mirror of
https://github.com/harvard-edge/cs249r_book.git
synced 2026-07-20 01:01:30 -05:00
[PR #1523] [MERGED] ci(mlsysim): harden PyPI publish — matrix tests, post-publish verify, attestations #9189
Closed
opened 2026-05-03 01:25:54 -05:00 by GiteaMirror
·
0 comments
No Branch/Tag Specified
dev
audit/mlperf-edu-readiness
feat/mlperf-edu-precondition
gh-pages
vol1/all-final
main
vol1/appendices-final
vol1/ch16-final
vol1/ch15-final
vol1/ch14-final
vol1/ch13-final
vol1/ch11-final
vol1/ch12-final
vol1/ch10-final
vol1/ch9-final
vol1/ch8-final
vol1/ch7-final
vol1/ch6-final
vol1/ch5-final
vol1/ch4-final
vol1/ch3-final
vol1/ch2-final
vol1/frontmater-final
kai/fixing-profile-setting-and-map
chore/staffml-ci-path
fix/callout-flow
vol1/ch10-pass4
vol1/ch9-pass4
vol1/ch8-pass4
vol1/ch7-pass4
vol1/ch6-pass4
vol1/ch5-pass4
vol1/apC-pass3
vol1/ch4-pass4
vol1/ch3-pass4
vol1/ch2-pass4
vol1/ch1-pass4
vol1/frontmatter
vol1/apE-pass3
vol1/apD-pass3
fmt-fix
vol1/ch14-pass3
kai/clarify-community-map-totals
vol1/ch13-pass3
vol1/ch12-pass3
vol1/ch11-pass3
vol1/ch10-pass3
vol1/ch7-pass3
vol1/ch9-pass3
vol1/ch8-pass3
vol1/ch6-pass3
vol1/ch5-pass3
vol1/ch4-pass3
vol1/ch3-pass3
vol1/ch2-pass3
vol1/ch1-pass3
vol1/ch6-pass2
vol1/ch5-pass2
vol1/ch4-pass2
vol1/ch3-pass2
vol1/ch2-pass2
fix/badge-fixes
chore/precommit-cleanup
cleanup/book-validate-paths
fix/staffml-trigger-on-workflow-edits
fix/staffml-reusable-concurrency
feat/container-preflight-urls
instructors-v0.1.1
vol1-pr1957-merged
vol2-v0.2.1
vol1-v0.7.1
vol1-v0.7.0+vol2-v0.2.0
slides-v0.1.0
vol2-v0.2.0
vol1-v0.7.0
tinytorch-v0.1.13
mlsysim-v0.2.0
vol2-v0.1.2
vol1-v0.6.2
tinytorch-v0.1.12
vol2-v0.1.1
vol1-v0.6.1
mlsysim-v0.1.3
vol2-v0.1.0
vol1-v0.6.0
mlsysim-v0.1.2
staffml-v0.1.1
tinytorch-v0.1.11
labs-v0.1.0
kits-v0.1.0
slides-latest
instructors-v0.1.0
staffml-v0.1.0
mlsysim-v0.1.1
mlsysim-v0.1.0
tinytorch-v0.1.10
build-verified-windows-v1
tinytorch-v0.1.9
tinytorch-v0.1.8
mit-submission-v1
tinytorch-v0.1.7
tinytorch-v0.1.6
tinytorch-v0.1.5
tinytorch-slides-v0.1.0
tinytorch-v0.1.3
tinytorch-v0.1.4
tinytorch-v0.1.2
tinytorch-v0.1.1
tinytorch-v0.1.0
book-v0.5.1
tinytorch-audio-v0.1.1
tinytorch-audio-assets-v0.1
book-v0.5.0
book-v0.4.2
book-v0.4.1
book-v0.4.0
book-v0.3.0
book-v0.2.0
book-v0.1.0
Labels
Clear labels
area: book
area: collabs
area: kits
area: labs
area: socratiq
area: staffml
area: tinytorch
area: tools
area: website
bug
dependencies
format: epub
format: pdf
javascript
link-health
link-rot
priority-high
pull-request
staffml
type: bug
type: citation
type: code
type: errata
type: improvement
type: new
type: question
vault-sli
Mirrored from GitHub Pull Request
No labels
pull-request
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/cs249r_book#9189
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
📋 Pull Request Information
Original PR: https://github.com/harvard-edge/cs249r_book/pull/1523
Author: @profvjreddi
Created: 4/24/2026
Status: ✅ Merged
Merged: 4/24/2026
Merged by: @profvjreddi
Base:
dev← Head:feat/mlsysim-pypi-hardening📝 Commits (1)
ac54472ci(mlsysim): harden PyPI workflow — matrix tests, post-publish verify, attestations📊 Changes
2 files changed (+102 additions, -18 deletions)
View changed files
📝
.github/workflows/mlsysim-pypi-publish.yml(+92 -14)📝
mlsysim/RELEASE.md(+10 -4)📄 Description
Summary
Three small, high-value additions to the mlsysim PyPI publish pipeline. No user-facing behavior change; the release-engineer-facing behavior becomes stricter and safer.
What changes
1. Python version matrix on the `test` stage
Tests now run in parallel on Python 3.10, 3.11, 3.12, and 3.13 — every version claimed in `pyproject.toml` classifiers. Catches "works on my Python, breaks on theirs" bugs before the wheel ships. Zero wall-clock cost (parallel fan-out); four jobs finish in ~the same time as the old single job.
`fail-fast: false` so one failing version doesn't mask the others — we see all failures at once.
2. New `verify-pypi` job (post-publish smoke)
Runs after `publish-pypi`. The existing pre-publish tests validate the local wheel; this one validates the remote wheel that PyPI is actually serving to users:
Closes the narrow-but-real failure class between "upload accepted" and "user `pip install` works": CDN issues, metadata rendering, platform tags.
3. Explicit `attestations: true` on the upload
`pypa/gh-action-pypi-publish` generates PEP 740 attestations by default with OIDC, but setting it explicitly makes the intent obvious and future-proofs against default changes. Records cryptographic provenance ("this wheel was built by this exact workflow run from this exact commit"), viewable on the PyPI project page.
Pipeline stages, before and after
Before (6 stages):
After (7 stages):
Test plan
Risk
Low. Workflow-only change; does not touch package code or user-facing metadata. Failure mode of the new `verify-pypi` job is "fails loud, release is still on PyPI" — the release succeeds, verification notices a problem. This is strictly additive visibility.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.