Bug hunt ledger: Deno #308
Replies: 9 comments
|
[agent] 2026-09-30: Deno bug-hunt run Tested: main Method: real This is the first run: there was no earlier ledger and no Cells
Issues
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: Deno bug-hunt run Tested: main Method: same as run 1. A real Re-triage
Cells
False positives ruled out / not filed
Probe
Next
|
|
[agent] 2026-10-01: Deno bug-hunt run (addendum to 20261001T021734Z; same main Same session, extended. No new issues were filed; all new findings went onto existing issues. Cells
Harness noteThe stub's vendored path needs the served tarball to carry the same after-bytes as the patch view. A mismatch gives Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Deno puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × Deno version cells for |
|
[agent] 2026-10-01: Deno bug-hunt run Tested: main Focus: the maintainer's global ( Filed
Cells (global mode)
Re-triageMain is unchanged since the last re-check (same SHA), so #373, #374 and #406 still stand as recorded in the earlier entries. Housekeeping
Next
|
|
[agent] 2026-10-01: Deno bug-hunt run Tested: main Re-triage
Cells
FiledNone. Every finding was already covered (#373 / #406 / #444) or passed. Housekeeping
Next
|
|
[agent] 2026-10-01: Deno bug-hunt run Tested: main Re-triage
Cells
Filed / commented / closedNone. One handover to npm (above). Housekeeping
Next
|
|
[agent] 2026-10-02: Deno bug-hunt run Tested: main Re-triage
Cells
Filed / commented / closedNo new issues. Comments on #373 and #516 (links above). Housekeeping
Next
|
|
[agent] 2026-10-02: Deno bug-hunt run Tested: main Re-triage
Cells
Filed / commented / closedNo new issues. One comment on #516 (link above). Housekeeping
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Deno bug-hunt routine (label pm:deno).
Last updated: 2026-10-02 (run 7), main
61cfb9b, latest release 4.0.0 (previous 3.3.0). Newest Deno is 2.9.7. Fix PR #496 for #373 passes against real layouts. Fix PR #517 for #516 misses Deno_1copies even with #496 (commented on #516).Method: real Deno binaries (GitHub release zips;
denoland/setup-denoin probes), a per-projectDENO_DIR, and a local manifest plus blobs driven byapply --offline. The patched bytes record themselves inglobalThis.__SP, sodeno runshows which patched modules actually loaded. For scan / get / hosted / vendored there's a local stub of the public proxy (SOCKET_PROXY_URL+SOCKET_PATCH_SERVER_URL) serving batch, by-package, view (real blobs), package grants and a patched tarball at/patch/npm/<uuid>/<name>-<ver>.tgz. Deno's npm packages arepkg:npm(npm crawler), and the Deno ecosystem proper is JSR (pkg:jsr).Coverage matrix
node_modules/.deno)nodeModulesDirnonevendor: true)--global-prefix vendor/jsr.io--prunedrops records)pkg:jsr(vendor_unsupported_ecosystem)links)61cfb9b)pkg:npmin a deno.lock-only project (vendor_lockfile_missing, exit 1, files untouched)Isolated
.denostore edge cases (agent mode, Linux)<name>@<ver>_1of a direct dep_<base32>@<ver>@scope+name@ver_1left unpatched, apply success, VEX not_affected); pass with #496find_by_purlsskips peer variants)nodeModulesLinker: "hoisted"(Deno ≥ 2.8, needsnodeModulesDir: manual), agent modeDENO_DIRcache untouchedworkspacemembersname@versiondeno installafter apply, then rollbackalreadyOriginal, rc 0, manifest emptied)Global mode (
-g/--global-prefix/SOCKET_GLOBAL),deno install -gof a tool with annpm:depscan -greportapply -g--global-prefixon$DENO_DIRlayoutsbin/.<tool>/node_modulesno_applicable_patches)applied+ VEX for local/JSR tools; pass fornpm:tools)node_modulesfor local tools by 2.7.14 (#444 comment)not_affectedOther passes (Linux): an immutable (
chattr +i) target fails loudly (apply_failed, exit 1),list --json, re-apply idempotency, rollback,remove, breaking cache hardlinks, end-to-endscan --mode agentvia the stub, unicode / space paths, and deno.lock v3 / v4 (2.2.15) / v5 never edited (--frozenstill OK, patched copy loads).Backlog
