← All tasks
pythonpsf/black #2703Reported task

dependency_tree broken tomli<2.0.0,>=0.2.6, it should be using latest version 2.0.0

envgap__psf__black-2703

01 / FAILURE SIGNATURE

Captured in a clean container

ERROR: Cannot install black==21.12b1.dev12+g61fe8418 and tomli==2.0.0 because these package versions have conflicting dependencies.

02 / ENVIRONMENT RECIPE

Base commit
61fe8418cc868723759fb08d76adab1542bb7630
Manifest
setup.py
Reproduce
git config --global --add safe.directory /work && python3 -m pip install setuptools==51.1.1 setuptools-scm==5.0.1 wheel==0.36.2 && python3 -m pip install --no-build-isolation . tomli==2.0.0 && python3 -c "import black; assert black.format_str('x=1', mode=black.FileMode()) == 'x = 1\n'; print(black.parse_pyproject_toml('pyproject.toml')['line_length'])"
Run under trace
python3 -c "import black; assert black.format_str('x=1', mode=black.FileMode()) == 'x = 1\n'; print(black.parse_pyproject_toml('pyproject.toml')['line_length'])"
Reference environment fix used for admission
diff --git a/setup.py b/setup.py
index a21bc872..e3c0e65b 100644
--- a/setup.py
+++ b/setup.py
@@ -99,7 +99,7 @@ setup(
     install_requires=[
         "click>=7.1.2",
         "platformdirs>=2",
-        "tomli>=0.2.6,<2.0.0",
+        "tomli>=0.2.6,<3.0.0",
         "typed-ast>=1.4.2; python_version < '3.8' and implementation_name == 'cpython'",
         "pathspec>=0.9.0, <1",
         "dataclasses>=0.6; python_version < '3.7'",

03 / ORIGINAL ISSUE TEXT

psf/black #2703 · read the original issue
<!--

Please make sure that the bug is not already fixed either in newer versions or the

current development version. To confirm this, you have three options:



1. Update Black's version if a newer release exists: `pip install -U black`

2. Use the online formatter at <https://black.vercel.app/?version=main>, which will use

   the latest main branch.

3. Or run _Black_ on your machine:

   - create a new virtualenv (make sure it's the same Python version);

   - clone this repository;

   - run `pip install -e .[d,python2]`;

   - run `pip install -r test_requirements.txt`

   - make sure it's sane by running `python -m pytest`; and

   - run `black` like you did last time.

-->



**Describe the bug**

black 21.12b0 requires tomli<2.0.0,>=0.2.6, but you have tomli 2.0.0 which is incompatible.



<!-- A clear and concise description of what the bug is. -->



**To Reproduce**



<!--

Minimal steps to reproduce the behavior with source code and Black's configuration.

-->



For example, take this code:



```python

this = "code"

```



And run it with these arguments:



```sh

$ black file.py --target-version py39

```



The resulting error is:



> cannot format file.py: INTERNAL ERROR: ...



**Expected behavior**



<!-- A clear and concise description of what you expected to happen. -->



**Environment**



<!-- Please complete the following information: -->



- Black's version: <!-- e.g. [main] -->

- OS and Python version: <!-- e.g. [Linux/Python 3.7.4rc1] -->



**Additional context**



<!-- Add any other context about the problem here. -->

Continue on GitHub ↗

04 / LABELS

Labels checked by running the task · assistant reviewed

conflictmisspecificationsecurity
Label rules and the text that matched
[
  {
    "category": "conflict",
    "rule": "signature.incompatible_declared_requirements",
    "source": "failure_signature",
    "excerpt": "ERROR: Cannot install black==21.12b1.dev12+g61fe8418 and tomli==2.0.0 because these package versions have conflicting dependencies."
  },
  {
    "category": "misspecification",
    "rule": "diff.changes_existing_manifest_line",
    "source": "manifest_diff:setup.py",
    "excerpt": "-        \"tomli>=0.2.6,<2.0.0\",\n+        \"tomli>=0.2.6,<3.0.0\","
  },
  {
    "category": "security",
    "rule": "audit.nonempty_security_flags",
    "source": "security_flags",
    "excerpt": "[\"unpinned\"]"
  }
]

Historical install-only results are not EnvGap validation.

Bootstrap commands are explicit benchmark prerequisites executed identically before original and gold manifests; they prevent unrelated modern build-tool/API drift.

Current registry downloads are permitted in these preparation checks. Unpinned transitives are not historically reconstructed.

Gold was verified in a fresh envgap-python-eval container; runtime tracing is scored separately by envgap eval.

Preparation uses current registries. Historical package availability is not enforced here; execution metadata records this limitation separately from the oracle's date-bounding policy.