cardinality
wirelog_result_write_csv
wirelog_session_create
wirelog_session_create_with_snapshot
wirelog_session_destroy
wirelog_session_insert
wirelog_session_insert_typed
wirelog_session_make_compound
wirelog_session_make_compound_typed
wirelog_session_remove
wirelog_session_remove_typed
wirelog_session_set_delta_cb
wirelog_session_set_typed_delta_cb
wirelog_session_snapshot
wirelog_session_snapshot_typed
wirelog_session_step
wirelog_version_string
Loading
Loading