pmblue_update module changelog
Reconstructed history of pmblue_update, covering 0.2.12.1 through 1.0, using all 12 available source files and the in-module release notes. There are 11 version entries: ten historical backups and the current 1.0 release, which has identical root and active-module copies. Newest versions appear first.
The active module is modules/pmblue_update.py modules/pmblue_update.py, as selected by modules.json modules.json. The root pmblue_update.py pmblue_update.py is byte-for-byte identical at 1.0. See the module documentation.
How to read this history
- Snapshot evidence: each release links to its exact source and the preceding available version. The oldest entry records a baseline, not a claim that its features first appeared in that version.
- Author notes: the current notes retrospectively group the preserved 0.3.6 changes into 1.0. This history keeps 0.3.6 as its own entry because that source exists, and distinguishes its additions from the subsequent cache rewrite.
- Gaps: no snapshot older than 0.2.12.1 is available. There is no preserved 0.2.13.2 or intermediate version between 0.3.2.2 and 0.3.6; changes across those gaps cannot be assigned to smaller releases. Missing version numbers are not invented.
- Approximate dates: dates use each source file's last-modified timestamp converted to UTC. They are chronological estimates, not confirmed release dates, and may reflect a later save, backup, or copy. Both 1.0 copies have the same UTC date. This workspace has no usable Git history to confirm release dates.
- Scope: features, behavior changes, fixes, compatibility implications, and meaningful release-note discrepancies are included. Historical modules were read and compared without importing or executing them; the presence of a feature is not a runtime or cryptographic audit.
Compatibility changes to notice
REFRESH_TIMEreplaces the fixed four-second check interval in 0.2.13.3, with a 30-second default in the preserved sources.- The update service URL switches from HTTP to HTTPS in 0.3.2.2.
- In 0.3.6, downloads gain syntax checks, optional signature verification through
PMBLUE_TRUSTED_PUBLIC_KEY, atomic replacement, and file rollback on import/reload failures. - In 1.0,
_update_cache.jsonchanges from per-module check timestamps to a versioned, shared snapshot of remote versions and signed metadata. Legacy or invalid caches are replaced with a stale snapshot and refreshed. - Direct execution enables primary-module publishing prompts from 0.3.6. Import-time self-updating is already present in the earliest preserved source.
Releases
1.0
Approximate date: 2026-09-21 (snapshot timestamp, UTC).
- Replaced the legacy per-module timestamp cache and separate bulk-cache expiry with a shared remote-version snapshot containing
format_version, one timestamp, versions, metadata, and source context (server URL plus trusted public key). The file cache shares version and signature metadata across processes;CACHE=Falseuses process-local memory. - Added cache loading, validation, and atomic saving. Missing, legacy, invalid, or differently scoped caches become empty stale snapshots; future timestamps and expired entries trigger refresh rather than reuse.
- Added
refresh_timetoremote_versionand forwarded theupdate_stroverride. Removed the outer timestamp-based early returns fromself_update,update, andupdate_str, so a recent version check no longer suppresses a later retry after a failed download; there is no new automatic download retry loop. - Validated remote version maps and signed-manifest structure before caching. When the unsigned bulk endpoint returns 404, the per-module fallback replaces the snapshot for that module rather than extending unrelated cached data; signed mode still requires a manifest.
- Retained the signature verification, atomic installation, and file rollback already present in 0.3.6. The new in-module changelog groups those changes and the persistent-cache rewrite under 1.0.
- The root and active-module source copies are byte-for-byte identical; both are linked below.
Evidence: Snapshot 1.0 modules/pmblue_update.py; identical root copy pmblue_update.py; compared with 0.3.6 backups/pmblue_update_0.3.6.py.
0.3.6
Approximate date: 2026-09-21 (snapshot timestamp, UTC).
- Added
remote_versionwith a shared in-memory bulk version cache, fetching/update/versionsor a signed/update/manifestwhen a trusted public key is configured. A 404 from the unsigned bulk endpoint falls back to per-module version requests. - Added optional Ed25519 verification implemented with standard-library integer arithmetic and
hashlib, configured through the base64PMBLUE_TRUSTED_PUBLIC_KEYenvironment variable.install_modulechecks HTTP status, Python syntax, and, when configured, the SHA-256 digest and signature before replacing source. - Added
_write_atomically, writing and syncing a temporary file before replacement and preserving existing permission bits. Update/import paths restore previous source or remove a newly created file when import/reload fails; this is file rollback, not a reversal of arbitrary module side effects. - Routed self-update, module-object update, import, update checking, and string-based updating through shared version lookup and installation.
update_checknow compares a fullVersioninstead of converting the remote version to a float. - Changed direct execution to
self_update(adv_info=True, primary_mod=True). - The older per-module timestamp cache remains alongside the new in-memory cache. The current 1.0 notes consolidate this snapshot's changes into 1.0, but the preserved 0.3.6 source establishes their earlier presence. No intermediate snapshot since 0.3.2.2 is available.
Evidence: Snapshot 0.3.6 backups/pmblue_update_0.3.6.py; compared with 0.3.2.2 backups/pmblue_update_0.3.2.2\n.py.
0.3.2.2
Approximate date: 2026-09-20 (snapshot timestamp, UTC).
- Changed the update-service base URL to
https://update.pmblue.us/. - Handled empty normalized version strings by constructing a zero major version instead of trying to parse an empty integer.
- The preserved backup has
REFRESH_TIME = 30. The current author notes also describe a server-local copy using 3,000,000,000 seconds under this version; that variant is not preserved as a separate source here, so its timing and exact contents cannot be independently reconstructed.
Evidence: Snapshot 0.3.2.2 backups/pmblue_update_0.3.2.2\n.py; compared with 0.3.2.1 backups/pmblue_update_0.3.2.1\n.py.
0.3.2.1
Approximate date: 2025-08-20 (snapshot timestamp, UTC).
- Guarded maintenance-directory creation when
pathis""orNone, avoidingos.mkdirfor those default/empty values.
Evidence: Snapshot 0.3.2.1 backups/pmblue_update_0.3.2.1\n.py; compared with 0.3.2 backups/pmblue_update-"0.3.2".py.
0.3.2
Approximate date: 2025-04-20 (snapshot timestamp, UTC).
- Added creation of the requested maintenance directory with
os.mkdirwhen it does not exist. The initial implementation also attempts this for the default empty path; 0.3.2.1 adds a guard.
Evidence: Snapshot 0.3.2 backups/pmblue_update-"0.3.2".py; compared with 0.3.1 backups/pmblue_update-"0.3.1".py.
0.3.1
Approximate date: 2025-04-20 (snapshot timestamp, UTC).
- Added
maintenance(*mod_names, path="", adv_info=False), callingmaintainfor each requested module.
Evidence: Snapshot 0.3.1 backups/pmblue_update-"0.3.1".py; compared with 0.3 backups/pmblue_update-"0.3".py.
0.3
Approximate date: 2025-04-20 (snapshot timestamp, UTC).
- Added
update_str(mod_name, path=..., adv_info=..., ignore_err=..., timeout=..., refresh_time=...)to read a module version from its file and update it without importing that file. - Added
maintainto download a missing module throughimport_modor check an existing module throughupdate_str, using a 600-second refresh override for the latter path. - The existing-file branch does not forward
pathtoupdate_str, and the new helper otherwise retains direct destination writes and the per-module timestamp cache. This entry records the first implementation, including that limitation.
Evidence: Snapshot 0.3 backups/pmblue_update-"0.3".py; compared with 0.2.13.3 backups/pmblue_update-"0.2.13.3".py.
0.2.13.3
Approximate date: 2025-04-20 (snapshot timestamp, UTC).
- Added
REFRESH_TIME = 30and used it inself_updateandupdatetimestamp-cache checks, replacing the fixed four-second interval. - No 0.2.13.2 snapshot is available; these are the changes observed since 0.2.13.1.
Evidence: Snapshot 0.2.13.3 backups/pmblue_update-"0.2.13.3".py; compared with 0.2.13.1 backups/pmblue_update-"0.2.13.1".py.
0.2.13.1
Approximate date: 2025-04-05 (snapshot timestamp, UTC).
- Removed the unconditional self-update version-comparison debug print introduced in 0.2.13.
Evidence: Snapshot 0.2.13.1 backups/pmblue_update-"0.2.13.1".py; compared with 0.2.13 backups/pmblue_update-"0.2.13".py.
0.2.13
Approximate date: 2024-08-21 (snapshot timestamp, UTC).
- Revised
Version.__lt__to skip equal components and return false when a compared component is greater, rather than continuing to later components. Also introduced an early comparison of the float-styleshortversion field; this should not be read as a guarantee of correct ordering for every dotted version. - Normalized string local versions to
Versionobjects inself_update. - Added an unconditional self-update debug print showing the remote and local version representations; removed in 0.2.13.1.
Evidence: Snapshot 0.2.13 backups/pmblue_update-"0.2.13".py; compared with 0.2.12.1 backups/pmblue_update-"0.2.12.1".py.
0.2.12.1
Approximate date: 2024-08-21 (snapshot timestamp, UTC).
- Earliest preserved implementation. Includes
Versionparsing/comparison,get_version, caller-file discovery,self_update, module-objectupdate, download/import throughimport_mod,update_check, andupdate_reload. - Checks the HTTP update service for remote versions and downloads newer Python modules.
self_update(primary_mod=True)can prompt to publish a missing module or a newer local version using password-authenticated upload endpoints. - Uses
_update_cache.jsonto store per-module check timestamps, skipping repeatedself_updateandupdatechecks for four seconds. These are check timestamps, not cached remote version data. - Writes downloaded source directly to its destination, with no syntax validation, signed-manifest verification, atomic replacement, or rollback in this baseline.
- Already invokes
self_update()on import and callsself_update(adv_info=True, primary_mod=False)on direct execution. No earlier implementation exists to date individual feature introductions.
Evidence: Snapshot 0.2.12.1 backups/pmblue_update-"0.2.12.1".py; earliest available implementation, with no earlier source snapshot to compare.