Bug hunt ledger: Composer #321
Replies: 12 comments
|
[agent] 2026-09-30: Composer bug-hunt run This is the first run, so the ledger started empty and there were no Tested: main Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: Composer bug-hunt run Tested: main All fixtures were offline (path repositories, local VCS repos, a local Composer repository, and a local mock of the patch API). The sandbox's GitHub zipball problem doesn't affect any cell. Re-triage
Cells
Issues
False positives ruled out
Housekeeping
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Composer puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × Composer version cells for |
|
[agent] 2026-10-01: Composer bug-hunt run Tested: main This run took up the maintainer backlog item: global ( Re-triage
Cells (global mode)
Issues
False positives ruled out
Housekeeping
Next
|
|
[agent] 2026-10-01: Composer bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Housekeeping
Next
|
|
[agent] 2026-10-01: Composer bug-hunt run Tested: main Re-triage
Cells (all on
|
|
[agent] 2026-10-01: Composer bug-hunt run Tested: main Re-triage
Cells (all on
|
|
[agent] 2026-10-02: Composer bug-hunt run Tested: main Re-triage
Cells (all on
|
|
[agent] 2026-10-02: Composer bug-hunt run Tested: main Re-triage
Cells (all on
|
|
[agent] Janitor: ledger drift. The coverage matrix still lists these issues as
This is a heads-up only. The janitor never edits ledgers. Generated by Claude Code |
|
[agent] 2026-10-03: Composer bug-hunt run Tested: main Re-triage
Cells (main
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Composer bug-hunt routine (label pm:composer).
Last updated: 2026-10-03 (run 11), main
045d7ec(after #555 lockfile-only apply skip, #503 pypi-only takeover), latest release v4.0.0.Coverage matrix
Cells are "pass", "fail #N" or "untested". Upstream
composer-compatibility.ymlalready covers the plain dist-install hosted/vendored capstones for 1.10 → 2.10 on Ubuntu/Windows/macOS. This ledger tracks the edges it doesn't.setup(LF)setupCRLF / escapesoptions→ transport-options"Vendored: source install" covers both
--prefer-sourceand source-only VCS lock entries (no dist). "Agent: apply (path repo)" means the patch is written through the path-repo link into the sibling directory; see Known non-bugs.Hosted v5 defaults (run 5, main
61cfb9b, Linux PHP 8.3 unless noted)scan→ reinstall → vex (idempotent re-run)--package/scan apps/*/get <uuid>updates[],--max-new-patches 0)packages-dev/ CRLF lockVendored v5 edges (run 6, main
61cfb9b, Linux PHP 8.3)transport-options→ install → revertrequire-dev+ space/unicode project path → install /--no-dev/ vexrepair/ re-vendorvendor×4Hosted packagist-origin psr/log (lockfile-only, 2.10.3): scan → rollback byte-identical: pass. Hand-added
transport-optionskept: #399.Mode takeovers (run 7, main
61cfb9b, Linux PHP 8.3, packagist-origin psr/log 3.0.2)rollbackvendor --revert→ hosted (control)macOS/Windows: untested (pure lock logic; Composer 1's
transport-optionscrash is cross-OS per #399's probe).Global (
-g) mode — run 3, main2463257scan -greport (default home)-grefusal-gapply / vex / rollback~/.config;XDG_CONFIG_HOMEpass on203e092); fail #586 on 2.x when a stale~/.composeralso exists045d7ec)045d7ec(was fail #438)045d7ec)Local agent scan with a user-level
$COMPOSER_HOME/config.jsonvendor-dir: fail #439 (Linux 2.8.12). Hosted on v5: #399 still reproduces.composer/installers
installer-paths(run 4, main2463257, Linux, installers 1.12.0 / 2.3.0)install-pathrecordednot_affected)not_applied)OS-independent (pure path logic). macOS/Windows: untested.
Re-resolution, install flags, exec bits and plugins (run 8, main
61cfb9b, Linux PHP 8.3)require <other>keeps rewrite--prefer-source/reinstall/preferred-install: sourcecomposer-pluginactivates patched (hosted / vendored)get <uuid> --mode hostedover vendoredLockfile-only agent
apply(#555 / #403) — run 11, main045d7ec, Linux PHP 8.3--no-devdev pkg (v1.2.0lock):@1.2.0/@v1.2.0/@1.2.0.0/ uppercasevendor-dirscanlockfileOnlyPackagesrollbackmixed@1.2.0)Global
--global-prefixwith a space/unicode path andSOCKET_GLOBAL=1(2.10.3): pass.Backlog
$XDG_CONFIG_HOME/composerwith the global install, keep a stale~/.composer, and runscan -gwith composer off PATH (run 11's probe never created the XDG dir). Re-run Composer global-home fallback checks ~/.composer before the XDG home, so scan -g finds no Composer 2 global packages when a stale ~/.composer exists and composer isn't on PATH #586 once fixed.takeover_capableset (still missing on045d7ec). Cover bothscanandget <uuid> --mode hosted.vexand vendoredscan --vendoron a--no-devproject with a lock-onlyv-prefixed dev package.-gleftovers: a non-writable global dir must fail loudly (non-root probe), and Fix -g touching the cwd project's state (#436, #445) #446's-gscoping inside a hosted Composer project. Windows-gapply/rollback re-check on the On Windows, scan -g finds no Composer global packages in the default %APPDATA%\Composer home, so apply -g and vex -g silently do nothing #438 fix.transport-options), plus the Windows long-path depth of.socket/vendor/composer/<uuid>/<v>/<n>@<ver>.COMPOSER=<other>.jsonand Composer 1'scomposer require <other>re-resolving custom-repo entries.bughunt/composer/20260930-srconly-probe,bughunt/composer/20261001-global-probe,bughunt/composer/20261001-c1-toptsandbughunt/composer/20261003-home-probe(the sandbox git proxy refuses deletes). Needs a maintainer.Known non-bugs
composer update <pkg>drops the wiring (documented). Re-runscan.composer installafter rewiring (documented). Removevendor/<v>/<n>first."packages-dev": nulllock: Composer 2.8 itself can't install from it.npm link/file:posture, and Composer created the link from the user's own composer.json./in a dev branch version (dev-feature/foo) withunsafe_coordinates: an explicit fail-closed refusal on a shape Socket patches don't target.setup(and its--check/ CRLF issues) is gone in v5 (v5 prerelease: scan → vex → vendor workflow, hosted by default #277/v5: removesetup(WS7) + patch UI streamlining (WS8) #279). Don't filesetupbugs against main.vendor/.gitignorepattern also ignores.socket/vendor/. Use/vendor/.-gkeeps.socket/manifest.jsonin the cwd, so runrollback -gfrom the same directory. This is per-cwd manifest design.beforeBlobContentor a/patches/blob/<hash>route, or rollback fails with "Before blob could not be downloaded".composer global config <key> '<json>'throughcomposer.batmangles the quotes. Write$COMPOSER_HOME/composer.jsondirectly.COMPOSER=<other>.jsonrenamed manifest/lock isn't read (docs/testing/composer-compatibility.md "Not covered", stated for vex). Scan then reports 0 packages.vexstill attests when the live installed tree is pristine, with thevendored_tree_out_of_syncwarning: the committed.socket/vendorartifact that the lock consumes is the evidence (docs/usage.md VEX table).package/custom repository ("does not record packagist as its origin"; restore withgit checkout -- composer.lock). That's documented fail-closed behaviour, so use a packagist-origin fixture to test takeovers./patch/composer/<name>/<ver>/<token>/<uuid>/<leaf>.zipshape. Vendored mode needs a/patch/packageroute serving a single-top-dir dist zip.scan --package toolmatchingacme/toolis documented (last-segment, case-insensitive matching). Prefer purls.vexattests an uninstalled entry (--no-dev, lockfile-only) from the lock's pinned shasum (CLI_CONTRACT "Hosted … With nothing installed … attests from that pin").--patch-server-urlnames it. Pass--patch-server-urlin mock repros of upgrades,rollbackandvex.shell: bashon Actions runsbash -e. Putset +ein probes that record failing exit codes.vendor --offlinewithout a committed artifact isvendor_service_offline_conflict. MockPOST …/patches/package(granted, sha512 SRI) plus a single-top-dir zip.dist/sourcefrom packagist metadata (SOCKET_PACKAGIST_URL), not from the pre-rewrite lock, so hand-added fields such asdist.mirrorson a packagist-origin entry aren't restored. Documented. Packagist.org entries carry no mirrors.repairfetches/patches/diff/<uuid>. Without that route it reportsdownload_failed.source) doesn't reinstall over an existingvendor/on Composer 2 (Composer compares only version and dist/source references). The CLI's next steps say to removevendor/<v>/<n>first, andvexomits it asnot_applied.http://mock needssecure-http: false. Put it in$COMPOSER_HOME/config.json, not composer.json.composer require <other>re-resolves unchanged custom-repo (inlinepackage) entries from composer.json and drops a hosted rewrite. That's Composer 1 behaviour; Composer 2 keeps it. Re-runscan. (Not yet in the docs; see Backlog 5.)COMPOSER_ALLOW_SUPERUSER=1in plugin repros.rollbackof an inline/custom-repo entry is refused ("restore it from version control"): documented fail-closed behaviour.requirereports "Did you mean…"). Use inline/local repos for Composer 1 update cells.~/.composerover the XDG home even when both exist (global config homeon 1.10.28). socket-patch's~/.composer-first fallback is correct for Composer 1. Composer global-home fallback checks ~/.composer before the XDG home, so scan -g finds no Composer 2 global packages when a stale ~/.composer exists and composer isn't on PATH #586 is about Composer 2 only.--global-prefixnames the package root (Composer's globalvendor/dir), notCOMPOSER_HOME, the same way it takesnode_modulesor site-packages for other ecosystems. Pointing it at the home dir scans 0 packages by design.applyexits 0 for a manifest purl that composer.lock resolves but that isn't installed (--no-dev, or nocomposer installyet). That's Fix apply failing when patched deps are skipped (#403) #555's documented lockfile-only skip. A purl that isn't in the lock still exits 1.All reactions