Bug hunt ledger: npm #302
Replies: 7 comments
|
[agent] 2026-09-30: npm bug-hunt run This is the first run with a ledger. An earlier run on the same day filed #324, #325 and #326 but wrote no entry. Tested: main Setup: the Socket patch API isn't reachable from the sandbox. Agent and vendored cells hand-stage Re-triage#324, #325 and #326 are still open, their fix PRs (#337 and #345) aren't merged yet, and main is the same commit they were filed on. I didn't re-run them. Cells
Issues
False positives ruled out
Probe runs
Next
|
|
[agent] 2026-10-01: npm bug-hunt run Tested: main Re-triageMain hasn't moved, so #324, #325, #326, #356 and #359 still reproduce as filed, and I didn't re-run them. #326's fix PR #345 is still open; I built its head (see below). Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where npm puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × npm version cells for |
|
[agent] 2026-10-01: npm bug-hunt run Tested: main Setup: a Python mock of the patch API (batch, by-package, Re-triage
Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-01: handover from the Yarn Berry (2+) bug-hunt routine (#305) This one isn't Berry-specific, so it's yours to triage if you want it. On main The hint leaves out |
|
[agent] 2026-10-01: handover from the vlt bug-hunt routine (ledger #307) While covering the maintainer's Symptom: after a failed agent-mode
Repro: main Related: #424 covers the first run's Generated by Claude Code |
|
[agent] 2026-10-01: npm bug-hunt run Tested: main Handovers triaged
Re-triage
Cells
Issues
False positives ruled out
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled npm bug-hunt routine (label pm:npm).
Last updated: 2026-10-01 12:26Z (run 4 with a ledger), main
2463257(the v5 consolidation, #277; the binary still reports 4.0.0), latest release v4.0.0 (previous v3.3.0, both from npm@socketsecurity/socket-patch). v5 makes hosted the default, removessetup, and makes hostedrollbackre-resolve upstream registry entries. Cells marked (v4) were last verified onf6b7fb9.Coverage matrix
Cells are "pass", "fail #N" or "untested". Every cell uses a real npm install. Hosted cells use a local mock of the patch API with
--patch-server-urlpointed at it. Agent and vendored cells use the same mock or a hand-staged.socket/. "Cycle" means scan → freshnpm ci→vex→rollbackbyte-exact. "Suites" meanse2e_redirect_npm_build+e2e_vendor_npm_buildwithSOCKET_PATCH_NPM_E2E_REQUIRED=1.-g(scan report / get+apply / vex / rollback)-g(v4)overrides(flat, alias, nested). fail #432 (alias mirror, npm 6 consumer)-g(v4)getrerun after reinstall: fail #454 (dup)registry=mirror,.npmrcvariants,overrides, policy (--package,maxNewPatches,ignorePackages,minSeverity). fail #324, #325 (re-checked on v5)--global-prefix,SOCKET_GLOBAL,--mode hostedrefused. fail #464 (report-only hint has no-g)omit-lockfile-registry-resolved,overrides,install-strategy=linked/nested/shallowrepairnpm install <pkg>keeps the pin, path-scoped rollback, remove,registry=mirror, CRLF / spaced.npmrc. fail #433--global-prefixworks)Backlog
-g), still open: Linux, macOS and Windows are covered for npm 10/12 (Windows is On Windows,scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434). Remaining: npm 6/8/11 on macOS and Windows; an unwritable prefix (root-owned /Program Files); nvm, volta, fnm and Homebrew prefixes on macOS; and%APPDATA%\npmonce On Windows,scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 is fixed. Full checklist in the 20261001T040000Z entry. (Linux non-root read-only checks: see scan/get --json drop the agent-mode apply failure: exit 1 with failed: 0, the patch shown as "added", and no error anywhere (e.g. a read-only global ~/.m2) #424 and scan --sync / --mode agent never re-applies an already-recorded patch, so after a fresh Hatch env (or any reinstall) it exits 0 with the package unpatched #454.)npm ci --omit=optional/--omit=devagainst hosted and vendored entries plusvex.get/scan --mode agentrerun case (scan --sync / --mode agent never re-applies an already-recorded patch, so after a fresh Hatch env (or any reinstall) it exits 0 with the package unpatched #454).git push --deleteprints "Everything up-to-date"):bughunt/npm/20260930-alias-linked,20260930-win-mac-e2e,20260930-win-old-npm,20261001-crlf-paths,20261001-optional-dep,20261001-v5-hosted-global,20261001-win-global. A maintainer needs to delete them.Known non-bugs
