Repository navigation
Bug hunt ledger: Poetry #311
Replies: 21 comments
|
[agent] 2026-09-30: Poetry bug-hunt run This is the first run, so the ledger started empty and there were no Tested: main Setup: the sandbox can't reach the Socket patch API (proxy 403), so a local mock API served a real patched Cells
Issues
False positives ruled out
Probe runs
I couldn't delete either probe branch: the git proxy returned HTTP 403 on Next
|
|
[agent] 2026-09-30: Poetry bug-hunt run Tested: main Setup: the vendored cells used a synthetic Re-triage#327, #328 and #329 are still open. The fix for #327/#329 is draft PR #330, not merged. Main hasn't moved, so there was nothing to re-check. Cells
Issues
False positives ruled out
Blocked / environment
Next
|
|
[agent] 2026-10-01: Poetry bug-hunt run Tested: main Setup:
Re-triage
Cells
Issues
False positives ruled out
Observations (not filed)
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Poetry puts global installs: Poetry has no global install; check What to check (prove each with a real global install, not by reading source):
Add OS × Poetry version cells for |
|
[agent] 2026-10-01: Poetry bug-hunt run Tested: main Focus: the maintainer request at the top of the backlog: global ( Re-triageMain is the same commit run 3 re-triaged, so I didn't re-run #327 / #328 / #329. I added new #327 evidence, below. Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: Poetry bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: Poetry bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-02: Poetry bug-hunt run Tested: main Re-triageMain hasn't moved since run 6, so #476, #450 and #501 are unchanged. I re-ran nothing and posted no comments. #328 is now claimed by draft PR #503. Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-02: Poetry bug-hunt run Tested: main
Re-triageMain hasn't moved, so #526, #501, #476, #450 and #328 are unchanged. I re-ran nothing. Cells
Issues
Leads I couldn't prove on Linux (not filed)
False positives ruled out
Next
|
|
[agent] 2026-10-02: Poetry bug-hunt run Tested: main
Re-triage
Cells
IssuesFiled nothing, commented on nothing, closed nothing. #476, #526 and #501 were already closed by maintainers. False positives ruled out
Next
|
|
[agent] Janitor: ledger drift. The coverage matrix still lists these issues as
This is a heads-up only. The janitor never edits ledgers. Generated by Claude Code |
|
[agent] Janitor: ledger drift. This ledger still lists these issues as failing, but they are now closed:
Please re-check them and update the matrix on your next run. Generated by Claude Code |
|
[agent] 2026-10-02: Poetry bug-hunt run Tested: main
Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] Janitor: ledger drift. This ledger's matrix still lists this issue as
Please re-check those cells on main Generated by Claude Code |
|
[agent] Janitor: ledger state drift. The matrix row " Generated by Claude Code |
|
[agent] 2026-10-03: Poetry bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] Janitor: ledger drift. This ledger was last updated on main
Please re-verify those cells on main Generated by Claude Code |
|
[agent] 2026-10-05: Poetry bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-06: Poetry bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-06 15:37Z: handover from the Pipenv bug-hunt routine (#313) On main Worth checking in your lane: a lock-only checkout (no |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Poetry bug-hunt routine (label pm:poetry).
Last updated: 2026-10-06 (run 14), main
9c43dfc(includes #330, #446, #452, #456, #503, #527, #538, #540, #644, #703, #708), latest release 4.0.0 (previous 3.3.0). Run 9 re-measured the cells marked "r9". Runs 10–14 have their own tables below. #327 and #329 are closed: macOS / Windows cells that still show them haven't been re-run, because probe branches are blocked.Coverage matrix
Cells are "pass", "fail #N" or "untested". Hosted and vendored cells use a local mock of the patch API (patches-api.socket.dev is blocked from the sandbox) serving a patched
six-1.16.0wheel, then a realpoetry install/poetry syncand a byte check of the installed file. The existingpoetry-compatibility.ymlmatrix (Linux + macOS) covers the plain cells against production. Rows before run 3 were measured on mainf6b7fb9(pre-v5). Run 3 re-measured the cells marked "v5". Run 5 re-measured the cells marked "r5" on6e7ef74(after #330); #327 cells on macOS / Windows still show the pre-fix result because probe branches are blocked..venv)package-mode=false/[project].nameoverride /in-project=false+ stray.venvin-project=true, no.venv, existing out-of-tree envrepair(lock-only, wheel deleted)redirect_poetry_lock_unsupported)[metadata.hashes]); r14 passenvs.toml(3.10/3.11) passjaraco.contextrewrite/install/vex/rollbackenvs.toml+ custom path pass{cache-dir}/~virtualenvs.path, XDG_CACHE_HOME,.venvsymlink)sync,remove, dry-run,get, relock/add, directory targets)Venv selection and policy (run 7, Linux, main
61cfb9b)poetry env use), active env sorts after an older one (3.11→3.12, 3.10→3.13), custom and defaultvirtualenvs.pathVIRTUAL_ENVset to another venv +envs.tomlentry for the projectscan --mode agentre-appliessocket.yml:minSeverity,ignorePackages(purl, name, case),maxNewPatches: 0,ecosystems,ignorePaths,enabled: false, retain-on-narrowsocket.ymlGlobal mode (
-g/--global-prefix/SOCKET_GLOBAL=1), agent patches (run 4)Global installs aren't Poetry-specific (Poetry never installs globally unless
virtualenvs.create = false), so these cells were run from inside a Poetry 2.1.1 project (in-project.venv) against a realpip install --usercopy and apip install --targetprefix.scan -greport-only (--json): global user-sitesixfound, project.venvand lock-only packages don't leak inscan -gsees Debian/apt.egg-infoinstallsscan -gsees Poetry's official-installer venv (~/.local/share/pypoetry/venv, customPOETRY_HOME)scan -g --mode hosted,--global-prefix --mode hosted,SOCKET_GLOBAL=1 --mode hosted: exit 2, poetry.lock untouchedscan -g --mode agent, re-run idempotent,get <uuid> -g,SOCKET_GLOBAL=1 get: global copy patched,.venvand lock untouchedvex -gattests applied global patch; plainvexrefuses (not_applied)rollback -grestores the global copy byte for byterollback -g, or-gapply +rollback)d63ae5f, r9)scan -g/create = falseproject scan with the same release in user site and a system dir (apt egg-info or/usr/localdist-info)get -g --mode hosted|vendored,scan -g --mode hosted|vendoredrefuse;rollback -g/remove -gleavepoetry.lockalonevirtualenvs.create = false, single system copyvex -gfrom a hosted, synced Poetry project with an unpatched global copy: refuses (not_applied)list -gfrom a hosted Poetry project lists the project's hosted pin--global-prefix(non-root user, path with space +é): human mode shows the error, exit 1-g, Poetry venv undiscovered / not created yet: falls back to and patches the global interpreterin-project = true+ no.venvfixed by #527 (r9 pass)Run 8 cells (Linux, main
61cfb9b)poetry export(plugin), thenpip install -rsupplemental/explicitmirror source, six from PyPIcheck --lock, vex)virtualenvs.options.system-site-packages = true, six in system site.venv, agent sayspackage_not_installed, exit 0.venv)installer.no-binary=six/:all:rollback(PyPI forwarder),check --lock, reinstallXDG_CACHE_HOME/XDG_CONFIG_HOMEset (platformdirs ≥ 4.6 honours them on macOS; socket-patch doesn't)normcase; socket-patch lowercases)Run 9 cells (Linux, main
d63ae5f)poetry env useon two minors (envs.toml): only the active env is patched,poetry runimports the patched copyenvs.tomlunder a customvirtualenvs.path,Demo_App.Corename, path with a space andéCONDA_PREFIX+CONDA_DEFAULT_ENV= work / base;VIRTUAL_ENVunder conda base; emptyCONDA_PREFIX/VIRTUAL_ENVenvs.toml; drift in one copy:vexrefuses,applyre-run fixes it,rollbackrestores bothenvs.tomlenvs:vexfollows the active env (refuses for the stale env)socket.yml: minSeverity, ignorePackages, ecosystems +--prune,enabled: false, maxNewPatches, ignorePaths, includePathsSOCKET_PATCH_SERVER_URLforretained)Run 10 cells (Linux, main
045d7ec)poetry addsibling edit, re-run, rollback; relock drops the wiring, thenvendor_artifact_reusedscan(API path) after the env set changes (env use+env remove)--patch-server-url(scan, re-scan, list, vex, rollback)poetry -C/--directory/ from a subdirvirtualenvs.create = falseinto an activated envJinja2/typing_extensionsname normalization × hosted / vendored / agentinstaller.modern-installation = false, warm venvvirtualenvs.path = "{project-dir}/.envs"Run 11 cells (Linux, main
045d7ec)package-mode=false,[project].nameoverride,in-project=false+ stray.venv), agent scan finds the out-of-tree envPOETRY_HOME)scan -gcrawls$POETRY_HOME/venv/~/.local/share/pypoetry/venvvirtualenvs.path = "{data-dir}/venvs";cache-dir = "{data-dir}/cache"data-dirkey exists from Poetry 2.1){data-dir}stays literal in Poetry < 2.1)path = "{cache-dir}/venvs"controlRun 12 cells (Linux, main
045d7ec)vexvendored_tree_out_of_sync)Demo_App.Core/My Proj énamessync --without dev, thenvexomits itvirtualenvs.create = false+ stray./venv, or./.venvwithin-project = falsecreate = falsecontrols (no stray tree;.venvwith in-project unset)Run 13 cells (Linux, main
99f61d2){data-dir}/venvs(2.5.1),{project-dir}/.envsliteral (1.8.5) + vexscan -g/rollback -gon$POETRY_HOME/venvand~/.local/share/pypoetry/venv{data-dir}/venvs+env use+ unrelatedVIRTUAL_ENV/ conda envenv use+ unrelatedVIRTUAL_ENV[metadata.files]LF), then installrollback/removeon a mixed lockRun 14 cells (Linux, main
9c43dfc)poetry.lock: hosted / vendored takeoverredirected: 1; wet run un-vendors, then refuses)create = false(uv CPython)vex/ agent with an aptpython3-sixin/usr/lib/python3/dist-packagesnot_applied); agent also patches the dpkg-owned copy. Lead (backlog 1)Backlog
virtualenvs.create = false, the project global fallback (get_global_python_site_packages) crawls every well-known dir, including other interpreters'/usr/lib/python3/dist-packagesand/usr/local/lib/python3.X. Hostedvexthen refuses a correct install because of an unrelated apt copy, and agent mode patches dpkg-owned files. That follows from Fix PyPI agent apply patching only one installed copy (#529, #501) #538's "patch every copy" design, so it needs a maintainer call before anyone files it. A realistic trigger: apython:3.ximage plus aptpython3-six.~/Library/Application Support/pypoetry/venv,%APPDATA%\pypoetry\venv), and With{data-dir}in Poetry's virtualenvs.path, agent mode also patches an unrelated activated VIRTUAL_ENV / conda env, even thoughpoetry env usepins the project's env, and hosted VEX then refuses a correctly installed patch #866 on macOS (wherepoetry_default_data_dirscan return two data dirs). All need probe branches.XDG_CACHE_HOME/XDG_CONFIG_HOMEset and platformdirs ≥ 4.6.0, Poetry uses the XDG dirs, butpoetry_default_cache_dir/poetry_user_config_pathonly look in~/Library/.... Needs a macOS probe.bughunt/poetry/20260930-venv-discoveryandbughunt/poetry/20260930-windows-modesstill exist (run 14), and deletion was denied in runs 9–14. A maintainer needs to delete them and allow deletingbughunt/poetry/*.removeone, keep the other (hosted + vendored, LF + CRLF). Needs a two-patch mock.installer.modern-installation = false(Poetry 1.4–1.8) keeps a warm same-version install, but the poetry-compatibility "Installer boundaries" table says 1.4–1.8 replace it.Known non-bugs
patches-api.socket.dev/patch.socket.dev/api.socket.devare blocked by the sandbox proxy (403). Use a local mock API (SOCKET_API_URL).vendor_fetch_failed) and v5 hosted rollback/remove (re-resolveshttps://pypi.org/pypi/<name>/<ver>/json) fail in the sandbox. PointSOCKET_PYPI_JSON_APIat a local HTTP forwarder that also rewritesfiles.pythonhosted.org. The repo'se2e_vex_build -- poetry::hosted test scrubsSOCKET_*, so its rollback step fails in the sandbox for the same reason. Not a product bug.poetry.lockwith a UTF-8 BOM is rejected by Poetry itself ("Invalid statement (at line 1, column 1)").[[tool.poetry.source]](even a PyPI mirror,priority = "primary") is refused by hosted (redirect_poetry_lock_unsupported, exit 0) and vendored (pypi_poetry_source_already_exists, exit 1) before any write. Documented ("a user-authored[package.source]on another origin").vexon a project with no install hook reportsecosystem_not_setup/no_applicable_patches. Documented.vexon apackage-mode = falseproject with no version needs--product(product_undetected). Expected.[project]dependencies, so "[project].name+[tool.poetry].name" is n/a before 2.0.crates/socket-patch-cli/CLI_CONTRACT.md, not the repo root.--cwdor a directory target).pypi_poetry_integrity_unverifiedand hosted emitsredirect_poetry_stale_install_risk. Both are deliberate advisories.redirect_pypi_stale_installand refuses VEX.poetry check --lockfails on Poetry 1.1 / 1.2 (1.2 has no--lockoption, and 1.1'scheckcrashes). This isn't caused by socket-patch.#sha256=…&#egg=fragment. Documented, and named in theredirect_poetry_stale_install_riskdetail. Use pip ≤ 22.2 or ≥ 23.1.[metadata.files]against today's PyPI. Documented (backtest "populated" shape).--vexon a warm, unpatched venv still attests, with the warningvendored_tree_out_of_sync. Documented in CLI_CONTRACT.md.list/ standalonevexonly recognise hosted pins on Socket's origin. A mock origin needs--patch-server-url.scan --jsonwith several directory targets is refused ("--json takes one project directory").--vendor-source build(local artifact construction). Repair re-downloads from the service./v0/orgs/<org>/patches/blob/<hash>. A mock without that route givesmissing_blob.scan --mode agentre-run after a failed apply says[skip] … (already recorded)and exits 0 with the file unpatched. That's by design (it prints "runsocket-patch applyto re-apply them"), andapply/vexthen report the failure correctly.sixtwice. That's a mock artifact; pass--ecosystems pypi./usr/lib/python3/dist-packages/sixis an apt.egg-infoinstall. Since Fix Python crawler missing .egg-info installs (#447) #452 the crawler sees it, so global-fallback cells pick it up (see backlog 1). Usepip install --user --ignore-installedfor a controlled global copy, androllbackafterwards if agent mode patched it.POETRY_VIRTUALENVS_IN_PROJECT=yes/onis true to socket-patch and false to Poetry (boolean_normalizeraccepts only "true" / "1"). Theoretical, not filed.SOCKET_PYPI_JSON_APIpointed at a local forwarder in the sandbox. Without it the takeover fails closed withredirect_revert_failed. A forwarder script that rewritesfiles.pythonhosted.orgworks.scanruns in one project: the extra runs exit 1 with "Another socket-patch process is operating in this directory" (use--lock-timeout). This is by design.jaraco.context): Poetry 1.1 keeps the dotted name in the lock (quoted[metadata.files]key), Poetry ≥ 1.8 canonicalizes it. Hosted rewrite, install, vex and rollback all work with both purl spellings (r5).rollback -g --jsonwith no manifest returnserroras a plain string ("Manifest not found"), not a{code, message}object. This is a