Homebrew build inputs
This records the integrated supply-chain preparation and the separate
Formula qualification. Neither publishes a
tap or package. All four packages are published as 0.4.2; immutable release evidence is recorded in #232.
Issue #228 records
the completed Formula integration. Final-version qualification and publication
are tracked in #232.
Runtime provider
The runtime uses Homebrew python@3.14, a system-site-packages virtual
environment and the official pydantic formula. The first qualification requires
Pydantic 2.13.5 and pydantic-core 2.46.5. Import locations must resolve into
that formula's keg. The proof reproduces the dependency .pth written by
Homebrew's virtualenv_create, without modifying global Python files.
This is a different packaging contract from pip/uv: Homebrew owns Pydantic and
its runtime closure, and may update them. Future qualification must check
Apizr's public pydantic>=2.12,<3 constraint and record exact tested versions.
There is no claim of permanent byte parity with uv.lock, and no artificial
versioned Pydantic formula. Python 3.14 is the Homebrew interpreter selection;
Apizr's supported Python range remains 3.11–3.14.
Official references: Python formula guidance, Pydantic formula, and Homebrew virtualenv API.
Build-only inputs
homebrew-build = ["hatchling==1.28.0"] adds exactly two packages to the universal
lock: Hatchling 1.28.0 and trove-classifiers 2026.9.21.13. Existing packaging 26.3,
pathspec 1.1.1 and pluggy 1.6.0 complete the five-package closure. No existing
locked version changes. Python <3.11's conditional tomli dependency does not
apply to this repository's supported interpreters.
Hatchling 1.28.0 is the first stable minor after the declared 1.27 floor whose reviewed metadata explicitly lists Python 3.14; 1.27.0 does not. This bounded choice must pass the actual candidate build and current vulnerability audit. The exact Hatchling source and wheel were reviewed, including its PEP 517 hooks, dependency metadata and MIT notice. The exact trove-classifiers source and wheel were reviewed as classifier data and a listing CLI under Apache-2.0. Its wheel avoids executing its setuptools/calver source build. Preserve both complete notices when redistributing build inputs. The dependency policy retains those texts and binds the review to every newly locked artifact hash.
policy/homebrew-build-inputs.json separates the mutable Homebrew runtime
provider from checksummed build-only wheel identities. The generator traverses
the locked group, rejects ambiguous/conditional or non-universal artifacts, and
requires exact agreement with this reviewed policy. It checks downloaded hashes
and wheel metadata; no live-index version selection occurs.
uv run --locked python scripts/prepare_homebrew_build_inputs.py \
--lock uv.lock --policy policy/homebrew-build-inputs.json \
--output /tmp/apizr-homebrew-inputs
The new output contains build-wheelhouse/ and deterministic build-inputs.json.
It is temporary build tooling, not content for Apizr archives, a Cellar runtime
prefix, or a plugin store. The dedicated homebrew-build audit has no advisory
exceptions. Release evidence includes its policy and dedicated SBOM, as well as
the complete validation SBOM.
Offline architecture proof
The preserved entry candidate is outerspace_apizr-0.4.2rc1.tar.gz, SHA-256
5b841b7f0e3d335330f6280b8409986036069371fe700282b18625940cf380b4, from protected
commit 7af517627aa92009f8e0ece2d255e7e2fd98e529. It is only the architecture
comparison. Final feature evidence must instead identify a coordinated candidate
produced once for the exact feature commit; macOS jobs consume the original
sdist bytes without rebuilding or recompressing it.
uv run --locked python scripts/homebrew_build_proof.py \
--candidate /tmp/coordinated-candidate --source-sha EXACT_SOURCE_COMMIT \
--inputs /tmp/apizr-homebrew-inputs --output /tmp/apizr-homebrew-proof
The proof keeps PEP 517 isolation enabled, sets PIP_NO_INDEX=1, uses only the
reviewed local PIP_FIND_LINKS, disables user pip configuration and starts with
an empty cache. macOS sandbox-exec denies network access for all descendants.
