fix(runtime): request minor line for SQLite runtime repair + tests

Follow-up on the #70186 salvage. The cherry-picked repair pinned the
candidate to the exact current CPython patch (e.g. 3.11.14). Verified
live with uv 0.11.19: every published python-build-standalone artifact
for 3.11.14 links vulnerable SQLite 3.50.4 — even with --reinstall — so
the exact-patch pin made the repair permanently impossible on the
installs that need it most (repair_vulnerable_runtime returned
'failed: could not provision a fixed private Python runtime').

Request the minor line (3.11) instead — the same resolution a fresh
'uv python install' would make, still inside requires-python — and
tighten the drift gate to 'same minor, no downgrade'. E2E-verified
end-to-end on a real vulnerable venv: repair_vulnerable_runtime()
provisioned 3.11.15, built + smoke-tested the sibling venv, cut over,
and reported SQLite 3.50.4 → 3.53.1 with the old venv parked for
rollback.
This commit is contained in:
teknium1
2026-07-24 12:44:30 -07:00
committed by Teknium
parent 05a799e41c
commit be633c1c33
2 changed files with 95 additions and 5 deletions
+16 -5
View File
@@ -351,8 +351,17 @@ def _make_world_traversable(path: Path) -> None:
def _runtime_request(info: SQLiteRuntimeInfo) -> str:
"""Pin the candidate to the current exact CPython patch."""
return ".".join(str(part) for part in info.python_version)
"""Pin the candidate to the current CPython minor line (e.g. ``3.11``).
Requesting the exact patch can never repair some installs: for a given
patch, python-build-standalone may have no artifact with fixed SQLite at
all (e.g. every published 3.11.14 build links SQLite 3.50.4; the fix
only exists from 3.11.15). A newer patch on the same minor is what
``uv python install`` would resolve for a fresh install, stays inside
``requires-python``, and the locked ``uv sync`` + import smoke tests gate
compatibility before any cutover.
"""
return ".".join(str(part) for part in info.python_version[:2])
def _install_safe_python_generation(
@@ -438,10 +447,12 @@ def _install_safe_python_generation(
logger.warning("could not probe candidate Python runtime: %s", python)
_remove_tree(generation, boundary=python_root)
return None
if candidate.python_version != current.python_version:
if candidate.python_version[:2] != current.python_version[:2] or (
candidate.python_version < current.python_version
):
logger.warning(
"candidate Python patch drifted from %s to %s",
current.python_version,
"candidate Python drifted off the %s minor line or downgraded: %s",
".".join(str(p) for p in current.python_version[:2]),
candidate.python_version,
)
_remove_tree(generation, boundary=python_root)