{"record":{"id":"0f2d29979d7799c0","repo":"jdx/mise","slug":"unsupported-python-lock-project-settings","errorCode":null,"errorMessage":"unsupported Python lock project settings","messagePattern":"unsupported Python lock project settings","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/backend/pipx/lock.rs","lineNumber":426,"sourceCode":"                })?;\n            for wheel in wheels {\n                let hash = wheel\n                    .get(\"hash\")\n                    .and_then(toml::Value::as_str)\n                    .and_then(|h| h.strip_prefix(\"sha256:\"));\n                if !hash.is_some_and(|h| h.len() == 64 && h.bytes().all(|c| c.is_ascii_hexdigit()))\n                {\n                    bail!(\"{name} has a wheel without a SHA256 hash\");\n                }\n            }\n        }\n        if !root || !virtual_root {\n            bail!(\"Python lock is missing the requested root package\");\n        }\n        validate_portable_urls(&toml::Value::Table(lock.graph.clone()))?;\n        // No arbitrary project settings or build systems are accepted from a lockfile.\n        if lock.project.len() != 1 || project.len() != 4 {\n            bail!(\"unsupported Python lock project settings\");\n        }\n        Ok(())\n    }\n\n    pub(super) async fn install_uv_lock(\n        &self,\n        ctx: &InstallContext,\n        tv: &ToolVersion,\n    ) -> Result<()> {\n        let lock = tv\n            .uv_lock\n            .as_ref()\n            .ok_or_else(|| eyre!(\"missing uv lock\"))?\n            .load()?;\n        self.validate_uv_lock(tv, lock)?;\n        let uv = self.lock_uv_program(&ctx.config).await?;\n        let (python, _) = tv.uv_python.as_ref().ok_or_else(|| {\n            eyre!(","sourceCodeStart":408,"sourceCodeEnd":444,"githubUrl":"https://github.com/jdx/mise/blob/533346cc374382b41ec5ff70536252b2e96e725c/src/backend/pipx/lock.rs#L408-L444","documentation":"As a final guard, validate_uv_lock whitelists lockfile structure: exactly one [project] table and exactly four keys in it (dependencies, name, requires-python, and one more as produced by mise). Any extra project settings or build-system configuration in the lock is treated as untrusted/unsupported and rejected, since arbitrary project settings from a lockfile are never honored.","triggerScenarios":"Thrown from validate_uv_lock when `lock.project.len() != 1` (multiple [project] tables) or the project table's key count != 4 — i.e. the lock contains extra settings or a build system block; via prepare_install_version, resolve_uv_lock, install_uv_lock.","commonSituations":"The mise.lock was produced or merged by other tooling that added [build-system] or extra [project] keys; hand-edits added settings; an older/newer lock schema version; a lock copied from a real project's uv.lock instead of mise-generated one.","solutions":["Regenerate the lock with mise so it emits the canonical single 4-key project table: `mise lock --bump <tool>`.","Remove unsupported keys/tables ([build-system], extra [project] entries) from mise.lock — or better, re-lock instead of editing.","Use mise of a compatible version so the lock schema matches what the validator expects.","If you need custom project/build settings, do it in the package's own project, not in mise's synthetic lock project."],"exampleFix":"// before (mise.lock, extra section)\n[project]\nname = \"mise-pypi-tool-environment\"\ndependencies = [\"ruff==0.9\"]\nrequires-python = \">=3.8\"\n\n[build-system]\nrequires = [\"setuptools\"]\n\n// after: remove extras or regenerate\n$ mise lock --bump <tool>","handlingStrategy":"validation","validationCode":"// sanity-check lock structure before install\nif (lock.project.length !== 1 || Object.keys(lock.project[0]).length !== 4) run('mise lock --bump <tool>');","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Never merge or post-process mise.lock with external tooling","Don't copy a project uv.lock into mise.lock","Regenerate locks with mise instead of editing structure"],"tags":["python","uv","lockfile","whitelist"],"backgroundTag":"unsupported-config-value","analyzedSha":"533346cc374382b41ec5ff70536252b2e96e725c","analyzedAt":"2026-09-17T13:35:38.149Z","contentChangedAt":"2026-09-17T13:35:38.149Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}