Repository navigation
Conversation
Register the native ladder export as optional, validate path arrays, preserve typed errors and allocation ownership, and use the modern single-sign builder lifecycle. Add focused binding tests and isolated stock/candidate native qualification lanes without changing release pins. Co-authored-by: bibinbaby444 <bibinbaby444@gmail.com> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Use c2pa_free for new manifest allocations, include focused ladder tests in existing CI runs, reject optimized verification harness execution, and document the modern builder lifecycle.
|
The initial head checks only completed formatting/ref-resolution work; unit and wheel jobs were skipped by the existing authorization flow, so that run is not CI test qualification. Both aligned candidate PRs are now labeled Local verification is independently complete for the reported scope: final combined CI selection 475 tests plus 44 subtests; 31 focused tests on stock/candidate; fresh-process real-native stock/candidate checks. Cross-platform CI, packaged-wheel, and unpublished-native qualification remain distinct statuses. |
Include a documented synthetic fixture and offline native smoke in the existing CI selection. Enforce candidate capability on request, verify the native signature and shared manifest, and cover typed ctypes conversion without changing stock native pins or builder semantics. Co-authored-by: bibinbaby444 <bibinbaby444@gmail.com>
Aligned Python binding candidate: merge hold
Primary review: mstattma#2. Parallel Castlabs review: #3. Both use
mstattma:feat/single-file-presentation-signingat502b8bb, on frozenintegration/upstream-base-7785f540(Python 0.37.12).Tracking: mstattma/c2pa-rs#13. Native pair: mstattma/c2pa-rs#19 / castlabs/c2pa-rs#13. Bibin's stable binding #2 is now approved at
b13e8a3c; attribution is retained. Issues remain disabled in this repository; this PR owns binding-specific tracking without a repository-setting change.Contract
Optional
Builder.sign_laddersupports bounded ordered UTF-8 paths and an explicit signer. Missing native capability raises typedNotSupportedat call time, not import time. NUL/encoding/list errors are rejected before FFI; copy errors propagate; returned bytes are freed once throughc2pa_free. Modern signing closes the builder after an attempted native call; preflight preserves it and the signer remains caller-owned. This intentionally differs from stable builder reuse.Destinations must be new with existing parents. Failed calls can leave newly created partial outputs; no unconditional cleanup guarantee is made. Native pins, submodule, dependencies, releases and workflow guards are unchanged.
Latest test integration
502b8bbadds a committed 3,812-byte synthetic fixture with generation/hash provenance, typedCFUNCTYPEconversion tests, and an offline native pytest smoke in the file already selected by seven CI commands. The smoke checks the real export signature, shared embedded bytes/active manifests, ReaderValid, source preservation and lifecycle behavior. It signs two copies of one fixture, not different resolution encodes.Stock native lacks the export, so only that smoke skips.
C2PA_REQUIRE_SIGN_LADDER=1makes absence fail; a present export always runs, and missing fixture data always fails. The stronger fresh-process harness remains available with loaded-path/hash checks and rejects optimized Python that would disable assertions.Opus 5.5 reviewed the new additions without fallback. Signature checking and combined candidate execution address the review's main coverage suggestions; no production binding change was needed.
Verification
e7cc30bec2a4e14ba9600198ca82e28c025f6310279eec09c8960ac010d53f09; stockdfa68d2a8ee739bb75919dcb5300f2cb289e1b51ecce94b0f339ff287ebe0703.The published head has no failed/pending checks at inspection. Default CI tests the stock library and therefore skips the new real-native smoke; the unpublished-native lane above was executed separately. Do not interpret that skip as native release qualification. No live TSA/keystore/watermark, full release-stack, or all-filesystem success is claimed.
Do not merge into the frozen base or change release pins before native API acceptance and qualified artifacts. Reconcile the accepted Contentauth implementation across forks later; future upstream-authored content must not link back to fork issues/PRs. No Contentauth artifact or existing published upstream head was changed.