Repository navigation
Fix hosted uv unwind deleting user override pins (#411) - #1331
Merged
Mikola Lysenko (mikolalysenko) merged 4 commits intoOct 9, 2026
Merged
Conversation
Empty commit to open the draft PR. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A hosted rollback, remove or vendored takeover of a uv project deleted the user's own `[tool.uv] override-dependencies = ["six==1.16.0"]` pin (plus the lock's `[manifest] overrides` record and the emptied `[tool.uv]` table) and blamed hosted mode for adding it. The next `uv lock --upgrade` then moved six past the release the user had held back. Hosted mode keeps no ledger, so the restore guessed ownership from the entry's spelling. The hosted rewrite now puts a `# socket-patch hosted: ...` comment line above each override entry it adds, and the restore removes only a marked entry. A user's own pin of the same release (which the rewrite reuses instead of adding a second one) is kept, and its lock record gets its specifier back. Vendored mode is unchanged: its ledger records the originals. Fixes #411 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko)
marked this pull request as ready for review
October 9, 2026 17:25
Collaborator
Author
|
BugBot review |
Mikola Lysenko (mikolalysenko)
enabled auto-merge
October 9, 2026 17:25
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 6eefaf2. Configure here.
Tanmay Singla (Tanmay182003)
approved these changes
Oct 9, 2026
Collaborator
Author
|
Ready for review at
Labeled Generated by Claude Code |
Mikola Lysenko (mikolalysenko)
removed this pull request from the merge queue due to a manual request
Oct 9, 2026
Mikola Lysenko (mikolalysenko)
deleted the
agent/v5-uv-override-ownership
branch
October 9, 2026 21:56
Mikola Lysenko (mikolalysenko)
added a commit
that referenced
this pull request
Oct 10, 2026
Resolve python_script.rs by keeping both sides: the PR's refuse_direct_reference (PEP 508 direct-ref refusal, #767) and main's hosted override-dependencies marking (HOSTED_OVERRIDE_MARK, is_hosted_override, push_hosted_override, #411/#1331). The two were independent additions at the same spot. Re-bless tests/equivalence/python_lock_rewrite.golden with SOCKET_PATCH_BLESS_GOLDEN=1. Per-case dumps of all 1500 seeds from base, PR, main and merge: 1226 unchanged, 140 match main, 100 match the PR, 28 changed by both resolve to the PR's refusals plus main's marked override layout. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by Claude Code:claude-opus-5-5
Fixes #411
Summary
A hosted
rollback/remove(and the hosted → vendored takeover, which runs the same upstream restore) of a uv project deleted the user's own[tool.uv] override-dependencies = ["six==1.16.0"]pin, the lock's[manifest] overridesrecord of it and the emptied[tool.uv]table, then warnedupstream_uv_override_removedas if hosted mode had added it. The nextuv lock --upgrademoved six past the release the user had pinned.Root cause
v5 hosted mode keeps no ledger, so
pushed_overrideinpatch/redirect/upstream/uv.rsdecided ownership by spelling alone: any<name>==<version>override of a transitive dependency counted as the one the rewrite adds. The hosted rewrite (utils/python_script.rsrewrite_sources) reuses a user's identical override rather than adding one, so after the scan the two cases were byte-identical.Fix
# socket-patch hosted: pins a patched transitive dependency; rollback removes it(HOSTED_OVERRIDE_MARK). That comment is the ownership evidence. A new array is laid out multi-line. When the array already exists, only the new element is added, and removing it brings back the original bytes. Only the hosted (ArtifactSource::Url) lane is marked. Vendored script wiring is unchanged, because its ledger records the originals.pushed_overridematches only a marked entry. A user's unmarked pin is kept,restore_metadatareports no removal (so noupstream_uv_override_removed), and the lock's[manifest] overridesentry gets itsspecifierback from the declaration instead of being dropped.Note: v5 is unreleased, so no released build wrote unmarked hosted overrides. Under this rule, an unmarked entry left by a pre-release main build is kept (fail-safe). The lock and pyproject stay consistent.
Tests (red → green)
upstream::uv::tests::restore_keeps_a_user_authored_override_of_the_patched_release(hosted rewrite → restore round-trips a user override byte-for-byte, in three array spellings and a script)[manifest] overridesupstream::uv::declaration_tests::manifest_override_of_a_user_pin_is_restored_not_droppedupstream::uv::tests::restore_removes_the_override_the_rewrite_added(new array, existing single-line and multi-line user arrays, script)Red was verified by reverting only the ownership check in
pushed_override. Updated: fourpython_scriptrendering tests that pin the hosted output, and thepython_lock_rewritegolden (re-blessed; only output digests of cases that add an override changed).Commands run
cargo test -p socket-patch-core --lib: 6112 passedSOCKET_PATCH_UV_E2E_REQUIRED=1 cargo test -p socket-patch-cli --test e2e_redirect_uv_build -- --ignored hosted_uv_transitive_override_manifestless_vex hosted_uv_script_lock_manifestless_vex(real uv 0.11.19): both ok. The fresh install is patched, a plainuv synckeeps the lock, and the transitive revert restores the upstream registry entry.cargo fmt --all -- --check(my files clean;upstream/mod.rsdiff is pre-existing on main) andcargo clippy --workspace --all-features -- -D warnings: clean🤖 Generated with Claude Code