Repository navigation
revert: e2b floor sync in Python Code Interpreter/Desktop postVersion (#1926), unblocking the release - #1951
Conversation
…ktop when they are released Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Note
Newer findings are available below. Devin Review posted a newer report on this PR, in addition to the findings presented here.
🔍 Devin Review: 1 flag
Not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Package ArtifactsBuilt from 5e2dc8c. Download artifacts from this workflow run. JS SDK ( npm install ./e2b-2.53.1-devin-1791316341-postversion-floor-only-on-release.0.tgzCLI ( npm install ./e2b-cli-2.21.2-devin-1791316341-postversion-floor-only-on-release.0.tgzCode Interpreter JS SDK ( npm install ./e2b-code-interpreter-2.8.2-devin-1791316341-postversion-floor-only-on-release.0.tgzDesktop JS SDK ( npm install ./e2b-desktop-2.4.1-devin-1791316341-postversion-floor-only-on-release.0.tgzPython SDK ( pip install ./e2b-2.53.0+devin.1791316341.postversion.floor.only.on.release-py3-none-any.whlCode Interpreter Python SDK ( pip install ./e2b_code_interpreter-2.10.2+devin.1791316341.postversion.floor.only.on.release-py3-none-any.whlDesktop Python SDK ( pip install ./e2b_desktop-2.6.1+devin.1791316341.postversion.floor.only.on.release-py3-none-any.whl |
There was a problem hiding this comment.
TASTE.md review: 0 violations. The diff only changes Python release tooling (postVersion scripts in code-interpreter-python / desktop-python) and the e2b dependency floor in desktop-python/pyproject.toml — all outside the SDK public API surface the principles govern. Checked T-1 (the two scripts remain identical mirrors; the JS packages have no counterpart script, so no parity gap), T-56 (the SDK version is still derived from package.json / pyproject.toml, nothing hardcoded), and T-43 (interpolated values stay properly quoted in the composed commands). The [ "$(uv version --short)" = "$v" ] guard correctly scopes the floor bump to releases of the package itself.
There was a problem hiding this comment.
Devin Review found 1 new potential issue.
2 flags not posted on this PR by your GitHub settings — view them in Devin Review. (Configure)
| "scripts": { | ||
| "test": "uv run pytest -n 4 --verbose -x", | ||
| "postVersion": "uv version --frozen $(pnpm pkg get version --workspaces=false | tr -d \\\") && uv add --frozen \"$(node -p \"const v = require('../python-sdk/package.json').version; 'e2b>=' + v + ',<' + (Number(v.split('.')[0]) + 1) + '.0.0'\")\"", | ||
| "postVersion": "v=$(pnpm pkg get version --workspaces=false | tr -d \\\"); [ \"$(uv version --short)\" = \"$v\" ] || { uv version --frozen \"$v\" && uv add --frozen \"$(node -p \"const v = require('../python-sdk/package.json').version; 'e2b>=' + v + ',<' + (Number(v.split('.')[0]) + 1) + '.0.0'\")\"; }", |
There was a problem hiding this comment.
🟡 (optional) A partial failure during postVersion now makes the e2b floor permanently stuck out of sync, even though later runs report success. The guard [ "$(uv version --short)" = "$v" ] || { uv version --frozen "$v" && uv add --frozen "e2b>=..."; } (packages/desktop-python/package.json:7, same at packages/code-interpreter-python/package.json:7) only compares the package's own version. If uv version --frozen "$v" succeeds but the chained uv add --frozen fails, pyproject.toml's version is already written, so every subsequent run sees the version already matches and skips, never retrying the e2b floor update. Before this diff the script always re-ran both commands unconditionally, so it was self-healing; now it is not. Fix: only skip when both the version and the e2b dependency spec already match the target, or make the version-set and add steps atomic so a half-applied run is still detected as incomplete.
Why this was flagged
Trigger: a local pnpm run postVersion (per the PR's own verification section) or any re-invocation of this script where uv version --frozen "$v" at packages/desktop-python/package.json:7 succeeds but the following &&-chained uv add --frozen "e2b>=..." fails (network hiccup, uv registry error, or the node -p subshell reading ../python-sdk/package.json failing). The first command already wrote the new version into pyproject.toml on disk. On the next run, [ "$(uv version --short)" = "$v" ] now evaluates true, so the || branch that calls uv add --frozen never runs again, and the script exits 0 (success) without ever correcting the e2b floor. On the base branch (unconditional postVersion), every run re-executed both commands, so a retry would always re-attempt and eventually fix the floor — that self-healing property is lost by this diff's guard. Same pattern at packages/code-interpreter-python/package.json:7.
Verification: nit. Real but low-likelihood regression introduced by the new guard. At packages/desktop-python/package.json:7 (identical at packages/code-interpreter-python/package.json:7): the guard keys solely on the package's own version, which is exactly what uv version --frozen "$v" persists to disk; uv add --frozen "e2b>=..." does not affect that key.
## Summary The last Release run committed the version bumps in 2438c92 (`e2b`/`@e2b/python-sdk` 2.53.0, `@e2b/code-interpreter` 2.8.1, `@e2b/code-interpreter-python` 2.10.2), but the publish step then failed on the `e2b-desktop` PyPI hash mismatch that #1951 fixed. Nothing was published to npm or PyPI, and no tags were created. The commit consumed the changesets, so `is_release.sh` now finds none and a Release rerun would skip publishing. This PR adds a single patch changeset for the four packages, so the next Release run publishes those changes (#1949, #1927, and the code-interpreter Unicode fix). Their CHANGELOG entries are already under the 2.53.0 / 2.8.1 / 2.10.2 headings. `pnpm changeset status`: ``` e2b 2.53.1 @e2b/python-sdk 2.53.1 @e2b/code-interpreter 2.8.2 @e2b/code-interpreter-python 2.10.3 ``` `e2b-desktop` is excluded. Its floor stays at `e2b>=2.44.0`, so its rebuild matches the 2.6.1 already on PyPI. Link to Devin session: https://app.devin.ai/sessions/328bb32ba7344529858415273d98c0ec Open in Devin Desktop: https://app.devin.ai/desktop/session/328bb32ba7344529858415273d98c0ec?variant=devin <!-- devin-review-badge-begin --> --- <a href="https://app.devin.ai/review/e2b-dev/e2b/pull/1953" target="_blank"><picture><source media="(prefers-color-scheme: dark)" srcset="https://static.devin.ai/assets/gh-devin-review-dark.svg?v=4"><img src="https://static.devin.ai/assets/gh-devin-review-light.svg?v=4" alt="Devin Review"></picture></a> <!-- devin-review-badge-end --> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Summary
Fixes the failed release run Publish / Build and test SDK on
main(1de92fc). Reverts #1926.Root cause: #1926 made
postVersionrewritee2b>=<sdk version>inpyproject.tomlon every release, even when the package itself is not released. This release only bumped python-sdk, so Desktop's floor went frome2b>=2.44.0toe2b>=2.53.0while its version stayed at2.6.1.pnpm run -r postPublishrebuilds every Python package, anduv publish --check-urlonly skips files that are byte-identical to what's already on PyPI. The rebuilte2b_desktop-2.6.1had different METADATA, so uv rejected it, and the whole publish aborted. Nothing was uploaded: PyPI still hase2b2.52.1 ande2b-code-interpreter2.10.1, andchangeset publish(npm) never ran.Changes:
postVersionincode-interpreter-python/desktop-pythongoes back touv version --frozen <own version>(a revert of chore: sync the e2b floor of the Python Code Interpreter and Desktop SDKs on version #1926).e2b>=2.44.0,<3.0.0inpackages/desktop-python/pyproject.toml. The release commit 2438c92 had writtene2b>=2.53.0there, and 2.6.1 on PyPI declares>=2.44.0. Without this, the next release would fail the same way.code-interpreter-pythonkeeps thee2b>=2.53.0that 2438c92 wrote. It came with that package's own version bump (2.10.2, not yet published), so there's no mismatch.Verification
uv build(uv 0.10.0, the CI version) ofdesktop-pythonwith the restored floor gives the same sha256 as both files on PyPI (wheelcf1cfd6d…, sdistdc715a77…). So--check-urlwill skip them again.Follow-up
mainbut were never published to npm or PyPI. The next release with a changeset bumps the versions past them (the workflow keeps failed versions on purpose).e2bfloor has to be bumped by hand again.Link to Devin session: https://app.devin.ai/sessions/328bb32ba7344529858415273d98c0ec
Open in Devin Desktop: https://app.devin.ai/desktop/session/328bb32ba7344529858415273d98c0ec?variant=devin