Skip to main content
Yanked

This release has been yanked by its maintainers, and will be ignored by installers, except when explicitly specified.
Consider using release 0.3.3 instead.
Reason given by maintainers: security: fixed in 0.3.2; use 0.3.2 or later

sayfirstd — the operator surface

This distribution is the command the operator of a daemon of this repository types. It inspects; it starts nothing.

sayfirstd plugins list --config /etc/sayfirst/plugins.toml
sayfirstd whoami --socket /run/sayfirst/daemon.sock --mode system --daemon-user sayfirst
sayfirstd status --socket /run/sayfirst/daemon.sock --mode system --daemon-user sayfirst
sayfirstd conformance replay --socket allow=/run/conformance/allow.sock

whoami and status take --socket as an option: given none, a per-user profile is looked for at the per-user default address — the one a per-user daemon given no address serves at, sayfirst-daemon up --quickstart included — so sayfirstd status alone asks that daemon. A system profile always names its socket and the account the daemon runs as, as the two lines above do for a system daemon running as sayfirst. Without --mode system --daemon-user, a profile is per-user: it expects the daemon to run as the account asking, and a system daemon at that address is refused as server_not_the_daemon_principal before a byte is sent (exit 4).

The three names

The distribution is sayfirstd, the import package is sayfirstd, and the console script is sayfirstd. One name in all three forms, held by tests/test_client_distribution_names.py against the [project] tables and against the source tree.

The distribution sayfirst-cli, the import package sayfirst_cli and the console script sayfirst were claimed here until 2026-09-05. Two repositories claimed them, and the operator settled it: in all three forms they belong to the product command-line interface, and are not published from this repository. Nothing had been published under either claim (article 0), so the collision was a fact about two source trees and is now closed in both.

sayfirst remains the project's public name wherever it names the product — article 0, TRADEMARKS.md, the contract's attribute namespace, the sibling distributions sayfirst-contract, sayfirst-control-plane, sayfirst-conformance and sayfirst-testing. Only the three claims moved.

Why sayfirstd

The conventional Unix shape: the daemon and the commands that inspect it share one binary. Article 6's whoami, article 7's status and article 8's plugins list all ask the daemon about itself, so they belong with it.

What starts the daemon

Not this. sayfirst-daemon serve, from the sayfirst-control-plane distribution, starts it. The two are not yet one binary because folding serve in would make this distribution depend on the server it inspects, and article 14 points the dependency the other way: this package depends on sayfirst-contract and on nothing else of this repository, which packages/cli/tests/test_plugins_list.py holds. A remote operator forwards a socket over SSH and inspects a daemon on a host where this wheel is the only one installed (docs/deployment.md); a fold would put the whole server in that install.

What it answers, and what it forwards

plugins list is answered here: it reports configured selections against discovered package metadata and against a recorded composition, and it claims no provider is active that bootstrap would refuse. whoami, status and conformance replay are handed whole to sayfirst-contract, which implements them, so their parsers and exit codes stay in one place.

status reads the daemon's own account of itself over the same verified connection whoami uses: the integrity grade of article 7 with its basis and the interval it is re-evaluated on, the active privacy provider of article 11, and whether evidence is being delivered. Each of those has a value for "the daemon did not report it", and the command renders that value rather than a plausible one (article 2).

Metadata

Release files for sayfirstd 0.3.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sayfirstd 0.3.1
File Size Uploaded
sayfirstd-0.3.1.tar.gz 14.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for sayfirstd 0.3.1
File Interpreter ABI Platform
sayfirstd-0.3.1-py3-none-any.whl Python 3 none any Details

Total release size: 25.6 kB

Release files / sayfirstd-0.3.1.tar.gz

Download URL sayfirstd-0.3.1.tar.gz
Size 14.0 kB
Tags Source
SHA-256 checksum
How to use checksums
263bba5b683a903ae13805ff6bf880b65721c92486feebf478fb258a9dc3caf8
BLAKE2b-256 checksum
How to use checksums
70826b70130c8de928fea93a80d35bcd8f7472e8e74a96fd255a1330f47f81c7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.

Transparency log

Release files / sayfirstd-0.3.1-py3-none-any.whl

Download URL sayfirstd-0.3.1-py3-none-any.whl
Size 11.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5d554f66eeac5d9b154cf8c8d48d009b351c11eeb9fefa5616b0922a51b2d8be
BLAKE2b-256 checksum
How to use checksums
29e72a9460fb04baf5651b1b39abcf586b596500e4322c822f0b7f6be8b23a6b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.

Transparency log

Release history Release notifications | RSS feed

0.3.3

2 release files

0.3.2

2 release files

This release

0.3.1 This release

2 release files

0.3.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page