[agent] Filed by the scheduled architecture refactor routine. Register: E89 (the slice #1079 / #1121 left open).
Kind: bug (duplicated predicate). Source: register E89, remainder after #1121.
Problem
Verified on main 30a45b3. The "is this a pure wheel" rule is still written three times in vendor/lock_inventory:
python_package_archive (inventory) and recover::pure_wheel_from_uv_unit (recovery) are also the same package_artifacts → portable → http_url → sha256 pick written twice, differing only in the artifact keys and the portability rule.
Symptoms
A uv.lock (or poetry.lock) whose only hash-pinned wheel is six-1.16.0-cp311-none-any.whl, -pp310-none-any.whl or -py2-none-any.whl:
Test-only repro (on main): uv_inventory_and_ledger_recovery_pick_the_same_wheels → inventory, six-1.16.0-cp311-none-any.whl: left Some(".../six-1.16.0-cp311-none-any.whl") right None; the poetry variant returns Sha256Hex(..) instead of None.
Fix
One portable_wheel_artifact(package, keys) pick in lock_inventory/pypi.rs, used by the uv/PEP 751 inventory and by ledger recovery; the poetry reader classifies its file names through is_portable_wheel_url. Delete both suffix checks.
Acceptance
- No
ends_with("-none-any.whl") left in production lock_inventory.
- A table test runs every wheel shape where the suffix rule and the classifier differ through uv inventory, poetry inventory and recovery, and they agree with
wheel_platform_from_filename.
[agent] Filed by the scheduled architecture refactor routine. Register: E89 (the slice #1079 / #1121 left open).
Kind: bug (duplicated predicate). Source: register E89, remainder after #1121.
Problem
Verified on main
30a45b3. The "is this a pure wheel" rule is still written three times invendor/lock_inventory:pypi_distribution::is_portable_wheel_urllock_inventory/pypi.rs#L313(uv / PEP 751)url.split(['?','#'])…ends_with("-none-any.whl")lock_inventory/pypi.rs#L393(poetry)file.ends_with("-none-any.whl")python_package_archive(inventory) andrecover::pure_wheel_from_uv_unit(recovery) are also the samepackage_artifacts→ portable →http_url→ sha256 pick written twice, differing only in the artifact keys and the portability rule.Symptoms
A uv.lock (or poetry.lock) whose only hash-pinned wheel is
six-1.16.0-cp311-none-any.whl,-pp310-none-any.whlor-py2-none-any.whl:resolved= that URL,integrity= its sha256);cp311-none-anypatched wheel into Pipfile.lock with no warning, sopipenv syncfails on every other Python version (gap in the #932 fix) #1048) and refuse it.Test-only repro (on main):
uv_inventory_and_ledger_recovery_pick_the_same_wheels→inventory, six-1.16.0-cp311-none-any.whl: left Some(".../six-1.16.0-cp311-none-any.whl") right None; the poetry variant returnsSha256Hex(..)instead ofNone.Fix
One
portable_wheel_artifact(package, keys)pick inlock_inventory/pypi.rs, used by the uv/PEP 751 inventory and by ledger recovery; the poetry reader classifies itsfilenames throughis_portable_wheel_url. Delete both suffix checks.Acceptance
ends_with("-none-any.whl")left in productionlock_inventory.wheel_platform_from_filename.