docs(install): measure the uv install channel and correct the per-tree wheel range
The comment on [tool.uv.sources] claimed the built wheel carries `Requires-Dist: llm-ingestion-guard<0.3,>=0.2`. That is the `v0.4.0` tag's range, not this tree's, and it had been stale since the pin moved. A wheel built from this tree carries `<0.4,>=0.3`, measured against the built wheel. The old value is kept and attributed to the tag it belongs to rather than substituted, because it is still true there. Five measurements were run before editing, on uv 0.9.8 with an empty cache, because the plan of record was to REMOVE this entry and the README claim it supports had never been measured in more than one form: - uv, direct: the README one-command install resolves the guard from the tag's [tool.uv.sources]. Third independent confirmation (07-25, 08-20, 08-21). - uv, transitive: a separate consumer project naming only this package still resolves the guard from the entry, because this package reaches it as a git source. Not previously measured. - pip, negative: installing this package alone fails with exactly the error the README names, and the message prints the tag's own range. - pip, positive: the README's two commands in order install clean and import. - core install: brings the guard and no binary parser packages. The entry is therefore load-bearing, not scaffolding: a wheel carries Requires-Dist and nothing else, so it cannot survive an index install, and while the guard is off-index removing it would break the documented uv path. No package index carries the guard today, which was the premise removal depended on. The README install block measured correct as published and is unchanged. Its test count had drifted: 596 with the [extract] extra, 589 passed and 7 skipped without, both measured today. Wheel metadata is byte-identical before and after, so the change is inert.
This commit is contained in:
parent
658b7aafe0
commit
fb9812fbe7
2 changed files with 29 additions and 10 deletions
|
|
@ -248,8 +248,11 @@ From a checkout, the test suite runs with:
|
|||
.venv/bin/python -m pytest
|
||||
```
|
||||
|
||||
The suite is the verification surface for everything above: 589 tests, run on
|
||||
2026-08-13 against this branch. It is not shipped in an installed
|
||||
The suite is the verification surface for everything above: 596 tests, run on
|
||||
2026-08-21 against this branch with the `[extract]` extra installed. Without
|
||||
the extra the same suite is 589 passed and 7 skipped, measured the same day:
|
||||
the seven cover the parser path, and the tests holding the fail-fast rejection
|
||||
for an uninstalled extra run in both. It is not shipped in an installed
|
||||
distribution — `tests/` lives at the repository root, so this command needs a
|
||||
clone rather than a `pip install`.
|
||||
|
||||
|
|
|
|||
|
|
@ -75,13 +75,29 @@ module = ["llm_ingestion_guard", "llm_ingestion_guard.*"]
|
|||
ignore_missing_imports = true
|
||||
|
||||
# Install CHANNEL for the guard, which is not on a package index yet. It is
|
||||
# uv-specific, and it reaches further than a dev-only setting: measured
|
||||
# 2026-07-25, a consumer installing this package from git WITH UV picks the
|
||||
# guard up from this tag automatically, because uv reads this file when it
|
||||
# builds from the source tree. pip does not read it — it resolves
|
||||
# [project.dependencies] alone and fails with "No matching distribution found
|
||||
# for llm-ingestion-guard" until the guard is installed from its own tag first
|
||||
# (README). Either way the range above stays the pin: the built wheel carries
|
||||
# `Requires-Dist: llm-ingestion-guard<0.3,>=0.2`, verified against the wheel.
|
||||
# uv-specific, and it reaches further than a dev-only setting: a consumer
|
||||
# installing this package from git WITH UV picks the guard up from this tag
|
||||
# automatically, because uv reads this file when it builds from the source
|
||||
# tree. Measured against an empty cache 2026-07-25, 2026-08-20, and
|
||||
# 2026-08-21 on uv 0.9.8. The 08-21 run also measured the TRANSITIVE form: a
|
||||
# separate consumer project naming only this package still resolves the guard
|
||||
# from the entry below, because this package reaches it as a git source.
|
||||
#
|
||||
# That source is the whole reach. A wheel carries Requires-Dist and nothing
|
||||
# else, so this entry cannot survive an index install — and while the guard is
|
||||
# off-index, removing it would break the one-command uv path the README
|
||||
# documents.
|
||||
#
|
||||
# pip does not read it at all: it resolves [project.dependencies] alone and
|
||||
# fails with "No matching distribution found for llm-ingestion-guard" until
|
||||
# the guard is installed from its own tag first (README; measured 2026-08-21,
|
||||
# both the failure and the two-command recovery).
|
||||
#
|
||||
# Either way the range above stays the pin, and the pin is per-tree: a wheel
|
||||
# built from THIS tree carries `Requires-Dist: llm-ingestion-guard<0.4,>=0.3`,
|
||||
# measured 2026-08-21 against the built wheel. The `<0.3,>=0.2` this comment
|
||||
# carried before was the `v0.4.0` tag's range — still true of that tag, never
|
||||
# true of this tree. Reading a range off one and installing it against the
|
||||
# other is the one combination that fails.
|
||||
[tool.uv.sources]
|
||||
llm-ingestion-guard = { git = "https://git.fromaitochitta.com/open/llm-ingestion-pipeline-security.git", tag = "v0.3.4" }
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue