fix(pypi): build uv.lock git sources with pip - #4209
Open
thirtyseven wants to merge 1 commit into
Open
thirtyseven wants to merge 1 commit into
thirtyseven wants to merge 1 commit into
Conversation
`pip.parse(uv_lock = ...)` turned a package with `source = { git = ... }`
into a src whose `url` was the raw uv source string
(`https://host/repo?rev=<ref>#<commit>`), so `_whl_repo` handed it to the
Bazel downloader, which cannot fetch a git repository. The requirement line
was also `<name>==<version>`, which pip cannot satisfy for a VCS-only
version such as `0.12.0a0+39be1c6`.
Give git sources an empty `url` and `filename`, the same as a
`foo @ git+...` line from a requirements file, so they take the existing
pip path, and render the requirement as a pip direct reference pinned to
the commit uv resolved. A `subdirectory` query parameter is carried over as
`#subdirectory=`, percent-decoded because uv encodes it and pip reads it as
a literal path.
Fixes bazel-contrib#4139
thirtyseven
marked this pull request as ready for review
October 2, 2026 19:57
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
pip.parse(uv_lock = ...)passes a git-sourced package's raw uv source string (https://host/repo?rev=<ref>#<commit>) to the Bazel downloader as a URL, which cannot fetch a git repository (#4139). #4086 fixed the invalid repo name for these sources but kept the URL, so they still fail at fetch time.This makes uv.lock git sources match how a
foo @ git+...line from a requirements file is already handled:urlandfilename, so_whl_repotakes the existing pip path instead of the downloader.foo @ git+<repo url>@<commit>, pinned to the commit uv resolved rather than the requestedrev/tag/branch. Before, it wasfoo==<version>, which pip cannot satisfy for a VCS-only version such as0.12.0a0+39be1c6.subdirectoryquery parameter carries over as#subdirectory=<dir>. uv percent-encodes it (subdirectory=python%2Ffoo) and pip reads the fragment as a literal path, so it is decoded. I checked both against uv 0.9.30 and pip 26.2.1: pip fails on the encoded form with "does not appear to be a Python project" and builds the decoded one.Tests: updated
test_uv_lock_vcs_entryfor the new src shape and addedtest_uv_lock_vcs_entry_subdirectory.//tests/pypi/parse_requirements/...and//tests/pypi/hub_builder/...pass. End to end, a large monorepo usingpip.parse(uv_lock = ...)builds its git-sourcedtorchdatadependency against this branch via--override_module; we have been carrying the same change as a patch on 2.3.1.Fixes #4139