Skip to content

chore(release): 0.9.2 - #924

Merged
HuiJun merged 29 commits into
mainfrom
release/0.9.2
Oct 5, 2026
Merged

HuiJun merged 29 commits into
mainfrom
release/0.9.2

Conversation

@devin-ai-integration

@devin-ai-integration devin-ai-integration Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

What and why

Release 0.9.2, cut from main (v0.9.1 plus the Windows-MSI hotfixes #752/#753) by cherry-picking the merges from develop that #908 asks for, together with the Python-client fixes and enhancements since v0.9.1. Closes #908.

From #908 — API JSON and Convert fixes:

Python client:

Further fixes from develop that belong in a patch release (standalone, no feature coupling):

Fixed on the branch (both bugs exist on develop too; the hunks are self-contained so a main → develop back-merge carries them, otherwise they want a follow-up PR against develop):

  • initialEndsAgree (internal/translate/export/behavior.go) accepted a succession whose connector end has no ReferenceSubsetting/sysml:references target, so first a then b could be reconstructed from the source/target feature alone; it now refuses with an UnsupportedError. Regression test TestFirstThenWithAnUntargetedEndIsRefused.
  • The metamodel reader's _convert (client/python/opensysml/metamodel/_runtime.py) followed an @id reference on a property whose range is a primitive or an enumeration and returned the referenced element where a str/bool/enum was declared; it now raises MalformedValue. Regression tests in test_metamodel_reader.py.

SonarCloud scrub of the findings that develop's inventory places in code this release carries (the release branch itself is not scanned — the scan runs in CircleCI on main/develop only): cognitive complexity in tools/gen/pymetamodel/main.go (helpers index, computeEffective, c3Merge, …) and in binary.py (_cached_binary, _unavailable_details), duplicated literals in tools/gen/ontology/main.go and pin_release_checksums.py, seven pytest.raises blocks narrowed to one raising statement. Two triaged in sonar-project.properties with rationale: the generated metamodel/_generated.py joins the generated-code exclusions, and python:S8495 on binary.py (one candidate tag for a stable release, two spellings for a prerelease — deliberate). The Makefile also gained the ontology-table-check/python-metamodel-check recipes CI calls, which the cherry-picks had left behind.

Performance record: docs/project/performance-release-0.9.2-vs-0.9.1.md — every benchmark package on both revisions (six counts each, benchstat), rows left in doubt re-run interleaved, and whole-binary wall time/RSS on the generated, example and Apollo 11 models. Parity: no row regresses once interleaved; the model loader allocates +0.4–0.7% bytes per element; the binary is 128 KiB larger.

Release mechanics, per docs/project/releasing.md: VERSION = "0.9.2", @openmbee/opensysml and its five platform packages, the Java poms, editors/cameo/editors/syson/editors/vscode, and the Rust crate all at 0.9.2 with lockfiles regenerated; the 26 changelog fragments folded into the 0.9.2 — 2026-10-05 entry.

Not included, and why: develop features that only touch the Python surface in passing (#768 migrate, #773 explore, #777 unbounded ints, #906 ExecuteState trace); the spec-tightening rules (#750, #771, #817, #818, #868, #891, #897, #898), each of which makes previously accepted models error; the runtime fixes that sit on explore (#776, #784, #808, #811, #826, #831, #852, #864); #769 (migrator HTML cross-references, +1856 lines of new machinery and a stdlib-snapshot change); the Rust/Java/Julia/Node/MATLAB client hardening (#778, #779, #780, #785, #786), which conflicts throughout because it sits on client work absent from 0.9.1; and #810, whose JSON-RPC and Java fixes target code (internal/frontend/jsonrpc, the Connection.checked path) this release does not have — Sonar's analyzer reports no S2095 on the release's Connection.java.

How it was verified

After the added fixes: gofmt -l ., go build ./..., go vet ./..., make lint, go test -count=1 ./..., the corpus gates with all four corpora required (OPENSYSML_REQUIRE_TRAINING_CORPUS, _PILOT_CORPORA, _PSSM_SUITE, _PILOT_LIBRARY_XMI) over tests/corpus, tests/identity, tests/export and internal/translate/export, the pilot-differential provenance test in tools, make ontology-table-check python-metamodel-check, pytest client/python/tests/ (1317 passed, 123 skipped), scripts/check-doc-links.py, scripts/check-doc-ids.py, mkdocs build --strict.

Before them, on the first revision: On the branch: gofmt -l ., go build ./..., go vet ./..., make lint, go test -race -count=1 ./... (internal/exec/runtime and tests/model re-run with -timeout 40m, as CI's 30m budget allows; both pass), go test ./tests/corpus -run 'TestTrainingExamples|TestPilotCorpora|TestCorpusGates', make ontology-table-check python-metamodel-check, pytest client/python/tests/ against a make build-grpc service (1317 passed, 123 skipped after the reader fix), mypy on the client, cargo check --tests in client/rust, check_version.py --tag v0.9.2 --editors, scripts/check-doc-links.py (0 broken), mkdocs build --strict. Python release packaging rehearsed with the exact CircleCI build-python-package step bodies: the wheel pins the five service digests, an installed wheel downloads and verifies its own release without sigstore, tampered and unpinned downloads are refused.

After merge: wait for the main SonarCloud scan's quality gate, then tag v0.9.2 on main, then merge main back into develop. Note that CircleCI has run no pipeline on main since 2026-09-17 (the v0.9.1 merge did not start one; tag pipelines do run), so the main scan needs the project's branch-build setting changed or a pipeline triggered by hand.

Checklist

  • make test and make lint pass locally
  • Tests added or updated for the change
  • Documentation extended where it already covers the surface (see CONTRIBUTING.md)
  • Changelog entry added as changes/unreleased/<slug>.<section>.md, not as an edit to CHANGELOG.md — release branch: fragments folded with scripts/changelog.py release 0.9.2
  • baselines regenerated and make docs-counts run if a gate count moved (compliance rows need nothing: the census is counted at docs build)
  • No internal work-item labels (waves, slices, F4, K5) in the body, docs, or changelog

Link to Devin session: https://nasa-jpl-demo.devinenterprise.com/sessions/46106c5b519c430188ace045438d71b0
Open in Devin Desktop: https://nasa-jpl-demo.devinenterprise.com/desktop/session/46106c5b519c430188ace045438d71b0?variant=devin
Requested by: @HuiJun

HuiJun and others added 17 commits October 5, 2026 01:04
feat(export): name the standard library elements a converted model references (#731)
feat(grpc): Convert takes the id form, as sysml -id does (#732)
* fix(grpc): report the parser's warnings as the workspace does

ParseFile and ParseSources handed the analysis passes an empty parse-diagnostic list and never read parser.Parser.Warnings, so a reserved keyword written as a name loaded with no diagnostic where sysml -validate reports the reserved-keyword-name error, and strict conformance never escalated a parser nonstandard-notation warning.

parser.AsDiagnostics is the one conversion of a parse's errors and warnings to pass diagnostics; the workspace, the REPL, the gRPC service and the edit validator all use it. The service reports each document's diagnostics once, through the passes, instead of the raw parse errors beside them.

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* test(conformance): quote the reserved keyword the verification fixture uses as a name

The fixture named a part 'analysis' bare, which the service now reports as the reserved-keyword-name error the command line always reported, so every scenario over it errored.

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* test(grpc): quote the reserved keyword the symbol_attributes fixture uses as a name

Co-Authored-By: jason.han <hanhuijun@gmail.com>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: jason.han <hanhuijun@gmail.com>
feat(query): report the elementId Convert writes (#733)
fix(export): first a then b owns its connector ends (#760)
…aint-refs

fix(export): a bare assume, require or assert names its constraint by reference (#760)
…g-uniqueness

fix(check): conformance of an implicit subsetting (#726)
* fix(query): report each scoped element's own elementId (#793)

ElementIDs recorded the ids a conversion writes by qualified name, so of two
elements one name in two identity scopes declares, a query reported the id
written last for both. Record them by declaration node too, as each encoder
wrote them, and look a symbol's id up by its declaration first.

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* chore(ci): re-run checks after the static job timed out

Co-Authored-By: jason.han <hanhuijun@gmail.com>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: jason.han <hanhuijun@gmail.com>
fix(export): a transition owns its source member and parameters; chained ends stay chains (#803)
* fix(clients): download the release a client was built against when none is named

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(clients): clarify built-against release fallbacks

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(clients): separate implicit binary release from service requirements

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(clients): isolate fallback test cache and format Rust

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(rust): satisfy clippy in binary resolution

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(python): resolve built-against prerelease tags

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(python): retry unpinned prerelease candidates

Co-Authored-By: jason.han <hanhuijun@gmail.com>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: jason.han <hanhuijun@gmail.com>
* feat(rust): stamp each release's service digests into the published crate

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* ci(rust): install python3 for the crate digest stamp when the image lacks it

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(release): sync client digest copies when stamping the shared table

Co-Authored-By: jason.han <hanhuijun@gmail.com>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: jason.han <hanhuijun@gmail.com>
…stamp

* feat(python): stamp the release's sysml-grpc digests into the wheel

The committed release-digests.json pins only the releases that existed when
it was last back-filled, and the wheel for a tag was built before that tag's
service binaries, so every released opensysml had to verify its own release
through the signed manifest and the sigstore package at run time.

The release workflow now builds the binaries first (build-release-binaries),
and build-python-package hashes them with
pin_release_checksums.py --from-binaries dist/grpc into the table copy the
wheel and sdist package before python -m build, then fails unless both pin
all five assets for the tag. build-release assembles the release from the
two workspaces, writes SHA256SUMS.txt over the final distribution, fails
unless the wheel's pins are the manifest's service digests, and signs it as
before. Published bytes are the bytes those jobs verified.

A download refused because sigstore cannot be imported now raises
SigstoreUnavailableError naming the package, the install command, and that
this arises only for another release or an older client; the binary is
still never downloaded unverified.

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(release): persist only build-release's own files and name the missing verifier module

build-release attached build-release-binaries' dist/ layer and persisted the whole tree again. Workspace layers are additive and a path persisted by two upstream jobs fails the attach in every job downstream of both, which is every publish job; build-release now persists only the manifest, its signature and provenance bundles, the .sha256 sidecars and the Python distribution. A hygiene test holds the config to disjoint layers.

_load_sigstore reported "the sigstore package is not installed" for any ImportError, including one from cryptography, which _Sigstore imports first. The refusal now names the module that failed to import, as sigstore or a package sigstore depends on, with the same install command.

Co-Authored-By: jason.han <hanhuijun@gmail.com>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: jason.han <hanhuijun@gmail.com>
* feat(ontology): generate the metamodel table from the pilot's SysML.ecore (20250201)

Read the pinned pilot implementation's SysML.ecore instead of the 202407 OWL rendering, record each property's ordering, derivation, redefinitions, subsettings and opposite and each class's abstractness, and fail CI when the table drifts from the pin. Write nonunique as isUnique false and own the flow, payload, end, terminate and instantiation metaclasses through a FeatureMembership, still reading graphs earlier releases wrote.

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(ontology): check a multiply-typed subject as its most specific rdf:type

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* feat(ontology): record the metamodel's enumerations and their literals

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* feat(python): generate metaclass classes and read metamodel JSON

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(ontology): treat an upper bound above one as multi-valued

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(python): refine metamodel reader contracts

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* docs(python): add a metamodel classes and JSON guide page

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(python): fix API docs and CI type checking

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* ci(python): install protobuf stubs for the metamodel type check

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(python): validate reference ranges and unwrap standalone envelopes

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* feat(python): let read_json skip the reference range check

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(ontology): treat an ecore upper bound above one as multi-valued

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(ontology): read ecore upper bounds as EMF does, -2 unspecified included

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* style(ontology): preserve generator test spacing

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(ontology): keep the upstream upper-bound rule after merging

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(build): restore the build-release-wasm recipe lost in a merge

Co-Authored-By: jason.han <hanhuijun@gmail.com>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: jason.han <hanhuijun@gmail.com>
…uide in DEVELOPING.md

The README PyPI renders as the opensysml project description was the full
developer document, with paragraphs that ran for forty lines. Keep the
install, quickstart and documentation links in README.md, and move the
complete walkthrough to DEVELOPING.md, where the comments and guides that
cited it now point.

Co-Authored-By: jason.han <hanhuijun@gmail.com>
Co-Authored-By: jason.han <hanhuijun@gmail.com>
Fold the changelog fragments into the 0.9.2 entry and set every version
surface — opensysml, @openmbee/opensysml and its platform packages, the
Java client and the editors — to 0.9.2 in lockstep with the core.

Co-Authored-By: jason.han <hanhuijun@gmail.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@devin-ai-integration
devin-ai-integration Bot changed the base branch from develop to main October 5, 2026 01:35
…amodel Make targets

Split the pymetamodel generator's generate, newModel and linearize into
focused helpers and factor the cached-binary decision out of
_ensure_binary_locked, so each stays under the cognitive-complexity
threshold without changing generated output or download behavior. Name
the repeated Ecore classifier kinds and the .sha256 sidecar suffix once.
Give each exception test a single raising call.

Exclude the generated Python metaclasses from analysis like the other
generated code, and record why built_against_releases returns one or
two candidate tags.

The release Makefile listed ontology-table(-check) and
python-metamodel(-check) as phony targets but lost their recipes, so
CI's make calls were silently no-ops; restore them from develop.

Co-Authored-By: jason.han <hanhuijun@gmail.com>
@HuiJun
HuiJun marked this pull request as ready for review October 5, 2026 02:28
devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration Bot and others added 6 commits October 5, 2026 02:35
…ce where a scalar is declared

initialEndsAgree skipped a connector end with no ReferenceSubsetting or
sysml:references target, so writing `first a then b` from the
succession's sourceFeature/targetFeature invented the end's target on
the way back. Refuse it as standardEndText does.

The metamodel reader's _convert followed any @id object, so a primitive
or enumeration property holding a reference returned the referenced
element instead of raising MalformedValue. Reject reference objects for
scalar ranges before resolving them.

Co-Authored-By: jason.han <hanhuijun@gmail.com>
Every benchmark package on both revisions (six counts each, benchstat),
the rows left in doubt re-run interleaved, and whole-binary wall time and
RSS on the generated, example and Apollo 11 models. Parity: no row
regresses once interleaved, the model loader allocates +0.4-0.7% bytes
per element, the binary is 128 KiB larger.

Co-Authored-By: jason.han <hanhuijun@gmail.com>
* fix(quantity): absorb MeasurementReferences::one as the identity of the unit product

A factor written in the library's dimensionless unit survived as a named
power of the composed unit product, so 800 [W] * 120 [s] * 0.7 [one] spelt
[SI::'kg⋅m²⋅s⁻²'*one] and never folded to SI::J. normalizeProduct now
absorbs the identity: it leaves any product it shares with another unit
and any power of it alone is itself. The identity is recognised by
structure (Model.IsIdentityUnit): a unit of DimensionOneUnit itself, of no
specialization such as AngularMeasureUnit, reducing to scale one — so rad,
sr and a percent scaling one by convention stay in the product.

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* docs(skills): record how to test the dimension-one identity end to end

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(quantity): keep the absorbed identity for when the rest of the product cancels

An identity power (one) a product absorbs is remembered on UnitProduct.Identity
and is the unit again once every other power cancels, by symbol or by
reduction, so grouping does not change the result: (2 [one] * 3 [m]) / 3 [m] and
2 [one] * (3 [m] / 3 [m]) are both 2.0 [one]. Two identity declarations (one,
unity : DimensionOneUnit = one) are the same unit to normalisation, so
one * unity and unity * one agree and their measurement references compare equal.

Co-Authored-By: jason.han <hanhuijun@gmail.com>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: jason.han <hanhuijun@gmail.com>
(cherry picked from commit bf0df66)
* fix(migrate): write an initial into an orthogonal region as that region's entry

A SysML v1 initial pseudostate whose transition enters a sibling orthogonal
region was refused and its own region written with no entry, so the runtime
stopped the machine at initialization. The entry is now settled per machine
before any region is written, and the writer, the owner's default-entry note
and the ledger read that one plan: a region's own initial is the one entering
it; a stray initial is written as the entry of the region owning its target,
coincides with that region's own entry into the same vertex, or is refused
when it conflicts with one into another.

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(migrate): donate initials only across orthogonal regions, and past a transition-less initial

An initial whose transition enters a region of another, non-orthogonal state
is refused instead of being written as that region's entry. An initial
pseudostate no transition leaves is no entry, so a stray initial of an
orthogonal region may enter its region, and the owner's default entry is
gated on written entries only.

Co-Authored-By: jason.han <hanhuijun@gmail.com>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: jason.han <hanhuijun@gmail.com>
(cherry picked from commit a29c3e0)
* fix(examples): drop nonunique from the messages demo's channel messages

A message in a part implicitly subsets the unique Parts::Part::ownedActions,
so the two channel messages cannot be nonunique. The example validates clean,
leaves the known-failure list (which held only it), and the pilot-differential
baseline re-records the examples digest.

Fixes #758

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(migrate): write no nonunique where the v2 usage must be unique

A v1 property with isUnique=false, or a MagicDraw [] / [n] type modifier,
that becomes a usage implicitly subsetting a unique library feature, or that
redefines or subsets a feature written unique, is written without nonunique;
the report notes the dropped modifier and marks the entry approximated.

The decision reuses the checker's implicit-subsetting rules: semantics now
exposes ImplicitSubsettingCandidates over declaration kinds alone, and the
migrator reads the candidates' uniqueness from the bundled library.

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* fix(migrate): judge a repeated slot value by the feature's written uniqueness

slotConflict read the v1 isUnique flag, so a repeated instance in a slot of a
nonunique composite property passed although the part is now written unique.
It asks featureWrittenUnique instead, which also admits a repeat on a feature
an array type modifier writes nonunique.

Co-Authored-By: jason.han <hanhuijun@gmail.com>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: jason.han <hanhuijun@gmail.com>
(cherry picked from commit 341aa21)
* fix(repl): exit on Ctrl-C at an empty prompt, discard the continuation otherwise

Co-Authored-By: jason.han <hanhuijun@gmail.com>

* ci: give the static and integrity job 30 minutes

make lint alone takes about 12 of its 20 minutes, so the job was cancelled
before its last corpus gates ran.

Co-Authored-By: jason.han <hanhuijun@gmail.com>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: jason.han <hanhuijun@gmail.com>
(cherry picked from commit c5bff06)
devin-ai-integration Bot and others added 5 commits October 5, 2026 04:45
Co-Authored-By: jason.han <hanhuijun@gmail.com>
(cherry picked from commit addc9f8)
Co-Authored-By: jason.han <hanhuijun@gmail.com>
(cherry picked from commit 7076103)
Co-Authored-By: jason.han <hanhuijun@gmail.com>
(cherry picked from commit 9bef894)
Co-Authored-By: jason.han <hanhuijun@gmail.com>
(cherry picked from commit afaf845)
Co-Authored-By: jason.han <hanhuijun@gmail.com>
@HuiJun
HuiJun merged commit 0a55514 into main Oct 5, 2026
23 checks passed
@HuiJun
HuiJun deleted the release/0.9.2 branch October 5, 2026 10:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Release request: a new tag and npm update carrying the API JSON and Convert fixes merged since v0.9.1

1 participant