Skip to content

Fix get <name> missing PyPI names spelled with _ or . (#926) - #927

Merged
Mikola Lysenko (mikolalysenko) merged 3 commits into
mainfrom
agent/fix-get-pypi-name-normalize
Oct 7, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 3 commits into
mainfrom
agent/fix-get-pypi-name-normalize

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

Fixes #926

Root cause

crawlers::fuzzy_match::fuzzy_match_packages, which powers socket-patch get <name>, lowercases the query and the crawled names and compares them as strings. The Python crawler stores PyPI names after canonicalize_pypi_name (PEP 503: lowercased, with each run of -_. collapsed to -). So ruamel.yaml, typing_extensions and Typing.Extensions can never match ruamel-yaml / typing-extensions. get then prints "No packages matching" (status: no_match) and exits 0.

Fix

Why this cluster

This is a P1 (pip) correctness bug with a contained fix. The older P1 issues I checked either need a maintainer design call (#371: whether to add trustedDependencies or to warn) or overlap open PRs. #910 has the same wrong assumption in a different function, and #911 already fixes it.

Tests (red → green)

  • crawlers::fuzzy_match::tests::test_pypi_query_is_pep503_canonicalized, test_pypi_separator_spelling_ranks_as_exact, test_pypi_prefix_and_contains_use_canonical_form: all 3 failed on main and pass with the fix. test_npm_names_keep_their_separators guards the npm behavior.
  • in_process_get::get_package_name_matches_pypi_spellings_pip_accepts: get ruamel.yaml / ruamel_yaml / Ruamel.YAML against a venv fixture failed on main (no manifest written, no_match) and passes with the fix. It saves pkg:pypi/ruamel-yaml@0.18.6 after searching by the canonical PURL.
Issue Test
#926 fuzzy_match::tests::test_pypi_*, in_process_get::get_package_name_matches_pypi_spellings_pip_accepts

Local results

  • cargo clippy --workspace --all-features -- -D warnings: clean.
  • cargo test -p socket-patch-core --all-features: 5250 passed. 4 failed, all read-only-directory tests (copy_tree, vlt_heal, pypi_poetry, pypi_requirements) that can't fail as expected because the sandbox runs as root (uid 0 bypasses 0o555). They're unrelated to this change, and CI runs them as non-root.
  • cargo test -p socket-patch-cli --all-features --lib --test get --test in_process_get --test covgap_commands_get --test in_process_get_hosted_ecosystems: 1041 passed, 0 failed.
  • The full cargo test --workspace couldn't link every CLI test binary within the sandbox's disk allowance, so CI covers the rest.
  • cargo fmt --check: the files this PR touches are rustfmt-clean. main already has unformatted files elsewhere, and CI doesn't run fmt.

🤖 Generated with Claude Code


Note

Low Risk
User-facing change is a targeted fuzzy-match fix for PyPI with regression tests; digest call sites are a mechanical swap to shared helpers with unchanged semantics.

Overview
Fixes #926 so socket-patch get <name> resolves installed PyPI packages when the user types the same spellings pip uses (ruamel.yaml, ruamel_yaml, mixed case), not only the PEP 503 form stored by the crawler (ruamel-yaml).

Package matching: fuzzy_match_packages now PEP 503-canonicalizes the query and PyPI crawled names (via existing canonicalize_pypi_name) for exact, prefix, and contains matches. npm and other ecosystems still use case-insensitive string compare so _ and . stay distinct.

Tests: New unit tests in fuzzy_match and an in-process get test with a minimal .venv dist-info fixture assert exit 0, manifest save, and API search by canonical PURL.

Digest helpers: Gradle cache, JVM jar swap/rollback, and Maven sidecar SHA1 paths call utils::digest::sha1_hex_of / sha256_hex_of instead of ad-hoc sha1/sha2 + hex::encode (aligned with #878).

Reviewed by Cursor Bugbot for commit 61b720c. Configure here.


Generated by Claude Code

Assisted-by: Claude Code:claude-opus-5-5
`socket-patch get ruamel.yaml` (or `typing_extensions`, or
`Typing.Extensions`) reported "No packages matching" and exited 0
for an installed, patchable package. The package-name search only
lowercased the query, but the crawler stores PyPI names in PEP 503
form (`ruamel-yaml`), so any spelling with `.`, `_` or a run of
separators never matched. Users who copy a name from
requirements.txt or `pip list` were told nothing could be patched.

PyPI packages are now compared with both the query and the name
canonicalized per PEP 503, for exact, prefix and contains matches.
npm and other ecosystems keep the plain case-insensitive compare,
since `_` and `.` are distinct characters in their names.

Fixes #926

Assisted-by: Claude Code:claude-opus-5-5
main has failed socket-patch-core's lib tests since Gradle support
(#646) and the digest helpers (#865) both landed. The guard test
production_digests_go_through_the_helpers flags three files #646 added
that still hash inline: crawlers/gradle_cache.rs, patch/jvm_jar.rs and
patch/sidecars/maven.rs. That breaks test, test-release and coverage on
every open PR.

Each inline sha1/sha256 call now goes through sha1_hex_of or
sha256_hex_of, which compute the same lowercase hex. Behaviour is
unchanged.

Assisted-by: Claude Code:claude-opus-5-5
(cherry picked from commit 659ac2c)
@mikolalysenko
Mikola Lysenko (mikolalysenko) marked this pull request as ready for review October 6, 2026 09:07
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 61b720c. Configure here.

@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 6, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[agent] Ready for review at 61b720c.

  • CI: 412/412 check runs green or skipped on 61b720c; branch is 0 commits behind main, no conflicts.
  • Bugbot: reviewed 61b720c, no findings.
  • Reviewer focus: fuzzy_match_packages now PEP 503-canonicalises PyPI queries and names only; npm and other ecosystems keep case-insensitive compare. The digest-helper swaps in the Gradle/JVM/Maven files are the same mechanical change as Route Gradle digests through utils::digest #878.
  • Slack: not announced. This session's Slack connector can only read, so the next run should retry.

Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review

Projects

None yet

3 participants