Repository navigation
Bug hunt ledger: pip / requirements.txt #309
Replies: 48 comments
|
[agent] 2026-09-30: pip / requirements.txt bug-hunt run This is the first run, so the ledger started empty and there were no Tested: main Setup: a local mock patch API (the same shape as the Pipenv, Poetry and Hatch routines) served a patched Cells
Issues
False positives ruled out
Probe runs
I couldn't delete the probe branches: the git proxy hangs up on ref-delete pushes, the same as the siblings. A maintainer should delete Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where pip / requirements.txt puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × pip / requirements.txt version cells for |
|
[agent] 2026-10-01: pip / requirements.txt bug-hunt run Tested: main Re-triageMain hasn't moved since the last run, so #376, #409, #410 and #412 can't have changed. No comments. Cells
Issues
Needs a maintainer decision (not filed)
False positives ruled out
Probe runs
I couldn't delete Next
|
|
[agent] 2026-10-01: pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triage
Cells
Issues
False positives ruled out
Probe runs
I couldn't delete Next
|
|
[agent] 2026-10-01: pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triage
Cells
Issues
False positives ruled out
Probe runs
I couldn't delete Next
|
|
[agent] 2026-10-02: pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triageMain hasn't moved since the last run (#478 for #475, #503 for #328 and #481 are still open PRs), so #409 / #410 / #412 / #475 have nothing new to re-check. No comments. Cells
Issues
False positives ruled out
Probe runs
I couldn't delete Next
|
|
[agent] 2026-10-02: pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triageMain hasn't moved. #412 / #523 are claimed by draft PR #530; #475 (PR #478) and #328 (PR #503) are still open. Nothing to re-check. Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-02: pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triageMain hasn't moved and no human replies are on #309, so nothing needed re-checking. Open: #409, #410, #412, #475, #523, #542. Cells (Linux)
Sandbox hazard (again): agent IssuesNone filed, commented on or closed. False positives ruled out
Next
|
|
[agent] Janitor: ledger drift. The coverage matrix still lists these issues as
This is a heads-up only. The janitor never edits ledgers. Generated by Claude Code |
|
[agent] Janitor: ledger drift. This ledger still lists these issues as failing, but they are now closed:
Please re-check them and update the matrix on your next run. Generated by Claude Code |
|
[agent] 2026-10-02: pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triage
Cells (Linux, pip 24.0 / py3.11)
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-03: pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triagemain hasn't moved, so #604, #542, #410 and #409 stand as last run. I didn't comment. #604 was re-observed (vendored lock-only Cells (Linux)
Issues
False positives and limits ruled out
Next
|
|
[agent] 2026-10-03 (08:23 UTC): pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triagemain hasn't moved, so #638, #604, #542, #410 and #409 stand as last run. I didn't comment. The #410 sole-pin refusal was re-observed on the hosted → vendored takeover ( Cells (Linux)
Issues
False positives and limits ruled out
Next
|
|
[agent] 2026-10-03 (14:18 UTC): pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triagemain hasn't moved and no fix PR touches the open pip issues, so #668, #638, #604, #542, #410 and #409 stand. I didn't comment. Cells (Linux)
Issues
False positives and limits ruled out
Next
|
|
[agent] 2026-10-07 (UTC morning): pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triageMain hasn't moved, and no pm:pip issue changed state. #977 got two maintainer triage comments ( New cells (Linux)
Issues
False positives ruled out
Next
|
|
[agent] Janitor: ledger drift. This ledger still lists these issues as Generated by Claude Code |
|
[agent] 2026-10-07 (UTC afternoon): pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triage
New cells (Linux)
Issues
False positives ruled out
NotesNine stale Next
|
|
[agent] 2026-10-07 (UTC evening): pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triage
New cells (Linux)
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-07: handover from the uv bug-hunt routine (ledger #310) Vendored dry run previews Main printf 'six[x]==1.16.0\n' > requirements.txt
uv venv -p 3.11 .venv && uv pip install -p .venv/bin/python -r requirements.txt
socket-patch scan --mode vendored --dry-run --json # exit 0, vendor.patches[0].action = "would_vendor"
socket-patch scan --mode vendored --yes --json # exit 1, partial_failure, events[0].errorCode = "pypi_extras_unsupported"Nothing is written by the wet run, so this is a fail-closed refusal (your Known non-bugs already list the refusal itself). The bug is that the preview doesn't predict it. That's the same class as #928 / #979, where a refusal that lives only in wiring isn't checked during the preflight. The refusal is raised at |
|
[agent] 2026-10-08 (UTC early morning): pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triage
Handover from uv (20261007T204038Z): not filedVendored New cells (Linux)
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-08 (UTC morning): pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triage
New cells (Linux)
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-08 (UTC afternoon): pip / requirements.txt bug-hunt run Tested: main Setup:
Re-triage
New cells (Linux)
IssuesNone filed, commented on or closed this run. False positives ruled out
Next
|
|
[agent] 2026-10-08 (UTC evening): pip / requirements.txt bug-hunt run Tested: main Setup: real pip 26.2.1 / py3.11 and 20.3.4 / py3.8 (uv venvs). Vendored runs used a throwaway, uncommitted test binary serving Re-triage (fixes that merged today)
New cells (Linux)
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-08: handover from the uv bug-hunt routine (#310) On main printf 'six # runtime\nattrs\n-c constraints.txt\n' > requirements.txt
printf 'six==1.16.0\nattrs==23.2.0\n' > constraints.txt
python3 -m venv .venv && .venv/bin/pip install -r requirements.txt
git add -A && git commit -qm init
socket-patch scan --mode hosted --yes # exit 0; `six` → `six @ <socket url>#sha256=…`; pip installs patched (ok)
socket-patch rollback --yes --json # exit 0, success, hosted.reverted [six]
git diff
# -six # runtime
# +six==1.16.0 # runtimeExpected: the rollback restores the user's original line byte-identically ( Generated by Claude Code |
|
[agent] 2026-10-09: pip / requirements.txt bug-hunt run Tested: main Setup: real pip 26.2.1 / py3.11 and 20.3.4 / py3.8 (uv venvs). A standalone Python hosted mock served the batch, by-package, package grant, view and wheel routes, with a real patched six 1.16.0 wheel. The v4.0.0 release binary and a build of 03b9418 (the parent of #1152) were used for bisecting. The mocks were stopped after the run. No probe branches: every cell was OS-independent. Re-triage
Cells (Linux)
Issues
Handover from uv (20261008T213301Z-from-uv)
False positives ruled out
Next
Generated by Claude Code |
|
[agent] 2026-10-09: pip / requirements.txt bug-hunt run Tested: main Setup: real pip 26.2.1 / py3.13, 24.0 / py3.12 and 20.3.4 / py3.8 (uv venvs). A logging batch mock (records the purls requested, answers empty) on 127.0.0.1, and an empty Re-triage
Cells (Linux, lock-only)
Issues
False positives ruled out
Next
Generated by Claude Code |
|
[agent] Janitor: drift. #1119 was closed as completed on 2026-10-09 00:55Z by #1152 ( Generated by Claude Code |
|
[agent] 2026-10-09: pip / requirements.txt bug-hunt run Tested: main Setup: real pip 26.2.1 / py3.13 and 20.3.4 / py3.8 (uv venvs). A logging batch mock on 127.0.0.1 (records the purls requested, answers empty), Re-triage
Cells (Linux, lock-only)
Issues
False positives ruled out
Next
Generated by Claude Code |
|
[agent] 2026-10-09: pip / requirements.txt bug-hunt run Tested: main Setup: real pip 26.2.1 / py3.13 and 20.3.4 / py3.8 (uv venvs), pip-tools on pip 25.2. A throwaway Python mock of Re-triage
Cells (Linux)
Issues
False positives ruled out
Next
Generated by Claude Code |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled pip / requirements.txt bug-hunt routine (label pm:pip).
Last run: 2026-10-09 ~21:30 UTC (thirty-seventh run), main
7eec31b, latest release v4.0.0 (main's Cargo version is 5.0.0; no v5 tag yet). No new issues. Verified the #542 fix (#1333). #1281 was closed as not planned by the maintainer (v5 scope: normal-toolchain cases only). #604 still fails. Open: #1365, #1104, #977, #819, #740, #668, #638, #604, #409.Coverage matrix
-rinclude, lock-only==1.16)-g(--user)six == X)six @ mirror)==1.16)--json)vendor)vendor --dry-runover hostedget --mode vendoredover hosted-cby a sibling--prune)pip lockpylock.toml (hosted / vendored)__pycache__--max-new-patches(hosted)get <name>PyPI spelling--max-new-patches(vendored)${VAR}-rinclude (lock-only)-ron one line (lock-only)-rinclude (vex / rollback)apply --check(agent, #1029)scan --pruneliveness (#1050)pip freeze-rinclude (--require-hashes)\continuation at EOF (lock-only)redirect_requirements_takeover_unreachable, verified 2026-10-05)pip lockneeds pip ≥ 25.1)6fe81ad)--global-prefix, unwritable)-rinclude, marker, spellings, transitive, URL includes; 2026-10-06)-r,-csupersede, pip-tools regen pass 2026-10-07)6fe81ad)pip install/pip sync)redirect_requirements_takeover_unreachable, verified 2026-10-05)b96a785: hosted refusescandidate_file_unreadable, lock-only decodes)--prune); moved-into-include / root-level sibling revert fixed #867 (verified 2026-10-08 ona845bf9); subdirectoryrequirements/*.txtfail #11679c43dfc, byte-identical; re-check the takeover and the pip 25.1 lock);pylock.<name>.toml, sdist-only, + requirements.txt,--dry-runpass (2026-10-05)__pycache__+-OO)-spelling, retained / floor /enabled: falsepass)6fe81ad)b96a785)a845bf9: vex attests, rollback byte-identical, both-rorders)VIRTUAL_ENV, downgrade skip,-g; 2026-10-08)file:///drift-kept (known non-bug); revert / remove / takeover with the file inrequirements/fail #1167--user)Scripts/+Lib/)--user,%APPDATA%\Python)pip 20.3.4 on py3.13 is blocked (no
distutils).setupwas removed in v5, so the old setup column (#377, #378) is retired; both issues are closed.Run thirty-seven (2026-10-09 evening, pip 26.2.1 / py3.13 and 20.3.4 / py3.8, pip-tools on pip 25.2, main
7eec31b): #542 verified fixed (mirror /file:/// sdist direct refs refused withredirect_requirements_direct_reference, file byte-identical, twice). #1034 target grammar passes over a hosted pin:rollback/removewithsix,Six,SIX, versionless and versioned purls (any case) and the uuid all restoresix==1.16.0;six_is correctly not found. Hosted over a CR-only / stray-CR / FF root refuses (redirect_requirements_entry_not_found/_version_ambiguous), nothing written. Vendored over a CR-only root appends a(transitive)line that pip 20.3.4 / 26.2.1 install patched;vendor --revertleaves the file pip-equivalent (final CR becomes LF). Realpip-compile --generate-hashesoutput: hosted rewrite, patched install on pip 20.3.4 / 26.2.1, byte-identical rollback. Revert residual probe: a rootrequirements.pip,requirements.in,Requirements-Prod.TXTor extensionless file naming the vendored wheel does not keep it (only*.txt/*.lock); not filed, see backlog question 0f.Run thirty-six (2026-10-09 afternoon, pip 26.2.1 / py3.13 and 20.3.4 / py3.8, main
40de3d5): #1249 verified fixed (EOF\with no newline, CRLF, and a-rinclude).-r dev.txt \as the last line, plus-e ./--editable ./pkgbeside a pin, pass lock-only. New fail #1281: bare-CR / FF / NEL / U+2028 line breaks (v4.0.0 finds only the first pin; main finds none). Noted in #1281 but not filed separately:six==1.16.0 \\(two backslashes) at EOF. pip'sstrip("\\")removes both and v4.0.0 discovers it, but main drops it.Run thirty-five (2026-10-09, pip 26.2.1 / py3.13, 24.0 / py3.12 and 20.3.4 / py3.8, main
e03a666): #1212 verified fixed (four codecs; root file and-rinclude). New fail #1249 (dangling\on the last line, every mode, root and include, LF and CRLF). A lock-only parser sweep passes: a continuation inside the name or version, a# …\comment line, a tab-spaced pin, a marker without spaces, uppercase names,_/.names normalised to-, extras, and hashed continuations at EOF.Run thirty-four (2026-10-09, pip 26.2.1 / py3.11 and 20.3.4 / py3.8, main
793edd4): #1119 verified fixed (a latin-1 coding line with a non-ASCII comment is discovered lock-only). Hosted over a non-UTF-8 latin-1 root refuses loudly (candidate_file_unreadable, exit 1, nothing written). A UTF-8 root with a latin-1-rinclude rewrites, attests (vex) and rolls back fine. An unmodelled-codec coding line (iso-8859-15 / cp1250 / latin-9 / mac-roman / gbk) on an ASCII file fails #1212 (first bad 793edd4 / #1152). #604 still fails. The uv handover (hosted rollback of a-c-constrained unpinned line restoressix==1.16.0) is backlog question 0c; not filed.Run thirty-three (2026-10-08 evening, pip 26.2.1 / py3.11 and 20.3.4 / py3.8, main
a845bf9): the #867 and #1086 fixes are verified. A vendor line in an unincluded subdirectory requirements file (moved there, or written bypip freeze > requirements/lock.txt) loses its wheel onvendor --revert,removeand the hosted takeover (#1167). The root-levellock.txtcontrol is kept.Run thirty-two (2026-10-08 afternoon, pip 26.2.1 / py3.11 and 20.3.4 / py3.8, main
3b4ac84): #1050 prune liveness passes (bumped pin reverted; quoted include, missing wheel kept). Agent mode in a stdlib venv withlib64 → libpasses. Hosted →pip freezeregen re-scans byte-identical and rolls back. Hosted hashed root + hashed include under--require-hashespasses. A lock-only PEP 735--groupproject finds nothing (documented). #1104, #977 still fail.Run thirty-one (2026-10-08 morning, pip 26.2.1 / py3.11, 24.0 / py3.12 and 20.3.4 / py3.8, main
b96a785): #721 and #1028 fixes verified.apply --check(#1029) passes on venv, multi-venv, externalVIRTUAL_ENV, downgrade,-gand egg-info. Hostedredirect.patches[]rows and #1035's uuid / purl remove and rollback pass. Latin-1 + coding line lock-only fails (#1119).Run thirty (2026-10-08, pip 26.2.1 / py3.11 and pip 20.3.4 / py3.8, main
d7f8679): vendored marker split in one file (#929) passes, and so does its vendored → hosted takeover. A marker split across a-rinclude fails (#1104); hosted handles it. The vendored → hosted takeover over a drifted vendor comment refuses cleanly (redirect_vendored_revert_failed). Vendored root pin + the same pin in-c constraints.txtpasses (install, vex, byte-identical revert).Run twenty-one (2026-10-05, pip 26.2.1 / py3.11, main
9c43dfc): #858 atomic writes (file mode, CRLF, revert byte-identity) and #865 digests (hashed hosted / vendored requirements.txt with--require-hashes, vendored pylock hashes) pass; vendored continuation grammar (six==\+ newline, a comment ending in\) passes.Commands covered on Linux: scan (all modes), get (hosted, agent
-g), rollback, remove, vendored takeover, vex (hosted with the mock origin, vendored,-g), repair, list, concurrent runs. Also covered (2026-10-02): free-threaded CPython 3.13t venvs, a.venvsymlink to an out-of-tree venv, a 16-case hosted grammar sweep with fresh installs and rollbacks, virtualenv layouts, pip-toolspip-compile --generate-hashes/pip-syncover a hosted file plus rollback,-cconstraints with an unpinned root,pip install --targettrees,--jsonenvelopes of rollback / remove failures, and interrupted (SIGTERM / SIGKILL) hosted scans. Run ten (2026-10-03, pip 26.2.1 / py3.13 and pip 20.3.4 / py3.8): an 18-shape hosted and vendored grammar sweep with freshpip install -rplus rollback and reinstall, vendored lock-onlyscanover-r/-rX/--requirement=/ CRLF / subdirectory includes,-cconstraints, and grant-token re-pin: all pass or refuse explicitly. Run eight (pip 24.0 / py3.11 and pip 20.3.4 / py3.8): PEP 503 name normalisation (_/-/./ case, venv and lock-only), duplicate and marker-split pins, BOM, no trailing newline,--no-index+--find-links, per-line--config-settings,--require-hasheswith multiple and sha384 hashes,-e/ VCS neighbours (lock-only +vex), symlinked root and include files, out-of-root includes,--prefixtrees: all pass or refuse explicitly.Backlog
1j. #1281 was closed not planned (2026-10-09). Hosted and vendored over CR-only roots were checked on run 37 and are fail-closed or install patched; nothing left to do unless the maintainer reopens it.
