diff --git a/.cvsignore b/.cvsignore deleted file mode 100644 index 2b9f9a5..0000000 --- a/.cvsignore +++ /dev/null @@ -1 +0,0 @@ -pip-0.7.1.tar.gz diff --git a/.fmf/version b/.fmf/version new file mode 100644 index 0000000..d00491f --- /dev/null +++ b/.fmf/version @@ -0,0 +1 @@ +1 diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..72d39d5 --- /dev/null +++ b/.gitignore @@ -0,0 +1,7 @@ +/*.tar.gz +/*.zip +/pip-*/ +/pip/ +/results_python-pip/ +*.rpm +*.whl diff --git a/09a03f6cfa.patch b/09a03f6cfa.patch new file mode 100644 index 0000000..b6369a6 --- /dev/null +++ b/09a03f6cfa.patch @@ -0,0 +1,38 @@ +From 09a03f6cfaeecae8bf5774ae371d37c4369e2da4 Mon Sep 17 00:00:00 2001 +From: Damian Shaw +Date: Sat, 15 Aug 2026 13:36:05 -0400 +Subject: [PATCH] Allow flit-core 4 to build pip + +--- + pyproject.toml | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/pyproject.toml b/pyproject.toml +index 48f64c8018..fe6b39913d 100644 +--- a/pyproject.toml ++++ b/pyproject.toml +@@ -45,13 +45,13 @@ Source = "https://github.com/pypa/pip" + Changelog = "https://pip.pypa.io/en/stable/news/" + + [build-system] +-requires = ["flit-core >=3.11,<4"] ++requires = ["flit-core >=3.11,<5"] + build-backend = "flit_core.buildapi" + + [dependency-groups] + test = [ + "cryptography", +- "flit-core >= 3.11, < 4", ++ "flit-core >= 3.11, < 5", + "freezegun", + "installer", + # pytest-subket requires 7.0+ +@@ -69,7 +69,7 @@ test = [ + ] + + test-common-wheels = [ +- "flit-core >= 3.11, < 4", ++ "flit-core >= 3.11, < 5", + # We pin setuptools<80 because our test suite currently + # depends on setup.py develop to generate egg-link files. + "setuptools >= 70.1.0, <80", diff --git a/10dfb6b900.patch b/10dfb6b900.patch new file mode 100644 index 0000000..5b56c7e --- /dev/null +++ b/10dfb6b900.patch @@ -0,0 +1,347 @@ +From 10dfb6b9005484578b386f64b9f36982e3dc6679 Mon Sep 17 00:00:00 2001 +From: Damian Shaw +Date: Tue, 30 Jun 2026 21:52:39 -0400 +Subject: [PATCH] Fix Link.filename decoding URL path twice (#14110) + +Link already percent-decodes the URL path into `self._path`, but +`Link.filename` decoded the basename again, so a doubly-encoded +separator was decoded twice: `%252F` became `%2F` in `__init__`, then +`/` in `filename`, turning the single component `a%2Fb.whl` into +`a/b.whl`. + +Drop the second decode, and add a `join_within_directory` helper so the +download-path joins treat the name as a single path component. +--- + news/14110.bugfix.rst | 1 + + src/pip/_internal/models/link.py | 63 ++++++++++--- + src/pip/_internal/network/download.py | 20 +++-- + src/pip/_internal/operations/prepare.py | 6 +- + tests/unit/test_link.py | 113 +++++++++++++++++++++++- + 5 files changed, 182 insertions(+), 21 deletions(-) + create mode 100644 news/14110.bugfix.rst + +diff --git a/news/14110.bugfix.rst b/news/14110.bugfix.rst +new file mode 100644 +index 0000000000..f7d4f78882 +--- /dev/null ++++ b/news/14110.bugfix.rst +@@ -0,0 +1 @@ ++Fix ``Link.filename`` decoding the URL path twice. +diff --git a/src/pip/_internal/models/link.py b/src/pip/_internal/models/link.py +index 0a09c66222..cbbe945c17 100644 +--- a/src/pip/_internal/models/link.py ++++ b/src/pip/_internal/models/link.py +@@ -13,6 +13,7 @@ + from typing import ( + Any, + NamedTuple, ++ NewType, + ) + + from pip._internal.exceptions import InvalidEggFragment +@@ -30,6 +31,49 @@ + logger = logging.getLogger(__name__) + + ++# A single path component: percent-decoded once and reduced to a basename, so it ++# contains no path separator and is not a ``.`` or ``..`` reference. The empty ++# string means "no component". ++PathComponent = NewType("PathComponent", str) ++ ++ ++def _to_path_component(name: str) -> PathComponent: ++ """Reduce ``name`` to a single path component, or ``""`` if it has none. ++ ++ ``os.path.basename`` drops any directory part, drive letter, or separator; ++ a ``.``, ``..``, or empty result is not a component and becomes ``""``. ++ """ ++ name = os.path.basename(name) ++ if name in ("", os.curdir, os.pardir): ++ return PathComponent("") ++ ++ return PathComponent(name) ++ ++ ++def as_path_component(name: str) -> PathComponent: ++ """Like ``_to_path_component`` but reject the empty result. ++ ++ Use where a file is about to be written, so a missing name is an error ++ rather than a silent fallback to the directory itself. ++ """ ++ component = _to_path_component(name) ++ if not component: ++ raise ValueError(f"Unexpected file name derived from URL: {name!r}") ++ ++ return component ++ ++ ++def join_within_directory(directory: str, component: PathComponent) -> str: ++ """Join a single path ``component`` onto ``directory``. ++ ++ ``component`` is a :data:`PathComponent`, so by type it has no separator and ++ is not a ``.`` or ``..`` reference; the result can never escape ``directory``. ++ Requiring ``PathComponent`` rather than ``str`` lets the type checker enforce ++ at the call site that the name was reduced to a safe component beforehand. ++ """ ++ return os.path.join(directory, component) ++ ++ + # Order matters, earlier hashes have a precedence over later hashes for what + # we will pick to use. + _SUPPORTED_HASHES = ("sha512", "sha384", "sha256", "sha224", "sha1", "md5") +@@ -424,18 +468,13 @@ def redacted_url(self) -> str: + return redact_auth_from_url(self.url) + + @property +- def filename(self) -> str: +- path = self.path.rstrip("/") +- name = posixpath.basename(path) +- if not name: +- # Make sure we don't leak auth information if the netloc +- # includes a username and password. +- netloc, user_pass = split_auth_from_netloc(self.netloc) +- return netloc +- +- name = urllib.parse.unquote(name) +- assert name, f"URL {self._url!r} produced no filename" +- return name ++ def filename(self) -> PathComponent: ++ name = _to_path_component(posixpath.basename(self.path.rstrip("/"))) ++ if name: ++ return name ++ ++ # No component in the path; fall back to the netloc, dropping any auth. ++ return _to_path_component(split_auth_from_netloc(self.netloc)[0]) + + @property + def file_path(self) -> str: +diff --git a/src/pip/_internal/network/download.py b/src/pip/_internal/network/download.py +index 039b268878..6faafb5cb0 100644 +--- a/src/pip/_internal/network/download.py ++++ b/src/pip/_internal/network/download.py +@@ -19,7 +19,12 @@ + + from pip._internal.cli.progress_bars import BarType, get_download_progress_renderer + from pip._internal.exceptions import IncompleteDownloadError, NetworkConnectionError +-from pip._internal.models.link import Link ++from pip._internal.models.link import ( ++ Link, ++ PathComponent, ++ as_path_component, ++ join_within_directory, ++) + from pip._internal.network.cache import SafeFileCache, is_from_cache + from pip._internal.network.session import CacheControlAdapter, PipSession + from pip._internal.network.utils import HEADERS, raise_for_status, response_chunks +@@ -121,11 +126,14 @@ def parse_content_disposition(content_disposition: str, default_filename: str) - + return filename or default_filename + + +-def _get_http_response_filename(resp: Response, link: Link) -> str: ++def _get_http_response_filename(resp: Response, link: Link) -> PathComponent: + """Get an ideal filename from the given HTTP response, falling back to + the link filename if not provided. ++ ++ The result is validated as a single path component, so it can be joined onto ++ a download directory without escaping it. + """ +- filename = link.filename # fallback ++ filename: str = link.filename # fallback + # Have a look at the Content-Disposition header for a better guess + content_disposition = resp.headers.get("content-disposition") + if content_disposition: +@@ -139,7 +147,7 @@ def _get_http_response_filename(resp: Response, link: Link) -> str: + ext = os.path.splitext(resp.url)[1] + if ext: + filename += ext +- return filename ++ return as_path_component(filename) + + + @dataclass +@@ -192,7 +200,9 @@ def __call__(self, link: Link, location: str) -> tuple[str, str]: + resp = self._http_get(link) + download_size = _get_http_response_size(resp) + +- filepath = os.path.join(location, _get_http_response_filename(resp, link)) ++ filepath = join_within_directory( ++ location, _get_http_response_filename(resp, link) ++ ) + with open(filepath, "wb") as content_file: + download = _FileDownload(link, content_file, download_size) + self._process_response(download, resp) +diff --git a/src/pip/_internal/operations/prepare.py b/src/pip/_internal/operations/prepare.py +index afcc0376da..3b44403e0d 100644 +--- a/src/pip/_internal/operations/prepare.py ++++ b/src/pip/_internal/operations/prepare.py +@@ -29,7 +29,7 @@ + from pip._internal.index.package_finder import PackageFinder + from pip._internal.metadata import BaseDistribution, get_metadata_distribution + from pip._internal.models.direct_url import ArchiveInfo, DirectUrl +-from pip._internal.models.link import Link ++from pip._internal.models.link import Link, join_within_directory + from pip._internal.models.wheel import Wheel + from pip._internal.network.download import Downloader + from pip._internal.network.lazy_wheel import ( +@@ -201,7 +201,7 @@ def _check_download_dir( + """Check download_dir for previously downloaded file with correct hash + If a correct file is found return its path else None + """ +- download_path = os.path.join(download_dir, link.filename) ++ download_path = join_within_directory(download_dir, link.filename) + + if not os.path.exists(download_path): + return None +@@ -687,7 +687,7 @@ def save_linked_requirement(self, req: InstallRequirement) -> None: + # No distribution was downloaded for this requirement. + return + +- download_location = os.path.join(self.download_dir, link.filename) ++ download_location = join_within_directory(self.download_dir, link.filename) + if not os.path.exists(download_location): + shutil.copy(req.local_file_path, download_location) + download_path = display_path(download_location) +diff --git a/tests/unit/test_link.py b/tests/unit/test_link.py +index c49f8547ac..bc8cb8ab9b 100644 +--- a/tests/unit/test_link.py ++++ b/tests/unit/test_link.py +@@ -1,9 +1,17 @@ + from __future__ import annotations + ++import os ++import posixpath ++ + import pytest + + from pip._internal.exceptions import InvalidEggFragment, PipError +-from pip._internal.models.link import Link, links_equivalent ++from pip._internal.models.link import ( ++ Link, ++ as_path_component, ++ join_within_directory, ++ links_equivalent, ++) + from pip._internal.utils.hashes import Hashes + + +@@ -29,6 +37,13 @@ def test_repr(self, url: str, expected: str) -> None: + ("https://example.com/path/page.html", "page.html"), + # Test a quoted character. + ("https://example.com/path/page%231.html", "page#1.html"), ++ # A doubly-encoded separator must stay encoded: the path is decoded ++ # exactly once, so the file name keeps its literal "%2F" instead of ++ # collapsing into a "/". ++ ( ++ "https://example.com/a%252Fb.whl", ++ "a%2Fb.whl", ++ ), + ( + "http://yo/myproject-1.0%2Bfoobar.0-py2.py3-none-any.whl", + "myproject-1.0+foobar.0-py2.py3-none-any.whl", +@@ -49,6 +64,52 @@ def test_filename(self, url: str, expected: str) -> None: + link = Link(url) + assert link.filename == expected + ++ @pytest.mark.parametrize( ++ "url", ++ [ ++ "https://example.com/a%252Fb.whl", ++ "https://example.com/%252e%252e%252fb.whl", ++ ], ++ ) ++ def test_filename_decoded_once_stays_single_component(self, url: str) -> None: ++ # The path is decoded exactly once, so an encoded separator stays ++ # encoded and the file name remains a single path component rather ++ # than collapsing into a "/"-separated path. ++ filename = Link(url).filename ++ assert not posixpath.isabs(filename) ++ assert posixpath.basename(filename) == filename ++ ++ @pytest.mark.parametrize( ++ "url", ++ [ ++ "https://example.com/..", ++ "https://example.com/.", ++ "https://example.com/foo/%2e%2e", ++ ], ++ ) ++ def test_filename_parent_reference_falls_back_to_netloc(self, url: str) -> None: ++ # A path that is only a "." or ".." reference has no usable file name, ++ # so filename falls back to the netloc rather than handing back a ++ # traversal component that could escape a download directory. ++ assert Link(url).filename == "example.com" ++ ++ @pytest.mark.parametrize( ++ "url", ++ [ ++ # A path-less URL whose authority looks like a traversal: the netloc ++ # fallback must still reduce to a single path component. ++ "http://..\\..\\..\\evil.whl", ++ "http://../", ++ "http://..", ++ ], ++ ) ++ def test_filename_is_always_a_path_component(self, url: str) -> None: ++ # filename must never carry a separator or parent reference, so joining ++ # it onto a directory can never escape that directory. ++ name = Link(url).filename ++ assert os.path.basename(name) == name ++ assert name not in (os.curdir, os.pardir) ++ + def test_splitext(self) -> None: + assert ("wheel", ".whl") == Link("http://yo/wheel.whl").splitext() + +@@ -244,3 +305,53 @@ def test_links_equivalent(url1: str, url2: str) -> None: + ) + def test_links_equivalent_false(url1: str, url2: str) -> None: + assert not links_equivalent(Link(url1), Link(url2)) ++ ++ ++@pytest.mark.parametrize( ++ "name", ++ [ ++ "wheel.whl", ++ "myproject-1.0+foobar.0-py2.py3-none-any.whl", ++ # A literal "%2F" is a normal file name, not a separator. ++ "a%2Fb.whl", ++ ], ++) ++def test_as_path_component_keeps_plain_name(name: str) -> None: ++ assert as_path_component(name) == name ++ ++ ++@pytest.mark.parametrize( ++ "name", ++ [ ++ os.path.join(os.sep, "abs", "pkg.whl"), ++ os.path.join("..", "pkg.whl"), ++ os.path.join("nested", "pkg.whl"), ++ ], ++) ++def test_as_path_component_reduces_to_basename(name: str) -> None: ++ # A name carrying directory components is reduced to its basename, so the ++ # result always stays inside the directory it is later joined onto. ++ assert as_path_component(name) == os.path.basename(name) ++ ++ ++@pytest.mark.parametrize("name", ["", ".", "..", "/", os.path.join("sub", "..")]) ++def test_as_path_component_rejects_empty_or_parent_reference(name: str) -> None: ++ with pytest.raises(ValueError): ++ as_path_component(name) ++ ++ ++@pytest.mark.parametrize( ++ "name", ++ [ ++ "pkg.whl", ++ # A literal "%2F" is a normal file name, not a separator. ++ "a%2Fb.whl", ++ ], ++) ++def test_join_within_directory_stays_inside(name: str) -> None: ++ # The component is joined onto the directory as its final element, so the ++ # result stays inside the directory. ++ directory = os.path.join("base", "downloads") ++ joined = join_within_directory(directory, as_path_component(name)) ++ assert joined == os.path.join(directory, name) ++ assert os.path.basename(joined) == name diff --git a/4c6d7471de.patch b/4c6d7471de.patch new file mode 100644 index 0000000..d107561 --- /dev/null +++ b/4c6d7471de.patch @@ -0,0 +1,29 @@ +From 4c6d7471dec62fb004a47a7c2164b6b5b089ac06 Mon Sep 17 00:00:00 2001 +From: Richard Si +Date: Fri, 5 Jun 2026 15:44:14 -0400 +Subject: [PATCH] Also fix user site patching in test suite + +--- + tests/lib/venv.py | 6 ++++-- + 1 file changed, 4 insertions(+), 2 deletions(-) + +diff --git a/tests/lib/venv.py b/tests/lib/venv.py +index 67b01d9f31..4e86b92b3b 100644 +--- a/tests/lib/venv.py ++++ b/tests/lib/venv.py +@@ -174,11 +174,13 @@ def _customize_site(self) -> None: + site.ENABLE_USER_SITE = {self._user_site_packages} + # First, drop system-sites related paths. + original_sys_path = sys.path[:] ++ # To discover system-sites related paths, clear sys.path ++ # and build a new one with only system paths. ++ sys.path = [] + known_paths = set() + for path in site.getsitepackages(): + site.addsitedir(path, known_paths=known_paths) +- system_paths = sys.path[len(original_sys_path):] +- for path in system_paths: ++ for path in sys.path: + if path in original_sys_path: + original_sys_path.remove(path) + sys.path = original_sys_path diff --git a/6099a54ddd.patch b/6099a54ddd.patch new file mode 100644 index 0000000..0bc8ea7 --- /dev/null +++ b/6099a54ddd.patch @@ -0,0 +1,62 @@ +From 6099a54dddbfbc7fb912d53b6adad5ff6b8d1745 Mon Sep 17 00:00:00 2001 +From: Richard Si +Date: Fri, 5 Jun 2026 15:03:38 -0400 +Subject: [PATCH] Fix sitecustomize.py used for build isolation on Python 3.15+ + +The sitecustomize.py file pip uses to isolate build subprocesses from +the parent environment discovers system related paths by calling +site.addsitedir() for every system site-packages path and observing +what new entries are appended to sys.path. + +This breaks since Python 3.15b2 due to two changes: + +- site.addsitedir() won't add a path if it already exists in sys.path + +- site.addsitedir() won't re-execute .pth files if called for a known + directory (which includes the system sites because known_path is + mutated by addsitedir before it checks for .pth files) + +To cope with this, temporarily clear sys.path before using +site.addsitedir() to discover all system paths for exclusion. +--- + news/14033.bugfix.rst | 1 + + src/pip/_internal/build_env.py | 14 +++++++++----- + 2 files changed, 10 insertions(+), 5 deletions(-) + create mode 100644 news/14033.bugfix.rst + +diff --git a/news/14033.bugfix.rst b/news/14033.bugfix.rst +new file mode 100644 +index 0000000000..404196a2f0 +--- /dev/null ++++ b/news/14033.bugfix.rst +@@ -0,0 +1 @@ ++Prevent system packages from leaking into isolated build environments on Python 3.15 +diff --git a/src/pip/_internal/build_env.py b/src/pip/_internal/build_env.py +index 1a42a9d411..7639dabcad 100644 +--- a/src/pip/_internal/build_env.py ++++ b/src/pip/_internal/build_env.py +@@ -468,15 +468,19 @@ def __init__(self, installer: BuildEnvironmentInstaller) -> None: + """ + import os, site, sys + +- # First, drop system-sites related paths. ++ # First, discover all system-sites related paths. + original_sys_path = sys.path[:] ++ # Clear sys.path so addsitedir() will add system site paths and paths ++ # added by contained .pth files to sys.path reliably. This is necessary ++ # since Python 3.15, which notably no longer re-executes .pth files for ++ # known paths. ++ sys.path = [] + known_paths = set() + for path in {system_sites!r}: + site.addsitedir(path, known_paths=known_paths) +- system_paths = set( +- os.path.normcase(path) +- for path in sys.path[len(original_sys_path):] +- ) ++ system_paths = set(os.path.normcase(path) for path in sys.path) ++ ++ # Drop discovered system-sites related paths. + original_sys_path = [ + path for path in original_sys_path + if os.path.normcase(path) not in system_paths diff --git a/Makefile b/Makefile deleted file mode 100644 index 2a1826d..0000000 --- a/Makefile +++ /dev/null @@ -1,21 +0,0 @@ -# Makefile for source rpm: python-pip -# $Id: Makefile,v 1.1 2009/10/22 04:10:22 kevin Exp $ -NAME := python-pip -SPECFILE = $(firstword $(wildcard *.spec)) - -define find-makefile-common -for d in common ../common ../../common ; do if [ -f $$d/Makefile.common ] ; then if [ -f $$d/CVS/Root -a -w $$d/Makefile.common ] ; then cd $$d ; cvs -Q update ; fi ; echo "$$d/Makefile.common" ; break ; fi ; done -endef - -MAKEFILE_COMMON := $(shell $(find-makefile-common)) - -ifeq ($(MAKEFILE_COMMON),) -# attept a checkout -define checkout-makefile-common -test -f CVS/Root && { cvs -Q -d $$(cat CVS/Root) checkout common && echo "common/Makefile.common" ; } || { echo "ERROR: I can't figure out how to checkout the 'common' module." ; exit -1 ; } >&2 -endef - -MAKEFILE_COMMON := $(shell $(checkout-makefile-common)) -endif - -include $(MAKEFILE_COMMON) diff --git a/branch b/branch deleted file mode 100644 index 6ec5cef..0000000 --- a/branch +++ /dev/null @@ -1 +0,0 @@ -EL-4 diff --git a/changelog b/changelog new file mode 100644 index 0000000..f16cb91 --- /dev/null +++ b/changelog @@ -0,0 +1,496 @@ +* Mon Jan 22 2024 Miro Hrončok - 23.3.1-5 +- Switched to autogenerated BuildRequires for test dependencies, + which removed some that were no longer necessary + +* Mon Jan 22 2024 Fedora Release Engineering - 23.3.1-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Fri Jan 12 2024 Maxwell G - 23.3.1-3 +- Remove unused python3-mock dependency + +* Wed Jan 03 2024 Maxwell G - 23.3.1-2 +- Remove weak dependency on python3-setuptools + +* Thu Nov 16 2023 Petr Viktorin - 23.3.1-1 +- Update to 23.3.1 +Resolves: rhbz#2244306 + +* Fri Aug 04 2023 Miro Hrončok - 23.2.1-1 +- Update to 23.2.1 +Resolves: rhbz#2223082 + +* Fri Aug 04 2023 Miro Hrončok - 23.1.2-7 +- Actually run the tests and build the docs when building this package + +* Wed Jul 26 2023 Miro Hrončok - 23.1.2-6 +- Drop no-longer-needed custom changes to /usr/bin/pip* +- Stop Recommending libcrypt.so.1 on Python 3.12+ +Resolves: rhbz#2150373 + +* Tue Jul 25 2023 Python Maint - 23.1.2-5 +- Rebuilt for Python 3.12 + +* Fri Jul 21 2023 Fedora Release Engineering - 23.1.2-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Thu Jul 20 2023 Python Maint - 23.1.2-3 +- Rebuilt for Python 3.12 + +* Tue Jun 13 2023 Python Maint - 23.1.2-2 +- Bootstrap for Python 3.12 + +* Fri May 19 2023 Miro Hrončok - 23.1.2-1 +- Update to 23.1.2 +Resolves: rhbz#2186979 + +* Mon Mar 27 2023 Karolina Surma - 23.0.1-2 +- Fix compatibility with Sphinx 6+ +Resolves: rhbz#2180479 + +* Mon Feb 20 2023 Tomáš Hrnčiar - 23.0.1-1 +- Update to 23.0.1 +Resolves: rhbz#2165760 + +* Fri Jan 20 2023 Fedora Release Engineering - 22.3.1-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Mon Nov 14 2022 Karolina Surma - 22.3.1-1 +- Update to 22.3.1 +Resolves: rhbz#2135044 + +* Mon Sep 05 2022 Python Maint - 22.2.2-2 +- Fix crash when an empty dist-info/egg-info is present +Resolves: rhbz#2115001 +- No longer use the rpm_install prefix to determine RPM-installed packages +Related: rhbz#2026979 + +* Wed Aug 03 2022 Charalampos Stratakis - 22.2.2-1 +- Update to 22.2.2 +Resolves: rhbz#2109468 + +* Fri Jul 22 2022 Charalampos Stratakis - 22.2-1 +- Update to 22.2 +Resolves: rhbz#2109468 + +* Fri Jul 22 2022 Fedora Release Engineering - 22.0.4-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + +* Wed Jun 15 2022 Python Maint - 22.0.4-4 +- Rebuilt for Python 3.11 + +* Mon Jun 13 2022 Python Maint - 22.0.4-3 +- Bootstrap for Python 3.11 + +* Tue Apr 26 2022 Tomáš Hrnčiar - 22.0.4-2 +- Fallback to pep517 if setup.py is present and setuptools cannot be imported +- Fixes: rhbz#2020635 + +* Mon Mar 21 2022 Karolina Surma - 22.0.4-1 +- Update to 22.0.4 +Resolves: rhbz#2061262 + +* Wed Feb 16 2022 Lumír Balhar - 22.0.3-1 +- Update to 22.0.3 +Resolves: rhbz#2048243 + +* Fri Jan 21 2022 Fedora Release Engineering - 21.3.1-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + +* Mon Oct 25 2021 Miro Hrončok - 21.3.1-1 +- Update to 21.3.1 +- Resolves: rhbz#2016682 + +* Wed Oct 13 2021 Miro Hrončok - 21.3-1 +- Update to 21.3 +- Resolves: rhbz#2013026 +- Fix incomplete pip-updates in virtual environments + +* Wed Oct 06 2021 Charalampos Stratakis - 21.2.3-4 +- Remove bundled windows executables +- Resolves: rhbz#2005453 + +* Thu Sep 23 2021 Miro Hrončok - 21.2.3-3 +- Detect paths not to uninstall from via sysconfig's rpm_prefix install scheme + +* Mon Aug 16 2021 Miro Hrončok - 21.2.3-2 +- Fix broken uninstallation by a bogus downstream patch + +* Mon Aug 09 2021 Miro Hrončok - 21.2.3-1 +- Update to 21.2.3 +- Resolves: rhbz#1985635 + +* Fri Jul 23 2021 Fedora Release Engineering - 21.1.3-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + +* Tue Jun 29 2021 Lumír Balhar - 21.1.3-1 +- Update to 21.1.3 +Resolves: rhbz#1976449 + +* Mon Jun 07 2021 Karolina Surma - 21.1.2-1 +- Update to 21.1.2 +Resolves: rhbz#1963433 + +* Fri Jun 04 2021 Python Maint - 21.1.1-3 +- Rebuilt for Python 3.10 + +* Tue Jun 01 2021 Python Maint - 21.1.1-2 +- Bootstrap for Python 3.10 + +* Mon May 10 2021 Karolina Surma - 21.1.1-1 +- Update to 21.1.1 + +* Sat Mar 13 2021 Miro Hrončok - 21.0.1-2 +- python-pip-wheel: Remove bundled provides and libcrypt recommends for Python 2 + (The wheel is Python 3 only for a while) + +* Wed Feb 17 2021 Lumír Balhar - 21.0.1-1 +- Update to 21.0.1 +Resolves: rhbz#1922592 + +* Tue Jan 26 2021 Lumír Balhar - 21.0-1 +- Update to 21.0 (#1919530) + +* Thu Dec 17 2020 Petr Viktorin - 20.3.3-1 +- Update to 20.3.3 + +* Mon Nov 30 2020 Miro Hrončok - 20.3-1 +- Update to 20.3 +- Add support for PEP 600: Future manylinux Platform Tags +- New resolver +- Fixes: rhbz#1893470 + +* Mon Oct 19 2020 Lumír Balhar - 20.2.4-1 +- Update to 20.2.4 (#1889112) + +* Wed Aug 05 2020 Tomas Orsava - 20.2.2-1 +- Update to 20.2.2 (#1838553) + +* Wed Jul 29 2020 Fedora Release Engineering - 20.1.1-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Fri Jul 10 2020 Lumír Balhar - 20.1.1-6 +- Do not emit a warning about root privileges when --root is used + +* Wed Jul 08 2020 Miro Hrončok - 20.1.1-5 +- Update bundled provides to match 20.1.1 + +* Tue Jun 16 2020 Lumír Balhar - 20.1.1-4 +- Deselect tests incompatible with the latest virtualenv + +* Sun May 24 2020 Miro Hrončok - 20.1.1-3 +- Rebuilt for Python 3.9 + +* Thu May 21 2020 Miro Hrončok - 20.1.1-2 +- Bootstrap for Python 3.9 + +* Wed May 20 2020 Tomas Hrnciar - 20.1.1-1 +- Update to 20.1.1 + +* Wed Apr 29 2020 Tomas Hrnciar - 20.1-1 +- Update to 20.1 + +* Mon Apr 27 2020 Tomas Hrnciar - 20.1~b1-1 +- Update to 20.1~b1 + +* Wed Apr 15 2020 Miro Hrončok - 20.0.2-4 +- Only recommend setuptools, don't require them + +* Fri Apr 10 2020 Miro Hrončok - 20.0.2-3 +- Allow setting $TMPDIR to $PWD/... during pip wheel (#1806625) + +* Tue Mar 10 2020 Miro Hrončok - 20.0.2-2 +- Don't warn the user about pip._internal.main() entrypoint to fix ensurepip + +* Mon Mar 02 2020 Miro Hrončok - 20.0.2-1 +- Update to 20.0.2 (#1793456) + +* Thu Jan 30 2020 Fedora Release Engineering - 19.3.1-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild + +* Mon Nov 04 2019 Tomas Orsava - 19.3.1-1 +- Update to 19.3.1 (#1761508) +- Drop upstreamed patch that fixed expected output in test to not break with alpha/beta/rc Python versions + +* Wed Oct 30 2019 Miro Hrončok - 19.2.3-2 +- Make /usr/bin/pip(3) work with user-installed pip 19.3+ (#1767212) + +* Mon Sep 02 2019 Miro Hrončok - 19.2.3-1 +- Update to 19.2.3 (#1742230) +- Drop patch that should strip path prefixes from RECORD files, the paths are relative + +* Wed Aug 21 2019 Petr Viktorin - 19.1.1-8 +- Remove python2-pip +- Make pip bootstrap itself, rather than with an extra bootstrap RPM build + +* Sat Aug 17 2019 Miro Hrončok - 19.1.1-7 +- Rebuilt for Python 3.8 + +* Wed Aug 14 2019 Miro Hrončok - 19.1.1-6 +- Bootstrap for Python 3.8 + +* Wed Aug 14 2019 Miro Hrončok - 19.1.1-5 +- Bootstrap for Python 3.8 + +* Fri Jul 26 2019 Fedora Release Engineering - 19.1.1-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild + +* Mon Jul 15 2019 Petr Viktorin - 19.1.1-3 +- Recommend libcrypt.so.1 for manylinux1 compatibility +- Make /usr/bin/pip Python 3 + +* Mon Jun 10 2019 Miro Hrončok - 19.1.1-2 +- Fix root warning when pip is invoked via python -m pip +- Remove a redundant second WARNING prefix form the abovementioned warning + +* Wed May 15 2019 Miro Hrončok - 19.1.1-1 +- Update to 19.1.1 (#1706995) + +* Thu Apr 25 2019 Miro Hrončok - 19.1-1 +- Update to 19.1 (#1702525) + +* Wed Mar 06 2019 Miro Hrončok - 19.0.3-1 +- Update to 19.0.3 (#1679277) + +* Wed Feb 13 2019 Miro Hrončok - 19.0.2-1 +- Update to 19.0.2 (#1668492) + +* Sat Feb 02 2019 Fedora Release Engineering - 18.1-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild + +* Mon Dec 03 2018 Miro Hrončok - 18.1-2 +- Use the system level root certificate instead of the one bundled in certifi + +* Thu Nov 22 2018 Miro Hrončok - 18.1-1 +- Update to 18.1 (#1652089) + +* Tue Sep 18 2018 Victor Stinner - 18.0-4 +- Prevent removing of the system packages installed under /usr/lib + when pip install -U is executed. Original patch by Michal Cyprian. + Resolves: rhbz#1550368. + +* Wed Aug 08 2018 Miro Hrončok - 18.0-3 +- Create python-pip-wheel package with the wheel + +* Tue Jul 31 2018 Miro Hrončok - 18.0-2 +- Remove redundant "Unicode" from License + +* Mon Jul 