Skip to main content

PF — Package Floor

English | 简体中文

Find verified lower bounds for a Python package's direct dependencies.

What it does

PF discovers candidate versions in isolated environments. search optionally captures a ty static baseline from the highest versions your declarations allow, then runs the project's full test command. Compatibility conclusions come only from that dynamic evidence; ty may choose a later probe but cannot reject a candidate. It records an explainable, verified exact dependency vector. smoke and check run the same verifier without ty.

The search unit is one installable package and one compatibility cell: exact uv target triple, CPython minor, and extra surface. On a frozen candidate snapshot, PF returns a coordinate-minimal vector that passed full tests. It does not claim a global minimum over the Cartesian product of dependencies, and it does not prove that unprobed versions or other combinations work. The product contract is D001.

For admitted resolution and installation requests, an unattributed normal nonzero exit rejects that attempt, including failures inside a build backend. It does not prove a dependency conflict or a repeatable failure. A backend can report network or permission problems this way, so false rejections may raise the reported floor, miss feasible vectors, or leave no result. Timeouts, abnormal terminals and directly observed external or consistency failures remain indeterminate. Final results still require actual resolution, installation, graph checks and a full verifier PASS; PF does not add retries or promise reproducibility from one observation.

Installation

uv tool install package-floor

pip install package-floor also works. The CLI name is pf. From a clone, uv run pf uses the local tree.

Quick Start

The target project needs static project.dependencies (and optional-dependencies, if used). Test dependency groups are optional: omitting test-group selects dev, then test, from the workspace root or selected member. If neither exists, the group is empty. An explicit name selects only that group; a missing name also means an empty group. The default test command is pytest; PF does not install it automatically. For example, provide the test tools with:

[dependency-groups]
test = ["pytest"]

Then:

pf smoke
pf search
pf apply

smoke checks a fresh install at the newest allowed versions. search writes package-floor.json. apply updates the project's requirement floors from that report when authorization succeeds. After apply, check is the everyday command: it verifies the current declarations and does not require a report or Git.

Commands

Command What it does
pf smoke Fresh-install at newest allowed versions and run the full tests. Does not run ty, search, or write a report.
pf check Verify the lower bounds the project already declares. Does not require a prior search or apply, a report, or Git. Does not run ty, search, or write a report.
pf search Find verified floors and write package-floor.json. Never edits project metadata.
pf explain Read the report and show floors, coverage, and apply blockers.
pf apply Edit project metadata from an authorized report. --force only waives source-layer drift.
pf minimize Run search, then the default apply.
pf diagnose FAILURE_ID Explain one recorded rejection or indeterminate result. Offline; does not replay.
pf merge REPORT ... --output PATH Combine compatible reports produced on different hosts.

Onboarding: pf smokepf searchpf explainpf apply. Steady state: pf check. Use pf minimize to search and apply in one step. After a failed check, or when you want new floors, run pf searchpf apply again.

Requirements

  • Omit --package to select the installable workspace root. An explicit value is a canonical distribution name of one workspace member, not a path.
  • Each process only runs the target that matches the current host. Merge other hosts with pf merge. When this host succeeds and the only gaps are other hosts, pf search exits 0 with an incomplete report so CI can collect artifacts.
  • search writes package-floor.json. apply does not re-resolve dependencies or rerun ty or tests.

Configuration

Settings merge from the workspace root's [tool.pf] into the selected member's own [tool.pf]; explicit CLI flags override that run. For example:

[tool.pf]
test-command = ["pytest"]
search-resolution = "patch"
max-cells = 4

[tool.pf.search-space-defaults]
with-lower-bound = "majors[declaration-1:]"
without-lower-bound = "majors[baseline-2:]"

This is a configuration example, not a complete defaults table. See D001 configuration for groups, Cells, concurrency, timeouts and layer merging; see D037 candidate and search policy for spaces, conditional defaults, per-dependency overrides and exact baseline artifacts. search-resolution controls sampling within the chosen space; a verified floor remains an exact version.

A self-reference such as requests[socks] in the test group makes socks required in every Cell. Extra exploration is added to that required surface. A Cell without active external test dependencies installs the project plan directly and still runs the configured verifier. Changing the test command or harness changes the validation contract and can change the resulting floor; see D001 validation.

Pinned tools

Released PF pins uv 0.12.5 and ty 0.0.74. The resolver protocol accepts only that uv version; other versions fail closed. Upgrading either tool requires re-qualification before the pin changes.

Documentation

  • D001 — product and command contract: floors, commands, configuration, reports, and exit codes
  • Engineering docs index: contract ownership and layout
  • This repository's own [tool.pf] test-command is a targeted-runtime contract: in-process public interfaces only. Real uv/ty/CLI and qualification runs live in CI test lanes. An existing package-floor.json produced under a wider historical C is not a floor relative to the current command; see tests/README.md.

License

Apache License 2.0. See LICENSE.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

package_floor-0.4.0.tar.gz (251.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

package_floor-0.4.0-py3-none-any.whl (293.4 kB view details)

Uploaded Python 3

File details

Details for the file package_floor-0.4.0.tar.gz.

File metadata

  • Download URL: package_floor-0.4.0.tar.gz
  • Upload date:
  • Size: 251.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for package_floor-0.4.0.tar.gz
Algorithm Hash digest
SHA256 68d21e0e512f80df9eaf9787cbf0eb05bc1bbce79e31870ac4ca723f8f4ba392
MD5 5c686c82de0c2d70fad7b124c5fcea8c
BLAKE2b-256 bb57788d8b12173693102230c61d3947c868a57dc23f946e8bf61833994db425

See more details on using hashes here.

Provenance

The following attestation bundles were made for package_floor-0.4.0.tar.gz:

Publisher: publish.yml on BigTailFox/pf

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file package_floor-0.4.0-py3-none-any.whl.

File metadata

  • Download URL: package_floor-0.4.0-py3-none-any.whl
  • Upload date:
  • Size: 293.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for package_floor-0.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 149eed504166fa7f11a464c6d7ba9e3f21aada2181d912a611e32405f39a08fc
MD5 96b2140280f8c356c1c11f9c8ab13e8a
BLAKE2b-256 77e78dd39633fb706817174d2cc25dad600031396c9cd9e373198dfe8d40a1b9

See more details on using hashes here.

Provenance

The following attestation bundles were made for package_floor-0.4.0-py3-none-any.whl:

Publisher: publish.yml on BigTailFox/pf

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.4.0 This release

2 files

0.3.0

2 files

0.2.0

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page