Bug hunt ledger: uv #310
Replies: 10 comments
|
[agent] 2026-09-30: handover from the Poetry bug-hunt routine (ledger #311) While checking Poetry mode switches I hit the same defect on a uv project. I filed it as #328 with the Poetry evidence. Here's the uv side so you can add a uv comment to that issue, or file a uv-specific one if the root cause differs. hosted → vendored on a uv project is refused as a "user-authored" source. main printf '[project]\nname = "uvp"\nversion = "0.1.0"\nrequires-python = ">=3.9"\ndependencies = ["six==1.16.0"]\n' > pyproject.toml
uv lock && uv sync
socket-patch scan --mode hosted --json --yes # redirected: 1
uv sync
socket-patch scan --mode vendored --json --yes
# -> failed pypi_uv_source_already_exists "[tool.uv.sources] already declares a source for six; refusing to overwrite a user-authored source"
# uv.lock still: source = { url = "http://127.0.0.1:18080/patch/pypi/six/1.16.0/<token>/<uuid>/six-1.16.0-py2.py3-none-any.whl" }Root cause (shared): Not yet checked for uv: vendored → hosted, and lock-only hosted → vendored (on Poetry that fails Also unconfirmed for uv: on Poetry, vendored |
|
[agent] 2026-09-30: uv bug-hunt run This is the first run. The ledger started empty and there were no Tested: main Setup: the sandbox blocks the Socket patch hosts, so a local mock of the authenticated patch API ( Cells (Linux unless noted)
Issues
False positives ruled out
Probe runs
I couldn't delete either probe branch: the git proxy silently ignores ref deletes ("Everything up-to-date"), the same as for the siblings. A maintainer needs to delete Next
|
|
[agent] 2026-09-30: handover from the PDM bug-hunt routine (ledger #312) While filing #382 (hosted PDM rollback/remove stuck once the patched package leaves This may already be covered by #379 (uv drift after |
|
[agent] 2026-10-01: uv bug-hunt run Tested: main Harness changes for v5: hosted mode now keeps no ledger. Rollback/remove re-derive the upstream entry from PyPI's JSON API, and they need Re-triage
Cells (Linux 0.12.21 unless noted)
Issues
False positives ruled out
Probe runs
Branch deletes are still silently ignored by the git proxy. A maintainer needs to delete Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where uv puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × uv version cells for |
|
[agent] 2026-10-01: uv bug-hunt run Tested: main Re-triageMain hasn't moved since #407, #408 and #411 were filed, so they're still open and unchanged. No re-test was needed. Cells (global mode)
Issues
False positives ruled out
Probe runs
Branch deletes are still silently ignored by the git proxy. A maintainer needs to delete Next
|
|
[agent] 2026-10-01: uv bug-hunt run Tested: main Re-triage
Cells (Linux 0.8.17 unless noted)
Issues
False positives ruled out
Probe runs
The git proxy still silently ignores branch deletes. A maintainer needs to delete Operator note: a failed Next
|
|
[agent] 2026-10-01: uv bug-hunt run Tested: main The harness is new this run. It uses a Python mock patch API: the wheel is deterministic (fixed zip dates), Re-triage
Cells (Linux 0.8.17 unless noted)
Issues
False positives ruled out
Probe runs
Next
|
|
[agent] 2026-10-02: uv bug-hunt run Tested: main Re-triageMain hasn't moved, so nothing needed re-running. Fixes are in flight: #512 (#407, #408), #481 (#474), and #449 is claimed (agent/fix-python-global-tool-roots). Cells (Linux, uv 0.8.17 unless noted)
Issues
False positives ruled out
Probe runsNone this run (everything new was OS-independent text edits or Linux env-var probing). No branches pushed. Next
|
|
[agent] 2026-10-02: uv bug-hunt run Tested: main Re-triageMain hasn't moved, so I re-ran nothing. Open fix PRs: #540 (#525 and the env discovery issues), #512 (#407, #408), #481 (#474). Cells (Linux)
Issues
False positives ruled out
Probe runsNone this run. #525 already has a fix PR (#540), and the new finding is a CLI text match that doesn't depend on the OS. Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled uv bug-hunt routine (label pm:uv).
Last run: 2026-10-02 (run 7) on main
61cfb9b(unchanged; this run added path/git siblings, legacy dev-dependencies, constraint-dependencies, vendored sources spellings and uv 0.12.22). Run 6 was also on61cfb9b(the dotted-name, sources-spelling, lock-only and UV_PROJECT_ENVIRONMENT cells). Run 5 was also on main61cfb9b(v5; CLI reports 4.0.0, and the released 4.0.0 predates both the v4 uv rewriter and the v5 upstream restore). Earlier cells are from2463257/6e7ef74. Linux runs use real uv against a local mock patch API (withintegrity.sha512in SRI form, a deterministic wheel, the/blob/route and--patch-server-url), plusSOCKET_PYPI_JSON_API→ a local pypi.org pass-through that must not rewrite file URLs. uv 0.1.x needsSSL_CERT_FILE; uv 0.0.5 needsPUFFIN_INDEX_URL→ a local/simple/proxy. macOS and Windows runs use probe branches.Coverage matrix
H = hosted, V = vendored, A = agent. "pass/fail" is Linux unless an OS is named. Results are from v5 main (
2463257/6e7ef74) unless marked (v4).[[distribution]])--frozen/--locked)uv add(Linux, macOS, Windows); fail #411 user override (Linux, Windows); fail #477uv synckeeps patched wheel after rollbackuv add(3 OS); fail #411 (3 OS); fail #473 (3 OS); fail #477 stale after rollback (uv.lock anduv pip sync)package = false,environments, self-ref extras, hashed-requirements variants, uv.lock + exported requirements.txt, two pylocks)uv remove/uv lock --upgrade-package; fail #407; fail #408 (re-confirmed on61cfb9b); fail #411; fail #473 include-group (3 OS); fail #477 stale after rollback/revertpylock.dev.toml, include-group); fail #474 script revert afteruv add --script(3 OS)uv syncafter rollback reinstalls upstream (uv-side fix in 0.8.18)--locked/--frozen/plain, inline sources, BOM, odd-case name, idempotent, VEX, pylock, script lock, CRLF, hashed requirements, markers, ranges, groups, extras, transitive override)uv add(3 OS), script lock, hashed requirements, CRLF, multi-file; fail #411 (3 OS); fail #407; fail #408; fail #473 (3 OS);uv pip syncafter requirements unwind fail #477 (3 OS)backports.tarfilein 3 spellings; dotted / root / inline sources spellings; lock-only checkout with space + unicode path,--frozencold cache, idempotent re-scan[tool.uv.sources.<name>]sub-table leaves an empty header (rollback, remove; also 0.5.31)UV_PROJECT_ENVIRONMENTignored (abs + relative)dev-dependencies(0.4.30 / 0.5.31 / 0.8.17),constraint-dependencies(0.8.17 / 0.9.5 / 0.12.22), inline[tool] uv = {…}/ roottool = {…}/sources.x.path--frozen --offline),[tool.uv.sources]before[project], CRLF; fail #544 dotted[tool.uv] sources.x/[tool] uv.sources.x: revert / remove half-revert (0.5.31, 0.8.17, 0.12.22)not a standard table)Global (
-g) modeUV_TOOL_DIR/XDG_DATA_HOMEUV_PYTHON_INSTALL_DIRnot_found)%APPDATA%\uv\tools)SOCKET_GLOBAL=1,--global-prefix/SOCKET_GLOBAL_PREFIXwith space and unicode paths, and project isolation (-gskips.venv) all pass on Linux.Backlog
sources.<pkg>line stays, souv sync --lockedfails (vendor --revert exits 0) #544 together with uv rollback, remove and vendor --revert leave an empty[tool.uv.sources]header behind when the project's sources are written as[tool.uv.sources.<name>]sub-tables #524 once a fix lands. Also check vendored root-leveltool.uv.sources.x = …, and vendoredrepairon dotted spellings.uv pip compilepylock.toml because its packages carry noindexkey #407, Hosted rollback rewrites uv pylock.tomlupload-timewith milliseconds, so the restored file never matches what uv writes #408 and Vendored uv script lock can't be reverted afteruv add --scriptadds an unrelated dependency (vendor_lock_entry_drifted, still exit 0) #474. Run macOS / Windows probes for uv projects whose env is set by UV_PROJECT_ENVIRONMENT are never probed: agent scan patches the PATH interpreter and uv tool envs instead, the real env stays vulnerable, and vex attests not_affected #525 (plus a stray./.venvnext toUV_PROJECT_ENVIRONMENT).-gapply / rollback / vex against a live free pypi patch (the e2e UUID725a5343-…returnsnot_found), plus the unwritable-prefix cell. Checklist in the 20261001T040000Z entry.[tool.uv]dotted sources.-g, and re-check Global scan (-g) misses uv tool environments on Windows (looks in %LOCALAPPDATA%\uv\tools, uv uses %APPDATA%\uv\tools) and on every OS when UV_TOOL_DIR, XDG_DATA_HOME or UV_PYTHON_INSTALL_DIR is set #449 on a Windows probe.pylock.<name>.tomlmixed index / no-index siblings (after Fix uv pylock rollback shape (#407, #408) #512). Windows CRLF checkout + vendoredrepairon uv.lock.uv pip compilepylock.toml because its packages carry noindexkey #407, Hosted rollback rewrites uv pylock.tomlupload-timewith milliseconds, so the restored file never matches what uv writes #408, Hosted uv rollback and remove delete a user-authoredoverride-dependencies = ["<pkg>==<ver>"]pin that hosted mode never added #411, Global scan (-g) misses uv tool environments on Windows (looks in %LOCALAPPDATA%\uv\tools, uv uses %APPDATA%\uv\tools) and on every OS when UV_TOOL_DIR, XDG_DATA_HOME or UV_PYTHON_INSTALL_DIR is set #449, Hosted uv rollback and remove refuse when the patched package reaches a dependency group through PEP 735include-group#473, Vendored uv script lock can't be reverted afteruv add --scriptadds an unrelated dependency (vendor_lock_entry_drifted, still exit 0) #474, After a hosted or vendored PDM rollback, pdm sync / pdm install keep the patched build installed, though rollback says the next install restores it #477 (uv part), uv rollback, remove and vendor --revert leave an empty[tool.uv.sources]header behind when the project's sources are written as[tool.uv.sources.<name>]sub-tables #524, uv projects whose env is set by UV_PROJECT_ENVIRONMENT are never probed: agent scan patches the PATH interpreter and uv tool envs instead, the real env stays vulnerable, and vex attests not_affected #525 and Vendored uv revert and remove half-revert a project whose sources use dotted keys under [tool.uv]: uv.lock is restored but thesources.<pkg>line stays, souv sync --lockedfails (vendor --revert exits 0) #544 once main moves.Known non-bugs
[tool.uv.workspace]or[manifest] membersbeyond the root) are refused in both modes (redirect_uv_project_unsupported/pypi_uv_workspace_unsupported). This is by design, though it's missing from docs/testing/uv-compatibility.md.redirect_uv_project_unsupported, exit 0). In v5,vendored_takeoveronly covers cargo/npm/golang. CLI_CONTRACT.md line ~123 says both directions "work in place on the locks the target mode accepts", so a maintainer may want to clarify that this is PyPI-wide (Poetry/PDM too).six>=1.10,<1.17) unless another lock entry shows uv's clause spelling. This is in theupstream/uv.rsmodule doc, not the user docs. It's justified: uv 0.2.37 keeps clause order and ≥0.5 sorts them.[[distribution]]locks,exclude-newer/no-binary/no-build, and non-PyPI registries (documented).--patch-server-urlfor a non-Socket origin reports "Manifest not found" (the origin isn't recognised as hosted). This is a harness artifact.vendor_fetch_failed/ "error sending request" for pypi.org / files.pythonhosted.org in the sandbox is a rustls vs proxy-CA artifact. Use a local forwarder viaSOCKET_PYPI_JSON_API.redirect_pypi_stale_installtext mentions Poetry on uv projects (cosmetic, v4 observation).scan -g --mode hosted(and--global-prefix/SOCKET_GLOBAL=1with hosted) exits 2 by design. A global scan with no mode is report-only.[[tool.uv.index]](for example a PyTorch index next to PyPI → "several registries"; only one sibling, on that index → "not PyPI"), even though the patched package came from PyPI. CLI_CONTRACT documents this ("other registry packages name … several, or one other than PyPI's simple index"). Hosted scan of a package that carries its own{ index = … }source is warn-onlyredirect_uv_project_unsupported("already declares a source"). Both are documented. The first is a candidate for a maintainer to narrow.repair→download_failedagainst the local mock is a harness gap (no diff archive served).Six===1.16.0restoressix==1.16.0, and a comment after a hash continuation is joined onto the last hash line. v5 upstream restore re-derives the pin, so the install is identical. uv never writes either spelling (cosmetic).--vexexits 1no_applicable_patcheswhile the venv is still stale (documented "installed evidence wins").uv remove --scriptof its only sibling refuses "no sibling registry package…" (documented; same as the project case).integrity.sha512→vendor_prebuilt_integrity_mismatch(the service sends SRIsha512-<b64>); a non-deterministic mock wheel → hash mismatch after a mock restart; a JSON forwarder that rewrites file URLs → rollback writes those URLs into the lock.redirect_uv_project_unsupported("marker-specific source mappings are required"), vendored ispypi_uv_lock_forked_package(exit 1). Documented in uv-compatibility.md:135.archive-v0entries containing patched bytes after hosted runs are the hosted wheels uv unpacked, not agent-mode pollution (agent apply breaks the hardlinks).[tool.uv] sources = { … }or[tool] uv = { … }) withpypi_uv_lock_parse_failed: … is not a standard table, before writing anything. Hosted mode grows the inline table in place. This is intentional (unit-tested in pypi_uv.rs) but undocumented.requirements.txtitself. A pin that lives only in a-c constraints.txtor-r base.txtinclude gets the warningredirect_requirements_entry_not_found(not silent). This is pip-generic, so don't file it under uv.All reactions