Bug hunt ledger: pip / requirements.txt #309
Replies: 6 comments
|
[agent] 2026-09-30: pip / requirements.txt bug-hunt run This is the first run, so the ledger started empty and there were no Tested: main Setup: a local mock patch API (the same shape as the Pipenv, Poetry and Hatch routines) served a patched Cells
Issues
False positives ruled out
Probe runs
I couldn't delete the probe branches: the git proxy hangs up on ref-delete pushes, the same as the siblings. A maintainer should delete Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where pip / requirements.txt puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × pip / requirements.txt version cells for |
|
[agent] 2026-10-01: pip / requirements.txt bug-hunt run Tested: main Re-triageMain hasn't moved since the last run, so #376, #409, #410 and #412 can't have changed. No comments. Cells
Issues
Needs a maintainer decision (not filed)
False positives ruled out
Probe runs
I couldn't delete Next
|
|
[agent] 2026-10-01: pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triage
Cells
Issues
False positives ruled out
Probe runs
I couldn't delete Next
|
|
[agent] 2026-10-01: pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triage
Cells
Issues
False positives ruled out
Probe runs
I couldn't delete Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled pip / requirements.txt bug-hunt routine (label pm:pip).
Last run: 2026-10-01 (fifth run), main
61cfb9b, latest release v4.0.0 (96df6ae). #376 and #447 are fixed on main (verified on all 3 OS).Coverage matrix
-rinclude, lock-only==1.16)-g(--user)--global-prefix, unwritable)pip install/pip sync)--user)Scripts/+Lib/)--user,%APPDATA%\Python)pip 20.3.4 on py3.13 is blocked (no
distutils).setupwas removed in v5, so the old setup column (#377, #378) is retired; both issues are closed.Commands covered on Linux: scan (all modes), get (hosted, agent
-g), rollback, remove, vendored takeover, vex (hosted with the mock origin, vendored,-g), repair, list, concurrent runs. Not yet covered:--jsonenvelopes of rollback / remove failures, interrupted runs.Backlog
six==1.16for an installed 1.16.0, soscanexits 0 and pip installs the unpatched release (regression from v4.0.0) #475 once Fix requirements.txt pins not matched under PEP 440 (#475) #478 merges, then lock-only discovery ofsix==1.16(purlsix@1.16). That needs a mock that mirrors how the real API matches versions.-g) mode. Left: Homebrew / PEP 668 interpreters, py launcher with several interpreters, pipx venvs (Fix global scan missing pipx venvs (#415) #418), non-root unwritable prefixes on CI. Open question for the maintainer: the non--gno-venv fallback to global site-packages (see the 20261001T083942Z entry; it also makes a lock-onlyvexomit packages the system Python has unpatched).pip install --target/--prefixtrees.pip-sync/pip-compile --generate-hashesre-runs over a hosted file.--jsonenvelopes for rollback / remove failures; interrupted runs.--system-site-packagesvenv, pip keeps the base interpreter's unpatched copy after a hosted rewrite, no stale-install warning fires, andvexattests it as patched #409 / Hostedrollback,removeand the vendored takeover refuse a requirements.txt whose only requirements are hosted pins (six==1.16.0alone can be patched but never unpatched) #410 / Lockfile-onlyscanignores pins in requirements.txt-rincludes, so a fresh checkout reports "No patches available" and installs unpatched (hosted and vendored) #412 / Hosted requirements.txt rewrite skips PEP 440-equivalent pins likesix==1.16for an installed 1.16.0, soscanexits 0 and pip installs the unpatched release (regression from v4.0.0) #475 as fixes land.Known non-bugs
requirements.txt; an installed pin reached only through-rgetsredirect_requirements_entry_not_found(vendored follows includes). The lock-only discovery gap is Lockfile-onlyscanignores pins in requirements.txt-rincludes, so a fresh checkout reports "No patches available" and installs unpatched (hosted and vendored) #412.redirect_pypi_stale_install) andvexomits it. The system-site-venv variant is In a--system-site-packagesvenv, pip keeps the base interpreter's unpatched copy after a hosted rewrite, no stale-install warning fires, andvexattests it as patched #409.vexattests from the committed artifact even when a plain venv still holds upstream bytes; it warnsvendored_tree_out_of_sync(documented).Six→six) and normalises spacing before a trailing comment; pip reads both forms the same way.===pins,==X.*wildcards and a tab before--hash(pypi_requirement_not_pinned). This is fail-closed and isn't filed (the==1.16zero-padding case is part of Hosted requirements.txt rewrite skips PEP 440-equivalent pins likesix==1.16for an installed 1.16.0, soscanexits 0 and pip installs the unpatched release (regression from v4.0.0) #475).--vendor-source buildwas removed in v5; vendoring always needs a patch-service artifact.rollbackin agent mode drops the manifest entry, so a laterapplyis a no-op (documented)..venv/venvis only found throughVIRTUAL_ENV.SOCKET_API_TOKENformat warnings and theuv pipHEAD 501 are mock artifacts.vex -ois--org, not--output.vex --jsonrequires--output.scan --mode agentafter a failedget(unwritable target) skips the recorded entry ("already recorded … runsocket-patch apply") and exits 0. This is documented, and the failedgetitself exits 1.vexignores hosted URLs that aren't onpatch.socket.dev. Pass--patch-server-url <mock origin>to attest mock-hosted projects locally.--hashin an otherwise unhashed file stays in that shape on a re-scan (exit 0), so pip still fails in hash mode. This is documented in Fix requirements.txt writers ignoring pip hash mode (#376) #383;socket-patch rollbackthen a re-scan rewrites it to the fragment form (verified).-rtree. That's harmless: in hash mode pip accepts a user-supplied direct URL's#sha256=fragment as its hash (pip 20.3.4–26.0).pip install -rmust run from the project root (documented in CLI_CONTRACT.md).rollbackonly recognises hosted URLs of the shape/patch/pypi/<name>/<ver>/<tok>/<uuid>/<file>; a mock without that path gets "Manifest not found".All reactions