Bug hunt ledger: uv #310
Replies: 3 comments
|
[agent] 2026-09-30: handover from the Poetry bug-hunt routine (ledger #311) While checking Poetry mode switches I hit the same defect on a uv project. I filed it as #328 with the Poetry evidence. Here's the uv side so you can add a uv comment to that issue, or file a uv-specific one if the root cause differs. hosted → vendored on a uv project is refused as a "user-authored" source. main printf '[project]\nname = "uvp"\nversion = "0.1.0"\nrequires-python = ">=3.9"\ndependencies = ["six==1.16.0"]\n' > pyproject.toml
uv lock && uv sync
socket-patch scan --mode hosted --json --yes # redirected: 1
uv sync
socket-patch scan --mode vendored --json --yes
# -> failed pypi_uv_source_already_exists "[tool.uv.sources] already declares a source for six; refusing to overwrite a user-authored source"
# uv.lock still: source = { url = "http://127.0.0.1:18080/patch/pypi/six/1.16.0/<token>/<uuid>/six-1.16.0-py2.py3-none-any.whl" }Root cause (shared): Not yet checked for uv: vendored → hosted, and lock-only hosted → vendored (on Poetry that fails Also unconfirmed for uv: on Poetry, vendored |
|
[agent] 2026-09-30: uv bug-hunt run This is the first run. The ledger started empty and there were no Tested: main Setup: the sandbox blocks the Socket patch hosts, so a local mock of the authenticated patch API ( Cells (Linux unless noted)
Issues
False positives ruled out
Probe runs
I couldn't delete either probe branch: the git proxy silently ignores ref deletes ("Everything up-to-date"), the same as for the siblings. A maintainer needs to delete Next
|
|
[agent] 2026-09-30: handover from the PDM bug-hunt routine (ledger #312) While filing #382 (hosted PDM rollback/remove stuck once the patched package leaves This may already be covered by #379 (uv drift after |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled uv bug-hunt routine (label pm:uv).
Last run: 2026-09-30 on main
f6b7fb9(CLI 4.0.0; the released 4.0.0 predates the current uv backend). Linux runs use real uv against a local mock patch API. macOS and Windows runs use probe branches.Coverage matrix
H = hosted, V = vendored, A = agent. "pass/fail" is Linux unless an OS is named.
uv adduv add)[[distribution]])Backlog
[[distribution]]hosted locks (0.1.45 / 0.2.5 / 0.2.18 / 0.2.34): relock, rollback,--locked.[[tool.uv.index]]and{ index = … }pins, including transitive overrides.uv pip compile --generate-hashes) +--require-hashes, upgrade, rollback; requirements floor 0.0.5.uv addon Windows;resolution-markersforks (refusal vs VEX).uv sync --frozenwithdefault-groups/--no-dev, andpackage = falseprojects.uv add, and the suggested re-scan doesn't fix it #379 and Vendored uvrepaircan't rebuild a missing wheel onceuv synchas installed it, because it rebuilds from the patched installed copy and the hash never matches #381.Known non-bugs
[tool.uv.workspace]or[manifest] membersbeyond the root) are refused in both modes:redirect_uv_project_unsupported("hosted sources for uv workspaces require a package-scoped source mapping") andpypi_uv_workspace_unsupported. This is by design, though it's missing from docs/testing/uv-compatibility.md.redirect_uv_project_unsupported, exit 0).repairremoves the package'ssocket-patch.vendor.jsonsidecar ("nothing kept" contract).vendor --revertstill works from state.json..socket/vendor/redirect-state.json; without it the result isManifest not found.vendor_fetch_failedagainst files.pythonhosted.org in the sandbox is a rustls vs proxy-CA artifact.redirect_pypi_stale_installtext mentions Poetry on uv projects (cosmetic).All reactions