Problem class: a release ships fresh code under a stale identity. The repo declares version X, but the artifact published as X serves OLD content (or an old version string). Everything looks green because every check compares the version number instead of the bytes.
Diagnosed and fixed. I built a faithful reproducer, reproduced the drift, implemented the fix, and verified it end-to-end. Full solution written to ~/published-artifact-version-content-drift.md.
Problem class: a release ships fresh code under a stale identity. The repo declares version X, but the artifact published as X serves OLD content (or an old version string). Everything looks green because every check compares the version number instead of the bytes.
Reference incident: get-h3/sdk-python ticks #307, GAP-061/GAP-068, the 0.1.6 publish.
Three failures stack and hide each other:
pyproject.toml [project].version is used when building, but src/h3_harness_sdk/_version.py hardcodes __version__ = "0.1.5". The repo builds 0.1.6, the module still reports 0.1.5._version.py as truth; the publisher reads pyproject.toml. Each looks self-consistent while disagreeing with the other.0.1.6?" — a wheel that claims 0.1.6 passes even though it was cut from an earlier commit.Fix: one version authority + a divergence test + a release gate that installs the published artifact and asserts a HEAD-only content marker.
# (1) fresh venv + pinned install of the PUBLISHED version -- never the source tree
python3 -m venv /tmp/diag && . /tmp/diag/bin/activate
pip install -q "h3-harness-sdk==0.1.6"
# (2) assert a CONTENT marker that only current HEAD defines
python - <<'PY'
import importlib.metadata as md, h3_harness_sdk as s
print("distribution version:", md.version("h3-harness-sdk"))
print("module __version__ :", s.__version__)
print("has HEAD marker :", hasattr(s, "session_count_marker"))
PY
# (3) probe the live wire for a value the artifact cannot fake
curl -sS https://<host>/v1/health
# (4) compare the two version authorities
grep -rn "__version__" src/h3_harness_sdk/_version.py
grep -n '^version' pyproject.toml
Observed on the reproducer:
distribution version : 0.1.6
module __version__ : 0.1.5 <-- second authority drifted
has HEAD marker : False <-- published 0.1.6 is stale content
wire /v1/health : {"version":"0.1.5","sessions":7}
hasattr on the post-release symbol is the decisive check — it separates fresh from stale at the same version number.
src/h3_harness_sdk/_version.py — delete the literal, read the built metadata:
from importlib.metadata import PackageNotFoundError, version
try:
__version__ = version("h3-harness-sdk")
except PackageNotFoundError: # uninstalled source tree
__version__ = "0.0.0+unknown"
pyproject.toml stays the only human-edited release authority. Repoint docs-version-sweep.py at pyproject.toml [project].version so it can never read a different source.
tests/test_version_authority.py)import pathlib, re, tomllib
import h3_harness_sdk as sdk
ROOT = pathlib.Path(__file__).resolve().parents[1]
def _pyproject_version():
with (ROOT / "pyproject.toml").open("rb") as fh:
return tomllib.load(fh)["project"]["version"]
def test_single_version_authority():
declared = _pyproject_version()
assert sdk.__version__ == declared
def test_no_hardcoded_release_string_in_module():
text = (ROOT / "src/h3_harness_sdk/_version.py").read_text()
hardcoded = [v for _, v in re.findall(r'''__version__\s*=\s*(["'])(.*?)\1''', text)
if not v.startswith("0.0.0")]
assert not hardcoded
def test_content_marker_present():
assert hasattr(sdk, "session_count_marker")
assert sdk.session_count_marker()
scripts/gate_published_artifact.sh)Installs the published wheel pinned to the pyproject version, then asserts the marker and that all version authorities agree:
#!/usr/bin/env bash
set -euo pipefail
INDEX="${1:?usage: gate_published_artifact.sh <index> [package] [marker]}"
PKG="${2:-h3-harness-sdk}"; MARKER="${3:-session_count_marker}"
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
VERSION="$(python3 -c 'import tomllib,sys;print(tomllib.load(open(sys.argv[1],"rb"))["project"]["version"])' "$ROOT/pyproject.toml")"
echo "[gate] release authority (pyproject) = $VERSION"
VENV="$(mktemp -d)/venv"; trap 'rm -rf "$(dirname "$VENV")"' EXIT; python3 -m venv "$VENV"
if [ -d "$INDEX" ]; then
"$VENV/bin/pip" install -q --no-index --find-links "$INDEX" "${PKG}==${VERSION}"
else
"$VENV/bin/pip" install -q --index-url "$INDEX" "${PKG}==${VERSION}"
fi
"$VENV/bin/python" - "$PKG" "$MARKER" "$VERSION" <<'PY'
import sys, importlib
from importlib.metadata import version
pkg, marker, expected = sys.argv[1], sys.argv[2], sys.argv[3]
mod = importlib.import_module(pkg.replace("-", "_"))
assert hasattr(mod, marker), f"artifact lacks content marker {marker!r} (stale build!)"
assert version(pkg) == expected, f"metadata {version(pkg)!r} != {expected!r}"
assert mod.__version__ == expected, f"module {mod.__version__!r} != {expected!r}"
print(f"[gate] OK: {pkg}=={version(pkg)} contains {marker}={getattr(mod, marker)()!r}")
PY
Marker must be a symbol added after the previous release; if the last wheel already has it, it can't distinguish fresh from stale.
curl -sS https://<host>/v1/health \
| python3 -c 'import json,sys; d=json.load(sys.stdin); assert isinstance(d["sessions"], int); print("wire ok", d)'
Also compare d["version"] to the release authority — a live wire still serving 0.1.5 while pyproject.toml says 0.1.6 is the same drift through another door.
Reproducer: built a stale 0.1.6 wheel, moved HEAD forward, then checked the published artifact.
Gate rejects a same-version stale artifact (metadata says 0.1.6, code lacks marker):
[gate] release authority (pyproject) = 0.1.6
AssertionError: artifact lacks content marker 'session_count_marker' (stale build!)
Gate accepts the freshly published artifact:
[gate] OK: h3-harness-sdk==0.1.6 contains session_count_marker='session_inventory_v2'
Divergence test: 3 passed.
Wire after fix: GET /v1/health -> {"status":"ok","version":"0.1.6","sessions":7} (before: "version":"0.1.5").
One-shot regression:
./scripts/gate_published_artifact.sh dist/same-version-stale && echo BAD || echo "good: blocked" # good: blocked
./scripts/gate_published_artifact.sh dist/published && echo "good: passed" # good: passed
python -m pytest tests/ -q # 3 passed
get-h3/sdk-python_version.py with the importlib.metadata version; delete the literal.docs-version-sweep at pyproject.toml [project].version.0.1.6 from the current commit; confirm the gate and /v1/health pass.Invariant for review: every release has exactly one version authority, a divergence test, and an artifact-content gate that installs the published wheel pinned to the fetched version and asserts a HEAD-only marker.
# Evidence - Problem class: published-artifact-version-content-drift - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-21T05:26:17.004Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Diagnosis method for a release that ships fresh code under a stale identity. Symptom: the repo declares version X, the published artifact serves OLD content (or a stale version string). Steps that worked: (1) fresh venv + pinned install of the PUBLISHED version (pip install h3-harness-sdk==X), never the source tree; (2) assert a CONTENT marker that only current HEAD defines (hasattr on a symbol added after the last release) - this is what separates fresh from stale at the same version number; (3) probe the live wire (GET /v1/health) for a value the artifact cannot fake, e.g. an integer session count; (4) THEN grep the source for hardcoded version strings (_version.py) and compare against pyproject [project] version - two independent version authorities drift silently, and the docs-version-sweep gate treats the module as the source of truth while pyproject is the release authority. Fix class: one version authority plus a divergence test; gate the build on artifact CONTENT (install the published wheel pinned to the fetched version and assert the marker), not on the version number alone. Reference: get-h3/sdk-python ticks #307 (GAP-061/GAP-068), 0.1.6 publish.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "published-artifact-version-content-drift", "provider": "openrouter", "solved_at": "2026-09-21T05:26:17.004Z", "version": ""}Diagnosed and fixed. I built a faithful reproducer, reproduced the drift, implemented the fix, and verified it end-to-end. Full solution written to ~/published-artifact-version-content-drift.md.
Problem class: a release ships fresh code under a stale identity. The repo declares version X, but the artifact published as X serves OLD content (or an old version string). Everything looks green because every check compares the version number instead of the bytes.
Reference incident: get-h3/sdk-python ticks #307, GAP-061/GAP-068, the 0.1.6 publish.
Three failures stack and hide each other:
pyproject.toml [project].version is used when building, but src/h3_harness_sdk/_version.py hardcodes __version__ = "0.1.5". The repo builds 0.1.6, the module still reports 0.1.5._version.py as truth; the publisher reads pyproject.toml. Each looks self-consistent while disagreeing with the other.0.1.6?" — a wheel that claims 0.1.6 passes even though it was cut from an earlier commit.Fix: one version authority + a divergence test + a release gate that installs the published artifact and asserts a HEAD-only content marker.
# (1) fresh venv + pinned install of the PUBLISHED version -- never the source tree
python3 -m venv /tmp/diag && . /tmp/diag/bin/activate
pip install -q "h3-harness-sdk==0.1.6"
# (2) assert a CONTENT marker that only current HEAD defines
python - <<'PY'
import importlib.metadata as md, h3_harness_sdk as s
print("distribution version:", md.version("h3-harness-sdk"))
print("module __version__ :", s.__version__)
print("has HEAD marker :", hasattr(s, "session_count_marker"))
PY
# (3) probe the live wire for a value the artifact cannot fake
curl -sS https://<host>/v1/health
# (4) compare the two version authorities
grep -rn "__version__" src/h3_harness_sdk/_version.py
grep -n '^version' pyproject.toml
Observed on the reproducer:
distribution version : 0.1.6
module __version__ : 0.1.5 <-- second authority drifted
has HEAD marker : False <-- published 0.1.6 is stale content
wire /v1/health : {"version":"0.1.5","sessions":7}
hasattr on the post-release symbol is the decisive check — it separates fresh from stale at the same version number.
src/h3_harness_sdk/_version.py — delete the literal, read the built metadata:
from importlib.metadata import PackageNotFoundError, version
try:
__version__ = version("h3-harness-sdk")
except PackageNotFoundError: # uninstalled source tree
__version__ = "0.0.0+unknown"
pyproject.toml stays the only human-edited release authority. Repoint docs-version-sweep.py at pyproject.toml [project].version so it can never read a different source.
tests/test_version_authority.py)import pathlib, re, tomllib
import h3_harness_sdk as sdk
ROOT = pathlib.Path(__file__).resolve().parents[1]
def _pyproject_version():
with (ROOT / "pyproject.toml").open("rb") as fh:
return tomllib.load(fh)["project"]["version"]
def test_single_version_authority():
declared = _pyproject_version()
assert sdk.__version__ == declared
def test_no_hardcoded_release_string_in_module():
text = (ROOT / "src/h3_harness_sdk/_version.py").read_text()
hardcoded = [v for _, v in re.findall(r'''__version__\s*=\s*(["'])(.*?)\1''', text)
if not v.startswith("0.0.0")]
assert not hardcoded
def test_content_marker_present():
assert hasattr(sdk, "session_count_marker")
assert sdk.session_count_marker()
scripts/gate_published_artifact.sh)Installs the published wheel pinned to the pyproject version, then asserts the marker and that all version authorities agree:
#!/usr/bin/env bash
set -euo pipefail
INDEX="${1:?usage: gate_published_artifact.sh <index> [package] [marker]}"
PKG="${2:-h3-harness-sdk}"; MARKER="${3:-session_count_marker}"
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
VERSION="$(python3 -c 'import tomllib,sys;print(tomllib.load(open(sys.argv[1],"rb"))["project"]["version"])' "$ROOT/pyproject.toml")"
echo "[gate] release authority (pyproject) = $VERSION"
VENV="$(mktemp -d)/venv"; trap 'rm -rf "$(dirname "$VENV")"' EXIT; python3 -m venv "$VENV"
if [ -d "$INDEX" ]; then
"$VENV/bin/pip" install -q --no-index --find-links "$INDEX" "${PKG}==${VERSION}"
else
"$VENV/bin/pip" install -q --index-url "$INDEX" "${PKG}==${VERSION}"
fi
"$VENV/bin/python" - "$PKG" "$MARKER" "$VERSION" <<'PY'
import sys, importlib
from importlib.metadata import version
pkg, marker, expected = sys.argv[1], sys.argv[2], sys.argv[3]
mod = importlib.import_module(pkg.replace("-", "_"))
assert hasattr(mod, marker), f"artifact lacks content marker {marker!r} (stale build!)"
assert version(pkg) == expected, f"metadata {version(pkg)!r} != {expected!r}"
assert mod.__version__ == expected, f"module {mod.__version__!r} != {expected!r}"
print(f"[gate] OK: {pkg}=={version(pkg)} contains {marker}={getattr(mod, marker)()!r}")
PY
Marker must be a symbol added after the previous release; if the last wheel already has it, it can't distinguish fresh from stale.
curl -sS https://<host>/v1/health \
| python3 -c 'import json,sys; d=json.load(sys.stdin); assert isinstance(d["sessions"], int); print("wire ok", d)'
Also compare d["version"] to the release authority — a live wire still serving 0.1.5 while pyproject.toml says 0.1.6 is the same drift through another door.
Reproducer: built a stale 0.1.6 wheel, moved HEAD forward, then checked the published artifact.
Gate rejects a same-version stale artifact (metadata says 0.1.6, code lacks marker):
[gate] release authority (pyproject) = 0.1.6
AssertionError: artifact lacks content marker 'session_count_marker' (stale build!)
Gate accepts the freshly published artifact:
[gate] OK: h3-harness-sdk==0.1.6 contains session_count_marker='session_inventory_v2'
Divergence test: 3 passed.
Wire after fix: GET /v1/health -> {"status":"ok","version":"0.1.6","sessions":7} (before: "version":"0.1.5").
One-shot regression:
./scripts/gate_published_artifact.sh dist/same-version-stale && echo BAD || echo "good: blocked" # good: blocked
./scripts/gate_published_artifact.sh dist/published && echo "good: passed" # good: passed
python -m pytest tests/ -q # 3 passed
get-h3/sdk-python_version.py with the importlib.metadata version; delete the literal.docs-version-sweep at pyproject.toml [project].version.0.1.6 from the current commit; confirm the gate and /v1/health pass.Invariant for review: every release has exactly one version authority, a divergence test, and an artifact-content gate that installs the published wheel pinned to the fetched version and asserts a HEAD-only marker.
# Evidence - Problem class: published-artifact-version-content-drift - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-21T05:26:17.004Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Diagnosis method for a release that ships fresh code under a stale identity. Symptom: the repo declares version X, the published artifact serves OLD content (or a stale version string). Steps that worked: (1) fresh venv + pinned install of the PUBLISHED version (pip install h3-harness-sdk==X), never the source tree; (2) assert a CONTENT marker that only current HEAD defines (hasattr on a symbol added after the last release) - this is what separates fresh from stale at the same version number; (3) probe the live wire (GET /v1/health) for a value the artifact cannot fake, e.g. an integer session count; (4) THEN grep the source for hardcoded version strings (_version.py) and compare against pyproject [project] version - two independent version authorities drift silently, and the docs-version-sweep gate treats the module as the source of truth while pyproject is the release authority. Fix class: one version authority plus a divergence test; gate the build on artifact CONTENT (install the published wheel pinned to the fetched version and assert the marker), not on the version number alone. Reference: get-h3/sdk-python ticks #307 (GAP-061/GAP-068), 0.1.6 publish.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "published-artifact-version-content-drift", "provider": "openrouter", "solved_at": "2026-09-21T05:26:17.004Z", "version": ""}