juc500 정상동작

This commit is contained in:
Macbook
2026-07-21 21:04:25 +09:00
parent ff60cee1cc
commit 1388668b56
2917 changed files with 708021 additions and 651 deletions
@@ -0,0 +1,11 @@
from __future__ import annotations
from .acquire import get_wheel, pip_wheel_env_run
from .util import Version, Wheel
__all__ = [
"Version",
"Wheel",
"get_wheel",
"pip_wheel_env_run",
]
@@ -0,0 +1,213 @@
"""Bootstrap."""
from __future__ import annotations
import logging
import re
import sys
from operator import eq, lt
from pathlib import Path
from subprocess import PIPE, CalledProcessError, Popen
from typing import TYPE_CHECKING
from .bundle import from_bundle
from .periodic_update import add_wheel_to_update_log
from .util import Version, Wheel, discover_wheels
if TYPE_CHECKING:
from virtualenv.app_data.base import AppData
LOGGER = logging.getLogger(__name__)
# PEP 503 normalized distribution name. Anything outside this character set on the way to ``pip download`` means
# somebody is smuggling pip options or extras, so reject it before we build the command line.
_DISTRIBUTION_RE = re.compile(
r"""
^
(?P<name>
[A-Za-z0-9] # must start with an alnum
(?:[A-Za-z0-9._-]* # inner chars: alnum plus . _ -
[A-Za-z0-9])? # must also end with an alnum (unless length is 1)
)
$
""",
re.VERBOSE,
)
# Version specifier that matches what ``Version.as_version_spec`` emits: either empty, ``==<ver>`` or ``<<ver>`` where
# ``<ver>`` is a subset of PEP 440 public versions. Kept deliberately strict so a crafted version cannot inject pip
# flags.
_VERSION_SPEC_RE = re.compile(
r"""
^
(?P<operator>==|<) # only the operators Version.as_version_spec can emit
(?P<version>[A-Za-z0-9._+!-]+) # PEP 440 public-version character set, no whitespace
$
""",
re.VERBOSE,
)
def get_wheel( # noqa: PLR0913
distribution: str,
version: str | None,
for_py_version: str,
search_dirs: list[Path],
download: bool,
app_data: AppData,
do_periodic_update: bool,
env: dict[str, str],
) -> Wheel | None:
"""Get a wheel with the given distribution-version-for_py_version trio, by using the extra search dir + download."""
# not all wheels are compatible with all python versions, so we need to py version qualify it
wheel = None
if not download or version != Version.bundle:
# 1. acquire from bundle
wheel = from_bundle(distribution, version, for_py_version, search_dirs, app_data, do_periodic_update, env)
if download and wheel is None and version != Version.embed:
# 2. download from the internet
wheel = download_wheel(
distribution=distribution,
version_spec=Version.as_version_spec(version),
for_py_version=for_py_version,
search_dirs=search_dirs,
app_data=app_data,
to_folder=app_data.house,
env=env,
)
if wheel is not None and app_data.can_update:
add_wheel_to_update_log(wheel, for_py_version, app_data)
return wheel
def download_wheel( # noqa: PLR0913
distribution: str,
version_spec: str | None,
for_py_version: str,
search_dirs: list[Path],
app_data: AppData,
to_folder: Path,
env: dict[str, str],
) -> Wheel:
"""Invoke ``pip download`` in a subprocess to fetch a seed wheel.
:param distribution: PEP 503 normalized project name; rejected if it contains anything other than
``[A-Za-z0-9._-]``.
:param version_spec: optional version specifier of the form ``==<ver>`` or ``<<ver>`` as emitted by
:func:`Version.as_version_spec`, or ``None``/empty for the latest compatible release.
:param for_py_version: major.minor Python version to pass through to ``pip --python-version``.
:param search_dirs: additional directories to treat as a local wheel index when bootstrapping pip.
:param app_data: application data store used to locate the embedded pip wheel.
:param to_folder: directory the downloaded wheel is written into.
:param env: environment mapping passed through to the subprocess.
:returns: the downloaded :class:`Wheel`.
:raises ValueError: if ``distribution`` or ``version_spec`` fail the strict allow-list check.
:raises CalledProcessError: if ``pip download`` exits with a non-zero status.
"""
_check_distribution(distribution)
_check_version_spec(version_spec)
to_download = f"{distribution}{version_spec or ''}"
LOGGER.debug("download wheel %s %s to %s", to_download, for_py_version, to_folder)
cmd = [
sys.executable,
"-m",
"pip",
"download",
"--progress-bar",
"off",
"--disable-pip-version-check",
"--only-binary=:all:",
"--no-deps",
"--python-version",
for_py_version,
"-d",
str(to_folder),
to_download,
]
# pip has no interface in python - must be a new sub-process
env = pip_wheel_env_run(search_dirs, app_data, env)
process = Popen(cmd, env=env, stdout=PIPE, stderr=PIPE, universal_newlines=True, encoding="utf-8")
out, err = process.communicate()
if process.returncode != 0:
kwargs = {"output": out, "stderr": err}
raise CalledProcessError(process.returncode, cmd, **kwargs)
result = _find_downloaded_wheel(distribution, version_spec, for_py_version, to_folder, out)
LOGGER.debug("downloaded wheel %s", result.name) # ty: ignore[unresolved-attribute]
return result # ty: ignore[invalid-return-type]
def _find_downloaded_wheel(
distribution: str, version_spec: str | None, for_py_version: str, to_folder: Path, out: str
) -> Wheel | None:
for line in out.splitlines():
stripped_line = line.lstrip()
for marker in ("Saved ", "File was already downloaded "):
if stripped_line.startswith(marker):
return Wheel(Path(stripped_line[len(marker) :]).absolute())
# if for some reason the output does not match fallback to the latest version with that spec
return find_compatible_in_house(distribution, version_spec, for_py_version, to_folder)
def find_compatible_in_house(
distribution: str, version_spec: str | None, for_py_version: str, in_folder: Path
) -> Wheel | None:
wheels = discover_wheels(in_folder, distribution, None, for_py_version)
start, end = 0, len(wheels)
if version_spec is not None and version_spec:
if version_spec.startswith("<"):
from_pos, op = 1, lt
elif version_spec.startswith("=="):
from_pos, op = 2, eq
else:
raise ValueError(version_spec)
version = Wheel.as_version_tuple(version_spec[from_pos:])
start = next((at for at, w in enumerate(wheels) if op(w.version_tuple, version)), len(wheels))
return None if start == end else wheels[start]
def pip_wheel_env_run(search_dirs: list[Path], app_data: AppData, env: dict[str, str]) -> dict[str, str]:
env = env.copy()
env.update({"PIP_USE_WHEEL": "1", "PIP_USER": "0", "PIP_NO_INPUT": "1", "PYTHONIOENCODING": "utf-8"})
wheel = get_wheel(
distribution="pip",
version=None,
for_py_version=f"{sys.version_info.major}.{sys.version_info.minor}",
search_dirs=search_dirs,
download=False,
app_data=app_data,
do_periodic_update=False,
env=env,
)
if wheel is None:
msg = "could not find the embedded pip"
raise RuntimeError(msg)
env["PYTHONPATH"] = str(wheel.path)
return env
def _check_distribution(distribution: str) -> None:
if not _DISTRIBUTION_RE.fullmatch(distribution):
msg = f"refusing to download wheel for suspicious distribution name: {distribution!r}"
raise ValueError(msg)
def _check_version_spec(version_spec: str | None) -> None:
if not version_spec:
return
if not _VERSION_SPEC_RE.fullmatch(version_spec):
msg = f"refusing to download wheel with suspicious version spec: {version_spec!r}"
raise ValueError(msg)
__all__ = [
"download_wheel",
"get_wheel",
"pip_wheel_env_run",
]
@@ -0,0 +1,65 @@
from __future__ import annotations
from typing import TYPE_CHECKING
from virtualenv.seed.wheels.embed import get_embed_wheel
from .periodic_update import periodic_update
from .util import Version, Wheel, discover_wheels
if TYPE_CHECKING:
from pathlib import Path
from virtualenv.app_data.base import AppData
def from_bundle( # noqa: PLR0913
distribution: str,
version: str | None,
for_py_version: str,
search_dirs: list[Path],
app_data: AppData,
do_periodic_update: bool,
env: dict[str, str],
) -> Wheel | None:
"""Load the bundled wheel to a cache directory."""
