Skip to content

Honor direct sources shared across workspace dependencies - #20797

Merged
charliermarsh merged 11 commits into
charlie/metadata-free-conditional-source-authorityfrom
charlie/metadata-free-shared-direct-sources
Jul 30, 2026
Merged

charliermarsh merged 11 commits into
charlie/metadata-free-conditional-source-authorityfrom
charlie/metadata-free-shared-direct-sources

Conversation

@charliermarsh

@charliermarsh charliermarsh commented Jul 29, 2026 •

Copy link
Copy Markdown
Member

Summary

Metadata-free lock freshness validation can reject a valid direct-source dependency when another dependency declares the same package without a source. Direct sources may be introduced by production requirements, optional extras, dependency groups, legacy development dependencies, projectless workspace-root groups, PEP 723 scripts, or non-workspace local source trees.

Index these direct requirements alongside constraints before reconstructing lockfile edges, including lowered [tool.uv.sources] mappings, and accept an unqualified dependency only when an applicable declaration selects the exact locked source. Preserve the fast path for ordinary workspace members and cover workspace, optional/group, transitive local, projectless-root, and script sources with offline, uncached integration regressions.

@charliermarsh
charliermarsh force-pushed the charlie/metadata-free-shared-direct-sources branch from 88db3c7 to 5b79b8a Compare July 30, 2026 02:54
@charliermarsh
charliermarsh force-pushed the charlie/metadata-free-direct-url-constraint-fix branch from 8199039 to 49a7abe Compare July 30, 2026 21:14
@charliermarsh
charliermarsh force-pushed the charlie/metadata-free-shared-direct-sources branch from 61b59a5 to f2db47c Compare July 30, 2026 21:15
Base automatically changed from charlie/metadata-free-direct-url-constraint-fix to main July 30, 2026 22:01
@charliermarsh
charliermarsh force-pushed the charlie/metadata-free-shared-direct-sources branch from f2db47c to b6cdd44 Compare July 30, 2026 22:29
@charliermarsh
charliermarsh changed the base branch from main to charlie/metadata-free-conditional-source-authority July 30, 2026 22:29
@charliermarsh
charliermarsh merged commit b6cdd44 into charlie/metadata-free-conditional-source-authority Jul 30, 2026
@charliermarsh
charliermarsh deleted the charlie/metadata-free-shared-direct-sources branch July 30, 2026 22:49
@charliermarsh
charliermarsh force-pushed the charlie/metadata-free-shared-direct-sources branch from b6cdd44 to 17b4cba Compare July 30, 2026 22:49
@charliermarsh

Copy link
Copy Markdown
Member Author

(This was accidentally closed during some branch changes; it didn't merge into main.)

@charliermarsh
charliermarsh restored the charlie/metadata-free-shared-direct-sources branch July 30, 2026 22:50
@charliermarsh

Copy link
Copy Markdown
Member Author

GitHub marked this pull request merged into the next feature branch while I was reordering the stack. The unchanged OpenAI-targeted diff now continues in #20847, based directly on main.

charliermarsh added a commit that referenced this pull request Jul 31, 2026
## Summary

When uv checks whether a metadata-free lockfile is still up to date, it
reconstructs the dependencies that should appear in the lock.

Previously, it looked at each package in isolation. That breaks when two
packages share a dependency but only one specifies where it comes from.
For example, package A might depend on `shared-package` from a local
path, while package B simply depends on `shared-package`. The lock
correctly resolves both dependencies to the local package, but
validation treated package B's unqualified dependency as a registry
dependency and rejected the lock. Offline, this meant a valid lock could
be rejected even though nothing had changed.

This change builds one shared view of direct-source requirements before
validating the individual packages. The validator can then see that
package A selected the exact source recorded in the lock when it checks
package B. This also covers direct sources declared through extras,
dependency groups, scripts, transitive local projects, and static or
dynamic package metadata, while preserving the fast path for ordinary
registry-only workspaces.

Supersedes #20797, which GitHub marked merged while the stack was being
reordered.

This branch was previously deployed

1 inactive deployment
automations — 17b4cba7 Deployed Jul 30, 2026 by charliermarsh via review / security review #43890
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant