Conversation
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The release-candidate commit rewrote tests/test_spm_household.py::test_state_only_graphs_require_geography_only_where_measurement_is_used to drive the assisted case through computed HUD semantics — `pha_payment_standard`, `receives_housing_assistance`, `spm_unit_allocated_housing_subsidy` and `spm_unit_allocated_tenant_payment`. Those are country behaviours the unified candidate policyengine-us#9467 carries, not the pinned model, and the rewrite went through the R1–R3 reviews unverified. Return the file to the reviewed content at 1b6c001. The rewrite comes back with the country repin, once #9467 publishes and the pin in pyproject.toml moves. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The release-candidate commit replaced the Publish job's inline `bundle.py check --published-spm --include-tros --strict-tros` with `release_build.py publish-check`, which runs that same check itself (scripts/release_build.py:1381). The bootstrap test still searched the Publish steps for the inline command, so its generator expression matched nothing and `next` raised StopIteration instead of asserting anything. Search for the step that now carries the gate. NotifyConsumers is unchanged: it runs after PyPI visibility without the package installed, so it keeps the dependency-light `python -S scripts/bundle.py check --published-spm`. That publish-check still performs the published-spm check is pinned separately by test_publication_checks_existing_strict_gates_before_member_comparison, which asserts its exact call sequence; the comment now points there. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
`assert_source_origin` refused every `policyengine*` module whose `__file__` was None. `policyengine.tax_benefit_models` has no `__init__.py`, so its `__file__` is None while its `__path__` points inside the checkout, and any interpreter that has imported a country model carries it. The test session does, through tests/conftest.py -> tests/fixtures/us_reform_fixtures.py:12, so test_source_origin_rejects_previously_imported_other_checkout failed even when run alone — an instrumented probe over the three import phases found that one module and no other. Locate each module through `module_origin`: by `__file__` when it has one, otherwise by every `__path__` portion, each of which must resolve inside the prepared source. A module with neither is unattributable and still refused, as is an empty `__path__` and any portion outside the checkout — the shape a synthesized stand-in takes. Namespace packages are recorded in the receipt as the list of their portions. tests/test_graph/test_extractor.py was the session's second poisoner: it installs bare stand-ins for `policyengine` and `policyengine.graph` at import time, i.e. during collection, and never took them out. It now restores sys.modules in a `finally`, which leaves nothing behind at all. The loaded module objects stay alive through the references it returns, and extractor.py resolves its own `from policyengine.graph.graph import VariableGraph` while the entries are still installed. Three new cases cover the namespace acceptance and the three refusals. Both directions are pinned: reverting the fix fails the acceptance test, and accepting any file-less module fails all three refusals. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Commit 4460450 wrote this lane's progress over the file rather than adding to it, dropping the prior lane's 178-line record: rulings A-E, the verified 2.0.1 prerequisites, the data-certification blocker, and the country archaeology behind the rebaselined snapshots. None of that is recoverable from anywhere else in the tree. Restore it verbatim and keep this lane's section above it. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Two claims made earlier in this lane needed tightening. The namespace package is first imported through tests/conftest.py:6 -> filtering_fixtures.py:7, not through us_reform_fixtures.py:12 as abf7545's message says; both are unrestored module-level imports and the fix covers either. And the rewrite's dependency on policyengine-us#9467 was asserted from the brief rather than checked: #9467's file list does add exactly the two absent variables, so the attribution now rests on the PR itself. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
An adversarial pass over the three fixes found four things worth closing, all
in the direction of keeping what the relaxed guard gave up.
A root `policyengine` stand-in used to be refused by the file rule before
anything else ran. Accepting a `__path__` let it through the walk and into
`files("policyengine")`, which raises AttributeError on it — a class main()
does not catch, so a hold would have ended in a traceback. Settle the root
package's own `__init__.py` first, and short-circuit before `files()`.
The relaxed rule newly admits a fileless module whose `__path__` points inside
the checkout. Neither `__file__` nor `__path__` is proof — an in-process caller
that can write sys.modules can assign either — so the docstring now says what
the check does and does not establish, and a test pins the admitted shape
instead of leaving it to be discovered.
WRAPPER-R3-CI-DIAGNOSIS-20260913.md §1 asks for the origin control to run in a
fresh interpreter matching the production `source_command` boundary, and a
root-approved patch (wrapper-ci-harness-repair-20260913/ROOT-REVIEW.json,
parent 818c894) does exactly that instead of touching the guard. Take the
subprocess control as well: it proves the cross-checkout refusal where no
collector has been, so the property survives independently of the allowance.
§2 asks that publish-check precede the tag as well as the upload. The git tag
is a public side effect between them, so assert the full order.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
MaxGhenis
force-pushed
the
max/spm-canonical-wrapper-release-20260910
branch
from
September 15, 2026 04:03
818c894 to
1b6c001
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Keeps the release-candidate tooling from
818c894eand fixes the two defects itcarries, plus a test rewrite that no review examined.
This stack cannot stand on
main. Verified againstorigin/main:scripts/release_lock.py,scripts/check_release_credentials.pyandscripts/spm_bundle.pydo not exist there;scripts/bundle.pyexists but has no--published-spm; andtrace_tro.schema.jsonexists but itspe:emittedInenumis
["local", "github-actions", "policyengine-api"], without therepository-bundlevaluerelease_build.pyemits. Base is thereforemax/spm-canonical-wrapper-release-20260910, whose head is already818c894e.What the reviews did and did not cover
The R1–R3 chain lives at
/Users/maxghenis/spm-rebuild-20260908/rollout/codex-continuation-20260912/.The author-side records are the six
WRAPPER-RELEASE-BUILD*files —-PREPARATION.mdand-SOURCE-INVENTORY.json(R1, staged patch39c12b24…),-R2-RESPONSE.mdand-SOURCE-INVENTORY-R2.json(patchcb7c8ef0…),-R3-RESPONSE.mdand-SOURCE-INVENTORY-R3.json(patchf8856478…). The independent verdicts sit beside them inwrapper-build-source-review/: R1INDEPENDENT-REVIEW.md"not APPROVE",thirteen findings; R2
INDEPENDENT-REVIEW-R2.md"APPROVE with limits,conditional on Findings 1–3"; R3
INDEPENDENT-REVIEW-R3.md"APPROVE withlimits", closed by
ROOT-REVIEW-R3.jsonassource_preparation_approved.Every reviewer worked without a shell and ran nothing. Two consequences show up
as the defects this PR fixes.
tests/test_spm_bundle_bootstrap.pyis named in none of the six files, noneof the three frozen inventories, and none of the three reviews. Nobody checked
whether its assertion still matched the workflow the patch rewrote.
tests/test_spm_household.pywas carried by hash, not read.WRAPPER-RELEASE-BUILD-R2-RESPONSE.md:35: "tests/test_spm_household.pyremains SHA256
061cbc1b…. It has been provided unchanged to root's separatehousehold verification agent. This lane did not run household calculations
against the unrelated installed 2.0.0 model." The three independent reviews
contain zero occurrences of "household".
assert_source_origincame from R1 finding F9(
INDEPENDENT-REVIEW.md:103-110) and was reviewed as a fix, never exercised.Commits
35981756— restore the reviewed household test. Returnstests/test_spm_household.pyto its1b6c001ccontent, byte-identical (sha256fe6df0c7…). The818c894erewrite (sha256061cbc1b…) drives the assistedcase through
spm_unit_allocated_housing_subsidyandspm_unit_allocated_tenant_payment. Neither exists in the pinnedpolicyengine-us 2.0.0 — zero
class <name>(Variable)definitions across theinstalled model — so
dispatch_extra_variablesraisesValueErrorbefore anyassertion runs. Both are added by the unified country candidate
PolicyEngine/policyengine-us#9467, verified from its file list:
policyengine_us/variables/household/income/spm_unit/spm_unit_allocated_housing_subsidy.pyand
…/spm_unit_allocated_tenant_payment.py. The other three names the rewriteintroduces (
pre_subsidy_rent,pha_payment_standard,receives_housing_assistance) do exist in 2.0.0.The rewrite returns with the country repin — once #9467 publishes and the
pin in
pyproject.tomlmoves, not before.1b6c001cis the reviewedpost-Ruling-A content, so this revert leaves Ruling A intact.
