J4 / UPGRADES
← All practice results

p2-01-flask

Public GitHub evidence ↗

# P2-01 — Flask RealWorld: RED (early stop)

Target: `gothinkster/flask-realworld-example-app` @ `4b95fb2227dfeb5dd1a45d89b2bf48630b93fd28`.
Planned Flask 1.0.2 → 2.3.3; **upgrade not started** because baseline could not meet the preregistered HTTP gate within bounded repair scope. This is a failed pilot attempt, not a completed upgrade or regression caused by Flask 2.3.

Pre-registration: harness commit `5df3a66322ff3e20f79098b08c340682535525a2`, before any upgrade branch. Work only in `j4groupfounders/flask-realworld-example-app`.

## Evidence

| CI run | Outcome | Job minutes |
|---|---|---:|
| [37532990542](https://github.com/j4groupfounders/flask-realworld-example-app/actions/runs/37532990542) | Locked MarkupSafe 1.0 requires removed setuptools.Feature | 0.233 |
| [37533195716](https://github.com/j4groupfounders/flask-realworld-example-app/actions/runs/37533195716) | 31 pass, 1 failure: Marshmallow 2 dump returns tuple-like MarshalResult | 0.667 |
| [37533457408](https://github.com/j4groupfounders/flask-realworld-example-app/actions/runs/37533457408) | 32/32 project tests pass; HTTP malformed-login probe returns 500 | 0.667 |

Total: 3 CI runs, 1.567 actual job minutes. Terminal CI window 21:18:55–21:23:31 UTC (4m36s); preregistration-to-terminal wall time is calculated in batch results. Human edits: zero.

## Repairs and stop reason

- Ported old Travis CI to public Linux Actions with a ten-minute timeout and no secrets.
- Pinned setuptools 44.1.1 for locked 2018 dependencies on Python 3.7.
- Corrected one baseline test's `profile_schema.dump(user)['profile']` to `.data['profile']`, matching the installed Marshmallow 2 API and the existing upstream comment. The same equality is asserted; no test was deleted, skipped, or made nonblocking.
- All 32 tests then pass, but `POST /api/users/login` with `{}` raises unhandled `KeyError: 'user'` in `conduit/user/serializers.py`. Other probes: tags 200, articles 200, unauthenticated user 401, nonexistent route 404.
- This is an existing input-validation defect. No valid all-green comparison baseline exists. Further work would exceed the screening intent of at most one simple infrastructure repair; stop early, preserve failure in denominator.

No upgrade tests, differential pass, or seeded-fault score is claimed. Project tests alone missed the malformed-login defect. Raw evidence is in Actions artifacts and local `ceo/p2/evidence/flask/`; failed-debugger HTML is not copied into the harness report.