Skip to content

setup writes socket-patch[hook] into requirements.txt, but socket-patch-hook was never published to PyPI, so pip silently installs socket-patch 3.3.0 and no .pth hook #377

Description

[agent] Found by the scheduled pip / requirements.txt bug-hunt routine (ledger #309).

Summary

For a pip project, socket-patch setup appends the line socket-patch[hook] to requirements.txt (HOOK_DEP, crates/socket-patch-core/src/setup/pypi/detect.rs:14). The hook extra on socket-patch 4.0.0 requires socket-patch-hook (Requires-Dist: socket-patch-hook; extra == "hook", scripts/build-pypi-wheels.py:197). But socket-patch-hook doesn't exist on PyPI: https://pypi.org/pypi/socket-patch-hook/json and /simple/socket-patch-hook/ both return 404, and .github/workflows/publish-pypi.yml has never run.

pip therefore can't satisfy socket-patch 4.0.0's [hook] extra. It backtracks to socket-patch 3.3.0, which has no hook extra, prints a WARNING, and reports success. No startup .pth is installed, so the committed .socket/ patches are never re-applied after a reinstall, even though setup reported status: success, updated: 1.

Impact

  • The whole agent-mode + setup flow for pip (README "Python (pip / uv / poetry / pdm / hatch)": "Installing it lays down a startup .pth … that re-applies your committed .socket/ patches") silently doesn't work. After pip install --force-reinstall or a fresh venv, the package stays unpatched.
  • As a side effect, it downgrades the user's socket-patch CLI to 3.3.0, which predates hosted and vendored modes.
  • Any other installer that resolves socket-patch[hook] from PyPI is presumably affected the same way (uv, Poetry, PDM, Hatch). I only verified pip, so the other routines may want to confirm.

Repro

python -m venv v
v/bin/pip install --no-cache-dir "socket-patch[hook]==4.0.0"
# ERROR: Could not find a version that satisfies the requirement socket-patch-hook; extra == "hook" (from socket-patch[hook]) (from versions: none)
v/bin/pip install --no-cache-dir "socket-patch[hook]"          # the exact line `setup` writes
# WARNING: socket-patch 3.3.0 does not provide the extra 'hook'
# Successfully installed socket-patch-3.3.0
v/bin/python -c "import sysconfig,os;sp=sysconfig.get_paths()['purelib'];print([f for f in os.listdir(sp) if f.endswith('.pth')])"
# []  (no socket-patch hook .pth)

End to end on main f6b7fb9 (Linux, pip 24.0): socket-patch setup --yes → requirements.txt gains socket-patch[hook] → pip install -r requirements.txt installs socket-patch 3.3.0 → socket-patch scan --mode agent patches six → pip install --force-reinstall six==1.16.0 → six stays UNPATCHED on every later interpreter start. Reproduced twice.

Expected vs actual

  • Expected (README setup, PyPI bullet): installing the dependency setup adds lays down the socket-patch-hook startup .pth, which re-applies patches. At the very least, setup or setup --check shouldn't report success for a dependency that can't be installed.
  • Actual: the hook distribution can't be installed from PyPI, pip quietly falls back to 3.3.0 with no hook, and setup reports success.

OS × version

Probe run https://github.com/SocketDev/socket-patch/actions/runs/36772070619:

OS Python 3.8 (pip 21.1 / 23.0) Python 3.13 (pip 25 / 26)
Linux fail (3.3.0 installed, no .pth) fail
macOS fail fail
Windows fail fail

First bad release

4.0.0 is the first release whose setup targets requirements.txt (3.3.0's setup is npm-only), and it is also the first whose metadata names the missing socket-patch-hook. Note: release/v5-prerelease removes setup (#279) and the PyPI distributions (#298), but main and the latest release still ship this path.

Suspect location

  • Release pipeline: .github/workflows/publish-pypi.yml:161 ("Publish socket-patch-hook to PyPI"). The workflow has no runs, and the project doesn't exist on PyPI (it needs its own trusted publisher, per the comment at :147).
  • crates/socket-patch-core/src/setup/pypi/edit.rs:143 (requirements_add): writes an unpinned socket-patch[hook], which lets pip resolve it to a release with no hook extra instead of failing loudly. Pinning to the running CLI version (socket-patch[hook]==4.0.0) would at least turn this into a visible install error.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions