Skip to content

[FEATURE] Release Autobahn|Python 26.7.1 #1930

Description

@oberstet

Part of the coordinated 26.7.1 release train (autobahn -> zlmdb -> crossbar)


Release Autobahn|Python 26.7.1

Why

Cut the 26.7.1 stable release. Master carries the completed WebSocket/RawSocket
payload size-limit security epic (#1907) plus the musllinux wheel track, none
of which has reached users yet — the tree is at 26.7.1.dev1.

The musllinux work in particular is merged but unpublished: the user who
asked for Alpine wheels (#1877) gets nothing until this release ships.

What's in it

Security (epic #1907, advisory GHSA-hxp9-w8x3-p566):

Wheels / build: musllinux (Alpine/musl) CPython wheels (#1877), aarch64 cp314
GIL-ABI fix (#1875), .cicd ABI-tag matching (wamp-cicd #11), ruff ANN/UP/TCH
gate (#1840), CalVer version recipes (#1894).

FlatBuffers: version() reliable on installed wheels (#1891).

Steps

  1. Branch fix_<issue-number> off master.
  2. just prep-release — finalises 26.7.1.dev1 -> 26.7.1 (pyproject + _version.py).
    Do not hand-edit the version. (autobahn does not track uv.lock, so no relock.)
  3. Review docs/changelog.rst 26.7.1 section is complete and accurate (it already
    carries the Security section for [BUG] permessage-deflate max_message_size cap silently truncates and corrupts messages (missing unconsumed_tail drain) #1908/[BUG] WebSocket maxMessagePayloadSize is enforced against compressed size, bypassed after permessage-deflate inflation #1909/[BUG] Backend-agnostic bounded decompression for permessage-compress (snappy / bzip2 / brotli parity with deflate) #1910/[BUG] asyncio RawSocket receive size limit is hardcoded to 16 MB (no setProtocolOptions), unlike the Twisted backend #1911).
  4. PR -> normal CI cycle -> merge to master.
  5. Human: git tag v26.7.1, push tag -> release workflow runs -> approve the
    manual pypi environment gate -> published to PyPI.
  6. Verify the release fileset: manylinux + musllinux_1_2 (CPython 3.11–3.14,
    x86_64 + aarch64) + PyPy + sdist. The check-release-fileset gate enforces this.
  7. Follow-up PR: just bump-dev to reopen the dev cycle.

Gotchas

  • softprops@v2 finalize can break the release via the discussion category
    ("valid category name"); workaround = lowercase category + re-run, durable fix =
    SHA-pin. Re-running a release reuses the OLD workflow file.
  • PyPy-on-musl ([FEATURE] Publish PyPy musllinux wheels (Alpine / musl libc) #1906) is explicitly out of scope for 26.7.1 (needs custom
    Alpine images; no official PyPA musllinux PyPy image).

Blocks / blocked by

  • Blocks crossbar 26.7.1 (crossbar #2250 pins autobahn>=26.7.1 + relocks).
  • Independent of the zlmdb 26.7.1 release (may run in parallel).
  • Advisory GHSA-hxp9-w8x3-p566 publication is coordinated separately (awaiting OP
    reply; CVE requested but not yet assigned).

This work is being completed with AI assistance (Claude Code).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions