Bug hunt ledger: Composer #321
Replies: 4 comments
|
[agent] 2026-09-30: Composer bug-hunt run This is the first run, so the ledger started empty and there were no Tested: main Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: Composer bug-hunt run Tested: main All fixtures were offline (path repositories, local VCS repos, a local Composer repository, and a local mock of the patch API). The sandbox's GitHub zipball problem doesn't affect any cell. Re-triage
Cells
Issues
False positives ruled out
Housekeeping
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Composer puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × Composer version cells for |
|
[agent] 2026-10-01: Composer bug-hunt run Tested: main This run took up the maintainer backlog item: global ( Re-triage
Cells (global mode)
Issues
False positives ruled out
Housekeeping
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Composer bug-hunt routine (label pm:composer).
Last updated: 2026-10-01 (run 3), main
2463257(v5 consolidation), latest release v4.0.0.Coverage matrix
Cells are "pass", "fail #N" or "untested". Upstream
composer-compatibility.ymlalready covers the plain dist-install hosted/vendored capstones for 1.10 → 2.10 on Ubuntu/Windows/macOS. This ledger tracks the edges it doesn't.setup(LF)setupCRLF / escapesoptions→ transport-options"Vendored: source install" covers both
--prefer-sourceand source-only VCS lock entries (no dist). "Agent: apply (path repo)" means the patch is written through the path-repo link into the sibling directory; see Known non-bugs.Global (
-g) mode — run 3, main2463257scan -greport (default home)-grefusal-gapply / vex / rollback~/.config), fail #438 withXDG_CONFIG_HOMECOMPOSER_HOME)Local agent scan with a user-level
$COMPOSER_HOME/config.jsonvendor-dir: fail #439 (Linux 2.8.12). Hosted on v5: #399 still reproduces.Backlog
-gmode. Remaining: a non-writable global dir must fail loudly (non-root probe),SOCKET_GLOBAL=1and space/unicode--global-prefixcells, and a re-run after On Windows, scan -g finds no Composer global packages in the default %APPDATA%\Composer home, so apply -g and vex -g silently do nothing #438/Composer crawler ignores a vendor-dir set in the global Composer config, so scan -g and agent scans report "No packages found" and leave installs unpatched #439 are fixed.notification-url,ssltransport options). Re-check Composer vendor copies a --prefer-source package's .git into .socket/vendor, so git commits it as an embedded repo and a fresh clone installs an empty package #355 on v5 vendored.install-path(a WordPress plugin) for agent apply and vendored discovery, Composer 2 vs 1.COMPOSER=<other>.jsonprojects (crawler vendor-dir resolution).vendor+composer install; an interrupted vendor followed byrepair.bughunt/composer/20260930-srconly-probeandbughunt/composer/20261001-global-probe(the sandbox git proxy refuses deletes). Needs a maintainer.Known non-bugs
composer update <pkg>drops the wiring (documented). Re-runscan.composer installafter rewiring (documented). Removevendor/<v>/<n>first."packages-dev": nulllock: Composer 2.8 itself can't install from it.npm link/file:posture, and Composer created the link from the user's own composer.json./in a dev branch version (dev-feature/foo) withunsafe_coordinates: an explicit fail-closed refusal on a shape Socket patches don't target.setup(and its--check/ CRLF issues) is gone in v5 (v5 prerelease: scan → vex → vendor workflow, hosted by default #277/v5: removesetup(WS7) + patch UI streamlining (WS8) #279). Don't filesetupbugs against main.vendor/.gitignorepattern also ignores.socket/vendor/. Use/vendor/.-gkeeps.socket/manifest.jsonin the cwd, so runrollback -gfrom the same directory. This is per-cwd manifest design.beforeBlobContentor a/patches/blob/<hash>route, or rollback fails with "Before blob could not be downloaded".composer global config <key> '<json>'throughcomposer.batmangles the quotes. Write$COMPOSER_HOME/composer.jsondirectly.All reactions