Skip to content

Fix union(range, public_version) to fill local-variant punctures - #950

Merged
radoering merged 2 commits into
python-poetry:mainfrom
dimbleby:union-bug
Jun 11, 2026
Merged

radoering merged 2 commits into
python-poetry:mainfrom
dimbleby:union-bug

Conversation

@dimbleby

@dimbleby dimbleby commented Jun 6, 2026

Copy link
Copy Markdown
Contributor

The constraint algebra treated '==X' as the literal point [X, X] when computing 'range.union(public_X)', returning the range unchanged whenever the range already allowed X. But per PEP 440 release-equality '==X' also matches every local-tagged variant 'X+local', so a range whose bound is such a variant (e.g. '>=X,<X+local' or '>X+local,<Y') must be broadened to include those variants in the union.

Apply the broadening symmetrically in VersionRange.union(Version), handling both bounds in a single pass, and delegate Version.union(non Version) to the other operand so the rules apply regardless of operand order.

Resolves: python-poetry#

  • Added tests for changed code.
  • Updated documentation for changed code.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 1 issue, and left some high level feedback:

  • In the parametrized test_union_with_public_version_is_symmetric, the parameter names min and max shadow builtins and make the test harder to read; consider renaming them (e.g., min_version, max_version) for clarity.
  • The broadening of the upper bound using other.stable.next_patch() in VersionRange.union assumes other behaves like a final release; it may be worth explicitly considering or guarding how this behaves for non-final versions (pre/dev/post releases) to ensure it matches the intended PEP 440 semantics.
Prompt for AI Agents
Please address the comments from this code review:

## Overall Comments
- In the parametrized `test_union_with_public_version_is_symmetric`, the parameter names `min` and `max` shadow builtins and make the test harder to read; consider renaming them (e.g., `min_version`, `max_version`) for clarity.
- The broadening of the upper bound using `other.stable.next_patch()` in `VersionRange.union` assumes `other` behaves like a final release; it may be worth explicitly considering or guarding how this behaves for non-final versions (pre/dev/post releases) to ensure it matches the intended PEP 440 semantics.

## Individual Comments

### Comment 1
<location path="tests/constraints/version/test_version_range.py" line_range="738-756" />
<code_context>
     assert isinstance(result, EmptyConstraint)


+def test_union_upper_bound_local_with_public_extends_to_next_patch() -> None:
+    """``>=X,<X+local ∪ ==X`` broadens the upper bound to
+    ``X.next_patch()`` (exclusive). ``==X`` matches every ``X+local``
+    variant by PEP 440 release-equality, so the union must cover them.
+    """
+    range_below = VersionRange(
+        Version.parse("0.21.0"),
+        Version.parse("0.21.0+cpu"),
+        include_min=True,
+        include_max=False,
+    )
+    public = Version.parse("0.21.0")
+    expected = VersionRange(
+        Version.parse("0.21.0"),
+        Version.parse("0.21.1"),
+        include_min=True,
+        include_max=False,
+    )
+    assert range_below.union(public) == expected
+
+
</code_context>
<issue_to_address>
**suggestion (testing):** Add a case where both bounds are local variants of the same public version to ensure the range collapses as intended

Current tests only cover cases where one bound is local and the other is public. Please add a case where both bounds are local variants of the same public version (e.g. `>=0.21.0+cpu,<=0.21.0+gpu ∪ ==0.21.0`) and assert it collapses to `[0.21.0, 0.21.1)`, checking both `range ∪ ==X` and `==X ∪ range` for symmetry.

```suggestion
def test_union_upper_bound_local_with_public_extends_to_next_patch() -> None:
    """``>=X,<X+local ∪ ==X`` broadens the upper bound to
    ``X.next_patch()`` (exclusive). ``==X`` matches every ``X+local``
    variant by PEP 440 release-equality, so the union must cover them.
    """
    range_below = VersionRange(
        Version.parse("0.21.0"),
        Version.parse("0.21.0+cpu"),
        include_min=True,
        include_max=False,
    )
    public = Version.parse("0.21.0")
    expected = VersionRange(
        Version.parse("0.21.0"),
        Version.parse("0.21.1"),
        include_min=True,
        include_max=False,
    )
    assert range_below.union(public) == expected


def test_union_local_bounds_with_public_collapses_to_next_patch() -> None:
    """``>=X+local1,<=X+local2 ∪ ==X`` collapses to ``[X, X.next_patch())``.

    Both bounds are local variants of the same public version ``X``.
    Since ``==X`` matches all of them by PEP 440 release-equality, the
    union must cover the entire public range up to ``X.next_patch()``.
    """
    range_locals = VersionRange(
        Version.parse("0.21.0+cpu"),
        Version.parse("0.21.0+gpu"),
        include_min=True,
        include_max=True,
    )
    public = Version.parse("0.21.0")
    expected = VersionRange(
        Version.parse("0.21.0"),
        Version.parse("0.21.1"),
        include_min=True,
        include_max=False,
    )

    # range ∪ ==X
    assert range_locals.union(public) == expected
    # ==X ∪ range (symmetry)
    assert public.union(range_locals) == expected
```
</issue_to_address>

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
Comment thread tests/constraints/version/test_version_range.py
Comment thread src/poetry/core/constraints/version/version_range.py
The constraint algebra treated '==X' as the literal point [X, X] when
computing 'range.union(public_X)', returning the range unchanged
whenever the range already allowed X. But per PEP 440 release-equality
'==X' also matches every local-tagged variant 'X+local', so a range
whose bound is such a variant (e.g. '>=X,<X+local' or '>X+local,<Y')
must be broadened to include those variants in the union.

Apply the broadening symmetrically in VersionRange.union(Version),
handling both bounds in a single pass, and delegate Version.union(non
Version) to the other operand so the rules apply regardless of operand
order.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- remove mostly duplicated test and test for symmetry in other tests instead
- add test with both local bounds
@radoering
radoering merged commit d2041c1 into python-poetry:main Jun 11, 2026
19 checks passed
@dimbleby
dimbleby deleted the union-bug branch June 11, 2026 12:54
mwalbeck pushed a commit to mwalbeck/docker-python-poetry that referenced this pull request Sep 26, 2026
This PR contains the following updates:

| Package | Update | Change | Pending |
|---|---|---|---|
| [poetry](https://github.com/python-poetry/poetry) ([changelog](https://python-poetry.org/history/)) | minor | `2.4.3` → `2.5.0` | `2.5.1` |

---

### Release Notes

<details>
<summary>python-poetry/poetry (poetry)</summary>

### [`v2.5.0`](https://github.com/python-poetry/poetry/blob/HEAD/CHANGELOG.md#250---2026-09-19)

[Compare Source](python-poetry/poetry@2.4.3...2.5.0)

##### Added

- Add an `installer.builtin-uninstall` setting to uninstall packages with a built-in uninstaller instead of invoking `pip uninstall` ([#&#8203;10931](python-poetry/poetry#10931)).
- Add official support for Python 3.15 ([#&#8203;11046](python-poetry/poetry#11046)).

##### Changed

- Do not send credentials configured for an `https` repository via `http` ([#&#8203;11073](python-poetry/poetry#11073)).
- Fail with an error when the current Python version is not compatible with the project and `virtualenvs.create` is `false` ([#&#8203;10941](python-poetry/poetry#10941)).
- Validate version constraints that are entered interactively in `poetry init` ([#&#8203;10909](python-poetry/poetry#10909)).
- Include the path of the `pyproject.toml` file in the message about already present packages in `poetry add` ([#&#8203;10908](python-poetry/poetry#10908)).
- Improve performance of processing package links and repository pages ([#&#8203;10895](python-poetry/poetry#10895),
  [#&#8203;10896](python-poetry/poetry#10896),
  [#&#8203;10903](python-poetry/poetry#10903),
  [#&#8203;10949](python-poetry/poetry#10949),
  [#&#8203;10951](python-poetry/poetry#10951),
  [#&#8203;10953](python-poetry/poetry#10953)).
- Improve performance of dependency resolution ([#&#8203;10907](python-poetry/poetry#10907),
  [#&#8203;10954](python-poetry/poetry#10954)).
- Improve performance of choosing and installing wheels ([#&#8203;10905](python-poetry/poetry#10905),
  [#&#8203;10958](python-poetry/poetry#10958)).
- Improve performance by avoiding redundant keyring lookups for repositories without credentials ([#&#8203;10959](python-poetry/poetry#10959)).
- Improve performance by reducing the number of subprocesses to discover virtual environment data ([#&#8203;11042](python-poetry/poetry#11042)).
- Improve performance of `poetry search` for single-token queries ([#&#8203;10906](python-poetry/poetry#10906)).
- Improve startup time by deferring the import of `requests` ([#&#8203;11004](python-poetry/poetry#11004)).
- Improve performance of schema validation by caching compiled JSON schema validators ([#&#8203;11033](python-poetry/poetry#11033)).

##### Fixed

- Fix an issue where credentials of the wrong repository were used under certain circumstances when multiple repositories were configured on the same host ([#&#8203;11072](python-poetry/poetry#11072)).
- Fix an issue where credentials of a repository on another host were used for git dependencies if the path of the URL was the same ([#&#8203;11074](python-poetry/poetry#11074)).
- Fix an issue where dependency resolution failed for conflicting requirements of different packages even though the requirements had mutually exclusive markers ([#&#8203;10944](python-poetry/poetry#10944)).
- Fix an issue where dependency resolution failed when the same package was required with different extras in several optional dependencies or dependency groups ([#&#8203;10943](python-poetry/poetry#10943)).
- Fix an issue where dependency resolution failed with a `KeyError` ([#&#8203;11008](python-poetry/poetry#11008)).
- Fix an issue where the dependencies of an extra were missing in the lock file after adding the extra to a locked dependency, e.g. a git dependency, in the `pyproject.toml` file ([#&#8203;10987](python-poetry/poetry#10987)).
- Fix an issue where a path or git dependency was not reinstalled when its `develop` setting changed ([#&#8203;11022](python-poetry/poetry#11022)).
- Fix an issue where scripts of type `file` were not installed when installing the project ([#&#8203;10736](python-poetry/poetry#10736)).
- Fix an issue where GUI scripts were not installed when installing the project ([#&#8203;10973](python-poetry/poetry#10973)).
- Fix an issue where a relative path was written to `direct_url.json` for path dependencies ([#&#8203;10917](python-poetry/poetry#10917)).
- Fix an issue where `poetry show <package>` showed a version that was not relevant for the current environment if there were multiple versions of the package in the lock file ([#&#8203;11003](python-poetry/poetry#11003)).
- Fix an issue where `poetry show --outdated` did not find newer versions of packages from sources with `explicit` priority ([#&#8203;10982](python-poetry/poetry#10982)).
- Fix an issue where `poetry env activate` ignored the environment that was determined by the application, e.g. when using `--directory` ([#&#8203;10916](python-poetry/poetry#10916)).
- Fix an issue where `poetry init` proposed an invalid package name if the directory name was not a valid package name ([#&#8203;10975](python-poetry/poetry#10975)).

##### Docs

- Document the `--license` option of `poetry init` and `poetry new` ([#&#8203;11064](python-poetry/poetry#11064)).
- Clarify which dependencies are locked when running `poetry update` with dependency groups ([#&#8203;11024](python-poetry/poetry#11024)).
- Clarify the portability of path dependencies ([#&#8203;11020](python-poetry/poetry#11020)).
- Clarify the usage of `poetry run` with console scripts ([#&#8203;10984](python-poetry/poetry#10984)).
- Clarify what `--no-cache` disables ([#&#8203;10915](python-poetry/poetry#10915)).
- Document how to use package sources for `poetry self update` ([#&#8203;10923](python-poetry/poetry#10923)).
- Fix the stale minimum Python version ([#&#8203;11050](python-poetry/poetry#11050)).
- Update outdated links ([#&#8203;10913](python-poetry/poetry#10913),
  [#&#8203;10938](python-poetry/poetry#10938),
  [#&#8203;11000](python-poetry/poetry#11000),
  [#&#8203;11043](python-poetry/poetry#11043)).

##### poetry-core ([`2.5.0`](https://github.com/python-poetry/poetry-core/releases/tag/2.5.0))

- Add Python 3.15 to the automatically generated classifiers ([#&#8203;961](python-poetry/poetry-core#961)).
- Fix an issue where a `<V` version constraint wrongly allowed pre-releases of `V` in some cases ([#&#8203;939](python-poetry/poetry-core#939)).
- Fix an issue where version ranges with coincident bounds were not recognized as empty ([#&#8203;939](python-poetry/poetry-core#939)).
- Fix an issue where the string representation of a version union did not describe the same constraint after being parsed again ([#&#8203;939](python-poetry/poetry-core#939)).
- Fix an issue where the intersection of a version range with a local version resulted in a wrong constraint ([#&#8203;949](python-poetry/poetry-core#949)).
- Fix an issue where the union of a version range and a public version did not include all local versions of the public version ([#&#8203;950](python-poetry/poetry-core#950)).
- Fix an issue where the union of a public version and one of its local versions did not result in the public version ([#&#8203;966](python-poetry/poetry-core#966)).
- Fix an issue where the difference between a public version and one of its local versions still allowed the local version, which could result in an infinite loop during dependency resolution ([#&#8203;953](python-poetry/poetry-core#953)).
- Fix an issue where a version range that excluded some local versions of a public version was wrongly considered to allow all versions of the public version ([#&#8203;959](python-poetry/poetry-core#959)).
- Fix an issue where a `!= <value>` constraint was wrongly considered to allow all values of a `<value> not in` constraint ([#&#8203;955](python-poetry/poetry-core#955)).
- Fix an issue where merging `platform_release` markers with incompatible constraint types failed ([#&#8203;956](python-poetry/poetry-core#956)).
- Fix an issue where the string representation of a version range whose upper bound only consists of zeros raised an `IndexError` ([#&#8203;964](python-poetry/poetry-core#964)).
- Fix an issue where formatting a Python constraint that only allows unknown Python versions raised an `IndexError` ([#&#8203;971](python-poetry/poetry-core#971)).
- Fix an issue where marker values containing spaces could not be parsed ([#&#8203;972](python-poetry/poetry-core#972)).
- Fix an issue where the upper bound of a `~=` constraint was wrong for versions with more than three release segments ([#&#8203;973](python-poetry/poetry-core#973)).
- Fix an issue where the filename of a link created from a Windows path was wrong and reject filenames containing path separators ([#&#8203;974](python-poetry/poetry-core#974)).

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI2MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Reviewed-on: https://git.walbeck.it/mwalbeck/docker-python-poetry/pulls/1762
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants