Fix uv hosted unwind declaration matching (#606, #473) - #625
Mikola Lysenko (mikolalysenko) wants to merge 8 commits into
Conversation
Assisted-by: Claude Code:claude-opus-5-5
Rollback, remove and the hosted to vendored takeover refused to unwind a hosted uv pin when the package was declared with different specifiers in dependencies and an extra (or under different markers), or reached a dependency group through a PEP 735 include-group. Each lock entry is now matched to the declaration uv lowered it from: the marker's extra terms pick the extra, the rest of the marker picks among marker-split lines, and include-group members are expanded. An entry no declaration matches is still refused. Adds real-uv extras and include-group lanes to e2e_redirect_uv_build. Fixes #606, #473. Assisted-by: Claude Code:claude-opus-5-5
Lock an idna sibling in the extras and include-group lanes so the hosted rollback actually re-derives the registry entry, and require it to restore byte for byte. Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
|
Ready for review at head
Generated by Claude Code |
|
Review updated for The unwind preserves unambiguous simple All 87 focused tests and both real uv 0.11.19 capstones passed on The author added the required discovery golden in Windows CI exposed a separate fixture checkout issue: Git converted LF to CRLF, then the regression test created invalid double-CRLF bytes. The author added the existing repo convention of Independent marker and rollback reviews are clear. The committed sources match the tested files; core clippy and diff checks pass, and new production/test blocks match rustfmt, with the existing unrelated macOS warning recorded. The commit merges cleanly with current main. No remaining actionable finding from this review. The Ready label is restored after all checks completed on the corrected commit. CI note: macOS Bun 1.3.10 initially hit a patch-service connection timeout before the expected workspace refusal; its other 52 cases passed and the harness recorded no project-file changes. One targeted job retry passed all 53 cases, including the correct refusal. No source change was needed for that network failure. |
A dependencies line can carry its own extra == 'x' marker, so its lock entry looks exactly like one lowered from extra x. When the two declare different specifiers, which entry mirrors which is not derivable; the unwind now refuses instead of restoring both from the optional declaration and silently dropping the direct requirement. A refused hit also leaves uv.lock exactly as it was: its entry and requirement arrays are restored together or not at all. Assisted-by: Claude Code:claude-opus-5-5
|
[agent] Confirmed the P2 finding and fixed it in 413ffb3. A Tests (red without the narrowing fix, green with it): Generated by Claude Code |
|
BugBot review Generated by Claude Code |
Preserve simple forward extra equality and all-agree matching, but keep other declaration-owned extra expressions ambiguous when clauses differ. Reversed equality can produce the same native uv marker as an optional group, so selecting only that group loses the original requirement. Add native-fixture transaction coverage for both comparison directions, LF/CRLF and dry runs, retaining all hosted bytes when unwind is refused.
|
BugBot review Please review the corrected commit |
|
[agent] CI: Generated by Claude Code |
|
[agent] CI: Generated by Claude Code |
|
[agent] Update on the PDM run for Generated by Claude Code |
The uv explicit-extra fixture added under tests/fixtures/upstream joins the VEX discovery golden corpus, which needs a golden for every fixture directory. Regenerated with SOCKET_PATCH_UPDATE_GOLDEN=1: the pristine lock has no hosted refs, only its two registry packages. Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
|
[agent] CI: Generated by Claude Code |
On Windows, autocrlf turned the uv explicit-extra fixture into CRLF, so the restore test's CRLF variant became CR CR LF and failed. Mark tests/fixtures/upstream as -text like the other native lock fixtures. Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
|
[agent] CI: Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit cfae77e. Configure here.
|
[agent] CI: Generated by Claude Code |
LLM Description written by Claude Code:claude-opus-5-5
Fixes #606 and #473. Hosted uv rollback, removal and vendored takeover previously refused when a package had different specifiers across ordinary dependencies, extras or marker-split declarations, or when it reached a dependency group through a PEP 735 include.
The unwind now records which optional group each declaration came from, expands normalized
include-groupreferences with a cycle guard, and uses the lock entry's marker to find the matching declaration. Marker comparisons account for uv's supportedpython_version→python_full_versionrewrites. When every candidate's version clauses agree, the unwind uses them without having to work out which declaration the entry came from.Declarations whose own markers use
extraneed care. uv can give a direct dependency and an optional dependency identical lock markers even though their version constraints differ. A simple forward equality (extra == 'name') is still matched when that's unambiguous. Any other explicit-extra expression, including the reversed'name' == extra, refuses when the clauses differ, so the unwind can't silently report success after writing the wrong requirement. The supported subset and the refusal behavior are documented indocs/testing/uv-compatibility.md.Each package's lock edits are restored together or discarded together on refusal, and the new transaction regression confirms that a refusal leaves both
uv.lockandpyproject.tomluntouched.Validation:
extrasandinclude-grouplanes ofe2e_redirect_uv_build) cover the hosted rewrite, fresh and plain installs, VEX, online PyPI reconstruction and a byte-exact rollback of both project files.uv lock --check --offlineaccepts the pristine lock and rejects the wrongly collapsed one.upstream.jsonwas added for the new native fixture (two registry packages, no patched references). The 17 existing snapshots are unchanged.tests/fixtures/upstream/** -text, the same rule the other native lock fixtures use.cfae77e3: 488/488 green. Compatibility-lane jobs that failed on earlier commits (PDM, Poetry, Bun) were in code paths this PR doesn't reach, and they passed on re-run or on the next commit.🤖 Generated with Claude Code