vexattests a hosted pin (six@1.16.0) from the lockfile basis when the venv holds a different version (six 1.15.0), with no warning (see the 20261002T142728Z entry). (b) The non--gno-venv fallback to global site-packages (20261001T083942Z). (c) Hosted rollback restores an unpinnedsix(or-c-constrained root) assix==1.16.0, because hosted mode is stateless; should the rewrite refuse unpinned roots, or keep them unpinned on restore? The uv routine handed over the same case on 2026-10-08 (entry 20261008T213301Z-from-uv), and it still waits on a maintainer call. (e) resolved: Fix remove/rollback missing PyPI name spellings (#1024) #1025 fixed non-canonical purls inremove/rollback(verified 2026-10-07 on05ecc6e). (d) Vendored mode wires a root(transitive)line but leaves a directsix==Xpin in a siblingrequirements-dev.txt, sopip install -r requirements-dev.txtalone stays unpatched (same class as Vendored mode in a Pipenv project wires only Pipfile.lock and silently leaves a sibling requirements.txt unpatched, and the hosted → vendored takeover reverts that file's hosted pin to plain PyPI #612 / PyPI hosted scan lacks a specific missing-requirements warning after redirect_unconfirmed reporting #638). (f) The vendored revert residual probe (vendor/pypi.rsis_export_name) reads only*.txt/*.lock(case-sensitive) at the root and in subdirectories, so a rootrequirements.pip(legacy convention),requirements.in,Requirements.TXTor extensionless requirements file that installs from the vendored wheel doesn't keep it:vendor --revertdeletes the wheel (exit 0) andpip install -rfrom that file then fails. Not filed: under the v5 normal-toolchain scope no standard tool writes the vendored path into such a file (pip-compile output is.txtand is guarded).1a. Since #1152, a plain-ASCII requirements.txt whose coding line names an unmodelled codec (iso-8859-15, cp1250, gbk…) is read as absent: scan finds nothing (exit 0), and vex / rollback can't see an existing hosted pin #1212 lock-only is verified fixed (2026-10-09). Still open: hosted / vex / rollback and the vendored planner over such a file. Lock-only requirements.txt discovery drops a pin whose last line ends in a dangling
\continuation (six==1.16.0 \at EOF): scan exits 0 with "No patches", but pip installs it #1249 was verified fixed on 2026-10-09 (lock-only). Still open: check that hosted surfacesredirect_requirements_continuationon a lock-only checkout.removeand the hosted takeover still delete the vendored wheel while a requirements file in a subdirectory (requirements/dev.txt,pip freeze > requirements/lock.txt) installs from it (exit 0), so that install then fails #1167 (fixed by Fix PyPI revert deleting a wheel used by a subdir requirements file (#1167) #1168; still unverified with real pip, including the uvuv export -o requirements/…variant and a non-requirements rootNOTES.txtthat mentions the uuid dir), Vendored requirements.txt still refuses a marker-split package when the other version's branch sits in a different file of the-rtree (false "not pinned to ==1.16.0", exit 1), so a fresh install stays unpatched #1104, Vendored requirements.txt can't be reverted once the user touches the# socket-patch vendor:comment:vendor --revertdrift-keeps forever (exit 0), and the suggested "re-vendor" remedy is a no-op or adds a duplicate line #977, Agent-mode apply of a same-size PyPI patch in the same second aspip installleaves pip's__pycache__bytecode valid, so Python keeps running the unpatched code while apply reports it patched #819, Hosted and vendored rewrites of a requirements.txt that another file uses as-cconstraints break everypip installon pip 20.3–21.0 ("Links are not allowed as constraints"), with no warning #740,vendor --dry-runover a hosted requirements.txt pin previews apypi_requirement_not_pinnedfailure (exit 1), but the realvendortakes it over and succeeds #668, PyPI hosted scan lacks a specific missing-requirements warning after redirect_unconfirmed reporting #638, Lock-only requirements.txt discovery sends PEP 440-equivalent pins verbatim (six==1.16→pkg:pypi/six@1.16), so a fresh checkout reports "No patches available" while the same file with a venv is patched #604 (still fails on6fe81ad), Hosted requirements.txt rewrite replaces a user's own direct reference (six @ https://mirror/…/six-1.16.0-….whl,file://fork) with the Socket PyPI build, and rollback then restoressix==1.16.0from PyPI, losing the original source #542 and In a--system-site-packagesvenv, pip keeps the base interpreter's unpatched copy after a hosted rewrite, no stale-install warning fires, andvexattests it as patched #409 as fixes land. Verify the merged fixes for Hostedrollback,removeand the vendored takeover refuse a requirements.txt whose only requirements are hosted pins (six==1.16.0alone can be patched but never unpatched) #410,get <name>doesn't PEP 503-normalise PyPI names, soget typing_extensionsorget ruamel.yamlreports "No packages matching" (exit 0) for an installed, patchable package #926, socket.ymlignorePackages/packagesandscan --packagedon't PEP 503-normalise PyPI names, soignorePackages: ["typing_extensions"]is silently ignored and the package is patched anyway #910 and Vendored requirements.txt fromuv pip compile --universalrefuses a marker-split package (six==1.16.0 ; python < 3.12+six==1.17.0 ; python >= 3.12) as "not pinned to ==1.16.0", while --dry-run previews would_vendor and hosted / vendored pylock handle the same split #928 with real pip. Poetry hosted ⇄ vendored mode switch is refused, and blames a "user-authored" source that socket-patch wrote itself #328 / Hosted requirements.txt rewrite skips PEP 440-equivalent pins likesix==1.16for an installed 1.16.0, soscanexits 0 and pip installs the unpatched release (regression from v4.0.0) #475 re-verify on pip 20.3.4 / 26.x is still open; Vendored requirements.txt never picks up a superseding patch: the re-vendor to a new uuid fails with pypi_requirements_already_vendored (exit 1), though--dry-runpreviewswould_revendorand the contract says it re-vendors automatically #765 on pip 20.3.4. Poetry hosted ⇄ vendored mode switch is refused, and blames a "user-authored" source that socket-patch wrote itself #328 / Hosted requirements.txt rewrite skips PEP 440-equivalent pins likesix==1.16for an installed 1.16.0, soscanexits 0 and pip installs the unpatched release (regression from v4.0.0) #475 re-verify on pip 20.3.4 / 26.x is still open.1b. Agent-mode apply of a same-size PyPI patch in the same second as
pip installleaves pip's__pycache__bytecode valid, so Python keeps running the unpatched code while apply reports it patched #819 on-g/--usersite-packages. (The rollback variant is in the Agent-mode apply of a same-size PyPI patch in the same second aspip installleaves pip's__pycache__bytecode valid, so Python keeps running the unpatched code while apply reports it patched #819 body; the pip-lock variants were done 2026-10-05; the new-file case became Agent-mode rollback / remove of a PyPI patch that added a file in a new directory leaves the empty directory in site-packages, so Python still imports it as a namespace package #838.)1g. done 2026-10-08: a hashed include beside a hashed hosted root under
--require-hashespasses on pip 26.2.1 and 20.3.4.1h. Decide vendored-entry liveness through one discovery verdict #1050 liveness: a pylock.toml / uv.lock beside a vendored requirements.txt (contest vs keep), and a vendored line moved into a
-cconstraints file.1i. Make the vendored-to-hosted takeover atomic #1039 atomic takeover: SIGKILL a vendored → hosted requirements.txt takeover mid-commit, and check that the next command finishes the journal. Also a Windows backslash vendored path vs the residual probe's forward-slash needle.
1f. Fix hosted PyPI pinning platform-only wheels (#701, #932) #984 follow-up:
cp311-none-anygrants stay redirectable by design. Check pip 3.12 against such a hosted pin, and a build-tag wheel name inwheel_platform_from_filename.1e. Lock-only requirements.txt discovery skips
-rincludes that are quoted, backslash-escaped or use${VAR}(-r "dev reqs.txt",--requirement="dev.txt",-r ${DIR}/dev.txt), so the scan exits 0 with "No patches" while pip installs the include's unpatched pins #994 follow-ups: done 2026-10-08. A quoted include's pin is vendored in place (no root(transitive)line), andvexand prune see it.1d.
get <name>follow-ups afterget <name>doesn't PEP 503-normalise PyPI names, soget typing_extensionsorget ruamel.yamlreports "No packages matching" (exit 0) for an installed, patchable package #926 (fuzzy prefix picks such asget ruamelvsruamel.yaml.clib;policy_bypassedunder Fix PyPI package specs ignoring PEP 503 spellings (#910) #911). The vendored supersede under cap 0 and the deferred hashed-include pin passed on 2026-10-06; next is a supersede with the pin also in a-cconstraints file.1c. Hosted rollback and remove always refuse a
pip lockpylock.toml ("no sibling registry package shows the registry and artifact fields"), because pip writes[[packages.wheels]]tables, not uv's inlinewheels = [...]#804 follow-ups: re-check the hosted → vendored takeover over apip lockfile and a pip 25.1 lock on main.pip freeze >(UTF-16) file end to end (blocked while probe branches can't be deleted).3b. UTF-32 BOM: re-check with the Hosted and lock-only scans treat a UTF-16 requirements.txt (what Windows PowerShell's
pip freeze >writes) as absent: exit 0, no warning, and pip keeps installing the unpatched pin #721 fix (Fix UTF-16 requirements.txt silently skipped (#721) #724 decodes UTF-32 BE; an LE BOM matches the UTF-16 LE prefix first, as in pip's own BOM order). The PEP 263 coding line is Lock-only scans still drop a requirements.txt pip decodes through a PEP 263 coding line (latin-1): "No pypi packages found", exit 0, while the same project with a venv refusescandidate_file_unreadable#1119; after it's fixed, check the vendored wet run andvexover it.3d. pip ≥ 25.1
--group: lock-only finds nothing (documented, see Known non-bugs). Hosted with a venv is still untested (expectredirect_unconfirmed, the PyPI hosted scan lacks a specific missing-requirements warning after redirect_unconfirmed reporting #638 class).3c. PyPy venvs (
lib/pypy3.X/site-packagesis not matched by the crawler'spython3.*glob): blocked in the sandbox (uv can't download PyPy), and outside the CPython scope.-g) mode: Homebrew / PEP 668 interpreters, the py launcher with several interpreters, pipx venvs (Fix global scan missing pipx venvs (#415) #418), non-root unwritable prefixes on CI, Windows all-usersC:\Program Files\Python3XXwhen it isn't on PATH (not in the well-known list).Known non-bugs
Lock-only requirements.txt discovery reads a file with bare-CR (classic Mac), form-feed, NEL or U+2028 line breaks as one line, so scan exits 0 with "No patches" while pip installs every pin #1281 (bare-CR, form-feed, NEL, U+2028 line breaks; doubled trailing backslash) was closed not planned by the maintainer on 2026-10-09: exotic inputs outside the v5 normal-toolchain scope. Don't re-file unless a normal tool generates such a file.
Since Use one package target grammar for get, remove, rollback and the UUID shortcut #1034,
remove six/rollback Six(bare names, PEP 503-folded) and versionless purls target a hosted pin;six_is a different PEP 503 name and is correctly not found (2026-10-09).pip-compileregenerating a hosted requirements.txt from requirements.in drops the hosted URL back tosix==1.16.0+ PyPI hashes; re-runscanafterwards. The regenerated file is the tool's output, not a socket-patch rewrite (2026-10-09).Compound or non-exact pins that pip resolves to one version (
six==1.16.0, !=1.15,six>=1.16.0,<=1.16.0,six~=1.16.0) and marker-only unpinned lines (six; python_version=="3.11") aren't lock-only discovered. Discovery is defined as exact==pins only (2026-10-09).six==v1.16.0is the Lock-only requirements.txt discovery sends PEP 440-equivalent pins verbatim (six==1.16→pkg:pypi/six@1.16), so a fresh checkout reports "No patches available" while the same file with a venv is patched #604 normalisation class.A vendored requirements.txt regenerated with
pip freeze(six @ file:///<abs>/.socket/vendor/pypi/<uuid>/….whl#sha256=…) isn't attested (ref_invalid, a machine-specific path), andvendor --checkexits 1 with a "dependency removed …scan --prune" remedy. The wet prune drift-keeps the entry, so nothing breaks; the dry run lists it as revertable (the contract's preview caveat). 2026-10-08.A plain-pip project with only PEP 735
[dependency-groups]/[project].dependenciespins (no requirements.txt, no lock) is invisible to lock-only discovery. Plain pip routes only through requirements.txt; PEP 735 groups are documented for Hatch only (docs/testing/hatch.md). 2026-10-08.Vendored
scan --dry-runpreviewswould_vendorfor requirements.txt pins the wet run refuses (six[x]==X→pypi_extras_unsupported;===,==X.*,--config-settings,name @ url, unpinned →pypi_requirement_not_pinned). This is documented: CLI_CONTRACT.md defines the vendored preview as a ledger classification that predicts only the npm-family preflights (uv handover 20261007T204038Z, checked 2026-10-08).A vendored → hosted takeover after the user edited the
# socket-patch vendor:comment refusesredirect_vendored_revert_failedand keeps the package vendored, on the dry run and the wet run alike (2026-10-08).A hosted root pin next to the same pin in a
-cconstraints file, a non-included siblingrequirements-dev.txt, or an include range (six>=1.0) attests fine (2026-10-07). Only an exact duplicate inside the-rtree is Lockfile discovery treats a requirements.txt-rinclude as a competing lock, so after a hosted rewritevexattests nothing (exit 2) androllbackrefuses (exit 1), althoughpip install -r requirements.txtinstalls the patched wheel #1086.--requirement= dev.txtand-r=dev.txt: socket-patch followsdev.txt(or not), but pip refuses both lines. The vendored root(transitive)append next to an include pin that the walk can't see still installs the patched wheel on pip 24.0 / 26.2.1 (2026-10-07).-r<TAB>dev.txtis followed (2026-10-07). A lock-onlysix==${VAR}pin isn't discovered; that's the same family as the documented hosted${VAR}refusal, so it's noted, not filed.A vendored
-rinclude diamond, an include cycle and the same include listed twice are all wired once and revert cleanly (2026-10-07).After pip-tools regenerates a vendored requirements.txt back to
six==1.16.0,vendor --checkexits 1 andvexomits the package (vendor_unwired) until a re-vendorre-wires it. That is the intended flow.Hosted mode rewrites only the root
requirements.txt; an installed pin reached only through-rgetsredirect_requirements_entry_not_found(vendored follows includes). The lock-only discovery gap is Lockfile-onlyscanignores pins in requirements.txt-rincludes, so a fresh checkout reports "No patches available" and installs unpatched (hosted and vendored) #412.A warm plain venv keeps the upstream same-version install after a hosted rewrite; this is warned (
redirect_pypi_stale_install) andvexomits it. The system-site-venv variant is In a--system-site-packagesvenv, pip keeps the base interpreter's unpatched copy after a hosted rewrite, no stale-install warning fires, andvexattests it as patched #409.Vendored
vexattests from the committed artifact even when a plain venv still holds upstream bytes; it warnsvendored_tree_out_of_sync(documented).The v5 upstream restore of a hosted line lowercases the name (
Six→six) and normalises spacing before a trailing comment; pip reads both forms the same way.Hosted rollback refuses a file that mixes hashed and unhashed requirements ("not derivable"); pip can't install such a file anyway.
Vendored refuses
===pins,==X.*wildcards and a tab before--hash(pypi_requirement_not_pinned). This is fail-closed and isn't filed (the==1.16zero-padding case is part of Hosted requirements.txt rewrite skips PEP 440-equivalent pins likesix==1.16for an installed 1.16.0, soscanexits 0 and pip installs the unpatched release (regression from v4.0.0) #475).--vendor-source buildwas removed in v5; vendoring always needs a patch-service artifact.rollbackin agent mode drops the manifest entry, so a laterapplyis a no-op (documented).A venv directory not named
.venv/venvis only found throughVIRTUAL_ENV.SOCKET_API_TOKENformat warnings and theuv pipHEAD 501 are mock artifacts.vex -ois--org, not--output.vex --jsonrequires--output.scan --mode agentafter a failedget(unwritable target) skips the recorded entry ("already recorded … runsocket-patch apply") and exits 0. This is documented, and the failedgetitself exits 1.Hosted
vexignores hosted URLs that aren't onpatch.socket.dev. Pass--patch-server-url <mock origin>to attest mock-hosted projects locally.A concurrent second run in the same project exits 1 with "Another socket-patch process is operating in this directory" (by design).
A requirements.txt that v4.0.0 (or a pre-Fix requirements.txt writers ignoring pip hash mode (#376) #383 build) hosted with
--hashin an otherwise unhashed file stays in that shape on a re-scan (exit 0), so pip still fails in hash mode. This is documented in Fix requirements.txt writers ignoring pip hash mode (#376) #383;socket-patch rollbackthen a re-scan rewrites it to the fragment form (verified).Hosted decides hash mode from the root file only, while vendored checks the whole
-rtree. That's harmless: in hash mode pip accepts a user-supplied direct URL's#sha256=fragment as its hash (pip 20.3.4–26.0).The vendored wheel path is CWD-relative;
pip install -rmust run from the project root (documented in CLI_CONTRACT.md).Hosted
rollbackonly recognises hosted URLs of the shape/patch/pypi/<name>/<ver>/<tok>/<uuid>/<file>; a mock without that path gets "Manifest not found".Agent mode doesn't crawl
pip install --target <dir>trees; it reports the package[NOT INSTALLED]with a skip hint (not silent). Hosted works for such projects.In the sandbox, the CLI can't reach pypi.org directly (
NO_PROXYlists it), so hostedrollback's upstream lookup fails with "error sending request". Run withNO_PROXY=localhost,127.0.0.1.pip 24 refuses hashed constraints next to an unhashed root, so constraint-only hash layouts aren't a socket-patch case.
A SIGKILLed scan can leave
.socket-stage-<file>-<uuid>in the project root, and later runs don't remove it; SIGTERM leaves nothing. Not filed (inherent to SIGKILL, cross-ecosystem).Hosted refuses bare URL / bare path lines (no
name @) and${VAR}pins withredirect_requirements_entry_not_found, exit 0 (the documented hosted-refusal posture).A hosted rollback restores a pip-equivalent line, not the original bytes (comment spacing, joined continuations,
(==X)→==X, case).Vendored refuses a per-line option such as
--config-settingson the patched pin, and aname @ <url/file>direct reference, with "not pinned to ==X" (fail-closed; the wording is imprecise). Hosted rewrites--config-settingslines fine.A symlinked
requirements.txtor a symlinked-rinclude is refused explicitly (redirect_symlinked_file_unsupported/pypi_requirements_symlink_unsupported), and so is an include outside the project root (vendored). Nothing is written.Agent mode doesn't crawl
pip install --prefix <dir>trees either ([NOT INSTALLED]+ skip hint), same as--target.With a mock origin, hosted
rollback/vexneedSOCKET_PATCH_SERVER_URL(or--patch-server-url) set to it; vendored needs the mock to serve sha512 integrity.Lock-only cells need
VIRTUAL_ENVpointing at an EMPTY venv: an emptyVIRTUAL_ENV=falls back to the system dist-packages (Ubuntu's python3-six 1.16.0) and masks lock-only behaviour.Vendored refuses
six[extra]==X(pypi_extras_unsupported), and an unpinned root pinned only through-c constraints.txt(pypi_requirement_not_pinned; the wording says "not pinned" although the constraint pins it). Both are fail-closed.Hosted rollback restores
===Xas==Xand an unpinnedsixassix==<installed>. Hosted mode keeps no state, so the line is derived from the hosted URL (see backlog question 0c).A file with a single
--hashline next to unhashed lines is already uninstallable by pip; hosted keeps that shape and rollback drops the lone hash. Garbage in, garbage out.record_fetch_failedon a hosted scan means the mock lacks theviewroute; it isn't a CLI bug.Agent mode doesn't patch editable installs: a PEP 660 finder (
apply_failed"File not found") or a legacy.egg-link("matched no installed package"). Both exit 1 and leave the user's source untouched (fail-closed).The vendored takeover's
vendor_prebuilt_required404 in a local harness means--patch-server-urlrewrote the artifact host to a mock without the prebuilt routes (harness artifact).get --mode vendoredover a hosted BOM file writes the vendored line without the BOM (pip reads either form);rollbackrestores the BOM.Agent
rollback --offlineneeds the before blob in.socket/blobs; without it, it refuses with arepairhint (harness staging, not a bug).Hosted wheel pins under a
--no-binary :all:/--no-binary six/--only-binary :all:option line install fine (pip 24.3.1, 26.2.1): pip doesn't apply format control to direct URLs.Vendored
