v0.9.0 - Public API audit and hardening
Eight findings from a full public-API audit of v0.8.0 - a symbol-by-symbol
inventory, then a phased pass over naming, signatures, exceptions,
mutability, subclassing contracts, documentation, concurrency posture, and
import surface. All eight accepted, none rejected. Same methodology as
always: nothing taken from a summary, every finding reproduced against the
actual source before deciding on a fix.
🔒 Added
SETTOrchestrator.verify_ethical_audit_log(): delegates to
EthicalFilter.verify_audit_log(), reachable from the orchestrator
itself instead of requiring access to the private_ethical_filter
attribute. Closes a real gap: v0.8.0's tamper-evidence guarantee was
invisible to anyone using only the documented entry point.SETTValidationError(SETTError, ValueError): deliberate multiple
inheritance, the same pattern the standard library's own
json.JSONDecodeErroruses.RiskProfile.__post_init__now raises this
instead of a plainValueError; bothexcept SETTErrorand
except ValueErrorstill catch it.- A non-blocking warning (logged, not raised) when a
PhrasingExpert
subclass overridesresolve()against its own documented "template
method, do not override" contract. Fires at instantiation, does not
prevent the override from working.
🐛 Fixed
PrivateMemory.read()andget_all()returned mutable references into
internal state: a caller mutating a nested value could corrupt stored
data without ever callingwrite(), with no trace inget_history().
Both now returndeepcopy()s, the same treatmentUniversalMemory
already received in v0.8.0.tests/test_elevenlabs_adapter.pynow guards with
pytest.importorskip("requests"). Previously, a bare install (pip install -e ., without the[elevenlabs]extra) made these 12 tests
FAIL instead of skip, contradicting the project's own documented
install instructions. Present unchanged since v0.8.0 as published.
🗑️ Removed
sett/services_gen_ai/: an empty scaffold module (a one-line docstring,
no classes, no functions, not referenced anywhere) since v0.1.0. Will be
recreated with real content if a concrete use case appears.
📝 Docs
api_reference.md: documentedSafetyAssessment,ContextAnalysis,
TTSBase,STTBase,SentimentBase,SentimentResult, and
SentenceSentiment- all public, exported, used in real tests,
previously undocumented. Added a field table forEthicalRule.
DocumentedEthicalFilter.verify_audit_log()/
SETTOrchestrator.verify_ethical_audit_log(), and addedsequence,
previous_hash, andentry_hashto the audit log field lists. Added an
explicit Concurrency section: no thread-safety guarantee for the
framework as a whole beyondUniversalMemory's internal lock.
✅ Compatibility
Low risk, but not zero: import sett.services_gen_ai now raises
ModuleNotFoundError instead of importing an empty module. RiskProfile
now raises SETTValidationError instead of a plain ValueError; existing
except ValueError handlers keep working unchanged, since
SETTValidationError is one. No other public signature changed.
Status
- 275 tests passing (264 before this round), 11 new.
- Full audit methodology and findings: see
CHANGELOG.md.