|
| 1 | +[agent] 2026-10-09: pip / requirements.txt bug-hunt run |
| 2 | + |
| 3 | +**Tested:** main `40de3d5`; latest release v4.0.0 (the PyPI wheel, used as the baseline). The pip-relevant change since `e03a666` is #1254 (the #1249 fix). #1245 (the shared vendored revert step) doesn't touch the PyPI backends. |
| 4 | + |
| 5 | +**Setup:** real pip 26.2.1 / py3.13 and 20.3.4 / py3.8 (uv venvs). A logging batch mock on 127.0.0.1 (records the purls requested, answers empty), `SOCKET_PROXY_URL` pointed at it, and an empty `VIRTUAL_ENV`, so discovery was lock-only. pip's own `parse_requirements` and a real `pip install --no-deps -r` were the reference. No probe branches: every cell was OS-independent parsing. The mock was stopped after the run. |
| 6 | + |
| 7 | +## Re-triage |
| 8 | + |
| 9 | +- #1249 (closed by #1254): **verified fixed.** An EOF `six==1.16.0 \` with no newline, a CRLF variant, and a `-r` include ending that way are all discovered. Evidence is on #1249. |
| 10 | +- #604: **still fails** (`six==1.16` → `pkg:pypi/six@1.16`). No new information, so no comment. |
| 11 | + |
| 12 | +## Cells (Linux, lock-only) |
| 13 | + |
| 14 | +| Cell | Result | |
| 15 | +| --- | --- | |
| 16 | +| EOF `six==1.16.0 \` (no newline / CRLF / `-r` include) | pass (#1249 fixed) | |
| 17 | +| `-r dev.txt \` as the last line (include continuation at EOF) | pass | |
| 18 | +| `-e .` / `--editable ./pkg` beside a pin, and a marker continuation | pass | |
| 19 | +| **CR-only file `idna==3.4\rsix==1.16.0\r`** | **fail → #1281** (pip 20.3.4 / 26.2.1 install both; main asks for nothing; v4.0.0 asks for idna only) | |
| 20 | +| **CRLF file with one stray bare CR** | **fail → #1281** (main finds only the first pin) | |
| 21 | +| **form-feed / NEL / U+2028 separators** | **fail → #1281** | |
| 22 | +| `six==1.16.0 \\` (two backslashes) at EOF | divergence: pip strips both, main drops the pin, v4.0.0 finds it. Noted in #1281, not filed separately | |
| 23 | + |
| 24 | +## Issues |
| 25 | + |
| 26 | +- Filed #1281: https://github.com/SocketDev/socket-patch/issues/1281. `utils/requirements.rs:223` uses `content.lines()`, while pip uses `str.splitlines()`. |
| 27 | +- Commented on #1249 (fix verified): https://github.com/SocketDev/socket-patch/issues/1249#issuecomment-6082904302 |
| 28 | + |
| 29 | +## False positives ruled out |
| 30 | + |
| 31 | +- None this run. Every fail cell was checked against pip's own parser and a real install on both pip versions, and reproduced twice on main. |
| 32 | + |
| 33 | +## Next |
| 34 | + |
| 35 | +1. Hosted rewriter over a CR-only root with an installed six and a full hosted mock (it has its own `split_inclusive('\n')` splitter), and the vendored planner over it. |
| 36 | +2. Re-verify #1281 once fixed. |
| 37 | +3. Re-verify #1167 (fixed by #1168) with real pip: subdirectory `requirements/lock.txt`, the uv export variant, a root `NOTES.txt` false keep. |
| 38 | +4. #1212 follow-ups: hosted / vex / rollback over an unmodelled-codec file. |
| 39 | +5. #1039 atomic takeover: SIGKILL a vendored → hosted takeover mid-commit. |
| 40 | + |
| 41 | +--- |
| 42 | +_Generated by [Claude Code](https://claude.ai/code)_ |
0 commit comments