Skip to content

fix(hooks): run the uv hooks with --locked so lock drift is loud - #82

Merged
Cipher208 merged 1 commit into
masterfrom
fix/hooks-locked
Oct 6, 2026
Merged

Cipher208 merged 1 commit into
masterfrom
fix/hooks-locked

Conversation

@Cipher208

Copy link
Copy Markdown
Owner

A bare uv run re-resolves and rewrites uv.lock whenever pyproject.toml has drifted from it. Inside a pre-commit hook that is destructive in a way that takes a while to see: the rewrite lands on a file the hook is not allowed to change, pre-commit stashes the commit, the auto-fix conflicts with the stash, and it rolls everything back with Stashed changes conflicted with hook auto-fixes. The commit silently never happens, and uv.lock is left modified in the working tree. I lost two commits to this in this session before spotting it.

That is also how the five Dependabot PRs (#71-#75) could each leave the lock stale: locally, the first commit attempt would have quietly repaired it.

Why --locked and not --frozen

Measured on a deliberately drifted lock (alembic>=1.19.0 against a locked 1.20.0):

flag exit code rewrites lock fails loudly
--frozen 0 — proceeds silently no no
--locked 2 + clear error no yes

--frozen stops the destructive rewrite but happily runs against a stale lock, so the drift stays invisible. --locked stops the rewrite and fails, which is what makes it visible:

pytest gate (full suite).................................................Failed
- hook id: pytest-gate
- exit code: 2
error: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.

Checked both directions: with a consistent lock the commit goes through and git hash-object uv.lock is byte-identical before and after (no quiet rewrite); with drift the commit is blocked with exit code 1 and no stash-rollback.

This matches the uv lock --check gate added to CI in d12e941, so local and CI now agree.

The two --isolated --with ruff invocations in prepush-gate are deliberately left alone: --isolated ignores the project, so they never touch the lock.

A bare `uv run` re-resolves and rewrites uv.lock whenever pyproject.toml has
drifted from it. Inside a pre-commit hook that is destructive in a way that
takes a while to see: the rewrite lands on a file the hook is not allowed to
change, pre-commit stashes the commit, the auto-fix conflicts with the stash,
and it rolls everything back with "Stashed changes conflicted with hook
auto-fixes". The commit silently never happens, and uv.lock is left modified
in the working tree. That is how the five Dependabot PRs could each leave the
lock stale: locally the first commit attempt would have quietly repaired it.

--locked stops the rewrite and, unlike --frozen, actually fails: measured on
a drifted lock, `uv run --locked` exits 2 with "The lockfile at `uv.lock`
needs to be updated, but `--locked` was provided", where `--frozen` exits 0
and proceeds against the stale lock. Drift now blocks the commit instead of
being swallowed, matching the `uv lock --check` gate added to CI in d12e941.

The two `--isolated --with ruff` invocations are left alone: --isolated
ignores the project, so they never touch the lock.
@Cipher208
Cipher208 enabled auto-merge (squash) October 6, 2026 23:19
@github-actions github-actions Bot added the fix label Oct 6, 2026
@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Repository: Cipher208/a-memory/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 41652a71-6d62-47b7-8ab0-28134c4fa62a
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Cipher208
Cipher208 merged commit c0b8374 into master Oct 6, 2026
19 checks passed
@Cipher208
Cipher208 deleted the fix/hooks-locked branch October 6, 2026 23:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant