Bug hunt ledger: uv #310
Replies: 20 comments
|
[agent] 2026-09-30: handover from the Poetry bug-hunt routine (ledger #311) While checking Poetry mode switches I hit the same defect on a uv project. I filed it as #328 with the Poetry evidence. Here's the uv side so you can add a uv comment to that issue, or file a uv-specific one if the root cause differs. hosted → vendored on a uv project is refused as a "user-authored" source. main printf '[project]\nname = "uvp"\nversion = "0.1.0"\nrequires-python = ">=3.9"\ndependencies = ["six==1.16.0"]\n' > pyproject.toml
uv lock && uv sync
socket-patch scan --mode hosted --json --yes # redirected: 1
uv sync
socket-patch scan --mode vendored --json --yes
# -> failed pypi_uv_source_already_exists "[tool.uv.sources] already declares a source for six; refusing to overwrite a user-authored source"
# uv.lock still: source = { url = "http://127.0.0.1:18080/patch/pypi/six/1.16.0/<token>/<uuid>/six-1.16.0-py2.py3-none-any.whl" }Root cause (shared): Not yet checked for uv: vendored → hosted, and lock-only hosted → vendored (on Poetry that fails Also unconfirmed for uv: on Poetry, vendored |
|
[agent] 2026-09-30: uv bug-hunt run This is the first run. The ledger started empty and there were no Tested: main Setup: the sandbox blocks the Socket patch hosts, so a local mock of the authenticated patch API ( Cells (Linux unless noted)
Issues
False positives ruled out
Probe runs
I couldn't delete either probe branch: the git proxy silently ignores ref deletes ("Everything up-to-date"), the same as for the siblings. A maintainer needs to delete Next
|
|
[agent] 2026-09-30: handover from the PDM bug-hunt routine (ledger #312) While filing #382 (hosted PDM rollback/remove stuck once the patched package leaves This may already be covered by #379 (uv drift after |
|
[agent] 2026-10-01: uv bug-hunt run Tested: main Harness changes for v5: hosted mode now keeps no ledger. Rollback/remove re-derive the upstream entry from PyPI's JSON API, and they need Re-triage
Cells (Linux 0.12.21 unless noted)
Issues
False positives ruled out
Probe runs
Branch deletes are still silently ignored by the git proxy. A maintainer needs to delete Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where uv puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × uv version cells for |
|
[agent] 2026-10-01: uv bug-hunt run Tested: main Re-triageMain hasn't moved since #407, #408 and #411 were filed, so they're still open and unchanged. No re-test was needed. Cells (global mode)
Issues
False positives ruled out
Probe runs
Branch deletes are still silently ignored by the git proxy. A maintainer needs to delete Next
|
|
[agent] 2026-10-01: uv bug-hunt run Tested: main Re-triage
Cells (Linux 0.8.17 unless noted)
Issues
False positives ruled out
Probe runs
The git proxy still silently ignores branch deletes. A maintainer needs to delete Operator note: a failed Next
|
|
[agent] 2026-10-01: uv bug-hunt run Tested: main The harness is new this run. It uses a Python mock patch API: the wheel is deterministic (fixed zip dates), Re-triage
Cells (Linux 0.8.17 unless noted)
Issues
False positives ruled out
Probe runs
Next
|
|
[agent] 2026-10-02: uv bug-hunt run Tested: main Re-triageMain hasn't moved, so nothing needed re-running. Fixes are in flight: #512 (#407, #408), #481 (#474), and #449 is claimed (agent/fix-python-global-tool-roots). Cells (Linux, uv 0.8.17 unless noted)
Issues
False positives ruled out
Probe runsNone this run (everything new was OS-independent text edits or Linux env-var probing). No branches pushed. Next
|
|
[agent] 2026-10-02: uv bug-hunt run Tested: main Re-triageMain hasn't moved, so I re-ran nothing. Open fix PRs: #540 (#525 and the env discovery issues), #512 (#407, #408), #481 (#474). Cells (Linux)
Issues
False positives ruled out
Probe runsNone this run. #525 already has a fix PR (#540), and the new finding is a CLI text match that doesn't depend on the OS. Next
|
|
[agent] 2026-10-02: uv bug-hunt run Tested: main Re-triageMain hasn't moved, so nothing was re-run on main. I tested PR #545 against the new #544 spellings (below): fixed. Cells (Linux)
Issues
False positives ruled out
Probe runsNone this run. #564 is driven by config, not the OS. No branches pushed. Next
|
|
[agent] 2026-10-02: uv bug-hunt run Tested: main Re-triage (current main)
Cells (Linux)
Issues
False positives ruled out
Probe runsNone. #606 is OS-independent TOML logic. No branches were pushed. Next
|
|
[agent] 2026-10-03: uv bug-hunt run Tested: main Re-triage
Cells (Linux)
Issues
False positives ruled out
Probe runsNone. #639 is OS-independent TOML logic. Next
|
|
[agent] 2026-10-03: uv bug-hunt run Tested: main Re-triageMain hasn't moved since run 9, and PR #625 is still open, so nothing was re-run for #606 / #473 / #411 / #564 / #639.
Cells (Linux unless noted)
Issues
False positives ruled out
Probe runs
Next
|
|
[agent] 2026-10-03: uv bug-hunt run Tested: main Re-triageMain hasn't moved and no uv fix PR has merged (#672 and #625 are still open), so there was nothing to re-run. #606, #473, #411, #564, #639, #670 and #701 are unchanged. Cells (Linux)
Issues
False positives ruled out
Probe runsNone. The new cells are lock-text routing, which doesn't depend on the OS. Earlier probe branches still need maintainer cleanup (see 20261003T085904Z). Next
|
|
[agent] 2026-10-04: uv bug-hunt run Tested: main Re-triageMain hasn't moved, and no uv fix PR has merged (#672, #625 and #708 are still open; #730, which fixes Cells
Issues
False positives ruled out
Probe runs
Next
|
|
[agent] 2026-10-04: uv bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Probe runs
Next
|
|
[agent] 2026-10-04: uv bug-hunt run Tested: main Re-triageMain has had no new commits since run 15, and PRs #743 / #672 / #625 have the same heads, so I re-checked no issues (results would be identical). Cells
Issues
False positives ruled out
Probe runs
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled uv bug-hunt routine (label pm:uv).
Last run: 2026-10-04 (run 16) on main
045d7ec(new #788: uv 0.6.15–0.6.17 locks spellupload_time, so hosted rollback / remove / H→V takeover always refuse; 3 OS. Version sweep 0.6.17 / 0.7.22 / 0.9.30 / 0.10.12 / 0.11.33 otherwise passes; grant-token rotation passes; #767 extended to optional-dependencies and constraint-dependencies; requirements direct reference handed to pip). Run 15 (new #767: a PEP 508 direct-reference dependency (six @ https://…/git+…) gets vendored into a lock thatuv sync --lockedrejects while vex attests, and hosted overrides the user's URL and then refuses rollback; 3 OS × 3 uv versions. PR #743 verified to fix the hosted half of #742.-glifecycle passes on macOS / Windows via a probe. A uv lockless-pyproject shape was added to #638). Run 14 (new #742: a superseding patch uuid is never applied on uv. Hosted re-scan refuses its own[tool.uv.sources]pin with exit 0 while listing the upgrade; vendored failspypi_uv_source_already_exists. #701 extended to theuv pip compile --universalrequirements lane and to script locks. 0.12.23 baseline passes on 3 OS via a probe). Run 13 (new #723 V→H takeover strands a version-pinned-down vendored package while the dry run previews success; uv evidence added to #612, where vendored uv.lock + an exported requirements.txt is left silently unpatched; uv 0.12.23 baseline passes). Run 12 (#670 verified fixed on PR #672; new #701 hosted platform-specific wheel narrows the universal uv.lock; vendoredrepairwith two packages and a vendored platform wheel pass). Run 11 was on main045d7ec(new multi-package harness: requests / urllib3 / click / dateutil / jsonschema patches; hosted with deps / extras / partial unwind all pass; new #670 vendored multi-package revert residue; #449 Windows verified fixed on a probe). Run 10 was 2026-10-03 on main045d7ec+ draft PR #625 (new #639dynamic = ["dependencies"];conflicts,required-environments,dependency-metadatapass; PR #625 verified fixing #606 / #473). Run 9 was on main045d7ec(re-verified #525, #407, #408, #474 and #449-Linux as fixed; #473 and #411 still fail; new #606;[tool.uv]resolution settings, symlink link-mode). Run 8 was on main61cfb9b(unchanged; this run addedno-sources(#564), root-level dotted sources (#544, verified fixed on PR #545), vendored script dotted sources andrepairon dotted / CRLF). Run 7 added path/git siblings, legacy dev-dependencies, constraint-dependencies, vendored sources spellings and uv 0.12.22). Run 6 was also on61cfb9b(the dotted-name, sources-spelling, lock-only and UV_PROJECT_ENVIRONMENT cells). Run 5 was also on main61cfb9b(v5; CLI reports 4.0.0, and the released 4.0.0 predates both the v4 uv rewriter and the v5 upstream restore). Earlier cells are from2463257/6e7ef74. Linux runs use real uv against a local mock patch API (withintegrity.sha512in SRI form, a deterministic wheel, the/blob/route and--patch-server-url), plusSOCKET_PYPI_JSON_API→ a local pypi.org pass-through that must not rewrite file URLs. uv 0.1.x needsSSL_CERT_FILE; uv 0.0.5 needsPUFFIN_INDEX_URL→ a local/simple/proxy. macOS and Windows runs use probe branches.Coverage matrix
H = hosted, V = vendored, A = agent. "pass/fail" is Linux unless an OS is named. Results are from v5 main (
2463257/6e7ef74) unless marked (v4).[[distribution]])--frozen/--locked)uv add(Linux, macOS, Windows); fail #411 user override (Linux, Windows); fail #477uv synckeeps patched wheel after rollbackuv add(3 OS); fail #411 (3 OS); fail #473 (3 OS); fail #477 stale after rollback (uv.lock anduv pip sync)package = false,environments, self-ref extras, hashed-requirements variants, uv.lock + exported requirements.txt, two pylocks)uv remove/uv lock --upgrade-package; fail #407; fail #408 (re-confirmed on61cfb9b); fail #411; fail #473 include-group (3 OS); fail #477 stale after rollback/revertpylock.dev.toml, include-group); fail #474 script revert afteruv add --script(3 OS)uv syncafter rollback reinstalls upstream (uv-side fix in 0.8.18)--locked/--frozen/plain, inline sources, BOM, odd-case name, idempotent, VEX, pylock, script lock, CRLF, hashed requirements, markers, ranges, groups, extras, transitive override)uv add(3 OS), script lock, hashed requirements, CRLF, multi-file; fail #411 (3 OS); fail #407; fail #408; fail #473 (3 OS);uv pip syncafter requirements unwind fail #477 (3 OS)backports.tarfilein 3 spellings; dotted / root / inline sources spellings; lock-only checkout with space + unicode path,--frozencold cache, idempotent re-scan[tool.uv.sources.<name>]sub-table leaves an empty header (rollback, remove; also 0.5.31)UV_PROJECT_ENVIRONMENTignored (abs + relative)dev-dependencies(0.4.30 / 0.5.31 / 0.8.17),constraint-dependencies(0.8.17 / 0.9.5 / 0.12.22), inline[tool] uv = {…}/ roottool = {…}/sources.x.path--frozen --offline),[tool.uv.sources]before[project], CRLF; fail #544 dotted[tool.uv] sources.x/[tool] uv.sources.x: revert / remove half-revert (0.5.31, 0.8.17, 0.12.22)not a standard table)| 0.5.31 / 0.8.17 / 0.12.22 (run 8) | fail #564
[tool.uv] no-sources = true(alsouv.toml) | – | pass: script# [tool.uv]dotted sources,repairon dotted / CRLF; fail #544 root-leveltool.uv.sources.x(fixed on PR #545); existing{ index }source refused | pass (dotted, CRLF) | – | || 0.4.30 / 0.5.31 / 0.8.17 / 0.12.22 (run 9, main
045d7ec) | pass:exclude-newer-package,required-version,index-strategy,reinstall-package, default mirror index, pylock (compile + export; #407/#408 fixed); fail #606 six declared with different specifiers (deps + extra, two extras, marker split) | fail #606 (rollback, remove, takeover); fail #473 and #411 still reproduce; no-binary / no-build refused (documented) | pass: #606 pyproject; #474 script revert afteruv add --script(fixed) | – | pass:UV_PROJECT_ENVIRONMENTabs + relative (#525 fixed);UV_LINK_MODE=symlinkon 0.5.31 / 0.8.17 / 0.12.22 |-gUV_TOOL_DIRwith space + unicode: scan + agent apply pass (#449 Linux fixed) || 0.4.30 / 0.5.31 / 0.8.17 / 0.12.22 (run 10, main
045d7ec) | pass:[tool.uv] conflicts(extras),required-environments,dependency-metadata; fail #639dynamic = ["dependencies"](scan wires it) | fail #639 (rollback, remove, takeover; also on PR #625); #606 / #473 pass on PR #625 | pass: conflicts / required-environments / dependency-metadata (0.8.17, 0.12.22);dynamicrefused by design (pypi_uv_dynamic_dependencies) | – | – | || 0.5.31 / 0.8.17 / 0.12.22 (run 11, main
045d7ec) | pass: patched packages with deps / extras / markers (requests[socks], urllib3[socks,brotli], click, jsonschema[format] + transitive dateutil), two patched packages at once,uv pip compile --emit-*hashed requirements, pylock +pylock.dev.tomlwith deps | pass: full and partial rollback / remove (both orders), byte-identical | pass for a single package with deps; fail #670 two or more packages →vendor --revertleaves empty[tool.uv.sources](also hosted→vendored takeover); script locksdistreorder (cosmetic) | – | VEX after partial unwind pass | V→H takeover with 2 packages pass (#503) || 0.5.31 / 0.8.17 / 0.12.22 (run 12, main
045d7ec) | fail #701 platform-specific patched wheel (MarkupSafe cp311 manylinux) wired with no warning:uv sync --lockedfails on py3.12 and on macOS / Windows (--python-platform); pylock too | refused (documented: release has non-pure wheels) | pass: platform wheel (vendor_platform_locked), two packages afteruv add; #670 fixed on PR #672 (3 versions) | pass: two packages, one wheel deleted | – | || 0.5.31 / 0.8.17 / 0.12.22 / 0.12.23 (run 13, main
045d7ec) | pass: 0.12.23 baseline (uv.lock + exported requirements,--locked/ cold--frozen/uv pip sync, rollback byte-identical); V→H takeover with exported requirements | fail #723 V→H takeover after a vendored version pin-down (transitive / direct; 0.5.31, 0.8.17, 0.12.23; also on PR #708) | fail #612 (uv comment) uv.lock +uv exportrequirements.txt: requirements left unpatched with no warning (4 versions); script lock + uv.lock warns (documented) | – | pass (0.12.23 agent scan) | || 0.5.31 / 0.8.17 / 0.12.23 (run 14, main
045d7ec) | fail #742 patch upgrade (new uuid) not applied: project + script lock, exit 0; fail #701 (comment)uv pip compile --universalrequirements + script lock with a cp311 wheel; 0.12.23 baseline pass on Linux / macOS / Windows (probe) | pass: rollback byte-identical (3 OS); requirements platform-wheel rollback byte-identical | fail #742 re-vendor on a new uuid (pypi_uv_source_already_exists); baseline pass on 3 OS (unicode + space dir); H→V takeover with exported requirements: uv.lock pass, requirements.txt unpatched (#612) | – | – | V→H takeover pass on 3 OS || 0.5.31 / 0.8.17 / 0.12.23 (run 15, main
045d7ec) | fail #767 PEP 508 direct reference (six @ https://…): overrides the user URL; pylockarchiverollback becomes a registry entry; lockless pyproject is silent (#638 comment); pass: cross-version--locked, re-lock across revisions, trailing-slash index,resolution-markerslock,get(purl / uuid / name), concurrent scans; PR #743 fixes the #742 upgrade (project / override / script,--max-new-patches 0) | fail #767 (rollback refuses "direct reference", 3 OS) | fail #767 (requires-distgetsurl+path→--lockedfails, vex attests; also git refs, dependency groups; 3 OS); pass:get, forked lock | – | pass:UV_COMPILE_BYTECODE, 0.5.31 / 0.12.23 × hardlink / copy,get| script with space + unicode name pass || 0.6.15–0.6.17 / 0.7.22 / 0.9.30 / 0.10.12 / 0.11.33 (run 16, main
045d7ec) | pass: round trip on all; grant-token rotation (0.5.31 / 0.8.17 / 0.12.23); comments / editable path source formatting;build-constraint-dependencies;pylock.<name>.tomlnames; fail #767 direct ref in optional-dependencies / constraint-dependencies | fail #788 on 0.6.15–0.6.17 (upload_time: rollback, remove, takeover, script lock; 3 OS); pass on 0.7.x+ (3 OS for 0.7.22) | pass on all; fail #767 optional / constraint direct ref (--lockedfails, vex attests) | – | – | hosted write failure mid-commit leaves pyproject.toml half-written (recoverable by re-scan; candidate) |Global (
-g) modeUV_TOOL_DIR/XDG_DATA_HOMEUV_PYTHON_INSTALL_DIR--product/ rollback / get / remove; stale reinstall → vex refuses)045d7ec(#449 fixed:%APPDATA%\uv\tools)UV_TOOL_DIRwith space + unicode,XDG_DATA_HOME)SOCKET_GLOBAL=1,--global-prefix/SOCKET_GLOBAL_PREFIXwith space and unicode paths, and project isolation (-gskips.venv) all pass on Linux.Backlog
upload_timeinstead ofupload-time#788 (new), uv projects that declare the patched package as a PEP 508 direct URL (six @ https://…/git+…): vendored writes a lockuv sync --lockedrejects while vex attests, and hosted overrides the user's URL then refuses to roll it back #767, uv projects never pick up a superseding patch: hosted re-scan lists the upgrade in updates[] but refuses its own earlier [tool.uv.sources] pin (exit 0, still on the old uuid), and vendored re-scan fails pypi_uv_source_already_exists #742 (hosted half verified on PR Fix uv/Hatch hosted re-pin to a newer patch (#742, #650) #743; vendored slice pending), Vendored uv with two or more packages: vendor --revert (and remove in purl order) leave an empty[tool.uv.sources]header in pyproject.toml #670 once PR Fix vendored revert leaving created scaffold behind (#636, #670) #672 merges, Hosted uv rollback, remove and vendored takeover refuse when the patched package is declared with different specifiers independenciesand an extra (or under different markers), although each lock entry keeps its marker #606 / Hosted uv rollback and remove refuse when the patched package reaches a dependency group through PEP 735include-group#473 once PR Fix uv hosted unwind declaration matching (#606, #473) #625 merges, and uv vendored → hosted takeover strands a package that vendored mode pinned to a different version than uv.lock: the wet run reverts to the unpatched release (exit 1), while --dry-run previews a clean takeover #723 when a fix lands. Also Hosted uv rollback and remove delete a user-authoredoverride-dependencies = ["<pkg>==<ver>"]pin that hosted mode never added #411, Hosted and vendored uv wiring ignoreno-sources = true: scan and vendor report success,uv sync --lockedthen fails, and a plainuv syncreinstalls the unpatched wheel #564, Hosted uv scan wires adynamic = ["dependencies"]project, but rollback, remove and the vendored takeover then always refuse ("pyproject.toml no longer declares six") #639 and Hosted uv scan silently wires a platform-specific patched wheel (cp311 manylinux) into a universal uv.lock, souv sync --lockedfails on every other Python version, macOS and Windows, and rollback then refuses #701, and the Vendored mode in a Pipenv project wires only Pipfile.lock and silently leaves a sibling requirements.txt unpatched, and the hosted → vendored takeover reverts that file's hosted pin to plain PyPI #612 / Hostedscan --jsonon a PyPI project with no root requirements.txt (e.g. onlyrequirements-dev.txtorrequirements/base.txt) reports success with emptyskippedandwarnings, though the patched package is never pinned #638 uv shapes. Hosted rollback, remove and vendored takeover always refuse on auv pip compilepylock.toml because its packages carry noindexkey #407, Hosted rollback rewrites uv pylock.tomlupload-timewith milliseconds, so the restored file never matches what uv writes #408, Vendored uv script lock can't be reverted afteruv add --scriptadds an unrelated dependency (vendor_lock_entry_drifted, still exit 0) #474, uv projects whose env is set by UV_PROJECT_ENVIRONMENT are never probed: agent scan patches the PATH interpreter and uv tool envs instead, the real env stays vulnerable, and vex attests not_affected #525, uv rollback, remove and vendor --revert leave an empty[tool.uv.sources]header behind when the project's sources are written as[tool.uv.sources.<name>]sub-tables #524, Vendored uv revert and remove half-revert a project whose sources use dotted keys under [tool.uv]: uv.lock is restored but thesources.<pkg>line stays, souv sync --lockedfails (vendor --revert exits 0) #544 and Global scan (-g) misses uv tool environments on Windows (looks in %LOCALAPPDATA%\uv\tools, uv uses %APPDATA%\uv\tools) and on every OS when UV_TOOL_DIR, XDG_DATA_HOME or UV_PYTHON_INSTALL_DIR is set #449 (all OS, incl.UV_PYTHON_INSTALL_DIR) are verified fixed.six @ https://…/git+…): vendored writes a lockuv sync --lockedrejects while vex attests, and hosted overrides the user's URL then refuses to roll it back #767 comment + pip handover.) New: a Windows probe of hosted write atomicity (uv.lock held open without delete sharing); a lockless PEP 723 script; uv 0.12.22+ revision-5 specifics with git / path / url sources.git push --deletehangs up through the proxy). Thirteenbughunt/uv/*branches need maintainer cleanup, including20261004-global-lifecycle,20261004-direct-urland20261004-upload-time.-grollback / vex and the macOS-gre-probe, with the mock instead of a live patch. The unwritable-prefix cell is still open: ubuntu-latest runners exit 1 on apply / get / vex-gwhile the target is patched (likely the root-owned system six); confirm with stderr.Known non-bugs
[tool.uv.workspace]or[manifest] membersbeyond the root) are refused in both modes (redirect_uv_project_unsupported/pypi_uv_workspace_unsupported). This is by design, though it's missing from docs/testing/uv-compatibility.md.045d7ecit takes over in place (redirect_takeover_reverted_vendored) and unwinds byte-identically (run 11).six>=1.10,<1.17) unless another lock entry shows uv's clause spelling. This is in theupstream/uv.rsmodule doc, not the user docs. It's justified: uv 0.2.37 keeps clause order and ≥0.5 sorts them.[[distribution]]locks,exclude-newer/no-binary/no-build, and non-PyPI registries (documented).--patch-server-urlfor a non-Socket origin reports "Manifest not found" (the origin isn't recognised as hosted). This is a harness artifact.vendor_fetch_failed/ "error sending request" for pypi.org / files.pythonhosted.org in the sandbox is a rustls vs proxy-CA artifact. Use a local forwarder viaSOCKET_PYPI_JSON_API.redirect_pypi_stale_installtext mentions Poetry on uv projects (cosmetic, v4 observation).scan -g --mode hosted(and--global-prefix/SOCKET_GLOBAL=1with hosted) exits 2 by design. A global scan with no mode is report-only.[[tool.uv.index]](for example a PyTorch index next to PyPI → "several registries"; only one sibling, on that index → "not PyPI"), even though the patched package came from PyPI. CLI_CONTRACT documents this ("other registry packages name … several, or one other than PyPI's simple index"). Hosted scan of a package that carries its own{ index = … }source is warn-onlyredirect_uv_project_unsupported("already declares a source"). Both are documented. The first is a candidate for a maintainer to narrow.repair→download_failedagainst the local mock is a harness gap (no diff archive served).Six===1.16.0restoressix==1.16.0, and a comment after a hash continuation is joined onto the last hash line. v5 upstream restore re-derives the pin, so the install is identical. uv never writes either spelling (cosmetic).--vexexits 1no_applicable_patcheswhile the venv is still stale (documented "installed evidence wins").uv remove --scriptof its only sibling refuses "no sibling registry package…" (documented; same as the project case).integrity.sha512→vendor_prebuilt_integrity_mismatch(the service sends SRIsha512-<b64>); a non-deterministic mock wheel → hash mismatch after a mock restart; a JSON forwarder that rewrites file URLs → rollback writes those URLs into the lock.redirect_uv_project_unsupported("marker-specific source mappings are required"), vendored ispypi_uv_lock_forked_package(exit 1). Documented in uv-compatibility.md:135.archive-v0entries containing patched bytes after hosted runs are the hosted wheels uv unpacked, not agent-mode pollution (agent apply breaks the hardlinks).[tool.uv] sources = { … }or[tool] uv = { … }) withpypi_uv_lock_parse_failed: … is not a standard table, before writing anything. Hosted mode grows the inline table in place. This is intentional (unit-tested in pypi_uv.rs) but undocumented.requirements.txtitself. A pin that lives only in a-c constraints.txtor-r base.txtinclude gets the warningredirect_requirements_entry_not_found(not silent). This is pip-generic, so don't file it under uv.[tool.uv.sources]entry (for example{ index = "…" }) withpypi_uv_source_already_exists(exit 1, nothing written). This is intentional but undocumented in uv-compatibility.md.uv run --scripton uv ≤0.8.17 keeps the cached patched env. This is uv-side (0.12.22 reinstalls upstream), the same as the 0.8.18 boundary foruv sync.[tool.uv.sources]header (no entries) is removed with the rollback. Both are cosmetic: uv sees the same configuration anduv lock --checkpasses. Not filed.vendor_prebuilt_required"tarball artifact has no sha512 integrity" is a mock gap. Serve SRI sha512 on/patch/package.dynamic = ["dependencies"]projects up front (pypi_uv_dynamic_dependencies, nothing written). This is intentional but undocumented in uv-compatibility.md. Hosted mode has no such guard (Hosted uv scan wires adynamic = ["dependencies"]project, but rollback, remove and the vendored takeover then always refuse ("pyproject.toml no longer declares six") #639).--cwddownward (docs/configuration.md), unlike uv's upward project discovery. This is generic and not uv-specific.redirect_uv_entry_not_foundfor a patched package missing from one of several pylocks (for example a--only-group devexport). This is accurate and informational.uv remove,vendor --revertdrift-keeps (vendor_lock_entry_drifted/vendor_revert_kept, success,removed 0) and.socket/vendorstays, although nothing references it any more. This is documented (CLI_CONTRACT: "the drift-kept artifact and entry stay, every backend alike"), andvexcorrectly refuses. It's a candidate to narrow: composer / maven / nuget drop the artifact once no file references it.--vendor-source buildwas removed, andvendor --offlinewith the default source failsvendor_service_offline_conflict. The harness must mockPOST /patch/package(use--vendor-url/--proxy-url/--patch-server-url).override-dependencies, and a directsix>=1.15or evensix>=1.17gets a path source to the 1.16.0 wheel; uv accepts it). This is intentional (pypi_uv.rsoverride_wiring_matches_fixture_byte_identically) but undocumented, and Pipenv refuses the same case (pypi_pipenv_version_mismatch). It's a candidate to warn on. Its takeover consequence is filed as uv vendored → hosted takeover strands a package that vendored mode pinned to a different version than uv.lock: the wet run reverts to the unpatched release (exit 1), while --dry-run previews a clean takeover #723.content_mismatch_overwritten). This is the documented v3.4 default;--strictrefuses.pypi_multiple_lockfiles. This is documented ("uv.lockkeeps its exclusive precedence").UV_NO_SOURCES=1/uv sync --no-sourcesat install time bypasses the sources-based hosted and vendored wiring (0.12.23:--lockedfails and a plain sync relocks to unpatched; 0.8.17 still installs patched). That's the user's explicit opt-out at install time. The config-levelno-sources = trueat scan time is Hosted and vendored uv wiring ignoreno-sources = true: scan and vendor report success,uv sync --lockedthen fails, and a plainuv syncreinstalls the unpatched wheel #564.pypi_requirements_already_vendored) is pip-generic. It was handed to the pip routine in run 14; don't re-file it under uv.SOCKET_PYPI_JSON_APImust be<mock>/pypi(the CLI appends/<name>/<version>/json).sub/(lock-only or with a.venv) and a script lock inscripts/are not discovered from the repo root (scannedPackages: 0, exit 0). This is generic, not uv-specific; nested-project discovery is planned (PR Speed up hosted and vendored scans: concurrent API requests, parallel crawl, single-pass rewriters #257 follow-ups).pypi_uv_lock_revision_untestedon uv 0.12.x vendored runs: uv writes lock revision 5, and the fixtures only test up to 3. It's an informationalskippedevent that isn't counted insummary.skipped; the fixtures should be bumped.vex -gwith no detectable product exits 2 asking for--product(usage).UV_COMPILE_BYTECODE=1venv is safe: uv writes timestamp-based pycs, so the patched source is recompiled.[project](dependency-groups only; uv 0.12 locks it) is refused cleanly: hosted warnsredirect_uv_project_unsupported("no project table"), vendored failspypi_uv_lock_root_missing, and nothing is written. Undocumented, but honest.scan/rollback/removewrite pyproject.toml and uv.lock one after another with no undo, so a write failure on uv.lock (exit 1, reported) leaves pyproject.toml changed. After a failed rollback, rollback / remove / list failhosted_wiring_contesteduntilscan --mode hostedis re-run, which the error suggests and which heals it. The code acknowledges this (RestoreOutcome::flush_error). It's generic across ecosystems and recoverable; vendored has a commit journal. A candidate to harden; not filed (run 16).pylock.a.b.toml,pylock..tomlandPYLOCK.tomlitself, so whether socket-patch discovers them doesn't matter.no-binary/no-buildrefusal matches any[tool.uv] no-binary*key, includingno-binary-packagefor an unrelated package. This is documented ("options filter files"), but broad.All reactions