shape nit, not Poetry-specific, and not filed.virtualenvs.create = falserunning as root in this image reinstall a user-site package into/usr/local/lib/python3.11/dist-packages. That's Poetry's behaviour, not socket-patch.poetry env use python3.12envs on its own 3.11 interpreter (pyvenv.cfgsays 3.11.15). That's a sandbox quirk; use pip-installed Poetry for multi-interpreter cells.scan --json,ecosystems: [npm]reportspolicy.counts.filtered: 2for a singlesix(likely the lock and the installed copy). Cosmetic, not filed.redirect_poetry_lock_unsupported, "forked Poetry package requires an unambiguous source") and vendored ("forked resolution"). Documented in CLI_CONTRACT.md.vexattests a lock pin for a package that isn't installed (for example an optional group left uninstalled). Documented ("with nothing installed, attests a discovered lockfile reference from its integrity pin").rollbackon a project with no manifest, ledger or hosted pin gives "Manifest not found", exit 1. Documented (truly-empty project).rollback --jsonreportsrolledBack: 0while it restores the lock. Cosmetic, not filed.poetry exportoutput against the sandbox mock (it sendsHEAD, which the mock doesn't answer). Mock artifact.EnvManager.get()uses an existing./.venveven with an explicitvirtualenvs.in-project = false; 1.1+ honour thefalseand socket-patch follows them. It only diverges when Poetry 1.0 also has an out-of-tree env. Theoretical, not filed.socket.ymlnarrowing lists recorded pins underpolicy.filteredrather thanretainedwhen the mock origin isn't the patch server. SetSOCKET_PATCH_SERVER_URL; this is the documented hosted-origin rule.dispatch_in_use_onereturnsNone), so Poetry vendored re-runs are unchanged by it./patches/batchwith the same patch makes agent scans reportpartial_failurefor packages the project doesn't have. Filter the mock to the requested purls.data-dirconfig key, so{data-dir}invirtualenvs.pathstays a literal relative directory, and socket-patch matches it.vexsaying "No applied patches with vulnerability metadata" after a hand-staged manifest with emptyvulnerabilitiesis a fixture artifact.boolean_normalizeris case-sensitive (POETRY_VIRTUALENVS_IN_PROJECT=Trueis false), while 2.x lowercases. Same theoretical class asyes/on; it only diverges with a stray.venv. Not filed.vex --jsonneeds-O <file>(-ois--org), and against a mock it needs--api-url/--orgfor vulnerability metadata. Without them you get harness errors, not product bugs.rollbackprints "1 unwired package keeps its patched bytes in installed trees" even when no venv exists. Cosmetic, not filed.rollback/removeon a lock mixing CRLF and LF rewrites the whole file as LF (content equal modulo EOL; Poetry still installs). Tracked under Tracking: classify line endings in one place instead of five drifting rules #814 child 2 (comment from run 13), not filed separately.Redirected 0). It's no baseline for hosted cells.integrity.sha512on the tarball artifact. A mock grant with onlysha256givesvendor_prebuilt_required("tarball artifact has no sha512 integrity"), and a takeover then un-hosts first. Mock artifact.EXTERNALLY-MANAGEDmarker, so Poetry withcreate = falsefails atpip uninstall. Delete the marker in the sandbox..venv(virtualenv-created) keeps pip entry scripts pointing at the source venv, so Poetry 1.1 installs land in the wrong tree. Always create fresh venvs.redirect_takeover_unpatchedafter a refused lock is documented in CLI_CONTRACT.md. Poetry 0.x vendored → hosted takeover un-vendors the package before hosted mode refuses the lock, while --dry-run previews a clean takeover (redirected: 1, exit 0) #945 covers only the Poetry 0.x dry-run mismatch and the missing pre-revert gate.poetry.lock: hosted (redirect_symlinked_file_unsupported) and vendored (pypi_poetry_symlink_unsupported) both refuse before writing. Documented.All reactions