Bug hunt ledger: Deno #308
Replies: 5 comments
|
[agent] 2026-09-30: Deno bug-hunt run Tested: main Method: real This is the first run: there was no earlier ledger and no Cells
Issues
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: Deno bug-hunt run Tested: main Method: same as run 1. A real Re-triage
Cells
False positives ruled out / not filed
Probe
Next
|
|
[agent] 2026-10-01: Deno bug-hunt run (addendum to 20261001T021734Z; same main Same session, extended. No new issues were filed; all new findings went onto existing issues. Cells
Harness noteThe stub's vendored path needs the served tarball to carry the same after-bytes as the patch view. A mismatch gives Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Deno puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × Deno version cells for |
|
[agent] 2026-10-01: Deno bug-hunt run Tested: main Focus: the maintainer's global ( Filed
Cells (global mode)
Re-triageMain is unchanged since the last re-check (same SHA), so #373, #374 and #406 still stand as recorded in the earlier entries. Housekeeping
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Deno bug-hunt routine (label pm:deno).
Last updated: 2026-10-01 (run 3, global mode), main
2463257(#277, the v5 consolidation;setupremoved), latest release 4.0.0 (previous 3.3.0).Method: real Deno binaries (GitHub release zips;
denoland/setup-denoin probes), a per-projectDENO_DIR, and a local manifest plus blobs driven byapply --offline. The patched bytes record themselves inglobalThis.__SP, sodeno runshows which patched modules actually loaded. For scan / get / hosted / vendored there's a local stub of the public proxy (SOCKET_PROXY_URL+SOCKET_PATCH_SERVER_URL) serving batch, by-package, view (real blobs), package grants and a patched tarball at/patch/npm/<uuid>/<name>-<ver>.tgz. Deno's npm packages arepkg:npm(npm crawler), and the Deno ecosystem proper is JSR (pkg:jsr).Coverage matrix
node_modules/.deno)nodeModulesDirnonevendor: true)--global-prefix vendor/jsr.io--prunedrops records)pkg:jsr(vendor_unsupported_ecosystem)Global mode (
-g/--global-prefix/SOCKET_GLOBAL),deno install -gof a tool with annpm:depscan -greportapply -g--global-prefixon$DENO_DIRlayoutsbin/.<tool>/node_modulesno_applicable_patches)applied+ VEX for local/JSR tools; pass fornpm:tools)not_affectedOther passes (Linux): re-apply idempotency, rollback,
remove, breaking cache hardlinks, end-to-endscan --mode agentvia the stub, unicode / space paths, and deno.lock v3 / v5 never edited (--frozenstill OK).Backlog
DENO_INSTALL_ROOT/DENO_DIR) on all 3 OSes (blocked on Linux because the sandbox runs as root),rollback -gafter Global mode can't see any Deno global install: the npm packages under $DENO_DIR/npm/registry.npmjs.org are never crawled, so scan -g misses them and Deno 2.9's per-tool node_modules gets patched and VEX-attested while the tool runs the unpatched copy #444 is fixed,DENO_DIRwith spaces or unicode, and macOS/Windows hosted-refusal cells. Full checklist in the 20261001T040000Z entry.bughunt/deno/20260930-deno-store,bughunt/deno/20261001-scoped-jsrandbughunt/deno/20261001-global. The git proxy refusespush --delete.bin/.<tool>dir (absent in 2.4.5, present in 2.9.6), for Global mode can't see any Deno global install: the npm packages under $DENO_DIR/npm/registry.npmjs.org are never crawled, so scan -g misses them and Deno 2.9's per-tool node_modules gets patched and VEX-attested while the tool runs the unpatched copy #444..denopeer-variant and scoped transitive entries, once Deno nodeModulesDir: transitive npm packages under node_modules/.deno are "not installed", and apply/scan exit 0 leaving them unpatched #373 is fixed.get/scanforpkg:jsragainst the real proxy (the stub can't decide the real grant status).deno.jsonc/deno.lock, andDENO_DIRwith spaces, on Windows.Known non-bugs
patches-api.socket.devanddl.deno.land/deno.landare proxy-denied in the sandbox. Use GitHub release zips and a local stub.nodeModulesDir: "none"(the Deno 2 default without package.json) keeps npm packages only in the sharedDENO_DIR/npm/registry.npmjs.org/<name>/<ver>. Agent apply fails loudly (package_not_installed,partialFailure).scansays "No packages found" because deno.lock isn't a documented lockfile-supplement source.setupwas removed in v5 (v5 prerelease: scan → vex → vendor workflow, hosted by default #277). The earlier "package.json postinstall hook Deno never runs" GAP and thesetup.manualVEX gating no longer apply; v5 VEX attests agent patches from the installed bytes without any setup.vex --no-verifytrusts agent records without hashing, by documented design.scanin a deno.json-only project warnsredirect_npm_no_lockfileand exits 0 / success. Hosted refusals don't change exit status (CLI_CONTRACT).get pkg:jsr/...givesredirected: 0with only a human "no lockfile entry" line (no JSON code). Unverified against the real proxy; revisit (backlog 3).nodeModulesDir: "auto"/"manual"are Deno 2 values; on 1.x, usetrue.setup.manual: ["deno"](legacy) covered onlypkg:jsr;npm:deps are the npm ecosystem.get -g --mode hosted|vendorednot refusing isget -g --mode hosted|vendoredandscan -g --mode vendoredrewrite the current project's yarn.lock instead of refusing, leaving the global copy unpatched #436 (generic). Don't re-file it from Deno.scan -g --mode hosted/--global-prefix --mode hostedexit 2 with the documented refusal. That's correct.npm:-entrypoint global tool gets"nodeModulesDir": "manual"and really loadsbin/.<tool>/node_modules. Only local/JSR-entrypoint tools load theDENO_DIRcopy (Global mode can't see any Deno global install: the npm packages under $DENO_DIR/npm/registry.npmjs.org are never crawled, so scan -g misses them and Deno 2.9's per-tool node_modules gets patched and VEX-attested while the tool runs the unpatched copy #444).All reactions