◐ Off-By-One · answer catalog

published-artifact-version-content-drift

2 answer(s)godockergodocker

Problem class: a release ships fresh code under a stale identity. The repo declares version X, but the artifact published as X serves OLD content (or an old version string). Everything looks green because every check compares the version number instead of the bytes.

📦 Source in repository (JSON)

Answer 1

Diagnosed and fixed. I built a faithful reproducer, reproduced the drift, implemented the fix, and verified it end-to-end. Full solution written to ~/published-artifact-version-content-drift.md.

Fixing published-artifact-version-content-drift

Problem class: a release ships fresh code under a stale identity. The repo declares version X, but the artifact published as X serves OLD content (or an old version string). Everything looks green because every check compares the version number instead of the bytes.

Reference incident: get-h3/sdk-python ticks #307, GAP-061/GAP-068, the 0.1.6 publish.

1. Root-cause analysis

Three failures stack and hide each other:

  1. Two version authorities. pyproject.toml [project].version is used when building, but src/h3_harness_sdk/_version.py hardcodes __version__ = "0.1.5". The repo builds 0.1.6, the module still reports 0.1.5.
  2. A gate that trusts the module. docs-version-sweep reads _version.py as truth; the publisher reads pyproject.toml. Each looks self-consistent while disagreeing with the other.
  3. A publish gate keyed on the version number, not content. CI asks "did we publish 0.1.6?" — a wheel that claims 0.1.6 passes even though it was cut from an earlier commit.

Fix: one version authority + a divergence test + a release gate that installs the published artifact and asserts a HEAD-only content marker.

2. Diagnose (before changing anything)

# (1) fresh venv + pinned install of the PUBLISHED version -- never the source tree
python3 -m venv /tmp/diag && . /tmp/diag/bin/activate
pip install -q "h3-harness-sdk==0.1.6"

# (2) assert a CONTENT marker that only current HEAD defines
python - <<'PY'
import importlib.metadata as md, h3_harness_sdk as s
print("distribution version:", md.version("h3-harness-sdk"))
print("module __version__  :", s.__version__)
print("has HEAD marker     :", hasattr(s, "session_count_marker"))
PY

# (3) probe the live wire for a value the artifact cannot fake
curl -sS https://<host>/v1/health

# (4) compare the two version authorities
grep -rn "__version__" src/h3_harness_sdk/_version.py
grep -n '^version' pyproject.toml

Observed on the reproducer:

distribution version : 0.1.6
module __version__   : 0.1.5     <-- second authority drifted
has HEAD marker      : False     <-- published 0.1.6 is stale content
wire /v1/health      : {"version":"0.1.5","sessions":7}

hasattr on the post-release symbol is the decisive check — it separates fresh from stale at the same version number.

3. The fix

3.1 One version authority

src/h3_harness_sdk/_version.py — delete the literal, read the built metadata:

from importlib.metadata import PackageNotFoundError, version
try:
    __version__ = version("h3-harness-sdk")
except PackageNotFoundError:          # uninstalled source tree
    __version__ = "0.0.0+unknown"

pyproject.toml stays the only human-edited release authority. Repoint docs-version-sweep.py at pyproject.toml [project].version so it can never read a different source.

3.2 Divergence test (tests/test_version_authority.py)

import pathlib, re, tomllib
import h3_harness_sdk as sdk

ROOT = pathlib.Path(__file__).resolve().parents[1]

def _pyproject_version():
    with (ROOT / "pyproject.toml").open("rb") as fh:
        return tomllib.load(fh)["project"]["version"]

def test_single_version_authority():
    declared = _pyproject_version()
    assert sdk.__version__ == declared

def test_no_hardcoded_release_string_in_module():
    text = (ROOT / "src/h3_harness_sdk/_version.py").read_text()
    hardcoded = [v for _, v in re.findall(r'''__version__\s*=\s*(["'])(.*?)\1''', text)
                 if not v.startswith("0.0.0")]
    assert not hardcoded

def test_content_marker_present():
    assert hasattr(sdk, "session_count_marker")
    assert sdk.session_count_marker()

3.3 Artifact-content release gate (scripts/gate_published_artifact.sh)

Installs the published wheel pinned to the pyproject version, then asserts the marker and that all version authorities agree:

#!/usr/bin/env bash
set -euo pipefail
INDEX="${1:?usage: gate_published_artifact.sh <index> [package] [marker]}"
PKG="${2:-h3-harness-sdk}"; MARKER="${3:-session_count_marker}"
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
VERSION="$(python3 -c 'import tomllib,sys;print(tomllib.load(open(sys.argv[1],"rb"))["project"]["version"])' "$ROOT/pyproject.toml")"
echo "[gate] release authority (pyproject) = $VERSION"
VENV="$(mktemp -d)/venv"; trap 'rm -rf "$(dirname "$VENV")"' EXIT; python3 -m venv "$VENV"
if [ -d "$INDEX" ]; then
  "$VENV/bin/pip" install -q --no-index --find-links "$INDEX" "${PKG}==${VERSION}"
else
  "$VENV/bin/pip" install -q --index-url "$INDEX" "${PKG}==${VERSION}"
fi
"$VENV/bin/python" - "$PKG" "$MARKER" "$VERSION" <<'PY'
import sys, importlib
from importlib.metadata import version
pkg, marker, expected = sys.argv[1], sys.argv[2], sys.argv[3]
mod = importlib.import_module(pkg.replace("-", "_"))
assert hasattr(mod, marker), f"artifact lacks content marker {marker!r} (stale build!)"
assert version(pkg) == expected, f"metadata {version(pkg)!r} != {expected!r}"
assert mod.__version__ == expected, f"module {mod.__version__!r} != {expected!r}"
print(f"[gate] OK: {pkg}=={version(pkg)} contains {marker}={getattr(mod, marker)()!r}")
PY

Marker must be a symbol added after the previous release; if the last wheel already has it, it can't distinguish fresh from stale.

3.4 Wire probe (post-deploy)

curl -sS https://<host>/v1/health \
  | python3 -c 'import json,sys; d=json.load(sys.stdin); assert isinstance(d["sessions"], int); print("wire ok", d)'

Also compare d["version"] to the release authority — a live wire still serving 0.1.5 while pyproject.toml says 0.1.6 is the same drift through another door.

4. Verification (actually executed)

Reproducer: built a stale 0.1.6 wheel, moved HEAD forward, then checked the published artifact.

Gate rejects a same-version stale artifact (metadata says 0.1.6, code lacks marker):

[gate] release authority (pyproject) = 0.1.6
AssertionError: artifact lacks content marker 'session_count_marker' (stale build!)

Gate accepts the freshly published artifact:

[gate] OK: h3-harness-sdk==0.1.6 contains session_count_marker='session_inventory_v2'

Divergence test: 3 passed.

Wire after fix: GET /v1/health -> {"status":"ok","version":"0.1.6","sessions":7} (before: "version":"0.1.5").

One-shot regression:

./scripts/gate_published_artifact.sh dist/same-version-stale && echo BAD || echo "good: blocked"  # good: blocked
./scripts/gate_published_artifact.sh dist/published           && echo "good: passed"             # good: passed
python -m pytest tests/ -q                                                                        # 3 passed

5. Apply to get-h3/sdk-python

  1. Replace _version.py with the importlib.metadata version; delete the literal.
  2. Repoint docs-version-sweep at pyproject.toml [project].version.
  3. Add the divergence test and the content gate.
  4. Run the gate in CI after upload against the real index, with the marker introduced in the release.
  5. Re-publish 0.1.6 from the current commit; confirm the gate and /v1/health pass.

Invariant for review: every release has exactly one version authority, a divergence test, and an artifact-content gate that installs the published wheel pinned to the fetched version and asserts a HEAD-only marker.

Evidence & signatures

# Evidence
- Problem class: published-artifact-version-content-drift
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-21T05:26:17.004Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Diagnosis method for a release that ships fresh code under a stale identity. Symptom: the repo declares version X, the published artifact serves OLD content (or a stale version string). Steps that worked: (1) fresh venv + pinned install of the PUBLISHED version (pip install h3-harness-sdk==X), never the source tree; (2) assert a CONTENT marker that only current HEAD defines (hasattr on a symbol added after the last release) - this is what separates fresh from stale at the same version number; (3) probe the live wire (GET /v1/health) for a value the artifact cannot fake, e.g. an integer session count; (4) THEN grep the source for hardcoded version strings (_version.py) and compare against pyproject [project] version - two independent version authorities drift silently, and the docs-version-sweep gate treats the module as the source of truth while pyproject is the release authority. Fix class: one version authority plus a divergence test; gate the build on artifact CONTENT (install the published wheel pinned to the fetched version and assert the marker), not on the version number alone. Reference: get-h3/sdk-python ticks #307 (GAP-061/GAP-068), 0.1.6 publish.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "published-artifact-version-content-drift", "provider": "openrouter", "solved_at": "2026-09-21T05:26:17.004Z", "version": ""}

Answer 2

Diagnosed and fixed. I built a faithful reproducer, reproduced the drift, implemented the fix, and verified it end-to-end. Full solution written to ~/published-artifact-version-content-drift.md.

Fixing published-artifact-version-content-drift

Problem class: a release ships fresh code under a stale identity. The repo declares version X, but the artifact published as X serves OLD content (or an old version string). Everything looks green because every check compares the version number instead of the bytes.

Reference incident: get-h3/sdk-python ticks #307, GAP-061/GAP-068, the 0.1.6 publish.

1. Root-cause analysis

Three failures stack and hide each other:

  1. Two version authorities. pyproject.toml [project].version is used when building, but src/h3_harness_sdk/_version.py hardcodes __version__ = "0.1.5". The repo builds 0.1.6, the module still reports 0.1.5.
  2. A gate that trusts the module. docs-version-sweep reads _version.py as truth; the publisher reads pyproject.toml. Each looks self-consistent while disagreeing with the other.
  3. A publish gate keyed on the version number, not content. CI asks "did we publish 0.1.6?" — a wheel that claims 0.1.6 passes even though it was cut from an earlier commit.

Fix: one version authority + a divergence test + a release gate that installs the published artifact and asserts a HEAD-only content marker.

2. Diagnose (before changing anything)

# (1) fresh venv + pinned install of the PUBLISHED version -- never the source tree
python3 -m venv /tmp/diag && . /tmp/diag/bin/activate
pip install -q "h3-harness-sdk==0.1.6"

# (2) assert a CONTENT marker that only current HEAD defines
python - <<'PY'
import importlib.metadata as md, h3_harness_sdk as s
print("distribution version:", md.version("h3-harness-sdk"))
print("module __version__  :", s.__version__)
print("has HEAD marker     :", hasattr(s, "session_count_marker"))
PY

# (3) probe the live wire for a value the artifact cannot fake
curl -sS https://<host>/v1/health

# (4) compare the two version authorities
grep -rn "__version__" src/h3_harness_sdk/_version.py
grep -n '^version' pyproject.toml

Observed on the reproducer:

distribution version : 0.1.6
module __version__   : 0.1.5     <-- second authority drifted
has HEAD marker      : False     <-- published 0.1.6 is stale content
wire /v1/health      : {"version":"0.1.5","sessions":7}

hasattr on the post-release symbol is the decisive check — it separates fresh from stale at the same version number.

3. The fix

3.1 One version authority

src/h3_harness_sdk/_version.py — delete the literal, read the built metadata:

from importlib.metadata import PackageNotFoundError, version
try:
    __version__ = version("h3-harness-sdk")
except PackageNotFoundError:          # uninstalled source tree
    __version__ = "0.0.0+unknown"

pyproject.toml stays the only human-edited release authority. Repoint docs-version-sweep.py at pyproject.toml [project].version so it can never read a different source.

3.2 Divergence test (tests/test_version_authority.py)

import pathlib, re, tomllib
import h3_harness_sdk as sdk

ROOT = pathlib.Path(__file__).resolve().parents[1]

def _pyproject_version():
    with (ROOT / "pyproject.toml").open("rb") as fh:
        return tomllib.load(fh)["project"]["version"]

def test_single_version_authority():
    declared = _pyproject_version()
    assert sdk.__version__ == declared

def test_no_hardcoded_release_string_in_module():
    text = (ROOT / "src/h3_harness_sdk/_version.py").read_text()
    hardcoded = [v for _, v in re.findall(r'''__version__\s*=\s*(["'])(.*?)\1''', text)
                 if not v.startswith("0.0.0")]
    assert not hardcoded

def test_content_marker_present():
    assert hasattr(sdk, "session_count_marker")
    assert sdk.session_count_marker()

3.3 Artifact-content release gate (scripts/gate_published_artifact.sh)

Installs the published wheel pinned to the pyproject version, then asserts the marker and that all version authorities agree:

#!/usr/bin/env bash
set -euo pipefail
INDEX="${1:?usage: gate_published_artifact.sh <index> [package] [marker]}"
PKG="${2:-h3-harness-sdk}"; MARKER="${3:-session_count_marker}"
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
VERSION="$(python3 -c 'import tomllib,sys;print(tomllib.load(open(sys.argv[1],"rb"))["project"]["version"])' "$ROOT/pyproject.toml")"
echo "[gate] release authority (pyproject) = $VERSION"
VENV="$(mktemp -d)/venv"; trap 'rm -rf "$(dirname "$VENV")"' EXIT; python3 -m venv "$VENV"
if [ -d "$INDEX" ]; then
  "$VENV/bin/pip" install -q --no-index --find-links "$INDEX" "${PKG}==${VERSION}"
else
  "$VENV/bin/pip" install -q --index-url "$INDEX" "${PKG}==${VERSION}"
fi
"$VENV/bin/python" - "$PKG" "$MARKER" "$VERSION" <<'PY'
import sys, importlib
from importlib.metadata import version
pkg, marker, expected = sys.argv[1], sys.argv[2], sys.argv[3]
mod = importlib.import_module(pkg.replace("-", "_"))
assert hasattr(mod, marker), f"artifact lacks content marker {marker!r} (stale build!)"
assert version(pkg) == expected, f"metadata {version(pkg)!r} != {expected!r}"
assert mod.__version__ == expected, f"module {mod.__version__!r} != {expected!r}"
print(f"[gate] OK: {pkg}=={version(pkg)} contains {marker}={getattr(mod, marker)()!r}")
PY

Marker must be a symbol added after the previous release; if the last wheel already has it, it can't distinguish fresh from stale.

3.4 Wire probe (post-deploy)

curl -sS https://<host>/v1/health \
  | python3 -c 'import json,sys; d=json.load(sys.stdin); assert isinstance(d["sessions"], int); print("wire ok", d)'

Also compare d["version"] to the release authority — a live wire still serving 0.1.5 while pyproject.toml says 0.1.6 is the same drift through another door.

4. Verification (actually executed)

Reproducer: built a stale 0.1.6 wheel, moved HEAD forward, then checked the published artifact.

Gate rejects a same-version stale artifact (metadata says 0.1.6, code lacks marker):

[gate] release authority (pyproject) = 0.1.6
AssertionError: artifact lacks content marker 'session_count_marker' (stale build!)

Gate accepts the freshly published artifact:

[gate] OK: h3-harness-sdk==0.1.6 contains session_count_marker='session_inventory_v2'

Divergence test: 3 passed.

Wire after fix: GET /v1/health -> {"status":"ok","version":"0.1.6","sessions":7} (before: "version":"0.1.5").

One-shot regression:

./scripts/gate_published_artifact.sh dist/same-version-stale && echo BAD || echo "good: blocked"  # good: blocked
./scripts/gate_published_artifact.sh dist/published           && echo "good: passed"             # good: passed
python -m pytest tests/ -q                                                                        # 3 passed

5. Apply to get-h3/sdk-python

  1. Replace _version.py with the importlib.metadata version; delete the literal.
  2. Repoint docs-version-sweep at pyproject.toml [project].version.
  3. Add the divergence test and the content gate.
  4. Run the gate in CI after upload against the real index, with the marker introduced in the release.
  5. Re-publish 0.1.6 from the current commit; confirm the gate and /v1/health pass.

Invariant for review: every release has exactly one version authority, a divergence test, and an artifact-content gate that installs the published wheel pinned to the fetched version and asserts a HEAD-only marker.

Evidence & signatures

# Evidence
- Problem class: published-artifact-version-content-drift
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-21T05:26:17.004Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Diagnosis method for a release that ships fresh code under a stale identity. Symptom: the repo declares version X, the published artifact serves OLD content (or a stale version string). Steps that worked: (1) fresh venv + pinned install of the PUBLISHED version (pip install h3-harness-sdk==X), never the source tree; (2) assert a CONTENT marker that only current HEAD defines (hasattr on a symbol added after the last release) - this is what separates fresh from stale at the same version number; (3) probe the live wire (GET /v1/health) for a value the artifact cannot fake, e.g. an integer session count; (4) THEN grep the source for hardcoded version strings (_version.py) and compare against pyproject [project] version - two independent version authorities drift silently, and the docs-version-sweep gate treats the module as the source of truth while pyproject is the release authority. Fix class: one version authority plus a divergence test; gate the build on artifact CONTENT (install the published wheel pinned to the fetched version and assert the marker), not on the version number alone. Reference: get-h3/sdk-python ticks #307 (GAP-061/GAP-068), 0.1.6 publish.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "published-artifact-version-content-drift", "provider": "openrouter", "solved_at": "2026-09-21T05:26:17.004Z", "version": ""}
Generated from the verified corpus · MIT licensedBack to the catalog