An audit observer records and refuses Python socket attempts, including in
pip's generated backend environments. Negative controls verify both layers;
the successful build must observe the requirements and wheel-building child
hooks with zero network attempts. A wrapper records actual dynamic PEP 517
requirements without changing them. Missing or unreviewed requirements fail;
there is no fallback to an index or disabled build isolation.
After wheel construction the temporary build environment is destroyed. A separate
fresh Homebrew-Python environment installs the wheel with --no-deps and checks
metadata, import provenance, runtime inventory, apizr --version, apizr init
and local apizr doctor with generated operator policy. Hatchling and
trove-classifiers must be absent. No Maturin, Flit, Hatch Fancy PyPI Readme, Rust
or Cargo closure belongs to this Apizr build toolchain; Homebrew remains
responsible for building its own Pydantic dependency.
The read-only Homebrew build inputs workflow runs on pull requests and manual
dispatch, with a narrowly scoped branch push trigger for qualification before
opening the preparation PR. The required build-input proof targets Apple Silicon
on macos-26. Intel provisioning is not a required PR job. Linux Homebrew runtime
and Formula installation are not qualified by this proof. No final Formula or
public tap should be inferred from a successful build-input receipt.
Homebrew distribution qualification boundary
Apizr 0.4.2 Homebrew qualification targets current Homebrew Tier-1 macOS,
which in the October 2026 support window is Apple Silicon. The intended host
must meet Homebrew's complete Tier-1 requirements, including supported macOS,
physical Apple hardware, a compatible prefix and official dependency bottles.
Homebrew Python 3.14 and Pydantic satisfying >=2.12,<3 are required; the exact
versions and import provenance used in each proof remain recorded.
Intel macOS is Homebrew Tier 3 and not qualified by Apizr's Homebrew distribution. It is documented and non-blocking for this preparation. Linux Homebrew runtime is also not qualified in 0.4.2. This narrower distribution boundary does not change Apizr's Python 3.11–3.14 compatibility declaration.
policy/homebrew-qualification.json is a separate, strictly validated
apizr.homebrew-qualification/v1 contract. Unknown, duplicate, missing or
contradictory classifications are rejected. The build-input policy, lock,
wheel identities and historical manifest remain byte-for-byte unchanged;
the manifest SHA-256 remains
c981a11d84ec319cd10d156b18b31e073ca480e1f2b62f3880c4a17cac0f5405.
The boundary validator binds its deterministic receipt to that manifest, and
release evidence archives both policies.
GitHub's hosted macOS runners
are virtual machines. macos-26 supplies an ARM64 CI proof for the intended
target; it is not itself certified as a Homebrew Tier-1 host. A separate
physical Apple Silicon Mac proof is required before this preparation PR opens.
Its host receipt records only a physical-host classification, architecture,
macOS and provider versions, relative import locations and qualification results.
Hardware probes are reduced to a classification; device identifiers and private
paths are not retained. It consumes the same candidate bytes and reviewed
wheelhouse as CI, and applies the unchanged offline build and runtime acceptance
criteria.
The upstream audit on 2026-10-01 used Homebrew's Support Tiers revision 5cec100 (commit dated 2026-09-23; document review date 2026-09-21). It lists “Intel x86_64 systems running macOS” under Tier 3, without full CI coverage or regular bottle production. Apple Silicon macOS 15, 26 and 27 are in its current Tier-1 OS window, subject to all configuration requirements.
The official
Pydantic formula revision 433eb8a
provides Pydantic 2.13.5 bottles for Apple Silicon macOS and Linux, but none for
Intel macOS. The formula source SHA-256 from the official API is
78b3164fbc745cfceb19330c2140b80243709c27b063a383d5cfbc6d7ad60097.
These are dated upstream observations, not immutable future provider guarantees.
Preserved Intel evidence
The first Intel job correctly refused the runner's stale Pydantic 2.13.4. After refreshing Homebrew, the updated provisioning job entered the native dependency bootstrap for OpenSSL, Python, LLVM, Rust and Pydantic. It reached the unchanged 45-minute job limit during LLVM compilation, before Pydantic 2.13.5 became available to the runtime-provider preflight. The equivalent final-head Intel attempt was then canceled; its records remain in run 36897250817 and issue #228.
This is an UPSTREAM PLATFORM QUALIFICATION LIMITATION. It did not reach
Apizr's isolated PEP 517 build and is not evidence of a build-closure failure
or success on Intel. No retry-until-green, relaxed provider version,
continue-on-error, or extended bootstrap timeout is used.
Intel qualification can be revisited if Homebrew restores a usable supported
provider path or Apizr intentionally adopts a separately maintained Intel
strategy; neither is part of the 0.4.2 commitment.
Preserved Apple Silicon evidence
The Apple Silicon job
passed at 78a3d87de13bb5767584cd90c4f125c1d85ab2cb with Homebrew 7.0.7,
Python 3.14.8, Pydantic 2.13.5 and pydantic-core 2.46.5. Its original candidate
sdist SHA-256 is
a707f8fbd486106c48550fd82f666f6d8bf28b20c65c30f24d2a3fb22e5abb01;
the resulting wheel SHA-256 is
8528c0f4e50cff41238b74da6c709c0f217e06cf35bef9ba707fee9d470be9ab.
The isolated build observed no dynamic requirements or network attempts;
the separate runtime passed version, init and doctor after build-environment
destruction. These historical bytes and receipts remain unchanged. The boundary
correction must receive a new exact-head proof through the normal workflow.
Physical Apple Silicon proof
policy/homebrew-physical-qualification.json retains the sanitized physical
proof for the original candidate above. It passed on macOS 27.0.1 with Homebrew
7.0.7, Python 3.14.8, Pydantic 2.13.5 and pydantic-core 2.46.5. The current patch,
physical Apple Silicon host, internal storage, default prefix and official
provider bottles satisfy the audited Homebrew Tier-1 host requirements.
The isolated build produced the identical wheel SHA-256 recorded above, with
no dynamic requirements and zero observed network attempts. Both network-refusal
controls passed. After the build environment was destroyed, the fresh runtime
installed only Apizr with --no-deps, imported Pydantic from the Homebrew keg,
contained no Hatchling or trove-classifiers, and passed version, init and doctor.
This receipt qualifies exact candidate bytes, not an arbitrary later commit. After committing this boundary correction, the new coordinated candidate's core sdist hash must equal the physically tested hash. If it differs, repeat the physical proof on the new bytes before opening the preparation PR. Hosted CI also qualifies the exact new head independently. Neither receipt qualifies a production Formula.
Formula qualification
scripts/homebrew_formula.py deterministically generates Formula/apizr.rb,
README.md and a portable source receipt. The Formula uses Homebrew's
virtualenv_create with Python 3.14 and visibility of the Homebrew Pydantic
provider. Only Apizr is installed into libexec, with runtime dependency
resolution disabled. The five reviewed universal wheels are build-only resources;
they feed the isolated PEP 517 environment and never enter the runtime.
Homebrew denies network access during the build. pip uses an empty cache,
PIP_NO_INDEX=1, PIP_CONFIG_FILE=/dev/null and only the reviewed wheelhouse.
Qualification mode requires an exact coordinated candidate and source commit.
It consumes the original sdist through file://, without rebuilding or
recompressing it. The source, Formula and unchanged build-input manifest hashes
are recorded. Because the qualification URL is local, Formula hashes are compared
only for the same source location; no private paths appear in the JSON receipts.
Publication mode additionally requires an explicit immutable GitHub release URL, source SHA-256, signed CI evidence archive and provenance bundle. The renderer verifies the exact protected release-line signature, signed candidate membership, and the immutable public asset's digest and size before producing output. Local, temporary CI and arbitrary unsigned URLs are rejected. No PyPI URL is invented and rendering does not publish anything.
The Homebrew Formula workflow builds one coordinated candidate for its exact
source head, then consumes those original bytes on macos-26. The real Formula
is installed through a disposable local tap, with brew style, readall,
audit --strict, install, test, info, uninstall and untap checks. Online source
audit against the immutable public v0.4.2 archive now passes. Its installed CLI
passes version, init, doctor, bash/zsh/fish completion and explicitly authorized
ci check against safe local fixtures. The existing plugin lifecycle, sync and
update proofs compare the entire Cellar prefix before and after, with plugins
outside that prefix. apizr.homebrew-formula/v1 retains only portable facts.
The same candidate can be downloaded for a physical Apple Silicon qualification
with scripts/qualify_homebrew_formula.py --host physical; a hosted VM cannot
claim that status. Apple Silicon Tier-1 qualification does not qualify Intel
macOS (Tier 3, non-blocking) or Linux Homebrew runtime. The official Alien6 tap is public
and its real Apple Silicon install/test, strict online audit and isolated-plugin
lifecycle pass. Issue #228 is complete; Homebrew/core is not targeted. The earlier build-closure receipt is not a
substitute for the real Formula installation proof.
Final-version qualification
The final 0.4.2 promotion changes only the coordinated project version in
uv.lock; the five reviewed build wheels and their hashes remain unchanged.
The final build-input manifest SHA-256 is
2ecca88800dc2d4c752f012c7afee472496c729fa5a49e1cc0b6eb9a59052a58.
The physical build-closure receipt above remains historical RC evidence and is
not relabeled. Fresh hosted and physical Formula qualification against the exact
final candidate is recorded in #232.
Public tap verification
The public tap commit is 661bb30754021c1419687d6bf604328d3d054cdf.
Its Formula SHA-256 is
0e1c0611de224f4b2b5f9af7a54a0ca4932d7a97a3135a0c71f9e062293e164b;
the immutable core sdist SHA-256 is
ca0348d7e16fd880271f10f62f1365fc52b5f264f856878426ae0628f7b51ed9.
The Formula is the publication-mode renderer output from release source
a21cfd41eecc7ca3259e2fb72f6a028a288b9030, without semantic edits.
The physical Apple Silicon proof uses brew tap alien6-studio/tap and
brew install alien6-studio/tap/apizr against that public repository. All 17
checks pass, including style, readall, strict online audit, test, info, init,
doctor, three shell completions, CI check and plugin lifecycle/sync/update.
Apizr imports from Formula libexec; Pydantic imports from the Homebrew provider.
Plugin environments stay outside the Cellar and the entire core prefix remains
unchanged. The verification installation was then uninstalled and untapped.
Master integration identity
Master preserves its previously reviewed test/documentation tool versions.
Because the build manifest includes the entire lockfile hash, its integration
identity is 925b8881feec75466ae489e7a0a71f9e97a2b7da0d6b75cdead210781009ea1b. Only lock_sha256 differs from the immutable
release manifest above: all five build wheel identities, root requirements,
build policy and generated Formula bytes are unchanged. The release manifest
and public tap remain bound to the original released source and are not relabeled.
0.4.3 candidate identity
The 0.4.3 candidate manifest is
76d36c8d868c866f4bd906980ffd54d1fa58c86860934f566874ea6566f0b0ae.
Only lock_sha256 changes from the master integration identity above, because
the lock records the core version. All five build wheels, their hashes, root
requirements and the build-input policy are identical. The active qualification
policy binds the new manifest and retains the same host boundary. Historical
physical and public-tap evidence still describes its original source; it is not
relabeled as a 0.4.3 qualification.