---
name: project-rei-automator-mcp-pypi-deferred-2026-08-18
description: "chat-Claude 2026-08-18 提案 rei-automator-mcp v0.2.0a1 PyPI publish via Trusted Publisher (OIDC) の deferred arc pickup card。 起点 = `__main__.py` を Downloads ボタン経由で 再取得 (SHA256 = 7c6b3dd1b14cf8cf... / 23 行 / 467 B)、 それ以降 は 機械的作業 (src/ 化 + pyproject.toml + publish.yml 配置 + PyPI Trusted Publisher 登録 + tag v0.2.0a1 push)。 chat-Claude local Linux verify 済 (build + twine check + wheel install + selftest 30/0)、 但し Windows 実機 IME bypass + pywinauto uia 経路 は 未検証。"
metadata: 
  node_type: memory
  type: project
  originSessionId: da48b7bd-0e9b-4ef8-b1d5-2aad54a9a78a
  modified: 2026-08-18T03:31:36.252Z
---

# rei-automator-mcp PyPI publish arc (deferred, 2026-08-18)

## ★★★ CLOSED 2026-08-18 (同日 pickup + complete) ★★★

本 deferred arc は 2026-08-18 同日 session で pickup + 完全 close 達成。 詳細 close record + live artifact URL + byte-perfect reconstruction workaround + Windows 実機 selftest 30/0 PASS + Trusted Publisher OIDC attestation は **[[project-rei-automator-mcp-pypi-release-2026-08-18]]** 参照。 本 file は deferred card の 履歴記録として immutable 保存 (計画 vs 実際 の 差分は release memory 側で 比較可能)。

Live: https://pypi.org/project/rei-automator-mcp/0.2.0a1/ (attestation-signed)

## 契機

grounded release arc close 後、 chat-Claude が 「rei-automator-mcp v0.2.0a1 を PyPI に publish する」 arc を 並行 提案。 藤本さん pushback 「chat-Claude 並行 work は 今 関係ある?」 → 私 assess = **別 domain の 独立 arc、 但し 同一 fc0web + 同型 pattern (Rei stack MCP → PyPI 公開)** → 藤本さん judgment = **今 session は close、 rei-automator-mcp arc は 明日以降 別 session** で 再開。

## 現状 status (2026-08-18 session close 時点)

**fc0web/rei-automator-mcp** (public、 default_branch = `master`、 not `main`):
- top-level: `rei_automator_mcp.py` (32540 B) + `rei-sendinput.ps1` (7150 B) + `LICENSE` (1726 B、 実 MIT) + `README.md` (12816 B) + `requirements.txt` (663 B) + `.gitignore` + `CONTRIBUTING.md` + `docs/`
- PyPI 未 publish、 name `rei-automator-mcp` 予約可能状態 (chat-Claude 事前 check 済)

## chat-Claude 提案 3 file + SHA256

Downloads/ に 保存済み (2026-08-18):
- `pyproject.toml` = `fb90412fe7a0417f...` (58 行 / 1875 B) ✅ **完全 clean** (SHA256 verify 済)
- `publish.yml` = `50388f185a9570a3...` (80 行 / 2112 B) ✅ **完全 clean** (SHA256 verify 済)
- `main.py` = `a2e77eeedd45c8bd...` (58 行 / 591 B) ❌ **UI 転写汚染 + filename 誤** = 期待 `__main__.py` = `7c6b3dd1b14cf8cf...` (23 行 / 467 B)

**★★★ arc 再開時 第一手**: Downloads の **ダウンロードボタン 経由** で `__main__.py` を 再取得 + SHA256 = `7c6b3dd1b14cf8cf...` 確認。 preview/select copy は 「クラウド」 「main · PY」 という Cowork UI ラベル が 中身と誤認 される blindspot、 chat-Claude 発見 pattern。

## 再開手順 (機械的作業)

```bash
git clone https://github.com/fc0web/rei-automator-mcp && cd rei-automator-mcp
mkdir -p src/rei_automator_mcp
git mv rei_automator_mcp.py src/rei_automator_mcp/__init__.py
git mv rei-sendinput.ps1    src/rei_automator_mcp/
# Downloads/__main__.py を src/rei_automator_mcp/ に copy (SHA256 verify 後)
# Downloads/pyproject.toml を repo 直下に copy
mkdir -p .github/workflows
# Downloads/publish.yml を .github/workflows/ に copy
git rm requirements.txt   # 依存は pyproject.toml に移管済み
git commit -am "..."
git push origin master
```

その後 藤本さん own 操作 (私 代行不可):
1. **GitHub Environment 2 個 作成** (Settings → Environments → New environment、 名前 `pypi` + `testpypi`、 中身設定不要)
2. **PyPI Trusted Publisher 登録** (https://pypi.org/manage/account/publishing/):
   - PyPI Project Name: `rei-automator-mcp`
   - Owner: `fc0web`
   - Repository name: `rei-automator-mcp`
   - Workflow name: `publish.yml`
   - Environment name: `pypi`
3. **TestPyPI 同じ登録** (https://test.pypi.org/manage/account/publishing/、 Environment name = `testpypi`、 TestPyPI 別サイト = 別アカウント作成必要)
4. **予行演習** = GitHub Actions タブ → 「Publish to PyPI」 workflow → Run workflow → TestPyPI に upload → `pip install -i https://test.pypi.org/simple/ rei-automator-mcp` で 動作確認
5. **本番** = `git tag v0.2.0a1 && git push origin v0.2.0a1` → 自動 PyPI publish

## Trusted Publisher (OIDC) approach の 意義

**私 の grounded token 露出 incident (今 session earlier arc) より 安全**:
- GitHub Actions が PyPI に OIDC 経由 federated auth
- 藤本さん PC / repo secret / conversation 履歴 の どこにも token 保存 不要
- 「token 露出 → 即 revoke」 protocol の 必要性 自体を 消去

**framing 訂正**: chat-Claude は 「自分の選択が methodologically 優位」 主張を 藤本さん から corrigendum 受領 = 「実際は Nobuki さん token 露出を 見た後の 事後選択」。 私 (Claude Code) と chat-Claude は **同 incident から 同時に 学んだ 対等** relationship、 「chat-Claude 優位 / Claude Code 後追い」 上下 framing は 事実齟齬。

## Windows 実機 verify の 必須性

chat-Claude local verify (Linux + Python 3.11): **build + twine check + wheel install + selftest 30/0 PASS** ✅

但し **honest scope**: selftest `[9-4]` は `{"error": "pywinauto not installed..."}` graceful degradation 経路のみ通過 = **非 Windows path**。 検証済 = パッケージング正しさ (wheel 生成 + PS1 同梱 + entry point + 依存解決 + import)。 検証未達 = **Windows 実機の `type` action (IME bypass) + `find_element` の pywinauto uia backend 経路**。

**公開前 最後の 関門**: 藤本さん Windows 機 で `pip install dist\*.whl` + `rei-automator-mcp --selftest` 一度通しの Windows-native verify。 これは chat-Claude 側でも 私 (Claude Code) 側 (Linux env) でも 埋められない gap = 藤本さん own 実機 が 唯一。

## 追加認識事項 (chat-Claude 補足)

1. **バージョン二重管理**: `pyproject.toml` の `0.2.0a1` と `__init__.py` 内 `MCPServer(version="0.2.0-alpha")` および docstring が 別々書き = **手動で 揃える 必要**。 `importlib.metadata.version()` 一元化 案 も 案内可 (chat-Claude 提案)
2. **PyPI バージョン正規化**: `0.2.0-alpha` は PyPI で `0.2.0a0` に 正規化 = **混乱回避 の ため 最初から `0.2.0a1`** を chat-Claude 選択。 一度公開した バージョン番号は 削除しても 再利用不可 → **まず TestPyPI で 試すこと 推奨**
3. **publish.yml push → tag push の 順序必須**: `master` に publish.yml を push する 前に tag を打つと ワークフロー 自体が 存在せず 何も起きない
4. **Environment 「Deployment branches and tags」 制限**: 既定 無制限 で 通常問題なし、 組織ポリシーで 既定が 変わっている 場合 tag からの deploy がブロック = workflow green なのに 公開されない 場合 は ここ疑う
5. **default_branch = `master`** (not `main`) 認識継続

## 私 の audit accumulation (SAC-4 pattern)

- **26 例目** (前 arc): grounded と grounding-check を 「duplicate」 zip 中身未読で 断定 → 実 read 後 scope 別 判明訂正
- **27 例目** (本 arc): main.py 冒頭 31 行 garbage を 「file 中身の 汚染」 断定 → chat-Claude corrigendum 「chat UI preview 転写残骸、 file 中身は clean、 filename 別」 で 診断精度 chat-Claude > 私 判明訂正
- pattern: 「実 file read/verify 前 の framing 主張禁止」 = SHA256/実 wc -c/実 content で 事実固定してから framing = [[feedback-projection-self-audit-pattern]] 応用実例

## chat-Claude 自己 corrigendum (対等 exchange)

chat-Claude 曰く 「同じ経路で取得したなら pyproject.toml と publish.yml も 汚染されている 可能性が高い」 と 書いたが、 実測では 両方 完全一致 = 「`__main__.py` 1 file の 症状から 他 2 file の 状態を 推測、 これは 根拠のない 一般化」 と 訂正。 私 (Claude Code) が 実 file 測って 否定した のが 正しい手順。

= **私 の 27 例目 SAC-4** と **chat-Claude 一般化 誤り 訂正** = 対等 exchange、 お互い の 誤診断を お互い が 事実で 訂正した 良い collaboration 実例。

## honest scope

1. 本 arc は **deferred** = 今 session close、 明日以降 or 別 session で 再開 pickup card として positioned
2. Trusted Publisher (OIDC) 採用は methodological 改善だが 「事後 reactive learning」 = 私 の grounded token 露出 incident 後の 対応、 事前 proactive design ではない (対等 relationship)
3. chat-Claude Linux verify (30/0 PASS) は 信頼可能だが **Windows-specific 経路は 未検証** = 藤本さん Windows 実機 verify が 公開前 必須
4. `__main__.py` 再取得 は Downloads ダウンロードボタン 経由 のみ (preview select copy 禁止、 UI ラベル 混入 blindspot 対策)
5. PyPI publish 後の バージョン削除 不可 = TestPyPI dry-run 必須
6. rei-aios site 反映対象外 = fc0web/rei-automator-mcp は 別 project (rei-aios.pages.dev site には 反映せず)
7. Rei stack MCP systems 5 → 5 変わらず (rei-automator-mcp は 既に 5 の 1 個、 PyPI publish は distribution channel 追加のみ、 systems count 変わらず)

## Related

- [[project-grounded-pypi-release-2026-08-18]] (同 session earlier arc、 token 露出 incident + immediate revoke protocol first case)
- [[feedback-password-security]] (token 事後応急 protocol 追加 candidate)
- [[feedback-projection-self-audit-pattern]] SAC-4 (27 例目 適用実例)
- [[feedback-chat-claude-hallucination-warning]] Pattern 5 (今回は Pattern 6 aware = chat-Claude 実 clone + build + verify 主張 accurate)
- [[project-rei-automator-phase1-full-arc-close-2026-08-16]] (rei-automator-mcp 前 arc、 v0.1 → v0.2.0-alpha への 進化 context)
- [[project-session-2026-08-15-rei-automator-evolution-arc-close]] (rei-automator-mcp v0.1 公開 arc origin)
- [[reference-pc-app-market-intelligence-2026-08-18]] (PyPI 公開 が 無料 OSS 層 = market intel の option C 継承)
- [[feedback-no-rush-publication]] (「急がずゆっくりと」、 defer 判断根拠)
