Fix PyPI package specs ignoring PEP 503 spellings (#910) - #911
Open
Mikola Lysenko (mikolalysenko) wants to merge 4 commits into
Open
Mikola Lysenko (mikolalysenko) wants to merge 4 commits into
Mikola Lysenko (mikolalysenko) wants to merge 4 commits into
Conversation
Assisted-by: Claude Code:claude-opus-5-5
socket.yml `ignorePackages` / `packages`, `scan --package` and get's policy check compared PyPI names by case only. PyPI purls are PEP 503 canonical (`typing-extensions`), so a spec spelled `typing_extensions` or `typing.extensions` never matched: an ignore list silently stopped excluding the package (the hosted scan still rewrote requirements.txt), and an allowlist or `--package` silently selected nothing. Compare PyPI names, in both bare and purl specs, by their PEP 503 canonical form. Other ecosystems keep their exact case-folded names. Fixes #910 Assisted-by: Claude Code:claude-opus-5-5
Run the #910 repro end to end: a requirements.txt project with typing_extensions installed, scanned against a mock patch API with each spec spelling in socket.yml ignorePackages, the packages allowlist and `scan --package`. Children spawn through the shared hermetic builder. Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko)
marked this pull request as ready for review
October 6, 2026 03:49
Collaborator
Author
|
BugBot review Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 34051e4. Configure here.
Collaborator
Author
|
Ready for review at head
Generated by Claude Code |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by Claude Code:claude-opus-5-5
Fixes #910
Summary
socket.yml
patches.ignorePackages/patches.packages,scan --packageandget's policy check now match PyPI packages by their PEP 503 canonical name. A spec writtentyping_extensions,Typing_Extensions,typing.extensionsorpkg:pypi/typing_extensionsnow namespkg:pypi/typing-extensions, the same way pip treats them.Root cause
policy::package_spec_matchesis the one matcher behind all four of those entry points. It compared names withto_lowercase()only. Every PyPI purl socket-patch builds is canonical (_/./-runs become-), so a spec spelled with_or.never matched:requirements.txt. That is a policy bypass.--packagefailed closed: nothing was selected, with no hint that the spelling was the cause.Fix
pkg:pypi/purls, the matcher canonicalizes the name of both the target purl and a purl spec (canonical_pypi_purl), and a bare spec compares withcanonicalize_pypi_name.left_padstill does not matchpkg:npm/left-pad, andcfg_ifstill does not matchpkg:cargo/cfg-if.CLI_CONTRACT.md's--packagerow now documents the PyPI rule.npm/,pypi/andgem/only dispatch to the binary.Tests (red → green)
ignorePackagestyping_extensions/Typing_Extensions/typing.extensions/pkg:pypi/typing_extensions(hosted)policy_pypi_names::hosted_ignore_packages_matches_pep503_spellingsignorePackagestyping_extensions,--mode agentpolicy_pypi_names::agent_ignore_packages_matches_pep503_spellingpackagesallowlisttyping_extensionspolicy_pypi_names::hosted_packages_allowlist_matches_pep503_spellingscan --package typing_extensionspolicy_pypi_names::hosted_scan_package_flag_matches_pep503_spellingpolicy_pypi_names::hosted_ignore_packages_canonical_spelling_excludespolicy::tests::pypi_package_specs_compare_pep503_canonical_names,policy::tests::pypi_ignore_and_allow_lists_use_pep503_namesWithout the fix: the 4 new CLI cases and both new unit tests fail; the control passes.
With the fix:
cargo test -p socket-patch-cli --all-features --test policy_pypi_namespassed, 5/5.cargo test -p socket-patch-core --all-features --lib policy::passed, 69/69.e2e_socket_yml_policypassed, 24/24, andspawn_env_hygienepassed, 9/9. The new test spawns throughhermetic::binary_command.cargo clippy --workspace --all-features -- -D warningsis clean.Not run locally:
cargo test --workspace --all-featuresran out of disk in this sandbox while compiling every test binary, so CI is the full-suite check (green, see above).socket-patch-core --libhas 4 local failures:copy_treesymlinked root,vlt_healunremovable lock, and twowire_*_failuretests. They depend onchmod 0o555denials, which root bypasses, and the sandbox runs as uid 0. They pass on CI's non-root runners.Inherited main failure
Main CI is red: the
utils::digest::tests::production_digests_go_through_the_helpersguard fails on the Gradle files, intest,test-releaseandcoverage. Commit 34051e4 ports #878's three-file fix so this PR can go green. It becomes a no-op once #878 lands.🤖 Generated with Claude Code
https://claude.ai/code/session_01Gf2MHGGcCkPZz7pit6onaT