of_version = Version.of_version(version)
wheel = load_embed_wheel(app_data, distribution, for_py_version, of_version)
if version != Version.embed:
# 2. check if we have upgraded embed
if app_data.can_update:
per = do_periodic_update
wheel = periodic_update(distribution, of_version, for_py_version, wheel, search_dirs, app_data, per, env)
# 3. acquire from extra search dir
found_wheel = from_dir(distribution, of_version, for_py_version, search_dirs)
if found_wheel is not None and (wheel is None or found_wheel.version_tuple > wheel.version_tuple):
wheel = found_wheel
return wheel
def load_embed_wheel(app_data: AppData, distribution: str, for_py_version: str, version: str | None) -> Wheel | None:
wheel = get_embed_wheel(distribution, for_py_version)
if wheel is not None:
version_match = version == wheel.version
if version is None or version_match:
with app_data.ensure_extracted(wheel.path, lambda: app_data.house) as wheel_path: # ty: ignore[invalid-argument-type]
wheel = Wheel(wheel_path)
else: # if version does not match ignore
wheel = None
return wheel
def from_dir(distribution: str, version: str | None, for_py_version: str, directories: list[Path]) -> Wheel | None:
"""Load a compatible wheel from a given folder."""
for folder in directories:
for wheel in discover_wheels(folder, distribution, version, for_py_version):
return wheel
return None
__all__ = [
"from_bundle",
"load_embed_wheel",
]
@@ -0,0 +1,135 @@
from __future__ import annotations
import hashlib
import zipfile
from pathlib import Path
from virtualenv.info import IS_ZIPAPP, ROOT
from virtualenv.seed.wheels.util import Wheel
BUNDLE_FOLDER = Path(__file__).absolute().parent
BUNDLE_SUPPORT = {
"3.9": {
"pip": "pip-26.0.1-py3-none-any.whl",
"setuptools": "setuptools-82.0.1-py3-none-any.whl",
},
"3.10": {
"pip": "pip-26.1.2-py3-none-any.whl",
"setuptools": "setuptools-83.0.0-py3-none-any.whl",
},
"3.11": {
"pip": "pip-26.1.2-py3-none-any.whl",
"setuptools": "setuptools-83.0.0-py3-none-any.whl",
},
"3.12": {
"pip": "pip-26.1.2-py3-none-any.whl",
"setuptools": "setuptools-83.0.0-py3-none-any.whl",
},
"3.13": {
"pip": "pip-26.1.2-py3-none-any.whl",
"setuptools": "setuptools-83.0.0-py3-none-any.whl",
},
"3.14": {
"pip": "pip-26.1.2-py3-none-any.whl",
"setuptools": "setuptools-83.0.0-py3-none-any.whl",
},
"3.15": {
"pip": "pip-26.1.2-py3-none-any.whl",
"setuptools": "setuptools-83.0.0-py3-none-any.whl",
},
"3.16": {
"pip": "pip-26.1.2-py3-none-any.whl",
"setuptools": "setuptools-83.0.0-py3-none-any.whl",
},
}
MAX = next(reversed(BUNDLE_SUPPORT))
MIN = next(iter(BUNDLE_SUPPORT))
def _release_tuple(version: str) -> tuple[int, ...]:
return tuple(int(part) for part in version.split("."))
# oldest target Python version virtualenv still bundles seed wheels for; anything below this has no embedded pip
OLDEST_SUPPORTED = _release_tuple(MIN)
# SHA-256 of every bundled wheel. Verified on load so a corrupted or tampered wheel on disk fails loud instead of
# being handed to pip. Generated together with ``BUNDLE_SUPPORT`` by ``tasks/upgrade_wheels.py``.
BUNDLE_SHA256 = {
"pip-26.0.1-py3-none-any.whl": "bdb1b08f4274833d62c1aa29e20907365a2ceb950410df15fc9521bad440122b",
"pip-26.1.2-py3-none-any.whl": "382ff9f685ee3bc25864f820aa50505825f10f5458ffff07e30a6d96e5715cab",
"setuptools-82.0.1-py3-none-any.whl": "a59e362652f08dcd477c78bb6e7bd9d80a7995bc73ce773050228a348ce2e5bb",
"setuptools-83.0.0-py3-none-any.whl": "29b23c360f22f414dc7336bb39178cc7bcbf6021ed2733cde173f09dba19abb3",
}
_VERIFIED_WHEELS: set[str] = set()
def get_embed_wheel(distribution: str, for_py_version: str | None) -> Wheel | None:
"""Return the bundled wheel that ships with virtualenv for a given distribution and Python version.
:param distribution: project name of the seed package, for example ``pip`` or ``setuptools``.
:param for_py_version: major.minor Python version string the environment will be created for, or ``None`` to use the
newest bundle.
:returns: a :class:`Wheel` pointing at the verified bundled file, or ``None`` when no wheel is bundled for the
requested combination, including target versions below the oldest bundled one.
:raises RuntimeError: if the bundled wheel on disk fails SHA-256 verification.
"""
if for_py_version is None or _release_tuple(for_py_version) > _release_tuple(MAX):
# no specific target, or a Python newer than anything bundled: reuse the newest bundle
mapping = BUNDLE_SUPPORT[MAX]
else: # versions below the oldest bundled one fall through to None instead of an incompatible newer wheel
mapping = BUNDLE_SUPPORT.get(for_py_version)
if not mapping:
return None
wheel_file = mapping.get(distribution)
if wheel_file is None:
return None
path = BUNDLE_FOLDER / wheel_file
_verify_bundled_wheel(path)
return Wheel.from_path(path)
def _verify_bundled_wheel(path: Path) -> None:
name = path.name
if name in _VERIFIED_WHEELS:
return
expected = BUNDLE_SHA256.get(name)
if expected is None:
msg = f"bundled wheel {name} has no recorded sha256 in BUNDLE_SHA256"
raise RuntimeError(msg)
actual = _hash_bundled_wheel(path)
if actual != expected:
msg = f"bundled wheel {name} sha256 mismatch: expected {expected}, got {actual}"
raise RuntimeError(msg)
_VERIFIED_WHEELS.add(name)
def _hash_bundled_wheel(path: Path) -> str:
# ``path`` is under the package directory; when virtualenv runs from a zipapp the wheel lives inside the
# archive and cannot be opened as a regular file, so read the bytes straight from the zipapp entry.
digest = hashlib.sha256()
if IS_ZIPAPP:
entry = path.resolve().relative_to(Path(ROOT).resolve()).as_posix()
with zipfile.ZipFile(ROOT, "r") as archive, archive.open(entry) as stream:
for chunk in iter(lambda: stream.read(1 << 20), b""):
digest.update(chunk)
else:
with path.open("rb") as stream:
for chunk in iter(lambda: stream.read(1 << 20), b""):
digest.update(chunk)
return digest.hexdigest()
__all__ = [
"BUNDLE_FOLDER",
"BUNDLE_SHA256",
"BUNDLE_SUPPORT",
"MAX",
"MIN",
"OLDEST_SUPPORTED",
"get_embed_wheel",
]
@@ -0,0 +1,473 @@
"""Periodically update bundled versions."""
from __future__ import annotations
import json
import logging
import os
import ssl
import sys
from datetime import datetime, timedelta, timezone
from itertools import groupby
from pathlib import Path
from shutil import copy2
from subprocess import DEVNULL, Popen
from textwrap import dedent
from threading import Thread
from typing import TYPE_CHECKING
from urllib.error import URLError
from urllib.request import urlopen
from virtualenv.app_data import AppDataDiskFolder
from virtualenv.seed.wheels.embed import BUNDLE_SUPPORT
from virtualenv.seed.wheels.util import Wheel
from virtualenv.util.subprocess import CREATE_NO_WINDOW
if TYPE_CHECKING:
from collections.abc import Generator
from virtualenv.app_data.base import AppData
LOGGER = logging.getLogger(__name__)
GRACE_PERIOD_CI = timedelta(hours=1) # prevent version switch in the middle of a CI run
GRACE_PERIOD_MINOR = timedelta(days=28)
UPDATE_PERIOD = timedelta(days=14)
UPDATE_ABORTED_DELAY = timedelta(hours=1)
def periodic_update( # noqa: PLR0913
distribution: str,
of_version: str | None,
for_py_version: str,
wheel: Wheel | None,
search_dirs: list[Path],
app_data: AppData,
do_periodic_update: bool,
env: dict[str, str],
) -> Wheel | None:
if do_periodic_update:
handle_auto_update(distribution, for_py_version, wheel, search_dirs, app_data, env)
now = datetime.now(tz=timezone.utc)
def _update_wheel(ver: NewVersion) -> Wheel:
updated_wheel = Wheel(app_data.house / ver.filename)
LOGGER.debug("using %supdated wheel %s", "periodically " if updated_wheel else "", updated_wheel)
return updated_wheel
u_log = UpdateLog.from_app_data(app_data, distribution, for_py_version)
if of_version is None:
for _, group in groupby(u_log.versions, key=lambda v: v.wheel.version_tuple[0:2]):
# use only latest patch version per minor, earlier assumed to be buggy
all_patches = list(group)
ignore_grace_period_minor = any(version for version in all_patches if version.use(now))
for version in all_patches:
if wheel is not None and Path(version.filename).name == wheel.name:
return wheel
if version.use(now, ignore_grace_period_minor):
return _update_wheel(version)
else:
for version in u_log.versions:
if version.wheel.version == of_version:
return _update_wheel(version)
return wheel
def handle_auto_update( # noqa: PLR0913
distribution: str,
for_py_version: str,
wheel: Wheel | None,
search_dirs: list[Path],
app_data: AppData,
env: dict[str, str],
) -> None:
embed_update_log = app_data.embed_update_log(distribution, for_py_version)
u_log = UpdateLog.from_dict(embed_update_log.read())
if u_log.needs_update:
u_log.periodic = True
u_log.started = datetime.now(tz=timezone.utc)
embed_update_log.write(u_log.to_dict())
trigger_update(distribution, for_py_version, wheel, search_dirs, app_data, periodic=True, env=env)
def add_wheel_to_update_log(wheel: Wheel, for_py_version: str, app_data: AppData) -> None:
embed_update_log = app_data.embed_update_log(wheel.distribution, for_py_version)
LOGGER.debug("adding %s information to %s", wheel.name, embed_update_log.file) # ty: ignore[unresolved-attribute]
u_log = UpdateLog.from_dict(embed_update_log.read())
if any(version.filename == wheel.name for version in u_log.versions):
LOGGER.warning("%s already present in %s", wheel.name, embed_update_log.file) # ty: ignore[unresolved-attribute]
return
# we don't need a release date for sources other than "periodic"
version = NewVersion(wheel.name, datetime.now(tz=timezone.utc), None, "download")
u_log.versions.append(version) # always write at the end for proper updates
embed_update_log.write(u_log.to_dict())
DATETIME_FMT = "%Y-%m-%dT%H:%M:%S.%fZ"
def dump_datetime(value: datetime | None) -> str | None:
return None if value is None else value.strftime(DATETIME_FMT)
def load_datetime(value: str | None) -> datetime | None:
return None if value is None else datetime.strptime(value, DATETIME_FMT).replace(tzinfo=timezone.utc)
class NewVersion: # noqa: PLW1641
def __init__(self, filename: str, found_date: datetime, release_date: datetime | None, source: str) -> None:
self.filename = filename
self.found_date = found_date
self.release_date = release_date
self.source = source
@classmethod
def from_dict(cls, dictionary: dict[str, str | None]) -> NewVersion:
return cls(
filename=dictionary["filename"], # ty: ignore[invalid-argument-type]
found_date=load_datetime(dictionary["found_date"]), # ty: ignore[invalid-argument-type]
release_date=load_datetime(dictionary["release_date"]),
source=dictionary["source"], # ty: ignore[invalid-argument-type]
)
def to_dict(self) -> dict[str, str | None]:
return {
"filename": self.filename,
"release_date": dump_datetime(self.release_date),
"found_date": dump_datetime(self.found_date),
"source": self.source,
}
def use(self, now: datetime, ignore_grace_period_minor: bool = False, ignore_grace_period_ci: bool = False) -> bool: # noqa: FBT002
if self.source == "manual":
return True
if self.source == "periodic" and (self.found_date < now - GRACE_PERIOD_CI or ignore_grace_period_ci):
if not ignore_grace_period_minor:
compare_from = self.release_date or self.found_date
return now - compare_from >= GRACE_PERIOD_MINOR
return True
return False
def __repr__(self) -> str:
return (
f"{self.__class__.__name__}(filename={self.filename}), found_date={self.found_date}, "
f"release_date={self.release_date}, source={self.source})"
)
def __eq__(self, other: object) -> bool:
return type(self) == type(other) and all( # noqa: E721
getattr(self, k) == getattr(other, k) for k in ["filename", "release_date", "found_date", "source"]
)
def __ne__(self, other: object) -> bool:
return not (self == other)
@property
def wheel(self) -> Wheel:
return Wheel(Path(self.filename))
class UpdateLog:
def __init__(
self, started: datetime | None, completed: datetime | None, versions: list[NewVersion], periodic: bool | None
) -> None:
self.started = started
self.completed = completed
self.versions = versions
self.periodic = periodic
@classmethod
def from_dict(cls, dictionary: dict[str, object] | None) -> UpdateLog:
if dictionary is None:
dictionary = {}
return cls(
load_datetime(dictionary.get("started")), # ty: ignore[invalid-argument-type]
load_datetime(dictionary.get("completed")), # ty: ignore[invalid-argument-type]
[NewVersion.from_dict(v) for v in dictionary.get("versions", [])], # ty: ignore[not-iterable]
dictionary.get("periodic"), # ty: ignore[invalid-argument-type]
)
@classmethod
def from_app_data(cls, app_data: AppData, distribution: str, for_py_version: str) -> UpdateLog:
raw_json = app_data.embed_update_log(distribution, for_py_version).read()
return cls.from_dict(raw_json)
def to_dict(self) -> dict[str, object]:
return {
"started": dump_datetime(self.started),
"completed": dump_datetime(self.completed),
"periodic": self.periodic,
"versions": [r.to_dict() for r in self.versions],
}
@property
def needs_update(self) -> bool:
now = datetime.now(tz=timezone.utc)
if self.completed is None: # never completed
return self._check_start(now)
if now - self.completed <= UPDATE_PERIOD:
return False
return self._check_start(now)
def _check_start(self, now: datetime) -> bool:
return self.started is None or now - self.started > UPDATE_ABORTED_DELAY
def trigger_update( # noqa: PLR0913
distribution: str,
for_py_version: str,
wheel: Wheel | None,
search_dirs: list[Path],
app_data: AppData,
env: dict[str, str],
periodic: bool,
) -> None:
wheel_path = None if wheel is None else str(wheel.path)
cmd = [
sys.executable,
"-c",
dedent(
"""
from virtualenv.report import setup_report, MAX_LEVEL
from virtualenv.seed.wheels.periodic_update import do_update
setup_report(MAX_LEVEL, show_pid=True)
do_update({!r}, {!r}, {!r}, {!r}, {!r}, {!r})
""",
)
.strip()
.format(distribution, for_py_version, wheel_path, str(app_data), [str(p) for p in search_dirs], periodic),
]
debug = env.get("_VIRTUALENV_PERIODIC_UPDATE_INLINE") == "1"
pipe = None if debug else DEVNULL
kwargs = {"stdout": pipe, "stderr": pipe}
if not debug and sys.platform == "win32":
kwargs["creationflags"] = CREATE_NO_WINDOW
process = Popen(cmd, **kwargs) # ty: ignore[no-matching-overload]
LOGGER.info(
"triggered periodic upgrade of %s%s (for python %s) via background process having PID %d",
distribution,
"" if wheel is None else f"=={wheel.version}",
for_py_version,
process.pid,
)
if debug:
process.communicate() # on purpose not called to make it a background process
else:
# set the returncode here -> no ResourceWarning on main process exit if the subprocess still runs
process.returncode = 0
def do_update( # noqa: PLR0913
distribution: str,
for_py_version: str,
embed_filename: str | None,
app_data: str | AppData,
search_dirs: list[str] | list[Path],
periodic: bool,
) -> list[NewVersion] | None:
versions = None
try:
versions = _run_do_update(app_data, distribution, embed_filename, for_py_version, periodic, search_dirs)
finally:
LOGGER.debug("done %s %s with %s", distribution, for_py_version, versions)
return versions
def _run_do_update( # noqa: C901, PLR0913
app_data: str | AppData,
distribution: str,
embed_filename: str | None,
for_py_version: str,
periodic: bool,
search_dirs: list[str] | list[Path],
) -> list[NewVersion]:
from virtualenv.seed.wheels import acquire # noqa: PLC0415
wheel_filename = None if embed_filename is None else Path(embed_filename)
embed_version = None if wheel_filename is None else Wheel(wheel_filename).version_tuple
app_data = AppDataDiskFolder(app_data) if isinstance(app_data, str) else app_data
search_dirs = [Path(p) if isinstance(p, str) else p for p in search_dirs]
wheelhouse = app_data.house
embed_update_log = app_data.embed_update_log(distribution, for_py_version)
u_log = UpdateLog.from_dict(embed_update_log.read())
now = datetime.now(tz=timezone.utc)
update_versions, other_versions = [], []
for version in u_log.versions:
if version.source in {"periodic", "manual"}:
update_versions.append(version)
else:
other_versions.append(version)
if periodic:
source = "periodic"
else:
source = "manual"
# mark the most recent one as source "manual"
if update_versions:
update_versions[0].source = source
if wheel_filename is not None:
dest = wheelhouse / wheel_filename.name
if not dest.exists():
copy2(str(wheel_filename), str(wheelhouse))
last, last_version, versions, filenames = None, None, [], set()
while last is None or not last.use(now, ignore_grace_period_ci=True):
download_time = datetime.now(tz=timezone.utc)
dest = acquire.download_wheel(
distribution=distribution,
version_spec=None if last_version is None else f"<{last_version}",
for_py_version=for_py_version,
search_dirs=search_dirs,
app_data=app_data,
to_folder=wheelhouse,
env=os.environ, # ty: ignore[invalid-argument-type]
)
if dest is None or (update_versions and update_versions[0].filename == dest.name):
break
release_date = release_date_for_wheel_path(dest.path)
last = NewVersion(filename=dest.path.name, release_date=release_date, found_date=download_time, source=source)
LOGGER.info("detected %s in %s", last, datetime.now(tz=timezone.utc) - download_time)
versions.append(last)
filenames.add(last.filename)
last_wheel = last.wheel
last_version = last_wheel.version
if embed_version is not None and embed_version >= last_wheel.version_tuple:
break # stop download if we reach the embed version
u_log.periodic = periodic
if not u_log.periodic:
u_log.started = now
# update other_versions by removing version we just found
other_versions = [version for version in other_versions if version.filename not in filenames]
u_log.versions = versions + update_versions + other_versions
u_log.completed = datetime.now(tz=timezone.utc)
embed_update_log.write(u_log.to_dict())
return versions
def release_date_for_wheel_path(dest: Path) -> datetime | None:
wheel = Wheel(dest)
# the most accurate is to ask PyPi - e.g. https://pypi.org/pypi/pip/json,
# see https://warehouse.pypa.io/api-reference/json/ for more details
content = _pypi_get_distribution_info_cached(wheel.distribution)
if content is not None:
try:
upload_time = content["releases"][wheel.version][0]["upload_time"] # ty: ignore[not-subscriptable]
return datetime.strptime(upload_time, "%Y-%m-%dT%H:%M:%S").replace(tzinfo=timezone.utc)
except Exception as exception: # noqa: BLE001
LOGGER.error("could not load release date %s because %r", content, exception) # noqa: TRY400
return None
#: Opt-in escape hatch to restore the pre-2026 behavior of falling back to an unverified HTTPS context when the
#: verified request fails. Off by default: a failed TLS handshake on the PyPI metadata lookup now aborts the update
#: instead of silently downgrading, because the response drives which wheel version virtualenv thinks is up to date.
_INSECURE_FALLBACK_ENV = "VIRTUALENV_PERIODIC_UPDATE_INSECURE"
def _request_context() -> Generator[ssl.SSLContext | None, None, None]:
yield None
if os.environ.get(_INSECURE_FALLBACK_ENV):
LOGGER.warning(
"falling back to unverified HTTPS for PyPI metadata because %s is set",
_INSECURE_FALLBACK_ENV,
)
yield ssl._create_unverified_context() # noqa: S323, SLF001
_PYPI_CACHE = {}
def _pypi_get_distribution_info_cached(distribution: str) -> dict[str, object] | None:
if distribution not in _PYPI_CACHE:
_PYPI_CACHE[distribution] = _pypi_get_distribution_info(distribution)
return _PYPI_CACHE[distribution]
def _pypi_get_distribution_info(distribution: str) -> dict[str, object] | None:
content, url = None, f"https://pypi.org/pypi/{distribution}/json"
try:
for context in _request_context():
if (content := _fetch_pypi_json(url, context)) is not None:
break
except Exception as exception: # noqa: BLE001
LOGGER.error("failed to access %s because %r", url, exception) # noqa: TRY400
return content
def _fetch_pypi_json(url: str, context: ssl.SSLContext | None) -> dict[str, object] | None:
try:
with urlopen(url, context=context) as file_handler: # noqa: S310
return json.load(file_handler)
except URLError as exception:
LOGGER.error("failed to access %s because %r", url, exception) # noqa: TRY400
return None
def manual_upgrade(app_data: AppData, env: dict[str, str]) -> None:
threads = []
for for_py_version, distribution_to_package in BUNDLE_SUPPORT.items():
# load extra search dir for the given for_py
for distribution in distribution_to_package:
thread = Thread(target=_run_manual_upgrade, args=(app_data, distribution, for_py_version, env))
thread.start()
threads.append(thread)
for thread in threads:
thread.join()
def _run_manual_upgrade(app_data: AppData, distribution: str, for_py_version: str, env: dict[str, str]) -> None:
start = datetime.now(tz=timezone.utc)
from .bundle import from_bundle # noqa: PLC0415
current = from_bundle(
distribution=distribution,
version=None,
for_py_version=for_py_version,
search_dirs=[],
app_data=app_data,
do_periodic_update=False,
env=env,
)
LOGGER.warning(
"upgrade %s for python %s with current %s",
distribution,
for_py_version,
"" if current is None else current.name,
)
versions = do_update(
distribution=distribution,
for_py_version=for_py_version,
embed_filename=current.path, # ty: ignore[invalid-argument-type, unresolved-attribute]
app_data=app_data,
search_dirs=[],
periodic=False,
)
args = [
distribution,
for_py_version,
datetime.now(tz=timezone.utc) - start,
]
if versions:
args.append("\n".join(f"\t{v}" for v in versions))
ver_update = "new entries found:\n%s" if versions else "no new versions found"
msg = f"upgraded %s for python %s in %s {ver_update}"
LOGGER.warning(msg, *args)
__all__ = [
"NewVersion",
"UpdateLog",
"add_wheel_to_update_log",
"do_update",
"dump_datetime",
"load_datetime",
"manual_upgrade",
"periodic_update",
"release_date_for_wheel_path",
"trigger_update",
]
@@ -0,0 +1,125 @@
from __future__ import annotations
from operator import attrgetter
from typing import TYPE_CHECKING
from zipfile import ZipFile
if TYPE_CHECKING:
from pathlib import Path
class Wheel:
def __init__(self, path: Path) -> None:
# https://www.python.org/dev/peps/pep-0427/#file-name-convention
# The wheel filename is {distribution}-{version}(-{build tag})?-{python tag}-{abi tag}-{platform tag}.whl
self.path = path
self._parts = path.stem.split("-")
@classmethod
def from_path(cls, path: Path) -> Wheel | None:
if path is not None and path.suffix == ".whl" and len(path.stem.split("-")) >= 5: # noqa: PLR2004
return cls(path)
return None
@property
def distribution(self) -> str:
return self._parts[0]
@property
def version(self) -> str:
return self._parts[1]
@property
def version_tuple(self) -> tuple[int, ...]:
return self.as_version_tuple(self.version)
@staticmethod
def as_version_tuple(version: str) -> tuple[int, ...]:
result = []
for part in version.split(".")[0:3]:
try:
result.append(int(part))
except ValueError: # noqa: PERF203
break
if not result:
raise ValueError(version)
return tuple(result)
@property
def name(self) -> str:
return self.path.name
def support_py(self, py_version: str) -> bool:
name = f"{'-'.join(self.path.stem.split('-')[0:2])}.dist-info/METADATA"
with ZipFile(str(self.path), "r") as zip_file:
metadata = zip_file.read(name).decode("utf-8")
marker = "Requires-Python:"
requires = next((i[len(marker) :] for i in metadata.splitlines() if i.startswith(marker)), None)
if requires is None: # if it does not specify a python requires the assumption is compatible
return True
py_version_int = tuple(int(i) for i in py_version.split("."))
for require in (i.strip() for i in requires.split(",")):
# https://www.python.org/dev/peps/pep-0345/#version-specifiers
for operator, check in [
("!=", lambda v: py_version_int != v),
("==", lambda v: py_version_int == v),
("<=", lambda v: py_version_int <= v),
(">=", lambda v: py_version_int >= v),
("<", lambda v: py_version_int < v),
(">", lambda v: py_version_int > v),
]:
if require.startswith(operator):
ver_str = require[len(operator) :].strip()
version = tuple((int(i) if i != "*" else None) for i in ver_str.split("."))[0:2]
if not check(version):
return False
break
return True
def __repr__(self) -> str:
return f"{self.__class__.__name__}({self.path})"
def __str__(self) -> str:
return str(self.path)
def discover_wheels(from_folder: Path, distribution: str, version: str | None, for_py_version: str) -> list[Wheel]:
wheels = []
for filename in from_folder.iterdir():
wheel = Wheel.from_path(filename)
if (
wheel
and wheel.distribution == distribution
and (version is None or wheel.version == version)
and wheel.support_py(for_py_version)
):
wheels.append(wheel)
return sorted(wheels, key=attrgetter("version_tuple", "distribution"), reverse=True)
class Version:
#: the version bundled with virtualenv
bundle = "bundle"
embed = "embed"
#: custom version handlers
non_version = (bundle, embed)
@staticmethod
def of_version(value: str | None) -> str | None:
return None if value in Version.non_version else value
@staticmethod
def as_pip_req(distribution: str, version: str | None) -> str:
return f"{distribution}{Version.as_version_spec(version)}"
@staticmethod
def as_version_spec(version: str | None) -> str:
of_version = Version.of_version(version)
return "" if of_version is None else f"=={of_version}"
__all__ = [
"Version",
"Wheel",
"discover_wheels",
]