61cfb9b, no fix PR). Still to do: an unwritable global prefix (read-onlyDENO_INSTALL_ROOT/DENO_DIR) on macOS / Windows,rollback -gafter Global mode can't see any Deno global install: the npm packages under $DENO_DIR/npm/registry.npmjs.org are never crawled, so scan -g misses them and Deno 2.9's per-tool node_modules gets patched and VEX-attested while the tool runs the unpatched copy #444 is fixed, andDENO_DIRwith spaces or unicode.bughunt/deno/20260930-deno-store,bughunt/deno/20261001-scoped-jsr,bughunt/deno/20261001-globalandbughunt/deno/20261001-hoisted. The git proxy and the session permission policy both refusepush --delete._1, hashed_<base32>names, scoped transitive, scan discovery andscan --prune. Close it if everything passes..deno/<name>@<ver>_1partial-revert VEX case. As of0f45d24+ Fix npm crawler missing Bun, Deno and Yarn 4 stores (#366, #373, #405, #495) #496 it still attestsnot_affected(Agent-mode npmvexhashes only the first installed copy of a package, so it attests not_affected while another nested copy of the same name@version is unpatched #516 comment)..deno_1/_<base32>folders (case-insensitive FS) once Fix npm crawler missing Bun, Deno and Yarn 4 stores (#366, #373, #405, #495) #496 lands.applyon a hardlinked.denostore. Hoisted +vendor: trueJSR is low value (it's just Deno JSR packages are never found in a real Deno project: the crawler only probes $DENO_DIR/npm/jsr.io, and the matching ./vendor/jsr.io layout from "vendor": true is ignored #374).Known non-bugs
patches-api.socket.devanddl.deno.land/deno.landare proxy-denied in the sandbox. Use GitHub release zips and a local stub.nodeModulesDir: "none"(the Deno 2 default without package.json) keeps npm packages only in the sharedDENO_DIR/npm/registry.npmjs.org/<name>/<ver>. Agent apply fails loudly (package_not_installed,partialFailure).scansays "No packages found" because deno.lock isn't a documented lockfile-supplement source.setupwas removed in v5 (v5 prerelease: scan → vex → vendor workflow, hosted by default #277). The earlier "package.json postinstall hook Deno never runs" GAP and thesetup.manualVEX gating no longer apply; v5 VEX attests agent patches from the installed bytes without any setup.vex --no-verifytrusts agent records without hashing, by documented design.scanin a deno.json-only project warnsredirect_npm_no_lockfileand exits 0 / success. Hosted refusals don't change exit status (CLI_CONTRACT).get pkg:jsr/...givesredirected: 0with only a human "no lockfile entry" line (no JSON code). Unverified against the real proxy; revisit (backlog 3).nodeModulesDir: "auto"/"manual"are Deno 2 values; on 1.x, usetrue.setup.manual: ["deno"](legacy) covered onlypkg:jsr;npm:deps are the npm ecosystem.get -g --mode hosted|vendorednot refusing wasget -g --mode hosted|vendoredandscan -g --mode vendoredrewrite the current project's yarn.lock instead of refusing, leaving the global copy unpatched #436 (generic), fixed by Fix -g touching the cwd project's state (#436, #445) #446. It now refuses on61cfb9b.scan -g --mode hosted/--global-prefix --mode hostedexit 2 with the documented refusal. That's correct.npm:-entrypoint global tool gets"nodeModulesDir": "manual"and really loadsbin/.<tool>/node_modules. Only local/JSR-entrypoint tools load theDENO_DIRcopy (Global mode can't see any Deno global install: the npm packages under $DENO_DIR/npm/registry.npmjs.org are never crawled, so scan -g misses them and Deno 2.9's per-tool node_modules gets patched and VEX-attested while the tool runs the unpatched copy #444).nodeModulesLinker: "hoisted": everydeno install(including--frozen) re-links fromDENO_DIRand drops agent patches. Agent mode needsapplyafter each install (documented), and vex then saysnot_applied.repair --offlineGCs before-blobs, so a laterrollback --offlinefails withmissing_bloband a repair remedy. Offline design, not Deno-specific.list --jsonfiles[].verifiedis alwaysfalse(hardcoded). Generic, cosmetic.vexwithout--productin a deno.json-only project fails with "Could not auto-detect a top-level product PURL". deno.json isn't in the documented auto-detect list."links"copies the linked package intonode_modules/.deno/<name>@<ver>. An agent patch only touches that copy, never the linked source.name@versionis a generic npm-family defect (commands/vex.rs:556), handed over to npm. Don't re-file it from Deno; comment on the npm issue instead..deno/<name>@<ver>_N(copy index) and a mixed-case package.deno/_<base32 hash>@<ver>(in$DENO_DIRtoo). Those are real installs, not junk; Fix npm crawler missing Bun, Deno and Yarn 4 stores (#366, #373, #405, #495) #496 decodes both.applied+already_patchedevents for one PURL in an isolated Deno workspace come from the membernode_modules/<dep>symlink reaching the same file. Cosmetic.All reactions