Skip to content

Fix global scan missing pipx venvs (#415) - #418

Merged
Mikola Lysenko (mikolalysenko) merged 3 commits into
mainfrom
agent/fix-global-pipx-venv-discovery
Oct 1, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 3 commits into
mainfrom
agent/fix-global-pipx-venv-discovery

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

Fixes #415

Summary

scan -g, apply -g, rollback -g and vex -g now find packages inside pipx's per-app venvs, so the dependencies of a pipx-installed tool such as Hatch (pipx install hatch, one of Hatch's documented install methods) are reported, patched and rolled back like uv-tool installs already are.

Root cause

get_global_python_site_packages (crates/socket-patch-core/src/crawlers/python_crawler.rs) probes uv tool venvs, conda, pyenv, Homebrew, the python.org framework and pip --user, but never probed pipx's venvs.

Change

  • New pipx_home_candidates() returns every directory pipx may use as its home: $PIPX_HOME, legacy ~/.local/pipx, and platformdirs' data dir ($XDG_DATA_HOME/pipx, default ~/.local/share/pipx, on Linux; ~/Library/Application Support/pipx on macOS; %USERPROFILE%\pipx and %LOCALAPPDATA%\pipx\pipx on Windows).
  • Global discovery scans <home>/venvs/*/{lib,lib64}/python3.*/site-packages (Unix) or <home>\venvs\*\Lib\site-packages (Windows) for each candidate that exists. It scans all of them, not just the one pipx would pick today: an app installed under an older default is still a real install, and the existing seen set removes overlaps.
  • No wrapper changes are needed (npm/, pypi/, gem/ only dispatch to the binary).
  • The diff is 2 files. The first fix commit accidentally ran cargo fmt --all over the workspace; d391f14 restores the 126 unrelated files to main.

Test evidence

New tests in crates/socket-patch-core/tests/crawler_python_e2e.rs (each stages a venv under a stubbed HOME / PIPX_HOME / XDG_DATA_HOME):

Test Layout Platforms
..._discovers_pipx_venvs_linux ~/.local/share/pipx/venvs/{hatch,black} Linux
..._discovers_pipx_venvs_under_xdg_data_home $XDG_DATA_HOME/pipx/venvs/hatch Linux
..._discovers_pipx_venv_lib64 venvs/hatch/lib64/python3.11/site-packages Unix
..._discovers_pipx_venvs_legacy_home ~/.local/pipx/venvs/hatch Unix
..._discovers_pipx_venvs_macos_app_support ~/Library/Application Support/pipx macOS
..._discovers_pipx_venvs_windows %USERPROFILE%\pipx\venvs\hatch\Lib\site-packages Windows
..._discovers_pipx_venvs_under_pipx_home $PIPX_HOME/venvs/hatch (path with a space) all
  • Red before the fix (Linux): cargo test -p socket-patch-core --all-features --test crawler_python_e2e pipx gave 5 failed, 0 passed.
  • Green after: crawler_python_e2e gave 47 passed, 0 failed.
  • Real pipx check: pipx==1.7.1 install pycowsay under a scratch HOME, then scan -g --json --ecosystems pypi. scannedPackages was 42 on main and is 43 with this branch (the pipx venv's package).
  • cargo clippy --workspace --all-features -- -D warnings is clean. The added code is rustfmt-clean. cargo fmt --all -- --check isn't clean on main itself, and CI doesn't run it, so this PR leaves the rest of the workspace alone.
  • cargo test --workspace --all-features --no-fail-fast: everything passes except 16 write-failure tests in covgap_commands_vendor, in_process_redirect, repair and core --lib. They simulate write failures with chmod 0o555, which the root-run sandbox bypasses, and none of them touch the code changed here. They pass in CI, which runs as non-root.
  • CI on d391f14: all 6 workflows that ran are green (CI, Audit GHA Workflows, npm, pnpm, Pipenv, vlt). Bugbot reviewed d391f14 and found no issues.

Per-issue checklist


Generated by Claude Code

Assisted-by: Claude Code:claude-opus-5-5
scan -g, apply -g, rollback -g and vex -g never looked inside pipx's
per-app venvs, so the dependencies of a pipx-installed tool such as
Hatch were never reported or patched on any OS. Global discovery now
scans <pipx home>/venvs/* under PIPX_HOME and every pipx default home.

Fixes #415

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

The previous commit ran rustfmt over the whole workspace, which
reformatted 126 files the fix doesn't touch. Restore them to main so
the PR only carries the pipx discovery change and its tests.

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit d391f14. Configure here.

@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 1, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[burn-down agent] Ready for review on d391f14: mergeable, 0 commits behind main.

  • CI: 97/97 completed checks green on d391f14 (3 skipped by workflow conditions).
  • Bugbot: reviewed d391f14, no new issues; 0 unresolved review threads.
  • Reviewer note: New pipx home probing in python_crawler.rs (pipx_home_candidates); reviewer may want to check the Windows/macOS home paths.

Generated by Claude Code

@mikolalysenko
Mikola Lysenko (mikolalysenko) merged commit 6b8b355 into main Oct 1, 2026
338 checks passed
@mikolalysenko
Mikola Lysenko (mikolalysenko) deleted the agent/fix-global-pipx-venv-discovery branch October 1, 2026 16:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Global scan (-g) never crawls pipx venvs, so the dependencies of a pipx-installed Hatch are never reported, patched or rolled back on any OS

3 participants