`pip` sometimes includes debug messages on `stdout`
envgap__pypa__pip-audit-122
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
74d3d7c864faea4111bf9a8c32ef1ce2e6015091- Manifest
setup.py- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
pypa/pip-audit #122 · read the original issue
This is an abbreviated copy of #115 and #116, since those have been filled up with additional debugging. Summary: In rare cases (currently N=1), we fail to collect environmental dependencies from `PipSource`. `PipSource` uses `pip-api` internally, which boils down to `pip list --format=json`. What *seems* to happen is that the `pip list --format=json` command doesn't emit *just* JSON. Instead, it *also* emits a trailing log message that looks like this: ``` Given no hashes to check 181 links for project 'pip': discarding no candidates ``` According to `pip`'s source code, that message is produced by a call to `log.debug`, which **should** be going to `stderr` instead of `stdout`. `pip-api` only uses `stdout` from `pip` subprocesses, so this is a strong indicator that the two streams are being mixed and/or confused somewhere, potentially with a logging override. The original reporter also traced the process and confirmed that the log was produced on `stdout`. The original reporter found this on Python 3.9, `pip` version `20.3.3`. I was unable to reproduce it locally, and they were also unable to reliably reproduce it locally.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]