← All tasks
pythonpython-poetry/poetry #1584Not a task: not reproduced

Poetry export does not include setuptools even when it is a direct dependency.

envgap__python-poetry__poetry-1584

Original GitHub issue ↗Opened 2019-11-15

01 / FAILURE SIGNATURE

As reported upstream

ERROR: Project file:///workspace has a 'pyproject.toml' and its build backend is missing the 'build_editable' hook. Since it does not have a 'setup.py' nor a 'setup.cfg', it cannot be installed in editable mode. Consider using a build backend that supports PEP 660.
Not a benchmark task.
  • No curated issue-specific recipe or verified environment fix is available.

02 / ENVIRONMENT RECIPE

Base commit
Not freshly verified
Manifest
requirements.txt
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

python-poetry/poetry #1584 · read the original issue
<!--

  Hi there! Thank you for discovering and submitting an issue.



  Before you submit this; let's make sure of a few things.

  Please make sure the following boxes are ticked if they are correct.

  If not, please try and fulfill these first.

-->



<!-- Checked checkbox should look like this: [x] -->

- [x] I am on the [latest](https://github.com/sdispater/poetry/releases/latest) Poetry version.

- [x] I have searched the [issues](https://github.com/sdispater/poetry/issues) of this repo and believe that this is not a duplicate.

- [x] If an exception occurs when executing a command, I executed it again in debug mode (`-vvv` option).



<!--

  Once those are done, if you're able to fill in the following list with your information,

  it'd be very helpful to whoever handles the issue.

-->



- **OS version and name**: Fedora 31

- **Poetry version**: 1.0.0b4 (at the time of writing b5 is not on PyPi, will retry later on)

- **Link of a [Gist](https://gist.github.com/) with the contents of your pyproject.toml file**: https://gist.github.com/apollo13/1d0c72978531d3a5688f1e3847fa6fe6



## Issue

Using the `pyproject.toml` file from the Gist and executing `poetry lock` I get the following lockfile:

```

[[package]]

category = "main"

description = "WSGI HTTP Server for UNIX"

name = "gunicorn"

optional = false

python-versions = ">=3.4"

version = "20.0.0"



[package.dependencies]

setuptools = ">=3.0"



[package.extras]

eventlet = ["eventlet (>=0.9.7)"]

gevent = ["gevent (>=0.13)"]

setproctitle = ["setproctitle"]

tornado = ["tornado (>=0.2)"]



[metadata]

content-hash = "20c8a1cc7d149b3ad58ca5063dfd37654f03ba65ee8b484d2faefe7ce28b7daf"

python-versions = "^3.7"



[metadata.files]

gunicorn = [

    {file = "gunicorn-20.0.0-py2.py3-none-any.whl", hash = "sha256:0806b5e8a2eb8ba9ac1be65d7b743ec896fc25f5d6cb16c5e051540157b315bb"},

    {file = "gunicorn-20.0.0.tar.gz", hash = "sha256:ef69dea4814df95e64e3f40b47b7ffedc6911c5009233be9d01cfd0d14aa3f50"},

]

```

setuptools is correctly discovered as dependency of gunicorn (see https://github.com/benoitc/gunicorn/blob/94ab2091173c6037b504f94e56f4e88816d540bf/setup.py#L71-L77 -- it does indeed require it), but the lockfile *does not contain* any hashes for setuptools.

If I now export to requirements.txt the file looks like this:

```

gunicorn==20.0.0 \

    --hash=sha256:0806b5e8a2eb8ba9ac1be65d7b743ec896fc25f5d6cb16c5e051540157b315bb \

    --hash=sha256:ef69dea4814df95e64e3f40b47b7ffedc6911c5009233be9d01cfd0d14aa3f50

```

Which is not installable with `pip install --require-hashes --force-reinstall -r requirements.txt` (note the `--require-hases` there):

```

Collecting gunicorn==20.0.0 (from -r requirements.txt (line 1))

  Using cached https://files.pythonhosted.org/packages/60/0d/3dbda0324f5bf007f3274e5ea09f0f3bcbf0ca01a75b80ff4f1ff9f8ecfd/gunicorn-20.0.0-py2.py3-none-any.whl

Collecting setuptools>=3.0 (from gunicorn==20.0.0->-r requirements.txt (line 1))

ERROR: In --require-
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]

Issue-specific recipe and runtime smoke command require review against the complete issue and repository.

Legacy reproduction is generic install-only; match the actual issue failure before admission.