[agent] Found by the scheduled pip / requirements.txt bug-hunt routine (ledger #309).
Summary
For a pip project, socket-patch setup appends the line socket-patch[hook] to requirements.txt (HOOK_DEP, crates/socket-patch-core/src/setup/pypi/detect.rs:14). The hook extra on socket-patch 4.0.0 requires socket-patch-hook (Requires-Dist: socket-patch-hook; extra == "hook", scripts/build-pypi-wheels.py:197). But socket-patch-hook doesn't exist on PyPI: https://pypi.org/pypi/socket-patch-hook/json and /simple/socket-patch-hook/ both return 404, and .github/workflows/publish-pypi.yml has never run.
pip therefore can't satisfy socket-patch 4.0.0's [hook] extra. It backtracks to socket-patch 3.3.0, which has no hook extra, prints a WARNING, and reports success. No startup .pth is installed, so the committed .socket/ patches are never re-applied after a reinstall, even though setup reported status: success, updated: 1.
Impact
- The whole agent-mode +
setup flow for pip (README "Python (pip / uv / poetry / pdm / hatch)": "Installing it lays down a startup .pth … that re-applies your committed .socket/ patches") silently doesn't work. After pip install --force-reinstall or a fresh venv, the package stays unpatched.
- As a side effect, it downgrades the user's
socket-patch CLI to 3.3.0, which predates hosted and vendored modes.
- Any other installer that resolves
socket-patch[hook] from PyPI is presumably affected the same way (uv, Poetry, PDM, Hatch). I only verified pip, so the other routines may want to confirm.
Repro
python -m venv v
v/bin/pip install --no-cache-dir "socket-patch[hook]==4.0.0"
# ERROR: Could not find a version that satisfies the requirement socket-patch-hook; extra == "hook" (from socket-patch[hook]) (from versions: none)
v/bin/pip install --no-cache-dir "socket-patch[hook]" # the exact line `setup` writes
# WARNING: socket-patch 3.3.0 does not provide the extra 'hook'
# Successfully installed socket-patch-3.3.0
v/bin/python -c "import sysconfig,os;sp=sysconfig.get_paths()['purelib'];print([f for f in os.listdir(sp) if f.endswith('.pth')])"
# [] (no socket-patch hook .pth)
End to end on main f6b7fb9 (Linux, pip 24.0): socket-patch setup --yes → requirements.txt gains socket-patch[hook] → pip install -r requirements.txt installs socket-patch 3.3.0 → socket-patch scan --mode agent patches six → pip install --force-reinstall six==1.16.0 → six stays UNPATCHED on every later interpreter start. Reproduced twice.
Expected vs actual
- Expected (README
setup, PyPI bullet): installing the dependency setup adds lays down the socket-patch-hook startup .pth, which re-applies patches. At the very least, setup or setup --check shouldn't report success for a dependency that can't be installed.
- Actual: the hook distribution can't be installed from PyPI, pip quietly falls back to 3.3.0 with no hook, and
setup reports success.
OS × version
Probe run https://github.com/SocketDev/socket-patch/actions/runs/36772070619:
| OS |
Python 3.8 (pip 21.1 / 23.0) |
Python 3.13 (pip 25 / 26) |
| Linux |
fail (3.3.0 installed, no .pth) |
fail |
| macOS |
fail |
fail |
| Windows |
fail |
fail |
First bad release
4.0.0 is the first release whose setup targets requirements.txt (3.3.0's setup is npm-only), and it is also the first whose metadata names the missing socket-patch-hook. Note: release/v5-prerelease removes setup (#279) and the PyPI distributions (#298), but main and the latest release still ship this path.
Suspect location
- Release pipeline:
.github/workflows/publish-pypi.yml:161 ("Publish socket-patch-hook to PyPI"). The workflow has no runs, and the project doesn't exist on PyPI (it needs its own trusted publisher, per the comment at :147).
crates/socket-patch-core/src/setup/pypi/edit.rs:143 (requirements_add): writes an unpinned socket-patch[hook], which lets pip resolve it to a release with no hook extra instead of failing loudly. Pinning to the running CLI version (socket-patch[hook]==4.0.0) would at least turn this into a visible install error.
[agent] Found by the scheduled pip / requirements.txt bug-hunt routine (ledger #309).
Summary
For a pip project,
socket-patch setupappends the linesocket-patch[hook]torequirements.txt(HOOK_DEP,crates/socket-patch-core/src/setup/pypi/detect.rs:14). Thehookextra on socket-patch 4.0.0 requiressocket-patch-hook(Requires-Dist: socket-patch-hook; extra == "hook",scripts/build-pypi-wheels.py:197). Butsocket-patch-hookdoesn't exist on PyPI:https://pypi.org/pypi/socket-patch-hook/jsonand/simple/socket-patch-hook/both return 404, and.github/workflows/publish-pypi.ymlhas never run.pip therefore can't satisfy socket-patch 4.0.0's
[hook]extra. It backtracks to socket-patch 3.3.0, which has nohookextra, prints a WARNING, and reports success. No startup.pthis installed, so the committed.socket/patches are never re-applied after a reinstall, even thoughsetupreportedstatus: success, updated: 1.Impact
setupflow for pip (README "Python (pip / uv / poetry / pdm / hatch)": "Installing it lays down a startup.pth… that re-applies your committed.socket/patches") silently doesn't work. Afterpip install --force-reinstallor a fresh venv, the package stays unpatched.socket-patchCLI to 3.3.0, which predates hosted and vendored modes.socket-patch[hook]from PyPI is presumably affected the same way (uv, Poetry, PDM, Hatch). I only verified pip, so the other routines may want to confirm.Repro
End to end on main
f6b7fb9(Linux, pip 24.0):socket-patch setup --yes→requirements.txtgainssocket-patch[hook]→pip install -r requirements.txtinstalls socket-patch 3.3.0 →socket-patch scan --mode agentpatches six →pip install --force-reinstall six==1.16.0→ six stays UNPATCHED on every later interpreter start. Reproduced twice.Expected vs actual
setup, PyPI bullet): installing the dependencysetupadds lays down thesocket-patch-hookstartup.pth, which re-applies patches. At the very least,setuporsetup --checkshouldn't report success for a dependency that can't be installed.setupreportssuccess.OS × version
Probe run https://github.com/SocketDev/socket-patch/actions/runs/36772070619:
First bad release
4.0.0 is the first release whose
setuptargets requirements.txt (3.3.0'ssetupis npm-only), and it is also the first whose metadata names the missingsocket-patch-hook. Note:release/v5-prereleaseremovessetup(#279) and the PyPI distributions (#298), but main and the latest release still ship this path.Suspect location
.github/workflows/publish-pypi.yml:161("Publish socket-patch-hook to PyPI"). The workflow has no runs, and the project doesn't exist on PyPI (it needs its own trusted publisher, per the comment at:147).crates/socket-patch-core/src/setup/pypi/edit.rs:143(requirements_add): writes an unpinnedsocket-patch[hook], which lets pip resolve it to a release with nohookextra instead of failing loudly. Pinning to the running CLI version (socket-patch[hook]==4.0.0) would at least turn this into a visible install error.