Skip to content

Fix Hatch-derived pylock.toml lock-only rewrite (#479) - #1336

Merged
Mikola Lysenko (mikolalysenko) merged 4 commits into
mainfrom
agent/v5-hatch-pylock
Oct 10, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 4 commits into
mainfrom
agent/v5-hatch-pylock

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

Fixes #479

Summary

Hatch 1.17+ locked environments (lock-envs = true, [tool.hatch.envs.<env>] locked = true) write a PEP 751 pylock.toml / pylock.<env>.toml that Hatch derives from pyproject and regenerates whenever the dependency hash changes. Both modes rewrote only that lock and reported success with no warnings:

  • An existing Hatch env stayed unpatched, because pyproject was unchanged so Hatch didn't sync.
  • A fresh env made Hatch regenerate the lock from pyproject, which threw the Socket URL away.
  • Vendored skipped the documented "Vendored Hatch requires the pip installer" refusal.

Root cause

rewrite_hatch (patch/redirect/mod.rs) returned early whenever any is_python_lock_name file existed, and detect_pypi_flavor (vendor/pypi.rs, step 2) sent a pylock containing the package to the python-lock lane. Neither could tell a Hatch-derived lock from an independent one (uv export, pip lock).

Fix

  • utils::hatch::is_hatch_lock(files, path) returns true for a pylock*.toml in a Hatch project (is_hatch) whose pyproject [tool.hatch] or hatch.toml locks environments (lock-envs = true, an env's locked = true or lock-filename).
  • Hosted: rewrite_hatch no longer stops at a Hatch-derived pylock. It wires the Hatch declarations (pyproject / hatch.toml) and warns redirect_hatch_lock_regenerated (run hatch dep lock). The python-lock lane still rewrites the lock as well, so lockfile discovery sees one consistent wiring; when only pyproject was wired, the attribution gate (redirect_unattributable) withheld the dep. Hatch then regenerates the lock from the wired pyproject.
  • Vendored: detect_pypi_flavor leaves Hatch-derived pylocks out of the standalone-lock lane, so the project routes to the Hatch flavor and its guards. That includes the uv-installer refusal locked environments hit.
  • A pylock in a Hatch project without locked environments is still wired as a standalone lock (unchanged).
  • docs/testing/hatch.md and the CLI_CONTRACT.md warning table are updated.

Tests (red → green)

Case Test Before After
hosted rewrite: locked = true + uv installer, lock-envs = true, named env pylock.test.toml: pyproject wired + warning; control without locked envs keeps the lock-only lane patch::redirect::hatch_tests::hatch_locked_env_pylock_also_wires_pyproject FAILED ok
vendored routing: locked envs → PypiFlavor::Hatch; without → PythonLocks vendor::pypi::tests::hatch_locked_env_pylock_routes_to_hatch FAILED ok
CLI: hosted scan wires pyproject + lock, warns; vendored refuses (pip installer) and writes nothing mode_migration_pypi::hatch_locked_env_pylock_wires_pyproject FAILED ok

Red was verified by short-circuiting is_hatch_lock to false. Hatch isn't installed locally, so the real-Hatch matrix from the issue wasn't re-run here.

Commands run

  • cargo test -p socket-patch-core --lib: 6111 passed
  • cargo test -p socket-patch-cli --test mode_migration_pypi --test in_process_get_hosted_ecosystems --test e2e_vendor_pypi_build --test in_process_rollback_hosted: 47 + 10 + 44 + 35 passed
  • cargo clippy --workspace --all-features -- -D warnings: clean. cargo fmt --all -- --check: my files clean (the upstream/mod.rs diff is pre-existing on main)

🤖 Generated with Claude Code

Empty commit to open the draft PR.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Hatch 1.17+ locked environments write a pylock.toml that Hatch derives
from pyproject and regenerates whenever the dependency hash changes.
Both modes treated it as a standalone lock and rewrote only it, with
`success` and no warning. Existing Hatch envs stayed unpatched, the
next fresh env regenerated the lock from pyproject and dropped the
patch, and vendored mode skipped the documented "Vendored Hatch
requires the pip installer" refusal.

A pylock in a Hatch project whose environments are locked
(`lock-envs`, `locked`, `lock-filename`) is now Hatch's own: hosted
mode wires the Hatch declarations in pyproject / hatch.toml as well
as the lock, and warns `redirect_hatch_lock_regenerated` to run
`hatch dep lock`. Vendored mode routes the project to the Hatch lane,
so its guards (including the pip-installer refusal) apply. A pylock in
a Hatch project without locked environments is still wired as a
standalone lock.

Fixes #479

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@mikolalysenko
Mikola Lysenko (mikolalysenko) marked this pull request as ready for review October 9, 2026 18:50
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is ON. A cloud agent has been kicked off to fix the reported issue.

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 7e64816. Configure here.

Comment thread crates/socket-patch-core/src/utils/hatch.rs
Hatch merges hatch.toml over pyproject's [tool.hatch] by top-level
key: a hatch.toml `envs` table replaces every pyproject environment,
and a hatch.toml `lock-envs` overrides pyproject's. The locked-env
check ORed both documents, so a shadowed `locked = true` marked an
independent pylock as Hatch-derived. It now reads each key from
hatch.toml first, then from [tool.hatch].

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Resolve conflicts with #1334/#1335 in mode_migration_pypi.rs (keep the
hatch pylock test alongside the PEP 440 lock-only and uv workspace member
tests) and with main's CLI_CONTRACT.md edits (keep both the
redirect_hatch_lock_regenerated and redirect_requirements_direct_reference
rows).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Merged via the queue into main with commit f631631 Oct 10, 2026
53 checks passed
@mikolalysenko
Mikola Lysenko (mikolalysenko) deleted the agent/v5-hatch-pylock branch October 10, 2026 00:43
Mikola Lysenko (mikolalysenko) added a commit that referenced this pull request Oct 10, 2026
Pick up #1336 (Hatch-derived pylock.toml lock-only rewrite); merges cleanly.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko) added a commit that referenced this pull request Oct 10, 2026
Picks up #1336 (Hatch pylock.toml lock-only rewrite); no conflicts.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants