Skip to content

Fix PyPI package specs ignoring PEP 503 spellings (#910) - #911

Open
Mikola Lysenko (mikolalysenko) wants to merge 4 commits into
mainfrom
agent/fix-policy-pypi-name-normalize
Open

Mikola Lysenko (mikolalysenko) wants to merge 4 commits into
mainfrom
agent/fix-policy-pypi-name-normalize

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

Fixes #910

Summary

socket.yml patches.ignorePackages / patches.packages, scan --package and get's policy check now match PyPI packages by their PEP 503 canonical name. A spec written typing_extensions, Typing_Extensions, typing.extensions or pkg:pypi/typing_extensions now names pkg:pypi/typing-extensions, the same way pip treats them.

Root cause

policy::package_spec_matches is the one matcher behind all four of those entry points. It compared names with to_lowercase() only. Every PyPI purl socket-patch builds is canonical (_ / . / - runs become -), so a spec spelled with _ or . never matched:

  • ignore list failed open: the exclusion was silently dropped, and the hosted scan still rewrote requirements.txt. That is a policy bypass.
  • allowlist and --package failed closed: nothing was selected, with no hint that the spelling was the cause.

Fix

  • For pkg:pypi/ purls, the matcher canonicalizes the name of both the target purl and a purl spec (canonical_pypi_purl), and a bare spec compares with canonicalize_pypi_name.
  • Other ecosystems are unchanged: left_pad still does not match pkg:npm/left-pad, and cfg_if still does not match pkg:cargo/cfg-if.
  • CLI_CONTRACT.md's --package row now documents the PyPI rule.
  • No wrapper changes are needed: npm/, pypi/ and gem/ only dispatch to the binary.

Tests (red → green)

#910 table row Test
ignorePackages typing_extensions / Typing_Extensions / typing.extensions / pkg:pypi/typing_extensions (hosted) policy_pypi_names::hosted_ignore_packages_matches_pep503_spellings
ignorePackages typing_extensions, --mode agent policy_pypi_names::agent_ignore_packages_matches_pep503_spelling
packages allowlist typing_extensions policy_pypi_names::hosted_packages_allowlist_matches_pep503_spelling
scan --package typing_extensions policy_pypi_names::hosted_scan_package_flag_matches_pep503_spelling
canonical spelling (control, already passing) policy_pypi_names::hosted_ignore_packages_canonical_spelling_excludes
unit-level matcher (bare and purl specs, versioned, non-PyPI unchanged) policy::tests::pypi_package_specs_compare_pep503_canonical_names, policy::tests::pypi_ignore_and_allow_lists_use_pep503_names

Without the fix: the 4 new CLI cases and both new unit tests fail; the control passes.

With the fix:

  • cargo test -p socket-patch-cli --all-features --test policy_pypi_names passed, 5/5.
  • cargo test -p socket-patch-core --all-features --lib policy:: passed, 69/69.
  • e2e_socket_yml_policy passed, 24/24, and spawn_env_hygiene passed, 9/9. The new test spawns through hermetic::binary_command.
  • cargo clippy --workspace --all-features -- -D warnings is clean.
  • CI: all 412 check runs on 34051e4 passed or were skipped. Bugbot reviewed 34051e4 and found no issues.

Not run locally:

  • cargo test --workspace --all-features ran out of disk in this sandbox while compiling every test binary, so CI is the full-suite check (green, see above).
  • socket-patch-core --lib has 4 local failures: copy_tree symlinked root, vlt_heal unremovable lock, and two wire_*_failure tests. They depend on chmod 0o555 denials, which root bypasses, and the sandbox runs as uid 0. They pass on CI's non-root runners.

Inherited main failure

Main CI is red: the utils::digest::tests::production_digests_go_through_the_helpers guard fails on the Gradle files, in test, test-release and coverage. Commit 34051e4 ports #878's three-file fix so this PR can go green. It becomes a no-op once #878 lands.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Gf2MHGGcCkPZz7pit6onaT

Assisted-by: Claude Code:claude-opus-5-5
socket.yml `ignorePackages` / `packages`, `scan --package` and get's
policy check compared PyPI names by case only. PyPI purls are PEP 503
canonical (`typing-extensions`), so a spec spelled `typing_extensions`
or `typing.extensions` never matched: an ignore list silently stopped
excluding the package (the hosted scan still rewrote
requirements.txt), and an allowlist or `--package` silently selected
nothing.

Compare PyPI names, in both bare and purl specs, by their PEP 503
canonical form. Other ecosystems keep their exact case-folded names.

Fixes #910

Assisted-by: Claude Code:claude-opus-5-5
Run the #910 repro end to end: a requirements.txt project with
typing_extensions installed, scanned against a mock patch API with
each spec spelling in socket.yml ignorePackages, the packages
allowlist and `scan --package`. Children spawn through the shared
hermetic builder.

Assisted-by: Claude Code:claude-opus-5-5
Main is red: the utils::digest guard test lists the Gradle files
that hash inline. This ports #878's change so this PR's CI can go
green; it becomes a no-op once #878 lands.

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko
Mikola Lysenko (mikolalysenko) marked this pull request as ready for review October 6, 2026 03:49
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 34051e4. Configure here.

@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 6, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Ready for review at head 34051e4.

  • CI: all 8 workflows on 34051e4 passed (CI, Gradle, Composer, npm, pnpm, vlt, Benchmarks, Audit GHA). Base main is still 9c43dfc and the branch merges cleanly.
  • Bugbot: reviewed 34051e4 and found no issues; there are no open review threads.
  • For the reviewer:

Generated by Claude Code

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review

Projects

None yet

2 participants