Repository navigation
Fix requirements pin dropped at a dangling EOF \ (#1249) - #1254
Mikola Lysenko (mikolalysenko) merged 2 commits into
Conversation
Assisted-by: Claude Code:claude-opus-5-5
A requirements file whose last line is `six==1.16.0 \` with nothing after it was read with the backslash still attached, so scan never asked the patch API about six and reported "No patches" while pip installed the unpatched release. pip strips that dangling backslash and reads the line as `six==1.16.0`; the shared requirements lexer now does the same, so lock-only discovery, the vendored planner and VEX discovery all see the pin, in the root file or a `-r` include, with LF or CRLF endings. Hosted rewrites keep refusing such a line with redirect_requirements_continuation; discovery now finds the pin, so a patched package gets that warning instead of silence. Fixes #1249 Assisted-by: Claude Code:claude-opus-5-5
ea1f5cc to
8e23559
Compare
|
BugBot review Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 8e23559. Configure here.
|
Labeled Ready for review by the burn-down agent.
Generated by Claude Code |
Final review brief (
|
LLM Description written by Claude Code:claude-opus-5-5
Fixes #1249
Root cause
utils::requirements::logical_linesjoins a\continuation only when aphysical line follows it, and strips the backslash only from lines that
have a successor. A file whose last line is
six==1.16.0 \(no lineafter it) keeps the backslash in the logical line's text, so
exact_pinrejects it and lock-only discovery never requests the purl.pip's
req_file.join_linesstrips the backslash from every continuedline and flushes the pending line at EOF, so it installs
six==1.16.0.Change
logical_linesnow also strips the backslash of a continued line thatends the file (not a comment line).
physicalstays raw, so thevendored writer's recorded original and revert are unchanged. Every
reader of the shared lexer benefits: lock-only discovery
(
inventory_requirements_txt, root file and-rtree), the vendoredrequirements planner and
vex::discover::pypi_other. The hostedredirect rewriter has its own lexer and keeps refusing the line with
redirect_requirements_continuation. Now that discovery finds the pin,a patched package gets that warning instead of no output at all.
No wrapper changes:
npm/,pypi/andgem/only dispatch to the binary.Formatting-only files: 18 of the 22 changed files are
cargo fmt --alloutput only (import order and line wrapping, no token changes), becausemaincurrently failscargo fmt --all -- --check. The functional diff isutils/requirements.rs,vendor/lock_inventory/tests.rsandtests/scan_requirements_lock_only.rs.Tests (red on main, green with the fix)
utils::requirements::tests::lexer_strips_a_dangling_continuation_at_eof-rincludevendor::lock_inventory::tests::requirements_dangling_eof_continuation_is_inventoried--mode vendored)scan_requirements_lock_only::lock_only_scan_discovers_pin_with_dangling_eof_continuationAll three failed before the fix (lexer kept
\; inventory returnedNone; the CLI never sent the purl) and pass after it.Local checks
cargo fmt --all -- --check: cleancargo clippy --workspace --all-features -- -D warnings: cleancargo test -p socket-patch-core --all-features: 5980 passed, 4 failed. The same 4 fail onorigin/mainhere: they are permission tests that don't hold when run as root (wire_failure_rolls_back_already_written_files,wire_write_failure_maps_error_and_leaves_lock_untouched,an_unremovable_hidden_lock_keeps_every_store_entry,relax_loop_must_not_traverse_symlinked_root).scan_requirements_lock_only,scan_vendor_requirements_unwired,e2e_vex_redirect,policy_pypi_names,in_process_vendor_pypi_takeover: all pass. Inmode_migration_pypi, 44 pass and 1 fails (pipenv_hosted_to_vendored_names_the_unpatched_requirements); it fails identically onorigin/mainin this sandbox.cargo test --workspacedidn't fit in this sandbox's disk (linker hit ENOSPC), so CI is the full run.🤖 Generated with Claude Code
https://claude.ai/code/session_01XSB4zeguGS1uuS1Ji5LBjg
Generated by Claude Code