Skip to content

v0.9.0 - Public API audit and hardening

Choose a tag to compare

@EduDanielV EduDanielV released this 03 Aug 00:50
· 11 commits to main since this release
20d1e7e

Eight findings from a full public-API audit of v0.8.0 - a symbol-by-symbol
inventory, then a phased pass over naming, signatures, exceptions,
mutability, subclassing contracts, documentation, concurrency posture, and
import surface. All eight accepted, none rejected. Same methodology as
always: nothing taken from a summary, every finding reproduced against the
actual source before deciding on a fix.

🔒 Added

  • SETTOrchestrator.verify_ethical_audit_log(): delegates to
    EthicalFilter.verify_audit_log(), reachable from the orchestrator
    itself instead of requiring access to the private _ethical_filter
    attribute. Closes a real gap: v0.8.0's tamper-evidence guarantee was
    invisible to anyone using only the documented entry point.
  • SETTValidationError(SETTError, ValueError): deliberate multiple
    inheritance, the same pattern the standard library's own
    json.JSONDecodeError uses. RiskProfile.__post_init__ now raises this
    instead of a plain ValueError; both except SETTError and
    except ValueError still catch it.
  • A non-blocking warning (logged, not raised) when a PhrasingExpert
    subclass overrides resolve() against its own documented "template
    method, do not override" contract. Fires at instantiation, does not
    prevent the override from working.

🐛 Fixed

  • PrivateMemory.read() and get_all() returned mutable references into
    internal state: a caller mutating a nested value could corrupt stored
    data without ever calling write(), with no trace in get_history().
    Both now return deepcopy()s, the same treatment UniversalMemory
    already received in v0.8.0.
  • tests/test_elevenlabs_adapter.py now guards with
    pytest.importorskip("requests"). Previously, a bare install (pip install -e ., without the [elevenlabs] extra) made these 12 tests
    FAIL instead of skip, contradicting the project's own documented
    install instructions. Present unchanged since v0.8.0 as published.

🗑️ Removed

  • sett/services_gen_ai/: an empty scaffold module (a one-line docstring,
    no classes, no functions, not referenced anywhere) since v0.1.0. Will be
    recreated with real content if a concrete use case appears.

📝 Docs

  • api_reference.md: documented SafetyAssessment, ContextAnalysis,
    TTSBase, STTBase, SentimentBase, SentimentResult, and
    SentenceSentiment - all public, exported, used in real tests,
    previously undocumented. Added a field table for EthicalRule.
    Documented EthicalFilter.verify_audit_log() /
    SETTOrchestrator.verify_ethical_audit_log(), and added sequence,
    previous_hash, and entry_hash to the audit log field lists. Added an
    explicit Concurrency section: no thread-safety guarantee for the
    framework as a whole beyond UniversalMemory's internal lock.

✅ Compatibility

Low risk, but not zero: import sett.services_gen_ai now raises
ModuleNotFoundError instead of importing an empty module. RiskProfile
now raises SETTValidationError instead of a plain ValueError; existing
except ValueError handlers keep working unchanged, since
SETTValidationError is one. No other public signature changed.

Status

  • 275 tests passing (264 before this round), 11 new.
  • Full audit methodology and findings: see CHANGELOG.md.