Skip to content

Fix uv pylock rollback shape (#407, #408) - #512

Merged
Mikola Lysenko (mikolalysenko) merged 3 commits into
mainfrom
agent/fix-uv-pylock-restore-shape
Oct 2, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 3 commits into
mainfrom
agent/fix-uv-pylock-restore-shape

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

Fixes #407
Fixes #408

Summary

Hosted rollback, remove and the hosted → vendored takeover now restore a pylock.toml written by uv pip compile. Before, they refused every such lock. A restored pylock entry also now comes back with the bytes uv writes.

Root cause

The PEP 751 branch of the upstream restore (crates/socket-patch-core/src/patch/redirect/upstream/uv.rs, lock_shape / upload_time) applied uv.lock rules to pylock*.toml:

Fix

  • lock_shape classifies each pylock sibling as Named(index), PypiFiles (no index, and every sdist/wheels url is on files.pythonhosted.org) or Files(host) (no index, another host). A lock whose siblings are all PypiFiles restores against PyPI and writes no index, matching its siblings. Files(host) refuses as "not PyPI". Mixed kinds refuse as ambiguous, as several registries already did. Packages with no registry artifacts (vcs / directory / archive) are skipped, as before.
  • Shape.whole_seconds: for pylock, upload-time is truncated to whole seconds unless a sibling artifact shows fractional seconds. uv.lock keeps milliseconds.
  • CLI_CONTRACT.md "Hosted unwind coverage" (pypi) now documents both.

Tests (red → green)

Issue Test Before fix After fix
#407 upstream_restore_golden::pylock_without_index_round_trips (LF and CRLF, plus a non-PyPI-host sibling that must still refuse) FAILED: Refused("…no sibling registry package shows the registry…") ok
#408 upstream_restore_golden::pylock_whole_second_upload_times_round_trip FAILED: restored upload-time = 2023-10-17T17:46:21.184Z, expected …:21Z ok
#408 uv::tests::pylock_upload_times_truncate_to_whole_seconds (unit) n/a (new signature) ok
both real-uv e2e e2e_redirect_uv_build hosted_uv_{export,pip_compile}_pylock_manifestless_vex: the lanes now lock a pure-Python PyPI sibling (idna==3.7, hosted mode only) and require a byte-exact rollback. Before, they accepted the documented refusal, which hid #407. FAILED locally: "no sibling registry package" refusal CI: green on every uv leg (REQUIRED=1, so a refusal or skip would fail)

Commands run locally (Linux, uv 0.8.17):

  • cargo test -p socket-patch-core --all-features --test upstream_restore_golden: 42 passed
  • cargo test -p socket-patch-core --all-features --lib upstream: 56 passed; --test uv_hosted: 4 passed
  • cargo clippy --workspace --all-features -- -D warnings (CI's invocation): clean
  • e2e_vendor_pypi_build -- --include-ignored (shares the modified lane builder): 20 passed
  • e2e_redirect_uv_build -- --ignored: 5 passed. The 2 pylock lanes now get past the shape check. Locally they then fail only at GET https://pypi.org/pypi/six/1.16.0/json, because socket-patch's rustls client can't trust this sandbox's egress-proxy CA. CI has direct network for that step.
  • cargo test --workspace --all-features: the remaining local failures are permission-based write-failure tests (the sandbox runs as root, so read-only dirs don't block writes) plus disk-pressure fallout. None touch uv, pylock or upstream restore code.
  • cargo fmt --all -- --check: main is not fmt-clean with the pinned 1.93.1 toolchain (126 files differ), and CI doesn't run it. I formatted only the hunks this PR adds.

No wrapper (npm/, pypi/, gem/) changes are needed: this is core restore logic.

🤖 Generated with Claude Code

https://claude.ai/code/session_01C2RLuAmoRAnZpABj1eX1rE


Generated by Claude Code

Assisted-by: Claude Code:claude-opus-5-5
A uv pip compile pylock (no index key) refuses to roll back (#407),
and a restored pylock entry gets millisecond upload-time values where
uv writes whole seconds (#408).

Assisted-by: Claude Code:claude-opus-5-5
Hosted rollback, remove and the vendored takeover refused every
pylock.toml written by `uv pip compile`, because that command records
no `index` key and the restore only read the registry from one (#407).
Packages without an `index` whose files are all on PyPI now show the
registry, and the entry is restored without an `index` too.

A rolled-back pylock also never matched what uv writes: restored
`upload-time` values kept milliseconds, while uv writes whole seconds
in pylock files (#408). The restore now follows the lock's own
precision.

The real-uv hosted e2e lanes for `uv export` and `uv pip compile`
pylocks now lock a PyPI sibling and require a byte-exact rollback.

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko
Mikola Lysenko (mikolalysenko) marked this pull request as ready for review October 2, 2026 00:09
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 116d022. Configure here.

@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 2, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Ready for review — burn-down agent.

  • Head: 116d02272a
  • CI: 484/484 non-skipped check runs green (3 skipped), no failing commit statuses
  • Mergeable: no conflicts, 0 commits behind main
  • Bugbot: reviewed 116d02272a, 0 unresolved threads
  • Reviewer focus: lock_shape classification of pylock siblings (Named / PypiFiles / Files(host)) in crates/socket-patch-core/src/patch/redirect/upstream/uv.rs, and the whole-seconds upload-time rule.

Generated by Claude Code

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Reviewed 116d02272aff362b7b83185196a44c7aa7c309bf. Recommendation: ready to merge from code review. No actionable correctness or security regressions found. Checked unindexed PyPI sibling inference, mixed/foreign registry refusal, preservation of omitted index, timestamp precision, and the restore callers.

Validation: all 42 upstream_restore_golden tests and all 56 core unit tests matching upstream passed (cargo test -p socket-patch-core --all-features). The real-uv CLI matrix and full workspace suite were not rerun.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review

Projects

None yet

3 participants