Fix uv unwind of locks spelling upload_time (#788) - #789
Open
Mikola Lysenko (mikolalysenko) wants to merge 2 commits into
Open
Mikola Lysenko (mikolalysenko) wants to merge 2 commits into
Mikola Lysenko (mikolalysenko) wants to merge 2 commits into
Conversation
Assisted-by: Claude Code:claude-opus-5-5
uv 0.6.15 to 0.6.17 write the lock's artifact timestamp as upload_time. Rollback, remove and the hosted-to-vendored takeover refused these locks as carrying an unknown field, so a hosted patch could be applied but never taken off again. The upstream restore now accepts both spellings and re-derives the entry in the spelling the lock's other packages use, so these locks restore byte-identically. Fixes #788 Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko)
marked this pull request as ready for review
October 4, 2026 16:15
Collaborator
Author
|
BugBot review Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 39254e9. Configure here.
Collaborator
Author
|
Ready for review — burn-down agent
Generated by Claude Code |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by Claude Code:claude-opus-5-5
Fixes #788
Summary
On a uv 0.6.15–0.6.17 project, a hosted patch could be applied but never taken off again.
rollback,removeand the hosted→vendored takeover all exited 1 withsibling artifacts carry an unknown field \upload_time`. They now restorepyproject.tomlanduv.lock` byte-identically, as they already did on uv 0.7+.Root cause
uv 0.6.15–0.6.17 write lock revision 2 artifacts with the timestamp key spelled
upload_time. uv 0.7.0+ and PEP 751 pylocks spell itupload-time. The upstream restore (patch/redirect/upstream/uv.rs) re-derives the unpatched entry in the shape a sibling registry package shows, but four places only knew the hyphenated key:lock_shape, which refused the key;render_artifactmatch.Rollback, remove and the takeover all share this one restore, so fixing it here fixes all three.
Fix
UPLOAD_TIME_KEYS(both spellings) and anupload_time_valuehelper, used by the allowlist and both probes.render_artifactaccepts either key and writes it in the sibling's spelling, so the restored entry matches the rest of the lock.upload_time.Test evidence
uv_underscore_upload_time_locks_round_tripincrates/socket-patch-core/tests/upstream_restore_golden.rs. It covers a hosted round trip of a 0.6.17-shapeduv.lock(LF and CRLF) and a PEP 723 script lock, with everyupload-timespelledupload_time.Refused("cannot restore pkg:pypi/urllib3@1.26.18 to its upstream registry entry: uv.lock: sibling artifacts carry an unknown field \upload_time`; …")`, which is the issue's error.uv_*golden tests pass.cargo clippy --workspace --all-features -- -D warnings: clean.rustfmt --checkon the changed source file: clean. I did not run repo-widecargo fmt --all, because the pinned 1.93.1 rustfmt would reformat about 130 unrelated files onmainand CI has no fmt gate.cargo test --workspace --all-features --no-fail-fastlocally: 211 test binaries pass. 20 tests fail, all outside this change and all only because of the sandbox. They pass in CI on this head:chmod, which can't block writes for uid 0;update_*/self_update_channels_e2etests need network access.e2e_redirect_uv_build/e2e_vendor_pypi_buildlegs.Per-issue checklist
upload_timeinstead ofupload-time#788: rollback / remove / takeover of anupload_timelock →uv_underscore_upload_time_locks_round_trip(project lock LF + CRLF, script lock)Follow-ups
None. I made no wrapper changes (npm/pypi/gem), because this is core-only restore logic.
🤖 Generated with Claude Code
Generated by Claude Code