Repository navigation
Fix uv pylock rollback shape (#407, #408) - #512
Conversation
Assisted-by: Claude Code:claude-opus-5-5
Hosted rollback, remove and the vendored takeover refused every pylock.toml written by `uv pip compile`, because that command records no `index` key and the restore only read the registry from one (#407). Packages without an `index` whose files are all on PyPI now show the registry, and the entry is restored without an `index` too. A rolled-back pylock also never matched what uv writes: restored `upload-time` values kept milliseconds, while uv writes whole seconds in pylock files (#408). The restore now follows the lock's own precision. The real-uv hosted e2e lanes for `uv export` and `uv pip compile` pylocks now lock a PyPI sibling and require a byte-exact rollback. Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 116d022. Configure here.
|
Ready for review — burn-down agent.
Generated by Claude Code |
|
Reviewed Validation: all 42 |
LLM Description written by Claude Code:claude-opus-5-5
Fixes #407
Fixes #408
Summary
Hosted
rollback,removeand the hosted → vendored takeover now restore apylock.tomlwritten byuv pip compile. Before, they refused every such lock. A restored pylock entry also now comes back with the bytes uv writes.Root cause
The PEP 751 branch of the upstream restore (
crates/socket-patch-core/src/patch/redirect/upstream/uv.rs,lock_shape/upload_time) applied uv.lock rules topylock*.toml:uv pip compilepylock.toml because its packages carry noindexkey #407: it took the registry only from a sibling'sindexkey.uv pip compile --format pylock.tomlnever writesindex, so no sibling counted as a registry package, and the restore refused with "no sibling registry package shows the registry…".upload-timewith milliseconds, so the restored file never matches what uv writes #408: it formattedupload-timewith uv.lock's millisecond rule. uv truncates pylockupload-timeto whole seconds (checked against realuv pip compileoutput on uv 0.8.17), so a rolled-back pylock always showed a diff.Fix
lock_shapeclassifies each pylock sibling asNamed(index),PypiFiles(noindex, and everysdist/wheelsurl is onfiles.pythonhosted.org) orFiles(host)(noindex, another host). A lock whose siblings are allPypiFilesrestores against PyPI and writes noindex, matching its siblings.Files(host)refuses as "not PyPI". Mixed kinds refuse as ambiguous, as several registries already did. Packages with no registry artifacts (vcs/directory/archive) are skipped, as before.Shape.whole_seconds: for pylock,upload-timeis truncated to whole seconds unless a sibling artifact shows fractional seconds. uv.lock keeps milliseconds.Tests (red → green)
upstream_restore_golden::pylock_without_index_round_trips(LF and CRLF, plus a non-PyPI-host sibling that must still refuse)Refused("…no sibling registry package shows the registry…")upstream_restore_golden::pylock_whole_second_upload_times_round_tripupload-time = 2023-10-17T17:46:21.184Z, expected…:21Zuv::tests::pylock_upload_times_truncate_to_whole_seconds(unit)e2e_redirect_uv_buildhosted_uv_{export,pip_compile}_pylock_manifestless_vex: the lanes now lock a pure-Python PyPI sibling (idna==3.7, hosted mode only) and require a byte-exact rollback. Before, they accepted the documented refusal, which hid #407.Commands run locally (Linux, uv 0.8.17):
cargo test -p socket-patch-core --all-features --test upstream_restore_golden: 42 passedcargo test -p socket-patch-core --all-features --lib upstream: 56 passed;--test uv_hosted: 4 passedcargo clippy --workspace --all-features -- -D warnings(CI's invocation): cleane2e_vendor_pypi_build -- --include-ignored(shares the modified lane builder): 20 passede2e_redirect_uv_build -- --ignored: 5 passed. The 2 pylock lanes now get past the shape check. Locally they then fail only atGET https://pypi.org/pypi/six/1.16.0/json, because socket-patch's rustls client can't trust this sandbox's egress-proxy CA. CI has direct network for that step.cargo test --workspace --all-features: the remaining local failures are permission-based write-failure tests (the sandbox runs as root, so read-only dirs don't block writes) plus disk-pressure fallout. None touch uv, pylock or upstream restore code.cargo fmt --all -- --check:mainis not fmt-clean with the pinned 1.93.1 toolchain (126 files differ), and CI doesn't run it. I formatted only the hunks this PR adds.No wrapper (
npm/,pypi/,gem/) changes are needed: this is core restore logic.🤖 Generated with Claude Code
https://claude.ai/code/session_01C2RLuAmoRAnZpABj1eX1rE
Generated by Claude Code