23 2018 Marcel Plch - 18.0-7 +- Update to 18.0 + +* Sat Jul 14 2018 Fedora Release Engineering - 9.0.3-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild + +* Mon Jun 18 2018 Miro Hrončok - 9.0.3-5 +- Rebuilt for Python 3.7 + +* Wed Jun 13 2018 Miro Hrončok - 9.0.3-4 +- Bootstrap for Python 3.7 + +* Wed Jun 13 2018 Miro Hrončok - 9.0.3-3 +- Bootstrap for Python 3.7 + +* Fri May 04 2018 Miro Hrončok - 9.0.3-2 +- Allow to import pip10's main from pip9's /usr/bin/pip +- Do not show the "new version of pip" warning outside of venv +Resolves: rhbz#1569488 +Resolves: rhbz#1571650 +Resolves: rhbz#1573755 + +* Thu Mar 29 2018 Charalampos Stratakis - 9.0.3-1 +- Update to 9.0.3 + +* Wed Feb 21 2018 Lumír Balhar - 9.0.1-16 +- Include built HTML documentation (in the new -doc subpackage) and man page + +* Fri Feb 09 2018 Fedora Release Engineering - 9.0.1-15 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild + +* Mon Dec 04 2017 Charalampos Stratakis - 9.0.1-14 +- Reintroduce the ipaddress module in the python3 subpackage. + +* Mon Nov 20 2017 Charalampos Stratakis - 9.0.1-13 +- Add virtual provides for the bundled libraries. (rhbz#1096912) + +* Tue Aug 29 2017 Tomas Orsava - 9.0.1-12 +- Switch macros to bcond's and make Python 2 optional to facilitate building + the Python 2 and Python 3 modules + +* Thu Jul 27 2017 Fedora Release Engineering - 9.0.1-11 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild + +* Tue May 23 2017 Tomas Orsava - 9.0.1-10 +- Modernized package descriptions +Resolves: rhbz#1452568 + +* Tue Mar 21 2017 Tomas Orsava - 9.0.1-9 +- Fix typo in the sudo pip warning + +* Fri Mar 03 2017 Tomas Orsava - 9.0.1-8 +- Patch 1 update: No sudo pip warning in venv or virtualenv + +* Thu Feb 23 2017 Tomas Orsava - 9.0.1-7 +- Patch 1 update: Customize the warning with the proper version of the pip + command + +* Tue Feb 14 2017 Tomas Orsava - 9.0.1-6 +- Added patch 1: Emit a warning when running with root privileges + +* Sat Feb 11 2017 Fedora Release Engineering - 9.0.1-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild + +* Mon Jan 02 2017 Tomas Orsava - 9.0.1-4 +- Provide symlinks to executables to comply with Fedora guidelines for Python +Resolves: rhbz#1406922 + +* Fri Dec 09 2016 Charalampos Stratakis - 9.0.1-3 +- Rebuild for Python 3.6 with wheel + +* Fri Dec 09 2016 Charalampos Stratakis - 9.0.1-2 +- Rebuild for Python 3.6 without wheel + +* Fri Nov 18 2016 Orion Poplawski - 9.0.1-1 +- Update to 9.0.1 + +* Fri Nov 18 2016 Orion Poplawski - 8.1.2-5 +- Enable EPEL Python 3 builds +- Use new python macros +- Cleanup spec + +* Fri Aug 05 2016 Tomas Orsava - 8.1.2-4 +- Updated the test sources + +* Fri Aug 05 2016 Tomas Orsava - 8.1.2-3 +- Moved python-pip into the python2-pip subpackage +- Added the python_provide macro + +* Tue Jul 19 2016 Fedora Release Engineering - 8.1.2-2 +- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages + +* Tue May 17 2016 Tomas Orsava - 8.1.2-1 +- Update to 8.1.2 +- Moved to a new PyPI URL format +- Updated the prefix-stripping patch because of upstream changes in pip/wheel.py + +* Mon Feb 22 2016 Slavek Kabrda - 8.0.2-1 +- Update to 8.0.2 + +* Thu Feb 04 2016 Fedora Release Engineering - 7.1.0-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild + +* Wed Oct 14 2015 Robert Kuska - 7.1.0-3 +- Rebuilt for Python3.5 rebuild +- With wheel set to 1 + +* Tue Oct 13 2015 Robert Kuska - 7.1.0-2 +- Rebuilt for Python3.5 rebuild + +* Wed Jul 01 2015 Slavek Kabrda - 7.1.0-1 +- Update to 7.1.0 + +* Tue Jun 30 2015 Ville Skyttä - 7.0.3-3 +- Install bash completion +- Ship LICENSE.txt as %%license where available + +* Thu Jun 18 2015 Fedora Release Engineering - 7.0.3-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild + +* Thu Jun 04 2015 Matej Stuchlik - 7.0.3-1 +- Update to 7.0.3 + +* Fri Mar 06 2015 Matej Stuchlik - 6.0.8-1 +- Update to 6.0.8 + +* Thu Dec 18 2014 Slavek Kabrda - 1.5.6-5 +- Only enable tests on Fedora. + +* Mon Dec 01 2014 Matej Stuchlik - 1.5.6-4 +- Add tests +- Add patch skipping tests requiring Internet access + +* Tue Nov 18 2014 Matej Stuchlik - 1.5.6-3 +- Added patch for local dos with predictable temp dictionary names + (http://seclists.org/oss-sec/2014/q4/655) + +* Sat Jun 07 2014 Fedora Release Engineering - 1.5.6-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild + +* Sun May 25 2014 Matej Stuchlik - 1.5.6-1 +- Update to 1.5.6 + +* Fri Apr 25 2014 Matej Stuchlik - 1.5.4-4 +- Rebuild as wheel for Python 3.4 + +* Thu Apr 24 2014 Matej Stuchlik - 1.5.4-3 +- Disable build_wheel + +* Thu Apr 24 2014 Matej Stuchlik - 1.5.4-2 +- Rebuild as wheel for Python 3.4 + +* Mon Apr 07 2014 Matej Stuchlik - 1.5.4-1 +- Updated to 1.5.4 + +* Mon Oct 14 2013 Tim Flink - 1.4.1-1 +- Removed patch for CVE 2013-2099 as it has been included in the upstream 1.4.1 release +- Updated version to 1.4.1 + +* Sun Aug 04 2013 Fedora Release Engineering - 1.3.1-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild + +* Tue Jul 16 2013 Toshio Kuratomi - 1.3.1-4 +- Fix for CVE 2013-2099 + +* Thu May 23 2013 Tim Flink - 1.3.1-3 +- undo python2 executable rename to python-pip. fixes #958377 +- fix summary to match upstream + +* Mon May 06 2013 Kevin Kofler - 1.3.1-2 +- Fix main package Summary, it's for Python 2, not 3 (#877401) + +* Fri Apr 26 2013 Jon Ciesla - 1.3.1-1 +- Update to 1.3.1, fix for CVE-2013-1888. + +* Thu Feb 14 2013 Fedora Release Engineering - 1.2.1-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild + +* Tue Oct 09 2012 Tim Flink - 1.2.1-2 +- Fixing files for python3-pip + +* Thu Oct 04 2012 Tim Flink - 1.2.1-1 +- Update to upstream 1.2.1 +- Change binary from pip-python to python-pip (RHBZ#855495) +- Add alias from python-pip to pip-python, to be removed at a later date + +* Tue May 15 2012 Tim Flink - 1.1.0-1 +- Update to upstream 1.1.0 + +* Sat Jan 14 2012 Fedora Release Engineering - 1.0.2-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild + +* Sat Oct 22 2011 Tim Flink - 1.0.2-1 +- update to 1.0.2 and added python3 subpackage + +* Wed Jun 22 2011 Tim Flink - 0.8.3-1 +- update to 0.8.3 and project home page + +* Tue Feb 08 2011 Fedora Release Engineering - 0.8.2-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild + +* Mon Dec 20 2010 Luke Macken - 0.8.2-1 +- update to 0.8.2 of pip +* Mon Aug 30 2010 Peter Halliday - 0.8-1 +- update to 0.8 of pip +* Thu Jul 22 2010 David Malcolm - 0.7.2-5 +- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild + +* Wed Jul 7 2010 Peter Halliday - 0.7.2-1 +- update to 0.7.2 of pip +* Sun May 23 2010 Peter Halliday - 0.7.1-1 +- update to 0.7.1 of pip +* Fri Jan 1 2010 Peter Halliday - 0.6.1.4 +- fix dependency issue +* Fri Dec 18 2009 Peter Halliday - 0.6.1-2 +- fix spec file +* Thu Dec 17 2009 Peter Halliday - 0.6.1-1 +- upgrade to 0.6.1 of pip +* Mon Aug 31 2009 Peter Halliday - 0.4-1 +- Initial package diff --git a/downstream-remove-pytest-subket.patch b/downstream-remove-pytest-subket.patch new file mode 100644 index 0000000..ea3e26d --- /dev/null +++ b/downstream-remove-pytest-subket.patch @@ -0,0 +1,54 @@ +From 9710f03327c685194b7a63c2271a84697425cb47 Mon Sep 17 00:00:00 2001 +From: Karolina Surma +Date: Tue, 10 Feb 2026 15:19:10 +0100 +Subject: [PATCH] Downstream-Only: Remove pytest-subket from tests + +--- + tests/conftest.py | 17 ----------------- + 1 file changed, 17 deletions(-) + +diff --git a/tests/conftest.py b/tests/conftest.py +index 1b65e9d..8e1b595 100644 +--- a/tests/conftest.py ++++ b/tests/conftest.py +@@ -447,18 +447,6 @@ def coverage_install( + return _common_wheel_editable_install(tmpdir_factory, common_wheels, "coverage") + + +-@pytest.fixture(scope="session") +-def socket_install(tmpdir_factory: pytest.TempPathFactory, common_wheels: Path) -> Path: +- lib_dir = _common_wheel_editable_install( +- tmpdir_factory, common_wheels, "pytest_subket" +- ) +- # pytest-subket is only included so it can intercept and block unexpected +- # network requests. It should NOT be visible to the pip under test. +- dist_info = next(lib_dir.glob("*.dist-info")) +- shutil.rmtree(dist_info) +- return lib_dir +- +- + def install_pth_link( + venv: VirtualEnvironment, project_name: str, lib_dir: Path + ) -> None: +@@ -475,7 +463,6 @@ def virtualenv_template( + pip_editable_parts: tuple[Path, ...], + setuptools_install: Path, + coverage_install: Path, +- socket_install: Path, + ) -> VirtualEnvironment: + venv_type: VirtualEnvironmentType + if request.config.getoption("--use-venv"): +@@ -489,10 +476,6 @@ def virtualenv_template( + + # Install setuptools, pytest-subket, and pip. + install_pth_link(venv, "setuptools", setuptools_install) +- install_pth_link(venv, "pytest_subket", socket_install) +- # Also copy pytest-subket's .pth file so it can intercept socket calls. +- with open(venv.site / "pytest_socket.pth", "w") as f: +- f.write(socket_install.joinpath("pytest_socket.pth").read_text()) + + pth, dist_info = pip_editable_parts + +-- +2.52.0 + diff --git a/dummy-certifi.patch b/dummy-certifi.patch new file mode 100644 index 0000000..ce34415 --- /dev/null +++ b/dummy-certifi.patch @@ -0,0 +1,103 @@ +From 7b5fbac83944e3a0dd975ff17b69358791b68721 Mon Sep 17 00:00:00 2001 +From: Karolina Surma +Date: Thu, 27 Jun 2024 10:38:53 +0200 +Subject: [PATCH] Dummy certifi patch + +--- + src/pip/_vendor/certifi/core.py | 80 +++------------------------------ + 1 file changed, 6 insertions(+), 74 deletions(-) + +diff --git a/src/pip/_vendor/certifi/core.py b/src/pip/_vendor/certifi/core.py +index 2f2f7e0..bec6595 100644 +--- a/src/pip/_vendor/certifi/core.py ++++ b/src/pip/_vendor/certifi/core.py +@@ -4,80 +4,12 @@ certifi.py + + This module returns the installation location of cacert.pem or its contents. + """ +-import sys +-import atexit + +-def exit_cacert_ctx() -> None: +- _CACERT_CTX.