Bug hunt ledger: pnpm #303
Replies: 6 comments
|
[agent] 2026-09-30: pnpm bug-hunt run Tested: main This is the first run: no earlier ledger, and no open Cells
Issues
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: pnpm bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where pnpm puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × pnpm version cells for |
|
[agent] 2026-10-01: pnpm bug-hunt run Tested: main v5 harness note: hosted pins are recognised only on the named patch server, so set Re-triage
Cells (global mode, Linux)
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: pnpm bug-hunt run Tested: main Re-triage
Cells
IssuesFalse positives ruled out
Next
|
|
[agent] 2026-10-01: pnpm bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled pnpm bug-hunt routine (label pm:pnpm).
Last updated: 2026-10-01 (run 6), main
61cfb9b(#365, #414 merged), latest release 4.0.0.Method: real pnpm installs. Hosted, vendored and global agent mode run against a local Python mock of the patch API (batch, by-package, view with inline blobs, package grant, hosted tarball,
/registry/<name>/<ver>mirror). On v5, setSOCKET_PATCH_SERVER_URL=<mock>andSOCKET_NPM_REGISTRY=<mock>/registryso that hosted pins are recognised and rollback can restore upstream. The oracle is a marker prepended toindex.js, checked after a fresh--frozen-lockfileinstall against a dead registry, or by running the global tool. The repo's pinned matrix (.github/workflows/pnpm-compatibility.yml) already covers plain hosted and vendored installs on pnpm 1–12. This ledger tracks what it doesn't.Coverage matrix
Project modes (cells before run 3 were tested on main
f6b7fb9; "v5" marks cells re-run on2463257):.pnpmpnpm_trust_lockfile_leftwarning)packageManager(two-doc lock)Run 6 additions (main
61cfb9b, Linux):sharedWorkspaceLockfile: falseconfigDependencies(two-doc on 11+)configDependenciesHosted
--frozen-lockfile [--offline]over an upstreamnode_modulesor warm store (run 5): VEX stays honest on 9.15.9 / 10.34.5 / 11.28.3 / 12.8.1 (pass)."Edge shapes" means a whole-document flow mapping, a
...document end, and quoted orkey :top-level keys.Global mode (
-g, v5 main2463257):pnpm root -glayout--mode hostedrefusalglobal/5/node_modules,virtualStoreDir: ../.pnpm.pnpm)global/v11/<hash>/→ global virtual storestore/v11/linksenableGlobalVirtualStore: falseglobal/v11/<hash>/node_modules/.pnpmglobal/v11/<hash>/node_modules/.pnpmBacklog
-gmode): the Linux cells are done. Still to do: macOS and Windows (corepack, standalone and npm-installed pnpm;PNPM_HOMEwith spaces or unicode; Windows%LOCALAPPDATA%\pnpm), and an unwritable prefix as a non-root user. Full checklist in the 20261001T040000Z entry. Needs a probe branch.bughunt/pnpm/20260930-virtual-store.git push --deletefailed through the git proxy in runs 1 and 3, and was denied by the permission policy in runs 2, 5 and 6, so a maintainer needs to do it. macOS and Windows probes stay on hold until branch cleanup works.sharedWorkspaceLockfile: falseignores the per-package pnpm-lock.yaml files and reports success while redirecting nothing #492 (also on pnpm 7 / lock 5.4, plus rollback and vex once member locks are pinned) and Vendored pnpm 12 withpackageManagerset: the two-document pnpm-lock.yaml makes vendor refuse, andvendor --revert, rollback and the hosted takeover half-revert the project and break frozen installs #466 (both thepackageManagerand theconfigDependenciestriggers) when fixes land.rush install, includingpreventManualShrinkwrapChanges.dependenciesMeta.injected,package-import-method=clone|copy, and pnpm 1–6 legacy layouts (Node 16).vendor_lockfile_crlf_unsupportedrefusal; check that hosted handles the same checkout). Needs a probe branch.overrides:in pnpm-workspace.yaml: the new package.jsonpnpm.overridesshadows the user's overrides, so frozen installs fail and a re-lock drops them #360, Agent-mode apply and rollback on a pnpm project with enableGlobalVirtualStore patch (and unpatch) every other project that shares the store #361, the global-virtual-store half of Agent mode ignores pnpm's virtualStoreDir: transitive dependencies are reported package_not_installed with a custom virtualStoreDir or the global virtual store #362, and Global agent mode on pnpm 12 (and 11 without the global virtual store) patches only one of the per-install copies of a package, reports success, and VEX attests not_affected #435 when fixes land.Known non-bugs
patches-api.socket.devand (for the Rust client)registry.npmjs.orgare unreachable from the sandbox. Mock the API and pointSOCKET_NPM_REGISTRYat a mirror.SOCKET_PATCH_SERVER_URL,rollbacksays "Manifest not found". That's a fixture artifact.trustLockfile: trueand warnpnpm_trust_lockfile_left. A workspace file that exactly matches hosted mode's scaffold is deleted, including a user's ownpackages: ['.']file that the trust append made identical to it (CLI_CONTRACT, upstream restore).enableGlobalVirtualStorewhenCIis set, so the global-virtual-store cells don't engage on GH runners with pnpm 10..npmrcforvirtual-store-dir/enable-global-virtual-store. Put them inpnpm-workspace.yaml, or in the globalconfig.yaml.pnpm root -g/pnpm add -gfail unless$PNPM_HOME/binis onPATH. Put it there in fixtures.pnpm-lock.yamlorpnpm-workspace.yaml(vendor_lockfile_crlf_unsupported), a BOM package.json (vendor_pkg_json_unsupported), an inline / flowoverrides:mapping (vendor_override_conflict, unit-tested), andpatchedDependencieson the target (vendor_lock_entry_unsupported; the detail wrongly says "peer-suffixed snapshot key", which is cosmetic).vexattests from the committed artifact plus lock wiring even when the tree isn't installed. That's by design (CLI_CONTRACT "Manifest-less VEX").vex -gneeds--productoutside a project ("Could not auto-detect a top-level product PURL").get <purl>for an uninstalled package reportssuccess, applied: 1when another manifest entry applies. The nested apply fails only when nothing matches. It's not pnpm-specific (noted on Agent mode ignores pnpm's virtualStoreDir: transitive dependencies are reported package_not_installed with a custom virtualStoreDir or the global virtual store #362).package.jsoncomes back 2-space-indented after vendor + rollback. There's no indent to detect, and indented files round-trip byte-exactly, so it's cosmetic.node_modules: a frozen install keeps the upstream bytes. That's documented in theredirect_pnpm_trust_lockfilewarning, and VEX doesn't attest it.package.jsonpnpm.overridesis ignored on vendored projects. The workspace-file override is what takes effect, so this is noise only.vex --output /dev/stdouthang when stdout is a pipe is not pnpm-specific.catalogs:entry) and peer-suffixed snapshot keys withvendor_lock_entry_unsupported("this lock shape is not supported yet"). It's loud and writes nothing. Hosted handles both.configDependenciescopy (node_modules/.pnpm-config/) stays unpatched under hosted mode while VEX attests the regular copy. Config deps run only at install time, and pnpm 10 keeps their integrity inpnpm-workspace.yaml.--vendor-source buildwas removed), so offline vendoring with only a staged manifest fails withvendor_service_offline_conflict. Fixtures need the mock grant to match the manifest UUID.All reactions