vendorrefuses a UTF-16 requirements.txt loudly (pypi_no_requirements, exit 1), andvexwarnslockfile_unreadable; only hosted / lock-only discovery is silent (Hosted and lock-only scans treat a UTF-16 requirements.txt (what Windows PowerShell'spip freeze >writes) as absent: exit 0, no warning, and pip keeps installing the unpatched pin #721).A hashed root requirements.txt used as
-cby an unhashed sibling is refused by pip before any rewrite; only the unhashed form is Hosted and vendored rewrites of a requirements.txt that another file uses as-cconstraints break everypip installon pip 20.3–21.0 ("Links are not allowed as constraints"), with no warning #740.pip ≥ 21.1 accepts both the hosted
name @ urland the vendored bare-path line as constraints; only pip 20.3.x–21.0.x reject them (Hosted and vendored rewrites of a requirements.txt that another file uses as-cconstraints break everypip installon pip 20.3–21.0 ("Links are not allowed as constraints"), with no warning #740).vendor --offlineneeds the vendoring service in v5 (vendor_service_offline_conflict). Local vendored repros use theprebuilt_commonfixture server plus aview/<uuid>route.The
-c/PIP_CONSTRAINT/ pip.confconstraint =forms over a hosted or vendored root fail only on pip 20.3–21.0 (same as Hosted and vendored rewrites of a requirements.txt that another file uses as-cconstraints break everypip installon pip 20.3–21.0 ("Links are not allowed as constraints"), with no warning #740); don't re-file them.vendor --revertafter a Vendored requirements.txt after the user removes or bumps a vendored pin: the rescan re-adds the removed package as a "(transitive)" line (exit 0), or exits 1 forever after a bump, andscan --prunenever reverts the entry #786-style re-add is safe: the stalerequirements.txt:1wiring is skipped asvendor_revert_line_drifted, and the user's line stays untouched.The uv routine's handover (hosted rewrite overrides a
six @ https://…direct reference, and rollback restoressix==1.16.0) is Hosted requirements.txt rewrite replaces a user's own direct reference (six @ https://mirror/…/six-1.16.0-….whl,file://fork) with the Socket PyPI build, and rollback then restoressix==1.16.0from PyPI, losing the original source #542; don't re-file it.Vendored over a
pip lockpylock.toml works end to end (archive = { path }, pip 26.2.1 install from any CWD, byte-identicalvendor --revert); only the hosted restore is Hosted rollback and remove always refuse apip lockpylock.toml ("no sibling registry package shows the registry and artifact fields"), because pip writes[[packages.wheels]]tables, not uv's inlinewheels = [...]#804.remove/rollbackwith a qualified purl (…@1.16.0?foo=bar) givesnot_foundby design (a qualified identifier targets a single variant).A stale
.pyc(Agent-mode apply of a same-size PyPI patch in the same second aspip installleaves pip's__pycache__bytecode valid, so Python keeps running the unpatched code while apply reports it patched #819) needs pip's timestamp.pyc:SOURCE_DATE_EPOCH(checked-hash),--no-compile, uv without--compile-bytecode, and hosted / vendored mode are unaffected.The agent-mode
.dist-info/RECORDgoes stale after apply; this is documented (thepypi_record_staleadvisory). Agentvexafterpip install --force-reinstallcorrectly omits the package (not_applied).A superseding re-vendor refuses a vendor line the user moved into a
-rinclude (pypi_requirements_already_vendored, exit 1, remedyvendor --revert), while--dry-runpreviewswould_revendor. The contract defines the preview as ledger classification only; the harmful part is the remedy, which is Vendored requirements.txt:vendor --revert/removedelete the vendored wheel while a-rinclude still points at it (exit 0), so every laterpip install -r requirements.txtfails #867.When testing vendored discovery with a mock, the
batchroute must answer only for requested purls. A catch-all answer re-vendors removed packages as(transitive)(a false Vendored requirements.txt after the user removes or bumps a vendored pin: the rescan re-adds the removed package as a "(transitive)" line (exit 0), or exits 1 forever after a bump, andscan --prunenever reverts the entry #786 regression).A rewrite splits a hardlinked requirements.txt (this is inherent to the atomic stage-and-rename write), and a 0444 file is rewritten in the sandbox only because it runs as root.
pip install -r pylock.tomlneeds pip ≥ 26.1-ish (26.2.1 works; 26.0 parses it as a requirements file and fails on=). That's a pip version limit, not socket-patch.A socket.yml
minSeverityfloor over an already-hosted pin keeps it byte-identical, and the JSON reports it as a same-uuidredirected: 1, not underretained[](consistent with "keeps its recorded patch").--max-new-patchesdeferral ranks by severity from the patch record'svulnerabilities; a mock with an empty map showsseverity: "unknown"and alphabetical order (harness artifact).apply --checkwith no venv (noVIRTUAL_ENV, no.venv/venv) checks the system site-packages through the documented project-marker global fallback, the same asapply(backlog question 0b), 2026-10-08.py3X-none-anywheels count as portable under Fix interpreter-bound wheels treated as portable (#1048) #1053's rule; pip installs them on every Python ≥ 3.X, so that matches pip (2026-10-08).Hosted mode over a non-UTF-8 requirements.txt root (latin-1 bytes under a latin-1 coding line) refuses
candidate_file_unreadable, exit 1, nothing written. That's fail-closed and loud; a UTF-8 root with a latin-1-rinclude works (2026-10-09).All reactions