Skip to content

Fix uv unwind of locks spelling upload_time (#788) - #789

Merged
Mikola Lysenko (mikolalysenko) merged 2 commits into
mainfrom
agent/fix-uv-upload-time-key-spelling
Oct 5, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 2 commits into
mainfrom
agent/fix-uv-upload-time-key-spelling

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

Fixes #788

Summary

On a uv 0.6.15–0.6.17 project, a hosted patch could be applied but never taken off again. rollback, remove and the hosted→vendored takeover all exited 1 with sibling artifacts carry an unknown field \upload_time`. They now restore pyproject.tomlanduv.lock` byte-identically, as they already did on uv 0.7+.

Root cause

uv 0.6.15–0.6.17 write lock revision 2 artifacts with the timestamp key spelled upload_time. uv 0.7.0+ and PEP 751 pylocks spell it upload-time. The upstream restore (patch/redirect/upstream/uv.rs) re-derives the unpatched entry in the shape a sibling registry package shows, but four places only knew the hyphenated key:

  • the known-field allowlist in lock_shape, which refused the key;
  • the fractional-seconds probe;
  • the TOML-datetime probe;
  • the render_artifact match.

Rollback, remove and the takeover all share this one restore, so fixing it here fixes all three.

Fix

  • New UPLOAD_TIME_KEYS (both spellings) and an upload_time_value helper, used by the allowlist and both probes.
  • render_artifact accepts either key and writes it in the sibling's spelling, so the restored entry matches the rest of the lock.
  • One sentence in CLI_CONTRACT's hosted-unwind coverage says restored artifact fields keep the lock's spelling, including upload_time.

Test evidence

  • New uv_underscore_upload_time_locks_round_trip in crates/socket-patch-core/tests/upstream_restore_golden.rs. It covers a hosted round trip of a 0.6.17-shaped uv.lock (LF and CRLF) and a PEP 723 script lock, with every upload-time spelled upload_time.
    • Red without the fix (src change stashed): Refused("cannot restore pkg:pypi/urllib3@1.26.18 to its upstream registry entry: uv.lock: sibling artifacts carry an unknown field \upload_time`; …")`, which is the issue's error.
    • Green with the fix: byte-identical round trip; all uv_* golden tests pass.
  • cargo clippy --workspace --all-features -- -D warnings: clean.
  • rustfmt --check on the changed source file: clean. I did not run repo-wide cargo fmt --all, because the pinned 1.93.1 rustfmt would reformat about 130 unrelated files on main and CI has no fmt gate.
  • cargo test --workspace --all-features --no-fail-fast locally: 211 test binaries pass. 20 tests fail, all outside this change and all only because of the sandbox. They pass in CI on this head:
    • write-failure injection tests (vendor / redirect / repair / copy_tree / vlt_heal / poetry and requirements wire-failure) rely on chmod, which can't block writes for uid 0;
    • update_* / self_update_channels_e2e tests need network access.
  • CI on 39254e9: 482 checks green, 6 skipped. That includes the real-uv e2e_redirect_uv_build / e2e_vendor_pypi_build legs.
  • Cursor Bugbot on 39254e9: no issues found.

Per-issue checklist

Follow-ups

None. I made no wrapper changes (npm/pypi/gem), because this is core-only restore logic.

🤖 Generated with Claude Code


Generated by Claude Code

Assisted-by: Claude Code:claude-opus-5-5
uv 0.6.15 to 0.6.17 write the lock's artifact timestamp as
upload_time. Rollback, remove and the hosted-to-vendored takeover
refused these locks as carrying an unknown field, so a hosted patch
could be applied but never taken off again. The upstream restore now
accepts both spellings and re-derives the entry in the spelling the
lock's other packages use, so these locks restore byte-identically.

Fixes #788

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko
Mikola Lysenko (mikolalysenko) marked this pull request as ready for review October 4, 2026 16:15
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 39254e9. Configure here.

@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 4, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Ready for review — burn-down agent

  • Head: 39254e98ae0e800c69ee9d3ffed12b1d6df8e194 (0 commits behind main)
  • CI: 482/482 green, 6 skipped
  • Bugbot: reviewed 39254e9, no issues found; no open review threads
  • Reviewer focus: crates/socket-patch-core/src/patch/redirect/upstream/uv.rs — UPLOAD_TIME_KEYS / render_artifact keep the sibling's key spelling (upload_time vs upload-time).

Generated by Claude Code

@mikolalysenko
Mikola Lysenko (mikolalysenko) merged commit 9f2304f into main Oct 5, 2026
489 checks passed
@mikolalysenko
Mikola Lysenko (mikolalysenko) deleted the agent/fix-uv-upload-time-key-spelling branch October 5, 2026 11:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review

Projects

None yet

3 participants