|
| 1 | +[agent] 2026-10-01: Poetry bug-hunt run |
| 2 | + |
| 3 | +**Tested:** main `6e7ef74` (it now includes #330 `5678b76`, "Fix Poetry venv discovery to match Poetry (#327, #329)"). Latest release 4.0.0. Linux only. Real Poetry 1.1.15 (py3.9), 1.8.5, 2.0.1 and 2.5.1 installs. Two local mock patch APIs (agent, hosted grant and wheel, blob routes): one for `six` 1.16.0, one for `jaraco.context` 4.3.0 with a dotted or canonical purl. A local pypi.org forwarder (`SOCKET_PYPI_JSON_API`) for the hosted rollback and takeover legs. |
| 4 | + |
| 5 | +## Re-triage |
| 6 | + |
| 7 | +- **#327 / #329** were closed by #330. I verified the Linux side of the fix with real Poetry: agent `scan` patches the env Poetry installed into, 2/2 each, in 18 layouts: |
| 8 | + - nameless `package-mode = false` (1.8.5, 2.0.1, 2.5.1) |
| 9 | + - `[project].name` + `[tool.poetry].name` (2.0.1, 2.5.1) |
| 10 | + - `in-project = false` + a stray `.venv` (1.8.5, 2.0.1, 2.5.1) |
| 11 | + - PEP 621 `[project]`-only (2.5.1) |
| 12 | + - a 60-char dotted/underscored name truncated to 42 characters, with a hash containing `-` (2.5.1) |
| 13 | + - a symlinked project dir (2.5.1) |
| 14 | + - relative `virtualenvs.path` in `poetry.toml` (2.5.1) |
| 15 | + - `{cache-dir}/custom-envs` (2.5.1) |
| 16 | + - `POETRY_VIRTUALENVS_PATH='~/alt envs'` (2.5.1) |
| 17 | + - `.venv` as a symlink to a venv (2.5.1) |
| 18 | + - `XDG_CACHE_HOME` (2.5.1) |
| 19 | + - a project path with a space and `é` (1.8.5, 2.0.1) |
| 20 | + |
| 21 | + The hosted half also works now: for the nameless, both-names, `in-project = false`, 1.8.5 and relative-path layouts, a stale env gives `redirect_pypi_stale_install` and `vex_omitted`, and after `poetry sync` VEX attests. Windows (#329) wasn't verified because probe branches are blocked. |
| 22 | +- **#328:** I commented with the new status (https://github.com/SocketDev/socket-patch/issues/328#issuecomment-5934259603). **Hosted → vendored now works** on Poetry 2.5.1 (`vendor_takeover_reverted_redirect`, exit 0, `poetry check --lock` OK, `poetry sync` installs the patched vendored wheel, and rollback restores the lock byte for byte). Without the PyPI forwarder it fails closed with `redirect_revert_failed`, which is a sandbox artifact. **Vendored → hosted still reproduces** (`redirect_poetry_lock_unsupported`, `redirected: 0`, exit 0). The issue stays open. |
| 23 | +- **#450:** still reproduces on `6e7ef74` (`-g` apply then project `rollback` gives `success`, the manifest is emptied, and the global copy stays patched), 2/2. `rollback.rs` is unchanged since the report. No comment. |
| 24 | + |
| 25 | +## Cells |
| 26 | + |
| 27 | +- Agent venv discovery, the 18 layouts above: **pass**. |
| 28 | +- **Agent and hosted with `virtualenvs.in-project = true` but no `./.venv`, after Poetry already created its out-of-tree env: fail. Filed #476.** Poetry keeps using the out-of-tree env (`EnvManager.get()` only takes `./.venv` when it exists), but socket-patch skips the out-of-tree probe for an explicit `true`. Agent mode patches the global user-site copy instead (`added`, exit 0), or skips with `package_not_installed` (exit 0). Hosted `scan --vex` attests `not_affected` while the env holds upstream bytes. This happens on 1.1.15, 1.8.5, 2.0.1 and 2.5.1, with `poetry.toml` and with user `config.toml`. It never worked (it isn't a #330 regression). |
| 29 | +- Full agent cycle on the nameless out-of-tree project (2.5.1): apply, re-run `skipped`, `vex` attests, `rollback` restores byte for byte. Pass 2/2. |
| 30 | +- Hosted, dotted name `jaraco.context` with both the dotted purl and the canonical `jaraco-context` purl, lock 1.1 (Poetry 1.1.15, quoted `"jaraco.context" = [...]` in `[metadata.files]`), 2.0 (1.8.5) and 2.1 (2.5.1): rewrite, real `poetry install` (patched bytes land), `vex`, and `rollback` (lock byte-identical). **Pass** in every cell. |
| 31 | +- 6 concurrent `scan --mode hosted` runs on one Poetry project: one wins and the other 5 get "Another socket-patch process is operating in this directory", exit 1. The lock is valid (`poetry check --lock`). Pass. |
| 32 | +- `vex -g` from a hosted, synced Poetry project with an unpatched global `six`: refuses (`not_applied`). Pass. |
| 33 | +- `list -g` from that project lists the project's hosted pin (`mode: hosted`, `lockfiles: [poetry.lock]`). Not filed: PR #446 already says "`vex -g` and `list -g` still read cwd lockfile discovery. Neither one writes to the project." |
| 34 | +- `virtualenvs.create = false`: blocked. The sandbox's system Python already has apt `six` (egg-info, #447), so Poetry installs nothing. |
| 35 | +- macOS / Windows: blocked. `git push origin --delete` still fails ("remote end hung up"), so I created no probe branches. |
| 36 | + |
| 37 | +## Issues |
| 38 | + |
| 39 | +- Filed #476: https://github.com/SocketDev/socket-patch/issues/476 |
| 40 | +- Commented on #328 (partially fixed). |
| 41 | + |
| 42 | +## False positives ruled out |
| 43 | + |
| 44 | +- I first saw the #476 symptom with the `jaraco.context` dotted purl and suspected name canonicalization. The canonical-purl control passed, but that project also had no `poetry.toml`. The real trigger was the `in-project = true` I'd set in the dotted-name project. Dotted purls work in every cell. |
| 45 | +- `POETRY_VIRTUALENVS_IN_PROJECT=yes` / `on`: socket-patch reads them as true, Poetry as false (`boolean_normalizer` accepts only "true" / "1"). It's a theoretical divergence and not worth filing. |
| 46 | +- When `VIRTUAL_ENV` is set **and** `envs.toml` has an entry for the project, Poetry ignores `VIRTUAL_ENV`, but socket-patch always prefers it. Contrived, so not filed. It's in the backlog. |
| 47 | + |
| 48 | +## Next |
| 49 | + |
| 50 | +1. macOS / Windows verification of #330 (#329 Windows hash, macOS case-preserving `realpath` vs Rust `canonicalize` case) once probe branches can be deleted. |
| 51 | +2. Re-test #436 / #445 on a Poetry project after PR #446 merges. |
| 52 | +3. `VIRTUAL_ENV` + `poetry env use` (envs.toml) precedence; conda `CONDA_PREFIX` as Poetry's active env. |
| 53 | +4. `socket.yml` policy (`minSeverity`, `maxNewPatches`) on a Poetry project with several patches (the mocks are now parameterized by package). |
| 54 | +5. Poetry 0.12 / 1.0 agent mode out-of-tree (Poetry 1.0's pre-1.2 hash used the unnormalized cwd). |
0 commit comments