diff --git a/.gitignore b/.gitignore index d09ab5e..36e4cb1 100644 --- a/.gitignore +++ b/.gitignore @@ -1,170 +1 @@ -/pubgrub-3f0ba760951ab0deeac874b98bb18fc90103fcf7.tar.gz -/reqwest-middleware-21ceec9a5fd2e8d6f71c3ea2999078fecbd13cbe.tar.gz -/rs-async-zip-011b24604fa7bc223daaad7712c0694bac8f0a87.tar.gz -/uv-0.2.32.tar.gz -/uv-0.2.33.tar.gz -/pubgrub-2fac39371a47e7cb821e510aaa4de25405413d29.tar.gz -/uv-0.2.34.tar.gz -/uv-0.2.35.tar.gz -/uv-0.2.37-filtered.tar.zst -/uv-0.3.0-filtered.tar.zst -/pubgrub-aaef464c1b0d8eea4ff9ffaee4f3458c236d10da.tar.gz -/reqwest-middleware-5e3eaf254b5bd481c75d2710eed055f95b756913.tar.gz -/uv-0.3.2-filtered.tar.zst -/uv-0.3.3-filtered.tar.zst -/pubgrub-388685a8711092971930986644cfed152d1a1f6c.tar.gz -/uv-0.3.4-filtered.tar.zst -/tl-6e25b2ee2513d75385101a8ff9f591ef51f314ec.tar.gz -/uv-0.3.5-filtered.tar.zst -/uv-0.4.0-filtered.tar.zst -/uv-0.4.1-filtered.tar.zst -/uv-0.4.2-filtered.tar.zst -/uv-0.4.4-filtered.tar.zst -/uv-0.4.5-filtered.tar.zst -/uv-0.4.6-filtered.tar.zst -/uv-0.4.7-filtered.tar.zst -/uv-0.4.8-filtered.tar.zst -/uv-0.4.9-filtered.tar.zst -/uv-0.4.10-filtered.tar.zst -/uv-0.4.15.tar.gz -/uv-0.4.16.tar.gz -/uv-0.4.17.tar.gz -/uv-0.4.18.tar.gz -/uv-0.4.19.tar.gz -/uv-0.4.20.tar.gz -/uv-0.4.21.tar.gz -/uv-0.4.22.tar.gz -/uv-0.4.23.tar.gz -/pubgrub-19c77268c0ad5f69d7e12126e0cfacfbba466481.tar.gz -/uv-0.4.24.tar.gz -/uv-0.4.25.tar.gz -/pubgrub-7243f4faf8e54837aa8a401a18406e7173de4ad5.tar.gz -/reqwest-middleware-d95ec5a99fcc9a4339e1850d40378bbfe55ab121.tar.gz -/uv-0.4.26.tar.gz -/uv-0.4.27.tar.gz -/uv-0.4.28.tar.gz -/uv-0.4.29.tar.gz -/pubgrub-95e1390399cdddee986b658be19587eb1fdb2d79.tar.gz -/uv-0.4.30.tar.gz -/uv-0.5.0.tar.gz -/uv-0.5.1.tar.gz -/uv-0.5.2.tar.gz -/rs-async-zip-c909fda63fcafe4af496a07bfda28a5aae97e58d.tar.gz -/uv-0.5.3.tar.gz -/pubgrub-57afc831bf2551f164617a10383cf288bf5d190d.tar.gz -/uv-0.5.4.tar.gz -/uv-0.5.5.tar.gz -/pubgrub-9cd9049a64c7352de2ff3b525b9ae36421b0cc18.tar.gz -/uv-0.5.6.tar.gz -/pubgrub-57832d0588fbb7aab824813481104761dc1c7740.tar.gz -/uv-0.5.7.tar.gz -/uv-0.5.8.tar.gz -/uv-0.5.9.tar.gz -/uv-0.5.10.tar.gz -/pubgrub-05e8d12cea8d72c6d2d017900e478d0abd28fef4.tar.gz -/uv-0.5.11.tar.gz -/uv-0.5.12.tar.gz -/pubgrub-648aa343486e5529953153781fc86025c73c4a61.tar.gz -/uv-0.5.13.tar.gz -/uv-0.5.14.tar.gz -/uv-0.5.15.tar.gz -/uv-0.5.16.tar.gz -/uv-0.5.17.tar.gz -/uv-0.5.18.tar.gz -/uv-0.5.19.tar.gz -/uv-0.5.20.tar.gz -/uv-0.5.21.tar.gz -/uv-0.5.22.tar.gz -/uv-0.5.23.tar.gz -/uv-0.5.24.tar.gz -/uv-0.5.25.tar.gz -/uv-0.5.26.tar.gz -/uv-0.5.27.tar.gz -/pubgrub-b70cf707aa43f21b32f3a61b8a0889b15032d5c4.tar.gz -/tokio-tar-ba2b140f27d081c463335f0d68b5f8df8e6c845e.tar.gz -/uv-0.5.28.tar.gz -/tokio-tar-efeaea927c7a40ee66121de2e1bebfd5d7a4a602.tar.gz -/uv-0.5.29.tar.gz -/uv-0.5.30.tar.gz -/uv-0.5.31.tar.gz -/uv-0.6.0.tar.gz -/uv-0.6.1.tar.gz -/uv-0.6.2.tar.gz -/uv-0.6.3.tar.gz -/uv-0.6.4.tar.gz -/uv-0.6.5.tar.gz -/uv-0.6.6.tar.gz -/uv-0.6.7.tar.gz -/uv-0.6.8.tar.gz -/uv-0.6.9.tar.gz -/uv-0.6.10.tar.gz -/uv-0.6.11.tar.gz -/uv-0.6.12.tar.gz -/uv-0.6.13.tar.gz -/uv-0.6.14.tar.gz -/uv-0.6.16.tar.gz -/uv-0.6.17.tar.gz -/pubgrub-a3b4db3abb1829ce889fb89fa6d157fef529ef7e.tar.gz -/uv-0.7.0.tar.gz -/uv-0.7.1.tar.gz -/uv-0.7.2.tar.gz -/uv-0.7.3.tar.gz -/uv-0.7.4.tar.gz -/pubgrub-73d6ecf5a4e4eb1c754b8c3255c4d31bdc266fdb.tar.gz -/uv-0.7.5.tar.gz -/uv-0.7.6.tar.gz -/uv-0.7.8.tar.gz -/pubgrub-06ec5a5f59ffaeb6cf5079c6cb184467da06c9db.tar.gz -/uv-0.7.9.tar.gz -/uv-0.7.10.tar.gz -/uv-0.7.11.tar.gz -/uv-0.7.12.tar.gz -/uv-0.7.13.tar.gz -/uv-0.7.14.tar.gz -/reqwest-middleware-ad8b9d332d1773fde8b4cd008486de5973e0a3f8.tar.gz -/uv-0.7.15.tar.gz -/uv-0.7.16.tar.gz -/uv-0.7.17.tar.gz -/uv-0.7.18.tar.gz -/uv-0.7.19.tar.gz -/uv-0.7.20.tar.gz -/uv-0.7.21.tar.gz -/uv-0.7.22.tar.gz -/uv-0.8.0.tar.gz -/uv-0.8.1.tar.gz -/uv-0.8.2.tar.gz -/uv-0.8.3.tar.gz -/uv-0.8.4.tar.gz -/uv-0.8.5.tar.gz -/uv-0.8.6.tar.gz -/rs-async-zip-285e48742b74ab109887d62e1ae79e7c15fd4878.tar.gz -/uv-0.8.7.tar.gz -/uv-0.8.8.tar.gz -/uv-0.8.9.tar.gz -/uv-0.8.10.tar.gz -/uv-0.8.11.tar.gz -/uv-0.8.12.tar.gz -/tokio-tar-f1488188f1d1b54a73eb0c42a8b8f4b9ee87d688.tar.gz -/uv-0.8.13.tar.gz -/uv-0.8.14.tar.gz -/uv-0.8.15.tar.gz -/reqwest-middleware-7650ed76215a962a96d94a79be71c27bffde7ab2.tar.gz -/uv-0.8.16.tar.gz -/uv-0.8.17.tar.gz -/uv-0.8.18.tar.gz -/uv-0.8.19.tar.gz -/uv-0.8.20.tar.gz -/pubgrub-d8efd77673c9a90792da9da31b6c0da7ea8a324b.tar.gz -/uv-0.8.21.tar.gz -/uv-0.8.22.tar.gz -/uv-0.8.23.tar.gz -/uv-0.8.24.tar.gz -/uv-0.9.0.tar.gz -/uv-0.9.1.tar.gz -/uv-0.9.2.tar.gz -/uv-0.9.3.tar.gz -/uv-0.9.4.tar.gz -/uv-0.9.5.tar.gz -/uv-0.9.6.tar.gz -/rs-async-zip-f6a41d32866003c868d03ed791a89c794f61b703.tar.gz -/uv-0.9.7.tar.gz +/uv-*.tar.gz diff --git a/0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch b/0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch index d60ea47..1552d94 100644 --- a/0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch +++ b/0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch @@ -1,4 +1,4 @@ -From 2a9baed6b1246c566e1bed531b17363277e99c0f Mon Sep 17 00:00:00 2001 +From 831cf2937a4b8b781d56d5fa18916d2bc42b244d Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Sun, 23 Jun 2024 16:29:05 -0400 Subject: [PATCH] Downstream patch: always find the system-wide uv executable @@ -13,7 +13,7 @@ https://github.com/astral-sh/uv/issues/4451 1 file changed, 8 insertions(+) diff --git a/python/uv/_find_uv.py b/python/uv/_find_uv.py -index 736288a4c..306451db2 100644 +index ebe6b8d5a..e25a2e28c 100644 --- a/python/uv/_find_uv.py +++ b/python/uv/_find_uv.py @@ -35,6 +35,14 @@ def find_uv_bin() -> str: @@ -32,5 +32,5 @@ index 736288a4c..306451db2 100644 for target in targets: if not target: -- -2.50.1 +2.53.0 diff --git a/20174.patch b/20174.patch new file mode 100644 index 0000000..2ae827b --- /dev/null +++ b/20174.patch @@ -0,0 +1,170 @@ +From c77c2abf16c13b3ef26fae52b6bec97a7abad65b Mon Sep 17 00:00:00 2001 +From: "Benjamin A. Beasley" +Date: Tue, 7 Jul 2026 06:57:19 +0100 +Subject: [PATCH 1/4] Add BSD-3-Clause LICENSE file to ecosystem/jupyterlab + +https://github.com/jupyterlab/jupyterlab/raw/refs/tags/v4.6.1/LICENSE +--- + test/ecosystem/jupyterlab/LICENSE | 27 +++++++++++++++++++++++++++ + 1 file changed, 27 insertions(+) + create mode 100644 test/ecosystem/jupyterlab/LICENSE + +diff --git a/test/ecosystem/jupyterlab/LICENSE b/test/ecosystem/jupyterlab/LICENSE +new file mode 100644 +index 0000000000000..c73604f78a1f6 +--- /dev/null ++++ b/test/ecosystem/jupyterlab/LICENSE +@@ -0,0 +1,27 @@ ++Copyright (c) 2015-2025 Project Jupyter Contributors ++All rights reserved. ++ ++Redistribution and use in source and binary forms, with or without ++modification, are permitted provided that the following conditions are met: ++ ++1. Redistributions of source code must retain the above copyright notice, this ++ list of conditions and the following disclaimer. ++ ++2. Redistributions in binary form must reproduce the above copyright notice, ++ this list of conditions and the following disclaimer in the documentation ++ and/or other materials provided with the distribution. ++ ++3. Neither the name of the copyright holder nor the names of its ++ contributors may be used to endorse or promote products derived from ++ this software without specific prior written permission. ++ ++THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" ++AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE ++IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE ++DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE ++FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL ++DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER ++CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, ++OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE ++OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +From 0561c227905e972b0d415b0170053ce6ec278184 Mon Sep 17 00:00:00 2001 +From: "Benjamin A. Beasley" +Date: Tue, 7 Jul 2026 06:58:21 +0100 +Subject: [PATCH 2/4] Add BSD-3-Clause LICENSE file to ecosystem/pandas + +https://github.com/pandas-dev/pandas/raw/refs/tags/v3.0.4/LICENSE +--- + test/ecosystem/pandas/LICENSE | 31 +++++++++++++++++++++++++++++++ + 1 file changed, 31 insertions(+) + create mode 100644 test/ecosystem/pandas/LICENSE + +diff --git a/test/ecosystem/pandas/LICENSE b/test/ecosystem/pandas/LICENSE +new file mode 100644 +index 0000000000000..bd1cc2a30c626 +--- /dev/null ++++ b/test/ecosystem/pandas/LICENSE +@@ -0,0 +1,31 @@ ++BSD 3-Clause License ++ ++Copyright (c) 2008-2011, AQR Capital Management, LLC, Lambda Foundry, Inc. and PyData Development Team ++All rights reserved. ++ ++Copyright (c) 2011-2026, Open source contributors. ++ ++Redistribution and use in source and binary forms, with or without ++modification, are permitted provided that the following conditions are met: ++ ++* Redistributions of source code must retain the above copyright notice, this ++ list of conditions and the following disclaimer. ++ ++* Redistributions in binary form must reproduce the above copyright notice, ++ this list of conditions and the following disclaimer in the documentation ++ and/or other materials provided with the distribution. ++ ++* Neither the name of the copyright holder nor the names of its ++ contributors may be used to endorse or promote products derived from ++ this software without specific prior written permission. ++ ++THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" ++AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE ++IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE ++DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE ++FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL ++DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER ++CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, ++OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE ++OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +From d21662e1800682b4058dac8bb39079620eb21400 Mon Sep 17 00:00:00 2001 +From: "Benjamin A. Beasley" +Date: Tue, 7 Jul 2026 06:59:25 +0100 +Subject: [PATCH 3/4] Add MIT LICENSE file to ecosystem/poetry + +https://github.com/python-poetry/poetry/raw/refs/tags/2.4.1/LICENSE +--- + test/ecosystem/poetry/LICENSE | 20 ++++++++++++++++++++ + 1 file changed, 20 insertions(+) + create mode 100644 test/ecosystem/poetry/LICENSE + +diff --git a/test/ecosystem/poetry/LICENSE b/test/ecosystem/poetry/LICENSE +new file mode 100644 +index 0000000000000..81a8e1e473986 +--- /dev/null ++++ b/test/ecosystem/poetry/LICENSE +@@ -0,0 +1,20 @@ ++Copyright (c) 2018-present Sébastien Eustace ++ ++Permission is hereby granted, free of charge, to any person obtaining ++a copy of this software and associated documentation files (the ++"Software"), to deal in the Software without restriction, including ++without limitation the rights to use, copy, modify, merge, publish, ++distribute, sublicense, and/or sell copies of the Software, and to ++permit persons to whom the Software is furnished to do so, subject to ++the following conditions: ++ ++The above copyright notice and this permission notice shall be ++included in all copies or substantial portions of the Software. ++ ++THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, ++EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF ++MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND ++NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE ++LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION ++OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION ++WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. + +From 708d1e5dfaaaee539308d60dbbfc0faa186885fd Mon Sep 17 00:00:00 2001 +From: "Benjamin A. Beasley" +Date: Tue, 7 Jul 2026 07:06:54 +0100 +Subject: [PATCH 4/4] Add MIT LICENSE file to ecosystem/semantic-kernel + +https://github.com/microsoft/semantic-kernel/raw/refs/tags/python-1.43.1/python/LICENSE +--- + test/ecosystem/semantic-kernel/LICENSE | 21 +++++++++++++++++++++ + 1 file changed, 21 insertions(+) + create mode 100644 test/ecosystem/semantic-kernel/LICENSE + +diff --git a/test/ecosystem/semantic-kernel/LICENSE b/test/ecosystem/semantic-kernel/LICENSE +new file mode 100644 +index 0000000000000..9e841e7a26e4e +--- /dev/null ++++ b/test/ecosystem/semantic-kernel/LICENSE +@@ -0,0 +1,21 @@ ++ MIT License ++ ++ Copyright (c) Microsoft Corporation. ++ ++ Permission is hereby granted, free of charge, to any person obtaining a copy ++ of this software and associated documentation files (the "Software"), to deal ++ in the Software without restriction, including without limitation the rights ++ to use, copy, modify, merge, publish, distribute, sublicense, and/or sell ++ copies of the Software, and to permit persons to whom the Software is ++ furnished to do so, subject to the following conditions: ++ ++ The above copyright notice and this permission notice shall be included in all ++ copies or substantial portions of the Software. ++ ++ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR ++ IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, ++ FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE ++ AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER ++ LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, ++ OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE ++ SOFTWARE diff --git a/sources b/sources index f7ed181..ce4d7d8 100644 --- a/sources +++ b/sources @@ -1,5 +1 @@ -SHA512 (uv-0.9.7.tar.gz) = 4a9c1beda1c53a4658c657c0e20f6bd3865e034ae87ce7a9e02f0b0125785f46e316f8e95aa3ce24b3c71a6e6d8011dea55bbe9a61e48ad11c684b09804afa9d -SHA512 (rs-async-zip-f6a41d32866003c868d03ed791a89c794f61b703.tar.gz) = 8eb19bc6780aff9dd0084df81fe3191b4cd7cd051cbe085b24bb237229af6aa94db1fc88bdc386866d192b0c15e148e3bc014b2f5d091833852be09848fcdda3 -SHA512 (pubgrub-d8efd77673c9a90792da9da31b6c0da7ea8a324b.tar.gz) = 3a2a146fd9d9b458dced6563a1f5674e81e8ba36de11be5c189b0c76b6ede6f32957f48fb0978b97b0892768822c6c4c32c6870141e8fc1ea5d8b8f7d8b5b464 -SHA512 (reqwest-middleware-7650ed76215a962a96d94a79be71c27bffde7ab2.tar.gz) = 904fd652b0f3ecc90eee571d5488aba977dee643a1d6267e2fda264fa4c7b4bfcfacd4d5a23287dfb710ecc82d667479fcd0c48166259c2368df0e8b0c9d6707 -SHA512 (tl-6e25b2ee2513d75385101a8ff9f591ef51f314ec.tar.gz) = 4abbc4240ed129c92da8d616e27a6df0f24cdc85a0803acfdae588ca91f9e5b8d482e3ac88b2e657ff68917b1b43cef1e7ef3c887f624659b231fa5a13fcae68 +SHA512 (uv-0.12.3.tar.gz) = a4933b9b9b852dee2485800ad82ee3be111a4a5a437ab32d5064cfd4004e124ba733294a546a097379c74cf1fc234d1da0488aec7725037c7b967ec1aa862a71 diff --git a/uv-0.12.1-revert-blake2-beta.patch b/uv-0.12.1-revert-blake2-beta.patch new file mode 100644 index 0000000..805ef98 --- /dev/null +++ b/uv-0.12.1-revert-blake2-beta.patch @@ -0,0 +1,11 @@ +diff -Naur uv-0.12.1-original/crates/uv-extract/src/hash.rs uv-0.12.1/crates/uv-extract/src/hash.rs +--- uv-0.12.1-original/crates/uv-extract/src/hash.rs 2026-07-31 20:05:57.000000000 +0100 ++++ uv-0.12.1/crates/uv-extract/src/hash.rs 2026-08-02 11:53:13.406289238 +0100 +@@ -1,4 +1,6 @@ +-use sha2::{Digest, digest::consts::U32}; ++// BLAKE2 still uses the `digest` 0.10 trait, while MD5 and SHA-2 use 0.11. ++use blake2::digest::{Digest as _, consts::U32}; ++use sha2::Digest; + use std::pin::Pin; + use std::task::{Context, Poll}; + use tokio::io::{AsyncReadExt, ReadBuf}; diff --git a/uv.rpmlintrc b/uv.rpmlintrc index a24db03..1c25d20 100644 --- a/uv.rpmlintrc +++ b/uv.rpmlintrc @@ -1,5 +1,6 @@ # Not real spelling errors -addFilter(r"spelling-error \('([Dd]eduplication|pipx|macOS|virtualenv)',") +addFilter(r"spelling-error \('([Ll]ockfile|[Ww]orkspace)s?',") +addFilter(r"spelling-error \('([Dd]eduplication|pipx|macOS|(py|virtual)env)',") # TODO: We would like to add man pages. addFilter(r" no-manual-page-for-binary uv$") # Since it is just equivalent to “uv tool run,” uvx is unlikely to get its own diff --git a/uv.spec b/uv.spec index 584006c..3583aa3 100644 --- a/uv.spec +++ b/uv.spec @@ -1,17 +1,18 @@ %bcond check 1 -# Should we run integration tests, many of which require specific Python -# interpreter versions (major.minor, not major.minor.patch)? This adds a few -# dozen tests, but adds BuildRequires on more Pythons, and could reduce our -# confidence that everything works correctly in an environment that only has -# the main system Python. -# -# EPEL10 does not have alternative versions of Python, so we cannot run most of -# the integration tests there, and manually selecting those we can run would be -# far too tedious. -%bcond it %{undefined el10} +# Should we run tests that require specific Python interpreter versions +# (major.minor, not major.minor.patch)? This adds a few dozen tests, but adds +# BuildRequires on more Python interpreters (which aren’t available in EPEL). +%bcond other_python_versions %{undefined epel} Name: uv -Version: 0.9.7 +Version: 0.12.3 +# The uv package has a permanent exception to the Updates Policy in Fedora, so +# it can be updated in stable releases across SemVer boundaries (subject to +# good judgement and actual compatibility of any reverse dependencies). See +# https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/#_other_packages, +# https://pagure.io/fesco/issue/3262. It also has a corresponding exception in +# EPEL, but only in leading branches and only until version 1.0; see +# https://pagure.io/epel/issue/317. Release: %autorelease Summary: An extremely fast Python package installer and resolver, written in Rust @@ -33,17 +34,18 @@ Summary: An extremely fast Python package installer and resolver, written # - crates/uv-python/packaging/ is vendored and forked from # python3dist(packaging) # -# (Apache-2.0 OR MIT) AND BSD-3-CLause: +# (Apache-2.0 OR MIT) AND BSD-3-Clause: # - The function wheel_metadata_from_remote_zip in # crates/uv-client/src/remote_metadata.rs is vendored and forked from the # function lazy_read_wheel_metadata in src/index/lazy_metadata.rs in # crate(rattler_installs_packages) and is BSD-3-Clause AND (Apache-2.0 OR -# MIT): the original routine is BSD-3-CLause, and subsequent modifications +# MIT): the original routine is BSD-3-Clause, and subsequent modifications # are explicitly (Apache-2.0 OR MIT). # # MIT # - crates/uv-virtualenv/src/activator/ is vendored and forked from # python3dist(virtualenv) +# - crates/uv-netrc/ is vendored from crate(rust-netrc) # # Additionally, the following are bundled/forked but happen to be under the # same (Apache-2.0 OR MIT) terms as uv itself: @@ -51,36 +53,36 @@ Summary: An extremely fast Python package installer and resolver, written # forked from crate(ripunzip) # # The following are present in the source but believed not to contribute to the -# licenses of the binary RPMs. Note that ecosystem/ contains only +# licenses of the binary RPMs. Note that test/ecosystem/ contains only # pyproject.toml files used for testing, not complete bundled projects. # # Apache-2.0: -# - ecosystem/airflow/ -# - ecosystem/home-assistant-core/ -# - ecosystem/transformers/ -# - ecosystem/warehouse/ +# - test/ecosystem/airflow/ +# - test/ecosystem/home-assistant-core/ +# - test/ecosystem/transformers/ +# - test/ecosystem/warehouse/ # Apache-2.0 OR MIT: -# - ecosystem/packse/ +# - test/ecosystem/packse/ # BSD-2-Clause-Patent: -# - ecosystem/github-wikidata-bot/ +# - test/ecosystem/github-wikidata-bot/ # BSD-3-Clause: -# - ecosystem/saleor/ +# - test/ecosystem/jupyterlab/ +# - test/ecosystem/pandas/ +# - test/ecosystem/saleor/ # MIT: # - crates/uv-python/fetch-download-metadata.py is derived from # https://github.com/mitsuhiko/rye/tree/f9822267a7f00332d15be8551f89a212e7bc9017 # which was MIT. -# - ecosystem/black/ +# - test/ecosystem/black/ +# - test/ecosystem/poetry/ +# - test/ecosystem/semantic-kernel/ # # Rust crates compiled into the executable contribute additional license terms. # To obtain the following list of licenses, build the package and note the -# output of %%{cargo_license_summary}. This should automatically include the -# licenses of the following bundled forks: -# - async_zip, Source100, is MIT. -# - pubgrub/version-ranges, Source200, is MPL-2.0. -# - reqwest-middleware/reqwest-retry, Source300, is (MIT OR Apache-2.0). -# - tl, Source400, is MIT. +# output of %%{cargo_license_summary}. # # (Apache-2.0 OR MIT) AND BSD-3-Clause +# (MIT OR Apache-2.0) AND Apache-2.0 AND CC0-1.0 # (MIT OR Apache-2.0) AND Unicode-3.0 # (MIT OR Apache-2.0) AND Unicode-DFS-2016 # 0BSD @@ -100,39 +102,43 @@ Summary: An extremely fast Python package installer and resolver, written # ISC # LGPL-3.0-or-later OR MPL-2.0 # MIT +# MIT AND (MIT OR Apache-2.0) # MIT OR Apache-2.0 # MIT OR LGPL-3.0-or-later # MIT OR Zlib OR Apache-2.0 +# MIT-0 # MIT-0 OR Apache-2.0 # MPL-2.0 # Unicode-3.0 # Unlicense OR MIT # Zlib License: %{shrink: - 0BSD AND - (0BSD OR Apache-2.0 OR MIT) AND - Apache-2.0 AND - (Apache-2.0 OR BSD-2-Clause) AND - (Apache-2.0 OR BSD-2-Clause OR MIT) AND - (Apache-2.0 OR BSL-1.0) AND - (Apache-2.0 OR ISC OR MIT) AND - (Apache-2.0 OR MIT) AND - (Apache-2.0 OR MIT OR Zlib) AND - (Apache-2.0 OR MIT-0) AND - (Apache-2.0 WITH LLVM-exception) AND - (Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT) AND - BSD-3-Clause AND - CDLA-Permissive-2.0 AND - ISC AND - (LGPL-3.0-or-later OR MIT) AND - (LGPL-3.0-or-later OR MPL-2.0) AND - MIT AND - (MIT OR Unlicense) AND - MPL-2.0 AND - Unicode-3.0 AND - Unicode-DFS-2016 AND - Zlib - } + 0BSD AND + (0BSD OR Apache-2.0 OR MIT) AND + Apache-2.0 AND + (Apache-2.0 OR BSD-2-Clause) AND + (Apache-2.0 OR BSD-2-Clause OR MIT) AND + (Apache-2.0 OR BSL-1.0) AND + (Apache-2.0 OR ISC OR MIT) AND + (Apache-2.0 OR MIT) AND + (Apache-2.0 OR MIT OR Zlib) AND + (Apache-2.0 OR MIT-0) AND + (Apache-2.0 WITH LLVM-exception) AND + (Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT) AND + BSD-3-Clause AND + CC0-1.0 AND + CDLA-Permissive-2.0 AND + ISC AND + (LGPL-3.0-or-later OR MIT) AND + (LGPL-3.0-or-later OR MPL-2.0) AND + MIT AND + MIT-0 AND + (MIT OR Unlicense) AND + MPL-2.0 AND + Unicode-3.0 AND + Unicode-DFS-2016 AND + Zlib + } # LICENSE.dependencies contains a full license breakdown URL: https://github.com/astral-sh/uv Source0: %{url}/archive/%{version}/uv-%{version}.tar.gz @@ -140,67 +146,21 @@ Source0: %{url}/archive/%{version}/uv-%{version}.tar.gz # https://docs.astral.sh/uv/configuration/files Source1: uv.toml -# Currently, uv must use a fork of async_zip, as explained in: -# Restore central directory buffering -# https://github.com/astral-sh/rs-async-zip/pull/2 -# and further discussed in -# Please consider supporting the current release of async_zip -# https://github.com/prefix-dev/async_http_range_reader/issues/14 -# We therefore bundle the fork as prescribed in -# https://docs.fedoraproject.org/en-US/packaging-guidelines/Rust/#_replacing_git_dependencies -%global async_zip_git https://github.com/astral-sh/rs-async-zip -%global async_zip_rev f6a41d32866003c868d03ed791a89c794f61b703 -%global async_zip_baseversion 0.0.17 -%global async_zip_snapdate 20251014 -Source100: %{async_zip_git}/archive/%{async_zip_rev}/rs-async-zip-%{async_zip_rev}.tar.gz - -# For the foreseeable future, uv must use a fork of pubgrub (and the -# version-ranges crate, which belongs to the same project), as explained in: -# Plans for eventually using published pubgrub? -# https://github.com/astral-sh/uv/issues/3794 -# We therefore bundle the fork as prescribed in -# https://docs.fedoraproject.org/en-US/packaging-guidelines/Rust/#_replacing_git_dependencies -%global pubgrub_git https://github.com/astral-sh/pubgrub -%global pubgrub_rev d8efd77673c9a90792da9da31b6c0da7ea8a324b -%global pubgrub_baseversion 0.3.0 -%global pubgrub_snapdate 20250810 -%global version_ranges_baseversion 0.1.1 -Source200: %{pubgrub_git}/archive/%{pubgrub_rev}/pubgrub-%{pubgrub_rev}.tar.gz - -# Until “Report retry count on Ok results,” -# https://github.com/TrueLayer/reqwest-middleware/pull/235, is reviewed, -# merged, and released, uv must use a fork of reqwest-middleware/reqwest-retry -# to support the changes in “Show retries for HTTP status code errors,” -# https://github.com/astral-sh/uv/pull/13897. We therefore bundle the fork as -# prescribed in -# https://docs.fedoraproject.org/en-US/packaging-guidelines/Rust/#_replacing_git_dependencies -%global reqwest_middleware_git https://github.com/astral-sh/reqwest-middleware -%global reqwest_middleware_rev 7650ed76215a962a96d94a79be71c27bffde7ab2 -%global reqwest_middleware_snapdate 20250828 -%global reqwest_middleware_baseversion 0.4.2 -%global reqwest_retry_baseversion 0.7.0 -Source300: %{reqwest_middleware_git}/archive/%{reqwest_middleware_rev}/reqwest-middleware-%{reqwest_middleware_rev}.tar.gz - -# For the time being, uv must use a fork of tl. See: -# Path back to using released tl crate dependency? -# https://github.com/astral-sh/uv/issues/6687 -# It should be possible to stop forking and bundling if tl upstream merges and -# releases the following fix: -# Avoid truncating URLs in unquoted hrefs -# https://github.com/y21/tl/pull/69 -# We therefore bundle the fork as prescribed in -# https://docs.fedoraproject.org/en-US/packaging-guidelines/Rust/#_replacing_git_dependencies -%global tl_git https://github.com/astral-sh/tl -%global tl_rev 6e25b2ee2513d75385101a8ff9f591ef51f314ec -%global tl_baseversion 0.7.8 -%global tl_snapdate 20240825 -Source400: %{tl_git}/archive/%{tl_rev}/tl-%{tl_rev}.tar.gz - # Downstream-only: Always find the system-wide uv executable # See discussion in # Should uv.find_uv_bin() be able to find /usr/bin/uv? # https://github.com/astral-sh/uv/issues/4451 Patch: 0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch +# Downstream-only: revert source-code changes from “Upgrade BLAKE2 to unify +# hashing digest versions”, https://github.com/astral-sh/uv/pull/20834. We do +# not wish to upgrade rust-blake2 to a pre-release. +Patch: uv-0.12.1-revert-blake2-beta.patch +# Add license texts for new contents of test/ecosystem/ from PR#20068 +# https://github.com/astral-sh/uv/pull/20174 +Patch: %{url}/pull/20174.patch + +BuildSystem: pyproject +BuildOption(install): --assert-license uv # https://fedoraproject.org/wiki/Changes/EncourageI686LeafRemoval ExcludeArch: %{ix86} @@ -209,35 +169,34 @@ ExcludeArch: %{ix86} # of memory in the final linking step. This cannot be fixed by adding # "-C link-args=-Wl,--no-keep-memory" to the RUSTFLAGS (as that seems to have # no significant effect on memory requirements), nor can it be fixed by -# reducing parallelism with e.g. the _smp_tasksize_proc global (although we do -# need this as well), since nothing else is happening at that point in the -# build. See: +# reducing parallelism (although we do need this as well), since nothing else +# is happening at that point in the build. See: # https://doc.rust-lang.org/rustc/codegen-options/index.html#debuginfo %global rustflags_debuginfo 1 -# As a separate limitation, memory exhaustion can occur on builders with very -# many CPUs. Typical workspace crates peak out at 2-4 GB per rustc invocation. -# The uv crate needs much more memory to compile (see the RUSTFLAGS adjustment -# in %%build), but in practice it is also compiled alone after all the other -# crates have finished, so it does not need to influence (and does not benefit -# from) this setting. Even though some crates will require more than 3GB, the -# average should be below that on many-core systems. Increase as needed. -%global _smp_tasksize_proc 4096 +# As a separate limitation, memory exhaustion (OOM) can occur during parallel +# portions of the build. +# - Because very many workspace crates can be built in parallel, builders with +# a very large number of CPUs may OOM. Typical workspace crates peak out at +# roughly 2–4 GB per rustc process. +# - The uv crate needs much more memory to compile and link, at least 8 GB, and +# when building the tests we may be building bin and lib versions at the same +# time, along with the it (integration test) crate, which is also rather +# large. This is a problem for “low memory” builders (<20 GB or so). +# Unfortunately, this means that we need to scale the memory per task based on +# the memory requirements of the top-level uv crate in order to avoid OOM on +# all kinds of builders. +%global _smp_tasksize_proc 10240 # Compilation may fail on builders with very many cores (e.g. 192 cores) due to # “too many open files.” Try to keep the files/core ratio from getting too low. -%global _smp_ncpus_max 128 +%global _smp_ncpus_max 48 -BuildRequires: cargo-rpm-macros >= 24 +BuildRequires: cargo-rpm-macros BuildRequires: rust2rpm-helper BuildRequires: tomcli -BuildRequires: python3-devel -%if %{with check} && %{with it} +%if %{with check} && %{with other_python_versions} # See trove classifiers in pyproject.toml for supported Pythons. -%if %{defined fc41} -# https://fedoraproject.org/wiki/Changes/RetirePython3.8 -BuildRequires: /usr/bin/python3.8 -%endif BuildRequires: /usr/bin/python3.9 BuildRequires: /usr/bin/python3.10 BuildRequires: /usr/bin/python3.11 @@ -248,46 +207,31 @@ BuildRequires: /usr/bin/python3.14 BuildRequires: /usr/bin/python3.14t %endif -# This is a fork of async_zip; see the notes about Source100. -%global async_zip_snapinfo %{async_zip_snapdate}git%{sub %{async_zip_rev} 1 7} -%global async_zip_version %{async_zip_baseversion}^%{async_zip_snapinfo} -Provides: bundled(crate(async_zip)) = %{async_zip_version} -# This is a fork of pubgrub/version-ranges; see the notes about Source200. -%global pubgrub_snapinfo %{pubgrub_snapdate}git%{sub %{pubgrub_rev} 1 7} -%global pubgrub_version %{pubgrub_baseversion}^%{pubgrub_snapinfo} -%global version_ranges_version %{version_ranges_baseversion}^%{pubgrub_snapinfo} -Provides: bundled(crate(pubgrub)) = %{pubgrub_version} -Provides: bundled(crate(version-ranges)) = %{version_ranges_version} -# This is a fork of reqwest-middleware/reqwest-retry; see the notes about -# Source300. -%global reqwest_middleware_snapinfo %{reqwest_middleware_snapdate}git%{sub %{reqwest_middleware_rev} 1 7} -%global reqwest_middleware_version %{reqwest_middleware_baseversion}^%{reqwest_middleware_snapinfo} -%global reqwest_retry_version %{reqwest_retry_baseversion}^%{reqwest_middleware_snapinfo} -Provides: bundled(crate(reqwest-middleware)) = %{reqwest_middleware_version} -Provides: bundled(crate(reqwest-retry)) = %{reqwest_retry_version} -# This is a fork of tl; see the notes about Source400. -%global tl_snapinfo %{tl_snapdate}git%{sub %{tl_rev} 1 7} -%global tl_version %{tl_baseversion}^%{tl_snapinfo} -Provides: bundled(crate(tl)) = %{tl_version} - # In https://github.com/astral-sh/uv/issues/5588#issuecomment-2257823242, # upstream writes “These have diverged significantly and the upstream versions # are only passively maintained, uv requires these custom versions and can't # use a system copy.” # # crates/uv-pep440/ -# Version number from Cargo.toml: +# Version number from crates/uv-pep440/CHANGELOG.md; it was also in +# crates/uv-pep440/Cargo.toml until uv 0.9.11, when internal crates started +# being versioned and published on crates.io. Provides: bundled(crate(pep440_rs)) = 0.7.0 # crates/uv-pep508/ -# Cargo.toml has 0.6.0, but Changelog.md shows 0.7.0, and the source reflects -# the changes for 0.7.0: +# Version number from crates/uv-pep508/Changelog.md; it was also in +# crates/uv-pep508/Cargo.toml until uv 0.9.11, when internal crates started +# being versioned and published on crates.io, but the version in Cargo.toml was +# 0.6.0. The source reflects upstream changes in 0.7.0. Provides: bundled(crate(pep508_rs)) = 0.7.0 # crates/uv-virtualenv/ # As a whole, this crate is derived from https://github.com/konstin/gourgeist # 0.0.4, which was published as https://crates.io/crates/gourgeist. It looks -# looks like the project was subsumed into `uv`, and the link to `uv` at -# https://konstin.github.io/gourgeist/ seems to support this, so we consider -# this not to be a real case of bundling, and we do not add: +# like the project was subsumed into `uv`, and the link to `uv` at +# https://konstin.github.io/gourgeist/ (“See +# https://github.com/astral-sh/uv/tree/main/crates/uv-virtualenv for the up to +# date version”) supports this. We therefore consider this not to be a real +# case of bundling, since the source in uv is now the canonical one, and we do +# not add: # Provides: bundled(crate(gourgeist)) = 0.0.4 # crates/uv-extract/src/vendor/cloneable_seekable_reader.rs @@ -331,6 +275,19 @@ Provides: bundled(crate(r-shquote)) = 0.1.1 # appear to be any prospect of unbundling. Provides: bundled(crate(keyring)) = 4.0.0~rc2 +# crates/uv-netrc +# From crates/uv-netrc/README.md, “This crate vendors the rust-netrc parser for +# use by uv. The source was vendored from gribouille/netrc, as published in +# rust-netrc 0.1.2[…]” +# +# Upstream justifies the bundling in +# https://github.com/astral-sh/uv/pull/19409: they want unreleased bug fixes, +# including those pertaining to https://github.com/astral-sh/uv/issues/16083, +# and to avoid a dependency on thiserror v1. In response to the mandatory +# query, they report they are open to de-vendoring if a new rust-netrc release +# with the desired changes appears. +Provides: bundled(crate(rust-netrc)) = 0.1.2 + # The contents of crates/uv-virtualenv/src/activator/ are a bundled and # slightly forked copy of a subset of https://pypi.org/project/virtualenv; see # https://github.com/pypa/virtualenv/tree/main/src/virtualenv/activation. @@ -341,9 +298,10 @@ Provides: bundled(crate(keyring)) = 4.0.0~rc2 # https://github.com/astral-sh/uv/issues/5588#issuecomment-2257474140 # # The scripts were last updated from virtualenv upstream in -# https://github.com/astral-sh/uv/pull/3376 on 2024-05-04; the latest -# virtualenv release at that time was 20.26.0. -Provides: bundled(python3dist(virtualenv)) = 20.26 +# https://github.com/astral-sh/uv/pull/15272 on 2025-09-05. The PR was opened +# on 2025-08-14 and last revised on 2025-08-30; the latest virtualenv release +# throughout that time interval was 20.34.0. +Provides: bundled(python3dist(virtualenv)) = 20.34 # The contents of crates/uv-python/python/packaging/ are a bundled copy of a # subset of https://pypi.org/project/packaging. @@ -384,24 +342,21 @@ Provides: bundled(python3dist(packaging)) = 24.1~dev0^20240310gitcc938f9 Provides: bundled(python3dist(pipreqs)) = 0.5.0 %global common_description %{expand: -An extremely fast Python package installer and resolver, written in Rust. -Designed as a drop-in replacement for common pip and pip-tools workflows. +An extremely fast Python package and project manager, written in Rust. Highlights: - • ⚖️ Drop-in replacement for common pip, pip-tools, and virtualenv commands. - • ⚡️ 10-100x faster than pip and pip-tools (pip-compile and pip-sync). - • 💾 Disk-space efficient, with a global cache for dependency deduplication. - • 🐍 Installable via curl, pip, pipx, etc. uv is a static binary that can be - installed without Rust or Python. - • 🧪 Tested at-scale against the top 10,000 PyPI packages. - • 🖥️ Support for macOS, Linux, and Windows. - • 🧰 Advanced features such as dependency version overrides and alternative - resolution strategies. - • ⁉️ Best-in-class error messages with a conflict-tracking resolver. - • 🤝 Support for a wide range of advanced pip features, including editable - installs, Git dependencies, direct URL dependencies, local dependencies, - constraints, source distributions, HTML and JSON indexes, and more.} + • A single tool to replace pip, pip-tools, pipx, poetry, pyenv, twine, + virtualenv, and more. + • 10-100x faster than pip. + • Provides comprehensive project management, with a universal lockfile. + • Runs scripts, with support for inline dependency metadata. + • Installs and manages Python versions. + • Runs and installs tools published as Python packages. + • Includes a pip-compatible interface for a performance boost with a familiar + CLI. + • Supports Cargo-style workspaces for scalable projects. + • Disk-space efficient, with a global cache for dependency deduplication.} %description %{common_description} @@ -418,109 +373,36 @@ Requires: uv = %{version}-%{release} This package provides an importable Python module for uv. -%prep -%autosetup -N -%autopatch -p1 -M99 - -# Usage: git2path SELECTOR PATH -# Replace a git dependency with a path dependency in Cargo.toml -git2path() { - tomcli set Cargo.toml del "${1}.git" - tomcli set Cargo.toml del "${1}.rev" - tomcli set Cargo.toml str "${1}.path" "${2}" -} - -# See comments above Source100: -%setup -q -T -D -b 100 -n uv-%{version} -# Adding the crate to the workspace (in this case implicitly, by linking it -# under crates/) means %%cargo_generate_buildrequires can handle it correctly. -ln -s '../../rs-async-zip-%{async_zip_rev}' crates/async_zip -git2path workspace.dependencies.async_zip crates/async_zip -pushd crates/async_zip -%autopatch -p1 -m100 -M199 -popd -install -t LICENSE.bundled/async_zip -D -p -m 0644 crates/async_zip/LICENSE - -# See comments above Source200: -%setup -q -T -D -b 200 -n uv-%{version} -ln -s '../../pubgrub-%{pubgrub_rev}' crates/pubgrub -git2path workspace.dependencies.pubgrub crates/pubgrub -pushd crates/pubgrub -%autopatch -p1 -m200 -M299 -popd -install -t LICENSE.bundled/pubgrub -D -p -m 0644 crates/pubgrub/LICENSE -# Drop a benchmark-only dev-dependency. -tomcli set crates/pubgrub/Cargo.toml del dev-dependencies.criterion -# Omit tests requiring varisat; it is not packaged and has significant -# dependencies of its own. -tomcli set crates/pubgrub/Cargo.toml del dev-dependencies.varisat -mv crates/pubgrub/tests/proptest.rs{,.disabled} -mv crates/pubgrub/tests/sat_dependency_provider.rs{,.disabled} -# We can’t have two workspaces! -tomcli set crates/pubgrub/Cargo.toml del workspace -# Note that install does always dereference symlinks, which is what we want: -install -t LICENSE.bundled/version-ranges -D -p -m 0644 \ - crates/pubgrub/version-ranges/LICENSE -git2path workspace.dependencies.version-ranges crates/pubgrub/version-ranges - -# See comments above Source300: -%setup -q -T -D -b 300 -n uv-%{version} -pushd '../reqwest-middleware-%{reqwest_middleware_rev}' -%autopatch -p1 -m300 -M399 -# The (path-based) dev-dependency on reqwest-tracing is required only for an -# example in README.md; avoid it. -tomcli set reqwest-middleware/Cargo.toml del dev-dependencies.reqwest-tracing -sed -r -i 's/^```rust$/&,ignore/' README.md -popd -ln -s '../../reqwest-middleware-%{reqwest_middleware_rev}/reqwest-middleware' \ - crates/reqwest-middleware -git2path workspace.dependencies.reqwest-middleware crates/reqwest-middleware -git2path patch.crates-io.reqwest-middleware crates/reqwest-middleware -install -t LICENSE.bundled/reqwest-middleware -D -p -m 0644 \ - crates/reqwest-middleware/LICENSE* -ln -s '../../reqwest-middleware-%{reqwest_middleware_rev}/reqwest-retry' \ - crates/reqwest-retry -git2path workspace.dependencies.reqwest-retry crates/reqwest-retry -git2path patch.crates-io.reqwest-retry crates/reqwest-retry -install -t LICENSE.bundled/reqwest-retry -D -p -m 0644 \ - crates/reqwest-retry/LICENSE* -# We do not need the reqwest-tracing crate. -rm -rv '../reqwest-middleware-%{reqwest_middleware_rev}/reqwest-tracing' - -# See comments above Source400: -%setup -q -T -D -b 400 -n uv-%{version} -ln -s '../../tl-%{tl_rev}' crates/tl -git2path workspace.dependencies.tl crates/tl -pushd crates/tl -%autopatch -p1 -m400 -M499 -popd -install -t LICENSE.bundled/tl -D -p -m 0644 crates/tl/LICENSE -# Drop a benchmark-only dev-dependency. -tomcli set crates/tl/Cargo.toml del dev-dependencies.criterion - -# Collect license files of vendored dependencies in the main source archive -install -t LICENSE.bundled/packaging -D -p -m 0644 \ +%prep -a +# Collect license files of vendored dependencies +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/packaging \ crates/uv-python/python/packaging/LICENSE.* -install -t LICENSE.bundled/pep440_rs -D -p -m 0644 crates/uv-pep440/License-* -install -t LICENSE.bundled/pep508_rs -D -p -m 0644 crates/uv-pep508/License-* -install -t LICENSE.bundled/pipreqs -D -p -m 0644 \ +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/pep440_rs crates/uv-pep440/License-* +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/pep508_rs crates/uv-pep508/License-* +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/pipreqs \ crates/uv-build-frontend/src/pipreqs/LICENSE -install -t LICENSE.bundled/ripunzip -D -p -m 0644 \ - crates/uv-extract/src/vendor/LICENSE +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/ripunzip crates/uv-extract/src/vendor/LICENSE +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/rust-netrc crates/uv-netrc/LICENSE # The original license text from rattler_installs_packages is present in a # comment, but we want it in a separate file so we can ensure it is present in # the binary RPM. -install -d LICENSE.bundled/rattler_installs_packages +install --directory LICENSE.bundled/rattler_installs_packages awk '$2 == "BSD" { out=1 }; $2 == "```" { out=0 }; out' \ crates/uv-client/src/remote_metadata.rs | - sed -r 's@^///( |$)@@' | + sed --regexp-extended 's@^///( |$)@@' | tee LICENSE.bundled/rattler_installs_packages/LICENSE # Similarly for virtualenv. All files in # crates/uv-virtualenv/src/activator/activate/ have the same license text. -install -d LICENSE.bundled/virtualenv +install --directory LICENSE.bundled/virtualenv awk '$1 == "#" { out=1 }; $1 != "#" { out=0; exit }; out' \ crates/uv-virtualenv/src/activator/activate | - sed -r 's@^#( |$)@@' | + sed --regexp-extended 's@^#( |$)@@' | tee LICENSE.bundled/virtualenv/LICENSE # Patch out foreign (e.g. Windows-only) dependencies. Follow symbolic links so @@ -529,15 +411,27 @@ find -L . -type f -name Cargo.toml -print \ -execdir rust2rpm-helper strip-foreign -o '{}' '{}' ';' # The uv-trampoline crate (a fork of posy trampolines, from -# https://github.com/njsmith/posy) contains a set of trampoline Windows -# executables for launching Python scripts. We must remove these to prove they -# are not used in the build (and since they are only used on Windows, nothing -# is lost by doing so). -rm -v crates/uv-trampoline/trampolines/*.exe -# Per Cargo.toml, uv-trampoline is excluded from the workspace and not -# compiled because it still requires a nightly compiler. For now, we remove it -# entirely to show that we do not need to document bundling from posy. -rm -rv crates/uv-trampoline +# https://github.com/njsmith/posy) uses a set of trampoline Windows executables +# for launching Python scripts. These precompiled executables are funished by +# the uv-trampoline-builder crate. We must remove them to prove they are not +# used in the build. Since they are used only on Windows, nothing is lost by +# doing so. +rm --verbose crates/uv-trampoline-builder/trampolines/*.exe +# Per Cargo.toml, uv-trampoline is excluded from the workspace and not compiled +# because it still requires a nightly compiler. For now, we remove it entirely +# to show that we do not need to document bundling from posy. Note that we +# *cannot* cleanly remove uv-trampoline-builder, only the precompiled +# trampolines themselves. +rm --recursive --verbose crates/uv-trampoline + +# Remove the dependency on embed-manifest, which applies only when (cross-?) +# compiling for Windows. +tomcli set Cargo.toml del workspace.dependencies.embed-manifest +# We may have to do something more sophisticated if this build script ever +# starts to do anything other than just embedding a manifest on Windows. +rm --verbose crates/uv/build.rs +tomcli set crates/uv/Cargo.toml del build-dependencies.embed-manifest +# The embed-manifest depenency is also used in uv-trampoline, which we removed. # Do not strip the compiled executable; we need useful debuginfo. Upstream set # this intentionally, so this change makes sense to keep downstream-only. @@ -548,57 +442,73 @@ tomcli set Cargo.toml false profile.release.strip # benchmarks, and it brings in unwanted additional dev dependencies. tomcli set Cargo.toml append workspace.exclude crates/uv-bench # The uv-dev crate provides “development utilities for uv,” which should not be -# needed here, and it also brings in extra dependencies that we would prefer to -# do without. +# needed here. It also brings extra dependencies that we would prefer to avoid. tomcli set Cargo.toml append workspace.exclude crates/uv-dev -# Do not request static linking of anything (particularly, liblzma) -tomcli set crates/uv/Cargo.toml lists delitem \ - features.default 'uv-distribution/static' -tomcli set crates/uv-distribution/Cargo.toml del features.static -tomcli set crates/uv-extract/Cargo.toml del features.static - # Disable several default features that control which tests are compiled and # executed, and which are not usable in offline builds: # -# - crates-io: Introduces a testing dependency on crates.io. -# - git: Introduces a testing dependency on Git. This sounds innocuous – we -# have git! – but in fact, it controls tests of git dependencies, which +# - test-crates-io: Introduces a testing dependency on crates.io. +# - test-git: Introduces a testing dependency on Git. This sounds innocuous – +# we have git! – but in fact, it controls tests of git dependencies, which # implies accessing remote repositories, e.g. on GitHub. -# - pypi: Introduces a testing dependency on PyPI. -# - python-managed: Introduces a testing dependency on managed Python +# - test-git-lfs: as for git, but also require Git Large File Storage; again, +# this implies accessing remote repositories +# - test-pypi: Introduces a testing dependency on PyPI. +# - test-python-managed: Introduces a testing dependency on managed Python # installations. (These are pre-compiled Pythons downloaded from the # Internet.) -# - r2: Introduces a testing dependency on R2. +# - test-r2: Introduces a testing dependency on R2. # # These are OK: -# - python: Introduces a testing dependency on a local Python installation. -# - slow-tests: Include "slow" test cases. +# - test-python: Introduces a testing dependency on a local Python installation. +# - test-slow: Include "slow" test cases. # - test-ecosystem: Includes test cases that require ecosystem packages # # Note that the python-patch feature, which ”introduces a dependency on a local # Python installation with specific patch versions,” is already not among the # default features. -tomcli set crates/uv/Cargo.toml lists delitem features.default-tests \ - '(crates-io|git|pypi|python-managed|r2)' +tomcli set crates/uv/Cargo.toml lists delitem features.test-defaults \ + 'test-(crates-io|git(-lfs)?|pypi|python-managed|r2)' +# - -test-osv: Introduces a testing dependency on osv.dev. +tomcli set crates/uv-audit/Cargo.toml lists delitem features.default \ + 'test-(osv)' -%if %{without it} -# Integration tests (it crate) nearly all require specific Python interpreter -# versions (major.minor, not major.minor.patch, unless the python-patch feature -# is enabled). We might choose to disable this in order to double-check that -# everything else works well with only the primary system Python in the -# environment. +%if %{without other_python_versions} +# Many of these tests require specific Python versions (major.minor, not +# major.minor.patch, unless the python-patch feature is enabled). Manually +# selecting the tests in these modules that would succeed with just the system +# Python would be far too tedious. +omit_modules() { + set -o nounset + set -o errexit + main_module="${1}" + commented_modules='' + comment='Downstream-only: skip, needs specific Python interpreter versions' + shift + while [ "${#}" != 0 ] + do + commented_modules="${commented_modules-}${commented_modules+|}${1}" + shift + done + sed --regexp-extended --in-place \ + "s@mod (${commented_modules});@// ${comment}\n#[cfg(any())]\n&@" \ + "${main_module}" +} +# -p uv --test build +omit_modules crates/uv/tests/build/main.rs build_backend # -p uv --test it: -mods="${mods-}${mods+|}branching_urls" -mods="${mods-}${mods+|}build_backend" -mods="${mods-}${mods+|}pip_(check|list|show|tree|uninstall)" -mods="${mods-}${mods+|}python_(dir|find|install|list|pin)" -mods="${mods-}${mods+|}venv" -mods="${mods-}${mods+|}version" -mods="${mods-}${mods+|}workspace" -comment='Downstream-only: skip, needs specific Python interpreter versions' -sed -r -i "s@mod (${mods});@// ${comment}\n#[cfg(any())]\n&@" \ - crates/uv/tests/it/main.rs +omit_modules crates/uv/tests/it/main.rs \ + auth branching_urls network upgrade version +# -p uv --test python: +omit_modules crates/uv/tests/python/main.rs \ + 'python_(dir|find|install|list|pin)' venv +# -p uv --test workspace: +omit_modules crates/uv/tests/workspace/main.rs \ + workspace 'workspace_(dir|list|metadata)' +# -p uv --test pip: +omit_modules crates/uv/tests/pip/main.rs \ + 'pip_(debug|list|show|tree|uninstall)' %endif # For unclear reasons, maturin checks for the presence of optional crate @@ -619,26 +529,29 @@ tomcli set crates/uv/Cargo.toml del dependencies.tracing-durations-export # # https://bugzilla.redhat.com/show_bug.cgi?id=1234567 # tomcli set Cargo.toml str workspace.dependencies.foocrate.version 0.1.2 -# etcetera -# wanted: 0.11.0 -# currently packaged: 0.10.0 -# https://bugzilla.redhat.com/show_bug.cgi?id=2406801 -tomcli set Cargo.toml str workspace.dependencies.etcetera.version \ - '>=0.10.0, <0.12.0' +# tikv-jemallocator +# wanted: 0.6.0 +# currently packaged: 0.7.0 +# https://github.com/astral-sh/uv/pull/19735 +# We use sed instead of tomcli because the target.cfg(…) expression is a +# *mess*, and we don’t want to have to write it out here. +sed --regexp-extended --in-place \ + 's/^(tikv-jemallocator\b.*version = ")0\.6\.0"/\1>=0.6.0, <0.8.0"/' \ + crates/uv-performance-memory-allocator/Cargo.toml -# spdx -# wanted: 0.10.6 -# currently packaged: 0.10.9 (but we want to update to 0.12) -# https://bugzilla.redhat.com/show_bug.cgi?id=2387258 -# Update the spdx dependency to version 0.12 -# https://github.com/astral-sh/uv/pull/16552 -tomcli set Cargo.toml str workspace.dependencies.spdx.version \ - '>=0.10.6, <0.13.0' +# blake2 +# wanted: 0.11.0-rc.6 +# currently packaged: 0.10.6 +# https://github.com/astral-sh/uv/pull/19735 +# Downstream-only: revert “Upgrade BLAKE2 to unify hashing digest versions”, +# https://github.com/astral-sh/uv/pull/20834. We do not wish to upgrade +# rust-blake2 to a pre-release. There is an anccompanying source-code patch. +tomcli set Cargo.toml str workspace.dependencies.blake2.version 0.10.6 %cargo_prep -%generate_buildrequires +%generate_buildrequires -p # For unclear reasons, maturin checks for all crate dependencies when it is # invoked as part of %%pyproject_buildrequires – including those corresponding # to optional features. @@ -650,32 +563,14 @@ tomcli set Cargo.toml str workspace.dependencies.spdx.version \ # Since maturin always checks for dev-dependencies, we need -t so that they are # generated even when the “check” bcond is disabled. %cargo_generate_buildrequires -a -t -# These crates are excluded from the workspace – upstream writes: -# Only used to pull in features, allocators, etc. — we specifically don't -# want them to be part of a workspace-wide cargo check, cargo clippy, etc. -# – but they are still needed to support features, and the build will fail if -# we do not generate their dependencies, too: -for cratedir in \ - crates/uv-performance-memory-allocator -do - pushd "${cratedir}" >/dev/null - %cargo_generate_buildrequires -a -t - popd >/dev/null -done -%pyproject_buildrequires -%build -%pyproject_wheel - +%build -a %{cargo_license_summary} %{cargo_license} > LICENSE.dependencies -%install -%pyproject_install -%pyproject_save_files uv - +%install -a if [ '%{python3_sitearch}' != '%{python3_sitelib}' ] then # Maturin is really designed to build compiled Python extensions, but (when @@ -683,9 +578,10 @@ then # library is actually pure-Python, and the python3-uv subpackage can be # noarch. We can’t tell maturin to install to the appropriate site-packages # directory, but we can fix the installation path manually. - install -d %{buildroot}%{python3_sitelib} + install --directory %{buildroot}%{python3_sitelib} mv %{buildroot}%{python3_sitearch}/uv* %{buildroot}%{python3_sitelib} - sed -r -i 's@%{python3_sitearch}@%{python3_sitelib}@' %{pyproject_files} + sed --regexp-extended --in-place \ + 's@%{python3_sitearch}@%{python3_sitelib}@' %{pyproject_files} fi # generate and install shell completions @@ -701,10 +597,11 @@ do done # Install a default system-wide configuration file -install -t '%{buildroot}%{_sysconfdir}/uv' -p -m 0644 -D '%{SOURCE1}' +install -D --preserve-timestamps --mode=0644 \ + --target='%{buildroot}%{_sysconfdir}/uv' '%{SOURCE1}' -%check +%check -a %if %{with check} # These tests rely on debug assertions, and fail when tests are compiled in # release mode: @@ -715,25 +612,20 @@ skip="${skip-} --skip keyring::tests::fetch_url_with_empty_username" skip="${skip-} --skip keyring::tests::fetch_url_with_no_username" skip="${skip-} --skip keyring::tests::fetch_url_with_password" -%if %{without it} +%if %{without other_python_versions} # These tests require specific Python interpreter versions, which upstream # normally downloads, precompiled, into the build area. skip="${skip-} --skip version::self_version" skip="${skip-} --skip version::self_version_json" skip="${skip-} --skip version::self_version_short" -%else -# Some python_find:: tests don’t find system interpreters, require network -# https://github.com/astral-sh/uv/issues/16431 -skip="${skip-} --skip python_find::python_find_freethreaded_313" -skip="${skip-} --skip python_find::python_find_freethreaded_314" -skip="${skip-} --skip python_find::python_find_prerelease_version_specifiers" -skip="${skip-} --skip python_find::python_find_prerelease_with_patch_request" %endif %ifnarch %{x86_64} %{arm64} # On other architectures, the list of available downloads differs, e.g. pypy # and graalpy downloads may be missing. skip="${skip-} --skip python_list::python_list_downloads" +# Similarly, version numbers may not match exactly. +skip="${skip-} --skip python_list::python_list_with_mirrors" %endif %ifarch %{power64} # The error message lacks the expected hint: @@ -742,12 +634,29 @@ skip="${skip-} --skip python_list::python_list_downloads" # This might be worth reporting upstream, but is not a serious issue. skip="${skip-} --skip python_pin::python_pin_resolve" %endif -%ifarch %{power64} s390x +%ifarch riscv64 +# These expect managed interpreters of the form +# cpython-3.##-linux-riscv64gc-any, but crates/uv-python/download-metadata.json +# only has them for cpython-3.##-linux-riscv64-gnu. It’s not weird to find +# holes in the managed interpreter support matrix for less common +# architectures. +skip="${skip-} --skip python_find::python_find" +skip="${skip-} --skip python_list::python_list" +skip="${skip-} --skip python_pin::python_pin_resolve" +%endif + +# It’s not clear what causes the trivial discrepancy, but we find that this +# fails when building in qemu-user-static emulated chroots. +# 4 │- Caused by: Failed to query Python interpreter at `[TEMP_DIR]/bar` +# 5 │- Caused by: [PERMISSION DENIED] +# 4 │+ Caused by: Querying Python at `[TEMP_DIR]/bar` failed with +# exit status exit status: 127 +skip="${skip-} --skip python_find::python_find_path" + # Test registry_client::tests::test_redirect_to_server_with_credentials is -# flaky on ppc64le +# flaky # https://github.com/astral-sh/uv/issues/16447 skip="${skip-} --skip registry_client::tests::test_redirect_to_server_with_credentials" -%endif # This requires specific Python interpreter versions (so it would be grouped # with the conditionalized integration tests above), but it also requires @@ -756,14 +665,6 @@ skip="${skip-} --skip registry_client::tests::test_redirect_to_server_with_crede # https://github.com/astral-sh/uv/pull/13699#issuecomment-2916115588. skip="${skip-} --skip remote_metadata::remote_metadata_with_and_without_cache" -%if %[ %{defined fc41} || %{defined el10} ] -# Trivial difference in snapshots: packages appear in a different order. -skip="${skip-} --skip lock::tests::missing_dependency_source_unambiguous" -skip="${skip-} --skip lock::tests::missing_dependency_version_dynamic" -skip="${skip-} --skip lock::tests::missing_dependency_source_version_unambiguous" -skip="${skip-} --skip lock::tests::missing_dependency_version_unambiguous" -%endif - # Upstream is trying to ensure platform-independent byte-for-byte deterministic # wheels. This isn’t quite working out. It would be nice to understand this, # but this kind of reproducibility can be brittle, and there are many possible @@ -783,17 +684,50 @@ skip="${skip-} --skip lock::tests::missing_dependency_version_unambiguous" # ────────────┴─────────────────────────────────────────────────────────────────── skip="${skip-} --skip tests::built_by_uv_building" +# The list of HTTP status codes contains 103, but the expected list from the +# snapshot doesn’t. This seems like a trivial discrepancy, probably due to a +# dependency version differing from Cargo.lock. +skip="${skip-} --skip base_client::tests::retried_status_codes" + +# Harmless and trivial discrepancies in error messages: +# 8 │- Caused by: error decoding response body for url (http://[LOCALHOST]/tqdm/) +# 8 │+ Caused by: error decoding response body +skip="${skip-} --skip network::retry_read_timeout_index" +# 9 │- Caused by: error decoding response body for url (http://[LOCALHOST]/) +# 9 │+ Caused by: error decoding response body +skip="${skip-} --skip network::retry_read_timeout_python_downloads_json" + +# These fail flakily: most frequently on ppc64le, but this seems to be just a +# matter of luck, since we suspect a race condition. We have also seen failures +# on aarch64. This is probably a race involving the SSL_CERT_FILE environment +# variable, which process-isolated testing in “cargo nextest” (used by +# upstream) should avoid. That suggests there is nothing to report upstream. +# When this fails, the error looks something like: +# Error: failed to build HTTP client +# Caused by: +# 0: certificate in `/tmp/uv/tests/certs/.tmpFF0lkk/ca.pem` (from +# `SSL_CERT_FILE`) could not be used as a trust anchor on certificate +# `CN=uv-test-ca, O=Astral Software Inc.` +# 1: ExtensionValueInvalid +skip="${skip-} --skip user_agent_version::test_user_agent_has_linehaul" +skip="${skip-} --skip user_agent_version::test_user_agent_has_subcommand" +skip="${skip-} --skip user_agent_version::test_user_agent_has_version" +# Similarly, with an error like: +# Client::new(): reqwest::Error { +# kind: Builder, +# source: General("No CA certificates were loaded from the system") +# } +# There are probably more of these. +skip="${skip-} --skip retry::tests::retried_status_codes" + %cargo_test -- -- --exact ${skip-} %endif -%pyproject_check_import - %files %license LICENSE-APACHE LICENSE-MIT LICENSE.dependencies LICENSE.bundled/ %doc CHANGELOG.md %doc README.md -%doc PIP_COMPATIBILITY.md %{_bindir}/uv # Equivalent to “uv tool run”: