Skip to content

Parse requirements-style inputs into RequirementsInput - #21787

Merged
woodruffw merged 13 commits into
mainfrom
ww/req-newtype
Sep 18, 2026
Merged

woodruffw merged 13 commits into
mainfrom
ww/req-newtype

Conversation

@woodruffw

@woodruffw woodruffw commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

Summary

This adds a RequirementsInput API, which enumerates the Stdin, Local and Remote states discretely. The idea here is to make some of the current CLI behavior more correct by construction -- instead of parsing into a PathBuf and then trying to sniff what we really have, we parse into a RequirementsInput instead.

Some things to note:

  • This does the right default thing, i.e. file://... becomes RequirementsInput::Local instead of Remote with a file: scheme. And - becomes a RequirementsInput::Stdin.
  • This applies to --requirements, but also --constraints and any other flag that previously had local and remote requirements-style syntax.
  • We propagate RequirementsInput down to the parsing layer, meaning that we're now doing a better job of tracking the provenance of our inputs. This will be relevant when I resume uv audit: pylock.toml support #21601.
  • Right now we model - as RequirementsInput::Local, but that seems wrong. We probably want a new RequirementsInput::Stdin.
  • Because RequirementsInput::Remote is a DisplaySafeUrl, this also gets us free redaction in a few more places that weren't easy to cover before.

This also makes one behavioral change: we now handle remote nested requirements more correctly. Previously we would handle a subset of these incidentally, e.g.:

uv pip install -r https://example.com/foo/a.txt

and then a.txt:

-r b.txt

This would correctly fetch https://example.com/foo/b.txt.

However, if a.txt was this instead:

-r /b.txt

...we would attempt to load a local requirements file from /b.txt rather than https://example.com/b.txt. Now that requirements loading is more type-aware, we do the join correctly depending on whether it's a URL or a path.

This is super marginal in practice, but now our behavior matches pip's.

Test Plan

Updated the tests, and added new ones.

@woodruffw woodruffw self-assigned this Sep 17, 2026
@woodruffw woodruffw added the internal A refactor or improvement that is not user-facing label Sep 17, 2026
@woodruffw

Copy link
Copy Markdown
Member Author

NB d28726f is needed because #21067 added a test case where --find-links should give a local directory named https:links precedence over treatment as a URL.

Comment thread crates/uv-requirements-txt/src/lib.rs Outdated
@astral-sh-bot

astral-sh-bot Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

uv test inventory changes

This PR changes the tests when compared with the main base revision.

  • Added tests: 3
  • Removed tests: 0
  • Changed suites: 2
uv::it: +1 / -0

Added:

  • uv::it::requirements::parse_requirements_input

Removed: none

uv::pip_install: +2 / -0

Added:

  • uv::pip_install::pip_install::install_remote_requirements_txt_redacts_nested_url
  • uv::pip_install::pip_install::install_remote_requirements_txt_with_relative_include

Removed: none

@woodruffw
woodruffw marked this pull request as ready for review September 17, 2026 21:34
Comment thread crates/uv-configuration/src/requirements_input.rs Outdated
Comment thread crates/uv-configuration/src/requirements_input.rs
Comment thread crates/uv-configuration/src/requirements_input.rs
Comment thread crates/uv-configuration/src/requirements_input.rs Outdated
Comment thread crates/uv-configuration/src/requirements_input.rs Outdated
client_builder: &BaseClientBuilder<'_>,
cache: &mut SourceCache,
) -> Result<Self, RequirementsTxtFileError> {
let requirements_txt = requirements_txt.into();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

don't you mean to use from?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

My 0.02c is it's idiomatic when the receiver is impl Into<T> since there's no target ambiguity. @MichaReiser can strike me down though 🙂

Comment thread crates/uv-requirements-txt/src/lib.rs Outdated
Comment thread crates/uv-requirements-txt/src/lib.rs
Comment thread crates/uv-requirements-txt/src/lib.rs
Comment on lines +1226 to +1227
error: Invalid requirements input in `http://[LOCALHOST]/requirements.txt` at position 0: ambiguous user/pass authority in URL (not percent-encoded?): https:***@example.com/requirements.txt
cause: ambiguous user/pass authority in URL (not percent-encoded?): https:***@example.com/requirements.txt

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Probably outside this pr, but we're repeating this error clause

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, I'll do this as a fast-follow.

Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
@woodruffw
woodruffw merged commit 01776d7 into main Sep 18, 2026
120 checks passed
@woodruffw
woodruffw deleted the ww/req-newtype branch September 18, 2026 16:14

This branch was successfully deployed

1 active deployment
automations — ff4b5403 Deployed Sep 18, 2026 by woodruffw via review / security review #47131
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

internal A refactor or improvement that is not user-facing

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants