Skip to content

Fix uv dry run missing inline [tool.uv] refusal (#979) - #980

Merged
Mikola Lysenko (mikolalysenko) merged 8 commits into
mainfrom
agent/fix-uv-inline-table-preflight
Oct 7, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 8 commits into
mainfrom
agent/fix-uv-inline-table-preflight

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

Fixes #979
Refs #944 (only its remaining dry-run preview piece; that issue stays with #963's claim)

Summary

On a uv project whose [tool.uv] or [tool.uv.sources] is written as an inline table, vendor --dry-run previewed a clean vendor (exit 0), but the real run refused with pypi_uv_lock_parse_failed (exit 1), and only after downloading the prebuilt wheel. With this PR the dry run previews the same refusal, and the real run refuses before any download or write.

Root cause

The uv vendored backend can't add keys to a [tool], [tool.uv] or [tool.uv.sources] that is an inline table or a non-table value, so it refuses with pyproject.toml [<path>] is not a standard table. That refusal was raised only by ensure_table inside wire_uv. The preflight check_target_guards, which pypi.rs runs before the prebuilt download and before the dry run returns, never checked the table chain.

Fix

CI fix carried for main: stale digest pending list

main (db83f01) is red on test (macos/windows), test-release and coverage. utils::digest::tests::production_digests_go_through_the_helpers fails because #690 moved crawlers/gradle_cache.rs, patch/jvm_jar.rs and patch/sidecars/maven.rs onto the utils::digest helpers but left them on PENDING_INLINE_DIGESTS, and the guard fails on a stale entry. This PR's earlier port of #878 (Route Gradle digests through utils::digest) is now a no-op after merging main. Commit d456e5b drops the three stale entries. It is test-only and no-ops once main carries the same change. Other open PRs based on main will hit the same failure until it does.

Reproduced on main 1c6c509 locally: the guard test fails with left = the 6 real inline files, right = those 6 plus the 3 Gradle files. After d456e5b it passes, and CI coverage and test (macos-latest) are green on ef589a6.

Test evidence

Red before the fix, on main + tests only:

  • vendor::pypi_uv::tests::guards_refuse_non_standard_uv_tables_like_wire failed with unwrap_err() on an Ok value: Fresh (the preflight accepted the inline table).
  • vendor::pypi::tests::uv_inline_sources_table_refused_in_dry_and_wet_runs failed with dry_run=true: expected Refused, got Done { … success: true … vendor_prebuilt_downloaded … }. This reproduces the issue: the dry run reported success.

Green after the fix: both pass.

Per-issue checklist:

Local runs (Linux, toolchain 1.93.1, on the merge with main db83f01):

  • cargo clippy --workspace --all-features -- -D warnings: clean
  • cargo test --workspace --all-features --no-fail-fast: everything passes except 12 tests that make a path read-only (0o555) or unremovable and expect a write to fail. This container runs as root, and root ignores those permissions: covgap_commands_vendor::{vendor,revert,reconcile}_state_write_failure_*, 3 in_process_redirect write-failure tests, 2 repair cleanup-failure tests, copy_tree::relax_loop_must_not_traverse_symlinked_root, vlt_heal::an_unremovable_hidden_lock_keeps_every_store_entry, pypi_poetry::wire_write_failure_* and pypi_requirements::wire_failure_rolls_back_already_written_files. None of them touch this change, and CI runs as a non-root user.
  • cargo fmt: the changed files are rustfmt-clean.
  • Wrapper tests (npm/, pypi/, gem/): not affected. This is a Rust-only change.

Why this cluster

#979 was the only untriaged issue this run, and its fix is small and self-contained. It also closes the preview gap that #963 leaves open on #944, so one change helps two issues.

🤖 Generated with Claude Code

https://claude.ai/code/session_01S9NhAHzAgkz5oUuRrbkyV3


Generated by Claude Code

Assisted-by: Claude Code:claude-opus-5-5
A uv project whose [tool.uv] or [tool.uv.sources] is written as an
inline table (sources = { ... }, [tool] uv = { ... }, dotted
uv.sources = { ... }) can't be wired, and the real `vendor` run
refused it with pypi_uv_lock_parse_failed. But that refusal was only
raised while wiring, after the dry run had already returned, so
`vendor --dry-run` previewed a clean vendor (exit 0) and the real run
downloaded the prebuilt wheel before failing (exit 1).

The uv preflight now checks the same table chain wiring will edit
([tool.uv] for a transitive package, then [tool.uv.sources]) and
refuses with the same code and message. Dry runs now preview the
refusal, and the real run refuses before any download or write.

Fixes #979

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko
Mikola Lysenko (mikolalysenko) force-pushed the agent/fix-uv-inline-table-preflight branch from e889171 to 951740b Compare October 7, 2026 03:57
main has failed socket-patch-core's lib tests since Gradle support
(#646) and the digest helpers (#865) both landed. The guard test
production_digests_go_through_the_helpers flags three files #646 added
that still hash inline: crawlers/gradle_cache.rs, patch/jvm_jar.rs and
patch/sidecars/maven.rs. That breaks test, test-release and coverage on
every open PR.

Each inline sha1/sha256 call now goes through sha1_hex_of or
sha256_hex_of, which compute the same lowercase hex. Behaviour is
unchanged.

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko
Mikola Lysenko (mikolalysenko) marked this pull request as ready for review October 7, 2026 04:28
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[agent] Ready for review at 5f01753.


Generated by Claude Code

@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 7, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[agent] coverage on 2544b31 (the main merge) fails in socket-patch-core --lib, on utils::digest::tests::production_digests_go_through_the_helpers. This comes from main, not this PR:

Proposed patch for main (I checked locally that the test passes with it on this head):

--- a/crates/socket-patch-core/src/utils/digest.rs
+++ b/crates/socket-patch-core/src/utils/digest.rs
@@ const PENDING_INLINE_DIGESTS: &[&str] = &[
-        "crawlers/gradle_cache.rs",
-        "patch/jvm_jar.rs",
-        "patch/sidecars/maven.rs",
         "utils/group_commit.rs",

Once that's on main, merging main here clears the failure. I haven't re-run the job, because it fails the same way until main changes.


Generated by Claude Code

@mikolalysenko Mikola Lysenko (mikolalysenko) removed the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 7, 2026
main has been red on test (macos/windows), test-release and coverage
since #690: it moved crawlers/gradle_cache.rs, patch/jvm_jar.rs and
patch/sidecars/maven.rs onto the utils::digest helpers but left them
on PENDING_INLINE_DIGESTS. The guard test
production_digests_go_through_the_helpers fails on a stale entry, so
socket-patch-core's lib tests fail on main and on every PR based on it.

Remove the three entries. No production behaviour changes.

Assisted-by: Claude Code:claude-opus-5-5
…ght' into agent/fix-uv-inline-table-preflight
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit ef589a6. Configure here.

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[agent] native (ubuntu-latest, 2.17.3) failed on ef589a6, and I don't think this PR caused it:

  • What failed: the PDM backtest ran 44 cases. Only one failed: 2.17.3 transitive hosted, where rollbackExit0 came back empty and rollbackRestoresLockBytes failed. All other 2.17.3 cases passed, and so did every other PDM version that has finished.
  • Why it's outside this PR: against main, this PR changes only the uv vendored preflight (vendor/pypi.rs, vendor/pypi_uv.rs) and the digest test's pending list. PDM hosted rollback goes through none of that code.
  • Why it looks intermittent: the same job passed on Fix quoted and ${VAR} requirements includes (#994) #995's head, which was merged into main just before this head was built.

No fix exists for it. I'll re-run the failed job once when the workflow run finishes. If it fails the same way a second time, I'll treat it as a real failure and look into it.


Generated by Claude Code

Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 7, 2026
main is red on production_digests_go_through_the_helpers: #690
moved gradle_cache.rs, jvm_jar.rs and sidecars/maven.rs onto the
utils::digest helpers, but PENDING_INLINE_DIGESTS still lists them,
and the ratchet fails on a stale entry. Same three-line change as
#889 and #980; it no-ops once main carries it.

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[agent] native (macos-latest, 1.3.0) failed on ef589a6. This PR didn't cause it:

  • What failed: the Bun backtest passed 52 of 53 cases. The one failure is 1.3.0 isolated vendored, where bun install --ignore-scripts (Bun itself) hung past the harness's 180-second timeout. No assertion about socket-patch's output failed.
  • Why it's outside this PR: this PR changes only the uv vendored preflight and the digest test's pending list. No Bun or npm-family code is touched.
  • Update on the PDM failure: the one re-run of native (ubuntu-latest, 2.17.3) passed.

No fix exists for a hung bun install. I'll re-run this failed job once when its workflow run finishes. If it fails the same way a second time, I'll treat it as a real failure.


Generated by Claude Code

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[agent] Ready for review at ef589a6.

  • CI on head: 498 checks succeeded, 6 skipped, 0 failing. The only failure, native (macos-latest, 1.3.0), was bun install --ignore-scripts (Bun itself) timing out after 180 s in the 1.3.0 isolated vendored case. It passed on re-run (attempt 2), so it was a flake.
  • Conflicts: none. The branch already contains main (db83f01), and GitHub reports it MERGEABLE/CLEAN.
  • Fixes made in this sweep: none needed.
  • Bugbot: clean on ef589a6 ("found no new issues"). No unresolved review threads.
  • For reviewers: this PR's utils/digest.rs change (dropping 3 stale PENDING_INLINE_DIGESTS entries) is byte-identical to Fix main CI red on stale digest pending-list entries #1016 (same blob 630adefa). These two PRs merge cleanly in either order, so this one doesn't need to wait for Fix main CI red on stale digest pending-list entries #1016.

Generated by Claude Code

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[agent] Ready to merge at ef589a6:

  • CI: all 504 checks on ef589a6 passed or were skipped.
  • Re-runs: the PDM 2.17.3 job and the macOS Bun 1.3.0 job each failed once on a hang in the package-manager tool, and each passed on its single re-run.
  • Merge state: clean. Bugbot found no issues, and there's an approval.

It's waiting only on a maintainer to merge it.


Generated by Claude Code

@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 7, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Ready for review (burn-down agent). Head ef589a6. CI: all latest check runs green (480 success, 6 skipped, 0 failing). Bugbot reviewed ef589a6: no new issues; no unresolved review threads. Branch is 1 commit behind main (#1016, whose digest-list fix this PR already carries), mergeable. Reviewer focus: check_standard_tables in crates/socket-patch-core/src/vendor/pypi_uv.rs mirrors wire_uv's table-chain order.


Generated by Claude Code

@mikolalysenko
Mikola Lysenko (mikolalysenko) merged commit 1c3dcac into main Oct 7, 2026
599 of 601 checks passed
@mikolalysenko
Mikola Lysenko (mikolalysenko) deleted the agent/fix-uv-inline-table-preflight branch October 7, 2026 15:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review

Projects

None yet

3 participants