patches-api.socket.devis unreachable from the sandbox. Use hand-staged manifests, a local mock API, or the wiremock suites.scan --mode hostedfrom a workspace member directory finds no packages, because discovery is cwd-scoped. It's loud and writes nothing.allow-remoteother thanallis respected with a loudredirect_npm_allow_remotewarning, and a fresh npm 12 install then fails EALLOWREMOTE (fails closed). This is documented.npm updatere-resolves a hosted or vendored entry back to the registry. That's npm's behaviour;vexthen refuses (redirect_unwired/vendor_unwired).applyskips the package as "managed bysocket-patch vendor" with exit 0 and doesn't take ownership back. That's by design (apply.rsVENDOR_OWNED_MARKER), andvexrefuses.file:directory dependency into the linked directory.build,dist,vendor,tmp,temp,coverageand hidden directories, even when one is an npm workspace member (documented in docs/ecosystems.md).applyfrom a workspace member directory reportsnoManifestwhen.socket/lives at the root (--cwdscoping).lock_heldunless--lock-timeoutis set (documented).rollbackdrops the rolled-back manifest entries and GCs their blobs unless--preserve-stateis set (documented).vexomits patches (ecosystem_not_setup) when there's nosetuphook and nosetup.manual(documented).@idis the raw origin URL for a non-GitHub/GitLab/Bitbucket remote (documented invex --help).npm root -gstdout, soapply -gmisses a global prefix whose path contains a UUID. That's npm's behaviour, it's loud (exit 1), and--global-prefixworks around it. Not filed.SOCKET_PATCH_NPM_E2E_LOCK_WRITER_BIN(an npm ≥ 7 to write the v2 lock). That's a harness requirement.patch.socket.devor the--patch-server-urlorigin are invisible torollback,vex,listandremove(documented). Mock runs must pass--patch-server-url.rollbackcan't reach registry.npmjs.org (the Rust client doesn't trust the proxy CA). UseSOCKET_NPM_REGISTRYpointed at a local passthrough.rollbackre-addsresolvedunderomit-lockfile-registry-resolved=true: hosted keeps no ledger, and npm drops the field on its next install.allow-remote=allin.npmrc: exit 1, the documented mid-flush I/O residual.scanwires only the cwd project's lock. A nested non-workspace project warnsredirect_npm_entry_not_found.scan . subwires both, butrollback/vexfrom the root don't seesub's pins (use--cwd sub).rollback <path>path targets select installed copies, so a workspace member whose dependency is hoisted to the root matches nothing (documented).vexattests from the committed artifact and only warnsvendored_tree_out_of_syncwhen the live tree is stale (documented).scan -gwithout-ealso scans the cargo, pypi and gem global stores (by design).vex -goutside a project needs--product.setup, so the setup-hook cells are retired.rollbackrestoresresolvedtoregistry.npmjs.org(orSOCKET_NPM_REGISTRY) even when the project.npmrcuses aregistry=mirror. That's documented ("default upstream registry entry"), andnpm cistill works because of npm'sreplace-registry-host.--packageandignorePackagesmatch package names and purls, not npm alias dependency keys (lp@npm:left-padis matched byleft-pad, notlp).ALLOW-REMOTE=andallow_remote=keys in.npmrc, so socket-patch appendingallow-remote=allafter them is correct.minSeverityskips patches whose per-package records carry no severity (documented). Mocks must fillvulnerabilitiesinby-package.All reactions