Bug hunt ledger: vlt #307
Replies: 6 comments
|
[agent] 2026-09-30: vlt bug-hunt run Tested: main This is the first run: there was no earlier ledger and no CI status found
Cells
Issues
False positives ruled out
Probe
Next
mock.mjs (registry + patch API;
|
|
[agent] 2026-10-01: vlt bug-hunt run Tested: main Focus this run: v5 regressions. #277 replaced v4's hosted ledger with the upstream restore ( Re-triage
Cells (all pass unless noted)
Issues
False positives ruled out
Infra
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where vlt puts global installs: Whatever vlt's global install surface is on each vlt version (none, or What to check (prove each with a real global install, not by reading source):
Add OS × vlt version cells for |
|
[agent] 2026-10-01: vlt bug-hunt run Tested: main vlt has no global install surface: none of 1.0.10, 1.2.0 or 1.3.3 has Re-triage
Cells: probe run https://github.com/SocketDev/socket-patch/actions/runs/36834317384 (ubuntu / macos / windows × vlt 1.0.10 / 1.2.0 / 1.3.3) plus the Linux sandbox
Issues
False positives ruled out
Infra
Next
|
|
[agent] 2026-10-01: vlt bug-hunt run Tested: main Re-triage
Cells: probe run https://github.com/SocketDev/socket-patch/actions/runs/36871535059 (ubuntu / macos / windows × vlt 1.0.10 / 1.2.0 / 1.3.3) plus the Linux sandbox
Issues
False positives ruled out
Infra
Next
|
|
[agent] 2026-10-01: vlt bug-hunt run Tested: main Re-triage
Cells (Linux)
Issues
False positives ruled out
Infra
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled vlt bug-hunt routine (label pm:vlt).
Last updated: 2026-10-01 (run 5), main
61cfb9b, latest release 4.0.0 (no vlt support; previous 3.3.0). Newest vlt: 1.3.3 (2026-10-01). Locally, runvlt ci --allow-scripts :scripts(otherwise vlt ≥ rc.24 POSTs to api.socket.dev; see #448).Method: real vlt installs (
scripts/install-vlt.sh) against a local Node mock of the npm registry plus the patch API. It's a pure-JS tar writer, so it runs on every OS. The registry is on :18555 and the patch server on :18556 viaSOCKET_PATCH_SERVER_URL; setSOCKET_NPM_REGISTRYto the registry for v5 rollback. The oracle isrequire('left-pad')printingpatched/pristine. The 3-OS probe scripts are in the run-2 workflow (run 36803186961), the run-3 global-mode workflow (run 36834317384) and the run-4 bundled-copy workflow (run 36871535059, whose mock adds abundler@1.0.0that bundles left-pad). The mock's/patches/batchmust answer only for purls in the request body, orscan -gshows false hits. CI already runs the capstones and the native backtest on 57 releases × 3 OS.Coverage matrix
warmOrdinary, PR #277 run), root cause blockedconfig.registry3-tuple)tar.brregistriestar.bralternatestar.brvlt cipatched (probe run 3); peer-extra DepID across workspaces, alias / remote / file mix: pass (Linux, run 5); fail #372 withtar.br(Linux)vlt cipatched (probe run 3); frozen / vex / workspaces untestedBundled copies (a package bundling the patched name@version; vlt-lock.json never records the bundled copy)
Global mode (
-g; vlt has no global install, so this is an npm global prefix with a vlt project in the cwd)scan -greport-g/SOCKET_GLOBAL/--global-prefix×--mode hostedrefusal-g,get -g, env)--global-prefixwith space + unicoderollback -g/remove -gleave the project alonevendor -g/vendor --revert -gleave the project alonegetre-run → npm handoverBacklog
-grequest (20261001T040000Z): covered except Windows with the default prefix (On Windows,scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 / PR Fix global PM probes spawning bare names from the project (#421, #434, #438, #440) #442), the Windows unwritable prefix, and the macOS / Windows re-check ofrollback -gafter Fix -g touching the cwd project's state (#436, #445) #446.vendor -gandvendor --revert -gstill rewire the current project: on vlt,--revert -gsilently unpatches a vendored project (the #446 fix skipped vendor.rs) #498 (vendor -g/vendor --revert -g) on macOS / Windows, and a re-test once fixed.vexattests not_affected while a bundled copy of the same name@version in node_modules/.vlt stays unpatched (the #325 fix covers npm locks only) #471 follow-ups once PR Fix Bun/vlt bundled copies left unpatched (#469, #471) #472 lands: a bundled copy at a different version (must not contest), a nested bundle, and agent mode on the bundled store copy.dist.tarball(Artifactory scoped/-/@scope/name-ver.tgz).*peer across workspaces still dedupes to one instance (run 5), so try conflicting peer ranges.scan/rollbackon vlt projects.bughunt/vlt/*branches still need a maintainer to delete them.Known non-bugs
patch.socket.devorSOCKET_PATCH_SERVER_URL. Against a mock without it,rollbacksays "Manifest not found" (documented).config.registryorigin, vlt omits slot [3] on re-save and the pin becomes invisible. That's a mock artifact only.\rthrough scan and rollback.scan <member-dir>in hosted mode scans the member as its own project (contract: "as if it were--cwd"), so a workspace member with no lock redirects nothing (redirect_npm_no_lockfile, rc 0; the human output says "Switched 0").vendor_lock_entry_unsupported). That's loud and fail-closed.registries.npm.vendor_vlt_transitive_unsupportedfor a target that is also a transitive dep is documented and fail-closed.vlt installwith "Integrity check failure" against registries advertisingtar.bralternates (a vlt bug, fixed in 1.3.1).redirect_npm_no_lockfileon vlt projects: it predates vlt support.vlt install -g, as of 1.0.10 … 1.3.3).-gonly covers npm/pnpm/yarn/bun globals.vex -gin a hosted or vendored project attests the cwd project's patches (the project is the VEX product). That's deliberate percommands/vex.rs:1013(cwd ledgers gate discovery under--global).-g"unwritable prefix" test needs files the user doesn't own: socket-patch may chmod files it owns.vexattests not_affected while a bundled copy of the same name@version in node_modules/.vlt stays unpatched (the #325 fix covers npm locks only) #471 (not detecting it).vlt cifails EINTEGRITY on aremote~(tarball URL) dependency whenever vlt's machine cache is warm, with or without socket-patch. It's a vlt bug that's gone by 1.2.0.~peer.<hex>instance across workspaces when the peer range is*, even with different peer versions installed.All reactions