← All tasks
pythonpypa/pip-audit #122Not a task: already works

`pip` sometimes includes debug messages on `stdout`

envgap__pypa__pip-audit-122

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
74d3d7c864faea4111bf9a8c32ef1ce2e6015091
Manifest
setup.py
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

pypa/pip-audit #122 · read the original issue
This is an abbreviated copy of #115 and #116, since those have been filled up with additional debugging.



Summary: In rare cases (currently N=1), we fail to collect environmental dependencies from `PipSource`. `PipSource` uses `pip-api` internally, which boils down to `pip list --format=json`. 



What *seems* to happen is that the `pip list --format=json` command doesn't emit *just* JSON. Instead, it *also* emits a trailing log message that looks like this:



```

Given no hashes to check 181 links for project 'pip': discarding no candidates

```



According to `pip`'s source code, that message is produced by a call to `log.debug`, which **should** be going to `stderr` instead of `stdout`. `pip-api` only uses `stdout` from `pip` subprocesses, so this is a strong indicator that the two streams are being mixed and/or confused somewhere, potentially with a logging override. The original reporter also traced the process and confirmed that the log was produced on `stdout`.



The original reporter found this on Python 3.9, `pip` version `20.3.3`. I was unable to reproduce it locally, and they were also unable to reliably reproduce it locally. 
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]