# Task 01: authoritative wheel metadata

## Problem

The current builder synthesizes `METADATA` from recipe fields. That duplicates
the package's dependency declarations and can create a wheel that installs but
resolves the wrong environment.

## Deliverable

Generate distribution metadata using the package's build metadata path under
the controlled build environment. Preserve upstream `Name`, `Version`,
`Requires-Dist`, extras, Python requirements, entry points, licenses, and other
install-relevant files. SandboxedJS should add only its wheel tag, generator,
and `Build-ABI` assertion.

Recipe constraints may explicitly override a target-inapplicable dependency,
but every override must be visible, justified, and tested.

## Required tests

- A fixture declares a conditional and an extra dependency upstream; neither
  is copied into the recipe.
- The resulting wheel and generated `index.json` contain the authoritative
  requirements.
- The resolver respects at least one marker/extras case.
- A disagreement between recipe identity and upstream identity fails loudly.
- Existing extension runtime tests remain green.

## Exit gate

No generic setuptools fixture needs handwritten `requires` metadata, and the
index is provably derived from the wheel produced from upstream metadata.

