Add pipelines dehydrate with verified, portable component refs (v0.1.28) - #72
Merged
Volv-G merged 1 commit intoSep 30, 2026
Conversation
…1.28) Add a first-class `tangle sdk pipelines dehydrate PIPELINE -o OUTPUT [--mode auto|digest|name|url|file] [--components-dir DIR]` command backed by the shared PipelineDehydrator, and fix correctness bugs it exposed. - A published digest is emitted only when its own spec semantically matches the inline component, never merely because it exists. - Explicit DIGEST/NAME write a per-output resolve config with an ordered [verified primary, local copy] fallback; NAME pins the inspected owner. - A `fallback_on_error` resolve-config marker lets a generated primary fall through to its local copy; unmarked configs are unchanged. - Every mode fully dehydrates nested graphs. - Extracted subgraph files are content-addressed, fixing silent cross-output overwrites from per-run counter names. - Per-call extraction state resets, so reused instances cannot leak one output's bundle into another.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
(AI-assisted)
What
Adds a first-class
tangle sdk pipelines dehydrate PIPELINE -o OUTPUT [--mode auto|digest|name|url|file] [--components-dir DIR]command, the inverse ofpipelines hydrate. It is backed by the sharedPipelineDehydratorand does no traversal of its own. The PR also fixes the dehydrator correctness bugs that exposing the command revealed. Version 0.1.28.Visible behaviour changes
autoverifies content. A published digest is emitted only when its own published spec semantically matches the inline component, not merely because the digest exists. This affectspipeline-runs export --dehydrate: a mismatching digest now extracts a local file instead.digest/namealways write a local copy plus one<output stem>.components.yamlresolve config per output, referenced asresolve://./<stem>.components.yaml#<fragment>. Each fragment is an ordered list: the verified primary first, then the local copy.namepins the owner found viaComponentInspector.inspect_by_digest. It pins the author, not the version; hydration still resolves that owner's latest candidate.file/urlused to leave inline subgraph specs in place, producing a partially hydrated document.name_N.yamlbecomesname-<digest>.yaml, and thesubgraphs/directory location is unchanged.fallback_on_error: true. A marked entry that raises falls through to the next entry. Unmarked, single and last entries propagate errors exactly as before, so hand-authored configs are unaffected.Evidence
A silent cross-output corruption bug, pre-existing on master. Subgraph files were named
<name>_<counter>.yamlin a sharedsubgraphs/directory. Dehydrating pipeline A toa.yamland then a different pipeline B tob.yamlin the same directory made both writesubgraphs/judge_0.yaml, anda.yamlthen rehydrated to B's content. It was reproduced and is now covered by a regression test. Genuinely distinct specs still get separate files: a real case differing only in acomponent_yaml_pathprovenance annotation stays two files.Other bugs found and fixed during review, each reproduced first:
find_existing_componentsreturns rows without specs.null/false/[]input and wrote{}.Path("gs://…")collapsed the//into a localgs:/…path, and the command wrote there.base_urlwhen no client was passed.How
pipeline_dehydrator.py:subgraphs/, and processed deepest-first so a parent's address covers its children's names.client_factoryforwarded toTangleCliHandler.self._get_client().pipeline_hydrator.py: thefallback_on_errormarker only.pipelines.py:dehydrate_pipeline_fileandDehydrateResult. It loads input with the strictload_pipeline_file, rejects raw://URIs beforePath()normalization using the engine's own URI rule (so Windows drive paths stay local), and never echoes the URI value, which may carry credentials.pipelines_cli.py: the command.str-typed path arguments so URI detection sees the raw value,LazyTangleApiClient, and the same option and config plumbing ashydrate.Two semantics were deliberately accepted by the human:
Failure modes
--header/--auth-header: deliberately a loud error, not a silent local-only result.ResolveManifestUnavailableErrorrather than writing into the cwd.Testing
tests/test_packaging.py: 10/10 passed, identical on pristineorigin/mastergit diff --check: cleantest_dehydrator_portable_refs.py,test_pipelines_dehydrate_cli.pyandtest_dehydrator_subgraph_addressing.py. NAME and CLI tests drive the realTangleApiClient, stubbed only at its HTTP seams.Independent review by pi-135: six rounds, final verdict NO BLOCKING FINDINGS. Review page: https://piforge-preview.quick.shopify.io/?s=tangle-pipeline-crud&p=portable-dehydrator-references-independent-corre-bb128a37
Review focus
fallback_on_errorhydrator contract: the one shared-behaviour change for resolve configs.Known non-blocking follow-ups, not in this PR: