Operon 0.9.0
Pre-release
Pre-release
Highlights
- A unified per-user configuration layer.
operonoptionally reads an XDG
config file ($XDG_CONFIG_HOME/operon/config.yml, i.e.
~/.config/operon/config.yml), resolves the audit identity and the NCBI
contact through one documented chain, and keeps secrets out of that file
entirely:secret-tool→systemd-creds --user→ the macOS Keychain
(/usr/bin/security). Manage it with the newoperon configcommand group —
path,show,get,set,unset,check,init, plus
secret list/get/set/clear. - The TUI closes the self-service loop. Registry editing (
add,
add-accession,next-id), table import, taxonomy snapshot import and
reference-set compilation, coverage-profile editing, NCBI Datasets import,
and — on the Files screen —standardize,import-qcand the one-source
run-pipelineare available as preview-first, audited dialogs that call the
same core functions as the CLI and write the samechanges/
workflow_runsprovenance. - Byte-stable outputs across interpreters and backends. TSV cell quoting is
decided in Operon instead of delegated tocsv(ODR-0044), and cells a
spreadsheet would execute are escaped (ODR-0040) — in both alignment QC
backends and everywrite_tsvconsumer, with provenance hashes computed over
the escaped bytes.
New features
Configuration and secrets
operon/config.py:UserConfig/user_config()— XDG location, lazy load
(importing the module never touches the filesystem), 0600 file / 0700
directory modes, defaults back-filled, unknown keys preserved. Effective key
set:schema_version,identity.actor,ncbi.email,ui.splash.operon/secrets.py: a zero-dependency secret-backend chain with an
actionable error when no backend is available (pointing at--api-key/
NCBI_API_KEY). Secret resolution order:--api-key>NCBI_API_KEY>
stored secret; the file-backed stores are kept at 0600 in a 0700 directory,
andconfig shownever prints secret material.- Precedence is explicit and documented: CLI > environment > project
configuration > user configuration > defaults. Existing environment
variables keep working and take precedence over the file; nothing was
deprecated. resolve_actor()now backs every audit writer (CLI, TUI, import wizard,
adapters);resolve_ncbi_email()andresolve_splash()follow the same
shape with their own--effectivesource reporting.tests/unit/test_env_audit.pyguards the environment reads inside the
package (operon/**/*.py), so ad-hocos.environlookups cannot creep back
in.
TUI
- Entities:
add,add-accessionandnext-iddialogs. - Home: table-import dialog (template + preview-gated import) and the NCBI
Datasets import dialog (mandatory dry-run preflight; Cancel stops a
resume-able run). - Coverage: taxonomy snapshot import and reference-set compilation
(Import taxonomy…, Compile reference set…). - Config: the
taxonomy_coverageprofile editor joins the QC and
sequence-classification editors, with the same version bump, snapshot and
rollback machinery. - Files:
standardize(link-kind preview),import-qc(write-free plan
preview throughplan_qc_import), andrun-pipeline(entity prefill,
profile selection, forced dry-run preflight, and an explicit opt-in for
curated decisions in place of--yes). - Parity: the M4 scope is fully implemented; remaining gaps are registered
plannedwith milestones orcli-onlywith reasons, enforced by
tests/unit/test_tui_cli_parity.py.
Internals
operon/pipeline.py: the four-stage ingest → standardize → QC → evaluate
runner shared by the CLI and the TUI (CLI output stays byte-identical).operon/qc/imports.py: the shared import-qc core, withplan_qc_importas
its write-free preview.- Helper splits across
taxonomy,tools,entity_view,sequence_tools,
the NCBI adapter andenvironment; broad exception handlers narrowed or
documented; the wizard actor and every credential now resolve through the
user layer.
Fixed defects
See defects.yml.
Compatibility
- No storage changes: database schema stays 2.11, metadata schema stays
1.4; existing projects open unchanged. - Python 3.10–3.15, verified in CI on Linux and macOS for every version,
plus a strict Sphinx build of both documentation trees. - No new runtime dependencies. The configuration and secret layers use the
standard library and system tools only. - Environment variables keep working and keep precedence over the user
configuration file; no variable was deprecated.
Full Changelog: v0.8.5...v0.9.0