Bug hunt ledger: PDM #312
Replies: 4 comments
|
[agent] 2026-09-30: PDM bug-hunt run First run. The ledger was empty and there were no earlier Tested: main Filed
Cells covered (Linux unless noted)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-09-30: PDM bug-hunt run Tested: main Filed / commented
Re-triage
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-10-01: PDM bug-hunt run Tested: main Filed / closed
Cells covered (Linux)
Ruled out / not filed
Housekeeping
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where PDM puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × PDM version cells for |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled PDM bug-hunt routine (label pm:pdm).
Last run: 2026-10-01 03:16Z on main
2463257(v5 consolidation #277; latest tag v4.0.0). Linux runs use real PDM against a local mock patch API, because the sandbox blocks the Socket patch hosts. macOS and Windows runs use probe branches.Coverage matrix
__pypackages__sync, legacy[metadata.files]); untested on v5Modes × macOS/Windows for hosted and vendored: untested by this routine (the repo's pdm-compatibility.yml covers them).
Backlog
-g) mode for hosted patches on Linux, macOS and Windows across every major PDM version.scan -gmust report exactly the global installs that have hosted patches;-g --mode hostedmust refuse loudly;-gapply, rollback and vex must hit the real global copy. Full checklist in the 20261001T040000Z entry on this discussion.vendored_backend): 2.29.2 / 2.12.4 / 1.4.5, incl. private index + static_urls.pdm update --unconstrained/lock --update-allon hosted.feature.install_cachewith agent mode.bughunt/pdm/20260930-cache-symlinkstill needs a maintainer to delete it).Known non-bugs
__pypackages__(PEP 582) not crawled; agent mode falls through to the PATH interpreter (documented). Hosted mode installs into__pypackages__fine.pdm lock,--refresh,pdm update <pkg>) drops the hosted redirect (documented; re-scan). Rollback still works when the package stays at the same version.redirect_pdm_stale_install_risk, documented).vendor_fetch_unverifiable), by design.path(redirect_pdm_refused), by design (hosted-direction takeover is warn-only). Hosted→vendored for PyPI fails closed withpypi_pdm_source_already_exists(the same for uv/poetry): runrollbackfirst.pdm lock --append) lock holding the package at two versions is refused (redirect_pdm_refused), documented.install.cache_method=pth: agent apply fails closed withFile not found.pdm lockwithout-Gdoes not lock optional groups (PDM behaviour, not a socket-patch bug).redirected: 0on lock-only projects, so it can't be used to bisect hosted findings.pdm remove, upgrade): exit 1Manifest not foundis the documented truly-empty result (formerly Hosted PDM rollback and remove fail permanently once the patched package leaves pdm.lock (pdm remove, or an upgrade to another version), and the suggested re-scan doesn't help #382).cross_platform(PDM ≥ 2.17 defaultinherit_metadata): documented in CLI_CONTRACT "Hosted unwind coverage".cross_platformlock writes every PyPI release file (e.g. pyyaml 6.0.1: 51), where PDM locked a requires-python-filtered subset (39). Installs andlock --checkare unaffected; cosmetic.not_applied.All reactions