Skip to content

Declaring extras in constraints file installs also extra dependencies even if not instructed to #6628

Description

@mtvx

Environment

  • pip version: 19.1.1
  • Python version: 3.7.2
  • OS: KDE Neon

Description

In constraints file, when declaring a package with extras, all the dependencies of it get installed, even if actual requirement does not declare extras.

How to Reproduce

echo "requests[security]==2.20.1" > constraints.txt
pip install -c constraints.txt requests

Output

This installs not only direct requests dependencies:

Installing collected packages: chardet, certifi, idna, urllib3, requests

But also [security] extras:

Installing collected packages: idna, chardet, certifi, urllib3, six, pycparser, cffi, asn1crypto, cryptography, pyOpenSSL, requests

Expected behavior

pip should install only direct dependencies, even if extras are declared in constraints file.


This is such a simple case and easy to reproduce, it must be expected behavior. But why? And where is it documented?

Activity

  1. ghost added
    S: needs triageIssues/PRs that need to be triaged
    on Jun 20, 2019
  2. added
    C: constraintDealing with "constraints" (the -c option)
    C: extrasHandling optional dependencies
    type: bugA confirmed bug or unintended behavior
    on Jun 20, 2019
  3. ghost removed
    S: needs triageIssues/PRs that need to be triaged
    on Jun 20, 2019
  4. ghost removed
    S: needs triageIssues/PRs that need to be triaged
    on Jun 20, 2019
  5. ghost removed
    S: needs triageIssues/PRs that need to be triaged
    on Jun 20, 2019
  6. brainwane commented on Jun 24, 2020

    @brainwane
    Contributor

    @pfmoore @pradyunsg @uranusjr Do we need to resolve this before the 20.2b2, or do we just need to put a "known bug" item about it in the "migrating to the new resolver" guide?

  7. uranusjr commented on Jun 24, 2020

    @uranusjr
    Member

    I believe this already does not work in the new resolver (it rejects the constraints file immediately). This is worth a mention in the guide, along with other changes we made to constraints, but it shouldn’t be categorised as a bug, but a behavioural difference IMO. This issue is describing a “bug” in the old resolver that the new one does not have, but some may consider this is a feature the new resolver doesn’t (and won’t) implement

  8. pfmoore commented on Jun 24, 2020

    @pfmoore
    Member

    @uranusjr Is correct. This is a completely intentional change in constraints for the new resolver. I do think it needs clearly calling out in the release notes, though, as it's definitely a behaviour change and we'd need to get feedback on how it impacts people.

  9. brainwane commented on Jul 23, 2020

    @brainwane
    Contributor

    Am addressing in #8491.

  10. added a commit that references this issue on Jul 28, 2020
  11. brainwane commented on Aug 4, 2020

    @brainwane
    Contributor

    @pradyunsg @pfmoore @uranusjr ok to close this or rename it?

  12. pradyunsg commented on Aug 4, 2020

    @pradyunsg
    Member

    OK to close, given that we don't allow this form with the new resolver.

  13. uranusjr commented on Aug 15, 2020

    @uranusjr
    Member

    Closing since #8491 is merged and there’s not much else to do here.

  14. locked as resolved and limited conversation to collaborators on Oct 12, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    C: constraintDealing with "constraints" (the -c option)C: dependency resolutionAbout choosing which dependencies to installC: extrasHandling optional dependenciestype: bugA confirmed bug or unintended behavior

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions