Skip to content

Fix uv unwind of locks spelling upload_time (#788) - #789

Open
Mikola Lysenko (mikolalysenko) wants to merge 2 commits into
mainfrom
agent/fix-uv-upload-time-key-spelling
Open

Mikola Lysenko (mikolalysenko) wants to merge 2 commits into
mainfrom
agent/fix-uv-upload-time-key-spelling

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

Fixes #788

Summary

On a uv 0.6.15–0.6.17 project, a hosted patch could be applied but never taken off again. rollback, remove and the hosted→vendored takeover all exited 1 with sibling artifacts carry an unknown field \upload_time`. They now restore pyproject.tomlanduv.lock` byte-identically, as they already did on uv 0.7+.

Root cause

uv 0.6.15–0.6.17 write lock revision 2 artifacts with the timestamp key spelled upload_time. uv 0.7.0+ and PEP 751 pylocks spell it upload-time. The upstream restore (patch/redirect/upstream/uv.rs) re-derives the unpatched entry in the shape a sibling registry package shows, but four places only knew the hyphenated key:

  • the known-field allowlist in lock_shape, which refused the key;
  • the fractional-seconds probe;
  • the TOML-datetime probe;
  • the render_artifact match.

Rollback, remove and the takeover all share this one restore, so fixing it here fixes all three.

Fix

  • New UPLOAD_TIME_KEYS (both spellings) and an upload_time_value helper, used by the allowlist and both probes.
  • render_artifact accepts either key and writes it in the sibling's spelling, so the restored entry matches the rest of the lock.
  • One sentence in CLI_CONTRACT's hosted-unwind coverage says restored artifact fields keep the lock's spelling, including upload_time.

Test evidence

  • New uv_underscore_upload_time_locks_round_trip in crates/socket-patch-core/tests/upstream_restore_golden.rs. It covers a hosted round trip of a 0.6.17-shaped uv.lock (LF and CRLF) and a PEP 723 script lock, with every upload-time spelled upload_time.
    • Red without the fix (src change stashed): Refused("cannot restore pkg:pypi/urllib3@1.26.18 to its upstream registry entry: uv.lock: sibling artifacts carry an unknown field \upload_time`; …")`, which is the issue's error.
    • Green with the fix: byte-identical round trip; all uv_* golden tests pass.
  • cargo clippy --workspace --all-features -- -D warnings: clean.
  • rustfmt --check on the changed source file: clean. I did not run repo-wide cargo fmt --all, because the pinned 1.93.1 rustfmt would reformat about 130 unrelated files on main and CI has no fmt gate.
  • cargo test --workspace --all-features --no-fail-fast locally: 211 test binaries pass. 20 tests fail, all outside this change and all only because of the sandbox. They pass in CI on this head:
    • write-failure injection tests (vendor / redirect / repair / copy_tree / vlt_heal / poetry and requirements wire-failure) rely on chmod, which can't block writes for uid 0;
    • update_* / self_update_channels_e2e tests need network access.
  • CI on 39254e9: 482 checks green, 6 skipped. That includes the real-uv e2e_redirect_uv_build / e2e_vendor_pypi_build legs.
  • Cursor Bugbot on 39254e9: no issues found.

Per-issue checklist

Follow-ups

None. I made no wrapper changes (npm/pypi/gem), because this is core-only restore logic.

🤖 Generated with Claude Code


Generated by Claude Code

Assisted-by: Claude Code:claude-opus-5-5
uv 0.6.15 to 0.6.17 write the lock's artifact timestamp as
upload_time. Rollback, remove and the hosted-to-vendored takeover
refused these locks as carrying an unknown field, so a hosted patch
could be applied but never taken off again. The upstream restore now
accepts both spellings and re-derives the entry in the spelling the
lock's other packages use, so these locks restore byte-identically.

Fixes #788

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko
Mikola Lysenko (mikolalysenko) marked this pull request as ready for review October 4, 2026 16:15
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 39254e9. Configure here.

@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 4, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Ready for review — burn-down agent

  • Head: 39254e98ae0e800c69ee9d3ffed12b1d6df8e194 (0 commits behind main)
  • CI: 482/482 green, 6 skipped
  • Bugbot: reviewed 39254e9, no issues found; no open review threads
  • Reviewer focus: crates/socket-patch-core/src/patch/redirect/upstream/uv.rs — UPLOAD_TIME_KEYS / render_artifact keep the sibling's key spelling (upload_time vs upload-time).

Generated by Claude Code

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review

Projects

None yet

2 participants