Fix global scan missing pipx venvs (#415) - #418
Merged
Mikola Lysenko (mikolalysenko) merged 3 commits intoOct 1, 2026
Merged
Conversation
Assisted-by: Claude Code:claude-opus-5-5
scan -g, apply -g, rollback -g and vex -g never looked inside pipx's per-app venvs, so the dependencies of a pipx-installed tool such as Hatch were never reported or patched on any OS. Global discovery now scans <pipx home>/venvs/* under PIPX_HOME and every pipx default home. Fixes #415 Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko)
marked this pull request as ready for review
October 1, 2026 05:01
Collaborator
Author
|
BugBot review Generated by Claude Code |
The previous commit ran rustfmt over the whole workspace, which reformatted 126 files the fix doesn't touch. Restore them to main so the PR only carries the pipx discovery change and its tests. Assisted-by: Claude Code:claude-opus-5-5
Collaborator
Author
|
BugBot review Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit d391f14. Configure here.
Collaborator
Author
|
[burn-down agent] Ready for review on
Generated by Claude Code |
This was referenced Oct 1, 2026
Wenxin Jiang (Wenxin-Jiang)
approved these changes
Oct 1, 2026
Mikola Lysenko (mikolalysenko)
deleted the
agent/fix-global-pipx-venv-discovery
branch
October 1, 2026 16:48
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by Claude Code:claude-opus-5-5
Fixes #415
Summary
scan -g,apply -g,rollback -gandvex -gnow find packages inside pipx's per-app venvs, so the dependencies of a pipx-installed tool such as Hatch (pipx install hatch, one of Hatch's documented install methods) are reported, patched and rolled back like uv-tool installs already are.Root cause
get_global_python_site_packages(crates/socket-patch-core/src/crawlers/python_crawler.rs) probes uv tool venvs, conda, pyenv, Homebrew, the python.org framework and pip--user, but never probed pipx's venvs.Change
pipx_home_candidates()returns every directory pipx may use as its home:$PIPX_HOME, legacy~/.local/pipx, and platformdirs' data dir ($XDG_DATA_HOME/pipx, default~/.local/share/pipx, on Linux;~/Library/Application Support/pipxon macOS;%USERPROFILE%\pipxand%LOCALAPPDATA%\pipx\pipxon Windows).<home>/venvs/*/{lib,lib64}/python3.*/site-packages(Unix) or<home>\venvs\*\Lib\site-packages(Windows) for each candidate that exists. It scans all of them, not just the one pipx would pick today: an app installed under an older default is still a real install, and the existingseenset removes overlaps.npm/,pypi/,gem/only dispatch to the binary).cargo fmt --allover the workspace;d391f14restores the 126 unrelated files tomain.Test evidence
New tests in
crates/socket-patch-core/tests/crawler_python_e2e.rs(each stages a venv under a stubbedHOME/PIPX_HOME/XDG_DATA_HOME):..._discovers_pipx_venvs_linux~/.local/share/pipx/venvs/{hatch,black}..._discovers_pipx_venvs_under_xdg_data_home$XDG_DATA_HOME/pipx/venvs/hatch..._discovers_pipx_venv_lib64venvs/hatch/lib64/python3.11/site-packages..._discovers_pipx_venvs_legacy_home~/.local/pipx/venvs/hatch..._discovers_pipx_venvs_macos_app_support~/Library/Application Support/pipx..._discovers_pipx_venvs_windows%USERPROFILE%\pipx\venvs\hatch\Lib\site-packages..._discovers_pipx_venvs_under_pipx_home$PIPX_HOME/venvs/hatch(path with a space)cargo test -p socket-patch-core --all-features --test crawler_python_e2e pipxgave 5 failed, 0 passed.crawler_python_e2egave 47 passed, 0 failed.pipx==1.7.1 install pycowsayunder a scratchHOME, thenscan -g --json --ecosystems pypi.scannedPackageswas 42 on main and is 43 with this branch (the pipx venv's package).cargo clippy --workspace --all-features -- -D warningsis clean. The added code is rustfmt-clean.cargo fmt --all -- --checkisn't clean onmainitself, and CI doesn't run it, so this PR leaves the rest of the workspace alone.cargo test --workspace --all-features --no-fail-fast: everything passes except 16 write-failure tests incovgap_commands_vendor,in_process_redirect,repairand core--lib. They simulate write failures withchmod 0o555, which the root-run sandbox bypasses, and none of them touch the code changed here. They pass in CI, which runs as non-root.d391f14: all 6 workflows that ran are green (CI, Audit GHA Workflows, npm, pnpm, Pipenv, vlt). Bugbot reviewedd391f14and found no issues.Per-issue checklist
PIPX_HOME(all of the tests above).Generated by Claude Code