hundreds-carpet-28072
12/09/2025, 3:05 PM--isolated mode. Is there a way I can do this?curved-manchester-66006
12/09/2025, 4:15 PM--use-pip-confighundreds-carpet-28072
12/09/2025, 4:19 PMPIP_USER_CONF file may contain invalid config, which can cause this bootstrap of environments to fail, even though Pants itself won’t be using this Pip config.curved-manchester-66006
12/09/2025, 4:48 PMexample-python something like?:
$ tail -2 ~/.config/pip/pip.conf
invalid-junk
$ pants --local-store-dir=$(mktemp -d) --named-caches-dir=$(mktemp -d) --no-pantsd package ::
11:45:27.07 [INFO] Completed: Scheduling: Test binary /bin/bash.
11:45:27.07 [INFO] Completed: Scheduling: Test binary /usr/bin/bash.
11:45:31.22 [INFO] Completed: Scheduling: Find interpreter for constraints: CPython==3.12.*
11:45:31.30 [INFO] Canceled: Building build_backend.pex from <resource://pants.backend.python.subsystems/setuptools.lock>
11:45:33.24 [INFO] Completed: Building local_dists.pex
11:45:33.24 [INFO] Completed: Scheduling: Building local_dists.pex
11:45:36.48 [INFO] Completed: Building build_backend.pex from <resource://pants.backend.python.subsystems/setuptools.lock>
11:45:36.48 [INFO] Completed: Scheduling: Building build_backend.pex from <resource://pants.backend.python.subsystems/setuptools.lock>
11:45:36.49 [ERROR] 1 Exception encountered:
Engine traceback:
in `package` goal
ProcessExecutionFailure: Process 'Building build_backend.pex from <resource://pants.backend.python.subsystems/setuptools.lock>' failed with exit code 1.
stdout:
stderr:
received exit code 2 during execution of `['/tmp/pants-sandbox-mVrOCa/.tmp/tmp8qur1nbv/pip/bin/python3.12', '-s', '-E', '-m', 'pip', 'install', '-U', 'pip']` while trying to execute `['/tmp/pants-sandbox-mVrOCa/.tmp/tmp8qur1nbv/pip/bin/python3.12', '-s', '-E', '-m', 'pip', 'install', '-U', 'pip']`hundreds-carpet-28072
12/09/2025, 5:32 PMindex-url=<private-repo> entry for which pip would receive a 401 for (non-existent link) when querying for these internal dependencies such as pex.curved-manchester-66006
12/09/2025, 5:48 PMpip.conf file present" or "have the pip.conf file and auth present" are harder then they sound?
The specific issue -- at least in my repo -- is the get-the-right-pip bootstrapping process.
There is somewhat related discussion about this problem in the keyring provider case at https://github.com/pex-tool/pex/pull/2592 I was looking at the keyring path for use with an registry that only uses short lived tokens, but ended up going in a different direction.brief-scientist-13682
12/10/2025, 4:16 AMbrief-scientist-13682
12/10/2025, 5:25 AMpip_version and failing to apply all the standard options Pex uses for performing pip download (like --isolated). If you don't mind filing an issue, I'm AFK and won't be able to get to a fix for the next several days; possibly not until ~17th December.hundreds-carpet-28072
12/10/2025, 8:46 AMI take it, “don’t have thisNot necessarily harder, but it’s very useful to rely on the bootstrap process being as hermetic as Pants’ spun-up environments are, so that we can serve all users with less requirements on pre-bootstrap stuff.file present” or “have thepip.conffile and auth present” are harder then they sound?pip.conf
There is somewhat related discussion about this problem in the keyring provider case at https://github.com/pex-tool/pex/pull/2592 I was looking at the keyring path for use with an registry that only uses short lived tokens, but ended up going in a different direction.Having this exposed in Pants would be great. IMO keyring and keyring-provider logic within Pip could be improved quite a lot, we’ve found it to be quite frustrating to discover and validate all potential problem cases in our scenario which requires keyring, the gauth keyring backend and using it in solely subprocess mode.
this looks like a bug here: https://github.com/pex-tool/pex/blob/b42697bac49c8527523c29924dd65b6ca19c0273/pex/pip/installation.py#L258
Pex is bootstrapping the Pip forHappy to have assisted in uncovering a bug. I’ll take a look and understand the issue fully and write a ticket for you. No pressure on a fix, as we know what the problem is - but of course would be very useful to have in a release at some point.and failing to apply all the standard options Pex uses for performingpip_version(likepip download). If you don’t mind filing an issue, I’m AFK and won’t be able to get to a fix for the next several days; possibly not until ~17th December.--isolated
hundreds-carpet-28072
12/10/2025, 10:24 AM