Repository navigation
Pick pure pypi lock wheels through one shared portability rule (#1150) - #1151
Merged
Mikola Lysenko (mikolalysenko) merged 2 commits intoOct 8, 2026
Merged
Conversation
Assisted-by: Claude Code:claude-opus-5-5
Lock inventory picked a pypi package's "pure" wheel with its own `-none-any.whl` suffix check, so a uv.lock or poetry.lock whose only pinned wheel is cp311-, pp310- or py2-none-any was resolved as fetchable while vendored mode, the hosted redirect and ledger recovery call the same wheel platform-locked (#1048). The uv/PEP 751 inventory and ledger recovery now share one `portable_wheel_artifact` pick, and the poetry reader classifies its file names through `is_portable_wheel_url`. Both suffix checks and recovery's copy of the pick are gone. A table test runs every former caller over the wheel shapes where the rules differed. Fixes #1150 Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko)
marked this pull request as ready for review
October 8, 2026 17:16
Collaborator
Author
|
BugBot review Generated by Claude Code |
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 8, 2026
Tanmay Singla (Tanmay182003)
approved these changes
Oct 8, 2026
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 964f429. Configure here.
Collaborator
Author
|
Burn-down agent: labeled Ready for review at head
Generated by Claude Code |
Mikola Lysenko (mikolalysenko)
deleted the
arch-refactor/1150-shared-wheel-pick
branch
October 8, 2026 21:05
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by Claude Code:claude-opus-5-5
Fixes #1150
Summary
Lock inventory decided a pypi package's "pure" wheel with its own
-none-any.whlsuffix check (twice: uv/PEP 751 and poetry). Since #1053, the shared classifier (pypi_distribution::wheel_platform_from_filename, #1048) callscp311-,pp310-andpy2-none-anywheels platform-locked, and vendored mode, the hosted redirect and (since #1121) ledger recovery follow it. Inventory didn't, so a lock whose only pinned wheel had one of those tags was resolved as fetchable. Now every lock reader goes through one rule and one pick.Why (leverage)
Register row E89 (living document §6,
doc/06-discovery-vex.md), the slice #1121 left open. B 1 (#1150), U 0, D 2 (two suffix checks; the inventory/recovery wheel pick written twice), S 0, R L. Every file is free of openarch-refactor/*andagent/fix-*PRs (#1058, anarch-fix/*PR, touches a different hunk oflock_inventory/pypi.rs).What changed
lock_inventory/pypi.rs: newportable_wheel_artifact(package, keys):package_artifacts→is_portable_wheel_url→http_url→ that artifact's sha256. The uv/PEP 751 inventory calls it witharchive/wheels/wheel. Poetry'sfiles/[metadata.files]names are classified throughis_portable_wheel_url.lock_inventory/recover.rs:pure_wheel_from_uv_unitkeeps its unit parsing and calls the same pick witharchive/wheels/wheel/files(keys unchanged).Deleted
python_package_archive(inventory's copy of the pick) and recovery's inline copy of it.ends_with("-none-any.whl")checks; no copy remains in productionlock_inventory.git diff --stat: productionpypi.rs+25 / −14 (4 of the + lines declare the test module),recover.rs+5 / −18, so net −2 production lines; tests +101 (lock_inventory/pypi_wheel_tests.rs, a sibling module, becauselock_inventory/tests.rsis changed by an open PR).Behavior
uv / PEP 751 / poetry lock inventory no longer resolves or hash-pins a
cp*-none-any,pp*-none-anyorpy2-none-anywheel (the entry stays discovery-only,integrity: None), which matches vendored, hosted and recovery. A wheel name the classifier can't parse (fewer than three tags) is no longer called pure. Nothing else changes: portable wheels (py3,py2.py3,pyXY) and?query/#fragmentstripping work as before, and recovery's keys and fail-closed behavior are unchanged.Test evidence
pypi_wheel_tests.rsrun uv inventory, poetry inventory and ledger recovery over 8 wheel shapes (including the ones where the suffix rule and the classifier differed) and pin them towheel_platform_from_filename, plus a query/fragment case.main(red):uv_inventory_and_ledger_recovery_pick_the_same_wheels:inventory, six-1.16.0-cp311-none-any.whl: left Some(".../six-1.16.0-cp311-none-any.whl") right None;poetry_inventory_pins_only_a_portable_wheel:left Sha256Hex(..) right None.cargo clippy --workspace --all-features -- -D warnings: clean.cargo test -p socket-patch-core --lib: 5784 passed, 4 failed. Those 4 are the known root-only sandbox failures (copy_tree::relax_loop_must_not_traverse_symlinked_root,vlt_heal::an_unremovable_hidden_lock_keeps_every_store_entry,pypi_poetry::wire_write_failure_maps_error_and_leaves_lock_untouched,pypi_requirements::wire_failure_rolls_back_already_written_files), and they fail onmaintoo.in_process_vendor_pypi_takeover6/6,in_process_redirect_poetry7/7,hosted_superseding_pypi4/4,mode_migration_pypi40/41. The one failure,pipenv_hosted_to_vendored_names_the_unpatched_requirements, fails identically onmainin this sandbox because it needs a GET to pypi.org, which the sandbox doesn't allow.Risk
Low. The change is confined to wheel selection in lock inventory and recovery, and the only behavior change is the documented convergence with the #1048 classifier.
🤖 Generated with Claude Code
https://claude.ai/code/session_01LERMTm6HLt9J1WNEqVJUui
Note
Low Risk
Scope is wheel selection in lock inventory and recovery only; behavior aligns with the existing #1048 classifier already used in vendored and hosted paths.
Overview
PyPI lock inventory and ledger recovery no longer treat wheels as “pure” via a
-none-any.whlfilename suffix. They shareportable_wheel_artifact, which usesis_portable_wheel_url(same rule as vendored/hosted mode).python_lock_inventory(uv / PEP 751) and poetryfiles/ metadata hashing now only resolve or pin wheels the classifier considers portable (e.g.py3-none-any,py2.py3-none-any). Interpreter-taggedcp*/pp*-none-any,py2-none-any, and unparseable tag triples stay discovery-only with no integrity pin.pure_wheel_from_uv_unitin recovery delegates to the same helper instead of duplicating the pick.New
pypi_wheel_tests.rslocks uv inventory, poetry inventory, recovery, and the classifier to the same wheel table, including URLs with?/#suffixes.Reviewed by Cursor Bugbot for commit 964f429. Configure here.