Skip to content

Releases: dwrtz/purepy

PurePy v0.2.0

Choose a tag to compare

@github-actions github-actions released this 07 Sep 16:24

PurePy v0.2.0 release notes

PurePy now uses the functional language by default, on ordinary Python 3.14.
Running verified programs requires no PurePy runtime. Omit language from
configuration to use generic and recursive typing.NamedTuple records,
product tuples, type aliases, pure synchronous Callable values, stable nested
closures, rank-one generic functions, sealed copy.replace, and ord/chr.

The functional language contract describes exact rules and
conservative limits. Executable examples
cover composition, folds, immutable chain construction, ASCII lowercasing, and
persistent grouping. A production balanced map and broader Unicode function
interface remain future work.

Callback provenance flows through parameters, captures, and returned functions.
Authority reports include conservative function-value and closure dependencies.
Every function is rechecked even on a warm syntax cache. Generic recursion and
type expansion are bounded; unsupported or ambiguous programs fail verification.

Only language 0.2 is supported. It uses specification 0.4-draft and JSON schema 2. Host manifest
schema 1 and direct capability forwarding are unchanged. Higher-order effectful
or async functions and host-supplied callbacks are outside the new profile.

The reference service now runs on standard NamedTuple records. Python distribution
metadata and wheel/sdist/PyPI publishing have been removed. The former @value
implementation and compatibility paths have been removed. Native releases
contain the verifier, documentation, examples, source inventory, and dependency
licenses, with hashes and reproducible archive metadata.

Verification and runtime testing remain complementary. Verification does not
prove termination, prevent exceptions, or establish that external implementations
obey their declared host contracts. Historical performance reports remain evidence
for their original snapshots and do not measure this candidate.

PurePy v0.1.0-dev.4

PurePy v0.1.0-dev.4 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 06 Sep 01:50

PurePy v0.1.0-dev.4 release notes

This development release adds an agent skill for writing and verifying PurePy
projects, including CLI workflows and trusted host manifests. From a source
checkout, make install installs the CLI to ~/.local/bin/purepy and the skill
to ~/.agents/skills/purepy; make uninstall removes both while preserving
unrelated files. Override destinations with BINDIR and AGENTS_HOME. Native
archives also include skills/purepy/SKILL.md. The Python runtime remains at
version 0.1.0.

This release line implements the PurePy 0.1 language against specification
0.3-draft. The verifier's authoritative version is in
internal/app/check.go; the independently versioned Python runtime's name and
version are in python/pyproject.toml. Release archives record both identifiers.
A -dev verifier identifier denotes a development candidate, not a final tag.

The Python distribution is named purepy-lang and contains the small @value
runtime. After its PyPI publication, install it with
python -m pip install purepy-lang; code still imports from purepy import value.
The native Go verifier is distributed through
GitHub releases. Publisher configuration
alone does not indicate that a PyPI upload has completed.

The verifier checks Python 3.14 syntax without importing analyzed code. It
implements exact primitive, homogeneous tuple and optional types, finite nominal
@value records, deterministic module linking, sealed operations, direct known
calls, capability/host-reference forwarding and direct-await async composition.
Closed configuration and manifest schemas reject unknown fields, aliases and
coerced container shapes. Resource limits reject excessive inputs, and corrupt
cache entries fall back to reanalysis. Structured diagnostics, explanations and
authority reports share the frozen version-1 contracts.

The Python runtime supplies immutable records; selected CPython 3.12, 3.13 and
3.14 support is exercised by the release workflow. The reference service keeps
network, database and resource lifecycle mechanics in an explicit trusted host.
The source archive contains conformance tests, differential harnesses, fuzz seeds,
benchmark tooling and recorded service reports. Reports identify their original
source/binary fingerprints and remain finite evidence for those recorded inputs.
They should not be read as measurements of every later build.

Native release artifacts are prepared for Linux amd64 and macOS arm64. The
source archive supports building on other environments, but those environments
are outside this initial binary validation matrix. Archives include schemas,
usage/implementation documentation, the specification and plan, conformance
maps, reference service and available validation reports. Every artifact is
indexed and checksummed. The packaging workflow repeats builds and compares
bytes before artifact publication.

Deferred language features remain explicit exclusions:

  • Mutable lists/dicts/sets, comprehensions, generators and local builder scopes.
  • User-defined classes beyond data-only records, inheritance, protocols,
    descriptors, dynamic dispatch, callbacks, higher-order functions and generics.
  • General unions, recursive data types, pattern matching and unrestricted
    container methods; implicit mixed numeric arithmetic and exponentiation.
  • Dynamic/relative/star imports, aliases, package re-exports, executable module
    initialization and reflective/evaluation primitives.
  • Exception handling and user-visible exception values; exceptions from approved
    operations still terminate the current execution normally under Python rules.
  • Coroutine/task/stream values, async iterators and context managers, task spawn,
    detached work, general cancellation APIs and parallel_join.
  • Lexically scoped resources, affine/linear ownership, borrowing, cleanup proofs,
    lock APIs, callback lifetime verification and host-reference inspection.
  • In-process memoization, semantic-body cache hashes and fine-grained dependent
    body invalidation beyond the documented cache model.
  • Executable verifier plugins, dependency resolution, package registries,
    framework APIs and source-level unsafe blocks.

PurePy verifies admitted source operations under declared host assertions. It
cannot prove an external implementation obeys its manifest, prevent hostile
reflection by unverified Python, or guarantee liveness, cancellation cleanup or
resource bounds of the host. See the trust boundary, the
implementation contract, and conformance evidence.

PurePy v0.1.0-dev.3

PurePy v0.1.0-dev.3 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 05 Sep 18:46

PurePy 0.1 release notes

This release line implements the PurePy 0.1 language against specification
0.3-draft. The verifier's authoritative version is in
internal/app/check.go; the independently versioned Python runtime's name and
version are in python/pyproject.toml. Release archives record both identifiers.
A -dev verifier identifier denotes a development candidate, not a final tag.

The Python distribution is named purepy-lang and contains the small @value
runtime. After its PyPI publication, install it with
python -m pip install purepy-lang; code still imports from purepy import value.
The native Go verifier is distributed through
GitHub releases. Publisher configuration
alone does not indicate that a PyPI upload has completed.

The verifier checks Python 3.14 syntax without importing analyzed code. It
implements exact primitive, homogeneous tuple and optional types, finite nominal
@value records, deterministic module linking, sealed operations, direct known
calls, capability/host-reference forwarding and direct-await async composition.
Closed configuration and manifest schemas reject unknown fields, aliases and
coerced container shapes. Resource limits reject excessive inputs, and corrupt
cache entries fall back to reanalysis. Structured diagnostics, explanations and
authority reports share the frozen version-1 contracts.

The Python runtime supplies immutable records; selected CPython 3.12, 3.13 and
3.14 support is exercised by the release workflow. The reference service keeps
network, database and resource lifecycle mechanics in an explicit trusted host.
The source archive contains conformance tests, differential harnesses, fuzz seeds,
benchmark tooling and recorded service reports. Reports identify their original
source/binary fingerprints and remain finite evidence for those recorded inputs.
They should not be read as measurements of every later build.

Native release artifacts are prepared for Linux amd64 and macOS arm64. The
source archive supports building on other environments, but those environments
are outside this initial binary validation matrix. Archives include schemas,
usage/implementation documentation, the specification and plan, conformance
maps, reference service and available validation reports. Every artifact is
indexed and checksummed. The packaging workflow repeats builds and compares
bytes before artifact publication.

Deferred language features remain explicit exclusions:

  • Mutable lists/dicts/sets, comprehensions, generators and local builder scopes.
  • User-defined classes beyond data-only records, inheritance, protocols,
    descriptors, dynamic dispatch, callbacks, higher-order functions and generics.
  • General unions, recursive data types, pattern matching and unrestricted
    container methods; implicit mixed numeric arithmetic and exponentiation.
  • Dynamic/relative/star imports, aliases, package re-exports, executable module
    initialization and reflective/evaluation primitives.
  • Exception handling and user-visible exception values; exceptions from approved
    operations still terminate the current execution normally under Python rules.
  • Coroutine/task/stream values, async iterators and context managers, task spawn,
    detached work, general cancellation APIs and parallel_join.
  • Lexically scoped resources, affine/linear ownership, borrowing, cleanup proofs,
    lock APIs, callback lifetime verification and host-reference inspection.
  • In-process memoization, semantic-body cache hashes and fine-grained dependent
    body invalidation beyond the documented cache model.
  • Executable verifier plugins, dependency resolution, package registries,
    framework APIs and source-level unsafe blocks.

PurePy verifies admitted source operations under declared host assertions. It
cannot prove an external implementation obeys its manifest, prevent hostile
reflection by unverified Python, or guarantee liveness, cancellation cleanup or
resource bounds of the host. See the trust boundary, the
implementation contract, and conformance evidence.

PurePy v0.1.0-dev.2

PurePy v0.1.0-dev.2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 05 Sep 17:38

PurePy 0.1 release notes

This release line implements the PurePy 0.1 language against specification
0.3-draft. The verifier's authoritative version is in
internal/app/check.go; the independently versioned Python runtime's name and
version are in python/pyproject.toml. Release archives record both identifiers.
A -dev verifier identifier denotes a development candidate, not a final tag.

The verifier checks Python 3.14 syntax without importing analyzed code. It
implements exact primitive, homogeneous tuple and optional types, finite nominal
@value records, deterministic module linking, sealed operations, direct known
calls, capability/host-reference forwarding and direct-await async composition.
Closed configuration and manifest schemas reject unknown fields, aliases and
coerced container shapes. Resource limits reject excessive inputs, and corrupt
cache entries fall back to reanalysis. Structured diagnostics, explanations and
authority reports share the frozen version-1 contracts.

The Python runtime supplies immutable records; selected CPython 3.12, 3.13 and
3.14 support is exercised by the release workflow. The reference service keeps
network, database and resource lifecycle mechanics in an explicit trusted host.
The source archive contains conformance tests, differential harnesses, fuzz seeds,
benchmark tooling and recorded service reports. Reports identify their original
source/binary fingerprints and remain finite evidence for those recorded inputs.
They should not be read as measurements of every later build.

Native release artifacts are prepared for Linux amd64 and macOS arm64. The
source archive supports building on other environments, but those environments
are outside this initial binary validation matrix. Archives include schemas,
usage/implementation documentation, the specification and plan, conformance
maps, reference service and available validation reports. Every artifact is
indexed and checksummed. The packaging workflow repeats builds and compares
bytes before artifact publication.

Deferred language features remain explicit exclusions:

  • Mutable lists/dicts/sets, comprehensions, generators and local builder scopes.
  • User-defined classes beyond data-only records, inheritance, protocols,
    descriptors, dynamic dispatch, callbacks, higher-order functions and generics.
  • General unions, recursive data types, pattern matching and unrestricted
    container methods; implicit mixed numeric arithmetic and exponentiation.
  • Dynamic/relative/star imports, aliases, package re-exports, executable module
    initialization and reflective/evaluation primitives.
  • Exception handling and user-visible exception values; exceptions from approved
    operations still terminate the current execution normally under Python rules.
  • Coroutine/task/stream values, async iterators and context managers, task spawn,
    detached work, general cancellation APIs and parallel_join.
  • Lexically scoped resources, affine/linear ownership, borrowing, cleanup proofs,
    lock APIs, callback lifetime verification and host-reference inspection.
  • In-process memoization, semantic-body cache hashes and fine-grained dependent
    body invalidation beyond the documented cache model.
  • Executable verifier plugins, dependency resolution, package registries,
    framework APIs and source-level unsafe blocks.

PurePy verifies admitted source operations under declared host assertions. It
cannot prove an external implementation obeys its manifest, prevent hostile
reflection by unverified Python, or guarantee liveness, cancellation cleanup or
resource bounds of the host. See the trust boundary, the
implementation contract, and conformance evidence.