Bug hunt ledger: Poetry #311
Replies: 9 comments
|
[agent] 2026-09-30: Poetry bug-hunt run This is the first run, so the ledger started empty and there were no Tested: main Setup: the sandbox can't reach the Socket patch API (proxy 403), so a local mock API served a real patched Cells
Issues
False positives ruled out
Probe runs
I couldn't delete either probe branch: the git proxy returned HTTP 403 on Next
|
|
[agent] 2026-09-30: Poetry bug-hunt run Tested: main Setup: the vendored cells used a synthetic Re-triage#327, #328 and #329 are still open. The fix for #327/#329 is draft PR #330, not merged. Main hasn't moved, so there was nothing to re-check. Cells
Issues
False positives ruled out
Blocked / environment
Next
|
|
[agent] 2026-10-01: Poetry bug-hunt run Tested: main Setup:
Re-triage
Cells
Issues
False positives ruled out
Observations (not filed)
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Poetry puts global installs: Poetry has no global install; check What to check (prove each with a real global install, not by reading source):
Add OS × Poetry version cells for |
|
[agent] 2026-10-01: Poetry bug-hunt run Tested: main Focus: the maintainer request at the top of the backlog: global ( Re-triageMain is the same commit run 3 re-triaged, so I didn't re-run #327 / #328 / #329. I added new #327 evidence, below. Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: Poetry bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: Poetry bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-02: Poetry bug-hunt run Tested: main Re-triageMain hasn't moved since run 6, so #476, #450 and #501 are unchanged. I re-ran nothing and posted no comments. #328 is now claimed by draft PR #503. Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-02: Poetry bug-hunt run Tested: main
Re-triageMain hasn't moved, so #526, #501, #476, #450 and #328 are unchanged. I re-ran nothing. Cells
Issues
Leads I couldn't prove on Linux (not filed)
False positives ruled out
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Poetry bug-hunt routine (label pm:poetry).
Last updated: 2026-10-02 (run 8), main
61cfb9b(includes #330, #446, #452, #456), latest release 4.0.0 (previous 3.3.0).Coverage matrix
Cells are "pass", "fail #N" or "untested". Hosted and vendored cells use a local mock of the patch API (patches-api.socket.dev is blocked from the sandbox) serving a patched
six-1.16.0wheel, then a realpoetry install/poetry syncand a byte check of the installed file. The existingpoetry-compatibility.ymlmatrix (Linux + macOS) covers the plain cells against production. Rows before run 3 were measured on mainf6b7fb9(pre-v5). Run 3 re-measured the cells marked "v5". Run 5 re-measured the cells marked "r5" on6e7ef74(after #330); #327 cells on macOS / Windows still show the pre-fix result because probe branches are blocked..venv)package-mode=false/[project].nameoverride /in-project=false+ stray.venvin-project=true, no.venv, existing out-of-tree envrepair(lock-only, wheel deleted)redirect_poetry_lock_unsupported)[metadata.hashes])jaraco.contextrewrite/install/vex/rollback{cache-dir}/~virtualenvs.path, XDG_CACHE_HOME,.venvsymlink)sync,remove, dry-run,get, relock/add, directory targets)Venv selection and policy (run 7, Linux, main
61cfb9b)poetry env use), active env sorts after an older one (3.11→3.12, 3.10→3.13), custom and defaultvirtualenvs.pathVIRTUAL_ENVset to another venv +envs.tomlentry for the projectscan --mode agentre-appliessocket.yml:minSeverity,ignorePackages(purl, name, case),maxNewPatches: 0,ecosystems,ignorePaths,enabled: false, retain-on-narrowsocket.ymlGlobal mode (
-g/--global-prefix/SOCKET_GLOBAL=1), agent patches (run 4)Global installs aren't Poetry-specific (Poetry never installs globally unless
virtualenvs.create = false), so these cells were run from inside a Poetry 2.1.1 project (in-project.venv) against a realpip install --usercopy and apip install --targetprefix.scan -greport-only (--json): global user-sitesixfound, project.venvand lock-only packages don't leak inscan -gsees Debian/apt.egg-infoinstallsscan -gsees Poetry's official-installer venv (~/.local/share/pypoetry/venv)scan -g --mode hosted,--global-prefix --mode hosted,SOCKET_GLOBAL=1 --mode hosted: exit 2, poetry.lock untouchedscan -g --mode agent, re-run idempotent,get <uuid> -g,SOCKET_GLOBAL=1 get: global copy patched,.venvand lock untouchedvex -gattests applied global patch; plainvexrefuses (not_applied)rollback -grestores the global copy byte for byterollback -g, or-gapply +rollback)61cfb9b, r6)scan -g/create = falseproject scan with the same release in user site and a system dir (apt egg-info or/usr/localdist-info)get -g --mode hosted|vendored,scan -g --mode hosted|vendoredrefuse;rollback -g/remove -gleavepoetry.lockalonevirtualenvs.create = false, single system copyvex -gfrom a hosted, synced Poetry project with an unpatched global copy: refuses (not_applied)list -gfrom a hosted Poetry project lists the project's hosted pin--global-prefix(non-root user, path with space +é): human mode shows the error, exit 1-g, Poetry venv undiscovered / not created yet: falls back to and patches the global interpreterin-project = true+ no.venv(#476, re-confirmed r6 on61cfb9b; now lands in apt's dist-packages)Run 8 cells (Linux, main
61cfb9b)poetry export(plugin), thenpip install -rsupplemental/explicitmirror source, six from PyPIcheck --lock, vex)virtualenvs.options.system-site-packages = true, six in system site.venv, agent sayspackage_not_installed, exit 0.venv)installer.no-binary=six/:all:rollback(PyPI forwarder),check --lock, reinstallXDG_CACHE_HOME/XDG_CONFIG_HOMEset (platformdirs ≥ 4.6 honours them on macOS; socket-patch doesn't)normcase; socket-patch lowercases)Backlog
XDG_CACHE_HOME/XDG_CONFIG_HOMEset and platformdirs ≥ 4.6.0 (2026-02-12; Poetry 1.2–2.x pull 4.12.x), Poetry uses$XDG_CACHE_HOME/pypoetry/virtualenvsand$XDG_CONFIG_HOME/pypoetry/config.toml.python_crawler.rspoetry_default_cache_dir/poetry_user_config_pathonly look in~/Library/...on macOS. This needs a macOS probe.windows_normcase). This needs a Windows probe.realpath) and long paths. This needs probe branches.git push --deleteandgit push origin :refs/heads/...still fail (runs 1–8). A maintainer needs to deletebughunt/poetry/20260930-venv-discoveryandbughunt/poetry/20260930-windows-modes.CONDA_PREFIX(withCONDA_DEFAULT_ENV != base) as Poetry's env. Needs micromamba.virtualenvs.use-poetry-python/prefer-active-pythonwith noenvs.tomlentry (a With several Poetry envs for one project (poetry env useon two Python minors), agent mode patches the alphabetically first env instead of the one Poetry activated, and VEX attests not_affected #526 follow-on).socket.ymlpolicy on Poetry (the mock now has a grant route).Known non-bugs
patches-api.socket.dev/patch.socket.dev/api.socket.devare blocked by the sandbox proxy (403). Use a local mock API (SOCKET_API_URL).vendor_fetch_failed) and v5 hosted rollback/remove (re-resolveshttps://pypi.org/pypi/<name>/<ver>/json) fail in the sandbox. PointSOCKET_PYPI_JSON_APIat a local HTTP forwarder that also rewritesfiles.pythonhosted.org. The repo'se2e_vex_build -- poetry::hosted test scrubsSOCKET_*, so its rollback step fails in the sandbox for the same reason. Not a product bug.poetry.lockwith a UTF-8 BOM is rejected by Poetry itself ("Invalid statement (at line 1, column 1)").[[tool.poetry.source]](even a PyPI mirror,priority = "primary") is refused by hosted (redirect_poetry_lock_unsupported, exit 0) and vendored (pypi_poetry_source_already_exists, exit 1) before any write. Documented ("a user-authored[package.source]on another origin").vexon a project with no install hook reportsecosystem_not_setup/no_applicable_patches. Documented.vexon apackage-mode = falseproject with no version needs--product(product_undetected). Expected.[project]dependencies, so "[project].name+[tool.poetry].name" is n/a before 2.0.crates/socket-patch-cli/CLI_CONTRACT.md, not the repo root.--cwdor a directory target).pypi_poetry_integrity_unverifiedand hosted emitsredirect_poetry_stale_install_risk. Both are deliberate advisories.redirect_pypi_stale_installand refuses VEX.poetry check --lockfails on Poetry 1.1 / 1.2 (1.2 has no--lockoption, and 1.1'scheckcrashes). This isn't caused by socket-patch.#sha256=…&#egg=fragment. Documented, and named in theredirect_poetry_stale_install_riskdetail. Use pip ≤ 22.2 or ≥ 23.1.[metadata.files]against today's PyPI. Documented (backtest "populated" shape).--vexon a warm, unpatched venv still attests, with the warningvendored_tree_out_of_sync. Documented in CLI_CONTRACT.md.list/ standalonevexonly recognise hosted pins on Socket's origin. A mock origin needs--patch-server-url.scan --jsonwith several directory targets is refused ("--json takes one project directory").--vendor-source build(local artifact construction). Repair re-downloads from the service./v0/orgs/<org>/patches/blob/<hash>. A mock without that route givesmissing_blob.scan --mode agentre-run after a failed apply says[skip] … (already recorded)and exits 0 with the file unpatched. That's by design (it prints "runsocket-patch applyto re-apply them"), andapply/vexthen report the failure correctly.sixtwice. That's a mock artifact; pass--ecosystems pypi./usr/lib/python3/dist-packages/sixis an apt.egg-infoinstall, invisible to the crawler (Python crawler ignores.egg-infoinstalls, so packages pip ≤ 23.0 installed from sdists are never patched, never get a stale-install warning, and are invisible toscan -g#447). Usepip install --user --ignore-installedfor a real global copy.POETRY_VIRTUALENVS_IN_PROJECT=yes/onis true to socket-patch and false to Poetry (boolean_normalizeraccepts only "true" / "1"). Theoretical, not filed.SOCKET_PYPI_JSON_APIpointed at a local forwarder in the sandbox. Without it the takeover fails closed withredirect_revert_failed. A forwarder script that rewritesfiles.pythonhosted.orgworks.scanruns in one project: the extra runs exit 1 with "Another socket-patch process is operating in this directory" (use--lock-timeout). This is by design.jaraco.context): Poetry 1.1 keeps the dotted name in the lock (quoted[metadata.files]key), Poetry ≥ 1.8 canonicalizes it. Hosted rewrite, install, vex and rollback all work with both purl spellings (r5).rollback -g --jsonwith no manifest returnserroras a plain string ("Manifest not found"), not a{code, message}object. This is a shape nit, not Poetry-specific, and not filed.virtualenvs.create = falserunning as root in this image reinstall a user-site package into/usr/local/lib/python3.11/dist-packages. That's Poetry's behaviour, not socket-patch.poetry env use python3.12envs on its own 3.11 interpreter (pyvenv.cfgsays 3.11.15). That's a sandbox quirk; use pip-installed Poetry for multi-interpreter cells.scan --json,ecosystems: [npm]reportspolicy.counts.filtered: 2for a singlesix(likely the lock and the installed copy). Cosmetic, not filed.redirect_poetry_lock_unsupported, "forked Poetry package requires an unambiguous source") and vendored ("forked resolution"). Documented in CLI_CONTRACT.md.vexattests a lock pin for a package that isn't installed (for example an optional group left uninstalled). Documented ("with nothing installed, attests a discovered lockfile reference from its integrity pin").rollbackon a project with no manifest, ledger or hosted pin gives "Manifest not found", exit 1. Documented (truly-empty project).rollback --jsonreportsrolledBack: 0while it restores the lock. Cosmetic, not filed.poetry exportoutput against the sandbox mock (it sendsHEAD, which the mock doesn't answer). Mock artifact.All reactions