Skip to content

Lock inventory pins cp311/pp310/py2 "-none-any" wheels as pure, while vendored, hosted and recovery refuse them #1150

Description

[agent] Filed by the scheduled architecture refactor routine. Register: E89 (the slice #1079 / #1121 left open).

Kind: bug (duplicated predicate). Source: register E89, remainder after #1121.

Problem

Verified on main 30a45b3. The "is this a pure wheel" rule is still written three times in vendor/lock_inventory:

Site Rule
pypi_distribution::is_portable_wheel_url the shared tag classifier (#1048); vendored, hosted and, since #1121, ledger recovery use it
lock_inventory/pypi.rs#L313 (uv / PEP 751) url.split(['?','#'])…ends_with("-none-any.whl")
lock_inventory/pypi.rs#L393 (poetry) file.ends_with("-none-any.whl")

python_package_archive (inventory) and recover::pure_wheel_from_uv_unit (recovery) are also the same package_artifacts → portable → http_url → sha256 pick written twice, differing only in the artifact keys and the portability rule.

Symptoms

A uv.lock (or poetry.lock) whose only hash-pinned wheel is six-1.16.0-cp311-none-any.whl, -pp310-none-any.whl or -py2-none-any.whl:

Test-only repro (on main): uv_inventory_and_ledger_recovery_pick_the_same_wheels → inventory, six-1.16.0-cp311-none-any.whl: left Some(".../six-1.16.0-cp311-none-any.whl") right None; the poetry variant returns Sha256Hex(..) instead of None.

Fix

One portable_wheel_artifact(package, keys) pick in lock_inventory/pypi.rs, used by the uv/PEP 751 inventory and by ledger recovery; the poetry reader classifies its file names through is_portable_wheel_url. Delete both suffix checks.

Acceptance

  • No ends_with("-none-any.whl") left in production lock_inventory.
  • A table test runs every wheel shape where the suffix rule and the classifier differ through uv inventory, poetry inventory and recovery, and they agree with wheel_platform_from_filename.

Activity

  1. added
    bugSomething isn't working
    arch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)
    on Oct 8, 2026
  2. mikolalysenko commented on Oct 8, 2026

    @mikolalysenko
    CollaboratorAuthor

    [agent] Claiming this issue for the architecture refactor routine (highest leverage: a live mode-drift bug plus two duplicated wheel picks, all in files no open arch-refactor/* or agent/fix-* PR changes). Branch: arch-refactor/1150-shared-wheel-pick. Claim-ID: 2026-10-08T16:55:43Z-fbb614


    Generated by Claude Code

  3. mikolalysenko commented on Oct 8, 2026

    @mikolalysenko
    CollaboratorAuthor

    [agent] Draft PR: #1151.


    Generated by Claude Code

  4. added a commit that references this issue on Oct 8, 2026
    964f429
  5. mikolalysenko commented on Oct 8, 2026

    @mikolalysenko
    CollaboratorAuthor

    [agent] Triage: priority:p1 (uv / Poetry, PyPI family). Not a duplicate. Open PR #1151 (arch-refactor/1150-shared-wheel-pick) addresses it, so the issue stays open until that merges. No separate agent fix will be claimed.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:triagedarch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)bugSomething isn't workingpm:poetryPoetrypm:uvuvpriority:p1

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions