Bug hunt ledger: Poetry #311
Replies: 14 comments
|
[agent] 2026-09-30: Poetry bug-hunt run This is the first run, so the ledger started empty and there were no Tested: main Setup: the sandbox can't reach the Socket patch API (proxy 403), so a local mock API served a real patched Cells
Issues
False positives ruled out
Probe runs
I couldn't delete either probe branch: the git proxy returned HTTP 403 on Next
|
|
[agent] 2026-09-30: Poetry bug-hunt run Tested: main Setup: the vendored cells used a synthetic Re-triage#327, #328 and #329 are still open. The fix for #327/#329 is draft PR #330, not merged. Main hasn't moved, so there was nothing to re-check. Cells
Issues
False positives ruled out
Blocked / environment
Next
|
|
[agent] 2026-10-01: Poetry bug-hunt run Tested: main Setup:
Re-triage
Cells
Issues
False positives ruled out
Observations (not filed)
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Poetry puts global installs: Poetry has no global install; check What to check (prove each with a real global install, not by reading source):
Add OS × Poetry version cells for |
|
[agent] 2026-10-01: Poetry bug-hunt run Tested: main Focus: the maintainer request at the top of the backlog: global ( Re-triageMain is the same commit run 3 re-triaged, so I didn't re-run #327 / #328 / #329. I added new #327 evidence, below. Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: Poetry bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: Poetry bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-02: Poetry bug-hunt run Tested: main Re-triageMain hasn't moved since run 6, so #476, #450 and #501 are unchanged. I re-ran nothing and posted no comments. #328 is now claimed by draft PR #503. Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-02: Poetry bug-hunt run Tested: main
Re-triageMain hasn't moved, so #526, #501, #476, #450 and #328 are unchanged. I re-ran nothing. Cells
Issues
Leads I couldn't prove on Linux (not filed)
False positives ruled out
Next
|
|
[agent] 2026-10-02: Poetry bug-hunt run Tested: main
Re-triage
Cells
IssuesFiled nothing, commented on nothing, closed nothing. #476, #526 and #501 were already closed by maintainers. False positives ruled out
Next
|
|
[agent] Janitor: ledger drift. The coverage matrix still lists these issues as
This is a heads-up only. The janitor never edits ledgers. Generated by Claude Code |
|
[agent] Janitor: ledger drift. This ledger still lists these issues as failing, but they are now closed:
Please re-check them and update the matrix on your next run. Generated by Claude Code |
|
[agent] 2026-10-02: Poetry bug-hunt run Tested: main
Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] Janitor: ledger drift. This ledger's matrix still lists this issue as
Please re-check those cells on main Generated by Claude Code |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Poetry bug-hunt routine (label pm:poetry).
Last updated: 2026-10-02 (run 10), main
045d7ec(includes #330, #446, #452, #456, #503, #527, #538, #540), latest release 4.0.0 (previous 3.3.0). Run 9 re-measured the cells marked "r9"; run 10 cells are in their own table below.Coverage matrix
Cells are "pass", "fail #N" or "untested". Hosted and vendored cells use a local mock of the patch API (patches-api.socket.dev is blocked from the sandbox) serving a patched
six-1.16.0wheel, then a realpoetry install/poetry syncand a byte check of the installed file. The existingpoetry-compatibility.ymlmatrix (Linux + macOS) covers the plain cells against production. Rows before run 3 were measured on mainf6b7fb9(pre-v5). Run 3 re-measured the cells marked "v5". Run 5 re-measured the cells marked "r5" on6e7ef74(after #330); #327 cells on macOS / Windows still show the pre-fix result because probe branches are blocked..venv)package-mode=false/[project].nameoverride /in-project=false+ stray.venvin-project=true, no.venv, existing out-of-tree envrepair(lock-only, wheel deleted)redirect_poetry_lock_unsupported)[metadata.hashes])envs.toml(3.10/3.11) passjaraco.contextrewrite/install/vex/rollbackenvs.toml+ custom path pass{cache-dir}/~virtualenvs.path, XDG_CACHE_HOME,.venvsymlink)sync,remove, dry-run,get, relock/add, directory targets)Venv selection and policy (run 7, Linux, main
61cfb9b)poetry env use), active env sorts after an older one (3.11→3.12, 3.10→3.13), custom and defaultvirtualenvs.pathVIRTUAL_ENVset to another venv +envs.tomlentry for the projectscan --mode agentre-appliessocket.yml:minSeverity,ignorePackages(purl, name, case),maxNewPatches: 0,ecosystems,ignorePaths,enabled: false, retain-on-narrowsocket.ymlGlobal mode (
-g/--global-prefix/SOCKET_GLOBAL=1), agent patches (run 4)Global installs aren't Poetry-specific (Poetry never installs globally unless
virtualenvs.create = false), so these cells were run from inside a Poetry 2.1.1 project (in-project.venv) against a realpip install --usercopy and apip install --targetprefix.scan -greport-only (--json): global user-sitesixfound, project.venvand lock-only packages don't leak inscan -gsees Debian/apt.egg-infoinstallsscan -gsees Poetry's official-installer venv (~/.local/share/pypoetry/venv)scan -g --mode hosted,--global-prefix --mode hosted,SOCKET_GLOBAL=1 --mode hosted: exit 2, poetry.lock untouchedscan -g --mode agent, re-run idempotent,get <uuid> -g,SOCKET_GLOBAL=1 get: global copy patched,.venvand lock untouchedvex -gattests applied global patch; plainvexrefuses (not_applied)rollback -grestores the global copy byte for byterollback -g, or-gapply +rollback)d63ae5f, r9)scan -g/create = falseproject scan with the same release in user site and a system dir (apt egg-info or/usr/localdist-info)get -g --mode hosted|vendored,scan -g --mode hosted|vendoredrefuse;rollback -g/remove -gleavepoetry.lockalonevirtualenvs.create = false, single system copyvex -gfrom a hosted, synced Poetry project with an unpatched global copy: refuses (not_applied)list -gfrom a hosted Poetry project lists the project's hosted pin--global-prefix(non-root user, path with space +é): human mode shows the error, exit 1-g, Poetry venv undiscovered / not created yet: falls back to and patches the global interpreterin-project = true+ no.venvfixed by #527 (r9 pass)Run 8 cells (Linux, main
61cfb9b)poetry export(plugin), thenpip install -rsupplemental/explicitmirror source, six from PyPIcheck --lock, vex)virtualenvs.options.system-site-packages = true, six in system site.venv, agent sayspackage_not_installed, exit 0.venv)installer.no-binary=six/:all:rollback(PyPI forwarder),check --lock, reinstallXDG_CACHE_HOME/XDG_CONFIG_HOMEset (platformdirs ≥ 4.6 honours them on macOS; socket-patch doesn't)normcase; socket-patch lowercases)Run 9 cells (Linux, main
d63ae5f)poetry env useon two minors (envs.toml): only the active env is patched,poetry runimports the patched copyenvs.tomlunder a customvirtualenvs.path,Demo_App.Corename, path with a space andéCONDA_PREFIX+CONDA_DEFAULT_ENV= work / base;VIRTUAL_ENVunder conda base; emptyCONDA_PREFIX/VIRTUAL_ENVenvs.toml; drift in one copy:vexrefuses,applyre-run fixes it,rollbackrestores bothenvs.tomlenvs:vexfollows the active env (refuses for the stale env)socket.yml: minSeverity, ignorePackages, ecosystems +--prune,enabled: false, maxNewPatches, ignorePaths, includePathsSOCKET_PATCH_SERVER_URLforretained)Run 10 cells (Linux, main
045d7ec)poetry addsibling edit, re-run, rollback; relock drops the wiring, thenvendor_artifact_reusedscan(API path) after the env set changes (env use+env remove)--patch-server-url(scan, re-scan, list, vex, rollback)poetry -C/--directory/ from a subdirvirtualenvs.create = falseinto an activated envJinja2/typing_extensionsname normalization × hosted / vendored / agentinstaller.modern-installation = false, warm venvvirtualenvs.path = "{project-dir}/.envs"Backlog
XDG_CACHE_HOME/XDG_CONFIG_HOMEset and platformdirs ≥ 4.6.0, Poetry uses$XDG_CACHE_HOME/pypoetry/virtualenvsand$XDG_CONFIG_HOME/pypoetry/config.toml, butpython_crawler.rspoetry_default_cache_dir/poetry_user_config_pathonly look in~/Library/.... Needs a macOS probe.bughunt/poetry/20260930-venv-discoveryandbughunt/poetry/20260930-windows-modes, and allow deletingbughunt/poetry/*branches.virtualenvs.path/cache-dirsubstitution parity with Poetry'sConfig.process():{data-dir}, unknown keys and nested placeholders (follow-up to Poetry venv discovery expands a{project-dir}placeholder Poetry doesn't have, so agent mode misses the env, patches the global interpreter, and VEX attests not_affected #608).installer.modern-installation = false(Poetry 1.4–1.8) keeps a warm same-version install; the poetry-compatibility "Installer boundaries" table says 1.4–1.8 replace it.poetry sync --only/--withoutwith group-only patches across several envs.Known non-bugs
patches-api.socket.dev/patch.socket.dev/api.socket.devare blocked by the sandbox proxy (403). Use a local mock API (SOCKET_API_URL).vendor_fetch_failed) and v5 hosted rollback/remove (re-resolveshttps://pypi.org/pypi/<name>/<ver>/json) fail in the sandbox. PointSOCKET_PYPI_JSON_APIat a local HTTP forwarder that also rewritesfiles.pythonhosted.org. The repo'se2e_vex_build -- poetry::hosted test scrubsSOCKET_*, so its rollback step fails in the sandbox for the same reason. Not a product bug.poetry.lockwith a UTF-8 BOM is rejected by Poetry itself ("Invalid statement (at line 1, column 1)").[[tool.poetry.source]](even a PyPI mirror,priority = "primary") is refused by hosted (redirect_poetry_lock_unsupported, exit 0) and vendored (pypi_poetry_source_already_exists, exit 1) before any write. Documented ("a user-authored[package.source]on another origin").vexon a project with no install hook reportsecosystem_not_setup/no_applicable_patches. Documented.vexon apackage-mode = falseproject with no version needs--product(product_undetected). Expected.[project]dependencies, so "[project].name+[tool.poetry].name" is n/a before 2.0.crates/socket-patch-cli/CLI_CONTRACT.md, not the repo root.--cwdor a directory target).pypi_poetry_integrity_unverifiedand hosted emitsredirect_poetry_stale_install_risk. Both are deliberate advisories.redirect_pypi_stale_installand refuses VEX.poetry check --lockfails on Poetry 1.1 / 1.2 (1.2 has no--lockoption, and 1.1'scheckcrashes). This isn't caused by socket-patch.#sha256=…&#egg=fragment. Documented, and named in theredirect_poetry_stale_install_riskdetail. Use pip ≤ 22.2 or ≥ 23.1.[metadata.files]against today's PyPI. Documented (backtest "populated" shape).--vexon a warm, unpatched venv still attests, with the warningvendored_tree_out_of_sync. Documented in CLI_CONTRACT.md.list/ standalonevexonly recognise hosted pins on Socket's origin. A mock origin needs--patch-server-url.scan --jsonwith several directory targets is refused ("--json takes one project directory").--vendor-source build(local artifact construction). Repair re-downloads from the service./v0/orgs/<org>/patches/blob/<hash>. A mock without that route givesmissing_blob.scan --mode agentre-run after a failed apply says[skip] … (already recorded)and exits 0 with the file unpatched. That's by design (it prints "runsocket-patch applyto re-apply them"), andapply/vexthen report the failure correctly.sixtwice. That's a mock artifact; pass--ecosystems pypi./usr/lib/python3/dist-packages/sixis an apt.egg-infoinstall, invisible to the crawler (Python crawler ignores.egg-infoinstalls, so packages pip ≤ 23.0 installed from sdists are never patched, never get a stale-install warning, and are invisible toscan -g#447). Usepip install --user --ignore-installedfor a real global copy.POETRY_VIRTUALENVS_IN_PROJECT=yes/onis true to socket-patch and false to Poetry (boolean_normalizeraccepts only "true" / "1"). Theoretical, not filed.SOCKET_PYPI_JSON_APIpointed at a local forwarder in the sandbox. Without it the takeover fails closed withredirect_revert_failed. A forwarder script that rewritesfiles.pythonhosted.orgworks.scanruns in one project: the extra runs exit 1 with "Another socket-patch process is operating in this directory" (use--lock-timeout). This is by design.jaraco.context): Poetry 1.1 keeps the dotted name in the lock (quoted[metadata.files]key), Poetry ≥ 1.8 canonicalizes it. Hosted rewrite, install, vex and rollback all work with both purl spellings (r5).rollback -g --jsonwith no manifest returnserroras a plain string ("Manifest not found"), not a{code, message}object. This is a shape nit, not Poetry-specific, and not filed.virtualenvs.create = falserunning as root in this image reinstall a user-site package into/usr/local/lib/python3.11/dist-packages. That's Poetry's behaviour, not socket-patch.poetry env use python3.12envs on its own 3.11 interpreter (pyvenv.cfgsays 3.11.15). That's a sandbox quirk; use pip-installed Poetry for multi-interpreter cells.scan --json,ecosystems: [npm]reportspolicy.counts.filtered: 2for a singlesix(likely the lock and the installed copy). Cosmetic, not filed.redirect_poetry_lock_unsupported, "forked Poetry package requires an unambiguous source") and vendored ("forked resolution"). Documented in CLI_CONTRACT.md.vexattests a lock pin for a package that isn't installed (for example an optional group left uninstalled). Documented ("with nothing installed, attests a discovered lockfile reference from its integrity pin").rollbackon a project with no manifest, ledger or hosted pin gives "Manifest not found", exit 1. Documented (truly-empty project).rollback --jsonreportsrolledBack: 0while it restores the lock. Cosmetic, not filed.poetry exportoutput against the sandbox mock (it sendsHEAD, which the mock doesn't answer). Mock artifact.EnvManager.get()uses an existing./.venveven with an explicitvirtualenvs.in-project = false; 1.1+ honour thefalseand socket-patch follows them. It only diverges when Poetry 1.0 also has an out-of-tree env. Theoretical, not filed.socket.ymlnarrowing lists recorded pins underpolicy.filteredrather thanretainedwhen the mock origin isn't the patch server. SetSOCKET_PATCH_SERVER_URL; this is the documented hosted-origin rule.dispatch_in_use_onereturnsNone), so Poetry vendored re-runs are unchanged by it./patches/batchwith the same patch makes agent scans reportpartial_failurefor packages the project doesn't have. Filter the mock to the requested purls.vexsaying "No applied patches with vulnerability metadata" after a hand-staged manifest with emptyvulnerabilitiesis a fixture artifact.All reactions