Skip to content

feat(sdk): migrate to github-copilot-sdk 0.3.0, cross-platform binary… - #53

Merged
Mowri Mohan (mowree) merged 1 commit into
microsoft:mainfrom
HDMowri:feat/sdk-0.3.0-migration-binary-hardening
Apr 27, 2026
Merged

feat(sdk): migrate to github-copilot-sdk 0.3.0, cross-platform binary…#53
Mowri Mohan (mowree) merged 1 commit into
microsoft:mainfrom
HDMowri:feat/sdk-0.3.0-migration-binary-hardening

Conversation

@HDMowri

Copy link
Copy Markdown
Contributor

… hardening

Bump SDK pin to >=0.3.0,<0.4.0 and harden the binary resolution path.

SDK 0.3.0 breaking changes:

  • PermissionRequestResult.kind: "denied-by-rules" -> "reject"; removed fields encapsulated in make_permission_denied() factory (_imports.py)
  • SubprocessConfig gains session_idle_timeout_seconds

Cross-platform hardening:

  • _permissions.py: post-chmod stat() verification detects silent no-ops on NTFS/WSL /mnt/, FUSE, CIFS mounts; returns False instead of lying True
  • client.py: raises ProviderUnavailableError with platform-aware diagnostic before subprocess launch when ensure_executable returns False; clears _owned_client to keep singleton retryable
  • except (ProviderUnavailableError, ConfigurationError): raise -- prevents catchall from re-translating typed errors and changing retry semantics

Quality fixes:

  • amplifier-core dev floor 1.0.7 -> 1.3.0
  • _platform.py: OSError fallback covered; ternary comment clarified
  • contracts/sdk-boundary.md: MUST:9 (verified execute), MUST:10 (typed errors)
  • README: model table updated to SDK 0.3.0 live set

ruff: 0 errors | pyright: 0 errors
pytest (Windows/py3.13): 1,167 passed | pytest (Linux/py3.14): 1,169 passed

… hardening

Bump SDK pin to >=0.3.0,<0.4.0 and harden the binary resolution path.

SDK 0.3.0 breaking changes:
- PermissionRequestResult.kind: "denied-by-rules" -> "reject"; removed fields
  encapsulated in make_permission_denied() factory (_imports.py)
- SubprocessConfig gains session_idle_timeout_seconds

Cross-platform hardening:
- _permissions.py: post-chmod stat() verification detects silent no-ops on
  NTFS/WSL /mnt/, FUSE, CIFS mounts; returns False instead of lying True
- client.py: raises ProviderUnavailableError with platform-aware diagnostic
  before subprocess launch when ensure_executable returns False; clears
  _owned_client to keep singleton retryable
- except (ProviderUnavailableError, ConfigurationError): raise -- prevents
  catchall from re-translating typed errors and changing retry semantics

Quality fixes:
- amplifier-core dev floor 1.0.7 -> 1.3.0
- _platform.py: OSError fallback covered; ternary comment clarified
- contracts/sdk-boundary.md: MUST:9 (verified execute), MUST:10 (typed errors)
- README: model table updated to SDK 0.3.0 live set

ruff: 0 errors | pyright: 0 errors
pytest (Windows/py3.13): 1,167 passed | pytest (Linux/py3.14): 1,169 passed
@mowree
Mowri Mohan (mowree) merged commit d8e7e4b into microsoft:main Apr 27, 2026
@HDMowri
Mowri Mohan (HDMowri) deleted the feat/sdk-0.3.0-migration-binary-hardening branch April 27, 2026 22:07
Mowri Mohan (HDMowri) added a commit to HDMowri/amplifier-module-provider-github-copilot that referenced this pull request Apr 28, 2026
SDK 0.3.0 migration and cross-platform binary hardening
(PR microsoft#53) introduced new functionality warranting a minor bump:
- New SDK dependency constraint: >=0.3.0,<0.4.0
- ensure_executable raises ProviderUnavailableError before
  subprocess launch on filesystems that silently discard chmod
  mode bits (NTFS/WSL, FUSE, CIFS)
- Platform-aware diagnostic messages
- Typed amplifier-core errors not re-translated by catchall

ruff: 0 errors | pyright: 0 errors
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants