Repository navigation
Fix get <name> missing PyPI names spelled with _ or . (#926) - #927
Merged
Mikola Lysenko (mikolalysenko) merged 3 commits intoOct 7, 2026
Merged
Conversation
Assisted-by: Claude Code:claude-opus-5-5
`socket-patch get ruamel.yaml` (or `typing_extensions`, or `Typing.Extensions`) reported "No packages matching" and exited 0 for an installed, patchable package. The package-name search only lowercased the query, but the crawler stores PyPI names in PEP 503 form (`ruamel-yaml`), so any spelling with `.`, `_` or a run of separators never matched. Users who copy a name from requirements.txt or `pip list` were told nothing could be patched. PyPI packages are now compared with both the query and the name canonicalized per PEP 503, for exact, prefix and contains matches. npm and other ecosystems keep the plain case-insensitive compare, since `_` and `.` are distinct characters in their names. Fixes #926 Assisted-by: Claude Code:claude-opus-5-5
main has failed socket-patch-core's lib tests since Gradle support (#646) and the digest helpers (#865) both landed. The guard test production_digests_go_through_the_helpers flags three files #646 added that still hash inline: crawlers/gradle_cache.rs, patch/jvm_jar.rs and patch/sidecars/maven.rs. That breaks test, test-release and coverage on every open PR. Each inline sha1/sha256 call now goes through sha1_hex_of or sha256_hex_of, which compute the same lowercase hex. Behaviour is unchanged. Assisted-by: Claude Code:claude-opus-5-5 (cherry picked from commit 659ac2c)
Mikola Lysenko (mikolalysenko)
marked this pull request as ready for review
October 6, 2026 09:07
Collaborator
Author
|
BugBot review Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 61b720c. Configure here.
Collaborator
Author
|
[agent] Ready for review at
Generated by Claude Code |
Tanmay Singla (Tanmay182003)
approved these changes
Oct 6, 2026
Mikola Lysenko (mikolalysenko)
deleted the
agent/fix-get-pypi-name-normalize
branch
October 7, 2026 12:06
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by Claude Code:claude-opus-5-5
Fixes #926
Root cause
crawlers::fuzzy_match::fuzzy_match_packages, which powerssocket-patch get <name>, lowercases the query and the crawled names and compares them as strings. The Python crawler stores PyPI names aftercanonicalize_pypi_name(PEP 503: lowercased, with each run of-_.collapsed to-). Soruamel.yaml,typing_extensionsandTyping.Extensionscan never matchruamel-yaml/typing-extensions.getthen prints "No packages matching" (status: no_match) and exits 0.Fix
pkg:pypi/purls), the query and the name are compared in PEP 503 form. That covers exact, prefix and contains matches, so the_spelling of an installed name still ranks as an exact match._and.are distinct characters in their names.canonicalize_pypi_namestays where it is. Moving it is Move canonicalize_pypi_name and the PEP 508 name scanner out of crawlers and vendor into one PyPI name module #883's mechanical refactor, and doing it here would conflict with Fix PyPI package specs ignoring PEP 503 spellings (#910) #911.61b720cis a port of Route Gradle digests through utils::digest #878 (maincurrently failsutils::digest::tests::production_digests_go_through_the_helpersintest,test-releaseandcoverage). It becomes a no-op once Route Gradle digests through utils::digest #878 merges.Why this cluster
This is a P1 (pip) correctness bug with a contained fix. The older P1 issues I checked either need a maintainer design call (#371: whether to add
trustedDependenciesor to warn) or overlap open PRs. #910 has the same wrong assumption in a different function, and #911 already fixes it.Tests (red → green)
crawlers::fuzzy_match::tests::test_pypi_query_is_pep503_canonicalized,test_pypi_separator_spelling_ranks_as_exact,test_pypi_prefix_and_contains_use_canonical_form: all 3 failed on main and pass with the fix.test_npm_names_keep_their_separatorsguards the npm behavior.in_process_get::get_package_name_matches_pypi_spellings_pip_accepts:get ruamel.yaml/ruamel_yaml/Ruamel.YAMLagainst a venv fixture failed on main (no manifest written,no_match) and passes with the fix. It savespkg:pypi/ruamel-yaml@0.18.6after searching by the canonical PURL.fuzzy_match::tests::test_pypi_*,in_process_get::get_package_name_matches_pypi_spellings_pip_acceptsLocal results
cargo clippy --workspace --all-features -- -D warnings: clean.cargo test -p socket-patch-core --all-features: 5250 passed. 4 failed, all read-only-directory tests (copy_tree,vlt_heal,pypi_poetry,pypi_requirements) that can't fail as expected because the sandbox runs as root (uid 0 bypasses0o555). They're unrelated to this change, and CI runs them as non-root.cargo test -p socket-patch-cli --all-features --lib --test get --test in_process_get --test covgap_commands_get --test in_process_get_hosted_ecosystems: 1041 passed, 0 failed.cargo test --workspacecouldn't link every CLI test binary within the sandbox's disk allowance, so CI covers the rest.cargo fmt --check: the files this PR touches are rustfmt-clean.mainalready has unformatted files elsewhere, and CI doesn't run fmt.🤖 Generated with Claude Code
Note
Low Risk
User-facing change is a targeted fuzzy-match fix for PyPI with regression tests; digest call sites are a mechanical swap to shared helpers with unchanged semantics.
Overview
Fixes #926 so
socket-patch get <name>resolves installed PyPI packages when the user types the same spellings pip uses (ruamel.yaml,ruamel_yaml, mixed case), not only the PEP 503 form stored by the crawler (ruamel-yaml).Package matching:
fuzzy_match_packagesnow PEP 503-canonicalizes the query and PyPI crawled names (via existingcanonicalize_pypi_name) for exact, prefix, and contains matches. npm and other ecosystems still use case-insensitive string compare so_and.stay distinct.Tests: New unit tests in
fuzzy_matchand an in-processgettest with a minimal.venvdist-info fixture assert exit 0, manifest save, and API search by canonical PURL.Digest helpers: Gradle cache, JVM jar swap/rollback, and Maven sidecar SHA1 paths call
utils::digest::sha1_hex_of/sha256_hex_ofinstead of ad-hocsha1/sha2+hex::encode(aligned with #878).Reviewed by Cursor Bugbot for commit 61b720c. Configure here.
Generated by Claude Code