1f3b5bb093
## Summary This PR adds support for hash-checking mode in `pip install` and `pip sync`. It's a large change, both in terms of the size of the diff and the modifications in behavior, but it's also one that's hard to merge in pieces (at least, with any test coverage) since it needs to work end-to-end to be useful and testable. Here are some of the most important highlights: - We store hashes in the cache. Where we previously stored pointers to unzipped wheels in the `archives` directory, we now store pointers with a set of known hashes. So every pointer to an unzipped wheel also includes its known hashes. - By default, we don't compute any hashes. If the user runs with `--require-hashes`, and the cache doesn't contain those hashes, we invalidate the cache, redownload the wheel, and compute the hashes as we go. For users that don't run with `--require-hashes`, there will be no change in performance. For users that _do_, the only change will be if they don't run with `--generate-hashes` -- then they may see some repeated work between resolution and installation, if they use `pip compile` then `pip sync`. - Many of the distribution types now include a `hashes` field, like `CachedDist` and `LocalWheel`. - Our behavior is similar to pip, in that we enforce hashes when pulling any remote distributions, and when pulling from our own cache. Like pip, though, we _don't_ enforce hashes if a distribution is _already_ installed. - Hash validity is enforced in a few different places: 1. During resolution, we enforce hash validity based on the hashes reported by the registry. If we need to access a source distribution, though, we then enforce hash validity at that point too, prior to running any untrusted code. (This is enforced in the distribution database.) 2. In the install plan, we _only_ add cached distributions that have matching hashes. If a cached distribution is missing any hashes, or the hashes don't match, we don't return them from the install plan. 3. In the downloader, we _only_ return distributions with matching hashes. 4. The final combination of "things we install" are: (1) the wheels from the cache, and (2) the downloaded wheels. So this ensures that we never install any mismatching distributions. - Like pip, if `--require-hashes` is provided, we require that _all_ distributions are pinned with either `==` or a direct URL. We also require that _all_ distributions have hashes. There are a few notable TODOs: - We don't support hash-checking mode for unnamed requirements. These should be _somewhat_ rare, though? Since `pip compile` never outputs unnamed requirements. I can fix this, it's just some additional work. - We don't automatically enable `--require-hashes` with a hash exists in the requirements file. We require `--require-hashes`. Closes #474. ## Test Plan I'd like to add some tests for registries that report incorrect hashes, but otherwise: `cargo test`
243 lines
8.2 KiB
TOML
243 lines
8.2 KiB
TOML
[workspace]
|
|
members = ["crates/*"]
|
|
exclude = [
|
|
"scripts",
|
|
# Needs nightly
|
|
"crates/uv-trampoline",
|
|
]
|
|
resolver = "2"
|
|
|
|
[workspace.package]
|
|
edition = "2021"
|
|
rust-version = "1.77"
|
|
homepage = "https://pypi.org/project/uv/"
|
|
documentation = "https://pypi.org/project/uv/"
|
|
repository = "https://github.com/astral-sh/uv"
|
|
authors = ["uv"]
|
|
license = "MIT OR Apache-2.0"
|
|
|
|
[workspace.dependencies]
|
|
cache-key = { path = "crates/cache-key" }
|
|
distribution-filename = { path = "crates/distribution-filename" }
|
|
distribution-types = { path = "crates/distribution-types" }
|
|
install-wheel-rs = { path = "crates/install-wheel-rs", default-features = false }
|
|
once-map = { path = "crates/once-map" }
|
|
pep440_rs = { path = "crates/pep440-rs" }
|
|
pep508_rs = { path = "crates/pep508-rs" }
|
|
platform-tags = { path = "crates/platform-tags" }
|
|
pypi-types = { path = "crates/pypi-types" }
|
|
requirements-txt = { path = "crates/requirements-txt" }
|
|
uv = { path = "crates/uv" }
|
|
uv-auth = { path = "crates/uv-auth" }
|
|
uv-build = { path = "crates/uv-build" }
|
|
uv-cache = { path = "crates/uv-cache" }
|
|
uv-client = { path = "crates/uv-client" }
|
|
uv-dev = { path = "crates/uv-dev" }
|
|
uv-dispatch = { path = "crates/uv-dispatch" }
|
|
uv-distribution = { path = "crates/uv-distribution" }
|
|
uv-extract = { path = "crates/uv-extract" }
|
|
uv-fs = { path = "crates/uv-fs" }
|
|
uv-git = { path = "crates/uv-git" }
|
|
uv-installer = { path = "crates/uv-installer" }
|
|
uv-interpreter = { path = "crates/uv-interpreter" }
|
|
uv-normalize = { path = "crates/uv-normalize" }
|
|
uv-requirements = { path = "crates/uv-requirements" }
|
|
uv-resolver = { path = "crates/uv-resolver" }
|
|
uv-types = { path = "crates/uv-types" }
|
|
uv-configuration = { path = "crates/uv-configuration" }
|
|
uv-trampoline = { path = "crates/uv-trampoline" }
|
|
uv-version = { path = "crates/uv-version" }
|
|
uv-virtualenv = { path = "crates/uv-virtualenv" }
|
|
uv-warnings = { path = "crates/uv-warnings" }
|
|
uv-toolchain = { path = "crates/uv-toolchain" }
|
|
|
|
anstream = { version = "0.6.13" }
|
|
anyhow = { version = "1.0.80" }
|
|
async-channel = { version = "2.2.0" }
|
|
async-compression = { version = "0.4.6" }
|
|
async-trait = { version = "0.1.78" }
|
|
async_http_range_reader = { version = "0.7.1" }
|
|
async_zip = { git = "https://github.com/charliermarsh/rs-async-zip", rev = "1dcb40cfe1bf5325a6fd4bfcf9894db40241f585", features = ["deflate"] }
|
|
axoupdater = { version = "0.4.0", default-features = false }
|
|
backoff = { version = "0.4.0" }
|
|
base64 = { version = "0.22.0" }
|
|
cachedir = { version = "0.3.1" }
|
|
cargo-util = { version = "0.2.8" }
|
|
chrono = { version = "0.4.31" }
|
|
clap = { version = "4.5.3" }
|
|
clap_complete_command = { version = "0.5.1" }
|
|
configparser = { version = "3.0.4" }
|
|
console = { version = "0.15.8", default-features = false }
|
|
csv = { version = "1.3.0" }
|
|
ctrlc = { version = "3.4.4" }
|
|
dashmap = { version = "5.5.3" }
|
|
data-encoding = { version = "2.5.0" }
|
|
derivative = { version = "2.2.0" }
|
|
directories = { version = "5.0.1" }
|
|
dunce = { version = "1.0.4" }
|
|
either = { version = "1.9.0" }
|
|
encoding_rs_io = { version = "0.1.7" }
|
|
flate2 = { version = "1.0.28", default-features = false }
|
|
fs-err = { version = "2.11.0" }
|
|
fs2 = { version = "0.4.3" }
|
|
futures = { version = "0.3.30" }
|
|
git2 = { version = "0.18.1" }
|
|
glob = { version = "0.3.1" }
|
|
hex = { version = "0.4.3" }
|
|
hmac = { version = "0.12.1" }
|
|
home = { version = "0.5.9" }
|
|
html-escape = { version = "0.2.13" }
|
|
http = { version = "1.1.0" }
|
|
indexmap = { version = "2.2.5" }
|
|
indicatif = { version = "0.17.7" }
|
|
indoc = { version = "2.0.4" }
|
|
itertools = { version = "0.12.1" }
|
|
junction = { version = "1.0.0" }
|
|
mailparse = { version = "0.14.0" }
|
|
md-5 = { version = "0.10.6" }
|
|
miette = { version = "7.2.0" }
|
|
nanoid = { version = "0.4.0" }
|
|
once_cell = { version = "1.19.0" }
|
|
owo-colors = { version = "4.0.0" }
|
|
pathdiff = { version = "0.2.1" }
|
|
petgraph = { version = "0.6.4" }
|
|
platform-info = { version = "2.0.2" }
|
|
pubgrub = { git = "https://github.com/astral-sh/pubgrub", rev = "c26e485213e39582c6f2e4d45c0328422670e7a7" }
|
|
pyo3 = { version = "0.20.3" }
|
|
pyo3-log = { version = "0.9.0" }
|
|
rand = { version = "0.8.5" }
|
|
rayon = { version = "1.8.0" }
|
|
reflink-copy = { version = "0.1.15" }
|
|
regex = { version = "1.10.2" }
|
|
reqwest = { version = "0.12.3", default-features = false, features = ["json", "gzip", "brotli", "stream", "rustls-tls", "rustls-tls-native-roots"] }
|
|
reqwest-middleware = { version = "0.3.0" }
|
|
reqwest-retry = { version = "0.5.0" }
|
|
rkyv = { version = "0.7.43", features = ["strict", "validation"] }
|
|
rmp-serde = { version = "1.1.2" }
|
|
rust-netrc = { version = "0.1.1" }
|
|
rustc-hash = { version = "1.1.0" }
|
|
same-file = { version = "1.0.6" }
|
|
seahash = { version = "4.1.0" }
|
|
serde = { version = "1.0.197" }
|
|
serde_json = { version = "1.0.114" }
|
|
sha1 = { version = "0.10.6" }
|
|
sha2 = { version = "0.10.8" }
|
|
sys-info = { version = "0.9.1" }
