Bug hunt ledger: PDM #312
Replies: 13 comments
|
[agent] 2026-09-30: PDM bug-hunt run First run. The ledger was empty and there were no earlier Tested: main Filed
Cells covered (Linux unless noted)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-09-30: PDM bug-hunt run Tested: main Filed / commented
Re-triage
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-10-01: PDM bug-hunt run Tested: main Filed / closed
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where PDM puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × PDM version cells for |
|
[agent] 2026-10-01: PDM bug-hunt run Tested: main Filed / commented
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-10-01: PDM bug-hunt run Tested: main Filed / commented
Re-triage
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-10-01: PDM bug-hunt run Tested: main Filed / commented
Re-triage
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-10-02: PDM bug-hunt run Tested: main Filed / commented
Re-triage
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-10-02 (09:23Z): PDM bug-hunt run Tested: main Filed / commented
Re-triage
Cells covered (Linux, main
|
| Cell | Result |
|---|---|
hosted, CRLF pdm.lock, 2.29.2 / 2.12.4: scan keeps CRLF, lock --check, sync patched, vex, rollback byte-exact |
pass |
vendored, CRLF and mixed-ending pdm.lock, 2.29.2 / 2.12.4: scan, lock --check, sync patched, install --frozen-lockfile, vex, rollback byte-exact |
pass |
hosted, mixed CRLF/LF pdm.lock, 2.29.2 / 2.12.4: install, vex pass; rollback normalizes every line of the lock to LF (not byte-exact) |
minor, not filed (see below) |
UTF-8 BOM pdm.lock |
PDM itself rejects it (lock --check / sync fail before socket-patch runs), so out of scope |
urllib3[socks] (separate PDM extras [[package]] entry), hosted + vendored, 2.29.2 / 2.12.4: both entries rewritten, fresh frozen install patched, vex, rollback byte-exact |
pass |
vendored rollback --preserve-state → frozen install → re-scan rewires identically → rollback byte-exact; .socket/vendor removed |
pass |
3 concurrent scan runs (hosted and vendored, 2× each): one wins, the others exit 1 lock_held; lock valid, rollback byte-exact |
pass |
project path with spaces + unicode (sp ace/ünï-2.29.2): hosted, vendored, agent (apply, idempotent, vex, rollback) |
pass |
| PEP 582 hosted warning + vex (#528), 2.29.2 / 2.12.4 | fail #528 on main, pass on PR #540 |
venv.in_project=false agent + hosted (#502), 2.29.2 / 2.12.4 |
fail #502 on main, pass on PR #540 |
Ruled out / not filed
- Mixed-ending hosted rollback: scan only normalizes the edited
[[package]]unit, but hosted rollback rewrites the whole file to LF. Vendored rollback is byte-exact, and so is a pure-CRLF hosted rollback. PDM never writes a mixed lock, and the result is semantically identical (lock --checkpasses), so it's cosmetic. It does contradict pdm-compatibility.md's "preserves line endings". Recorded as a known non-bug. - BOM: PDM's own TOML reader rejects it.
- Harness pitfalls (not bugs):
pdm venv create/pdm usein a fresh dir can reuse another project's interpreter in.pdm-python; out-of-tree venvs are shared across copies of a project dir; hosted refs on a mock origin needSOCKET_PATCH_SERVER_URL; vendored grants needintegrity.sha512as SRI (sha512-<b64>).
Housekeeping
- No probe branches.
git push --deleteof the stalebughunt/pdm/20260930-cache-symlinkstill fails through the git proxy ("remote end hung up"), so it still needs a maintainer to delete it. macOS and Windows weren't covered.
Next
- Once Fix Python env discovery ignoring uv/PDM env (#502, #525, #528) #540 / Fix global Python scan missing uv and PDM installs (#449, #451) #522 merge: re-run the Agent and hosted mode ignore the interpreter PDM records in .pdm-python (venv.in_project = false, pdm use <venv>), so the real env is skipped or a stray .venv / the PATH python is patched, and VEX attests an unpatched install #502 / In a PDM
__pypackages__(PEP 582) project, hosted mode gives no stale-install warning andvexattests not_affected while the copypdm runimports is still unpatched #528 / Global scan (-g) never crawls PDM's global project venv or PDM-managed interpreters, sopdm add -gpackages are silently left out with exit 0 #451 matrix on main, including the.pdm.toml(PDM < 2.5) and PATH-python false-negative variants. - In a PDM
__pypackages__(PEP 582) project, hosted mode gives no stale-install warning andvexattests not_affected while the copypdm runimports is still unpatched #528 on PDM 1.4.5 (PEP 582 default, lock_version 2) and agent-gwith PEP 582. - Hash variant of Hosted PDM rollback and remove replace a private index's static_urls with files.pythonhosted.org, so PDM bypasses the mirror (or fails on 2.12 behind a firewall) #413 (private index serving different bytes).
- CRLF on lock_version 2 (PDM 1.4.5 legacy
[metadata.files]) for hosted and vendored. - Interrupted scan (SIGKILL mid-rewrite) leaves a coherent lock /
.socketstate.
|
[agent] 2026-10-02 (15:19Z): PDM bug-hunt run Tested: main Filed / commented
Re-triage
Cells covered (Linux, main
|
| Cell | Result |
|---|---|
-g, global project relocated via the site config, 2.29.2 / 2.12.4 |
fail #566 |
-g, same relocation via the user config (control), 2.29.2 |
pass (scan, get, rollback) |
-g, default global-project .venv (pdm use -g + global_project.user_site=true; PDM 2.29 still makes a venv), 2.29.2 |
pass |
| hosted #477 re-check, 2.29.2 | fail #477 (still) |
hosted, PDM 1.4.5 lock_version 2 (legacy [metadata.files]), CRLF lock: scan keeps CRLF, __pypackages__ sync patched, rollback byte-exact |
pass |
vendored, PDM 1.4.5 lock_version 2, CRLF lock: scan keeps CRLF, path entry, sync patched, rollback byte-exact, .socket removed |
pass |
SIGKILL at random points during hosted / vendored scan (85 kills, 2.29.2): the lock is always either original or fully rewritten, lock --check passes, re-scan → rollback byte-exact |
pass (leaves .socket-stage-pdm.lock-<uuid> litter, see below) |
Ruled out / not filed
- A SIGKILLed scan leaves
.socket-stage-pdm.lock-<uuid>files in the project root, and neither re-scan nor rollback sweeps them. It's generic staging (not PDM-specific) and only appears after a crash, so it's left to maintainers. Recorded as a known non-bug. - Harness pitfalls:
pdm add -gwith no global venv installed urllib3 1.26.18 into/usr/local/lib/python3.11/dist-packages. I couldn't remove it (denied), so later-gscan counts on python3.11 are masked; check file bytes instead.pgrep -f/pkill -fon the mock's name matches the calling shell, so use a pid file.
Housekeeping
- No probe branches; macOS and Windows weren't covered.
Next
- Global scan (-g) ignores PDM's site-wide config, so a global project relocated in /etc/xdg/pdm/config.toml is never crawled and get -g reports "applied" while the copy PDM runs stays unpatched #566 on macOS / Windows site-config paths (
/Library/Application Support/pdm,%PROGRAMDATA%\pdm\pdm) and forvenv.location/python.install_rootin the site config (use a non-3.11 interpreter, or a release the system copy doesn't have). - Once Fix Python env discovery ignoring uv/PDM env (#502, #525, #528) #540 merges: re-run the Agent and hosted mode ignore the interpreter PDM records in .pdm-python (venv.in_project = false, pdm use <venv>), so the real env is skipped or a stray .venv / the PATH python is patched, and VEX attests an unpatched install #502 / In a PDM
__pypackages__(PEP 582) project, hosted mode gives no stale-install warning andvexattests not_affected while the copypdm runimports is still unpatched #528 matrix on main (.pdm.tomlPDM < 2.5, PATH-python false negative). - In a PDM
__pypackages__(PEP 582) project, hosted mode gives no stale-install warning andvexattests not_affected while the copypdm runimports is still unpatched #528 on PDM 1.4.5 (PEP 582 default) with agent-g; PDM 1.x global project (~/.pdm/global-project,~/.pdm/config.toml) under-g. - Hash variant of Hosted PDM rollback and remove replace a private index's static_urls with files.pythonhosted.org, so PDM bypasses the mirror (or fails on 2.12 behind a firewall) #413 (private index serving different bytes).
- Agent mode on PDM 1.4.5 / 1.15.5 (still untested).
|
[agent] 2026-10-02 (21:12Z): PDM bug-hunt run Tested: main Filed / commented
Re-triage
Cells covered (Linux, main
|
| Cell | Result |
|---|---|
agent, 2.29.2, base .pdm-python + pdm.toml use_venv = "false" (PDM-written) + activated venv / stray .venv |
fail #609 |
agent, 2.29.2 / 2.26.9, use_venv false in the user config + stray .venv |
fail #609 |
agent, 2.29.2 / 2.26.9, pdm.toml bool use_venv = false + stray .venv / activated venv |
pass (__pypackages__ patched) |
agent, 2.29.2, PDM_USE_VENV=false + stray .venv |
pass |
agent vex after the #609 mis-patch |
pass (fails closed, not_applied) |
agent, PDM 1.4.5 (lock_version 2, .pdm.toml python.path, PEP 582 default): plain, activated venv, stray .venv |
pass (all 3) |
agent, PDM 1.15.5 (.pdm.toml, PEP 582): plain, stray .venv |
pass |
agent, PDM 2.0.3 pdm use -f <base> → PEP 582 with .pdm.toml python.path: plain, stray .venv, activated venv |
pass (all 3) |
pdm config -l python.use_venv false output by version |
bool on 2.12.4 / 2.20.1 / 2.24.2 / 2.26.9; string on 2.27.0 / 2.28.2 / 2.29.0 / 2.29.2 |
-g user-config parsing (global_project.path, venv.location, python.install_root) |
code read only; all string settings, so not affected by the 2.27 string change |
Ruled out / not filed
- Hosted stale-install warning / VEX under the PDM PEP 582 detection misses
python.use_venv = falseas PDM 2.27+ writes it (a TOML string) and in the user config, so agent mode patches an activated or stray venv and leaves__pypackages__unpatched #609 config: hosted never patches the stray venv, and VEX fails closed, so there's no separate false attestation. - PDM 2.0–2.4 treat a
.pdm.tomlwithout.pdm-pythonas "legacy, use_venv off". 2.0.3 withpdm use -f <base>really does use__pypackages__, so this matches PDM.
Housekeeping
- No probe branches; macOS and Windows weren't covered. Deleting the stale
bughunt/pdm/20260930-cache-symlinkwas denied by this session's permission policy, so it still needs a maintainer.
Next
- PDM PEP 582 detection misses
python.use_venv = falseas PDM 2.27+ writes it (a TOML string) and in the user config, so agent mode patches an activated or stray venv and leaves__pypackages__unpatched #609 on macOS / Windows user-config paths, plus the site config andPDM_CONFIG_FILEvariants. Check whether other PDM ≥ 2.27 string-valued settings matter elsewhere (e.g.venv.in_project = "false"for hosted/vendored stale checks). - Global scan (-g) ignores PDM's site-wide config, so a global project relocated in /etc/xdg/pdm/config.toml is never crawled and get -g reports "applied" while the copy PDM runs stays unpatched #566 on macOS / Windows site-config paths; PDM 1.x global project (
~/.pdm/global-project) under-g. - Re-run After a hosted or vendored PDM rollback, pdm sync / pdm install keep the patched build installed, though rollback says the next install restores it #477 hosted rollback on main once
pdm.rs/pypi_locks.rschange (re-arm the hosted mock: references + view endpoints). - Hash variant of Hosted PDM rollback and remove replace a private index's static_urls with files.pythonhosted.org, so PDM bypasses the mirror (or fails on 2.12 behind a firewall) #413 (private index serving different bytes).
- Agent mode with PDM install.cache on 1.x (
feature.install_cache).
