Skip to content

chore: give the fork its own identity and version namespace - #7

Merged
Marius1311 merged 1 commit into
mainfrom
chore/fork-identity
Aug 27, 2026
Merged

Marius1311 merged 1 commit into
mainfrom
chore/fork-identity

Conversation

@Marius1311

Copy link
Copy Markdown
Member

Replaces #6, which GitHub auto-closed when its base branch (chore/branch-model) was deleted on
merge. Same content, rebased onto main.

The wheel currently describes itself as upstream's, and its version claims a string upstream can
publish at any time.

Version → PEP 440 local identifier, 1.1.61+quadbio.N. Upstream has 86 .postN tags, ships
them to PyPI, and has already released 1.1.61 — so cirrocumulus 1.1.61.post1 is theirs to cut,
while we have a published wheel claiming it. Same name, same version, different bytes; anything
resolving cirrocumulus from an index can swap our fork for upstream's. Local versions are the
documented mechanism for "upstream's release plus our patches", and PyPI must not accept them,
which is what makes ours unforgeable.

tag_regex in pyproject.toml is required: setuptools_scm's default captures [^\+]* and would
silently drop the local segment. Verified empirically:

tag state version
on quadbio-1.1.61+quadbio.3 1.1.61+quadbio.3
one commit past 1.1.62.dev1+quadbio.3.gc0cc180

Both keep the marker, so local_scheme needs no override — setting no-local-version would have
dropped +quadbio.3 from the tagged build.

check_wheel.py now fails if +quadbio. is ever missing, so a bad derivation breaks CI instead
of shipping.

Identity — Homepage/Source point at quadbio, upstream gets its own key, a maintainer is
added, and README.rst (the wheel's long description) opens with a fork notice. Also drops the
stray dev = ['pre-commit', 'isort', 'black'] that upstream left sitting inside
[tool.hatch.version].

Licence-wise we were already fine: BSD-3 requires retaining the copyright notice, which
license = { file = 'LICENSE' } does, and has no modification-notice clause. This is a routing
and collision fix, not a compliance one.

The wheel described itself as upstream's: urls pointed at lilab-bcb, and the
version claimed a string upstream can publish. Upstream has 86 .postN tags on
PyPI and has already released 1.1.61, so cirrocumulus 1.1.61.post1 was theirs
to cut while we had published a wheel claiming it -- same name, same version,
different bytes.

- Version as a PEP 440 local identifier, 1.1.61+quadbio.N. Local versions are
  the mechanism for "upstream's release plus our patches", and PyPI must not
  accept them, so ours cannot collide. tag_regex keeps the local segment that
  setuptools_scm's default would drop; check_wheel.py fails the build if it
  ever goes missing.
- Point Homepage/Source at quadbio, record upstream under its own key, add a
  maintainer, and put a fork notice atop README.rst (the wheel's long
  description).
- Drop the stray `dev = [...]` key upstream left inside [tool.hatch.version].

Verified: on the tag -> 1.1.61+quadbio.N; one commit past ->
1.1.62.dev1+quadbio.N.g<sha>. Both keep the marker.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BQnnW5jCKXnefXA89eBDoL
@Marius1311
Marius1311 merged commit 3070196 into main Aug 27, 2026
1 check passed
@Marius1311
Marius1311 deleted the chore/fork-identity branch August 27, 2026 07:40
Marius1311 added a commit that referenced this pull request Aug 27, 2026
#7's tag_regex matched only `quadbio-*`, so setuptools_scm raised
`Can't parse version from tag '1.1.61'` on upstream's tags -- which are the
nearest ones reachable from main, since our two release tags were orphaned by
the old force-pushed integration branch. That broke release.yml on every push
to main.

Make the prefix optional so upstream's tags parse as a fallback, and only
require the +quadbio. segment on release builds: a build off an untagged main
is a .devN artifact that is never published and has no local segment to carry.


Claude-Session: https://claude.ai/code/session_01BQnnW5jCKXnefXA89eBDoL

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant