Skip to content

revert: e2b floor sync in Python Code Interpreter/Desktop postVersion (#1926), unblocking the release - #1951

Merged
mishushakov merged 2 commits into
mainfrom
devin/1791316341-postversion-floor-only-on-release
Oct 6, 2026
Merged

mishushakov merged 2 commits into
mainfrom
devin/1791316341-postversion-floor-only-on-release

Conversation

@devin-ai-integration

@devin-ai-integration devin-ai-integration Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fixes the failed release run Publish / Build and test SDK on main (1de92fc). Reverts #1926.

packages/desktop-python postVersion: e2b-desktop 2.6.1 => 2.6.1
...
packages/desktop-python postPublish: error: Local file and index file do not match for e2b_desktop-2.6.1-py3-none-any.whl. Local: sha256=6b05209c…, Remote: sha256=cf1cfd6d…
 ERR_PNPM_RECURSIVE_RUN_FIRST_FAIL  @e2b/desktop-python@2.6.1 postPublish: `uv build && uv publish --trusted-publishing always --check-url https://pypi.org/simple/`

Root cause: #1926 made postVersion rewrite e2b>=<sdk version> in pyproject.toml on every release, even when the package itself is not released. This release only bumped python-sdk, so Desktop's floor went from e2b>=2.44.0 to e2b>=2.53.0 while its version stayed at 2.6.1. pnpm run -r postPublish rebuilds every Python package, and uv publish --check-url only skips files that are byte-identical to what's already on PyPI. The rebuilt e2b_desktop-2.6.1 had different METADATA, so uv rejected it, and the whole publish aborted. Nothing was uploaded: PyPI still has e2b 2.52.1 and e2b-code-interpreter 2.10.1, and changeset publish (npm) never ran.

Changes:

  • postVersion in code-interpreter-python / desktop-python goes back to uv version --frozen <own version> (a revert of chore: sync the e2b floor of the Python Code Interpreter and Desktop SDKs on version #1926).
  • Restores e2b>=2.44.0,<3.0.0 in packages/desktop-python/pyproject.toml. The release commit 2438c92 had written e2b>=2.53.0 there, and 2.6.1 on PyPI declares >=2.44.0. Without this, the next release would fail the same way.
  • code-interpreter-python keeps the e2b>=2.53.0 that 2438c92 wrote. It came with that package's own version bump (2.10.2, not yet published), so there's no mismatch.

Verification

  • uv build (uv 0.10.0, the CI version) of desktop-python with the restored floor gives the same sha256 as both files on PyPI (wheel cf1cfd6d…, sdist dc715a77…). So --check-url will skip them again.

Follow-up

  • The 2.53.0 / 2.10.2 versions are committed on main but were never published to npm or PyPI. The next release with a changeset bumps the versions past them (the workflow keeps failed versions on purpose).
  • After this revert, Desktop's e2b floor has to be bumped by hand again.

Link to Devin session: https://app.devin.ai/sessions/328bb32ba7344529858415273d98c0ec
Open in Devin Desktop: https://app.devin.ai/desktop/session/328bb32ba7344529858415273d98c0ec?variant=devin


Devin Review

…ktop when they are released

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@cla-bot cla-bot Bot added the cla-signed label Oct 6, 2026
@changeset-bot

changeset-bot Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 956b915

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T19:56:05.083028Z d45d531 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@devin-ai-integration devin-ai-integration Bot left a comment •

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

Newer findings are available below. Devin Review posted a newer report on this PR, in addition to the findings presented here.

🔍 Devin Review: 1 flag

Not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)

Devin Review

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Package Artifacts

Built from 5e2dc8c. Download artifacts from this workflow run.

JS SDK (e2b@2.53.1-devin-1791316341-postversion-floor-only-on-release.0):

npm install ./e2b-2.53.1-devin-1791316341-postversion-floor-only-on-release.0.tgz

CLI (@e2b/cli@2.21.2-devin-1791316341-postversion-floor-only-on-release.0):

npm install ./e2b-cli-2.21.2-devin-1791316341-postversion-floor-only-on-release.0.tgz

Code Interpreter JS SDK (@e2b/code-interpreter@2.8.2-devin-1791316341-postversion-floor-only-on-release.0):

npm install ./e2b-code-interpreter-2.8.2-devin-1791316341-postversion-floor-only-on-release.0.tgz

Desktop JS SDK (@e2b/desktop@2.4.1-devin-1791316341-postversion-floor-only-on-release.0):

npm install ./e2b-desktop-2.4.1-devin-1791316341-postversion-floor-only-on-release.0.tgz

Python SDK (e2b==2.53.0+devin.1791316341.postversion.floor.only.on.release):

pip install ./e2b-2.53.0+devin.1791316341.postversion.floor.only.on.release-py3-none-any.whl

Code Interpreter Python SDK (e2b-code-interpreter==2.10.2+devin.1791316341.postversion.floor.only.on.release):

pip install ./e2b_code_interpreter-2.10.2+devin.1791316341.postversion.floor.only.on.release-py3-none-any.whl

Desktop Python SDK (e2b-desktop==2.6.1+devin.1791316341.postversion.floor.only.on.release):

pip install ./e2b_desktop-2.6.1+devin.1791316341.postversion.floor.only.on.release-py3-none-any.whl

@devin-ai-integration devin-ai-integration Bot changed the title fix(release): only raise the e2b floor of Python Code Interpreter/Desktop when they are released revert: e2b floor sync in Python Code Interpreter/Desktop postVersion (#1926), unblocking the release Oct 6, 2026

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TASTE.md review: 0 violations. The diff only changes Python release tooling (postVersion scripts in code-interpreter-python / desktop-python) and the e2b dependency floor in desktop-python/pyproject.toml — all outside the SDK public API surface the principles govern. Checked T-1 (the two scripts remain identical mirrors; the JS packages have no counterpart script, so no parity gap), T-56 (the SDK version is still derived from package.json / pyproject.toml, nothing hardcoded), and T-43 (interpolated values stay properly quoted in the composed commands). The [ "$(uv version --short)" = "$v" ] guard correctly scopes the floor bump to releases of the package itself.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 new potential issue.

2 flags not posted on this PR by your GitHub settings — view them in Devin Review. (Configure)

Devin Review

Comment thread packages/code-interpreter-python/package.json
@mishushakov
mishushakov enabled auto-merge (squash) October 6, 2026 19:58
@mishushakov
mishushakov merged commit 3ebd4b7 into main Oct 6, 2026
30 checks passed
@mishushakov
mishushakov deleted the devin/1791316341-postversion-floor-only-on-release branch October 6, 2026 19:59

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nothing blocking. The comments below are optional suggestions. There is no need to push a fix for them before merging.

Comment thread packages/desktop-python/package.json Outdated
"scripts": {
"test": "uv run pytest -n 4 --verbose -x",
"postVersion": "uv version --frozen $(pnpm pkg get version --workspaces=false | tr -d \\\") && uv add --frozen \"$(node -p \"const v = require('../python-sdk/package.json').version; 'e2b>=' + v + ',<' + (Number(v.split('.')[0]) + 1) + '.0.0'\")\"",
"postVersion": "v=$(pnpm pkg get version --workspaces=false | tr -d \\\"); [ \"$(uv version --short)\" = \"$v\" ] || { uv version --frozen \"$v\" && uv add --frozen \"$(node -p \"const v = require('../python-sdk/package.json').version; 'e2b>=' + v + ',<' + (Number(v.split('.')[0]) + 1) + '.0.0'\")\"; }",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 (optional) A partial failure during postVersion now makes the e2b floor permanently stuck out of sync, even though later runs report success. The guard [ "$(uv version --short)" = "$v" ] || { uv version --frozen "$v" && uv add --frozen "e2b>=..."; } (packages/desktop-python/package.json:7, same at packages/code-interpreter-python/package.json:7) only compares the package's own version. If uv version --frozen "$v" succeeds but the chained uv add --frozen fails, pyproject.toml's version is already written, so every subsequent run sees the version already matches and skips, never retrying the e2b floor update. Before this diff the script always re-ran both commands unconditionally, so it was self-healing; now it is not. Fix: only skip when both the version and the e2b dependency spec already match the target, or make the version-set and add steps atomic so a half-applied run is still detected as incomplete.

Why this was flagged

Trigger: a local pnpm run postVersion (per the PR's own verification section) or any re-invocation of this script where uv version --frozen "$v" at packages/desktop-python/package.json:7 succeeds but the following &&-chained uv add --frozen "e2b>=..." fails (network hiccup, uv registry error, or the node -p subshell reading ../python-sdk/package.json failing). The first command already wrote the new version into pyproject.toml on disk. On the next run, [ "$(uv version --short)" = "$v" ] now evaluates true, so the || branch that calls uv add --frozen never runs again, and the script exits 0 (success) without ever correcting the e2b floor. On the base branch (unconditional postVersion), every run re-executed both commands, so a retry would always re-attempt and eventually fix the floor — that self-healing property is lost by this diff's guard. Same pattern at packages/code-interpreter-python/package.json:7.

Verification: nit. Real but low-likelihood regression introduced by the new guard. At packages/desktop-python/package.json:7 (identical at packages/code-interpreter-python/package.json:7): the guard keys solely on the package's own version, which is exactly what uv version --frozen "$v" persists to disk; uv add --frozen "e2b>=..." does not affect that key.

mishushakov pushed a commit that referenced this pull request Oct 6, 2026
## Summary
The last Release run committed the version bumps in 2438c92
(`e2b`/`@e2b/python-sdk` 2.53.0, `@e2b/code-interpreter` 2.8.1,
`@e2b/code-interpreter-python` 2.10.2), but the publish step then failed
on the `e2b-desktop` PyPI hash mismatch that #1951 fixed. Nothing was
published to npm or PyPI, and no tags were created. The commit consumed
the changesets, so `is_release.sh` now finds none and a Release rerun
would skip publishing.

This PR adds a single patch changeset for the four packages, so the next
Release run publishes those changes (#1949, #1927, and the
code-interpreter Unicode fix). Their CHANGELOG entries are already under
the 2.53.0 / 2.8.1 / 2.10.2 headings.

`pnpm changeset status`:
```
e2b 2.53.1
@e2b/python-sdk 2.53.1
@e2b/code-interpreter 2.8.2
@e2b/code-interpreter-python 2.10.3
```
`e2b-desktop` is excluded. Its floor stays at `e2b>=2.44.0`, so its
rebuild matches the 2.6.1 already on PyPI.

Link to Devin session:
https://app.devin.ai/sessions/328bb32ba7344529858415273d98c0ec
Open in Devin Desktop:
https://app.devin.ai/desktop/session/328bb32ba7344529858415273d98c0ec?variant=devin
<!-- devin-review-badge-begin -->

---

<a href="https://app.devin.ai/review/e2b-dev/e2b/pull/1953"
target="_blank"><picture><source media="(prefers-color-scheme: dark)"
srcset="https://static.devin.ai/assets/gh-devin-review-dark.svg?v=4"><img
src="https://static.devin.ai/assets/gh-devin-review-light.svg?v=4"
alt="Devin Review"></picture></a>
<!-- devin-review-badge-end -->

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant