Repository navigation
Tracking: repository modernization #277
Description
Activity
Seven pull requests are open for review. None is merged. No issue is closed by
hand. Each pull request body holds aCloses #NNNline, which closes the issue
on merge.The pull requests
Pull request Base branch Closes Gate result #278 — set the Python 3.10 floor and remove the Python 2 support layer main#265, #266, #267 261 passed,flake80 errors#279 — migrate packaging to PEP 621 and replace flake8 with ruff #278 #268, #269, #270 261 passed,ruff checkclean,ruff format --checkclean#280 — modernize the tests-and-lint workflow and add Renovate #279 #271 261 passed,ruff checkclean,ruff format --checkclean#281 — gate publish.yml on tags and move PyPI to Trusted Publishing main#272 261 passed,flake80 errors#282 — replace assert guards, add an exception message, stop a password leak main#273 268 passed,flake80 errors#285 — harden the conftest fixtures and close the IPv6 and SASL gaps main#274 271 passed,flake80 errors#286 — remove the per-call struct format strings from the response parse path #278 #276 261 passed,flake80 errorsThe baseline on
mainis261 passed. #282 adds 7 tests. #285 adds 10 tests.
No pull request removes a test.Every gate ran in the Nix dev shell:
nix develop --command bash -c 'pytest -q'Merge order
#281, #282, and #285 are independent. Merge them in any order.
#278 first, then #279, then #280. Each stacks on the one before, so a reader
sees the incremental diff only. #286 also stacks on #278 and can merge as soon
as #278 lands.Two pull requests need an action before merge
#281 has a release hazard. It removes the
PYPI_API_TOKENpassword input.
Register the trusted publisher on pypi.org and create thepypienvironment in
GitHub settings before you merge. A merge without those steps breaks the next
tag push. The exact steps are at the top of the pull request body. I did not
touch PyPI settings, GitHub environment settings, or thePYPI_API_TOKEN
secret.#280 needs the Renovate GitHub App.
renovate.jsonalone does nothing.
Install the app at https://github.com/apps/renovate and grant it access to this
repository. Two settings in that file need your preference:timezoneis
Europe/Berlin, andscheduleruns once per week.Deferred
#275 (
py.typedand annotations) is not implemented. It depends on #278,
#279, and #282, all of which are open. I left a comment on #275 that states
this and records two facts that changed under it: the two# type: ignore
comments it names are already gone, and the lone comment-style hint at
bmemcached/client/mixin.py:153now reads# type: (str, int) -> bool.Nothing was blocked
Every issue in scope for this run is fully implemented. Two items came close.
The SASL integration test in #285 needed a memcached built with SASL, which
nixpkgs does not provide by default. #285 adds--enable-saslto the
flake.nixmemcached override, in the same way the flake already adds
--enable-tls, and addscyrus_sasl.binforsaslpasswd2. The test runs and
passes in the dev shell. It skips in CI, because.ci-before-script.sh
installs neithersasl2-binnor a SASL-enabled memcached. Adding those belongs
to #271, not to #274, so I did not fold it in.The
bytes()copy in_read_socket, the second item in #276, stays. #286
holds the measurement and the reason: removing it changes public return types,
because a bytearray slice is a bytearray. The acceptance criteria allow the
copy to stay with a stated reason.Two new issues
Both came out of #274 and are linked from #285. Neither is folded into a pull
request.- Map memcached SASL status 0x20 to InvalidCredentials #283 — memcached answers a failed SASL auth with status
0x20. The
client maps only0x08toInvalidCredentials, so a wrong password raises
the baseMemcachedException. The mocked test intest/test_auth.pyhid
this, because it feeds0x08by hand. The new SASL integration test asserts
the real behavior and names this issue in its docstring. - Replace the deprecated pytest.yield_fixture in test/test_tls.py #284 —
test/test_tls.py:16still uses the deprecated
pytest.yield_fixture. It is outside the file list of Harden test/conftest.py and close the IPv6 and SASL test gaps #274.
Notes on three decisions
flake.nixwas updated in the same pull request that removed each dependency,
so no later gate runs against a stale dev shell. #278 dropssixandmock.
#279 dropsflake8and addspkgs.ruff, plustwineso the packaging gate
runs there. #285 adds SASL to the memcached build.Three pin versions differ from the issue text, because the issue text is now
out of date..pre-commit-config.yamlin #279 usescommitizenv4.18.0and
pre-commit-hooksv6.0.0in place of the proposedv3.29.1andv4.6.0.
Theruffhook rev isv0.16.5, which matches the ruff version in the dev
shell, so local runs and hook runs agree.actions/upload-artifactin #280 stays atv4, as the issue text specifies.
The current release isv7.0.1. Renovate will propose the major bump once it
runs.Three findings in the "Out of scope" section of this issue are untouched, as
intended: the missing GitHub releases forv0.31.3,v0.31.4, andv0.32.0;
theunittest.TestCasestyle across eight test files; and the stale
intersphinx_mappingindocs/conf.py. The manual version copy at
flake.nix:68is also untouched, and #279 states this in its body.On the related report #250, which #274 asked me to check: #285 turns the most
likely cause, a missing or slowmemcached, into one clear skip message
instead of a wall ofConnectionRefusedError. It does not confirm the original
diagnosis, so I did not close that issue.- Map memcached SASL status 0x20 to InvalidCredentials #283 — memcached answers a failed SASL auth with status
This issue tracks the modernization of this repository. It links twelve work issues in four streams.
Four audits produced the work items. Each linked issue holds the evidence, the exact file and line references, and the acceptance criteria. Another contributor can pick up any issue without more context.
Decisions made up front
Two audits disagreed. These are the resolutions.
Minimum Python version: 3.10. Python 3.8 ended support in October 2024. Python 3.9 ended support in October 2025.
uhashring2.5, released 2026-08-03, declaresRequires-Python: >=3.10. A lower floor forces a permanentuhashring<2.5pin.Use Renovate, not Dependabot. Renovate groups patch and minor updates into one pull request. Dependabot cannot group by update type. See #271.
Keep
README.rst. Do not convert it to Markdown.README.rstis a symlink todocs/intro.rst. That file is a Sphinx source in reStructuredText. A conversion breaks the documentation build. The pandoc step in.github/workflows/publish.ymlstays.Streams
Stream 1: Python version and legacy code
sixdependency and deletebmemcached/compat.pyStream 2: Packaging and tooling
setup.pyto a PEP 621pyproject.tomlflake8withruffand modernize pre-commitrequirements_test.txtwith a PEP 735 dependency groupStream 3: CI and release
publish.ymlon tags and move PyPI to Trusted PublishingStream 4: Code quality
test/conftest.pyand close the IPv6 and SASL test gapspy.typedand annotate the leaf modulesOrder
Read this as follows.
bmemcached/protocol.py.pyproject.toml.tox.ini. Merge them in sequence.Work that runs in parallel now
Three issues need no predecessor: #271, #273, and #274.
Verified facts
These claims come from direct checks, not from reading alone.
str(MemcachedException('boom', 1))returns"('boom', 1)". The exception has no usable message. See Fix five defects: assert guards, exception message, password leak, circular import #273.uvx ruff@0.16.4 check --select E,F,W,I,UP,B,C4,SIM,PIE,RUF --line-length 120 --target-version py310reports 180 errors. 64 are auto-fixable.ruff format --checkreports 20 files to reformat out of 25. See Replace flake8 with ruff and modernize pre-commit #269.uhashring2.5 declaresRequires-Python: >=3.10. See Set the minimum supported Python version to 3.10 #265.memcached. Run34284112624usedmemcached 1.6.24-1ubuntu0.2on Ubuntu 24.04.test/test_tls.pyran 48 of 48 tests with 0 skips. TLS tests do not silently skip. See Modernize the tests-and-lint workflow and add Renovate #271.python -m compileall -q bmemcached testpasses. No syntax error exists in the repository.Out of scope
These items came up during the audits. Each one needs its own issue.
v0.31.3,v0.31.4, andv0.32.0have no GitHub release. The newest release isv0.31.2.flake.nix:68holds a manual copy of the version string. No automatic sync exists.unittest.TestCasein eight files. A conversion to pytest style is a large, separate change.docs/conf.pyholds a staleintersphinx_mappingin the pre-Sphinx-1.3 format. It is a no-op on a modern Sphinx.