Yeah, cost is relative to who is paying it. The lack of a good API here is going to be outsourced to all pip users.
For comparison, I would hazard a guess that if a new version of rust came out, and it cost 1ms on every single install command for uv, they would simply not upgrade and would compile only against older versions of rust until it was fixed, pip does not have such a luxury.
I’d also like to add the timeline from my perspective:
- I first had to argue why this was a security issue: PEP 810: Explicit lazy imports - #41 by notatallshaw
- It was then agreed and clarified that setting
sys.set_lazy_importstononewas the correct approach: PEP 810: Clarify security implications by notatallshaw · Pull Request #4660 · python/peps · GitHub - I was then informed that would not work but pip could reify all lazy imports upfront and block future imports by iterating
sys.lazy_modules: Concerns about `-X lazy_imports=none` - #10 by ZeroIntensity - And now
sys.lazy_modulesis apparently being removed, long after feature freeze, and even after the beta period, with the suggestion being pip walk the entire Python object tree (and I guess hope nothing has been injected into the Python environment that has nasty side effects when it is touched)
Personally, but driven by my obligations as a pip maintainer and PSRT member, I would prefer to see lazy modules delayed to Python 3.16 than providing no clean way for pip to secure itself. But I’m very aware that’s unrealistic.