A wheel installation copies a built distribution into an import environment, which can expose packaging omissions hidden by imports from a source checkout.
Python wheel installation: test the built artifact outside its source directory
Operation contract
The fixture builds an owned src-layout package offline, installs its wheel without dependencies into a fresh temporary target, and imports only from that target in an isolated child process. It checks the returned value and verifies that the imported file resides under the installation target. The source directory is not added to the child’s import path.
Failure and ownership boundary
No package index is contacted and no system site-packages directory is changed. Build tools execute the selected backend, so build inputs must be trusted. This test covers one pure-Python package and interpreter, not binary wheel compatibility, dependency resolution or a signed release pipeline. Python pyproject.toml: build a wheel and inspect its metadata, Python package resources: read data from a ZIP-backed package and Python compatibility checks: parse syntax and execute contracts as separate evidence identify separate release requirements.
Tested environment
Dependency check: this program was executed on CPython 3.14.6 with build==1.6.1, setuptools==84.0.0, pip==26.1.2. Install these versions in a separate virtual environment. The download includes the recorded environment snapshot; no third-party package is part of the website runtime.
Working program
from pathlib import Path
import subprocess
import sys
import tempfile
with tempfile.TemporaryDirectory() as directory:
owned = Path(directory); project = owned / "project"; target = owned / "installed"
package = project / "src" / "aitrove_installed_receipt"; package.mkdir(parents=True)
(package / "__init__.py").write_text('def surcharge():\n return 25\n', encoding="utf-8")
(project / "pyproject.toml").write_text('[build-system]\nrequires = ["setuptools==84.0.0"]\nbuild-backend = "setuptools.build_meta"\n[project]\nname = "aitrove-installed-receipt"\nversion = "0.1.0"\n[tool.setuptools.packages.find]\nwhere = ["src"]\n', encoding="utf-8")
subprocess.run([sys.executable, "-I", "-m", "build", "--wheel", "--no-isolation", str(project)], check=True, capture_output=True, text=True, timeout=15)
wheel = next((project / "dist").glob("*.whl"))
subprocess.run([sys.executable, "-I", "-m", "pip", "install", "--no-index", "--no-deps", "--no-cache-dir", "--disable-pip-version-check", "--target", str(target), str(wheel)], check=True, capture_output=True, text=True, timeout=15)
source = 'import sys\nfrom pathlib import Path\nsys.path.insert(0,sys.argv[1])\nimport aitrove_installed_receipt as receipt\nprint("installed amount:",receipt.surcharge())\nprint("installed origin:",Path(receipt.__file__).is_relative_to(Path(sys.argv[1])))\n'
result = subprocess.run([sys.executable, "-I", "-c", source, str(target)], cwd=owned, check=True, capture_output=True, text=True, timeout=5)
print(result.stdout.strip())Output
installed amount: 25
installed origin: TrueCosts and limits
Build and installation work depends on source size, backend behavior and the wheel. This tiny package is tested under explicit subprocess timeouts and owned temporary paths. No cross-platform wheel lock or supply-chain assurance is inferred from successful installation.
Common Mistakes
- Import the installed artifact outside the checkout when checking packaged contents.
- A successful local install does not verify every dependency or target platform.
Connected lessons
Python pyproject.toml: build a wheel and inspect its metadata, Python package resources: read data from a ZIP-backed package, Python compatibility checks: parse syntax and execute contracts as separate evidence.
Follow the service contract
Python wheel metadata: inspect an owned built artifact before installation.
