Bug hunt ledger: vlt #307
Replies: 5 comments
|
[agent] 2026-09-30: vlt bug-hunt run Tested: main This is the first run: there was no earlier ledger and no CI status found
Cells
Issues
False positives ruled out
Probe
Next
mock.mjs (registry + patch API;
|
|
[agent] 2026-10-01: vlt bug-hunt run Tested: main Focus this run: v5 regressions. #277 replaced v4's hosted ledger with the upstream restore ( Re-triage
Cells (all pass unless noted)
Issues
False positives ruled out
Infra
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where vlt puts global installs: Whatever vlt's global install surface is on each vlt version (none, or What to check (prove each with a real global install, not by reading source):
Add OS × vlt version cells for |
|
[agent] 2026-10-01: vlt bug-hunt run Tested: main vlt has no global install surface: none of 1.0.10, 1.2.0 or 1.3.3 has Re-triage
Cells: probe run https://github.com/SocketDev/socket-patch/actions/runs/36834317384 (ubuntu / macos / windows × vlt 1.0.10 / 1.2.0 / 1.3.3) plus the Linux sandbox
Issues
False positives ruled out
Infra
Next
|
|
[agent] 2026-10-01: vlt bug-hunt run Tested: main Re-triage
Cells: probe run https://github.com/SocketDev/socket-patch/actions/runs/36871535059 (ubuntu / macos / windows × vlt 1.0.10 / 1.2.0 / 1.3.3) plus the Linux sandbox
Issues
False positives ruled out
Infra
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled vlt bug-hunt routine (label pm:vlt).
Last updated: 2026-10-01 (run 4), main
5678b76, latest release 4.0.0 (no vlt support; previous 3.3.0). Newest vlt: 1.3.3 (2026-10-01).Method: real vlt installs (
scripts/install-vlt.sh) against a local Node mock of the npm registry plus the patch API. It's a pure-JS tar writer, so it runs on every OS. The registry is on :18555 and the patch server on :18556 viaSOCKET_PATCH_SERVER_URL; setSOCKET_NPM_REGISTRYto the registry for v5 rollback. The oracle isrequire('left-pad')printingpatched/pristine. The 3-OS probe scripts are in the run-2 workflow (run 36803186961), the run-3 global-mode workflow (run 36834317384) and the run-4 bundled-copy workflow (run 36871535059, whose mock adds abundler@1.0.0that bundles left-pad). The mock's/patches/batchmust answer only for purls in the request body, orscan -gshows false hits. CI already runs the capstones and the native backtest on 57 releases × 3 OS.Coverage matrix
warmOrdinary, PR #277 run), root cause blockedconfig.registry3-tuple)tar.brregistriestar.bralternatestar.brvlt cipatched (probe run 3); rollback via-gpath only (#445); fail #372 withtar.br(Linux)vlt cipatched (probe run 3); frozen / vex / workspaces untestedBundled copies (a package bundling the patched name@version; vlt-lock.json never records the bundled copy)
Global mode (
-g; vlt has no global install, so this is an npm global prefix with a vlt project in the cwd)scan -greport-g/SOCKET_GLOBAL/--global-prefix×--mode hostedrefusal-g,get -g, env)--global-prefixwith space + unicoderollback -g/remove -gleave the project alonegetre-run → npm handoverBacklog
-grequest (20261001T040000Z): covered in run 3, except Windows with the default prefix (blocked on On Windows,scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 / PR Fix global PM probes spawning bare names from the project (#421, #434, #438, #440) #442) and the Windows unwritable prefix (Program Files). Re-probe once Fix global PM probes spawning bare names from the project (#421, #434, #438, #440) #442 lands.rollback -gandremove <purl> -galso unwind the current project's hosted pins and vendored wiring; on vlt they delete node_modules/left-pad too #445 follow-ups once PR Fix -g touching the cwd project's state (#436, #445) #446 lands: a patched global plus a hosted project (only the global is restored), andrepair -g/vendor -gin a vlt project.vexattests not_affected while a bundled copy of the same name@version in node_modules/.vlt stays unpatched (the #325 fix covers npm locks only) #471 follow-ups once fixed: a bundled copy at a different version (must not contest), a bundle nested in a bundle, and agent mode on the bundled store copy.dist.tarball(Artifactory scoped/-/@scope/name-ver.tgz).remove.scan/rollbackon vlt projects.native (ubuntu, rc.14) hosted-direct warmOrdinaryfailure if it recurs.Known non-bugs
patch.socket.devorSOCKET_PATCH_SERVER_URL. Against a mock without it,rollbacksays "Manifest not found" (documented).config.registryorigin, vlt omits slot [3] on re-save and the pin becomes invisible. That's a mock artifact only.\rthrough scan and rollback.scan <member-dir>in hosted mode scans the member as its own project (contract: "as if it were--cwd"), so a workspace member with no lock redirects nothing (redirect_npm_no_lockfile, rc 0; the human output says "Switched 0").vendor_lock_entry_unsupported). That's loud and fail-closed.registries.npm.vendor_vlt_transitive_unsupportedfor a target that is also a transitive dep is documented and fail-closed.vlt installwith "Integrity check failure" against registries advertisingtar.bralternates (a vlt bug, fixed in 1.3.1).redirect_npm_no_lockfileon vlt projects: it predates vlt support.vlt install -g, as of 1.0.10 … 1.3.3).-gonly covers npm/pnpm/yarn/bun globals.vex -gin a hosted or vendored project attests the cwd project's patches (the project is the VEX product). That's deliberate percommands/vex.rs:1013(cwd ledgers gate discovery under--global).-g"unwritable prefix" test needs files the user doesn't own: socket-patch may chmod files it owns.vexattests not_affected while a bundled copy of the same name@version in node_modules/.vlt stays unpatched (the #325 fix covers npm locks only) #471 (not detecting it).All reactions