|
[agent] 2026-10-03 (03:15Z): PDM bug-hunt run Tested: main Filed
Re-triage
Cells covered (Linux, main
|
| Cell | Result |
|---|---|
hosted, PDM 0.12.3 (legacy [tool.pdm] manifest, lock 2), fresh env: scan → sync → re-scan → rollback |
pass (patched installed, rollback byte-exact); vex fail #642 |
| vendored, PDM 0.12.3, fresh env | pass (patched installed, rollback byte-exact); vex fail #642 |
hosted / vendored, PDM 1.0.0 ([project], lock 2), fresh env |
pass (patched installed, vex not_affected, rollback byte-exact) |
| hosted / vendored, PDM 1.5.3 (lock 2), fresh env | pass (patched installed, rollback byte-exact) |
| vendored, warm env, PDM 1.4.5 / 1.5.3 / 2.8.2 / 2.10.4 | fail #641 |
| vendored, warm env, PDM 2.11.2 / 2.29.2 | pass |
| hosted, warm env, PDM 2.10.4 (control) | pass (warns, vex fails closed) |
PDM 1.6.4 lock (lock_version "3"), hosted / vendored |
pass (refused redirect_pdm_refused / pypi_pdm_lock_version_unsupported, lock untouched) |
lock_version by release |
1.5.3 → 2, 1.6.4 → 3, 1.7.2 → 3.1 |
Ruled out / not filed
- PDM 1.5.x writes lock_version 2 and installs hosted/vendored rewrites correctly, so the accepted-format boundary is right. Docs nit: pdm-compatibility.md says "0.12 – 1.4 → 2" and "1.8 – 1.15 → 3.1", but 1.5.x also writes
2, 1.6.x writes3and 1.7.x writes3.1. Both are refused correctly, so it's doc drift only, not filed. - The vendored
vexattestation over an out-of-sync tree is by design (documented by thevendored_tree_out_of_syncdisclosure). Vendored PDM < 2.11 gives no stale-install warning, so after pdm sync the unpatched release stays installed while vex attests not_affected #641 is about the missing scan-time warning and the misleading remedy on PDM < 2.11. - PDM 1.5.3
pdm syncexits 1 only because it tries to self-install the throwaway project (harness artifact; urllib3 itself installed patched).
Housekeeping
- No probe branches this run (both findings come from PDM's installer and metadata handling, not the OS). The stale
bughunt/pdm/20260930-cache-symlinkstill needs a maintainer to delete it.
Next
- Vendored PDM < 2.11 gives no stale-install warning, so after pdm sync the unpatched release stays installed while vex attests not_affected #641 follow-ups: PEP 582
__pypackages__on PDM 1.x with vendored (a warm__pypackages__with no venv probe);pdm sync --reinstallas the documented remedy per version. - PDM PEP 582 detection misses
python.use_venv = falseas PDM 2.27+ writes it (a TOML string) and in the user config, so agent mode patches an activated or stray venv and leaves__pypackages__unpatched #609 on macOS / Windows user-config paths, site config andPDM_CONFIG_FILE. - Global scan (-g) ignores PDM's site-wide config, so a global project relocated in /etc/xdg/pdm/config.toml is never crawled and get -g reports "applied" while the copy PDM runs stays unpatched #566 on macOS / Windows site-config paths; PDM 1.x global project under
-g. - Re-run After a hosted or vendored PDM rollback, pdm sync / pdm install keep the patched build installed, though rollback says the next install restores it #477 / Hosted PDM rollback and remove replace a private index's static_urls with files.pythonhosted.org, so PDM bypasses the mirror (or fails on 2.12 behind a firewall) #413 once
patch/redirect/pdm.rsorupstream/pypi_locks.rschange. - Hash variant of Hosted PDM rollback and remove replace a private index's static_urls with files.pythonhosted.org, so PDM bypasses the mirror (or fails on 2.12 behind a firewall) #413; agent mode with PDM 1.x
feature.install_cache.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled PDM bug-hunt routine (label pm:pdm).
Last run: 2026-10-03 03:15Z on main
045d7ec(latest tag v4.0.0; #522 and #540 merged; #332/#451/#502/#528 closed by maintainers). Linux runs use real PDM against a local mock patch API, because the sandbox blocks the Socket patch hosts. macOS and Windows runs use probe branches.Coverage matrix
__pypackages__sync, legacy[metadata.files], rollback byte-exact; CRLF lock passd63ae5f); post-rollback install fail #477d63ae5f(CRLF lock, sync patched, rollback byte-exact).pdm.tomlpython.path) / untested / untestedvenv.in_project=false; pass on PR #540)pdm addrepair); fail #528 (PEP 582 stale warning + VEX; pass on PR #540); fail #413 (private index static_urls); post-rollback install fail #477; CRLF lock pass; extras[socks]pass[socks]); post-rollback install fail #477.venv); fail #502 Linux (venv.in_project=false/pdm use <venv>: real env skipped, stray.venvor PATH python patched; pass on PR #540); space/unicode path pass__pypackages__: no stale warning, VEX attests; pass on PR #540); CRLF lock pass, mixed-ending rollback LF-normalizes (cosmetic); extras[socks]pass; concurrent scanslock_heldpass; space/unicode path pass; pass on v5 (dev/optional groups,update --update-all/--update-reuse/--unconstrained,lock --refreshkeeps patch, lock-only scan, sync, manifest-less rollback byte-exact, VEX); multi-target fork refused (documented); fail #413 (re-confirmed61cfb9b); stale warning + VEX with out-of-tree env fail #502; post-rollback install fail #477static_urlsrollback byte-exact; nestedservices/*project; agent→vendored takeover; CRLF / mixed-ending lock; extras[socks];rollback --preserve-state→ re-scan; concurrent scans; space/unicode path); post-rollback /removeinstall fail #477.pdm.tomlpython.pathexternal venv)pdm add→ uninstallable lock (PDM reuse, #331); re-scan repairs (pass)pdm add→ rollback fails closed;pdm lock→ re-scan → rollback (pass).pdm.tomlpython.path; plain, activated venv, stray.venv) pass on045d7ecpdm.tomluse_venv = "false"(PDM-written string) + activated / stray venv: fail #609; bool form andPDM_USE_VENVpassuse_venvfalse in the user config + stray venv: fail #609[tool.pdm])vex/scan --vexfail #642vexfail #642pdm sync/installkeep upstream, vex attests: fail #641Modes × macOS/Windows for hosted and vendored: untested by this routine (the repo's pdm-compatibility.yml covers them).
Global mode (
-g, maintainer request)pdm use -g→global-project/.venvd63ae5f(#451 fixed)--global-prefix(incl. space/unicode path, install.cache symlink per-file)cpython@3.12venv.in_project=false→<data>/pdm/venvs/global-project-*venv.location, apply + rollback)global_project.pathset in the site config/etc/xdg/pdm/config.tomlpdm use -g <pdm python>(no venv)global-project/.venvscan --jsondrops the reason (#424)-g --mode hostedand--global-prefix --mode hostedrefuse with exit 2 (pass).SOCKET_GLOBAL=1matches-g(pass).--global-prefix <site-packages>finds both #451 locations (pass).Backlog
__pypackages__(PDM 1.x); per-versionpdm sync --reinstallremedy.python.use_venv = falseas PDM 2.27+ writes it (a TOML string) and in the user config, so agent mode patches an activated or stray venv and leaves__pypackages__unpatched #609 on macOS / Windows user-config paths, site config,PDM_CONFIG_FILE. (PDM ≥ 2.27 stringvenv.in_projectdoesn't matter: socket-patch never reads it and follows.pdm-pythoninstead.)venv.location/python.install_root(use a non-3.11 interpreter). PDM 1.x global project (~/.pdm/global-project) under-g.patch/redirect/pdm.rsorupstream/pypi_locks.rschange (hosted mock: references + view).feature.install_cachewith agent mode; PDM 1.8 – 1.14 agent cells.bughunt/pdm/20260930-cache-symlinkneeds a maintainer to delete it).__pypackages__(PEP 582) project, hosted mode gives no stale-install warning andvexattests not_affected while the copypdm runimports is still unpatched #528 on main for 1.4.5 / 1.15.5 / 2.0.3 agent PEP 582; CRLF lock_version 2, SIGKILL-interrupted scans, groups, relocks,pdm addafter hosted/vendored, CRLF / mixed / BOM locks, extras,rollback --preserve-state, concurrent scans, space/unicode paths.Known non-bugs
__pypackages__(PEP 582) not crawled; agent mode falls through to the PATH interpreter (documented). Hosted mode installs into__pypackages__fine.pdm lock,pdm update <pkg>) drops the hosted / vendored patch (documented; re-scan). Measured:pdm lock --refreshactually keeps it on 2.12.4 and 2.29.2 (the doc's claim is conservative drift, not a bug). Rollback still works when the package stays at the same version.redirect_pdm_stale_install_risk, documented).vendor_fetch_unverifiable), by design.path(redirect_pdm_refused), by design (hosted-direction takeover is warn-only). Hosted→vendored for PyPI fails closed withpypi_pdm_source_already_exists(the same for uv/poetry): runrollbackfirst.pdm lock --append) lock holding the package at two versions is refused (redirect_pdm_refused), documented.install.cache_method=pth: agent apply fails closed withFile not found.pdm lockwithout-Gdoes not lock optional groups (PDM behaviour, not a socket-patch bug).redirected: 0on lock-only projects, so it can't be used to bisect hosted findings.pdm remove, upgrade): exit 1Manifest not foundis the documented truly-empty result (formerly Hosted PDM rollback and remove fail permanently once the patched package leaves pdm.lock (pdm remove, or an upgrade to another version), and the suggested re-scan doesn't help #382).cross_platform(PDM ≥ 2.17 defaultinherit_metadata): documented in CLI_CONTRACT "Hosted unwind coverage".cross_platformlock writes every PyPI release file (e.g. pyyaml 6.0.1: 51), where PDM locked a requires-python-filtered subset (39). Installs andlock --checkare unaffected; cosmetic.not_applied.pdm add -gwith nopdm use -ginstalls into the system interpreter, whichscan -gdoes find; only the venv and PDM-managed interpreter cases are Global scan (-g) never crawls PDM's global project venv or PDM-managed interpreters, sopdm add -gpackages are silently left out with exit 0 #451.scan -g --mode vendoredis accepted (exit 0) while hosted refuses. It isn't PDM-specific, so it's left to maintainers; not filed.rollbackdeletes the manifest entry (documented: it removes local state), so a laterapplyis a no-op.scanwithout-g/--prunedefaults to hosted and rewritespdm.lock(documented default).scan 'services/*'writes per-project.socket/, butrollbackfrom the root reportsManifest not found(use--cwd services/api). That's generic, not PDM-specific; left to maintainers..socket/manifest.jsonstays as{"patches": {}}(cosmetic).HTTPS_PROXYis unset (sandbox artifact, not a bug).pdm add <other>after hosted/vendored keeps the patched hash but drops theurl/path(an uninstallable lock, PDM reuse behaviour, known from Hosted PDM rollback reports success but leaves the patch url/hash in pdm.lock afterpdm addorpdm lock --update-reuseand a re-scan #331). Hosted re-scan repairs it. Vendored re-scan refuses (pypi_pdm_source_already_exists, "runpdm lock") and rollback fails closed (drift); thepdm lock→ re-scan → rollback path works. 2.29.2 keeps the source.pdm sync --prod --cleanleaves dev/optional-only packages installed: identical without socket-patch (PDM behaviour).viewmust answer for it. Don'tpkill -f mock, which kills the calling shell.pdm.lockis rejected by PDM itself (lock --check/syncfail with no socket-patch involved).SOCKET_PATCH_SERVER_URL; vendored grants needintegrity.sha512as SRI.pdm usein a fresh dir can pick another project's interpreter, so write.pdm-pythonexplicitly. Out-of-tree PDM venvs are shared between copies of a project dir, so reset them (pdm sync --reinstall) between builds..socket-stage-pdm.lock-<uuid>files in the project root that re-scan / rollback never sweep. The lock itself is always original or fully rewritten (85 kills, 2.29.2). Generic staging behaviour and crash-only, so it's left to maintainers./usr/local/lib/python3.11/dist-packagesnow carries urllib3 1.26.18 (from apdm add -gwith no global venv), which masks-gscan counts on python3.11; check the file bytes of the target copy instead..pdm.tomlwith a basepython.path(frompdm use -f <base>) as PEP 582, and discovery agrees (verified on 2.0.3).vexafter a PDM PEP 582 detection missespython.use_venv = falseas PDM 2.27+ writes it (a TOML string) and in the user config, so agent mode patches an activated or stray venv and leaves__pypackages__unpatched #609 mis-patch fails closed (not_applied), so there's no false attestation there.lock_versionby release: 1.5.x writes2(supported, installs fine), 1.6.x writes3and 1.7.x writes3.1(both refused, lock untouched). pdm-compatibility.md's "0.12 – 1.4" / "1.8 – 1.15" ranges are slightly off (doc drift only).vexattestation over an out-of-sync installed tree is by design (thevendored_tree_out_of_syncdisclosure). Vendored PDM < 2.11 gives no stale-install warning, so after pdm sync the unpatched release stays installed while vex attests not_affected #641 covers only the missing scan warning and the remedy on PDM < 2.11.resolvelib==0.7.0; PDM 1.xpdm syncexits 1 on a throwaway[project]without[tool.pdm] distribution = false(self-install), unrelated to socket-patch.All reactions