Repository navigation
Polymorph Bridge 0.4.0a10 - Adversarial own-data hardening
Pre-release
Pre-release
Adversarial own-data hardening
An independently generated 18-scenario torture pack did more than confirm existing behavior: it exposed three real integration defects. Polymorph Bridge 0.4.0a10 fixes them while retaining the fail-closed authority boundary.
What changed
- Detects valid namespace-prefixed OOXML formula tags such as
<x:f>and retains cached-formula uncertainty for review. - Restores metadata-only
empty_stringquality evidence for empty CSV cells without exposing record values. - Replaces unsafe implicit INTEGER copies with one strict
parse_integertransform exercised by both preflight and execution. - Makes the exact CSV-to-SQLite route preflight-valid and promotable while ambiguous, localized and drifted routes remain REVIEW/BLOCK.
- Accepts an existing local
.sqlite3path directly inpolymorph inspect db; users no longer need to hand-writesqlite:///.... - Adds permanent, self-generating regression tests instead of committing the untrusted external pack or redundant binary fixtures.
Local evidence bound to this release
- Source commit:
51df10728225affe52f585a0ab088e4ad7a476e8 - Full suite: 1,255 passed, 8 skipped, 0 failed.
- Repeated end-to-end workflow: 370.39 to 372.50 rows/s; maximum peak RSS 83.16 MiB.
- Clean-wheel million-row trial: 1,000,000 records scanned in 34.22 seconds, 29,226.06 rows/s, 126.02 MiB process-tree peak RSS.
- Source-checkout scale comparison observed 141.53 MiB at 100k rows and 141.25 MiB at 1M rows.
- Hostile duplicate-key JSON, non-finite JSON, traversal ZIP and high-expansion ZIP inputs were rejected.
- Unsafe automatic decisions: 0. Destination writes: 0. Network requests: 0.
- Compile, Ruff, formatting, strict mypy,
validate_local.py, build, Twine, clean-wheel installation, Trust Center and SHA-256 manifest verification passed. - GitHub Actions remained disabled and were not used for these results.
The precise claim is: bounded streaming behavior was observed from 100k to 1M rows on this Windows test host. This is measured evidence, not a universal constant-memory or performance guarantee.
Install without cloning
py -m pip install "https://github.com/IamAngusU/polymorph/releases/download/v0.4.0a10/polymorph_bridge-0.4.0a10-py3-none-any.whl"
polymorph trial your-data.csv --open
polymorph inspect db .\target.sqlite3 --table customers -o customers.schema.jsonThe attached polymorph-torture-evidence.json contains the sanitized scenario outcomes, measurements, limitations and external-pack digest. The original untrusted ZIP and its scripts are intentionally not distributed.