Repository navigation
Fix hosted requirements rewrite of user direct refs (#542) - #1333
Merged
Mikola Lysenko (mikolalysenko) merged 2 commits intoOct 9, 2026
Merged
Conversation
Empty commit to open the draft PR. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
`scan --mode hosted` rewrote any `name @ <url>` line in requirements.txt whose archive named the patched release, whatever its origin: a private mirror, an internal fork build or a `file://` path was swapped for the Socket build of the public release, with no warning. Rollback then wrote `name==version`, so the user's own source was gone for good and the next install pulled public PyPI. A direct reference that is not socket-patch's own hosted artifact is now the user's source choice: the line is left byte-for-byte and the run warns `redirect_requirements_direct_reference`. socket-patch's own hosted line (a re-scan or a superseding patch) is still replaced, and a reference to another release is still not this package's entry. Fixes #542 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko)
marked this pull request as ready for review
October 9, 2026 18:04
Collaborator
Author
|
BugBot review |
Mikola Lysenko (mikolalysenko)
enabled auto-merge
October 9, 2026 18:05
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 54b3f10. Configure here.
Tanmay Singla (Tanmay182003)
approved these changes
Oct 9, 2026
Collaborator
Author
|
Ready for review at
Labeled Generated by Claude Code |
Mikola Lysenko (mikolalysenko)
deleted the
agent/v5-requirements-direct-refs
branch
October 9, 2026 20:26
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by Claude Code:claude-opus-5-5
Fixes #542
Summary
scan --mode hostedrewrote anyname @ <url>line inrequirements.txtwhose archive filename named the patched release, regardless of origin. A private mirror, an internal fork build or afile://path was replaced with the Socket build of the public release, and the only warning wasredirect_pypi_stale_install.rollbackthen restored the line asname==version, so the user's source was lost and the nextpip install -rpulled public PyPI.Root cause
In
patch/redirect/requirements.rs,requirement_versionturned every@ <location>tail whose filename parsed asname-version(archive_version) intoRequirementVersion::Exact, making it rewritable. There was no origin check, unlike the bun / Pipenv / Poetry / cargo rewriters, which refuse a user-authored foreign origin.Fix
lock_inventory::pypi::socket_reference_coords, the recognizer discovery already uses for our lines) becomesRequirementVersion::UserReference. When its archive names the patched release (PEP 440 equality), the line is left byte-for-byte andredirect_requirements_direct_referenceis reported. When it names another release, it isn't this patch's entry (unchanged behavior). socket-patch's own hosted line (a re-scan, rotated grant, or superseding patch) is still replaced.files.pythonhosted.orgURL. The issue called rewriting it "arguably fine", but rollback can't restore the URL form, so it's refused like any other user source. This matches how uv projects that declare the patched package as a PEP 508 direct URL (six @ https://…/git+…): vendored writes a lockuv sync --lockedrejects while vex attests, and hosted overrides the user's URL then refuses to roll it back #767 refuses uv direct references.Tests (red → green)
@ https://files.pythonhosted.org/…,@ http://127.0.0.1:…mirror,@ file:///…fork, PEP 440-equal spelling, with a marker: refused, unchanged, no confirmed uuidpatch::redirect::requirements::tests::user_direct_references_are_refused_not_rewrittenredirect_requirements_entry_not_foundarchive_urls_select_the_matching_distribution_version(the pythonhosted case moved to the refusal test)Red was verified by disabling just the origin check.
Commands run
cargo test -p socket-patch-core --lib: 6110 passedcargo test -p socket-patch-cli --test mode_migration_pypi --test in_process_rollback_hosted --test scan_requirements_lock_only --test in_process_get_hosted_ecosystems: 46 + 35 + 9 + 10 passedcargo clippy --workspace --all-features -- -D warnings: clean.cargo fmt --all -- --check: my files clean (theupstream/mod.rsdiff is pre-existing on main)🤖 Generated with Claude Code
Note
Medium Risk
Changes hosted-mode lock rewriting for requirements.txt direct references; behavior is more conservative (skip rewrite + new warning) but affects install/redirect paths users may rely on.
Overview
Hosted
requirements.txtredirect no longer overwrites user-authored PEP 508 direct references (name @ <url>), fixing #542.Previously, any
@line whose archive filename named the patched release was treated as an exact pin and swapped for Socket’s hosted artifact—including PyPI files, private mirrors, internal builds, andfile://paths—so rollback could only restorename==versionand lose the original source.The rewriter now classifies
@locations withsocket_reference_coords: only Socket’s own hosted/vendored URLs stayExactand remain replaceable on re-scan; everything else becomesUserReference. When that reference targets the patched release, the line is left byte-for-byte andredirect_requirements_direct_referenceis emitted (no confirmed uuid). Socket-hosted lines still rewrite as before.socket_reference_coordsispub(crate)so redirect can share the same origin check. CLI_CONTRACT and uv-compatibility docs describe the new warning and behavior. Unit tests cover refusal for several URL origins and unchanged “wrong version” handling.Reviewed by Cursor Bugbot for commit 54b3f10. Configure here.
Generated by Claude Code