Repository navigation
Conversation
PolicyBench is not on PyPI (pypi.org/simple/policybench/ and the JSON API returned 404 on 2026-10-06), so `pip install policybench` failed and would install a squatter's package if the name were ever registered. The quick start now installs from git+https://github.com/PolicyEngine/policybench with uv (pinned to Python 3.12) or pip, and the development path clones the repo and syncs the locked environment as CI does. tests/test_install_docs.py fails if any reader-facing doc installs the policybench distribution from a package index by name. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
An adversarial pass on #199 found the detector missed commands wrapped across lines, JSON-escaped note text and `uvx --with X policybench`, and failed prose such as "uv tool install puts policybench on your PATH" and trailing `# ... policybench` comments. It now decodes each surface first (JSON strings, HTML/TSX tags), reads code (fences, <pre>, inline spans and <code> joined across soft wraps) as full commands and prose only as an installer followed by the name, and tokenizes with shlex comments and operators. The README check reuses the tokenizer. README: the dashboard block runs `bun install --frozen-lockfile` first, as CI and the runbook do, and the benchmark run section says its commands are for a clone and need `uv run` there. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The README's quick start told readers to run
pip install policybench. PolicyBench is not on PyPI: on 2026-10-06 at 10:45 UTC, both https://pypi.org/pypi/policybench/json and https://pypi.org/simple/policybench/ returned HTTP 404. So the documented install fails today, and if anyone ever registers the name, it would install their package instead.This PR changes the quick start to install from GitHub, and adds a test that fails if any reader-facing doc installs
policybenchfrom a package index by name.Changes
uv tool install --python 3.12 git+https://github.com/PolicyEngine/policybench.pip install git+https://github.com/PolicyEngine/policybench, in a standard (not free-threaded) Python 3.11 to 3.14 virtual environment.git clone,cd) and installs the locked environment the way CI does (uv sync --locked --extra dev --python 3.12, thenuv run pytest). Before, it said "clone the full Git repository" without a clone command.bun install --frozen-lockfilebeforebun run lint, as CI anddocs/runbook.mddo. A fresh clone has noapp/node_modules, sobun run lintfailed there.results/local/, andanalyzealso writes the dashboard payload toapp/src/data.jsonby default (--app-data-outputinpolicybench/cli.py). They callpolicybenchasuv tool installputs it onPATH; a clone set up withuv syncneedsuv runin front, as the runbook does.name @ urlreferences don't count, and neither do--no-index/--offlineinstalls.pip/pip3/python -m pip/py -m pip/uv pipinstall,uv add,uv tool install,pipx install,conda/mambainstall,poetry/pdm add,uvx,uv tool run,pipx run,uv run --with, and requirements files.<pre>, one command per line, plus inline spans and<code>, joined across soft wraps. Code is read as a full command. Prose is read only as an installer followed by the name, so "uv tool install puts policybench on your PATH" passes.#comments, so quoted version specifiers, trailing comments and&&chains read correctly.pip install policybencheven as a warning fails, because readers copy commands.*.md(README, CLAUDE.md, RESULTS.md),docs/*.md,docs/requirements.txt, the paper source and its rendered HTML,sensitivity/*.md, app source and note copy, and the CI workflows. Each glob must match at least one file, so a moved file can't silently drop out of coverage.git+https://github.com/PolicyEngine/policybench, read with the same tokenizer, and showspolicybench --help.Why
uv tool installpins--python 3.12Without a pin, uv uses the interpreter it finds. On the verification machine that was the free-threaded CPython 3.14t.
tokenizers(pulled in by litellm) has no free-threaded wheel, so uv builds it from source, and the build fails at the link step.uv tool install git+https://github.com/PolicyEngine/policybenchwith no--pythonfailed exactly this way. CI tests 3.12.Verification (macOS arm64, 2026-10-06)
pip install git+https://github.com/PolicyEngine/policybench(stdlib venv, pip 26.2.1, no pip cache)policybench==2.0.0from commit2d399987;policybench --helpexit 0uv tool install --python 3.12 git+…(uv 0.11.7, fresh cache, isolated tool dir)policybench --helpexit 0uvx --python 3.12 --from git+… policybench --helpuv pip install git+…into a clean venvpolicybench --helpexit 0uv pip install git+…into clean standard venvspolicybench --help,policybench reference-outputs --help, andimport policybench.eval_no_tools, policybench.ground_truth, policybench.scenarios, policyengine_usall exit 0uv pip install git+…tokenizers0.23.2 (hence "not free-threaded" in the README)uv tool install git+…(no--python)origin/main's README, the detector flagspolicybench; against this branch's README, nothing.pip install uvin CI,jupyter-bookindocs/requirements.txt), so it is parsing the real files.ruff check .andruff format --check .are clean.testjob (uv run pytest -m "not slow"on a clean Ubuntu runner, Python 3.12) passed on the first head, as didlint,appand Vercel. Locally, 81 tests failed. The ones I inspected, intests/test_run_audit_claude.py, fail because the audit script runsclaude auth statusand refuses to start inside a Claude desktop session without a lane login. This PR doesn't touch that code.Adversarial pass
Before review, 24 in-session agents attacked the first head (8088fb8) along three lenses: breaking the detector, auditing every claim, and completeness. Each finding was then checked by an agent that tried to refute it.
Fixed in 91f37b7, confirmed findings:
uvx --with X policybench.--no-binary :all:and installs placed after a quoted specifier.# … policybenchcomments and prose that mentions an installer before the name.bun install.uv runthere).Rejected on verification:
app/public/metric-options.html, which has no install text.pip install -e ".[dev]", which installs from a clone.Accepted gaps:
Other docs checked
No other surface claims a PyPI install:
docs/runbook.mdanddocs/audit.mdrunuv run …from a clone.paper/README.mdusesuv sync --extra docs.CLAUDE.mdusespip install -e ".[dev]", an editable install from a clone.There is also no sign that a PyPI release was intended:
ci.ymlandpaper.yml);dashboard-data-*snapshots.So nothing here publishes. Whether to publish to PyPI, which would also claim the name, is a separate call for Max, queued as d1006. This PR doesn't depend on it.
Invariants the test holds
policybenchdistribution from a package index by name.policybenchfrom this GitHub repository, and showspolicybench --help.axiom: n/a: docs-only install instructions, no policy change
🤖 Generated with Claude Code