Skip to content

Fix hosted requirements rewrite of user direct refs (#542) - #1333

Merged
Mikola Lysenko (mikolalysenko) merged 2 commits into
mainfrom
agent/v5-requirements-direct-refs
Oct 9, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 2 commits into
mainfrom
agent/v5-requirements-direct-refs

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

Fixes #542

Summary

scan --mode hosted rewrote any name @ <url> line in requirements.txt whose archive filename named the patched release, regardless of origin. A private mirror, an internal fork build or a file:// path was replaced with the Socket build of the public release, and the only warning was redirect_pypi_stale_install. rollback then restored the line as name==version, so the user's source was lost and the next pip install -r pulled public PyPI.

Root cause

In patch/redirect/requirements.rs, requirement_version turned every @ <location> tail whose filename parsed as name-version (archive_version) into RequirementVersion::Exact, making it rewritable. There was no origin check, unlike the bun / Pipenv / Poetry / cargo rewriters, which refuse a user-authored foreign origin.

Fix

Tests (red → green)

Case Test Before After
@ https://files.pythonhosted.org/…, @ http://127.0.0.1:… mirror, @ file:///… fork, PEP 440-equal spelling, with a marker: refused, unchanged, no confirmed uuid patch::redirect::requirements::tests::user_direct_references_are_refused_not_rewritten FAILED ok
user ref to another release → redirect_requirements_entry_not_found same test ok ok
own hosted URL (rotated grant) still replaced existing archive_urls_select_the_matching_distribution_version (the pythonhosted case moved to the refusal test) ok ok

Red was verified by disabling just the origin check.

Commands run

  • cargo test -p socket-patch-core --lib: 6110 passed
  • cargo test -p socket-patch-cli --test mode_migration_pypi --test in_process_rollback_hosted --test scan_requirements_lock_only --test in_process_get_hosted_ecosystems: 46 + 35 + 9 + 10 passed
  • cargo clippy --workspace --all-features -- -D warnings: clean. cargo fmt --all -- --check: my files clean (the upstream/mod.rs diff is pre-existing on main)

🤖 Generated with Claude Code


Note

Medium Risk
Changes hosted-mode lock rewriting for requirements.txt direct references; behavior is more conservative (skip rewrite + new warning) but affects install/redirect paths users may rely on.

Overview
Hosted requirements.txt redirect no longer overwrites user-authored PEP 508 direct references (name @ <url>), fixing #542.

Previously, any @ line whose archive filename named the patched release was treated as an exact pin and swapped for Socket’s hosted artifact—including PyPI files, private mirrors, internal builds, and file:// paths—so rollback could only restore name==version and lose the original source.

The rewriter now classifies @ locations with socket_reference_coords: only Socket’s own hosted/vendored URLs stay Exact and remain replaceable on re-scan; everything else becomes UserReference. When that reference targets the patched release, the line is left byte-for-byte and redirect_requirements_direct_reference is emitted (no confirmed uuid). Socket-hosted lines still rewrite as before.

socket_reference_coords is pub(crate) so redirect can share the same origin check. CLI_CONTRACT and uv-compatibility docs describe the new warning and behavior. Unit tests cover refusal for several URL origins and unchanged “wrong version” handling.

Reviewed by Cursor Bugbot for commit 54b3f10. Configure here.


Generated by Claude Code

Empty commit to open the draft PR.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
`scan --mode hosted` rewrote any `name @ <url>` line in
requirements.txt whose archive named the patched release, whatever
its origin: a private mirror, an internal fork build or a `file://`
path was swapped for the Socket build of the public release, with no
warning. Rollback then wrote `name==version`, so the user's own
source was gone for good and the next install pulled public PyPI.

A direct reference that is not socket-patch's own hosted artifact is
now the user's source choice: the line is left byte-for-byte and the
run warns `redirect_requirements_direct_reference`. socket-patch's
own hosted line (a re-scan or a superseding patch) is still replaced,
and a reference to another release is still not this package's entry.

Fixes #542

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@mikolalysenko
Mikola Lysenko (mikolalysenko) marked this pull request as ready for review October 9, 2026 18:04
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 54b3f10. Configure here.

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Ready for review at 54b3f10c5129.

  • CI: required checks ci-ok and clippy green; 7 check suites succeeded, 1 skipped. 1 superseded workflow run(s) show as cancelled; the required gates passed on this head.
  • Mergeable against main, no CHANGELOG.md change.
  • Bugbot reviewed this head; no unresolved review threads.

Labeled Ready for review by the burn-down agent. Slack announcement pending (connector unavailable this run).


Generated by Claude Code

Merged via the queue into main with commit 7eec31b Oct 9, 2026
217 of 218 checks passed
@mikolalysenko
Mikola Lysenko (mikolalysenko) deleted the agent/v5-requirements-direct-refs branch October 9, 2026 20:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review

Projects

None yet

2 participants