Skip to content

fix: harden package name resolution + add pyp2spec dep tooling - #3014

Merged
zjhuntin merged 1 commit into
rpm/developfrom
fix/harden-package-resolution
Aug 31, 2026
Merged

zjhuntin merged 1 commit into
rpm/developfrom
fix/harden-package-resolution

Conversation

@Odilhao

@Odilhao Odilhao commented Aug 31, 2026

Copy link
Copy Markdown
Member

Closes #2988 (items 1 and 3; item 2 dropped — triggering test CI on packages/** changes is too costly at bump-wave scale).

Changes

A1 — Silent failure hardening (find_package.py, update_packages.sh)

find_package.py now exposes --resolve-dir <name>: resolves a raw PyPI name to its on-disk spec directory suffix, or exits 1 with a clear error. update_packages.sh uses this instead of the naive packages/python-$pkg/ template — so separator/prefix mismatches (e.g. ruamel.yaml → python-ruamel-yaml) are handled correctly, and a missing or malformed spec fails loudly instead of silently exiting 0.

A3 — build_matrix.py normalization + design comment

Applies PEP-503 canonicalization to matrix entries before emitting them (ruamel.yaml==0.19.1 → ruamel-yaml 0.19.1), so branch names and spec paths are always clean. Adds a comment documenting that the bypass of full resolve_package_dir() is intentional — this workflow is scoped to automation/requirements.txt packages only.

B — Dependency tooling (automation/dep_diff.py, automation/update_deps.py, scaffold_package.sh)

Three new tools using the PyPI JSON API (stdlib urllib only, no extra installs):

  • automation/dep_diff.py — compares a spec's Requires: against the new version's declared mandatory runtime deps from PyPI, outputs a markdown table. Runs as a CI step in update-pulp-packages.yml and injects the diff into the PR body.
  • automation/update_deps.py — rewrites the Requires: python3.12-* library entries in a spec in-place based on PyPI deps, preserving toolchain BuildRequires. Runs inside update_packages.sh as part of each bump.
  • scaffold_package.sh — scaffolds a new packages/python-<name>/ directory for a PyPI package using pyp2spec -a, fetches the tarball, and adds it via git annex add.

Test

Verified in CentOS Stream 10 container against PRs #3001 and #3002 (ruamel-yaml/ruamel-yaml-clib):

  • --resolve-dir ruamel.yaml → python-ruamel-yaml ✓
  • --resolve-dir on unknown package → exit 1 ✓
  • build_matrix.py with ruamel.yaml==0.19.1 → ruamel-yaml 0.19.1 ✓
  • dep_diff.py correctly flags python3.12-ruamel-yaml-clib as removed (became optional-only in 0.19.1) ✓
  • update_deps.py cleanly drops the stale Requires: python%{python3_pkgversion}-ruamel-yaml-clib >= 0.2.6 ✓

🤖 Generated with Claude Code

Closes #2988 (items 1 and 3; item 2 dropped as too costly on bump PRs).

- find_package.py: expose --resolve-dir <name> CLI flag so callers can
  resolve a raw PyPI name to its on-disk spec directory suffix or exit 1
  on failure, instead of silently succeeding with a wrong path.

- update_packages.sh: use find_package.py --resolve-dir to build the
  spec path (handles separator/prefix mismatches like ruamel.yaml →
  python-ruamel-yaml); add explicit error guards around rpmspec so a
  missing or malformed spec fails loudly instead of silently exiting 0.

- build_matrix.py: apply PEP-503 canonicalization (ruamel.yaml →
  ruamel-yaml) before emitting the matrix so branch names and spec
  paths are always clean. Documents the intentional bypass of full
  resolve_package_dir() resolution (scope is limited to
  automation/requirements.txt packages by design).

- automation/dep_diff.py: standalone tool (for agent/manual use) that
  compares a spec's mandatory Requires against the PyPI JSON API for a
  given version, outputting a markdown diff table of added/removed deps.

- automation/update_deps.py: standalone tool that rewrites the
  Requires: python3.12-* library entries in a spec in-place based on
  PyPI mandatory runtime deps, preserving toolchain BuildRequires.

- scaffold_package.sh: generate a new RPM spec for a PyPI package using
  pyp2spec -a, set up the packages/ directory, fetch the tarball via
  spectool, and add via git annex.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@Odilhao
Odilhao force-pushed the fix/harden-package-resolution branch from b13da8d to ed242f4 Compare August 31, 2026 21:15

@zjhuntin zjhuntin left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, resolves the issues at hand. My claude inspection told me there can be some deduplication of some test code, but for now I think this is g2g.

@zjhuntin
zjhuntin merged commit 0249192 into rpm/develop Aug 31, 2026
5 checks passed
@zjhuntin
zjhuntin deleted the fix/harden-package-resolution branch August 31, 2026 22:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Harden package name/version resolution around find_package.py's remaining gaps

2 participants