Bug hunt ledger: Poetry #311
Replies: 7 comments
|
[agent] 2026-09-30: Poetry bug-hunt run This is the first run, so the ledger started empty and there were no Tested: main Setup: the sandbox can't reach the Socket patch API (proxy 403), so a local mock API served a real patched Cells
Issues
False positives ruled out
Probe runs
I couldn't delete either probe branch: the git proxy returned HTTP 403 on Next
|
|
[agent] 2026-09-30: Poetry bug-hunt run Tested: main Setup: the vendored cells used a synthetic Re-triage#327, #328 and #329 are still open. The fix for #327/#329 is draft PR #330, not merged. Main hasn't moved, so there was nothing to re-check. Cells
Issues
False positives ruled out
Blocked / environment
Next
|
|
[agent] 2026-10-01: Poetry bug-hunt run Tested: main Setup:
Re-triage
Cells
Issues
False positives ruled out
Observations (not filed)
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Poetry puts global installs: Poetry has no global install; check What to check (prove each with a real global install, not by reading source):
Add OS × Poetry version cells for |
|
[agent] 2026-10-01: Poetry bug-hunt run Tested: main Focus: the maintainer request at the top of the backlog: global ( Re-triageMain is the same commit run 3 re-triaged, so I didn't re-run #327 / #328 / #329. I added new #327 evidence, below. Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: Poetry bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: Poetry bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Poetry bug-hunt routine (label pm:poetry).
Last updated: 2026-10-01 (run 6), main
61cfb9b(includes #330, #446, #452, #456), latest release 4.0.0 (previous 3.3.0).Coverage matrix
Cells are "pass", "fail #N" or "untested". Hosted and vendored cells use a local mock of the patch API (patches-api.socket.dev is blocked from the sandbox) serving a patched
six-1.16.0wheel, then a realpoetry install/poetry syncand a byte check of the installed file. The existingpoetry-compatibility.ymlmatrix (Linux + macOS) covers the plain cells against production. Rows before run 3 were measured on mainf6b7fb9(pre-v5). Run 3 re-measured the cells marked "v5". Run 5 re-measured the cells marked "r5" on6e7ef74(after #330); #327 cells on macOS / Windows still show the pre-fix result because probe branches are blocked..venv)package-mode=false/[project].nameoverride /in-project=false+ stray.venvin-project=true, no.venv, existing out-of-tree envrepair(lock-only, wheel deleted)redirect_poetry_lock_unsupported)[metadata.hashes])jaraco.contextrewrite/install/vex/rollback{cache-dir}/~virtualenvs.path, XDG_CACHE_HOME,.venvsymlink)sync,remove, dry-run,get, relock/add, directory targets)Global mode (
-g/--global-prefix/SOCKET_GLOBAL=1), agent patches (run 4)Global installs aren't Poetry-specific (Poetry never installs globally unless
virtualenvs.create = false), so these cells were run from inside a Poetry 2.1.1 project (in-project.venv) against a realpip install --usercopy and apip install --targetprefix.scan -greport-only (--json): global user-sitesixfound, project.venvand lock-only packages don't leak inscan -gsees Debian/apt.egg-infoinstallsscan -gsees Poetry's official-installer venv (~/.local/share/pypoetry/venv)scan -g --mode hosted,--global-prefix --mode hosted,SOCKET_GLOBAL=1 --mode hosted: exit 2, poetry.lock untouchedscan -g --mode agent, re-run idempotent,get <uuid> -g,SOCKET_GLOBAL=1 get: global copy patched,.venvand lock untouchedvex -gattests applied global patch; plainvexrefuses (not_applied)rollback -grestores the global copy byte for byterollback -g, or-gapply +rollback)61cfb9b, r6)scan -g/create = falseproject scan with the same release in user site and a system dir (apt egg-info or/usr/localdist-info)get -g --mode hosted|vendored,scan -g --mode hosted|vendoredrefuse;rollback -g/remove -gleavepoetry.lockalonevirtualenvs.create = false, single system copyvex -gfrom a hosted, synced Poetry project with an unpatched global copy: refuses (not_applied)list -gfrom a hosted Poetry project lists the project's hosted pin--global-prefix(non-root user, path with space +é): human mode shows the error, exit 1-g, Poetry venv undiscovered / not created yet: falls back to and patches the global interpreterin-project = true+ no.venv(#476, re-confirmed r6 on61cfb9b; now lands in apt's dist-packages)Backlog
~/Library/Python/3.X/...vs Homebrew / python.org framework site-packages). This needs probe branches.realpath), plus hosted/vendored on 2.5.1 and long paths (> 260 chars). This needs probe branches.git push --deletestill fails (runs 1–6). A maintainer needs to deletebughunt/poetry/20260930-venv-discoveryandbughunt/poetry/20260930-windows-modes.VIRTUAL_ENVset whileenvs.tomlhas an entry for the project, condaCONDA_PREFIX, severalpoetry env useminors.socket.ymlpolicy (minSeverity, package filters,maxNewPatches) on a Poetry project with several patches.poetry syncreinstall,scan --mode agentre-applies the recorded patch.Known non-bugs
patches-api.socket.dev/patch.socket.dev/api.socket.devare blocked by the sandbox proxy (403). Use a local mock API (SOCKET_API_URL).vendor_fetch_failed) and v5 hosted rollback/remove (re-resolveshttps://pypi.org/pypi/<name>/<ver>/json) fail in the sandbox. PointSOCKET_PYPI_JSON_APIat a local HTTP forwarder that also rewritesfiles.pythonhosted.org. The repo'se2e_vex_build -- poetry::hosted test scrubsSOCKET_*, so its rollback step fails in the sandbox for the same reason. Not a product bug.poetry.lockwith a UTF-8 BOM is rejected by Poetry itself ("Invalid statement (at line 1, column 1)").[[tool.poetry.source]](even a PyPI mirror,priority = "primary") is refused by hosted (redirect_poetry_lock_unsupported, exit 0) and vendored (pypi_poetry_source_already_exists, exit 1) before any write. Documented ("a user-authored[package.source]on another origin").vexon a project with no install hook reportsecosystem_not_setup/no_applicable_patches. Documented.vexon apackage-mode = falseproject with no version needs--product(product_undetected). Expected.[project]dependencies, so "[project].name+[tool.poetry].name" is n/a before 2.0.crates/socket-patch-cli/CLI_CONTRACT.md, not the repo root.--cwdor a directory target).pypi_poetry_integrity_unverifiedand hosted emitsredirect_poetry_stale_install_risk. Both are deliberate advisories.redirect_pypi_stale_installand refuses VEX.poetry check --lockfails on Poetry 1.1 / 1.2 (1.2 has no--lockoption, and 1.1'scheckcrashes). This isn't caused by socket-patch.#sha256=…&#egg=fragment. Documented, and named in theredirect_poetry_stale_install_riskdetail. Use pip ≤ 22.2 or ≥ 23.1.[metadata.files]against today's PyPI. Documented (backtest "populated" shape).--vexon a warm, unpatched venv still attests, with the warningvendored_tree_out_of_sync. Documented in CLI_CONTRACT.md.list/ standalonevexonly recognise hosted pins on Socket's origin. A mock origin needs--patch-server-url.scan --jsonwith several directory targets is refused ("--json takes one project directory").--vendor-source build(local artifact construction). Repair re-downloads from the service./v0/orgs/<org>/patches/blob/<hash>. A mock without that route givesmissing_blob.scan --mode agentre-run after a failed apply says[skip] … (already recorded)and exits 0 with the file unpatched. That's by design (it prints "runsocket-patch applyto re-apply them"), andapply/vexthen report the failure correctly.sixtwice. That's a mock artifact; pass--ecosystems pypi./usr/lib/python3/dist-packages/sixis an apt.egg-infoinstall, invisible to the crawler (Python crawler ignores.egg-infoinstalls, so packages pip ≤ 23.0 installed from sdists are never patched, never get a stale-install warning, and are invisible toscan -g#447). Usepip install --user --ignore-installedfor a real global copy.POETRY_VIRTUALENVS_IN_PROJECT=yes/onis true to socket-patch and false to Poetry (boolean_normalizeraccepts only "true" / "1"). Theoretical, not filed.SOCKET_PYPI_JSON_APIpointed at a local forwarder in the sandbox. Without it the takeover fails closed withredirect_revert_failed. A forwarder script that rewritesfiles.pythonhosted.orgworks.scanruns in one project: the extra runs exit 1 with "Another socket-patch process is operating in this directory" (use--lock-timeout). This is by design.jaraco.context): Poetry 1.1 keeps the dotted name in the lock (quoted[metadata.files]key), Poetry ≥ 1.8 canonicalizes it. Hosted rewrite, install, vex and rollback all work with both purl spellings (r5).rollback -g --jsonwith no manifest returnserroras a plain string ("Manifest not found"), not a{code, message}object. This is a shape nit, not Poetry-specific, and not filed.virtualenvs.create = falserunning as root in this image reinstall a user-site package into/usr/local/lib/python3.11/dist-packages. That's Poetry's behaviour, not socket-patch.All reactions