Vendored PyPI revert, remove, rollback and the hosted takeover still delete the vendored wheel while a uv export --format pylock.toml in a subdirectory installs from it (exit 0) #1213
Description
Activity
- addedbugSomething isn't workingSomething isn't workingbughuntFound by a scheduled package-manager bug-hunt agentFound by a scheduled package-manager bug-hunt agentpm:uvuvuv
on Oct 9, 2026 mikolalysenko commented
on Oct 9, 2026 CollaboratorAuthorMore actions[agent] Triage: priority:p1 (PyPI/uv). Confirmed on main
f3c6313:subdir_txt_names(crates/socket-patch-core/src/vendor/pypi.rs:2115) only collects*.txtbelow the root, while the root listing also acceptspython_lock::is_python_lock_name, so a subdirectorypylock.toml/pylock.<name>.tomlis never probed for residual references. No open PR addresses it. Related to #1184 (remove/rollback labelling of the residual keep) but a separate cause.
Generated by Claude Code
mikolalysenko commented
on Oct 9, 2026 CollaboratorAuthorMore actions[agent] Claiming this issue (single-issue cluster; root cause: the vendored PyPI residual-reference probe walks subdirectories for
*.txtonly, never for PEP 751pylock*.tomllocks). Branch: agent/fix-pypi-subdir-pylock-probe. Claim-ID: 2026-10-09T04:20:33Z-a22276
Generated by Claude Code
mikolalysenko commented
on Oct 9, 2026 CollaboratorAuthorMore actions- added 2 commits that reference this issue
on Oct 9, 2026 mikolalysenko commented
on Oct 9, 2026 CollaboratorAuthorMore actions[agent] uv bug-hunt run 35 (ledger #310): I checked PR #1223 (
b1f945f) with uv 0.12.24. It fixes the reported shapes:deploy/pylock.tomlanda/b/pylock.prod.tomlexports now keep the wheel onvendor --revert(exit 0) andremove(exit 1vendor_revert_kept, which is #1184's wording). Maine03a666still deletes it.The same probe still misses non-
.txtrequirements exports such asuv export -o requirements.lock(Rye's name), at the root or in a subdirectory, both on main and on #1223. I filed that separately as #1252, because the cause is the extension filter, not the subdirectory walk.
Generated by Claude Code
[agent] Found by the scheduled uv bug-hunt routine (ledger #310).
Summary
#996 (fixed by #997) made the vendored PyPI unwind keep
.socket/vendor/pypi/<uuid>/while a root file still installs from it. #1167 (fixed by #1168) extended that to requirements files in subdirectories, but only*.txt(subdir_txt_names). A PEP 751 lock exported into a subdirectory, which is the normal uv shape for a deploy or Docker context (uv export --format pylock.toml -o deploy/pylock.toml), is still not probed.vendor --revert,remove,rollbackand the vendored → hosted takeover all delete the wheel and exit 0. The exported pylock then can't install at all.The same file at the project root is kept correctly (
vendor_revert_residual_reference), so this is only the subdirectory gap #1168 left out. I raised it on #1167 before #1168 merged (#1167 (comment)). #1167 is now closed, so I'm filing it separately.Impact
The run reports success, and the next
uv pip install -r deploy/pylock.toml/uv pip sync deploy/pylock.toml(CI, Docker) fails withDistribution not found at: file:///…/.socket/vendor/pypi/<uuid>/six-1.16.0-py2.py3-none-any.whl. Nothing is installed unpatched, but a build that worked before the unwind now breaks, and the unwind gives no warning first.Repro (Linux, uv 0.12.24 or 0.8.24, main
b76d7ab)Patch data came from a local mock of the patch API (
six@1.16.0, which appends a marker tosix.py), the same mock as earlier uv issues.Expected vs actual
vendor_revert_residual_reference("… still resolves through it") while any project file still installs from the uuid dir, as it already does for a rootpylock.toml/pylock.<name>.tomland forrequirements/*.txt. CLI_CONTRACT.md's revert section says an unwind must not leave the project installing from a deleted artifact.Matrix (Linux, real
uv export+uv pip install -r; each cell run on a fresh fixture, all cells run twice)deploy/pylock.tomldeploy/pylock.prod.tomla/b/pylock.tomlpylock.prod.tomldeploy/pylock.toml,deploy/pylock.prod.toml,a/b/pylock.tomlpylock.prod.tomlreq/prod.txt(control, #1168)uv < 0.6.15 can't export pylock.toml, so the oldest cells don't apply. No probe branch: the walk has no OS-specific branch.
Suspect code
crates/socket-patch-core/src/vendor/pypi.rs:2151(subdir_txt_names): the subdirectory walk accepts onlyname.ends_with(".txt"). The root listing atpypi.rs:2030also acceptspython_lock::is_python_lock_name, so a subdirectorypylock.toml/pylock.<name>.toml(PEP 751'spylock.*.tomlnames) should be collected there too.