14e5db47— follow the publication gate through its new indirection.818c894ereplaced the Publish job's inlinebundle.py check --published-spm --include-tros --strict-troswithrelease_build.py publish-check. The test still searched the Publish steps forthe inline command, so its generator matched nothing and
nextraisedStopIterationinstead of asserting. It now finds the step that carries thegate (
push.yaml:164, index 2) and still requires it beforepypa/gh-action-pypi-publish(index 9).publish_checkruns that same checkitself (
scripts/release_build.py:1381), pinned bytest_publication_checks_existing_strict_gates_before_member_comparison.NotifyConsumers is untouched and keeps the dependency-light
python -S scripts/bundle.py check --published-spm.abf75454— place a namespace package by its portions.assert_source_originrefused everypolicyengine*module whose__file__wasNone.
policyengine.tax_benefit_modelshas no__init__.py, so its__file__is None while its
__path__points inside the checkout, and any interpreterthat has imported a country model carries it. An instrumented probe over three
import phases located it rather than guessing: bare
import policyenginegives0 offenders; after
tests/conftest.py, exactly one — that namespace package;after
tests/test_graph/test_extractor.py, two more. That is whytest_source_origin_rejects_previously_imported_other_checkoutfailed even whenrun alone.
module_originnow places a module by__file__when it has one, otherwise byevery
__path__portion, each of which must resolve inside the prepared source.A module with neither, an empty
__path__, or any portion outside is stillrefused — the shape a synthesized stand-in takes.
tests/test_graph/test_extractor.pywas the session's second poisoner: itinstalls bare stand-ins for
policyengineandpolicyengine.graphat importtime, i.e. during collection, and never removed them. It now restores
sys.modulesin afinallyand leaves nothing behind at all.Three new cases cover the acceptance and the three refusals, and both directions
are mutation-checked: reverting to the pre-fix logic fails the acceptance case,
and accepting any file-less module fails all three refusals.
44604506,b8cf1449,d841dae3,82721388ande98d280aare PROGRESS.md. The first overwrote theprior lane's 178-line record;
d841dae3restores it verbatim beneath thislane's section.
e0b1f4f2— hold the strict property where session state cannot reach it.An adversarial pass over the three fixes closed four gaps. A root
policyenginestand-in used to be refused by the file rule before anything else ran; accepting
a
__path__let it reachfiles("policyengine"), which raisesAttributeError— a class
main()does not catch, so a hold would have ended in a traceback.The root package's own
__init__.pyis now settled first. The docstring sayswhat the check does and does not establish: neither
__file__nor__path__isproof, since an in-process caller that can write
sys.modulescan assign either.A test pins the shape the allowance newly admits instead of leaving it to be
discovered. The subprocess control from the approved harness patch is adopted as
well, and
publish-checkis now required before the git tag, not only before theupload.
Conflicts with prior rulings
Two places where this brief and a prior approved ruling disagree. Reported, not
resolved here.
WRAPPER-R3-CI-DIAGNOSIS-20260913.md§1:"Keep the production guard strict. Do not delete arbitrary cached modules or
accept missing origins merely to pass the full suite." A root-approved patch
—
wrapper-ci-harness-repair-20260913/ROOT-REVIEW.json,approved: true,parent
818c894e, patch sha2569ad1e023…— repairs the same failure in theharness with a fresh subprocess and leaves
assert_source_originuntouched.e0b1f4f2adopts that subprocess control as an additional test, so the strictcross-checkout property is pinned either way and switching to the approved
patch would cost only the namespace branch.
assertion and complete the already approved final-country pin transaction".
The brief instructed the revert, recorded as returning with the repin. The
evidence justifying its restoration is
household-integration-20260912/REPORT.md: 84 wrapper controls against theauthenticated country
2.0.2rc1.§1's line-208 reading also means the restore is two-part: the rewrite needs both
the two absent variables and the country's assisted ordinary-resource
independence. Re-adding only the variables would still fail.
A fourth blocker these fixes do not touch
gh pr checks 515showsNonpublishing wrapper candidate (release)failing in12s at
scripts/check_release_credentials.py— "Release verification requiresan authenticated Hugging Face access token with role read" — before any strict
gate. This PR addresses the four
Test (3.x)failures. #515 stays red until thecredential is settled.
Verification
Locked environment,
uv sync --frozen, Python 3.14.4.pytest tests/test_release_build.py tests/test_spm_bundle_bootstrap.py tests/test_graph -q, beforepytest tests -qruff format --check .ruff check .The 11
ruff checkfindings are all present at818c894e, allUP038, and nonein a file this PR touches; the touched files pass clean. The local lock resolves
ruff 0.12.11, which still has
UP038; CI installs 0.16.7, which does not, andCI's Lint job passes on this tree.
Not verified here
The commit message on
abf75454namestests/conftest.py→tests/fixtures/us_reform_fixtures.py:12as the import path to the namespacepackage. That is a real path but not the first one:
tests/conftest.py:6→tests/fixtures/filtering_fixtures.py:7reaches it earlier in every session.Both are unrestored module-level imports; the fix covers either.
🤖 Generated with Claude Code