`lc init` pins `.python-version` to the exact interpreter running lc, and
the image build installs that pin with the uv copied from `UV_IMAGE`.
setup-uv gives CI the newest patch of each line, and since 2026-10-02
those are 3.11.17 and 3.13.16, which uv 0.12.5 does not know: every
container smoke test fails with "No download found for request:
cpython-3.13.16-linux-x86_64-gnu". uv 0.12.22 is the first release that
knows them.
The digest is the manifest list's (amd64 and arm64), read from ghcr's
registry API and checked by hashing the index body; the same method
reproduces the previous 0.12.5 pin exactly.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The container smoke tests have failed on every branch since 2026-10-02 (#245,
fix/sandbox-elf-interpreter,smoke-findings) with:Why
lc initpins.python-versionto the exact interpreter running lc. The image build then installs that pin with the uv copied fromUV_IMAGE. setup-uv gives CI the newest patch of each Python line, which since 2026-10-02 means 3.11.17 and 3.13.16. The pinned uv 0.12.5 predates both. The 3.12 job only passed because 3.12.14 is still known; 3.12.15 is out and would have broken it next.Change
UV_IMAGE→ghcr.io/astral-sh/uv:0.12.23@sha256:61d393e44e249f2e4b526b6c7ddcecce245946826e608e11c93ad4f5bba55b21.linux/amd64andlinux/arm64. I read it from ghcr's registry API and confirmed it by hashing the index body. The same method reproduces the old 0.12.5 pin (e85be844…) exactly.Effect on projects
This is an engine constant whose bump is meant to be visible (see the layer-6 invariants in CLAUDE.md):
lc buildrebuilds, and a newenv_version. Existing outputs readbehind; nothing is remade.Verification
tests/test_container_smoke.pyunder Python 3.13.16 (podman): the old pin fails with CI's exact error and image tag (lc-env-712be96723c9091c). The new pin passes all 6, including materialize in the image anddatalad rerunon a clone that starts with no file contents.test_image.py,test_container.py,test_identity.py: 96 passed.Note
This will happen again whenever a Python patch release is newer than the pinned uv: CI moves to the newest patch, and the image's uv does not. This PR only restores CI; a structural fix is a separate decision.
🤖 Generated with Claude Code