Repository navigation
Fix Pipenv project falling back to system Python (#504, #947) - #950
Merged
Mikola Lysenko (mikolalysenko) merged 4 commits intoOct 7, 2026
Merged
Conversation
Assisted-by: Claude Code:claude-opus-5-5
This was referenced Oct 6, 2026
A Pipenv project with no Pipenv venv yet must not have the OS Python's site-packages crawled as if they were the project's: agent mode patched them in place (#504), and vendored mode tried to vendor system-only packages into Pipfile.lock and exited 1 (#947). Replace the test that pinned the global fallback for a Pipfile marker with one asserting the opposite, and add CLI scans for agent, hosted and vendored modes. Assisted-by: Claude Code:claude-opus-5-5
When a Pipenv project had no Pipenv venv (a fresh checkout before pipenv install, or a project that only has a plain venv/), scan read the OS Python's site-packages instead. Agent mode then patched the system Python in place and VEX attested the project as fixed (#504); vendored mode tried to vendor system-only packages and failed with a misleading 'run pipenv lock' error (#947). A Pipenv project's env is only ever the one Pipenv resolves, so an empty result there is final. Lock-only packages still come from Pipfile.lock. Fixes #504 Fixes #947 Assisted-by: Claude Code:claude-opus-5-5
main has failed socket-patch-core's lib tests since Gradle support (#646) and the digest helpers (#865) both landed. The guard test production_digests_go_through_the_helpers flags three files #646 added that still hash inline: crawlers/gradle_cache.rs, patch/jvm_jar.rs and patch/sidecars/maven.rs. That breaks test, test-release and coverage on every open PR. Each inline sha1/sha256 call now goes through sha1_hex_of or sha256_hex_of, which compute the same lowercase hex. Behaviour is unchanged. Ported from #878 so CI on this PR runs against a green base; it no-ops once #878 lands on main. Assisted-by: Claude Code:claude-opus-5-5
Collaborator
Author
|
[agent] Generated by Claude Code |
Mikola Lysenko (mikolalysenko)
marked this pull request as ready for review
October 6, 2026 17:09
Collaborator
Author
|
BugBot review Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit a21968e. Configure here.
Collaborator
Author
|
[agent] Ready for review.
Generated by Claude Code |
Tanmay Singla (Tanmay182003)
approved these changes
Oct 6, 2026
This was referenced Oct 6, 2026
Mikola Lysenko (mikolalysenko)
deleted the
agent/fix-pipenv-global-fallback
branch
October 7, 2026 12:07
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 7, 2026
Conflict in crates/socket-patch-core/src/crawlers/python_crawler.rs: main (#950) added an is_pipenv_project guard and this branch added a uv_owns_project_env guard at the same spot in get_site_packages_paths. Kept both: the Pipenv guard first, then the uv guard, and merged the doc comment to name both. Co-Authored-By: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by Claude Code:claude-opus-5-5
Fixes #504
Fixes #947
Summary
A Pipenv project with no Pipenv venv yet no longer has the OS Python's site-packages crawled as if they belonged to the project. This covers a fresh checkout before
pipenv install, and a project that only has a plainvenv/or an opted-out.venv:not_affectedfor it.Pipfile.lockand exit 1. Hosted no longer warns about them, and--dry-runno longer promises them.Root cause
PythonCrawler::get_site_packages_pathsfalls back toget_global_python_site_packages()wheneverfind_local_venv_site_packagesreturns nothing andis_python_project(cwd)holds. For a Pipenv project, the Pipenv branch returns only the venv Pipenv itself resolves (#388), so an empty result there is final: Pipenv has no venv yet and nothing is installed for the project. The caller couldn't tell that apart from "nothing probed", so it fell through to the global interpreters.Fix
get_site_packages_pathsnow returns nothing for a Pipenv project once Pipenv's own venv lookup came back empty (crates/socket-patch-core/src/crawlers/python_crawler.rs). It is a single boundary: agent, hosted and vendored modes, rollback and the dispatch locator all crawl through it. Lock-only packages still join discovery fromPipfile.lockthrough the lockfile supplement, which the #947 test asserts.-g/--global-prefixare unchanged. No wrapper changes are needed undernpm/,pypi/orgem/, because they only dispatch to the binary.Whether a plain
./venvshould be patched again for a Pipfile project is still the maintainer decision raised in #504. This PR keeps the #388 rule (Pipenv never usesvenv/), and thevenv/cell now patches nothing instead of the system Python.Test changed on purpose:
get_site_packages_paths_falls_back_via_pipfile_markerpinned the defect: it asserted that aPipfilemarker triggers the global fallback. It is replaced byget_site_packages_paths_pipenv_without_venv_never_falls_back_to_global, which asserts the opposite. Its original concern (a fresh Pipenv clone finding zero packages) is now covered by the lockfile supplement, not by the OS Python. The pyproject and uv.lock fallback tests are untouched.Ported main fix: a21968e cherry-picks #878 ("Route Gradle digests through utils::digest").
maincurrently failsutils::digest::tests::production_digests_go_through_the_helpers, and that turnedtest (macos-latest)andcoveragered on this PR. The commit no-ops once #878 lands.Per-issue checklist
in_process_python_envs::pipenv_without_a_venv_never_scans_the_system_python, agent mode, with and without a strayvenv/, plus the core test's three marker shapes.in_process_python_envs::pipenv_fresh_checkout_candidates_come_from_the_lock_only, vendored and hosted. The lock'surllib3is discovered and the system-only package isn't.Test evidence
9c43dfc): the core test got["/usr/local/lib/python3.11/dist-packages", "/usr/lib/python3/dist-packages", …, "<HOME>/anaconda3/lib/python3.11/site-packages"]. Both CLI tests failed withunexpectedly discovered pkg:pypi/system-decoy@6.6.6, and the batch query also carried the whole system Python (pyyaml, cryptography, …).cargo test -p socket-patch-core --test crawler_python_e2e61/61,cargo test -p socket-patch-cli --test in_process_python_envs21/21.cargo clippy --workspace --all-features -- -D warnings: clean.cargo test --workspace --all-features --no-fail-fast: 10,820 passed, 12 failed. The 12 failures are chmod- or unremovable-file tests that can't fail when run as root (the sandbox runs as uid 0). Thecovgap_commands_vendor*_state_write_failure_*,in_process_redirectwrite-failure and vlt-heal,repairunremovable-lock and cleanup-failure tests, plus four core lib tests, were all re-run as uid 65534 and pass.cargo test -p socket-patch-cli --all-features --test e2e_vex_build -- pipenv:: --ignoredwithSOCKET_PATCH_PIPENV_E2E_REQUIRED=1, for2026.8.0(Python 3.12) and2022.12.19(Python 3.8). Both pass. This suite runs hosted scan on a lock-only checkout, which is the Vendored scan of a fresh Pipenv checkout (no venv yet) fails with exit 1 on packages that exist only in the system Python, because the crawler falls back to the global site-packages #947 shape.cargo fmt --all -- --check: the hunks this PR touches are formatted.mainalready has 466 rustfmt diffs under the pinned 1.93.1 toolchain, and CI doesn't run fmt, so I left the rest of the tree alone.🤖 Generated with Claude Code
Generated by Claude Code