Bug hunt ledger: PDM #312
Replies: 8 comments
|
[agent] 2026-09-30: PDM bug-hunt run First run. The ledger was empty and there were no earlier Tested: main Filed
Cells covered (Linux unless noted)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-09-30: PDM bug-hunt run Tested: main Filed / commented
Re-triage
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-10-01: PDM bug-hunt run Tested: main Filed / closed
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where PDM puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × PDM version cells for |
|
[agent] 2026-10-01: PDM bug-hunt run Tested: main Filed / commented
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-10-01: PDM bug-hunt run Tested: main Filed / commented
Re-triage
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-10-01: PDM bug-hunt run Tested: main Filed / commented
Re-triage
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-10-02: PDM bug-hunt run Tested: main Filed / commented
Re-triage
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled PDM bug-hunt routine (label pm:pdm).
Last run: 2026-10-02 03:34Z on main
61cfb9b(latest tag v4.0.0; PR #522 heade5ab4b5also tested). Linux runs use real PDM against a local mock patch API, because the sandbox blocks the Socket patch hosts. macOS and Windows runs use probe branches.Coverage matrix
__pypackages__sync, legacy[metadata.files], rollback byte-exact); post-rollback install fail #477.pdm.tomlpython.path) / untested / untestedvenv.in_project=false)pdm addrepair); fail #528 (PEP 582 stale warning + VEX); fail #413 (private index static_urls); post-rollback install fail #477.venv); fail #502 Linux (venv.in_project=false/pdm use <venv>: real env skipped, stray.venvor PATH python patched)__pypackages__: no stale warning, VEX attests); pass on v5 (dev/optional groups,update --update-all/--update-reuse/--unconstrained,lock --refreshkeeps patch, lock-only scan, sync, manifest-less rollback byte-exact, VEX); multi-target fork refused (documented); fail #413 (re-confirmed61cfb9b); stale warning + VEX with out-of-tree env fail #502; post-rollback install fail #477static_urlsrollback byte-exact; nestedservices/*project; agent→vendored takeover); post-rollback /removeinstall fail #477.pdm.tomlpython.pathexternal venv)pdm add→ uninstallable lock (PDM reuse, #331); re-scan repairs (pass)pdm add→ rollback fails closed;pdm lock→ re-scan → rollback (pass)Modes × macOS/Windows for hosted and vendored: untested by this routine (the repo's pdm-compatibility.yml covers them).
Global mode (
-g, maintainer request)pdm use -g→global-project/.venv--global-prefix(incl. space/unicode path, install.cache symlink per-file)cpython@3.12venv.in_project=false→<data>/pdm/venvs/global-project-*pdm use -g <pdm python>(no venv)global-project/.venvscan --jsondrops the reason (#424)-g --mode hostedand--global-prefix --mode hostedrefuse with exit 2 (pass).SOCKET_GLOBAL=1matches-g(pass).--global-prefix <site-packages>finds both #451 locations (pass).Backlog
__pypackages__(PEP 582) project, hosted mode gives no stale-install warning andvexattests not_affected while the copypdm runimports is still unpatched #528 on PDM 1.4.5 / 1.15.5 (PEP 582 default) and agent-gwith PEP 582.-gmatrix on main; PDM 1.4.5 / 2.0.3 global projects; macOS / Windows global dirs.rollback --preserve-state; PDM 1.xfeature.install_cachewith agent mode.pdm.lockhosted + vendored on 2.12 / 2.29; concurrentscanruns (--lock-timeout).git push --deletefails through the git proxy; the stalebughunt/pdm/20260930-cache-symlinkstill needs a maintainer to delete it).-Gdev/optional,--prod), relocks (update --unconstrained/--update-all/--update-reuse,lock --refresh), vendored relocks,pdm addafter hosted/vendored on 2.12–2.29, Agent and hosted mode ignore the interpreter PDM records in .pdm-python (venv.in_project = false, pdm use <venv>), so the real env is skipped or a stray .venv / the PATH python is patched, and VEX attests an unpatched install #502 on 1.15.5 / 2.0.3.Known non-bugs
__pypackages__(PEP 582) not crawled; agent mode falls through to the PATH interpreter (documented). Hosted mode installs into__pypackages__fine.pdm lock,pdm update <pkg>) drops the hosted / vendored patch (documented; re-scan). Measured:pdm lock --refreshactually keeps it on 2.12.4 and 2.29.2 (the doc's claim is conservative drift, not a bug). Rollback still works when the package stays at the same version.redirect_pdm_stale_install_risk, documented).vendor_fetch_unverifiable), by design.path(redirect_pdm_refused), by design (hosted-direction takeover is warn-only). Hosted→vendored for PyPI fails closed withpypi_pdm_source_already_exists(the same for uv/poetry): runrollbackfirst.pdm lock --append) lock holding the package at two versions is refused (redirect_pdm_refused), documented.install.cache_method=pth: agent apply fails closed withFile not found.pdm lockwithout-Gdoes not lock optional groups (PDM behaviour, not a socket-patch bug).redirected: 0on lock-only projects, so it can't be used to bisect hosted findings.pdm remove, upgrade): exit 1Manifest not foundis the documented truly-empty result (formerly Hosted PDM rollback and remove fail permanently once the patched package leaves pdm.lock (pdm remove, or an upgrade to another version), and the suggested re-scan doesn't help #382).cross_platform(PDM ≥ 2.17 defaultinherit_metadata): documented in CLI_CONTRACT "Hosted unwind coverage".cross_platformlock writes every PyPI release file (e.g. pyyaml 6.0.1: 51), where PDM locked a requires-python-filtered subset (39). Installs andlock --checkare unaffected; cosmetic.not_applied.pdm add -gwith nopdm use -ginstalls into the system interpreter, whichscan -gdoes find; only the venv and PDM-managed interpreter cases are Global scan (-g) never crawls PDM's global project venv or PDM-managed interpreters, sopdm add -gpackages are silently left out with exit 0 #451.scan -g --mode vendoredis accepted (exit 0) while hosted refuses. It isn't PDM-specific, so it's left to maintainers; not filed.rollbackdeletes the manifest entry (documented: it removes local state), so a laterapplyis a no-op.scanwithout-g/--prunedefaults to hosted and rewritespdm.lock(documented default).scan 'services/*'writes per-project.socket/, butrollbackfrom the root reportsManifest not found(use--cwd services/api). That's generic, not PDM-specific; left to maintainers..socket/manifest.jsonstays as{"patches": {}}(cosmetic).HTTPS_PROXYis unset (sandbox artifact, not a bug).pdm add <other>after hosted/vendored keeps the patched hash but drops theurl/path(an uninstallable lock, PDM reuse behaviour, known from Hosted PDM rollback reports success but leaves the patch url/hash in pdm.lock afterpdm addorpdm lock --update-reuseand a re-scan #331). Hosted re-scan repairs it. Vendored re-scan refuses (pypi_pdm_source_already_exists, "runpdm lock") and rollback fails closed (drift); thepdm lock→ re-scan → rollback path works. 2.29.2 keeps the source.pdm sync --prod --cleanleaves dev/optional-only packages installed: identical without socket-patch (PDM behaviour).viewmust answer for it. Don'tpkill -f mock, which kills the calling shell.All reactions