Skip to main content

dag-ml Python bindings

Thin PyO3/maturin bindings for DAG-ML JSON contracts.

This package validates, compiles and plans serialized DAG-ML contracts. Its owning training entry point also executes the native DAG-ML coordinator while operator implementations remain Python callbacks; no numerical or fold logic is reimplemented in the binding.

Build

This crate is excluded from the root cargo workspace (its abi3-py311 floor would force a Python >= 3.11 host on cargo test --workspace / cargo llvm-cov), so build and test it through its own manifest against a Python

= 3.11 interpreter:

PYO3_PYTHON=python3.11 cargo test --manifest-path crates/dag-ml-py/Cargo.toml
maturin build --release --features extension-module   # run from this crate dir
python3 ../../scripts/smoke_python_bindings.py        # after installing the wheel
PYTHONPATH=python python3.11 -m unittest discover -s tests

The source package also contains the tracked _dag_ml.abi3.so used by direct PYTHONPATH=crates/dag-ml-py/python imports. After changing compiled Rust inputs, refresh it with maturin develop --release inside an active Python 3.11+ virtual environment, run python scripts/check_so_freshness.py, and smoke the public source-tree import. The freshness gate rejects dirty or untracked Rust inputs when that tracked extension is unchanged.

Python Surface

dag_ml._dag_ml.probe_data_view_in_process(envelope_json, request_json, view_callback) exercises the host view callback without fitting a model. It creates native parent/view handles, rejects IDs outside the envelope relations, and requires a receipt with the same handle, view key, ordered IDs, and SHA-256 schema/content fingerprints. The caller supplies the request; this diagnostic does not prove scheduler fold membership or that training consumed those buffers. The CV/refit entry point therefore does not accept a view callback until the host resolver and native training identity are connected.

For a concrete host-managed pipeline without cross-validation, use execute_phase_in_process(dsl, envelope, controllers, callback, "REFIT", training_sample_ids=[...]). Rust verifies the supplied row ordering is an exact unique permutation of the attested training identities and records it in the effective campaign. Split invocations and unresolved operator choices are refused; use the CV/refit entry point for those campaigns.

The same entry point with phase="PREDICT" requires a separately attested V2 prediction cohort and forbids training_sample_ids. It executes only PREDICT, never fitting or selecting a model. Host-managed fitted state stays the host's responsibility and is not implicitly promoted to a portable predictor package. Both paths return JSON with native node_results, scores, phase and effective_plan; absent target observations produce no invented score.

import dag_ml

dag_ml.validate_graph_json(graph_json)  # raw JSON helper remains available

dsl = dag_ml.PipelineDslSpec(dsl_json)
controllers = dag_ml.ControllerManifests(controller_manifests_json)
artifact = dag_ml.compile_pipeline_dsl_artifact(dsl)
plan = dag_ml.build_execution_plan(
    "plan:example",
    artifact.graph,
    artifact.campaign_template,
    controllers,
)
plan_json = plan.json()

validated_request = dag_ml.TrainingRequest.from_path(
    "examples/fixtures/training/training_request_active_influence.v1.json"
)
validated_request = dag_ml.sign_training_request(unsigned_training_request)
relation_fingerprint = dag_ml.sample_relation_set_fingerprint_json(relations_json)
training_projection = validated_request.project()
package = dag_ml.PortablePredictorPackage.from_path(
    "examples/fixtures/training/portable_predictor_package.v1.json"
)

result = dag_ml.execute_training(
    native_training_request,
    data_envelopes={"model:base.x": signed_envelope},
    relations=sample_relations,
    training_influence=signed_influence,
    op_callback=run_node,
    outcome_id="outcome:example",
    run_id="run:example",
    bundle_id="bundle:example",
)
bundle = result.execution_bundle
scores = result.score_set
portable_artifacts = result.artifacts
result.detach()  # explicitly release callbacks, views and artifact handles

Portable package replay is available without the original TrainingResult. Hosts pass the signed package, a TrainingReplayRequest whose phase is either PREDICT or EXPLAIN, the current cohort data envelopes, and explicit sidecar artifact handles:

outcome = dag_ml.replay_loaded_predictor_package(
    package,
    replay_request,  # {"phase": "PREDICT"} or {"phase": "EXPLAIN"}
    data_envelopes,
    artifact_handles,
    run_node,
    outcome_id="outcome:package.replay",
    run_id="run:package.replay",
)

PREDICT must reproduce the requested package output bindings exactly. EXPLAIN must emit at least one explanation block and may include the final bound predictions for the requested bindings. The package remains handle-free; all process-local model handles are supplied through artifact_handles.

TrainingRequest, TrainingContractProjection, ParameterProjection, CacheNamespace and PortablePredictorPackage are validated by the native dag-ml-core contracts. sign_training_request() canonicalizes and signs an unsigned request through the same native structs, and sample_relation_set_fingerprint_json() exposes the core relation fingerprint for host-side data envelope assembly. project_training_request() is also available as a functional facade. The binding does not reproduce parameter projection, capability-derived influence or portability rules in Python.

execute_training() requires an envelope map keyed by the exact node_id.input_name requirement key plus the matching relations and influence manifest. The PyO3 layer releases the GIL while the core runs and reacquires it only for controller callbacks. TrainingResult retains the controller registry, attested provider and artifact store until detach() or object destruction; portable outcome, bundle, scores, outputs and artifact metadata remain readable after detach, while process-local handles are never serialized.

All Rust-side validation failures are raised as dag_ml.DagMlError. Native errors expose category, code, severity, remediation_hint, context, context_json and descriptor_json attributes for ADR-11-compatible handling.

Metadata

Release files for dag-ml 0.3.32

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dag-ml 0.3.32
File Size Uploaded
dag_ml-0.3.32.tar.gz 1.1 MB Details

Built distributions (wheels)

Table of built distributions (wheels) for dag-ml 0.3.32
File
dag_ml-0.3.32-cp311-abi3-win_amd64.whl CPython 3.11 abi3 Windows x86-64 Details
dag_ml-0.3.32-cp311-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.11 abi3 Linux glibc 2.17+ x86-64 Details
dag_ml-0.3.32-cp311-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl CPython 3.11 abi3 Linux glibc 2.17+ ARM64 Details
dag_ml-0.3.32-cp311-abi3-macosx_11_0_arm64.whl CPython 3.11 abi3 macOS 11.0+ ARM64 Details
dag_ml-0.3.32-cp311-abi3-macosx_10_12_x86_64.whl CPython 3.11 abi3 macOS 10.12+ x86-64 Details

Total release size: 53.5 MB

Release files / dag_ml-0.3.32.tar.gz

Download URL dag_ml-0.3.32.tar.gz
Size 1.1 MB
Tags Source
SHA-256 checksum
How to use checksums
a50fecfc93dad33fabe84a31eb6220bbf64c974964cbc538d1bf06772bfc2c65
BLAKE2b-256 checksum
How to use checksums
9b447ed9fc5ba5f1df3c7b8e2c29c7ab0b40b55028d5bef0bb8a9ecce6f8d3a3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / dag_ml-0.3.32-cp311-abi3-win_amd64.whl

Download URL dag_ml-0.3.32-cp311-abi3-win_amd64.whl
Size 10.2 MB
Tags CPython 3.11 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
0b0c6a9ebb8446f288701cd5b98e9b1578f6d6fdf06114a1cd3c33cb7cb9c6a5
BLAKE2b-256 checksum
How to use checksums
266b954e7b852424ac4b8ea9eab1decf2150e70b03367d1a630b8365468f578c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / dag_ml-0.3.32-cp311-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL dag_ml-0.3.32-cp311-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 11.0 MB
Tags CPython 3.11 Linux glibc 2.17+ x86-64 abi3
SHA-256 checksum
How to use checksums
1963f67b709765f7766e235a6418b0cdc160d5a38bc870020625e5183fcea3b2
BLAKE2b-256 checksum
How to use checksums
46cd055a8ac02a5b4983493dc7bf887646f35be8b153859939456c129ccec118
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / dag_ml-0.3.32-cp311-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl

Download URL dag_ml-0.3.32-cp311-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Size 11.0 MB
Tags CPython 3.11 Linux glibc 2.17+ ARM64 abi3
SHA-256 checksum
How to use checksums
6dd3513c4d37b665956732433e529e22700f247801fec15e268ed0a68d5be4c8
BLAKE2b-256 checksum
How to use checksums
6b15429ff90c72f3cc316e7024cb102ab38c5625be108d0371d67d88d5b9e793
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / dag_ml-0.3.32-cp311-abi3-macosx_11_0_arm64.whl

Download URL dag_ml-0.3.32-cp311-abi3-macosx_11_0_arm64.whl
Size 9.9 MB
Tags CPython 3.11 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
ddb8210c9405778a198675641f97431b6bea95686318d2cc97051b9af1f877e6
BLAKE2b-256 checksum
How to use checksums
c4837326c8f0b6595b7594c3c9ba843f9dea47dcdd377818a06b48e83f24db93
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / dag_ml-0.3.32-cp311-abi3-macosx_10_12_x86_64.whl

Download URL dag_ml-0.3.32-cp311-abi3-macosx_10_12_x86_64.whl
Size 10.4 MB
Tags CPython 3.11 abi3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
4ab8cdfa8c54edd291f95b0748f07bd989443248c21dd53b28889c524545d45b
BLAKE2b-256 checksum
How to use checksums
49bd7838cc5122ca29e994499fbd5cc4a36b9813f712010e8430d93d06fa784c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.3.32 This release

6 release files

0.3.30

6 release files

0.3.29

6 release files

0.3.28

6 release files

0.3.27

6 release files

0.3.26

6 release files

0.3.22

6 release files

0.3.21

6 release files

0.3.20

6 release files

0.3.19

6 release files

0.3.18

6 release files

0.3.17

6 release files

0.3.16

6 release files

0.3.15

6 release files

0.3.14

6 release files

0.3.13

6 release files

0.3.11

6 release files

0.3.10

6 release files

0.3.9

6 release files

0.3.8

6 release files

0.3.7

6 release files

0.3.6

6 release files

0.3.5

6 release files

0.3.4

6 release files

0.3.3

6 release files

0.3.2

6 release files

0.3.0

6 release files

0.2.7

6 release files

0.2.6

6 release files

0.2.5

6 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page