{"record":{"id":"acff0d8a94c654cf","repo":"pypa/pip","slug":"requested-ireq-has-inconsistent-name-between-its","errorCode":null,"errorMessage":"Requested {ireq} has inconsistent Name between its PEP 658 .metadata file and the wheel's METADATA: sidecar has {f_val!r}, wheel has {m_val!r}","messagePattern":"Requested (.+?) has inconsistent Name between its PEP 658 \\.metadata file and the wheel's METADATA: sidecar has (.+?), wheel has (.+?)","errorType":"exception","errorClass":"SidecarMetadataInconsistent","httpStatus":null,"severity":"error","filePath":"src/pip/_internal/operations/prepare.py","lineNumber":299,"sourceCode":") -> None:\n    \"\"\"Check that a .metadata-based distribution matches the wheel's METADATA.\n\n    Compare ``Name``, ``Version``, ``Requires-Dist``, ``Requires-Python``\n    and ``Provides-Extra`` between the two and abort the install on any\n    mismatch as PEP 658 requires the metadata files \"MUST be identical\".\n\n    While the PEP doesn't mandate that consumers enforce the identical\n    requirement, it's good nonetheless to check to prevent confusing\n    behaviour when an index misbehaves.\n\n    Also note for name and version, pip usually rejects wheels if they're\n    inconsistent already. Checking them again here is purely defensive.\n    \"\"\"\n\n    sidecar_name = canonicalize_name(sidecar_dist.raw_name)\n    wheel_name = canonicalize_name(wheel_dist.raw_name)\n    if sidecar_name != wheel_name:\n        raise SidecarMetadataInconsistent(req, \"Name\", sidecar_name, wheel_name)\n\n    if sidecar_dist.version != wheel_dist.version:\n        raise SidecarMetadataInconsistent(\n            req,\n            \"Version\",\n            str(sidecar_dist.version),\n            str(wheel_dist.version),\n        )\n\n    # For multi-use fields, only report the symmetric difference to avoid\n    # unnecessarily flagging matching values.\n    sidecar_requires = _canonical_requires(\n        req, sidecar_dist, \"the PEP 658 .metadata file\"\n    )\n    wheel_requires = _canonical_requires(req, wheel_dist, \"the wheel's METADATA\")\n    if sidecar_requires != wheel_requires:\n        raise SidecarMetadataInconsistent(\n            req,","sourceCodeStart":281,"sourceCodeEnd":317,"githubUrl":"https://github.com/pypa/pip/blob/f399c3718970b1b0e2478dac5296eb62679a9b86/src/pip/_internal/operations/prepare.py#L281-L317","documentation":"Raised by _check_sidecar_matches_wheel (prepare.py:298) as SidecarMetadataInconsistent. PEP 658 lets an index publish a separate .metadata sidecar file so resolvers can read dependencies without downloading the wheel; that sidecar MUST be byte-identical to the wheel's METADATA for the Name field. pip enforces this and aborts on a Name mismatch to prevent the resolver from planning against different metadata than what actually installs.","triggerScenarios":"The index/mirror served a PEP 658 .metadata file whose Name: field canonicalizes differently from the Name in the downloaded wheel's METADATA. Occurs during _fetch_metadata_using_link_data_attr when the sidecar is downloaded and compared to the wheel.","commonSituations":"A misconfigured private index/mirror that caches stale sidecar metadata after a package was republished/re-signed; a CDN serving a mismatched .metadata; metadata regeneration bugs in the index software.","solutions":["Report the mismatch to the index/mirror operator — the sidecar and wheel are out of sync server-side.","Switch to a different index or PyPI directly to confirm the package is intact upstream.","Clear local caches (pip cache purge) and retry to rule out a locally cached bad sidecar.","If you publish the package, rebuild and re-upload the wheel so the .metadata sidecar is regenerated consistently."],"exampleFix":"# before\npip install --index-url https://broken-mirror/simple/ pkg\n# after: use canonical PyPI\npip install --index-url https://pypi.org/simple/ pkg","handlingStrategy":"validation","validationCode":"# Compare a downloaded PEP 658 .metadata sidecar Name against the wheel METADATA Name before installing.\nfrom email.parser import Parser\nimport zipfile, requests\n\ndef sidecar_name_matches(wheel_url: str, sidecar_url: str) -> bool:\n    wheel = requests.get(wheel_url).content\n    name_w = Parser().parsestr(\n        zipfile.ZipFile(__import__('io').BytesIO(wheel))\n        .read(next(n for n in zipfile.ZipFile(__import__('io').BytesIO(wheel)).namelist()\n                   if n.endswith('.dist-info/METADATA'))).decode()\n    )['Name']\n    name_s = Parser().parsestr(requests.get(sidecar_url).text)['Name']\n    return name_s == name_w","typeGuard":"from pip._vendor.packaging.utils import canonicalize_name\n\ndef names_match(sidecar_name: str, wheel_name: str) -> bool:\n    return canonicalize_name(sidecar_name) == canonicalize_name(wheel_name)","tryCatchPattern":"# Verify against an alternate index before trusting a mirror.\nfrom subprocess import run\nrun([\"pip\", \"install\", \"--no-cache-dir\", \"-i\", \"https://pypi.org/simple/\", pkg], check=True)","preventionTips":["Prefer the official PyPI for reproducibility; treat custom mirrors as untrusted for metadata.","Purge pip cache when seeing sidecar mismatches to rule out stale local copies.","If you operate an index, invalidate/regenerate PEP 658 sidecars on every re-upload."],"tags":["pep658","metadata","sidecar","name","index","pip"],"backgroundTag":null,"analyzedSha":"f399c3718970b1b0e2478dac5296eb62679a9b86","analyzedAt":"2026-08-08T23:01:42.227Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}