Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
35 commits
Select commit Hold shift + click to select a range
cf3f5fb
chore: Update c2pa version to v0.90.16 (#316)
tmathern Aug 27, 2026
4d909cf
Drop wheel, setuptools and pytest from runtime dependencies (#320)
fwittreverce Sep 4, 2026
63d09c6
chore: Update c2pa version from v0.90.16 to v0.90.19 (#322)
tmathern Sep 4, 2026
7ca863d
feat: scaffold trusted VSI API
mstattma Sep 9, 2026
0d48e6a
refactor: reduce trusted VSI expert bindings
mstattma Sep 10, 2026
c27d51e
chore: Update C2PA version to 0.90.22 (#324)
tmathern Sep 14, 2026
05dbc97
Merge pull request #326 from contentauth/chore/rc-preflight-tooling
scouten-adobe Sep 17, 2026
f9ea2b2
Make test_sdk_version aware of the RC-preflight ref file (#327)
scouten-adobe Sep 17, 2026
4821daf
Fix test_sdk_version regression: gate on an env var, not file presenc…
scouten-adobe Sep 17, 2026
352e268
chore: bump c2pa-rs to v0.91.0 (#325)
scouten-adobe Sep 23, 2026
eafb98d
fix: Make memory benchmark run again (#331)
tmathern Sep 24, 2026
7785f54
chore: Bump version from 0.37.11 to 0.37.12 (#332)
tmathern Sep 24, 2026
ca7ea1a
feat: sign single-file rendition ladders with one manifest
mstattma Sep 25, 2026
6e54a5e
test: qualify ladder ownership in CI and native verification lanes
mstattma Sep 25, 2026
780e78f
feat: bind functional trusted VSI sessions
mstattma Sep 28, 2026
502b8bb
test: exercise ladder marshalling and native signing in pytest
mstattma Sep 28, 2026
7b17b36
fix(ci): accept setuptools sdist naming in functional build test
mstattma Sep 28, 2026
9f13fae
fix(ci): run release workflow shell helpers with Git bash on Windows
mstattma Sep 28, 2026
364a17e
ci: pin paired trusted VSI native to 3569fb86
mstattma Sep 29, 2026
32cc0ce
Merge commit '502b8bb2' into trial/python-presentation-signing-consol…
mstattma Sep 30, 2026
f48fbcc
fix: pair trusted VSI gate with exact consolidated native 0.92.0-dev
mstattma Sep 30, 2026
0047425
fix: propagate ladder callback errors and guard fragmented output cle…
mstattma Sep 30, 2026
c3085bd
fix: triage consume-first FFI rejections by the rejected handle id
mstattma Sep 30, 2026
f4f7dac
fix: declare C2paStream as the opaque native handle it is
mstattma Sep 30, 2026
4568ecd
chore: pair functional qualification with consolidated native 5c186c0…
mstattma Sep 30, 2026
941c2ad
fix: address review of consolidated Python deltas
mstattma Sep 30, 2026
8fbaf21
docs: record consolidated trusted VSI Python qualification
mstattma Sep 30, 2026
7ba8615
fix: preserve native ownership across consume-first failures
mstattma Sep 30, 2026
b3cc936
merge: native ownership hardening (7ba8615) and repin paired native t…
mstattma Sep 30, 2026
7058a8a
test: fail opaque ownership checks under paired qualification instead…
mstattma Sep 30, 2026
a303db8
test: clarify ownership cleanup and cover native pointer values
mstattma Sep 30, 2026
abef446
Merge commit 'a303db8dfcdd9bc493497d098bb6f0ce9249c7ed' into trial/py…
mstattma Sep 30, 2026
bc9e99d
docs: track remaining native ownership qualification follow-ups
mstattma Sep 30, 2026
5c64f2c
docs: scope stock Windows ARM64 ownership gap to this qualification
mstattma Sep 30, 2026
12d265d
ci: pair trusted VSI qualification with native 6b506352
mstattma Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 22 additions & 5 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,17 @@ permissions:
actions: read

jobs:
trusted-vsi-paired:
name: Trusted VSI paired-source API (not release artifacts)
if: |
!startsWith(github.ref, 'refs/tags/castlabs-v') &&
(github.event_name != 'pull_request' ||
github.event.pull_request.author_association == 'COLLABORATOR' ||
github.event.pull_request.author_association == 'MEMBER' ||
github.event.pull_request.user.login == 'dependabot[bot]' ||
contains(github.event.pull_request.labels.*.name, 'safe to test'))
uses: ./.github/workflows/trusted-vsi-paired.yml

read-version:
name: Read C2PA version
if: ${{ !startsWith(github.ref, 'refs/tags/castlabs-v') }}
Expand Down Expand Up @@ -144,7 +155,10 @@ jobs:
python3 -c "from c2pa import C2paError; print('C2paError imported successfully')"

- name: Run tests
run: python3 ./tests/test_unit_tests.py
run: python3 -m pytest tests/test_unit_tests.py tests/test_sign_ladder.py

- name: Test disabled trusted API against upstream native (not ABI qualification)
run: python3 -m pytest -q tests/test_trusted_vsi_api.py -k "not paired"

tests-windows:
name: Unit tests for developer setup (Windows)
Expand Down Expand Up @@ -230,7 +244,10 @@ jobs:
python -c "from c2pa import C2paError; print('C2paError imported successfully')"

- name: Run tests
run: python .\tests\test_unit_tests.py
run: python -m pytest .\tests\test_unit_tests.py .\tests\test_sign_ladder.py

- name: Test disabled trusted API against upstream native (not ABI qualification)
run: python -m pytest -q tests/test_trusted_vsi_api.py -k "not paired"

build-linux-wheel:
name: Build Linux wheel
Expand Down Expand Up @@ -315,7 +332,7 @@ jobs:
- name: Run tests with pytest (venv)
run: |
source venv/bin/activate
venv/bin/pytest tests/test_unit_tests.py -v
venv/bin/pytest tests/test_unit_tests.py tests/test_sign_ladder.py -v

build-windows-wheel:
name: Build Windows wheel
Expand Down Expand Up @@ -407,7 +424,7 @@ jobs:
- name: Run tests with pytest (venv)
run: |
.\venv\Scripts\activate
.\venv\Scripts\pytest .\tests\test_unit_tests.py -v
.\venv\Scripts\pytest .\tests\test_unit_tests.py .\tests\test_sign_ladder.py -v

build-macos-wheel:
name: Build macOS wheels
Expand Down Expand Up @@ -496,7 +513,7 @@ jobs:
- name: Run tests with pytest (venv)
run: |
source venv/bin/activate
venv/bin/pytest tests/test_unit_tests.py -v
venv/bin/pytest tests/test_unit_tests.py tests/test_sign_ladder.py -v

sdist:
runs-on: ubuntu-latest
Expand Down
14 changes: 13 additions & 1 deletion .github/workflows/castlabs-vsi-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,9 +7,14 @@ on:
workflow_dispatch:
inputs:
source_sha:
description: Full feat/live-video-vsi branch-tip SHA to release
description: Full Python SHA (feat/live-video-vsi tip for dev5; paired source for trusted_vsi_only)
required: true
type: string
trusted_vsi_only:
description: Only non-publishing paired-source trusted API tests; bypass all dev5 jobs
required: false
type: boolean
default: false

concurrency:
group: castlabs-vsi-release-0.37.8.dev5
Expand All @@ -24,7 +29,14 @@ env:
PYTHONHASHSEED: "0"

jobs:
trusted-vsi-paired:
if: github.event_name == 'workflow_dispatch' && inputs.trusted_vsi_only
uses: ./.github/workflows/trusted-vsi-paired.yml
with:
python-ref: ${{ inputs.source_sha }}

prepare:
if: ${{ !inputs.trusted_vsi_only }}
runs-on: ubuntu-24.04
timeout-minutes: 20
outputs:
Expand Down
208 changes: 208 additions & 0 deletions .github/workflows/test-c2pa-rs-source-build.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,208 @@
name: Test against c2pa-rs built from source

# Validates c2pa-python against a c2pa-rs git ref that has no published
# release artifacts (e.g. a release candidate tag), by building the native
# library from source instead of downloading a prebuilt one.
#
# This is the reusable tool for RC preflights: commit the target ref to
# c2pa-rs-preflight-ref.txt on a PR branch. Its mere presence is what opts
# the PR in, so this reruns automatically on every push to that PR -- same
# as any other check -- instead of you having to remember to re-dispatch by
# hand while iterating on fixes. Delete the file again once the PR is done
# with the RC (or once c2pa-rs ships a real release and you bump
# c2pa-native-version.txt through the normal process instead).
#
# Deliberately no workflow_dispatch trigger here: dispatching this workflow
# against the default branch would run in a context with write access to
# the default branch's Actions cache scope, while checking out and
# executing an arbitrary, unvalidated c2pa-rs ref -- exactly the cache
# poisoning pattern CodeQL's actions/cache-poisoning/poisonable-step query
# looks for. A same-repo pull_request only ever gets write access to its
# own branch's cache scope, so that path doesn't have the same exposure.

on:
pull_request:
types:
- opened
- reopened
- synchronize
- labeled

permissions:
contents: read

jobs:
resolve-ref:
name: Resolve c2pa-rs ref to test
runs-on: ubuntu-latest
outputs:
ref: ${{ steps.resolve.outputs.ref }}
steps:
- uses: actions/checkout@v4
- name: Resolve ref
id: resolve
run: |
if [ -f c2pa-rs-preflight-ref.txt ]; then
ref="$(tr -d '\r\n' < c2pa-rs-preflight-ref.txt)"
else
ref=""
fi
echo "ref=$ref" >> "$GITHUB_OUTPUT"
if [ -z "$ref" ]; then
echo "No c2pa-rs-preflight-ref.txt in this tree -- nothing to test, downstream jobs will skip."
else
echo "Testing against c2pa-rs ref: $ref"
fi

tests-unix:
name: Unit tests (Unix, ${{ matrix.os }})
needs: resolve-ref
if: |
needs.resolve-ref.outputs.ref != '' && (
github.event_name != 'pull_request' ||
github.event.pull_request.author_association == 'COLLABORATOR' ||
github.event.pull_request.author_association == 'MEMBER' ||
github.event.pull_request.user.login == 'dependabot[bot]' ||
contains(github.event.pull_request.labels.*.name, 'safe to test')
)

runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ macos-latest, ubuntu-latest, ubuntu-24.04-arm ]

steps:
- name: Checkout c2pa-python
uses: actions/checkout@v4
with:
path: c2pa-python

- name: Checkout c2pa-rs (${{ needs.resolve-ref.outputs.ref }})
uses: actions/checkout@v4
with:
repository: contentauth/c2pa-rs
ref: ${{ needs.resolve-ref.outputs.ref }}
path: c2pa-rs

- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.10"
# No pip cache here: this job checks out and builds an arbitrary,
# not-necessarily-reviewed c2pa-rs ref, and CodeQL flags caching in
# that context as a cache-poisoning vector into the default branch.

- name: Install project dependencies
working-directory: c2pa-python
run: |
python -m pip install -r requirements.txt
python -m pip install -r requirements-dev.txt

- name: Build native library from c2pa-rs source
working-directory: c2pa-python
env:
C2PA_RS_PATH: ${{ github.workspace }}/c2pa-rs
# Build for the runner's own arch rather than the universal2 macOS
# default: it's what a local `pip install -e .` picks up anyway,
# and skips the slow cross-compiled second-arch OpenSSL build.
C2PA_LIBS_PLATFORM: ${{ matrix.os == 'macos-latest' && 'aarch64-apple-darwin' || (matrix.os == 'ubuntu-24.04-arm' && 'aarch64-unknown-linux-gnu' || 'x86_64-unknown-linux-gnu') }}
run: python scripts/build_local_artifacts.py --clean

- name: Install package in development mode
working-directory: c2pa-python
run: |
pip uninstall -y c2pa
pip install -e .

- name: Verify installation
working-directory: c2pa-python
run: python -c "from c2pa import C2paError; print('C2paError imported successfully')"

- name: Run tests
working-directory: c2pa-python
env:
C2PA_PREFLIGHT_RUN: "1"
run: python -m pytest tests/test_unit_tests.py tests/test_sign_ladder.py

tests-windows:
name: Unit tests (Windows, ${{ matrix.runs-on }})
needs: resolve-ref
if: |
needs.resolve-ref.outputs.ref != '' && (
github.event_name != 'pull_request' ||
github.event.pull_request.author_association == 'COLLABORATOR' ||
github.event.pull_request.author_association == 'MEMBER' ||
github.event.pull_request.user.login == 'dependabot[bot]' ||
contains(github.event.pull_request.labels.*.name, 'safe to test')
)

runs-on: ${{ matrix.runs-on }}
strategy:
fail-fast: false
matrix:
include:
- runs-on: windows-latest
python-version: "3.10"
- runs-on: windows-11-arm
python-version: "3.11" # win-arm runner needs 3.11 at least

steps:
- name: Checkout c2pa-python
uses: actions/checkout@v4
with:
path: c2pa-python

- name: Checkout c2pa-rs (${{ needs.resolve-ref.outputs.ref }})
uses: actions/checkout@v4
with:
repository: contentauth/c2pa-rs
ref: ${{ needs.resolve-ref.outputs.ref }}
path: c2pa-rs

- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: ${{ matrix.python-version }}
# No pip cache here: this job checks out and builds an arbitrary,
# not-necessarily-reviewed c2pa-rs ref, and CodeQL flags caching in
# that context as a cache-poisoning vector into the default branch.

- name: Install ARM64 OpenSSL via vcpkg (Windows ARM64)
if: matrix.runs-on == 'windows-11-arm'
shell: pwsh
run: |
# Pre-installed OpenSSL on runner fails build.
# Static OpenSSL to avoid runtime DLL load complexities.
& "$env:VCPKG_INSTALLATION_ROOT\vcpkg.exe" install openssl:arm64-windows-static-md
$vcpkgRoot = "$env:VCPKG_INSTALLATION_ROOT\installed\arm64-windows-static-md"
echo "OPENSSL_DIR=$vcpkgRoot" >> $env:GITHUB_ENV
echo "OPENSSL_STATIC=1" >> $env:GITHUB_ENV

- name: Install project dependencies
working-directory: c2pa-python
run: |
python -m pip install -r requirements.txt
python -m pip install -r requirements-dev.txt

- name: Build native library from c2pa-rs source
working-directory: c2pa-python
env:
C2PA_RS_PATH: ${{ github.workspace }}\c2pa-rs
run: python scripts\build_local_artifacts.py --clean

- name: Install package in development mode
working-directory: c2pa-python
run: |
pip uninstall -y c2pa
pip install -e .

- name: Verify installation
working-directory: c2pa-python
run: python -c "from c2pa import C2paError; print('C2paError imported successfully')"

- name: Run tests
working-directory: c2pa-python
env:
C2PA_PREFLIGHT_RUN: "1"
run: python -m pytest .\tests\test_unit_tests.py .\tests\test_sign_ladder.py
Loading
Loading