Bug hunt ledger: pip / requirements.txt #309
Replies: 7 comments
|
[agent] 2026-09-30: pip / requirements.txt bug-hunt run This is the first run, so the ledger started empty and there were no Tested: main Setup: a local mock patch API (the same shape as the Pipenv, Poetry and Hatch routines) served a patched Cells
Issues
False positives ruled out
Probe runs
I couldn't delete the probe branches: the git proxy hangs up on ref-delete pushes, the same as the siblings. A maintainer should delete Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where pip / requirements.txt puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × pip / requirements.txt version cells for |
|
[agent] 2026-10-01: pip / requirements.txt bug-hunt run Tested: main Re-triageMain hasn't moved since the last run, so #376, #409, #410 and #412 can't have changed. No comments. Cells
Issues
Needs a maintainer decision (not filed)
False positives ruled out
Probe runs
I couldn't delete Next
|
|
[agent] 2026-10-01: pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triage
Cells
Issues
False positives ruled out
Probe runs
I couldn't delete Next
|
|
[agent] 2026-10-01: pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triage
Cells
Issues
False positives ruled out
Probe runs
I couldn't delete Next
|
|
[agent] 2026-10-02: pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triageMain hasn't moved since the last run (#478 for #475, #503 for #328 and #481 are still open PRs), so #409 / #410 / #412 / #475 have nothing new to re-check. No comments. Cells
Issues
False positives ruled out
Probe runs
I couldn't delete Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled pip / requirements.txt bug-hunt routine (label pm:pip).
Last run: 2026-10-02 (sixth run), main
61cfb9b, latest release v4.0.0 (96df6ae). New this run: #523 (lock-only discovery misses spaced exact pins).Coverage matrix
-rinclude, lock-only==1.16)-g(--user)six == X)--global-prefix, unwritable)pip install/pip sync)--user)Scripts/+Lib/)--user,%APPDATA%\Python)pip 20.3.4 on py3.13 is blocked (no
distutils).setupwas removed in v5, so the old setup column (#377, #378) is retired; both issues are closed.Commands covered on Linux: scan (all modes), get (hosted, agent
-g), rollback, remove, vendored takeover, vex (hosted with the mock origin, vendored,-g), repair, list, concurrent runs. Also covered (2026-10-02): virtualenv layouts, pip-toolspip-compile --generate-hashes/pip-syncover a hosted file plus rollback,-cconstraints with an unpinned root,pip install --targettrees,--jsonenvelopes of rollback / remove failures, and interrupted (SIGTERM / SIGKILL) hosted scans.Backlog
six==1.16for an installed 1.16.0, soscanexits 0 and pip installs the unpatched release (regression from v4.0.0) #475 (after Fix requirements.txt pins not matched under PEP 440 (#475) #478), Poetry hosted ⇄ vendored mode switch is refused, and blames a "user-authored" source that socket-patch wrote itself #328 (after Fix PyPI vendored to hosted takeover being refused (#328) #503) and Lockfile-only requirements.txt discovery skips exact pins written with spaces (six == 1.15.0,six (==1.15.0)), so a fresh checkout reports "No patches available" and pip installs the unpatched release #523 as fixes land; check lock-onlyvexwith spaced pins (vex/discover/pypi_other.rssharesexact_pin). Then lock-only discovery ofsix==1.16once Hosted requirements.txt rewrite skips PEP 440-equivalent pins likesix==1.16for an installed 1.16.0, soscanexits 0 and pip installs the unpatched release (regression from v4.0.0) #475 is fixed.-g) mode. Left: Homebrew / PEP 668 interpreters, py launcher with several interpreters, pipx venvs (Fix global scan missing pipx venvs (#415) #418), non-root unwritable prefixes on CI. Open question for the maintainer: the non--gno-venv fallback to global site-packages (see the 20261001T083942Z entry; it also makes a lock-onlyvexomit packages the system Python has unpatched, and it confounds lock-only tests when the system has the same version).six == 1.15.0,six (==1.15.0)), so a fresh checkout reports "No patches available" and pip installs the unpatched release #523: spaced==on\continuations,--hashbefore the marker,${VAR}lines,-e/ VCS lines next to a patched pin.pip install --prefixtrees; a.venvsymlink to an out-of-tree venv.--system-site-packagesvenv, pip keeps the base interpreter's unpatched copy after a hosted rewrite, no stale-install warning fires, andvexattests it as patched #409 / Hostedrollback,removeand the vendored takeover refuse a requirements.txt whose only requirements are hosted pins (six==1.16.0alone can be patched but never unpatched) #410 / Lockfile-onlyscanignores pins in requirements.txt-rincludes, so a fresh checkout reports "No patches available" and installs unpatched (hosted and vendored) #412 as fixes land.Known non-bugs
requirements.txt; an installed pin reached only through-rgetsredirect_requirements_entry_not_found(vendored follows includes). The lock-only discovery gap is Lockfile-onlyscanignores pins in requirements.txt-rincludes, so a fresh checkout reports "No patches available" and installs unpatched (hosted and vendored) #412.redirect_pypi_stale_install) andvexomits it. The system-site-venv variant is In a--system-site-packagesvenv, pip keeps the base interpreter's unpatched copy after a hosted rewrite, no stale-install warning fires, andvexattests it as patched #409.vexattests from the committed artifact even when a plain venv still holds upstream bytes; it warnsvendored_tree_out_of_sync(documented).Six→six) and normalises spacing before a trailing comment; pip reads both forms the same way.===pins,==X.*wildcards and a tab before--hash(pypi_requirement_not_pinned). This is fail-closed and isn't filed (the==1.16zero-padding case is part of Hosted requirements.txt rewrite skips PEP 440-equivalent pins likesix==1.16for an installed 1.16.0, soscanexits 0 and pip installs the unpatched release (regression from v4.0.0) #475).--vendor-source buildwas removed in v5; vendoring always needs a patch-service artifact.rollbackin agent mode drops the manifest entry, so a laterapplyis a no-op (documented)..venv/venvis only found throughVIRTUAL_ENV.SOCKET_API_TOKENformat warnings and theuv pipHEAD 501 are mock artifacts.vex -ois--org, not--output.vex --jsonrequires--output.scan --mode agentafter a failedget(unwritable target) skips the recorded entry ("already recorded … runsocket-patch apply") and exits 0. This is documented, and the failedgetitself exits 1.vexignores hosted URLs that aren't onpatch.socket.dev. Pass--patch-server-url <mock origin>to attest mock-hosted projects locally.--hashin an otherwise unhashed file stays in that shape on a re-scan (exit 0), so pip still fails in hash mode. This is documented in Fix requirements.txt writers ignoring pip hash mode (#376) #383;socket-patch rollbackthen a re-scan rewrites it to the fragment form (verified).-rtree. That's harmless: in hash mode pip accepts a user-supplied direct URL's#sha256=fragment as its hash (pip 20.3.4–26.0).pip install -rmust run from the project root (documented in CLI_CONTRACT.md).rollbackonly recognises hosted URLs of the shape/patch/pypi/<name>/<ver>/<tok>/<uuid>/<file>; a mock without that path gets "Manifest not found".pip install --target <dir>trees; it reports the package[NOT INSTALLED]with a skip hint (not silent). Hosted works for such projects.NO_PROXYlists it), so hostedrollback's upstream lookup fails with "error sending request". Run withNO_PROXY=localhost,127.0.0.1..socket-stage-<file>-<uuid>in the project root, and later runs don't remove it; SIGTERM leaves nothing. Not filed (inherent to SIGKILL, cross-ecosystem).All reactions