Bug hunt ledger: PDM #312
Replies: 6 comments
|
[agent] 2026-09-30: PDM bug-hunt run First run. The ledger was empty and there were no earlier Tested: main Filed
Cells covered (Linux unless noted)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-09-30: PDM bug-hunt run Tested: main Filed / commented
Re-triage
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-10-01: PDM bug-hunt run Tested: main Filed / closed
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where PDM puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × PDM version cells for |
|
[agent] 2026-10-01: PDM bug-hunt run Tested: main Filed / commented
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-10-01: PDM bug-hunt run Tested: main Filed / commented
Re-triage
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled PDM bug-hunt routine (label pm:pdm).
Last run: 2026-10-01 15:20Z on main
6e7ef74(latest tag v4.0.0). Linux runs use real PDM against a local mock patch API, because the sandbox blocks the Socket patch hosts. macOS and Windows runs use probe branches.Coverage matrix
__pypackages__sync, legacy[metadata.files], rollback byte-exact); post-rollback install fail #477Modes × macOS/Windows for hosted and vendored: untested by this routine (the repo's pdm-compatibility.yml covers them).
Global mode (
-g, maintainer request)pdm use -g→global-project/.venv--global-prefix(incl. space/unicode path, install.cache symlink per-file)cpython@3.12pdm use -g <pdm python>(no venv)scan --jsondrops the reason (#424)-g --mode hostedand--global-prefix --mode hostedrefuse with exit 2 (pass).SOCKET_GLOBAL=1matches-g(pass).--global-prefix <site-packages>finds both #451 locations (pass).Backlog
-g), still open: PDM 1.4.5 / 2.0.3 global (PEP 582 global project?);venv.in_project=falseglobal venv (<data>/pdm/venvs/global-project-*); PDM-managed interpreter apply via--global-prefix; macOS / Windows. Done this run: system-global apply/rollback/vex,--global-prefixvenv, unicode path, unwritable prefix, install-cache check (Agent mode writes the patch into PDM's shared install cache when PDM 2.0–2.12 installs packages as directory symlinks (install.cache + symlink) #332).remove <purl>,rollback --preserve-state; agent → vendored takeover on v5.static_urls(does vendored rollback keep the mirror URLs, unlike Hosted PDM rollback and remove replace a private index's static_urls with files.pythonhosted.org, so PDM bypasses the mirror (or fails on 2.12 behind a firewall) #413?).pdm update --unconstrained/lock --update-all; groups viapdm sync -G.feature.install_cachewith agent mode.git push --deletefails through the git proxy; the stalebughunt/pdm/20260930-cache-symlinkstill needs a maintainer to delete it).Known non-bugs
__pypackages__(PEP 582) not crawled; agent mode falls through to the PATH interpreter (documented). Hosted mode installs into__pypackages__fine.pdm lock,--refresh,pdm update <pkg>) drops the hosted redirect (documented; re-scan). Rollback still works when the package stays at the same version.redirect_pdm_stale_install_risk, documented).vendor_fetch_unverifiable), by design.path(redirect_pdm_refused), by design (hosted-direction takeover is warn-only). Hosted→vendored for PyPI fails closed withpypi_pdm_source_already_exists(the same for uv/poetry): runrollbackfirst.pdm lock --append) lock holding the package at two versions is refused (redirect_pdm_refused), documented.install.cache_method=pth: agent apply fails closed withFile not found.pdm lockwithout-Gdoes not lock optional groups (PDM behaviour, not a socket-patch bug).redirected: 0on lock-only projects, so it can't be used to bisect hosted findings.pdm remove, upgrade): exit 1Manifest not foundis the documented truly-empty result (formerly Hosted PDM rollback and remove fail permanently once the patched package leaves pdm.lock (pdm remove, or an upgrade to another version), and the suggested re-scan doesn't help #382).cross_platform(PDM ≥ 2.17 defaultinherit_metadata): documented in CLI_CONTRACT "Hosted unwind coverage".cross_platformlock writes every PyPI release file (e.g. pyyaml 6.0.1: 51), where PDM locked a requires-python-filtered subset (39). Installs andlock --checkare unaffected; cosmetic.not_applied.pdm add -gwith nopdm use -ginstalls into the system interpreter, whichscan -gdoes find; only the venv and PDM-managed interpreter cases are Global scan (-g) never crawls PDM's global project venv or PDM-managed interpreters, sopdm add -gpackages are silently left out with exit 0 #451.scan -g --mode vendoredis accepted (exit 0) while hosted refuses. It isn't PDM-specific, so it's left to maintainers; not filed.rollbackdeletes the manifest entry (documented: it removes local state), so a laterapplyis a no-op.scanwithout-g/--prunedefaults to hosted and rewritespdm.lock(documented default).All reactions