-
Notifications
You must be signed in to change notification settings - Fork 1.2k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Fall back to distributions without hashes in resolver (#2949)
## Summary This represents a change to `--require-hashes` in the event that we don't find a matching hash from the registry. The behavior in this PR is closer to pip's. Prior to this PR, if a distribution had no reported hash, or only mismatched hashes, we would mark it as incompatible. Now, we mark it as compatible, but we use the hash-agreement as part of the ordering, such that we prefer any distribution with a matching hash, then any distribution with no hash, then any distribution with a mismatched hash. As a result, if an index reports incorrect hashes, but the user provides the correct one, resolution now succeeds, where it would've failed. Similarly, if an index omits hashes altogether, but the user provides the correct one, resolution now succeeds, where it would've failed. If we end up picking a distribution whose hash ultimately doesn't match, we'll reject it later, after resolution.
- Loading branch information
1 parent
1f3b5bb
commit c18551f
Showing
5 changed files
with
319 additions
and
183 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.