Skip to content

release: 2.0.0 — to_dataframe() and the dataframe extra removed (#72) - #84

Merged
Polichinel merged 1 commit into
developmentfrom
release/2.0.0
Sep 18, 2026
Merged

Polichinel merged 1 commit into
developmentfrom
release/2.0.0

Conversation

@Polichinel

Copy link
Copy Markdown
Collaborator

Story S8 (#72) · Epic #66 · Tracking #73. Release 2.0.0 into development; the development → main PR, the v2.0.0 tag and the draft GitHub Release follow this merge. MAJOR under ADR-022 §5: the surface 1.1.0 deprecated is removed.

The release commit

pyproject.toml 1.1.0 → 2.0.0; CHANGELOG.md gains ## [2.0.0] — 2026-09-18 with the ADR-022 §7 checklist worked through; the register gains the dated block. The CHANGELOG guard was red on the version bump before the section was written and green after.

§3.2 notifications posted before the tag and cited by comment ID: views-pipeline-core#515 (comment 5733334619), views-reporting#289 (comment 5733334868). Consumer state, measured on a fresh fetch 2026-09-18: views-pipeline-core's released 3.2.0 still calls the removed method in stage.py and pins ^1.0.0, so 2.0.0 reaches them only when S10 raises the pin; views-reporting's main pins >=1.0.0,<3.0.0 and calls nothing removed, while its released v0.3.3 still pins <2.0.0. The checklist says plainly that 1.1.0 and 2.0.0 are cut on the same day: §2 counts cycles in releases, and the notes plus the notifications are the notice for a consumer who never installed 1.1.0.

Review findings addressed (15 of 15 from /code-review max, 2 from /review-diff)

The release diff reviewed is v1.1.0..HEAD, i.e. S7 plus the release commit; the findings were on S7's guards, and they are fixed here because a release should not ship guards known to have holes.

Finding Fix
Import allowlist keyed by file stem: profiles/__init__.py inherited the root package's allowance; a hard import views_frames there passed One path-keyed allowlist set to the measured census; the root package is not listed (find_spec is a probe, not an import)
The string-literal branch read literals under ANY call, gated on find_spec; float("nan") became an import whenever a nan package was importable or a nan/ directory sat on sys.path Literals read only under import machinery and its per-file aliases, name= included, with no find_spec gate; exec/eval forbidden everywhere; a synthetic positive control for every spelling claimed
Two walkers, two declarations that disagreed One walker, one declaration; the per-module and package-wide tests are the same parametrised test over every file, with a vacuity check on the parametrisation and an equality check against the census
Runtime probe never called save/load; pandas in MetricFrame.save() was invisible Probe now saves and loads
Runtime-dependency pin read one TOML layout and forbade the other Reads both via the shared _extras_table; asserts the extras' contents, the runtime set under either layout, and that views-frames stays optional
metrics/config_schema classified Level 0 by one guard but not by the logging guard or the standard All three lists agree
to_dict() returns the live dict; the only pin was deleted with to_dataframe Documented in the docstring; identity and the emit path's reading of it pinned
get_schema_results() tested on month only after the deletions Parametrised over all three schemas
Five-name denylist let a new public method through Public surface pinned as an allowlist, class and instance, for the report and the four dataclasses
FM1 raise's silence unasserted Asserted
Doc guard froze the unpublished [2.0.0] section as history; ad-hoc heading regex Scans [Unreleased] plus the section for the pyproject version, split with the shared fence-aware parser
_REMOVAL_FRAMING matched "is used to", "was the", removed_cols Word-anchored phrases only
Five 2.0-era block-wide _HISTORICAL_MARKERS widened the older guards' exemption Removed; the new guard never used them
CI probe passed an ISO string into the contract's int timestamp timestamp=int, evaluation_timestamp=str, type asserted, row count derived
README attributed EvaluationReport to the emit layer; CIC scoped FM1 to the class, cited no test for the frames branch, dated 2026-08-02 All corrected
(review-diff) "byte-for-byte" on dataclass instances; same-day cycle unstated Both reworded

C-37 evidence

Every fixed guard was seen red on the review's own injection: import views_frames in profiles/__init__.py, import_module(name="pandas"), exec("import pandas"), an aliased import_module("modin") in Level 0, pandas in save(), a month-only get_schema_results, a deep-copying to_dict, to_records on the report and as_rows on the base, a logging FM1 raise, a stale sentence inside [2.0.0], "is used to", removed_cols, "was the", and "since 2.0.0 + PandasAdapter" against the older guards. The false-red probe (os.path.join("tests", ...) in a package file) now passes.

Independent guard audit (/falsify guard, clean-context subagent): 64 mutations over 14 guards; nothing decorative; five guards WEAK with concrete survivors, all closed in this commit and re-verified red:

  • Import purity: a getattr(importlib, "import_module")("pandas") or a spec-loaded pandas inside a kernel the runtime probe never called survived; the probe now evaluates every implemented kernel in all four cells and asserts none was skipped. from views_evaluation.evaluation import metric_frame in Level 0 survived the crossing check; the walker now records imported names for absolute imports too.
  • Runtime dependency pin: a hard views-frames under a PEP 621 [project] dependencies list survived, and a correct PEP 621 extras entry with a version specifier fired falsely. Both layouts handled; hard vs declared sets asserted separately.
  • Public surface: a __getattr__ shim serving to_dataframe under a split token beat the dir() listing. The removed names are probed behaviourally on instances and __getattr__ is banned.
  • Logging scope: _logger = ... and from logging import getLogger beat the text regex. The guard now checks for Logger objects bound at module level.
  • Doc guard: a fenced code example in the [2.0.0] section was invisible (fence-stripped body), examples/README.md was unscanned, and line numbers were off by one. Raw-text section scanning with real line numbers; examples/**/*.md scanned; removes dropped from the framing list.

Residuals stated in the docstrings: string concatenation of a module name, a # deprecated trailer or an identifier named removed on the same line as the method, and warnings.warn before the FM1 raise.

Gate

994 passed · ruff clean · validate_docs.sh passed · the CI probe body executes locally and emits 12 rows.

🤖 Generated with Claude Code

Version 1.1.0 → 2.0.0 (MAJOR, ADR-022 §5). CHANGELOG gains the `[2.0.0] —
2026-09-18` section with the §7 checklist worked through; the register gains the
dated release block. §3.2 notifications posted before the tag and cited by comment
ID (views-pipeline-core#515, views-reporting#289). Consumer state measured at the
cut: views-pipeline-core's released 3.2.0 still calls the removed method and pins
^1.0.0; views-reporting's main admits 2.0.0, its released v0.3.3 does not.

The release review found fifteen guard and doc defects, fixed here and each seen
red on an injected defect:

- Import purity: one walker, one path-keyed allowlist set to the measured census
  (a stem key gave profiles/__init__.py the root package's allowance; a string
  literal under ANY call made `float("nan")` an import whenever a `nan` package
  was importable). Literals are read only under import machinery and its aliases,
  `name=` included; `exec`/`eval` are forbidden everywhere; the runtime probe also
  saves and loads a MetricFrame. The runtime-dependency pin reads both pyproject
  layouts and the extras' contents.
- Logging: `metrics` and `config_schema` added to the logging guard's Level-0
  list and to the standard's §5.1 list so the three classifications agree.
- Report: `to_dict()` documents and a test pins that `schemas` is the live
  structure; `get_schema_results()` is tested on all three schemas; the public
  surface is pinned as an allowlist (class and instance); the FM1 raise is
  asserted silent.
- Doc guard: scans the CHANGELOG section of the version being cut (it had frozen
  it as history), splits with the shared fence-aware parser, uses word-anchored
  removal framings, and drops the five block-wide 2.0-era markers that had widened
  the older guards' exemption.
- CI probe: passes an int `timestamp` and the ISO string as `evaluation_timestamp`
  (the contract's field is int; the exemplar had mis-stamped provenance), asserts
  the type, and derives the row count.
- Docs: README no longer attributes EvaluationReport to the emit layer; the CIC
  scopes FM1 to `get_schema_results()`, cites the transplanted extra-absent test,
  and is dated; the CHANGELOG states plainly that both releases were cut on the
  same day.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
@Polichinel
Polichinel merged commit 4ed450d into development Sep 18, 2026
4 checks passed
@Polichinel
Polichinel deleted the release/2.0.0 branch September 18, 2026 18:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant