You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Correctness / arch:
- audit_bundled_binaries.py: add an ELF e_machine arch gate (linux-64==x86_64,
linux-aarch64==aarch64) -- the Linux twin of assert_pe_machine.py; +3 tests.
- consolidate-conda-artifacts-job.yml: reconcile the win-arm64 accounting (25->28).
- build-conda-packages.sh + conda-build-pipeline.yml: correct the false osx-arm64
"static arm64-slice audit (lipo/otool)" claims (no such check exists) to admit the
arm64 slice is trusted from the universal2 wheel tag; real guards are PE + ELF.
Hygiene:
- rename test_026_driver_load_probe.py -> test_033 (dup with main's test_026).
- build-conda-packages.sh: idempotent conda_builder env create (set -e safe).
- tls_connect_probe.py: MS-ODBCSTR }} brace escaping in _split_top_level.
Bloat removal (ponytail):
- drop the YAGNI _DRIVER_LOAD_FAILURE_MARKERS / _OPENSSL_UNREACHABLE_MARKERS tables
(describe() decoration only; classifiers use separate positive-marker lists).
- remove the dead targetArch param + always-true ne(...,'arm64') condition + args.
- remove the vestigial -Package/-DriverCondaDir params + odbc no-op branches from
build-conda-packages.ps1.
Probe/audit unit tests pass; black clean. Validated on a NonOfficial ADO build run.
# an Intel agent (no reverse Rosetta): the arm64 Python genuinely cannot run here.
301
+
# CAVEAT: osx-arm64 arch is NOT independently verified in this pipeline. Unlike
302
+
# Windows (assert_pe_machine.py PE check) and Linux (audit_bundled_binaries.py ELF
303
+
# e_machine check), there is NO Mach-O arch audit, so the arm64 slice is trusted
304
+
# from the universal2 wheel tag -- exactly like the shipping PyPI universal2 wheel.
305
+
# Every OTHER target (linux-64/osx-64 native, linux-aarch64 under QEMU binfmt) MUST
306
+
# run its own import; a leg that cannot is a real failure, never a silent pass --
307
+
# otherwise a broken linux-aarch64 package ships unvalidated.
299
308
if [ "${CONDA_SUBDIR:-}"="osx-arm64" ] && [ "$(uname -s)"="Darwin" ];then
300
-
echo"=== [py $py] osx-arm64 cross on Intel: target Python not executable; skipping runtime import (static arm64-slice audit covers this leg). ==="
309
+
echo"=== [py $py] osx-arm64 cross on Intel: target Python not executable; skipping runtime import (osx-arm64 arch NOT independently verified -- trusted from the universal2 wheel tag). ==="
301
310
continue
302
311
fi
303
312
echo"ERROR: [py $py] target Python for CONDA_SUBDIR=${CONDA_SUBDIR:-native} is not executable on $(uname -s)/$(uname -m), and this is NOT the osx-arm64 cross-build. Refusing to silently skip validation (linux-aarch64 requires QEMU binfmt to be registered on this leg).">&2
0 commit comments