|
|
tempfile = { version = "3.9.0" }
|
|
textwrap = { version = "0.16.1" }
|
|
thiserror = { version = "1.0.56" }
|
|
tl = { version = "0.7.7" }
|
|
tokio = { version = "1.35.1", features = ["rt-multi-thread", "macros"] }
|
|
tokio-stream = { version = "0.1.14" }
|
|
tokio-tar = { version = "0.3.1" }
|
|
tokio-util = { version = "0.7.10", features = ["compat"] }
|
|
toml = { version = "0.8.12" }
|
|
tracing = { version = "0.1.40" }
|
|
tracing-durations-export = { version = "0.2.0", features = ["plot"] }
|
|
tracing-indicatif = { version = "0.3.6" }
|
|
tracing-subscriber = { version = "0.3.18", features = ["env-filter", "json", "registry"] }
|
|
tracing-tree = { version = "0.3.0" }
|
|
unicode-width = { version = "0.1.11" }
|
|
unscanny = { version = "0.1.0" }
|
|
url = { version = "2.5.0" }
|
|
urlencoding = { version = "2.1.3" }
|
|
wiremock = { version = "0.6.0" }
|
|
walkdir = { version = "2.5.0" }
|
|
which = { version = "6.0.0" }
|
|
winapi = { version = "0.3.9" }
|
|
zip = { version = "0.6.6", default-features = false, features = ["deflate"] }
|
|
|
|
[patch.crates-io]
|
|
# For pyproject-toml
|
|
pep440_rs = { path = "crates/pep440-rs" }
|
|
pep508_rs = { path = "crates/pep508-rs" }
|
|
|
|
[workspace.lints.rust]
|
|
unsafe_code = "warn"
|
|
unreachable_pub = "warn"
|
|
|
|
[workspace.lints.clippy]
|
|
pedantic = { level = "warn", priority = -2 }
|
|
# Allowed pedantic lints
|
|
char_lit_as_u8 = "allow"
|
|
collapsible_else_if = "allow"
|
|
collapsible_if = "allow"
|
|
implicit_hasher = "allow"
|
|
match_same_arms = "allow"
|
|
missing_errors_doc = "allow"
|
|
missing_panics_doc = "allow"
|
|
module_name_repetitions = "allow"
|
|
must_use_candidate = "allow"
|
|
similar_names = "allow"
|
|
too_many_lines = "allow"
|
|
# Disallowed restriction lints
|
|
print_stdout = "warn"
|
|
print_stderr = "warn"
|
|
dbg_macro = "warn"
|
|
empty_drop = "warn"
|
|
empty_structs_with_brackets = "warn"
|
|
exit = "warn"
|
|
get_unwrap = "warn"
|
|
rc_buffer = "warn"
|
|
rc_mutex = "warn"
|
|
rest_pat_in_fully_bound_structs = "warn"
|
|
|
|
[profile.profiling]
|
|
inherits = "release"
|
|
debug = true
|
|
|
|
[profile.fast-build]
|
|
inherits = "dev"
|
|
debug = 0
|
|
strip = "debuginfo"
|
|
|
|
# The profile that 'cargo dist' will build with.
|
|
[profile.dist]
|
|
inherits = "release"
|
|
lto = "thin"
|
|
|
|
# Config for 'cargo dist'
|
|
[workspace.metadata.dist]
|
|
# The preferred cargo-dist version to use in CI (Cargo.toml SemVer syntax)
|
|
cargo-dist-version = "0.13.0"
|
|
# CI backends to support
|
|
ci = ["github"]
|
|
# The installers to generate for each app
|
|
installers = ["shell", "powershell"]
|
|
# The archive format to use for windows builds (defaults .zip)
|
|
windows-archive = ".zip"
|
|
# The archive format to use for non-windows builds (defaults .tar.xz)
|
|
unix-archive = ".tar.gz"
|
|
# Target platforms to build apps for (Rust target-triple syntax)
|
|
targets = [
|
|
"aarch64-apple-darwin",
|
|
"aarch64-unknown-linux-gnu",
|
|
"aarch64-unknown-linux-musl",
|
|
"arm-unknown-linux-musleabihf",
|
|
"armv7-unknown-linux-gnueabihf",
|
|
"armv7-unknown-linux-musleabihf",
|
|
"i686-pc-windows-msvc",
|
|
"i686-unknown-linux-gnu",
|
|
"i686-unknown-linux-musl",
|
|
"powerpc64-unknown-linux-gnu",
|
|
"powerpc64le-unknown-linux-gnu",
|
|
"s390x-unknown-linux-gnu",
|
|
"x86_64-apple-darwin",
|
|
"x86_64-pc-windows-msvc",
|
|
"x86_64-unknown-linux-gnu",
|
|
"x86_64-unknown-linux-musl",
|
|
]# Whether to auto-include files like READMEs and CHANGELOGs (default true)
|
|
auto-includes = false
|
|
# Whether cargo-dist should create a Github Release or use an existing draft
|
|
create-release = true
|
|
# Publish jobs to run in CI
|
|
pr-run-mode = "skip"
|
|
# Whether CI should trigger releases with dispatches instead of tag pushes
|
|
dispatch-releases = true
|
|
# Whether CI should include auto-generated code to build local artifacts
|
|
build-local-artifacts = false
|
|
# Local artifacts jobs to run in CI
|
|
local-artifacts-jobs = ["./build-binaries"]
|
|
# Publish jobs to run in CI
|
|
publish-jobs = ["./publish-pypi"]
|