Skip to content

Commit ad26c35

Browse files
committed
Add docs for package substitution
Assisted By: Claude Opus 4.6
1 parent b790792 commit ad26c35

2 files changed

Lines changed: 44 additions & 0 deletions

File tree

‎docs/user/guides/_SUMMARY.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,3 +5,4 @@
55
* [Vulnerability Report](vulnerability_report.md)
66
* [Attestation Hosting](attestation.md)
77
* [Package Blocklist](blocklist.md)
8+
* [Package Substitution](package_substitution.md)
Lines changed: 43 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
1+
# Package Substitution
2+
3+
By default, Python repositories allow package substitution: uploading, syncing, or adding a package
4+
with the same filename as an existing package but a different checksum will silently replace it.
5+
6+
This behavior is controlled by the `allow_package_substitution` field on a Python repository.
7+
When set to `False`, any operation (upload, sync, or modify) that would replace an existing package with a different checksum is rejected.
8+
Re-adding a package with the same filename *and* the same checksum is always accepted (idempotent).
9+
10+
## Setup
11+
12+
If you do not already have a repository, create one:
13+
14+
```bash
15+
pulp python repository create --name foo
16+
```
17+
18+
Set the API base URL and repository HREF for use in the subsequent commands:
19+
20+
```bash
21+
PULP_API="http://localhost:5001"
22+
REPO_HREF=$(pulp python repository show --name foo | jq -r ".pulp_href")
23+
```
24+
25+
## Disable package substitution
26+
27+
```bash
28+
http PATCH "${PULP_API}${REPO_HREF}" allow_package_substitution=false
29+
```
30+
31+
You can also set this when creating a repository:
32+
33+
```bash
34+
http POST "${PULP_API}/pulp/api/v3/repositories/python/python/" name="bar" allow_package_substitution=false
35+
```
36+
37+
## Re-enable package substitution
38+
39+
```bash
40+
http PATCH "${PULP_API}${REPO_HREF}" allow_package_substitution=true
41+
```
42+
43+
Once re-enabled, packages with duplicate filenames can replace existing content again.

0 commit comments

Comments
 (0)