__exit__(None, None, None) # type: ignore[union-attr] ++# The RPM-packaged certifi always uses the system certificates ++def where() -> str: ++ return '/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem' + + +-if sys.version_info >= (3, 11): +- +- from importlib.resources import as_file, files +- +- _CACERT_CTX = None +- _CACERT_PATH = None +- +- def where() -> str: +- # This is slightly terrible, but we want to delay extracting the file +- # in cases where we're inside of a zipimport situation until someone +- # actually calls where(), but we don't want to re-extract the file +- # on every call of where(), so we'll do it once then store it in a +- # global variable. +- global _CACERT_CTX +- global _CACERT_PATH +- if _CACERT_PATH is None: +- # This is slightly janky, the importlib.resources API wants you to +- # manage the cleanup of this file, so it doesn't actually return a +- # path, it returns a context manager that will give you the path +- # when you enter it and will do any cleanup when you leave it. In +- # the common case of not needing a temporary file, it will just +- # return the file system location and the __exit__() is a no-op. +- # +- # We also have to hold onto the actual context manager, because +- # it will do the cleanup whenever it gets garbage collected, so +- # we will also store that at the global level as well. +- _CACERT_CTX = as_file(files("pip._vendor.certifi").joinpath("cacert.pem")) +- _CACERT_PATH = str(_CACERT_CTX.__enter__()) +- atexit.register(exit_cacert_ctx) +- +- return _CACERT_PATH +- +- def contents() -> str: +- return files("pip._vendor.certifi").joinpath("cacert.pem").read_text(encoding="ascii") +- +-else: +- +- from importlib.resources import path as get_path, read_text +- +- _CACERT_CTX = None +- _CACERT_PATH = None +- +- def where() -> str: +- # This is slightly terrible, but we want to delay extracting the +- # file in cases where we're inside of a zipimport situation until +- # someone actually calls where(), but we don't want to re-extract +- # the file on every call of where(), so we'll do it once then store +- # it in a global variable. +- global _CACERT_CTX +- global _CACERT_PATH +- if _CACERT_PATH is None: +- # This is slightly janky, the importlib.resources API wants you +- # to manage the cleanup of this file, so it doesn't actually +- # return a path, it returns a context manager that will give +- # you the path when you enter it and will do any cleanup when +- # you leave it. In the common case of not needing a temporary +- # file, it will just return the file system location and the +- # __exit__() is a no-op. +- # +- # We also have to hold onto the actual context manager, because +- # it will do the cleanup whenever it gets garbage collected, so +- # we will also store that at the global level as well. +- _CACERT_CTX = get_path("pip._vendor.certifi", "cacert.pem") +- _CACERT_PATH = str(_CACERT_CTX.__enter__()) +- atexit.register(exit_cacert_ctx) +- +- return _CACERT_PATH +- +- def contents() -> str: +- return read_text("pip._vendor.certifi", "cacert.pem", encoding="ascii") ++def contents() -> str: ++ with open(where(), encoding='utf=8') as data: ++ return data.read() +-- +2.50.1 + diff --git a/plan.fmf b/plan.fmf new file mode 100644 index 0000000..c3765d1 --- /dev/null +++ b/plan.fmf @@ -0,0 +1,115 @@ +execute: + how: tmt + +discover: + - name: tests_python + how: shell + url: https://src.fedoraproject.org/tests/python.git + tests: + - name: smoke + path: /smoke + test: ./venv.sh + - name: smoke_virtualenv + path: /smoke + test: METHOD=virtualenv ./venv.sh + - name: tests_python_fedora_only + how: shell + url: https://src.fedoraproject.org/tests/python.git + when: distro != fedora-eln and distro == fedora + tests: + - name: smoke310 + path: /smoke + test: VERSION=3.10 ./venv.sh + - name: smoke311 + path: /smoke + test: VERSION=3.11 ./venv.sh + - name: smoke312 + path: /smoke + test: VERSION=3.12 ./venv.sh + - name: smoke313 + path: /smoke + test: VERSION=3.13 ./venv.sh + - name: smoke314 + path: /smoke + test: VERSION=3.14 ./venv.sh + - name: smoke315 + path: /smoke + test: VERSION=3.15 ./venv.sh + - name: smoke310_virtualenv + path: /smoke + test: VERSION=3.10 METHOD=virtualenv ./venv.sh + - name: smoke311_virtualenv + path: /smoke + test: VERSION=3.11 METHOD=virtualenv ./venv.sh + - name: smoke312_virtualenv + path: /smoke + test: VERSION=3.12 METHOD=virtualenv ./venv.sh + - name: smoke313_virtualenv + path: /smoke + test: VERSION=3.13 METHOD=virtualenv ./venv.sh + - name: smoke314_virtualenv + path: /smoke + test: VERSION=3.14 METHOD=virtualenv ./venv.sh + - name: smoke315_virtualenv + path: /smoke + test: VERSION=3.15 METHOD=virtualenv ./venv.sh + - name: rpms_pyproject-rpm-macros + how: shell + url: https://src.fedoraproject.org/rpms/pyproject-rpm-macros.git + tests: + - name: pyproject_pytest + path: /tests + test: ./mocktest.sh python-pytest + - name: pyproject_entrypoints + path: /tests + test: ./mocktest.sh python-entrypoints + - name: pyproject_pluggy + path: /tests + test: ./mocktest.sh python-pluggy + - name: pyproject_clikit + path: /tests + test: ./mocktest.sh python-clikit + - name: same_repo + how: shell + dist-git-source: true + dist-git-download-only: true + tests: + - name: mock_bootstrap_build + test: | + cd $TMT_SOURCE_DIR && + $TMT_TREE/../discover/rpms_pyproject-rpm-macros/tests/tests/mocktest.sh python-pip --without tests --without man + - name: pip_install_upgrade + path: /tests/pip_install_upgrade/ + test: ./runtest.sh + - name: bash_completion + path: /tests/bash_completion + test: ./pip_completion_full_test.sh +prepare: + - name: Install dependencies + how: install + package: + - gcc + - virtualenv + - python3-devel + - python3-tox + - mock + - rpmdevtools + - rpm-build + - grep + - util-linux + - shadow-utils + - expect + - dnf + - name: Install dependencies (Fedora not ELN) + how: install + when: distro != fedora-eln and distro == fedora + package: + - python3.10-devel + - python3.11-devel + - python3.12-devel + - python3.13-devel + - python3.14-devel + - python3.15-devel + - name: Update packages + how: shell + script: dnf upgrade -y diff --git a/python-pip.rpmlintrc b/python-pip.rpmlintrc new file mode 100644 index 0000000..d32664b --- /dev/null +++ b/python-pip.rpmlintrc @@ -0,0 +1,9 @@ +# This is just temporary, when upstream merges PRs it can be removed +# https://github.com/psf/requests/pull/5410 +addFilter(r'(non-executable-script|wrong-script-interpreter) .+/pip/_vendor/requests/certs.py\b') + +# This file is actually a script but in the vendored context of pip, it is never executed +addFilter(r'non-executable-script .+/pip/_vendor/distro/distro.py\b') + +# We ship README with the main package but not with the wheel +addFilter(r'python-pip-wheel.noarch: W: no-documentation') diff --git a/python-pip.spec b/python-pip.spec index 41eb85d..732bf9c 100644 --- a/python-pip.spec +++ b/python-pip.spec @@ -1,63 +1,373 @@ -%{!?python_sitelib: %global python_sitelib %(%{__python} -c "from distutils.sysconfig import get_python_lib; print get_python_lib()")} +# The original RHEL N+1 content set is defined by (build)dependencies +# of the packages in Fedora ELN. Hence we disable tests here +# to prevent pulling many unwanted packages in. +%bcond tests %{defined fedora} +# Whether to build the manual pages (useful for bootstrapping Sphinx) +%bcond man 1 %global srcname pip +%global base_version 26.1.2 +%global upstream_version %{base_version}%{?prerel} +%global python_wheel_name %{srcname}-%{upstream_version}-py3-none-any.whl Name: python-%{srcname} -Version: 0.7.1 -Release: 1%{?dist} -Summary: Pip installs packages. Python packages. An easy_install replacement +Version: %{base_version}%{?prerel:~%{prerel}} +Release: %autorelease +Summary: A tool for installing and managing Python packages -Group: Development/Libraries -License: MIT -URL: http://pip.openplans.org -Source0: http://pypi.python.org/packages/source/p/pip/%{srcname}-%{version}.tar.gz -BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) +# We bundle a lot of libraries with pip, which itself is under MIT license. +# Here is the list of the libraries with corresponding licenses: + +# certifi: MPL-2.0 +# CacheControl: Apache-2.0 +# distlib: Python-2.0.1 +# distro: Apache-2.0 +# idna: BSD-3-Clause +# msgpack: Apache-2.0 +# packaging: Apache-2.0 OR BSD-2-Clause +# platformdirs: MIT +# pygments: BSD-2-Clause +# pyproject-hooks: MIT +# requests: Apache-2.0 +# resolvelib: ISC +# rich: MIT +# setuptools: MIT +# truststore: MIT +# tomli: MIT +# tomli-w: MIT +# urllib3: MIT + +License: MIT AND Python-2.0.1 AND Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND ISC AND MPL-2.0 AND (Apache-2.0 OR BSD-2-Clause) +URL: https://pip.pypa.io/ +Source0: https://github.com/pypa/pip/archive/%{upstream_version}/%{srcname}-%{upstream_version}.tar.gz + +# The following sources are wheels used only for tests. +# They are not bundled in the built package and do not contribute to the overall license. +# They are pre-built but only contain text files, rebuilding them in %%build has very little benefit. + +# setuptools.whl +# We cannot use RPM-packaged python-setuptools-wheel because upstream pins to <80. +# See https://github.com/pypa/pip/pull/13357 for rationale. +Source1: https://files.pythonhosted.org/packages/0d/6d/b4752b044bf94cb802d88a888dc7d288baaf77d7910b7dedda74b5ceea0c/setuptools-79.0.1-py3-none-any.whl + +# flit_core.whl +# This is not built as RPM-packaged wheel in Fedora at all. +Source3: https://files.pythonhosted.org/packages/f2/65/b6ba90634c984a4fcc02c7e3afe523fef500c4980fec67cc27536ee50acf/flit_core-3.12.0-py3-none-any.whl + +# coverage.whl +# There is no RPM-packaged python-coverage-wheel, the package is archful. +# Upstream uses this to measure coverage, which we don't. +# This is a dummy placeholder package that only contains empty coverage.process_startup(). +# That way, we don't need to patch the usage out of conftest.py. +Source4: coverage-0-py3-none-any.whl BuildArch: noarch -BuildRequires: python-devel -BuildRequires: python-setuptools-devel -Requires: python-setuptools + +%if %{with tests} +BuildRequires: /usr/bin/git +BuildRequires: /usr/bin/hg +BuildRequires: /usr/bin/bzr +BuildRequires: /usr/bin/svn +BuildRequires: python%{python3_pkgversion}-pytest-xdist +%endif + +%if %{with man} +# docs/requirements.txt contains many sphinx extensions +# however, we only build the manual pages thanks to +# https://github.com/pypa/pip/pull/13168 +# We also always use the "main" Sphinx, not python%%{python3_pkgversion}-sphinx +BuildRequires: python3-sphinx +%endif + +# Prevent removing of the system packages installed under /usr/lib +# when pip install -U is executed. +# https://bugzilla.redhat.com/show_bug.cgi?id=1550368#c24 +# Could be replaced with https://www.python.org/dev/peps/pep-0668/ +Patch: remove-existing-dist-only-if-path-conflicts.patch + +# Use the system level root certificate instead of the one bundled in certifi +# https://bugzilla.redhat.com/show_bug.cgi?id=1655253 +# The same patch is a part of the RPM-packaged python-certifi +Patch: dummy-certifi.patch + +# pytest-subket has been introduced to intercept network calls +# https://github.com/pypa/pip/commit/a4b40f62332ccb3228b12cc5ae1493c75177247a +# We don't need a layer to check that, as we're by default in an offline environment +Patch: downstream-remove-pytest-subket.patch + +# Fix sitecustomize.py used for build isolation on Python 3.15+ +Patch: https://github.com/pypa/pip/commit/6099a54ddd.patch + +# Fix user-site path ordering in the test suite on Python 3.15+ +# The same CPython gh-149819 change that broke build env isolation also broke +# _customize_site() in tests/lib/venv.py: site.addsitedir() no longer +# re-appends paths already in sys.path, so the detection of system-site paths +# produces an empty list and user site ends up after venv site-packages instead +# of before it, causing user-site install/uninstall tests to operate on the +# wrong installation. +Patch: https://github.com/pypa/pip/commit/4c6d7471de.patch + +# Allow flit-core 4 to build pip +# https://github.com/pypa/pip/commit/09a03f6cfa (non-existing files removed) +Patch: 09a03f6cfa.patch + +# CVE-2026-13346: Link.filename double URL decode allows path traversal +Patch: https://github.com/pypa/pip/commit/10dfb6b900.patch + +# Remove -s from Python shebang - ensure that packages installed with pip +# to user locations are seen by pip itself +%undefine _py3_shebang_s %description +pip is a package management system used to install and manage software packages +written in Python. Many packages can be found in the Python Package Index +(PyPI). pip is a recursive acronym that can stand for either "Pip Installs +Packages" or "Pip Installs Python". -Pip is a replacement for `easy_install -`_. It uses mostly the -same techniques for finding packages, so packages that were made -easy_installable should be pip-installable as well. -pip is meant to improve on easy_install.bulletin boards, etc.). + +# Virtual provides for the packages bundled by pip. +# You can generate it with: +# %%{_rpmconfigdir}/pythonbundles.py --namespace 'python%%{1}dist' src/pip/_vendor/vendor.txt +%global bundled() %{expand: +Provides: bundled(python%{1}dist(cachecontrol)) = 0.14.4 +Provides: bundled(python%{1}dist(certifi)) = 2026.2.25 +Provides: bundled(python%{1}dist(distlib)) = 0.4 +Provides: bundled(python%{1}dist(distro)) = 1.9 +Provides: bundled(python%{1}dist(idna)) = 3.11 +Provides: bundled(python%{1}dist(msgpack)) = 1.1.2 +Provides: bundled(python%{1}dist(packaging)) = 26.2 +Provides: bundled(python%{1}dist(platformdirs)) = 4.5.1 +Provides: bundled(python%{1}dist(pygments)) = 2.19.2 +Provides: bundled(python%{1}dist(pyproject-hooks)) = 1.2 +Provides: bundled(python%{1}dist(requests)) = 2.33.1 +Provides: bundled(python%{1}dist(resolvelib)) = 1.2.1 +Provides: bundled(python%{1}dist(rich)) = 14.2 +Provides: bundled(python%{1}dist(setuptools)) = 70.3 +Provides: bundled(python%{1}dist(tomli)) = 2.3.1 +Provides: bundled(python%{1}dist(tomli-w)) = 1.2 +Provides: bundled(python%{1}dist(truststore)) = 0.10.4 +Provides: bundled(python%{1}dist(urllib3)) = 2.6.3 +} + +# Some manylinux1 wheels need libcrypt.so.1. +# Manylinux1, a common (as of 2019) platform tag for binary wheels, relies +# on a glibc version that included ancient crypto functions, which were +# moved to libxcrypt and then removed in: +# https://fedoraproject.org/wiki/Changes/FullyRemoveDeprecatedAndUnsafeFunctionsFromLibcrypt +# The manylinux1 standard assumed glibc would keep ABI compatibility, +# but that's only the case if libcrypt.so.1 (libxcrypt-compat) is around. +# This should be solved in the next manylinux standard (but it may be +# a long time until manylinux1 is phased out). +# See: https://github.com/pypa/manylinux/issues/305 +# Note that manylinux is only applicable to x86 (both 32 and 64 bits) +# As of Python 3.12, we no longer use this, +# see https://discuss.python.org/t/29455/ +# However, we keep it around for previous Python versions that use the wheel package. +%global crypt_compat_recommends() %{expand: +Recommends: (libcrypt.so.1()(64bit) if python%{1}(x86-64)) +Recommends: (libcrypt.so.1 if python%{1}(x86-32)) +} + + + +%package -n python%{python3_pkgversion}-%{srcname} +Summary: A tool for installing and managing Python3 packages + +BuildRequires: python%{python3_pkgversion}-devel +# python3 bootstrap: this is rebuilt before the final build of python3, which +# adds the dependency on python3-rpm-generators, so we require it manually +# Note that the package prefix is always python3-, even if we build for 3.X +# The minimal version is for bundled provides verification script +BuildRequires: python3-rpm-generators >= 11-8 +BuildRequires: pyproject-rpm-macros +BuildRequires: python%{python3_pkgversion}-flit-core +BuildRequires: bash-completion +BuildRequires: ca-certificates +Requires: ca-certificates + +# Virtual provides for the packages bundled by pip: +%{bundled %{python3_pkgversion}} + +%if "%{python3_pkgversion}" == "3" +Provides: pip = %{version}-%{release} +%endif + +%description -n python%{python3_pkgversion}-%{srcname} +pip is a package management system used to install and manage software packages +written in Python. Many packages can be found in the Python Package Index +(PyPI). pip is a recursive acronym that can stand for either "Pip Installs +Packages" or "Pip Installs Python". + + +%package -n %{python_wheel_pkg_prefix}-%{srcname}-wheel +Summary: The pip wheel +Requires: ca-certificates + +# Virtual provides for the packages bundled by pip: +%{bundled %{python3_pkgversion}} + +# This is only relevant for Pythons that are older than 3.12 and don't use their own bundled wheels +# It is also only relevant when this wheel is shared across multiple Pythons +%if "%{python_wheel_pkg_prefix}" == "python" +%{crypt_compat_recommends 3.11} +%{crypt_compat_recommends 3.10} +%{crypt_compat_recommends 3.9} +%endif + +%description -n %{python_wheel_pkg_prefix}-%{srcname}-wheel +A Python wheel of pip to use with venv. %prep -%setup -q -n %{srcname}-%{version} -%{__sed} -i '1d' pip/__init__.py +%autosetup -p1 -n %{srcname}-%{upstream_version} + +# this goes together with patch4 +rm src/pip/_vendor/certifi/*.pem + +# Remove windows executable binaries +rm -v src/pip/_vendor/distlib/*.exe +sed -i '/\.exe/d' pyproject.toml + +# Remove unused test requirements +sed -Ei '/(pytest-(cov|xdist|rerunfailures|subket)|proxy\.py)/d' pyproject.toml + +# Remove unused pytest-subket options +sed -Ei '/(--disable-socket|--allow-unix-socket|--allow-hosts=localhost)/d' pyproject.toml + +# Disable --cov option since we don't use it in Fedora +sed -i 's/"--cov"/"--cov", default=None/' tests/conftest.py + +%if %{with tests} +# tests expect wheels in here +mkdir tests/data/common_wheels +cp -a %{SOURCE1} %{SOURCE3} %{SOURCE4} tests/data/common_wheels +%endif + + +%if %{with tests} +%generate_buildrequires +# we only use this to generate test requires +# the "pyproject" part is explicitly disabled as it generates a requirement on pip +%pyproject_buildrequires -N -g test +%endif + %build -%{__python} setup.py build +export PYTHONPATH=./src/ +%pyproject_wheel + +%if %{with man} +sphinx-build -t man -b man -d docs/build/doctrees/man -c docs/html docs/man docs/build/man +%endif + %install -%{__rm} -rf %{buildroot} -%{__python} setup.py install -O1 --skip-build --root %{buildroot} +export PYTHONPATH=./src/ +%pyproject_install +%pyproject_save_files -l pip -%clean -%{__rm} -rf %{buildroot} +# We'll install pip as pip3.X +# Later we'll provide symbolic links, manpage links and bashcompletion fixes for alternative names +%if "%{python3_pkgversion}" == "3" +%global alternate_names pip-%{python3_version} pip-3 pip3 pip +%else +%global alternate_names pip-%{python3_version} +%endif -%files -%defattr(-,root,root,-) -%doc PKG-INFO docs -%attr(755,root,root) %{_bindir}/pip -%{python_sitelib}/pip* +# Provide symlinks to executables +mv %{buildroot}%{_bindir}/pip %{buildroot}%{_bindir}/pip%{python3_version} +rm %{buildroot}%{_bindir}/pip3 +for pip in %{alternate_names}; do +ln -s ./pip%{python3_version} %{buildroot}%{_bindir}/$pip +done + +%if %{with man} +pushd docs/build/man +install -d %{buildroot}%{_mandir}/man1 +for MAN in *1; do +install -pm0644 $MAN %{buildroot}%{_mandir}/man1/${MAN/pip/pip%{python3_version}} +for pip in %{alternate_names}; do +echo ".so ${MAN/pip/pip%{python3_version}}" > %{buildroot}%{_mandir}/man1/${MAN/pip/$pip} +done +done +popd +%endif + +mkdir -p %{buildroot}%{bash_completions_dir} +PYTHONPATH=%{buildroot}%{python3_sitelib} \ + %{buildroot}%{_bindir}/pip%{python3_version} completion --bash \ + > %{buildroot}%{bash_completions_dir}/pip%{python3_version} + +# Make bash completion apply to all alternate names symlinks we install +sed -i -e "s/^\\(complete.*\\) pip%{python3_version}\$/\\1 pip%{python3_version} %{alternate_names}/" \ + -e s/_pip_completion/_pip%{python3_version_nodots}_completion/ \ + %{buildroot}%{bash_completions_dir}/pip%{python3_version} + +# Install the built wheel and inject SBOM into it (if the macro is available) +mkdir -p %{buildroot}%{python_wheel_dir} +install -pm0644 %{_pyproject_wheeldir}/%{python_wheel_name} -t %{buildroot}%{python_wheel_dir} +%{?python_wheel_inject_sbom:%python_wheel_inject_sbom %{buildroot}%{python_wheel_dir}/%{python_wheel_name}} + + +%check +# Verify bundled provides are up to date +%{_rpmconfigdir}/pythonbundles.py src/pip/_vendor/vendor.txt --compare-with '%{bundled 3}' + +# Verify no unwanted files are present in the package +grep "exe$" %{pyproject_files} && exit 1 || true +grep "pem$" %{pyproject_files} && exit 1 || true + +# Verify we can at least run basic commands without crashing +%{py3_test_envvars} %{buildroot}%{_bindir}/pip%{python3_version} --help +%{py3_test_envvars} %{buildroot}%{_bindir}/pip%{python3_version} list +%{py3_test_envvars} %{buildroot}%{_bindir}/pip%{python3_version} show pip + +%if %{with tests} +# Upstream tests +# bash completion tests only work from installed package +pytest_k='not completion' +# this clashes with our PYTHONPATH +pytest_k="$pytest_k and not environments_with_no_pip" +# this requires internet without the keyring local wheel +pytest_k="$pytest_k and not test_prompt_for_keyring_if_needed" +# this cannot import breezy, TODO investigate +pytest_k="$pytest_k and not (functional and bazaar)" +# failures to investigate +pytest_k="$pytest_k and not test_all_fields and not test_report_mixed_not_found and not test_basic_show" # "Editable project location" missing +pytest_k="$pytest_k and not test_basic_install_from_wheel" +pytest_k="$pytest_k and not test_check_unsupported" + +%pytest -n auto -m 'not network' -k "$(echo $pytest_k)" \ + --ignore tests/functional/test_proxy.py # no proxy.py in Fedora +%endif + + +%files -n python%{python3_pkgversion}-%{srcname} -f %{pyproject_files} +%doc README.rst +%if %{with man} +%if "%{python3_pkgversion}" == "3" +%{_mandir}/man1/pip{,3,-3}.1.* +%{_mandir}/man1/pip{,3,-3}-[^3]*.1.* +%endif +%{_mandir}/man1/pip{,-}%{python3_version}.1.* +%{_mandir}/man1/pip{,-}%{python3_version}-*.1.* +%endif +%if "%{python3_pkgversion}" == "3" +%{_bindir}/pip +%{_bindir}/pip3 +%{_bindir}/pip-3 +%endif +%{_bindir}/pip%{python3_version} +%{_bindir}/pip-%{python3_version} +%dir %{bash_completions_dir} +%{bash_completions_dir}/pip%{python3_version} + + +%files -n %{python_wheel_pkg_prefix}-%{srcname}-wheel +%license LICENSE.txt +# we own the dir for simplicity +%dir %{python_wheel_dir}/ +%{python_wheel_dir}/%{python_wheel_name} %changelog -* Sat May 22 2010 Peter Halliday - 0.7.1-1 -- update to 0.7.1 of pip -* Sat Mar 5 2010 Peter Halliday - 0.6.3-1 -- update to 0.6.3 of pip -* Fri Jan 1 2010 Peter Halliday - 0.6.1.4 -- fix dependency issue -* Tue Dec 18 2009 Peter Halliday - 0.6.1-2 -- fix spec file -* Mon Dec 17 2009 Peter Halliday - 0.6.1-1 -- upgrade to 0.6.1 of pip -* Mon Aug 31 2009 Peter Halliday - 0.4-1 -- Initial package - +%autochangelog diff --git a/remove-existing-dist-only-if-path-conflicts.patch b/remove-existing-dist-only-if-path-conflicts.patch new file mode 100644 index 0000000..02d0c69 --- /dev/null +++ b/remove-existing-dist-only-if-path-conflicts.patch @@ -0,0 +1,115 @@ +From a12217cf8f9bf3ab8e39d9bcc6b42e7043e79b08 Mon Sep 17 00:00:00 2001 +From: Karolina Surma +Date: Wed, 16 Feb 2022 08:36:21 +0100 +Subject: [PATCH] Prevent removing of the system packages installed under + /usr/lib when pip install --upgrade is executed. +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Resolves: rhbz#1550368 + +Co-Authored-By: Michal Cyprian +Co-Authored-By: Victor Stinner +Co-Authored-By: Petr Viktorin +Co-Authored-By: Lumir Balhar +Co-Authored-By: Miro Hrončok +Co-Authored-By: Karolina Surma +--- + src/pip/_internal/metadata/base.py | 12 +++++++++++- + src/pip/_internal/req/req_install.py | 2 +- + src/pip/_internal/resolution/legacy/resolver.py | 4 +++- + src/pip/_internal/resolution/resolvelib/factory.py | 12 ++++++++++++ + 4 files changed, 27 insertions(+), 3 deletions(-) + +diff --git a/src/pip/_internal/metadata/base.py b/src/pip/_internal/metadata/base.py +index 230e114..8bd5d31 100644 +--- a/src/pip/_internal/metadata/base.py ++++ b/src/pip/_internal/metadata/base.py +@@ -23,7 +23,7 @@ from pip._vendor.packaging.utils import NormalizedName, canonicalize_name + from pip._vendor.packaging.version import Version + + from pip._internal.exceptions import NoneMetadataError +-from pip._internal.locations import site_packages, user_site ++from pip._internal.locations import get_scheme, site_packages, user_site + from pip._internal.models.direct_url import ( + DIRECT_URL_METADATA_NAME, + DirectUrl, +@@ -575,6 +575,16 @@ class BaseDistribution(Protocol): + for extra in self._iter_egg_info_extras(): + metadata["Provides-Extra"] = extra + ++ @property ++ def in_install_path(self) -> bool: ++ """ ++ Return True if given Distribution is installed in ++ path matching distutils_scheme layout. ++ """ ++ norm_path = normalize_path(self.installed_location) ++ return norm_path.startswith(normalize_path( ++ get_scheme("").purelib.split('python')[0])) ++ + + class BaseEnvironment: + """An environment containing distributions to introspect.""" +diff --git a/src/pip/_internal/req/req_install.py b/src/pip/_internal/req/req_install.py +index aad2f0e..7b385b1 100644 +--- a/src/pip/_internal/req/req_install.py ++++ b/src/pip/_internal/req/req_install.py +@@ -439,7 +439,7 @@ class InstallRequirement: + f"lack sys.path precedence to {existing_dist.raw_name} " + f"in {existing_dist.location}" + ) +- else: ++ elif existing_dist.in_install_path: + self.should_reinstall = True + else: + if self.editable: +diff --git a/src/pip/_internal/resolution/legacy/resolver.py b/src/pip/_internal/resolution/legacy/resolver.py +index 6cc6311..4188ef1 100644 +--- a/src/pip/_internal/resolution/legacy/resolver.py ++++ b/src/pip/_internal/resolution/legacy/resolver.py +@@ -322,7 +322,9 @@ class Resolver(BaseResolver): + # Don't uninstall the conflict if doing a user install and the + # conflict is not a user install. + assert req.satisfied_by is not None +- if not self.use_user_site or req.satisfied_by.in_usersite: ++ if ((not self.use_user_site ++ or req.satisfied_by.in_usersite) ++ and req.satisfied_by.in_install_path): + req.should_reinstall = True + req.satisfied_by = None + +diff --git a/src/pip/_internal/resolution/resolvelib/factory.py b/src/pip/_internal/resolution/resolvelib/factory.py +index a74200a..99738cc 100644 +--- a/src/pip/_internal/resolution/resolvelib/factory.py ++++ b/src/pip/_internal/resolution/resolvelib/factory.py +@@ -4,6 +4,8 @@ import contextlib + import copy + import functools + import logging ++import sys ++import sysconfig + from collections.abc import Iterable, Iterator, Mapping, Sequence + from typing import ( + TYPE_CHECKING, +@@ -674,6 +676,16 @@ class Factory: + if dist is None: # Not installed, no uninstallation required. + return None + ++ # Prevent uninstalling packages from /usr ++ try: ++ if dist.installed_location in ( ++ sysconfig.get_path('purelib', scheme='posix_prefix', vars={'base': sys.base_prefix}), ++ sysconfig.get_path('platlib', scheme='posix_prefix', vars={'platbase': sys.base_prefix}), ++ ): ++ return None ++ except KeyError: # this Python doesn't have 'rpm_prefix' scheme yet ++ pass ++ + # We're installing into global site. The current installation must + # be uninstalled, no matter it's in global or user site, because the + # user site installation has precedence over global. +-- +2.54.0 + diff --git a/sources b/sources index 4a52c8b..786a390 100644 --- a/sources +++ b/sources @@ -1 +1,4 @@ -420c83ad67bdcb542f772eb64392cce6 pip-0.7.1.tar.gz +SHA512 (setuptools-79.0.1-py3-none-any.whl) = fef6cfc6f95a5bb7320f1680e1c665cb8d9a4e4227cde4d8aab8a50bed4bcf04320085b9d7d5343359f887008db5c5a861e57f3d08b7b0b2311a28adaeee6b4a +SHA512 (flit_core-3.12.0-py3-none-any.whl) = 790c12b1f43201e365fb3f8f2f0a54e1a578876799dfdf8bfeea679a25ea096bf62946d006618c1458ae6e37ce6d00998f37e9aba426d5ab80d32ef2d75da4e0 +SHA512 (pip-26.1.2.tar.gz) = e29c98a7da5e329183b7eef86a66f9d6c3473051f64aa6e762714306148547eb0de4220824484071822a9a62bd01a62a09ab16bba4c26e4b847bfc2609728608 +SHA512 (coverage-0-py3-none-any.whl) = e734192565347010efe68f8ba600254259c9b647f3c553fd4e5d87b1d7f955cb15d6f7d807716f4a6415d239beed945fbec7210feaf502e9cc849c332845926e diff --git a/tests/bash_completion/main.fmf b/tests/bash_completion/main.fmf new file mode 100644 index 0000000..cde6f68 --- /dev/null +++ b/tests/bash_completion/main.fmf @@ -0,0 +1,35 @@ +summary: PIP bash completion functionality smoke test +description: | + Comprehensive test for pip bash completion functionality on Fedora/RHEL systems. + + The test performs the following steps: + 1. Finds the bash completion script in the given (e.g. python3-pip) RPM package + 2. Discovers all pip executables in the package (e.g. /usr/bin/pip and /usr/bin/pip3.14) + 3. Sources the completion script and verifies completion for all executables is registered + 4. Runs functional TAB completion tests using expect (for regular and POSIX mode of Bash) + 5. Validates that completion works for basic pip commands + + This is a smoke test to ensure pip bash completion is properly + installed and functional after package installation. + +component: + - python3-pip + +test: ./pip_completion_full_test.sh + +framework: shell + +duration: 5m +tier: 1 + + +require: + - python3-pip + - bash-completion + - expect + - rpm + - bash + + +environment: + PACKAGE: python3-pip diff --git a/tests/bash_completion/pip_completion_full_test.sh b/tests/bash_completion/pip_completion_full_test.sh new file mode 100755 index 0000000..94fcdb9 --- /dev/null +++ b/tests/bash_completion/pip_completion_full_test.sh @@ -0,0 +1,88 @@ +#!/bin/bash + +# Comprehensive PIP bash completion test for RHEL +# Finds completion scripts from RPM, tests all pip binaries, and runs functional tests + +PACKAGE="${PACKAGE:-python3-pip}" + + +# Step 1: Find bash completion scripts in python3-pip RPM package +echo "Step 1: Finding bash completion scripts in $PACKAGE RPM package..." + +COMPLETION_FILE=$(rpm -ql $PACKAGE 2>/dev/null | grep -E "/usr/share/bash-completion/completions/" || true) + +if [[ -z "$COMPLETION_FILE" ]]; then + echo "✗ No bash completion files found in $PACKAGE package" + exit 1 +fi + +# Check if there's exactly one completion file +COMPLETION_FILE_COUNT=$(echo "$COMPLETION_FILE" | wc -l) + +if [[ $COMPLETION_FILE_COUNT -gt 1 ]]; then + echo "✗ Multiple bash completion files found in $PACKAGE package:" + echo "$COMPLETION_FILE" | sed 's/^/ - /' + echo "Expected exactly one completion file, found $COMPLETION_FILE_COUNT" + exit 1 +fi + + +echo "✓ Found completion file from $PACKAGE package:" +echo "$COMPLETION_FILE" | sed 's/^/ - /' + +# Step 2: Find all pip binaries +echo +echo "Step 2: Finding all pip binaries..." +PIP_BINARIES=() +PIP_FILES=$(rpm -ql $PACKAGE | grep /bin/p) +for pip_file in $PIP_FILES; do + if [[ -x "$pip_file" ]]; then + pip_cmd=$(basename "$pip_file") + PIP_BINARIES+=("$pip_cmd") + echo "✓ Found: $pip_cmd -> $pip_file" + fi +done + +if [[ ${#PIP_BINARIES[@]} -eq 0 ]]; then + echo "✗ No pip binaries found" + exit 1 +fi + +echo "Total pip binaries found: ${#PIP_BINARIES[@]}" + +# Step 3: Source completion scripts and test each binary +echo +echo "Step 3: Testing completion for each pip binary..." + +for AS_POSIX in 0 1; do + if [[ $AS_POSIX -eq 1 ]]; then + echo "Testing in POSIX mode" + POSIX="--posix" + else + echo "Testing in non-POSIX mode" + POSIX="" + fi + + echo "Sourcing: $COMPLETION_FILE" + if bash --norc $POSIX -c "source $COMPLETION_FILE" ; then + echo "✓ Successfully sourced $COMPLETION_FILE" + else + echo "! Warning: Failed to source $COMPLETION_FILE" + exit 1 + fi + + export AS_POSIX + for pip_exec in "${PIP_BINARIES[@]}"; do + echo "Running expect test with $COMPLETION_FILE and $pip_exec..." + if ./test_pip_completion.exp "$COMPLETION_FILE" "$pip_exec"; then + echo "✓ Functional test passed" + else + echo "✗ Functional test failed" + exit 1 + fi + done + +done + + +echo "✓ All tests completed successfully!" diff --git a/tests/bash_completion/test_pip_completion.exp b/tests/bash_completion/test_pip_completion.exp new file mode 100755 index 0000000..4389174 --- /dev/null +++ b/tests/bash_completion/test_pip_completion.exp @@ -0,0 +1,117 @@ +#!/usr/bin/expect -f + +# PIP bash completion smoke test using expect +# Tests actual TAB completion functionality +# Usage: test_pip_completion.exp [completion_file] [pip_binary] + +set timeout 5 + + +set completion_file [lindex $argv 0] +set pip_exec [lindex $argv 1] + + +puts "=== PIP Bash Completion Test (using expect) ===" +puts "Testing completion file: $completion_file" +puts "Testing pip binary: $pip_exec" + +# Check if completion file exists first +if {![file exists $completion_file]} { + puts "✗ Completion file not found: $completion_file" + exit 1 +} +puts "✓ Completion file found: $completion_file" + +# Start bash shell +if {[info exists env(AS_POSIX)] && $env(AS_POSIX) == "1"} { + spawn bash --norc --posix +} else { + spawn bash --norc +} +expect "$ " + +# Source the completion file +send "source $completion_file\r" +expect "$ " +puts "Attempted to source completion file" + +# Test 1: Basic pip command completion +puts "\nTest 1: Testing '$pip_exec ' + TAB completion..." +send "$pip_exec " +sleep 0.1 +# Send TAB TAB using hex codes +send "\x09\x09" +expect { + -re "(install|uninstall|list|show)" { + puts "✓ Basic pip commands found in completion" + expect "$ " + } + -re "Display all" { + puts "✓ Completion showing options menu" + send "n\r" + expect "$ " + } + timeout { + puts "✗ Timeout waiting for completion - test failed" + exit 1 + } +} + +# Clear the line and ensure clean prompt +send "\x03" +expect "$ " +send "\r" +expect "$ " + +# Test 2: Test partial command completion (simpler test) +puts "\nTest 2: Testing '$pip_exec insta' + TAB completion..." +send "$pip_exec insta" +sleep 0.1 +# Single TAB for completion +send "\x09" +expect { + -re "install" { + puts "✓ Partial command completion works (insta -> install)" + expect "$ " + } + timeout { + puts "✗ Timeout on partial completion test - test failed" + exit 1 + } +} + +# Clear the line and ensure clean prompt +send "\x03" +expect "$ " +send "\r" +expect "$ " + +# Test 3: Test help completion +puts "\nTest 3: Testing '$pip_exec --' + TAB completion..." +send "$pip_exec --" +sleep 0.1 +send "\x09\x09" +expect { + -re "(--help|--version)" { + puts "✓ Command options found in completion" + expect "$ " + } + timeout { + puts "✗ Timeout on options completion test - test failed" + exit 1 + } +} + +# Final cleanup - make sure we're at clean prompt +send "\x03" +expect "$ " +send "\r" +expect "$ " + +# Exit bash cleanly +send "exit\r" +expect eof + +puts "\n=== Completion Test Complete ===" +puts "PIP bash completion functionality tested!" + diff --git a/tests/pip_install_upgrade/runtest.sh b/tests/pip_install_upgrade/runtest.sh new file mode 100755 index 0000000..4c520f5 --- /dev/null +++ b/tests/pip_install_upgrade/runtest.sh @@ -0,0 +1,40 @@ +#!/bin/sh -eux +# This script requires root privileges and you should never run it on your own machine +test $EUID -eq 0 + +PYTHON_VERSION=$(/usr/bin/python3 -c 'import sys; print("{}.{}".format(*sys.version_info))') +RPM_SITELIB="/usr/lib/python${PYTHON_VERSION}/site-packages" +LOCAL_SITELIB="/usr/local/lib/python${PYTHON_VERSION}/site-packages" +USER_SITELIB="/home/fedora-test-user/.local/lib/python${PYTHON_VERSION}/site-packages" + +# First, let's install older Pello with pip as if it was installed by RPM +# This is an approximation, but it usually works +RPM_BUILD_ROOT=/ /usr/bin/pip install 'Pello==1.0.1' + +# Now, we'll upgrade it with regular pip +/usr/bin/pip install --upgrade 'Pello==1.0.2' + +# pip should see it +/usr/bin/pip freeze | grep '^Pello==1\.0\.2$' + +# Both installations should still exist +test -d "${RPM_SITELIB}/pello-1.0.1.dist-info" +test -d "${LOCAL_SITELIB}/Pello-1.0.2.dist-info" + +# Let's ditch the local one +/usr/bin/pip uninstall --yes Pello + +# It should only remove one of them +test -d "${RPM_SITELIB}/pello-1.0.1.dist-info" +! test -d "${LOCAL_SITELIB}/Pello-1.0.2.dist-info" + +# And pip should still see the RPM-installed one +/usr/bin/pip freeze | grep '^Pello==1\.0\.1$' + +# Again, but as regular user +useradd fedora-test-user +su fedora-test-user -c '/usr/bin/pip install "Pello==1.0.2"' +test -d "${USER_SITELIB}/Pello-1.0.2.dist-info" +su fedora-test-user -c '/usr/bin/pip freeze' | grep '^Pello==1\.0\.2$' +su fedora-test-user -c '/usr/bin/pip uninstall --yes Pello' +su fedora-test-user -c '/usr/bin/pip freeze' | grep '^Pello==1\.0\.1$'