Todo-list¶

Todo

Name the release that drops the deprecated [mpm] cooldown = "<duration>" top-level spelling. It is accepted as a migration aid with no removal scheduled, so the warning above has no deadline for a reader to act on.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/configuration.md, line 99.)

Todo

  • Detect pipx’s internal pip (or uv) at runtime. mpm’s pip manager has a hard >=26.1.0 floor, but pipx maintains its own virtualenvs whose pip may be older or whose resolution may be routed through uv (where the right env var is UV_EXCLUDE_NEWER instead of PIP_UPLOADED_PRIOR_TO). Probing the resolver per venv would let mpm refuse to advertise enforcement when the underlying pip is stale.

  • Per-package exemptions (--cooldown-exclude). The gate is currently all-or-nothing per run, so one legitimately-fresh package (a security fix, a package the user publishes themselves) forces the cooldown off for the whole tree. Both enforcing managers already expose the escape hatch natively: uv’s --exclude-newer-package takes a PACKAGE=DATE pair, npm’s min-release-age-exclude takes names or minimatch globs. The catch is that this would not fit the uniform cooldown_env_var injection: uv publishes no environment variable for --exclude-newer-package (only the plain --exclude-newer carries a UV_EXCLUDE_NEWER binding), so uv needs the exemption appended to the command line while npm can keep taking it through npm_config_min-release-age-exclude. Supporting it therefore means a per-manager hook alongside the env var rather than a one-line addition, which is worth knowing before the option is designed.

  • Onboard mechanisms as they ship upstream. Several managers have active work that would slot into the cooldown_env_var framework as a one-line addition once released: Composer (composer/composer#12692), conda (conda/conda#15759), dnf5 (rpm-software-management/dnf5#2743), Scoop (ScoopInstaller/Scoop#6513), winget (microsoft/winget-cli#6178), VS Code extension installs (microsoft/vscode#321136).

  • Watch the three gates that shipped outside mpm’s scope. Cargo, Bundler and mamba each ship a release-age gate that the commands mpm drives never reach. Onboard each one if upstream widens it to cargo install, to gem install, or to the mamba and micromamba command lines. The notes under the support table record what each gate covers today.

  • Track pixi’s global exclude-newer. The gate covers the scope mpm drives, but it reads only from the global manifest. Onboard it once prefix-dev/pixi#5018 adds a flag or an environment variable, and a release ships prefix-dev/pixi#7016.

  • Advisory mode for outdated on managers without a native gate. mpm could query each package registry directly (PyPI, RubyGems, crates.io, …) to annotate outdated with a “safe latest” column: purely informational, no install-side enforcement. This avoids the transitive-resolution trap while still being useful. It requires a new HTTP client surface and a state directory for date caching, neither of which mpm has today.

  • Consult a curated compromise-window denylist. aur-cooldown pairs its age gate with aur-malware-check’s campaigns.json, denying only the versions pushed inside a dated compromise window rather than freezing a package by name. This is orthogonal to release age: a version can be old enough to clear the cooldown yet still sit inside a known-bad window. Wiring such a feed into mpm would lean on the same HTTP client and state directory the advisory mode above already calls for.

  • Block-mode for the remaining bundled-artifact managers (snap, vscode). These install self-contained artifacts with no separate transitive resolution at install time, so the per-package hold shipped for flatpak and mas is sound for them too. The bottleneck is a server-set publish date the manager’s own CLI can reach: the VS Code Marketplace only answers over HTTP, and snap info prints no dates (snapd’s autonomous background refresh would bypass an mpm-side gate anyway).

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/cooldown.md, line 368.)

Todo

Implement a best matching strategy, across package managers of different kinds.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/dump.md, line 87.)

Todo

Track the origin remote of each installed flatpak package, so a Brewfile dump emits the with: ["remote_name"] keyword instead of leaving non-flathub entries to be edited in by hand.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/dump.md, line 167.)

Todo

Add an --installed boolean flag to search to reduce the searched packages to those already installed. (installed itself now accepts a QUERY argument to filter its own listing.)

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/duplicates.md, line 90.)

Todo

Drop the tree-sitter==0.25.2 pin the shexli job carries once the analyzer caps that dependency itself. shexli declares tree-sitter>=0.25.0 with no ceiling, so a fresh install pairs core 0.26.0 with the 0.25.0 grammar, the newest tree-sitter-javascript published, and that pair segfaults on this extension every time. Tracked upstream as Infrastructure/extensions-web#398.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/gnome-shell.md, line 255.)

Todo

aqua: Project scope, tracked in issue 1725. Every operation resolves the nearest aqua.yaml, so the listing reports what a config declares rather than what the host holds. Reassess if aquaproj/aqua#1900 gives install a package argument.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers.md, line 35.)

Todo

bower: Project scope, tracked in issue 1725. Alive, and its own readme steers new work elsewhere: “While Bower is maintained, we recommend yarn and webpack or parcel for new front-end projects!” What disqualifies it here is that it resolves into bower_components/ inside a working tree.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers.md, line 39.)

Todo

cabal: Project scope, tracked in issue 1725. cabal outdated answers for a package description or freeze file, there is no uninstall in any scope, and cabal list --installed needs GHC present to run at all.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers.md, line 43.)

Todo

cards: A NuTyX host. Assessed: cards list reports the installed packages and cards diff the ones the mirror has moved past, with install, remove, search, sync, upgrade and purge each holding their own command. cards prints its own version only inside an error message, so the probe is its sibling pkginfo --version, which the same suite ships.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers.md, line 47.)

Todo

glide: Project scope, tracked in issue 1725. Alive, and it manages “the vendor directory within a Go package”, which is a working tree rather than a machine.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers.md, line 51.)

Todo

netpkg: A Zenwalk host. Assessed: it is that distribution’s own manager, adding dependency metadata over Slackware .tgz packages, and Zenwalk still releases, its newest being dated 2025-01-16. What has to be settled against a real install is its relationship to slapt-get, which mpm wraps and which Zenwalk is also compatible with.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers.md, line 55.)

Todo

pkgman: A Haiku host. Assessed: pkgman search --all --installed-only is the inventory, beside install, uninstall, update, full-sync, refresh, search and cleanup. No binary of the suite reports a version, the usage screen offering --help alone, so the probe has to read Haiku’s own revision through a companion binary, as sun-tools does on Solaris.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers.md, line 59.)

Todo

poetry: Project scope, tracked in issue 1725. The archetype of the group, named in the scope docstring of meta_package_manager/manager.py.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers.md, line 63.)

Todo

protonplus: A Linux host with a Steam-like launcher, and a Python class: every verb is keyed on a launcher-and-runner pair, which a bundled definition cannot compose.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers.md, line 67.)

Todo

protonup: A release after 0.1.5, the newest on PyPI, which crashes installing any Proton-GE from GE-Proton11-4 on (upstream issue 46). The fix, pull request 47, merged on 2026-08-31 without a version bump, so no requirement can exclude the broken build. Assessed: -l lists the installed builds, and -t and -r install and remove one. No option prints a version, so the probe has to read the package metadata through the interpreter of the script.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers.md, line 71.)

Todo

rpm-ostree: A host booted on an ostree image, which Fedora Server is not: every verb refuses a package-based system. Assessed: rpm-ostree status --json reports the layered packages and the deployments carrying them, beside install, uninstall, upgrade and rollback, and rpm-ostree --version answers the probe. What it layers are the same Fedora RPMs dnf5 reaches, but Silverblue, Kinoite, IoT and CoreOS ship no dnf at all, so on those hosts nothing else reaches them.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers.md, line 75.)

Todo

slackpkg: A Slackware host. Assessed: it owns no listing, but install, upgrade and remove each take a package, which is what the vetting ladder asks of a tool with no inventory. slackpkg help prints the version, and -batch=on -default_answer=y answers the dialogs. Its relationship to the wrapped slapt-get has to be settled against a real install, like netpkg’s.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers.md, line 79.)

Todo

stack: Project scope, tracked in issue 1725. Predominantly a project build tool: no inventory, no outdated, and an uninstall that only prints instructions. The one host-wide axis it owns, fetching GHC, belongs to the wrapped ghcup.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers.md, line 83.)

Todo

upkg: A paldo host. Assessed: it is that distribution’s own manager, building from source or installing binaries against XML specifications, and paldo still releases, announcing GNOME 50.1 and Linux 7.0 on 2026-05-13.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers.md, line 87.)

Todo

vite-plus: Project scope, tracked in issue 1725. Its help groups one verb under Package Manager Commands, install, and every flag it carries is a package.json concept. No global install flag, no listing, no removal.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers.md, line 91.)

Todo

Declare outdated, upgrade_all and search. All three are expressible as further --eval forms, comparing package-alist against package-archive-contents, but none was captured on the drive that produced the samples below and no operation is declared from a form that was not run.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers/emacs.md, line 64.)

Todo

Implement outdated, on a host whose image has fallen behind its publisher: that is the only state emitting output that names both the installed and the available version, and the one illumos host available reported no packages have newer versions available.

The state cannot be manufactured on a consistent image, so do not spend time trying: installing a superseded build to force one is refused with did not match any allowable packages, the release incorporations constraining an image to one allowable version per package. Inventing a fixture is not an option either, a sample having to parse through this manager’s own parser and having to be real.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers/ips.md, line 58.)

Todo

Declare a logo once Simple Icons ships the pixi mark requested in simple-icons/simple-icons#13796, a request already cleared of trademark concerns (labelled permission not needed). Their pixiv mark is an unrelated brand, not a stand-in.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers/pixi.md, line 65.)

Todo

Declaring search would need a class: its records span three lines. It is worth the upgrade, because those records carry a server-set publication date (“Published on Mon Mar 2 17:23:45 2026”), which is what qualifies a manager for the per-package release_date() probe under --cooldown instead of the ❌ row this definition earns. Doing that would also unlock remove, the kind lookup being the same class-only capability.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/managers/platformio-core.md, line 70.)

Todo

Declare the marker so it takes that slot back, once a click-extra release carries a deprecated field on HelpKeywords:

mpm.extra_keywords = HelpKeywords(…, deprecated={UNMAINTAINED_MARKER})

Naming it on a release without the field raises TypeError at import, so this waits on the floor rather than being guarded.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/cli.py:docstring of meta_package_manager.cli.UNMAINTAINED_MARKER, line 22.)

Todo

Inert on click-extra 9.1 and below, which renders the table from the base class’s column set rather than the running option’s, so this override never reaches it. The one-line fix is proposed upstream; drop this paragraph once a release carrying it becomes the floor.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/cli.py:docstring of meta_package_manager.cli.SourcedParamsOption, line 13.)

Todo

Fold search’s --extended/--id-name-only and --exact/--fuzzy pair into a single --search-strategy=[exact, fuzzy, extended] option, whose help spells out what each strategy does. exact is case-sensitive and keeps every non-alphanumeric character. fuzzy lowercases the query, strips it of non-alphanumeric characters and tokenizes it, so word order stops mattering. extended is fuzzy widened past the package ID and name, reaching the description and whatever other metadata each manager supports.

The strategies sketched out were:

  1. strict: --exact, on ID or name.

  2. substring: regex, case-insensitive, no splitting.

  3. fuzzy: token-based.

  4. extended: fuzzy plus metadata.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/cli_explore.py:docstring of meta_package_manager.cli_explore, line 12.)

Todo

Add a --force/--reinstall flag to install.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/cli_maintenance.py:docstring of meta_package_manager.cli_maintenance, line 11.)

Todo

Resolve pkcon’s backend at dispatch time and merge it into that backend’s lane, in place of the fixed membership above. pkcon backend-details reports the backend in its first line, so the mapping needs no guessing, only a probe whose cost is paid once per run.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/dispatch.py:docstring of meta_package_manager.dispatch.SHARED_LOCK_FAMILIES, line 69.)

Todo

Delete this subclass once mpm requires the click-extra release after 9.2.0, whose commit 48812ca9 adds timer_style: pass timer_style=Style(dim=True) to the stock Spinner instead.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/execution.py:docstring of meta_package_manager.execution.Spinner, line 16.)

Todo

Delete the paragraph above once the click-extra floor reaches the release whose run_cli also kills a child’s descendants one PID at a time. It reads the process tree before the kill and signals every descendant, which reaps the escalated command with the sudo that spawned it. mpm cannot do this itself: it never sees the child’s PID, and the kill reparents the descendants before subprocess.TimeoutExpired surfaces, cutting the links a walk follows.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/execution.py:docstring of meta_package_manager.execution.CLIExecutor.run, line 38.)

Todo

Today every extractor is local-only (shell-outs to the manager’s CLI, plus on-disk reads). When extractors start reaching for network resources (PyPI’s JSON API, npm’s registry, crates.io, GitHub’s security advisories) the --bundled flag will no longer be a fine-grained enough knob: some users will want enrichment but not network traffic (offline scans, CI without egress). The natural split is a future --network/--no-network flag layered under --bundled to gate the network-touching code paths specifically, leaving local enrichment always-on for --bundled.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/manager.py:docstring of meta_package_manager.manager.PackageManager.package_metadata_batch, line 28.)

Todo

Implement project-scope discovery. The candidate ecosystems, the project files that signal each and the architecture this waits on are catalogued in Unsupported managers.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/manager.py:docstring of meta_package_manager.manager.PackageManager.discover_projects, line 13.)

Todo

Drop the second run, with _sibling_perl() and _symlinked_inc_targets(), once a fixed cpan -l reaches the Perl that Debian and Ubuntu ship. Reported upstream as andk/cpanpm#202.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/managers/cpan.py:docstring of meta_package_manager.managers.cpan.CPAN.installed, line 49.)

Todo

Use the removed variable to detect removed packages (which are reported with a (!) flag). See #17.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/managers/homebrew.py:docstring of meta_package_manager.managers.homebrew.Homebrew.installed, line 35.)

Todo

Surface pin state, or let mpm outdated filter on it, by reading the pinned and pinned_version fields the note above describes.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/managers/homebrew.py:docstring of meta_package_manager.managers.homebrew.Homebrew.outdated, line 103.)

Todo

Implement outdated, on a host whose image has fallen behind its publisher: that is the only state emitting output that names both the installed and the available version, and the one illumos host available reported no packages have newer versions available.

The state cannot be manufactured on a consistent image, so do not spend time trying: installing a superseded build to force one is refused with did not match any allowable packages, the release incorporations constraining an image to one allowable version per package. Inventing a fixture is not an option either, a sample having to parse through this manager’s own parser and having to be real.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/managers/ips.py:docstring of meta_package_manager.managers.ips.IPS, line 20.)

Todo

Evaluate findpython (the maintained MIT rewrite of pythonfinder) to replace the discovery loop here. It would only cover discovery: the eligibility filters (_running_from_bundled_app, _pip_install_blocked, _pip_module_missing) stay mpm’s job, since findpython locates interpreters but judges neither whether one carries pip nor whether pip install is allowed into it.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/managers/pip.py:docstring of meta_package_manager.managers.pip.Pip.search_all_cli, line 20.)

Todo

Drop the fallback, which mimics Pip.outdated(), once pipx 1.16.0 is old enough to be required outright.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/managers/pipx.py:docstring of meta_package_manager.managers.pipx.Pipx.outdated, line 57.)

Todo

Declare a logo once Simple Icons ships the pixi mark requested in simple-icons/simple-icons#13796, a request already cleared of trademark concerns (labelled permission not needed`). Their``pixiv` mark is an unrelated brand, not a stand-in.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/managers/pixi.py:docstring of meta_package_manager.managers.pixi.Pixi, line 20.)

Todo

Automatically uninstall the package if the technology is different:

> winget upgrade --id Microsoft.Edge
A newer version was found, but the install technology is different from the current version installed. Please uninstall the package and install the newer version.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/managers/winget.py:docstring of meta_package_manager.managers.winget.WinGet.upgrade_one_cli, line 17.)

Todo

Render with PackageURL.to_string() once packageurl-python keeps the case of npm names (package-url/packageurl-python#230) and encodes a / in a name (package-url/packageurl-python#123).

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/package.py:docstring of meta_package_manager.package.manager_purl, line 13.)

Todo

Contribute generic autodetection method to Click Extra?

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/sbom/base.py:docstring of meta_package_manager.sbom.base.SBOM.autodetect_export_format, line 4.)

Todo

Query OSV’s GIT ecosystem with a forge repository URL and release tag, derived from the download_url and vcs_url every extractor already fills. That is the second half of Homebrew’s approach, the half brew vulns itself runs on, and it reaches a package built from a plain forge tarball, which no registry purl covers.

It is also where the coverage is. Driving Homebrew’s own resolver over 246 installed formulae on one macOS host, 8 resolve to a registry purl and 124 to a repository URL plus tag, with no formula in both and 114 in neither.

Needs a tag parser and a forge-URL normalizer, not a new advisory source, and widens the scan past Homebrew to every manager that records an upstream source URL.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/sbom/vulnerabilities.py:docstring of meta_package_manager.sbom.vulnerabilities, line 45.)

Todo

Reuse the mapping that is proposed upstream to the package-url Python project.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/specifier.py:docstring of meta_package_manager.specifier.PURL_MAP, line 16.)

Todo

Parse with packageurl-python’s normalization, and drop the decoding done here, once it keeps the case of npm names (package-url/packageurl-python#230).

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/specifier.py:docstring of meta_package_manager.specifier.Specifier.parse_purl, line 16.)

Todo

Prime Microsoft’s sudo.exe once there is anything to prime. It caches nothing, so every escalation of a run raises a UAC dialog of its own, which is why ESCALATORS ranks it behind gsudo rather than beside it. microsoft/sudo#7 is the request that would give it a cache for prime_sudo() to warm; gsudo has the same gap open at gerardog/gsudo#378 for its own password path. Nothing else blocks the backend: the command line, the --preserve-env environment and the child’s exit code all survive the elevation, measured on build 26100.1742 from a Medium-integrity shell, the one path that really brokers it, so microsoft/sudo#117 never reaches the shapes this project builds.

Emulate an option a backend cannot express rather than failing on it: topgrade returns a hard error there, which its users report as a bug (topgrade-rs/topgrade#1435).

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/sudo.py:docstring of meta_package_manager.sudo, line 40.)

Todo

Escalate to the user owning a manager’s tree, not only to root: every escalate_args reaches root alone, where sudo --user and doas -u could reach the owner. The one legitimate case is a multi-user nix install, whose foreign-owned profiles are a first-class upstream configuration. A shared Homebrew prefix is not: Homebrew’s support tiers file “Multi-user Homebrew environments where multiple users share the same installation” as unsupported, so smoothing that setup over (as topgrade does for its brew step) would carry a burden upstream itself refuses. Stays unbuilt until a nix user asks.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/sudo.py:docstring of meta_package_manager.sudo, line 61.)

Todo

Rebrand the hidden password prompt of an internal escalator with a SUDO_ASKPASS helper, once the stall notice of _StallWatchdog proves insufficient in the field. It is also the only route serving a hardened sudoers policy, whose timestamps the primed cache cannot reach (see _SUDO_CACHE_WARM). That class records why the helper was rejected, and any implementation has to answer both of its points: the raw password it handles, and the tools it never reaches (brew honors the variable, fink’s plain sudo re-exec does not).

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/meta_package_manager/sudo.py:docstring of meta_package_manager.sudo, line 75.)

Todo

Make version pinning expressible in a manager definition. install and upgrade on a config-defined manager always let the manager choose the version today, and a {version} placeholder is not substituted.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/overrides.md, line 149.)

Todo

Drop the pyXXX-sqlite3 dependency once mpm requires a click-extra carrying kdeldycke/click-extra@c75292d, due in 9.1.0. That commit probes for the _sqlite3 extension at import time, and moves the sqlite3 import into the reader that needs it. An interpreter without the bindings then disables the SQLITE configuration format alone, and every other format keeps working, so mpm installs and starts on a stock FreeBSD Python with no preparation step. Other platforms gain the same guarantee: a distribution can package any standard library module wrapping a system library apart from its interpreter, and click-extra now covers that whole class rather than sqlite3 alone. Delete the note above and the FreeBSD note of docs/install.md in the same change.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/packaging.md, line 58.)

Todo

This is a big feature for the future, but is already delimited by the PROJECT concept, the discover_projects() extension point, and issue #1725.

(The original entry is located in /home/runner/work/meta-package-manager/meta-package-manager/docs/unsupported.md, line 728.)