Skip to content

uv.lock packages from a git source do not work#4139

Description

@scasagrande

馃悶 bug report

Affected Rule

pip.parse

Is this a regression?

not that I can tell

Description

pip.parse with uv_lock fails when the lock file contains a package with a git source entry with a rev hash due to the url in the lock file being used as the literal download url.

馃敩 Minimal Reproduction

same as #4084

pyproject.toml

...
mypackage = { git = "https://github.com/foo/bar", rev = "6323b05075dcb2347279e966a5a3b15b5ddc1d5b" }
...

uv.lock

...
[[package]]
name = "mypackage"
version = "0.0.1"
source = { git = "https://github.com/foo/bar?rev=6323b05075dcb2347279e966a5a3b15b5ddc1d5b#6323b05075dcb2347279e966a5a3b15b5ddc1d5b" }
dependencies = [
    ...
]
...

Resulting in https://github.com/foo/bar?rev=6323b05075dcb2347279e966a5a3b15b5ddc1d5b#6323b05075dcb2347279e966a5a3b15b5ddc1d5b being used as the download url in

result = rctx.download(
url = urls,
output = filename,
sha256 = rctx.attr.sha256,
integrity = rctx.attr.integrity if not rctx.attr.sha256 else "",
auth = get_auth(rctx, urls),
)

if pkg.get("source", {}).get("git"):
url = pkg["source"]["git"]
# Keep the revision in the URL, but exclude it from the repository filename.
url_path, _, _ = url.partition("?")
url_path, _, _ = url_path.partition("#")
_, _, filename = url_path.rpartition("/")
git_struct = struct(
filename = filename,
url = url,
digest = "",
kind = "git",
source = pkg["source"],
)

馃敟 Exception or Error

You end up getting wheel validation errors of the form:

INFO: Repo rules_python++pip+py_deps_311__mypackage defined by rule pip_archive in @@rules_python+//python/private/pypi:pip_archive.bzl
ERROR: /Users/steven/Library/Caches/bazel/_bazel_steven/6a872d6d476b57da51fdc42d46ec7cd5/external/rules_python+/python/private/repo_utils.bzl:101:16: An error occurred during the fetch of repository 'rules_python++pip+py_deps_311__mypackage':
   Traceback (most recent call last):
	File "/Users/steven/Library/Caches/bazel/_bazel_steven/6a872d6d476b57da51fdc42d46ec7cd5/external/rules_python+/python/private/pypi/pip_archive.bzl", line 317, column 36, in _pip_archive_impl
		pypi_repo_utils.execute_checked(
	File "/Users/steven/Library/Caches/bazel/_bazel_steven/6a872d6d476b57da51fdc42d46ec7cd5/external/rules_python+/python/private/pypi/pypi_repo_utils.bzl", line 140, column 38, in _execute_checked
		return repo_utils.execute_checked(
	File "/Users/steven/Library/Caches/bazel/_bazel_steven/6a872d6d476b57da51fdc42d46ec7cd5/external/rules_python+/python/private/repo_utils.bzl", line 247, column 29, in _execute_checked
		return _execute_internal(fail_on_error = True, *args, **kwargs)
	File "/Users/steven/Library/Caches/bazel/_bazel_steven/6a872d6d476b57da51fdc42d46ec7cd5/external/rules_python+/python/private/repo_utils.bzl", line 176, column 27, in _execute_internal
		return logger.fail((
	File "/Users/steven/Library/Caches/bazel/_bazel_steven/6a872d6d476b57da51fdc42d46ec7cd5/external/rules_python+/python/private/repo_utils.bzl", line 111, column 39, in lambda
		fail = lambda message_cb: _log(-1, "FAIL", message_cb, printer or fail),
	File "/Users/steven/Library/Caches/bazel/_bazel_steven/6a872d6d476b57da51fdc42d46ec7cd5/external/rules_python+/python/private/repo_utils.bzl", line 101, column 16, in _log
		printer("\nrules_python:{} {}:".format(
Error in fail: 
rules_python:pip_archive(@@rules_python++pip+py_deps_311__mypackage) FAIL: repo.execute: whl_library.BuildWheelFromSource(rules_python++pip+py_deps_311__mypackage, mypackage==0.0.1): end: failure:
  command: /Users/steven/Library/Caches/bazel/_bazel_steven/6a872d6d476b57da51fdc42d46ec7cd5/external/rules_python++python+python_3_11_host/python -B -m python.private.pypi.whl_installer.wheel_installer --requirement mypackage==0.0.1 --isolated --extra_pip_args "{\"arg\":[\"--find-links\",\".\"]}" --pip_data_exclude "{\"arg\":[]}" --environment "{\"arg\":{}}"
  return code: 1

馃實 Your Environment

Operating System:

  
macOS 26
  

Output of bazel version:

  
Bazelisk version: 1.29.0
Build label: 9.2.0
Build target: @@//src/main/java/com/google/devtools/build/lib/bazel:BazelServer
Build time: Mon Jul 13 18:19:39 2026 (1783966779)
Build timestamp: 1783966779
Build timestamp as int: 1783966779
  

Rules_python version:

  
2.3.2
  

and with latest main

Anything else relevant?

rules_pycross handles this scenario by cloning the url: https://github.com/jvolkman/rules_pycross/blob/1fb25cf1aa5019416a0ebb86d37ff1627736cf39/pycross/private/git_file.bzl#L3

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions