Entry points are distribution metadata naming importable objects under a declared group and name.
Python entry points: inspect a trusted distribution before loading its plugin
Operation contract
The fixture creates an owned temporary module and matching dist-info metadata. importlib.metadata discovers a receipt-validator entry point from that directory, then loads the callable and validates one owned identifier. The group name narrows selection. The example prints the selected name and result, not a machine-specific path.
Failure and ownership boundary
Loading an entry point imports and executes code. Metadata is a discovery mechanism, not a signature or sandbox. In a service, allowlist a trusted installed distribution and verify release provenance before invoking its plugin; failure and plugin lifetime need separate rules. Python plugin project: load owned code and publish only an accepted interface, Python packaging: inspect an imported module origin before using it and Python artifact hashes: verify owned bytes against a separately trusted expectation distinguish discovery from trust.
Working program
import importlib.metadata
import sys
import tempfile
from pathlib import Path
with tempfile.TemporaryDirectory() as directory:
root = Path(directory)
(root / "aitrove_receipt_check.py").write_text(
"def accepted(identifier):\n return identifier == 'R41'\n", encoding="utf-8")
metadata = root / "aitrove_receipt_check-1.0.dist-info"
metadata.mkdir()
(metadata / "METADATA").write_text(
"Metadata-Version: 2.1\nName: aitrove-receipt-check\nVersion: 1.0\n", encoding="utf-8")
(metadata / "entry_points.txt").write_text(
"[aitrove.receipts]\nvalidator = aitrove_receipt_check:accepted\n", encoding="utf-8")
sys.path.insert(0, directory)
try:
distribution = next(importlib.metadata.distributions(path=[directory]))
selected = [point for point in distribution.entry_points if point.group == "aitrove.receipts"]
print("entry point:", selected[0].name)
print("accepted:", selected[0].load()("R41"))
finally:
sys.path.remove(directory)
sys.modules.pop("aitrove_receipt_check", None)Output
entry point: validator
accepted: TrueCosts and limits
Metadata discovery scans distribution records on the selected path; loading also imports arbitrary module code. This tiny owned directory has fixed size. The example does not resolve dependencies, authenticate a publisher or isolate a malicious plugin.
Common Mistakes
- Do not treat an entry-point name as code authenticity.
- Loading the selected entry point executes its module.
Connected lessons
Python plugin project: load owned code and publish only an accepted interface, Python packaging: inspect an imported module origin before using it, Python artifact hashes: verify owned bytes against a separately trusted expectation.
