sayfirstd — the operator surface
This distribution is the command the operator of a daemon of this repository types. It inspects; it starts nothing.
sayfirstd plugins list --config /etc/sayfirst/plugins.toml
sayfirstd whoami --socket /run/sayfirst/daemon.sock --mode system --daemon-user sayfirst
sayfirstd status --socket /run/sayfirst/daemon.sock --mode system --daemon-user sayfirst
sayfirstd conformance replay --socket allow=/run/conformance/allow.sock
whoami and status take --socket as an option: given none, a per-user
profile is looked for at the per-user default address — the one a per-user
daemon given no address serves at, sayfirst-daemon up --quickstart included —
so sayfirstd status alone asks that daemon. A system profile always names its
socket and the account the daemon runs as, as the two lines above do for a
system daemon running as sayfirst. Without --mode system --daemon-user, a
profile is per-user: it expects the daemon to run as the account asking, and a
system daemon at that address is refused as server_not_the_daemon_principal
before a byte is sent (exit 4).
The three names
The distribution is sayfirstd, the import package is sayfirstd, and the
console script is sayfirstd. One name in all three forms, held by
tests/test_client_distribution_names.py against the [project] tables and
against the source tree.
The distribution sayfirst-cli, the import package sayfirst_cli and the
console script sayfirst were claimed here until 2026-09-05. Two repositories
claimed them, and the operator settled it: in all three forms they belong to the
product command-line interface, and are not published from this repository.
Nothing had been published under either claim (article 0), so the collision was
a fact about two source trees and is now closed in both.
sayfirst remains the project's public name wherever it names the product
— article 0, TRADEMARKS.md, the contract's attribute namespace, the sibling
distributions sayfirst-contract, sayfirst-control-plane,
sayfirst-conformance and sayfirst-testing. Only the three claims moved.
Why sayfirstd
The conventional Unix shape: the daemon and the commands that inspect it share
one binary. Article 6's whoami, article 7's status and article 8's
plugins list all ask the daemon about itself, so they belong with it.
What starts the daemon
Not this. sayfirst-daemon serve, from the sayfirst-control-plane
distribution, starts it. The two are not yet one binary because folding serve
in would make this distribution depend on the server it inspects, and article
14 points the dependency the other way: this package depends on
sayfirst-contract and on nothing else of this repository, which
packages/cli/tests/test_plugins_list.py holds. A remote operator forwards a
socket over SSH and inspects a daemon on a host where this wheel is the only
one installed (docs/deployment.md); a fold would put the whole server in that
install.
What it answers, and what it forwards
plugins list is answered here: it reports configured selections against
discovered package metadata and against a recorded composition, and it claims no
provider is active that bootstrap would refuse. whoami, status and
conformance replay are handed whole to sayfirst-contract, which implements
them, so their parsers and exit codes stay in one place.
status reads the daemon's own account of itself over the same verified
connection whoami uses: the integrity grade of article 7 with its basis and
the interval it is re-evaluated on, the active privacy provider of article 11,
and whether evidence is being delivered. Each of those has a value for "the
daemon did not report it", and the command renders that value rather than a
plausible one (article 2).
Metadata
Release files for sayfirstd 0.3.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| sayfirstd-0.3.3.tar.gz | 14.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| sayfirstd-0.3.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 25.6 kB
Release files / sayfirstd-0.3.3.tar.gz
| Download URL | sayfirstd-0.3.3.tar.gz |
|---|---|
| Size | 14.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
790e66761930b1372d45028c408b6ae6e339c307c1408bf7cd8714a96573c7be
|
|
BLAKE2b-256 checksum How to use checksums |
e8fda3fb25cbd8fb86cb261d49028158446caade84834c4097de6cbb0bf47120
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency logRelease files / sayfirstd-0.3.3-py3-none-any.whl
| Download URL | sayfirstd-0.3.3-py3-none-any.whl |
|---|---|
| Size | 11.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a2beb614e07587fdd87eda7182462f4b7b5aba17679e059f4a7dbdc9ccf7c22a
|
|
BLAKE2b-256 checksum How to use checksums |
ce5a9ca0ac30f9a7d11098141e9d709dd2e165304ec16cc3fcd73e7503ab8c81
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency log