diff --git a/.gitignore b/.gitignore index 5b782d0..36e4cb1 100644 --- a/.gitignore +++ b/.gitignore @@ -1,210 +1 @@ -/pubgrub-3f0ba760951ab0deeac874b98bb18fc90103fcf7.tar.gz -/reqwest-middleware-21ceec9a5fd2e8d6f71c3ea2999078fecbd13cbe.tar.gz -/rs-async-zip-011b24604fa7bc223daaad7712c0694bac8f0a87.tar.gz -/uv-0.2.32.tar.gz -/uv-0.2.33.tar.gz -/pubgrub-2fac39371a47e7cb821e510aaa4de25405413d29.tar.gz -/uv-0.2.34.tar.gz -/uv-0.2.35.tar.gz -/uv-0.2.37-filtered.tar.zst -/uv-0.3.0-filtered.tar.zst -/pubgrub-aaef464c1b0d8eea4ff9ffaee4f3458c236d10da.tar.gz -/reqwest-middleware-5e3eaf254b5bd481c75d2710eed055f95b756913.tar.gz -/uv-0.3.2-filtered.tar.zst -/uv-0.3.3-filtered.tar.zst -/pubgrub-388685a8711092971930986644cfed152d1a1f6c.tar.gz -/uv-0.3.4-filtered.tar.zst -/tl-6e25b2ee2513d75385101a8ff9f591ef51f314ec.tar.gz -/uv-0.3.5-filtered.tar.zst -/uv-0.4.0-filtered.tar.zst -/uv-0.4.1-filtered.tar.zst -/uv-0.4.2-filtered.tar.zst -/uv-0.4.4-filtered.tar.zst -/uv-0.4.5-filtered.tar.zst -/uv-0.4.6-filtered.tar.zst -/uv-0.4.7-filtered.tar.zst -/uv-0.4.8-filtered.tar.zst -/uv-0.4.9-filtered.tar.zst -/uv-0.4.10-filtered.tar.zst -/uv-0.4.15.tar.gz -/uv-0.4.16.tar.gz -/uv-0.4.17.tar.gz -/uv-0.4.18.tar.gz -/uv-0.4.19.tar.gz -/uv-0.4.20.tar.gz -/uv-0.4.21.tar.gz -/uv-0.4.22.tar.gz -/uv-0.4.23.tar.gz -/pubgrub-19c77268c0ad5f69d7e12126e0cfacfbba466481.tar.gz -/uv-0.4.24.tar.gz -/uv-0.4.25.tar.gz -/pubgrub-7243f4faf8e54837aa8a401a18406e7173de4ad5.tar.gz -/reqwest-middleware-d95ec5a99fcc9a4339e1850d40378bbfe55ab121.tar.gz -/uv-0.4.26.tar.gz -/uv-0.4.27.tar.gz -/uv-0.4.28.tar.gz -/uv-0.4.29.tar.gz -/pubgrub-95e1390399cdddee986b658be19587eb1fdb2d79.tar.gz -/uv-0.4.30.tar.gz -/uv-0.5.0.tar.gz -/uv-0.5.1.tar.gz -/uv-0.5.2.tar.gz -/rs-async-zip-c909fda63fcafe4af496a07bfda28a5aae97e58d.tar.gz -/uv-0.5.3.tar.gz -/pubgrub-57afc831bf2551f164617a10383cf288bf5d190d.tar.gz -/uv-0.5.4.tar.gz -/uv-0.5.5.tar.gz -/pubgrub-9cd9049a64c7352de2ff3b525b9ae36421b0cc18.tar.gz -/uv-0.5.6.tar.gz -/pubgrub-57832d0588fbb7aab824813481104761dc1c7740.tar.gz -/uv-0.5.7.tar.gz -/uv-0.5.8.tar.gz -/uv-0.5.9.tar.gz -/uv-0.5.10.tar.gz -/pubgrub-05e8d12cea8d72c6d2d017900e478d0abd28fef4.tar.gz -/uv-0.5.11.tar.gz -/uv-0.5.12.tar.gz -/pubgrub-648aa343486e5529953153781fc86025c73c4a61.tar.gz -/uv-0.5.13.tar.gz -/uv-0.5.14.tar.gz -/uv-0.5.15.tar.gz -/uv-0.5.16.tar.gz -/uv-0.5.17.tar.gz -/uv-0.5.18.tar.gz -/uv-0.5.19.tar.gz -/uv-0.5.20.tar.gz -/uv-0.5.21.tar.gz -/uv-0.5.22.tar.gz -/uv-0.5.23.tar.gz -/uv-0.5.24.tar.gz -/uv-0.5.25.tar.gz -/uv-0.5.26.tar.gz -/uv-0.5.27.tar.gz -/pubgrub-b70cf707aa43f21b32f3a61b8a0889b15032d5c4.tar.gz -/tokio-tar-ba2b140f27d081c463335f0d68b5f8df8e6c845e.tar.gz -/uv-0.5.28.tar.gz -/tokio-tar-efeaea927c7a40ee66121de2e1bebfd5d7a4a602.tar.gz -/uv-0.5.29.tar.gz -/uv-0.5.30.tar.gz -/uv-0.5.31.tar.gz -/uv-0.6.0.tar.gz -/uv-0.6.1.tar.gz -/uv-0.6.2.tar.gz -/uv-0.6.3.tar.gz -/uv-0.6.4.tar.gz -/uv-0.6.5.tar.gz -/uv-0.6.6.tar.gz -/uv-0.6.7.tar.gz -/uv-0.6.8.tar.gz -/uv-0.6.9.tar.gz -/uv-0.6.10.tar.gz -/uv-0.6.11.tar.gz -/uv-0.6.12.tar.gz -/uv-0.6.13.tar.gz -/uv-0.6.14.tar.gz -/uv-0.6.16.tar.gz -/uv-0.6.17.tar.gz -/pubgrub-a3b4db3abb1829ce889fb89fa6d157fef529ef7e.tar.gz -/uv-0.7.0.tar.gz -/uv-0.7.1.tar.gz -/uv-0.7.2.tar.gz -/uv-0.7.3.tar.gz -/uv-0.7.4.tar.gz -/pubgrub-73d6ecf5a4e4eb1c754b8c3255c4d31bdc266fdb.tar.gz -/uv-0.7.5.tar.gz -/uv-0.7.6.tar.gz -/uv-0.7.8.tar.gz -/pubgrub-06ec5a5f59ffaeb6cf5079c6cb184467da06c9db.tar.gz -/uv-0.7.9.tar.gz -/uv-0.7.10.tar.gz -/uv-0.7.11.tar.gz -/uv-0.7.12.tar.gz -/uv-0.7.13.tar.gz -/uv-0.7.14.tar.gz -/reqwest-middleware-ad8b9d332d1773fde8b4cd008486de5973e0a3f8.tar.gz -/uv-0.7.15.tar.gz -/uv-0.7.16.tar.gz -/uv-0.7.17.tar.gz -/uv-0.7.18.tar.gz -/uv-0.7.19.tar.gz -/uv-0.7.20.tar.gz -/uv-0.7.21.tar.gz -/uv-0.7.22.tar.gz -/uv-0.8.0.tar.gz -/uv-0.8.1.tar.gz -/uv-0.8.2.tar.gz -/uv-0.8.3.tar.gz -/uv-0.8.4.tar.gz -/uv-0.8.5.tar.gz -/uv-0.8.6.tar.gz -/rs-async-zip-285e48742b74ab109887d62e1ae79e7c15fd4878.tar.gz -/uv-0.8.7.tar.gz -/uv-0.8.8.tar.gz -/uv-0.8.9.tar.gz -/uv-0.8.10.tar.gz -/uv-0.8.11.tar.gz -/uv-0.8.12.tar.gz -/tokio-tar-f1488188f1d1b54a73eb0c42a8b8f4b9ee87d688.tar.gz -/uv-0.8.13.tar.gz -/uv-0.8.14.tar.gz -/uv-0.8.15.tar.gz -/reqwest-middleware-7650ed76215a962a96d94a79be71c27bffde7ab2.tar.gz -/uv-0.8.16.tar.gz -/uv-0.8.17.tar.gz -/uv-0.8.18.tar.gz -/uv-0.8.19.tar.gz -/uv-0.8.20.tar.gz -/pubgrub-d8efd77673c9a90792da9da31b6c0da7ea8a324b.tar.gz -/uv-0.8.21.tar.gz -/uv-0.8.22.tar.gz -/uv-0.8.23.tar.gz -/uv-0.8.24.tar.gz -/uv-0.9.0.tar.gz -/uv-0.9.1.tar.gz -/uv-0.9.2.tar.gz -/uv-0.9.3.tar.gz -/uv-0.9.4.tar.gz -/uv-0.9.5.tar.gz -/uv-0.9.6.tar.gz -/rs-async-zip-f6a41d32866003c868d03ed791a89c794f61b703.tar.gz -/uv-0.9.7.tar.gz -/uv-0.9.8.tar.gz -/uv-0.9.9.tar.gz -/uv-0.9.10.tar.gz -/uv-0.9.11.tar.gz -/uv-0.9.12.tar.gz -/uv-0.9.13.tar.gz -/uv-0.9.14.tar.gz -/uv-0.9.15.tar.gz -/uv-0.9.16.tar.gz -/uv-0.9.17.tar.gz -/uv-0.9.18.tar.gz -/uv-0.9.20.tar.gz -/uv-0.9.21.tar.gz -/uv-0.9.22.tar.gz -/uv-0.9.26.tar.gz -/uv-0.9.27.tar.gz -/uv-0.9.28.tar.gz -/uv-0.9.29.tar.gz -/uv-0.9.30.tar.gz -/uv-0.10.0.tar.gz -/uv-0.10.1.tar.gz -/uv-0.10.2.tar.gz -/uv-0.10.3.tar.gz -/uv-0.10.4.tar.gz -/uv-0.10.5.tar.gz -/uv-0.10.6.tar.gz -/uv-0.10.7.tar.gz -/uv-0.10.8.tar.gz -/uv-0.10.9.tar.gz -/uv-0.10.10.tar.gz -/uv-0.10.11.tar.gz -/uv-0.10.12.tar.gz -/uv-0.11.2.tar.gz -/uv-0.11.4.tar.gz -/uv-0.11.5.tar.gz -/uv-0.11.6.tar.gz -/uv-0.11.7.tar.gz -/uv-0.11.9.tar.gz -/uv-0.11.10.tar.gz -/uv-0.11.11.tar.gz +/uv-*.tar.gz diff --git a/20174.patch b/20174.patch new file mode 100644 index 0000000..2ae827b --- /dev/null +++ b/20174.patch @@ -0,0 +1,170 @@ +From c77c2abf16c13b3ef26fae52b6bec97a7abad65b Mon Sep 17 00:00:00 2001 +From: "Benjamin A. Beasley" +Date: Tue, 7 Jul 2026 06:57:19 +0100 +Subject: [PATCH 1/4] Add BSD-3-Clause LICENSE file to ecosystem/jupyterlab + +https://github.com/jupyterlab/jupyterlab/raw/refs/tags/v4.6.1/LICENSE +--- + test/ecosystem/jupyterlab/LICENSE | 27 +++++++++++++++++++++++++++ + 1 file changed, 27 insertions(+) + create mode 100644 test/ecosystem/jupyterlab/LICENSE + +diff --git a/test/ecosystem/jupyterlab/LICENSE b/test/ecosystem/jupyterlab/LICENSE +new file mode 100644 +index 0000000000000..c73604f78a1f6 +--- /dev/null ++++ b/test/ecosystem/jupyterlab/LICENSE +@@ -0,0 +1,27 @@ ++Copyright (c) 2015-2025 Project Jupyter Contributors ++All rights reserved. ++ ++Redistribution and use in source and binary forms, with or without ++modification, are permitted provided that the following conditions are met: ++ ++1. Redistributions of source code must retain the above copyright notice, this ++ list of conditions and the following disclaimer. ++ ++2. Redistributions in binary form must reproduce the above copyright notice, ++ this list of conditions and the following disclaimer in the documentation ++ and/or other materials provided with the distribution. ++ ++3. Neither the name of the copyright holder nor the names of its ++ contributors may be used to endorse or promote products derived from ++ this software without specific prior written permission. ++ ++THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" ++AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE ++IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE ++DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE ++FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL ++DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER ++CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, ++OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE ++OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +From 0561c227905e972b0d415b0170053ce6ec278184 Mon Sep 17 00:00:00 2001 +From: "Benjamin A. Beasley" +Date: Tue, 7 Jul 2026 06:58:21 +0100 +Subject: [PATCH 2/4] Add BSD-3-Clause LICENSE file to ecosystem/pandas + +https://github.com/pandas-dev/pandas/raw/refs/tags/v3.0.4/LICENSE +--- + test/ecosystem/pandas/LICENSE | 31 +++++++++++++++++++++++++++++++ + 1 file changed, 31 insertions(+) + create mode 100644 test/ecosystem/pandas/LICENSE + +diff --git a/test/ecosystem/pandas/LICENSE b/test/ecosystem/pandas/LICENSE +new file mode 100644 +index 0000000000000..bd1cc2a30c626 +--- /dev/null ++++ b/test/ecosystem/pandas/LICENSE +@@ -0,0 +1,31 @@ ++BSD 3-Clause License ++ ++Copyright (c) 2008-2011, AQR Capital Management, LLC, Lambda Foundry, Inc. and PyData Development Team ++All rights reserved. ++ ++Copyright (c) 2011-2026, Open source contributors. ++ ++Redistribution and use in source and binary forms, with or without ++modification, are permitted provided that the following conditions are met: ++ ++* Redistributions of source code must retain the above copyright notice, this ++ list of conditions and the following disclaimer. ++ ++* Redistributions in binary form must reproduce the above copyright notice, ++ this list of conditions and the following disclaimer in the documentation ++ and/or other materials provided with the distribution. ++ ++* Neither the name of the copyright holder nor the names of its ++ contributors may be used to endorse or promote products derived from ++ this software without specific prior written permission. ++ ++THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" ++AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE ++IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE ++DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE ++FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL ++DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER ++CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, ++OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE ++OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +From d21662e1800682b4058dac8bb39079620eb21400 Mon Sep 17 00:00:00 2001 +From: "Benjamin A. Beasley" +Date: Tue, 7 Jul 2026 06:59:25 +0100 +Subject: [PATCH 3/4] Add MIT LICENSE file to ecosystem/poetry + +https://github.com/python-poetry/poetry/raw/refs/tags/2.4.1/LICENSE +--- + test/ecosystem/poetry/LICENSE | 20 ++++++++++++++++++++ + 1 file changed, 20 insertions(+) + create mode 100644 test/ecosystem/poetry/LICENSE + +diff --git a/test/ecosystem/poetry/LICENSE b/test/ecosystem/poetry/LICENSE +new file mode 100644 +index 0000000000000..81a8e1e473986 +--- /dev/null ++++ b/test/ecosystem/poetry/LICENSE +@@ -0,0 +1,20 @@ ++Copyright (c) 2018-present Sébastien Eustace ++ ++Permission is hereby granted, free of charge, to any person obtaining ++a copy of this software and associated documentation files (the ++"Software"), to deal in the Software without restriction, including ++without limitation the rights to use, copy, modify, merge, publish, ++distribute, sublicense, and/or sell copies of the Software, and to ++permit persons to whom the Software is furnished to do so, subject to ++the following conditions: ++ ++The above copyright notice and this permission notice shall be ++included in all copies or substantial portions of the Software. ++ ++THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, ++EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF ++MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND ++NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE ++LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION ++OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION ++WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. + +From 708d1e5dfaaaee539308d60dbbfc0faa186885fd Mon Sep 17 00:00:00 2001 +From: "Benjamin A. Beasley" +Date: Tue, 7 Jul 2026 07:06:54 +0100 +Subject: [PATCH 4/4] Add MIT LICENSE file to ecosystem/semantic-kernel + +https://github.com/microsoft/semantic-kernel/raw/refs/tags/python-1.43.1/python/LICENSE +--- + test/ecosystem/semantic-kernel/LICENSE | 21 +++++++++++++++++++++ + 1 file changed, 21 insertions(+) + create mode 100644 test/ecosystem/semantic-kernel/LICENSE + +diff --git a/test/ecosystem/semantic-kernel/LICENSE b/test/ecosystem/semantic-kernel/LICENSE +new file mode 100644 +index 0000000000000..9e841e7a26e4e +--- /dev/null ++++ b/test/ecosystem/semantic-kernel/LICENSE +@@ -0,0 +1,21 @@ ++ MIT License ++ ++ Copyright (c) Microsoft Corporation. ++ ++ Permission is hereby granted, free of charge, to any person obtaining a copy ++ of this software and associated documentation files (the "Software"), to deal ++ in the Software without restriction, including without limitation the rights ++ to use, copy, modify, merge, publish, distribute, sublicense, and/or sell ++ copies of the Software, and to permit persons to whom the Software is ++ furnished to do so, subject to the following conditions: ++ ++ The above copyright notice and this permission notice shall be included in all ++ copies or substantial portions of the Software. ++ ++ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR ++ IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, ++ FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE ++ AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER ++ LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, ++ OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE ++ SOFTWARE diff --git a/sources b/sources index 3baf061..ce4d7d8 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.11.tar.gz) = f9129868fb8d343d63e4080deb0e71e71fdb5c71e2ea4f17d05d0f0c20338daf86f521895e8bd69795ffad36ddc94e8cf5ee8fbbb4eb5fdc0692524b21eef9c6 +SHA512 (uv-0.12.3.tar.gz) = a4933b9b9b852dee2485800ad82ee3be111a4a5a437ab32d5064cfd4004e124ba733294a546a097379c74cf1fc234d1da0488aec7725037c7b967ec1aa862a71 diff --git a/uv-0.12.1-revert-blake2-beta.patch b/uv-0.12.1-revert-blake2-beta.patch new file mode 100644 index 0000000..805ef98 --- /dev/null +++ b/uv-0.12.1-revert-blake2-beta.patch @@ -0,0 +1,11 @@ +diff -Naur uv-0.12.1-original/crates/uv-extract/src/hash.rs uv-0.12.1/crates/uv-extract/src/hash.rs +--- uv-0.12.1-original/crates/uv-extract/src/hash.rs 2026-07-31 20:05:57.000000000 +0100 ++++ uv-0.12.1/crates/uv-extract/src/hash.rs 2026-08-02 11:53:13.406289238 +0100 +@@ -1,4 +1,6 @@ +-use sha2::{Digest, digest::consts::U32}; ++// BLAKE2 still uses the `digest` 0.10 trait, while MD5 and SHA-2 use 0.11. ++use blake2::digest::{Digest as _, consts::U32}; ++use sha2::Digest; + use std::pin::Pin; + use std::task::{Context, Poll}; + use tokio::io::{AsyncReadExt, ReadBuf}; diff --git a/uv.spec b/uv.spec index cd80104..3583aa3 100644 --- a/uv.spec +++ b/uv.spec @@ -1,17 +1,11 @@ %bcond check 1 -# Should we run integration tests, many of which require specific Python -# interpreter versions (major.minor, not major.minor.patch)? This adds a few -# dozen tests, but adds BuildRequires on more Pythons, and could reduce our -# confidence that everything works correctly in an environment that only has -# the main system Python. -# -# EPEL10 does not have alternative versions of Python, so we cannot run most of -# the integration tests there, and manually selecting those we can run would be -# far too tedious. -%bcond it %{undefined el10} +# Should we run tests that require specific Python interpreter versions +# (major.minor, not major.minor.patch)? This adds a few dozen tests, but adds +# BuildRequires on more Python interpreters (which aren’t available in EPEL). +%bcond other_python_versions %{undefined epel} Name: uv -Version: 0.11.11 +Version: 0.12.3 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -51,6 +45,7 @@ Summary: An extremely fast Python package installer and resolver, written # MIT # - crates/uv-virtualenv/src/activator/ is vendored and forked from # python3dist(virtualenv) +# - crates/uv-netrc/ is vendored from crate(rust-netrc) # # Additionally, the following are bundled/forked but happen to be under the # same (Apache-2.0 OR MIT) terms as uv itself: @@ -71,12 +66,16 @@ Summary: An extremely fast Python package installer and resolver, written # BSD-2-Clause-Patent: # - test/ecosystem/github-wikidata-bot/ # BSD-3-Clause: +# - test/ecosystem/jupyterlab/ +# - test/ecosystem/pandas/ # - test/ecosystem/saleor/ # MIT: # - crates/uv-python/fetch-download-metadata.py is derived from # https://github.com/mitsuhiko/rye/tree/f9822267a7f00332d15be8551f89a212e7bc9017 # which was MIT. # - test/ecosystem/black/ +# - test/ecosystem/poetry/ +# - test/ecosystem/semantic-kernel/ # # Rust crates compiled into the executable contribute additional license terms. # To obtain the following list of licenses, build the package and note the @@ -103,6 +102,7 @@ Summary: An extremely fast Python package installer and resolver, written # ISC # LGPL-3.0-or-later OR MPL-2.0 # MIT +# MIT AND (MIT OR Apache-2.0) # MIT OR Apache-2.0 # MIT OR LGPL-3.0-or-later # MIT OR Zlib OR Apache-2.0 @@ -112,35 +112,33 @@ Summary: An extremely fast Python package installer and resolver, written # Unicode-3.0 # Unlicense OR MIT # Zlib -# bzip2-1.0.6 License: %{shrink: - 0BSD AND - (0BSD OR Apache-2.0 OR MIT) AND - Apache-2.0 AND - (Apache-2.0 OR BSD-2-Clause) AND - (Apache-2.0 OR BSD-2-Clause OR MIT) AND - (Apache-2.0 OR BSL-1.0) AND - (Apache-2.0 OR ISC OR MIT) AND - (Apache-2.0 OR MIT) AND - (Apache-2.0 OR MIT OR Zlib) AND - (Apache-2.0 OR MIT-0) AND - (Apache-2.0 WITH LLVM-exception) AND - (Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT) AND - BSD-3-Clause AND - CC0-1.0 AND - CDLA-Permissive-2.0 AND - ISC AND - (LGPL-3.0-or-later OR MIT) AND - (LGPL-3.0-or-later OR MPL-2.0) AND - MIT AND - MIT-0 AND - (MIT OR Unlicense) AND - MPL-2.0 AND - Unicode-3.0 AND - Unicode-DFS-2016 AND - Zlib AND - bzip2-1.0.6 - } + 0BSD AND + (0BSD OR Apache-2.0 OR MIT) AND + Apache-2.0 AND + (Apache-2.0 OR BSD-2-Clause) AND + (Apache-2.0 OR BSD-2-Clause OR MIT) AND + (Apache-2.0 OR BSL-1.0) AND + (Apache-2.0 OR ISC OR MIT) AND + (Apache-2.0 OR MIT) AND + (Apache-2.0 OR MIT OR Zlib) AND + (Apache-2.0 OR MIT-0) AND + (Apache-2.0 WITH LLVM-exception) AND + (Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT) AND + BSD-3-Clause AND + CC0-1.0 AND + CDLA-Permissive-2.0 AND + ISC AND + (LGPL-3.0-or-later OR MIT) AND + (LGPL-3.0-or-later OR MPL-2.0) AND + MIT AND + MIT-0 AND + (MIT OR Unlicense) AND + MPL-2.0 AND + Unicode-3.0 AND + Unicode-DFS-2016 AND + Zlib + } # LICENSE.dependencies contains a full license breakdown URL: https://github.com/astral-sh/uv Source0: %{url}/archive/%{version}/uv-%{version}.tar.gz @@ -153,6 +151,16 @@ Source1: uv.toml # Should uv.find_uv_bin() be able to find /usr/bin/uv? # https://github.com/astral-sh/uv/issues/4451 Patch: 0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch +# Downstream-only: revert source-code changes from “Upgrade BLAKE2 to unify +# hashing digest versions”, https://github.com/astral-sh/uv/pull/20834. We do +# not wish to upgrade rust-blake2 to a pre-release. +Patch: uv-0.12.1-revert-blake2-beta.patch +# Add license texts for new contents of test/ecosystem/ from PR#20068 +# https://github.com/astral-sh/uv/pull/20174 +Patch: %{url}/pull/20174.patch + +BuildSystem: pyproject +BuildOption(install): --assert-license uv # https://fedoraproject.org/wiki/Changes/EncourageI686LeafRemoval ExcludeArch: %{ix86} @@ -166,24 +174,28 @@ ExcludeArch: %{ix86} # https://doc.rust-lang.org/rustc/codegen-options/index.html#debuginfo %global rustflags_debuginfo 1 -# As a separate limitation, memory exhaustion can occur on builders with very -# many CPUs. Typical workspace crates peak out at 2-4 GB per rustc invocation. -# The uv crate needs much more memory to compile and link, but in practice it -# is also compiled alone after all the other crates have finished, so it does -# not need to influence (and does not benefit from) this setting. This setting -# does not necessarily have to reflect the maximum memory required to compile a -# workspace crate; keeping it well above the average suffices in practice on -# many-core systems. Increase as needed. -%global _smp_tasksize_proc 4096 +# As a separate limitation, memory exhaustion (OOM) can occur during parallel +# portions of the build. +# - Because very many workspace crates can be built in parallel, builders with +# a very large number of CPUs may OOM. Typical workspace crates peak out at +# roughly 2–4 GB per rustc process. +# - The uv crate needs much more memory to compile and link, at least 8 GB, and +# when building the tests we may be building bin and lib versions at the same +# time, along with the it (integration test) crate, which is also rather +# large. This is a problem for “low memory” builders (<20 GB or so). +# Unfortunately, this means that we need to scale the memory per task based on +# the memory requirements of the top-level uv crate in order to avoid OOM on +# all kinds of builders. +%global _smp_tasksize_proc 10240 # Compilation may fail on builders with very many cores (e.g. 192 cores) due to # “too many open files.” Try to keep the files/core ratio from getting too low. -%global _smp_ncpus_max 72 +%global _smp_ncpus_max 48 -BuildRequires: cargo-rpm-macros >= 24 +BuildRequires: cargo-rpm-macros BuildRequires: rust2rpm-helper BuildRequires: tomcli -%if %{with check} && %{with it} +%if %{with check} && %{with other_python_versions} # See trove classifiers in pyproject.toml for supported Pythons. BuildRequires: /usr/bin/python3.9 BuildRequires: /usr/bin/python3.10 @@ -263,6 +275,19 @@ Provides: bundled(crate(r-shquote)) = 0.1.1 # appear to be any prospect of unbundling. Provides: bundled(crate(keyring)) = 4.0.0~rc2 +# crates/uv-netrc +# From crates/uv-netrc/README.md, “This crate vendors the rust-netrc parser for +# use by uv. The source was vendored from gribouille/netrc, as published in +# rust-netrc 0.1.2[…]” +# +# Upstream justifies the bundling in +# https://github.com/astral-sh/uv/pull/19409: they want unreleased bug fixes, +# including those pertaining to https://github.com/astral-sh/uv/issues/16083, +# and to avoid a dependency on thiserror v1. In response to the mandatory +# query, they report they are open to de-vendoring if a new rust-netrc release +# with the desired changes appears. +Provides: bundled(crate(rust-netrc)) = 0.1.2 + # The contents of crates/uv-virtualenv/src/activator/ are a bundled and # slightly forked copy of a subset of https://pypi.org/project/virtualenv; see # https://github.com/pypa/virtualenv/tree/main/src/virtualenv/activation. @@ -348,32 +373,36 @@ Requires: uv = %{version}-%{release} This package provides an importable Python module for uv. -%prep -%autosetup -p1 - -# Collect license files of vendored dependencies in the main source archive -install -t LICENSE.bundled/packaging -D -p -m 0644 \ +%prep -a +# Collect license files of vendored dependencies +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/packaging \ crates/uv-python/python/packaging/LICENSE.* -install -t LICENSE.bundled/pep440_rs -D -p -m 0644 crates/uv-pep440/License-* -install -t LICENSE.bundled/pep508_rs -D -p -m 0644 crates/uv-pep508/License-* -install -t LICENSE.bundled/pipreqs -D -p -m 0644 \ +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/pep440_rs crates/uv-pep440/License-* +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/pep508_rs crates/uv-pep508/License-* +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/pipreqs \ crates/uv-build-frontend/src/pipreqs/LICENSE -install -t LICENSE.bundled/ripunzip -D -p -m 0644 \ - crates/uv-extract/src/vendor/LICENSE +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/ripunzip crates/uv-extract/src/vendor/LICENSE +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/rust-netrc crates/uv-netrc/LICENSE # The original license text from rattler_installs_packages is present in a # comment, but we want it in a separate file so we can ensure it is present in # the binary RPM. -install -d LICENSE.bundled/rattler_installs_packages +install --directory LICENSE.bundled/rattler_installs_packages awk '$2 == "BSD" { out=1 }; $2 == "```" { out=0 }; out' \ crates/uv-client/src/remote_metadata.rs | - sed -r 's@^///( |$)@@' | + sed --regexp-extended 's@^///( |$)@@' | tee LICENSE.bundled/rattler_installs_packages/LICENSE # Similarly for virtualenv. All files in # crates/uv-virtualenv/src/activator/activate/ have the same license text. -install -d LICENSE.bundled/virtualenv +install --directory LICENSE.bundled/virtualenv awk '$1 == "#" { out=1 }; $1 != "#" { out=0; exit }; out' \ crates/uv-virtualenv/src/activator/activate | - sed -r 's@^#( |$)@@' | + sed --regexp-extended 's@^#( |$)@@' | tee LICENSE.bundled/virtualenv/LICENSE # Patch out foreign (e.g. Windows-only) dependencies. Follow symbolic links so @@ -387,20 +416,20 @@ find -L . -type f -name Cargo.toml -print \ # the uv-trampoline-builder crate. We must remove them to prove they are not # used in the build. Since they are used only on Windows, nothing is lost by # doing so. -rm -v crates/uv-trampoline-builder/trampolines/*.exe +rm --verbose crates/uv-trampoline-builder/trampolines/*.exe # Per Cargo.toml, uv-trampoline is excluded from the workspace and not compiled # because it still requires a nightly compiler. For now, we remove it entirely # to show that we do not need to document bundling from posy. Note that we # *cannot* cleanly remove uv-trampoline-builder, only the precompiled # trampolines themselves. -rm -rv crates/uv-trampoline +rm --recursive --verbose crates/uv-trampoline # Remove the dependency on embed-manifest, which applies only when (cross-?) # compiling for Windows. tomcli set Cargo.toml del workspace.dependencies.embed-manifest # We may have to do something more sophisticated if this build script ever # starts to do anything other than just embedding a manifest on Windows. -rm -v crates/uv/build.rs +rm --verbose crates/uv/build.rs tomcli set crates/uv/Cargo.toml del build-dependencies.embed-manifest # The embed-manifest depenency is also used in uv-trampoline, which we removed. @@ -416,14 +445,6 @@ tomcli set Cargo.toml append workspace.exclude crates/uv-bench # needed here. It also brings extra dependencies that we would prefer to avoid. tomcli set Cargo.toml append workspace.exclude crates/uv-dev -# Do not request static linking of anything (particularly, liblzma) -tomcli set Cargo.toml lists delitem \ - workspace.dependencies.xz2.features 'static' -tomcli set crates/uv/Cargo.toml lists delitem \ - features.default 'uv-distribution/static' -tomcli set crates/uv-distribution/Cargo.toml del features.static -tomcli set crates/uv-extract/Cargo.toml del features.static - # Disable several default features that control which tests are compiled and # executed, and which are not usable in offline builds: # @@ -453,23 +474,41 @@ tomcli set crates/uv/Cargo.toml lists delitem features.test-defaults \ tomcli set crates/uv-audit/Cargo.toml lists delitem features.default \ 'test-(osv)' -%if %{without it} -# Integration tests (it crate) nearly all require specific Python interpreter -# versions (major.minor, not major.minor.patch, unless the python-patch feature -# is enabled). We might choose to disable this in order to double-check that -# everything else works well with only the primary system Python in the -# environment. +%if %{without other_python_versions} +# Many of these tests require specific Python versions (major.minor, not +# major.minor.patch, unless the python-patch feature is enabled). Manually +# selecting the tests in these modules that would succeed with just the system +# Python would be far too tedious. +omit_modules() { + set -o nounset + set -o errexit + main_module="${1}" + commented_modules='' + comment='Downstream-only: skip, needs specific Python interpreter versions' + shift + while [ "${#}" != 0 ] + do + commented_modules="${commented_modules-}${commented_modules+|}${1}" + shift + done + sed --regexp-extended --in-place \ + "s@mod (${commented_modules});@// ${comment}\n#[cfg(any())]\n&@" \ + "${main_module}" +} +# -p uv --test build +omit_modules crates/uv/tests/build/main.rs build_backend # -p uv --test it: -mods="${mods-}${mods+|}branching_urls" -mods="${mods-}${mods+|}build_backend" -mods="${mods-}${mods+|}pip_(check|list|show|tree|uninstall)" -mods="${mods-}${mods+|}python_(dir|find|install|list|pin)" -mods="${mods-}${mods+|}venv" -mods="${mods-}${mods+|}version" -mods="${mods-}${mods+|}workspace" -comment='Downstream-only: skip, needs specific Python interpreter versions' -sed -r -i "s@mod (${mods});@// ${comment}\n#[cfg(any())]\n&@" \ - crates/uv/tests/it/main.rs +omit_modules crates/uv/tests/it/main.rs \ + auth branching_urls network upgrade version +# -p uv --test python: +omit_modules crates/uv/tests/python/main.rs \ + 'python_(dir|find|install|list|pin)' venv +# -p uv --test workspace: +omit_modules crates/uv/tests/workspace/main.rs \ + workspace 'workspace_(dir|list|metadata)' +# -p uv --test pip: +omit_modules crates/uv/tests/pip/main.rs \ + 'pip_(debug|list|show|tree|uninstall)' %endif # For unclear reasons, maturin checks for the presence of optional crate @@ -490,10 +529,29 @@ tomcli set crates/uv/Cargo.toml del dependencies.tracing-durations-export # # https://bugzilla.redhat.com/show_bug.cgi?id=1234567 # tomcli set Cargo.toml str workspace.dependencies.foocrate.version 0.1.2 +# tikv-jemallocator +# wanted: 0.6.0 +# currently packaged: 0.7.0 +# https://github.com/astral-sh/uv/pull/19735 +# We use sed instead of tomcli because the target.cfg(…) expression is a +# *mess*, and we don’t want to have to write it out here. +sed --regexp-extended --in-place \ + 's/^(tikv-jemallocator\b.*version = ")0\.6\.0"/\1>=0.6.0, <0.8.0"/' \ + crates/uv-performance-memory-allocator/Cargo.toml + +# blake2 +# wanted: 0.11.0-rc.6 +# currently packaged: 0.10.6 +# https://github.com/astral-sh/uv/pull/19735 +# Downstream-only: revert “Upgrade BLAKE2 to unify hashing digest versions”, +# https://github.com/astral-sh/uv/pull/20834. We do not wish to upgrade +# rust-blake2 to a pre-release. There is an anccompanying source-code patch. +tomcli set Cargo.toml str workspace.dependencies.blake2.version 0.10.6 + %cargo_prep -%generate_buildrequires +%generate_buildrequires -p # For unclear reasons, maturin checks for all crate dependencies when it is # invoked as part of %%pyproject_buildrequires – including those corresponding # to optional features. @@ -505,20 +563,14 @@ tomcli set crates/uv/Cargo.toml del dependencies.tracing-durations-export # Since maturin always checks for dev-dependencies, we need -t so that they are # generated even when the “check” bcond is disabled. %cargo_generate_buildrequires -a -t -%pyproject_buildrequires -%build -%pyproject_wheel - +%build -a %{cargo_license_summary} %{cargo_license} > LICENSE.dependencies -%install -%pyproject_install -%pyproject_save_files -L uv - +%install -a if [ '%{python3_sitearch}' != '%{python3_sitelib}' ] then # Maturin is really designed to build compiled Python extensions, but (when @@ -526,9 +578,10 @@ then # library is actually pure-Python, and the python3-uv subpackage can be # noarch. We can’t tell maturin to install to the appropriate site-packages # directory, but we can fix the installation path manually. - install -d %{buildroot}%{python3_sitelib} + install --directory %{buildroot}%{python3_sitelib} mv %{buildroot}%{python3_sitearch}/uv* %{buildroot}%{python3_sitelib} - sed -r -i 's@%{python3_sitearch}@%{python3_sitelib}@' %{pyproject_files} + sed --regexp-extended --in-place \ + 's@%{python3_sitearch}@%{python3_sitelib}@' %{pyproject_files} fi # generate and install shell completions @@ -544,10 +597,11 @@ do done # Install a default system-wide configuration file -install -t '%{buildroot}%{_sysconfdir}/uv' -p -m 0644 -D '%{SOURCE1}' +install -D --preserve-timestamps --mode=0644 \ + --target='%{buildroot}%{_sysconfdir}/uv' '%{SOURCE1}' -%check +%check -a %if %{with check} # These tests rely on debug assertions, and fail when tests are compiled in # release mode: @@ -558,7 +612,7 @@ skip="${skip-} --skip keyring::tests::fetch_url_with_empty_username" skip="${skip-} --skip keyring::tests::fetch_url_with_no_username" skip="${skip-} --skip keyring::tests::fetch_url_with_password" -%if %{without it} +%if %{without other_python_versions} # These tests require specific Python interpreter versions, which upstream # normally downloads, precompiled, into the build area. skip="${skip-} --skip version::self_version" @@ -580,6 +634,25 @@ skip="${skip-} --skip python_list::python_list_with_mirrors" # This might be worth reporting upstream, but is not a serious issue. skip="${skip-} --skip python_pin::python_pin_resolve" %endif +%ifarch riscv64 +# These expect managed interpreters of the form +# cpython-3.##-linux-riscv64gc-any, but crates/uv-python/download-metadata.json +# only has them for cpython-3.##-linux-riscv64-gnu. It’s not weird to find +# holes in the managed interpreter support matrix for less common +# architectures. +skip="${skip-} --skip python_find::python_find" +skip="${skip-} --skip python_list::python_list" +skip="${skip-} --skip python_pin::python_pin_resolve" +%endif + +# It’s not clear what causes the trivial discrepancy, but we find that this +# fails when building in qemu-user-static emulated chroots. +# 4 │- Caused by: Failed to query Python interpreter at `[TEMP_DIR]/bar` +# 5 │- Caused by: [PERMISSION DENIED] +# 4 │+ Caused by: Querying Python at `[TEMP_DIR]/bar` failed with +# exit status exit status: 127 +skip="${skip-} --skip python_find::python_find_path" + # Test registry_client::tests::test_redirect_to_server_with_credentials is # flaky # https://github.com/astral-sh/uv/issues/16447 @@ -616,6 +689,14 @@ skip="${skip-} --skip tests::built_by_uv_building" # dependency version differing from Cargo.lock. skip="${skip-} --skip base_client::tests::retried_status_codes" +# Harmless and trivial discrepancies in error messages: +# 8 │- Caused by: error decoding response body for url (http://[LOCALHOST]/tqdm/) +# 8 │+ Caused by: error decoding response body +skip="${skip-} --skip network::retry_read_timeout_index" +# 9 │- Caused by: error decoding response body for url (http://[LOCALHOST]/) +# 9 │+ Caused by: error decoding response body +skip="${skip-} --skip network::retry_read_timeout_python_downloads_json" + # These fail flakily: most frequently on ppc64le, but this seems to be just a # matter of luck, since we suspect a race condition. We have also seen failures # on aarch64. This is probably a race involving the SSL_CERT_FILE environment @@ -631,12 +712,17 @@ skip="${skip-} --skip base_client::tests::retried_status_codes" skip="${skip-} --skip user_agent_version::test_user_agent_has_linehaul" skip="${skip-} --skip user_agent_version::test_user_agent_has_subcommand" skip="${skip-} --skip user_agent_version::test_user_agent_has_version" +# Similarly, with an error like: +# Client::new(): reqwest::Error { +# kind: Builder, +# source: General("No CA certificates were loaded from the system") +# } +# There are probably more of these. +skip="${skip-} --skip retry::tests::retried_status_codes" %cargo_test -- -- --exact ${skip-} %endif -%pyproject_check_import - %files %license LICENSE-APACHE LICENSE-MIT LICENSE.dependencies LICENSE.bundled/