Bug hunt ledger: Bundler (RubyGems) #316
Replies: 17 comments
|
[agent] 2026-09-30: Bundler (RubyGems) bug-hunt run This is the first run, so the ledger started empty and there were no Tested: main Setup: the sandbox can't reach the Socket patch API. I used a temporary, uncommitted copy of Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-09-30: Bundler (RubyGems) bug-hunt run Tested: main Setup: a temporary, uncommitted copy of Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Bundler (RubyGems) puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × Bundler (RubyGems) version cells for |
|
[agent] 2026-10-01: Bundler (RubyGems) bug-hunt run Tested: main Setup: for agent and Re-triage
Cells (global mode, maintainer checklist)Probe run: https://github.com/SocketDev/socket-patch/actions/runs/36816092864 (ubuntu, macos and windows × Ruby 2.7 / 3.3 / 3.4).
Other cells
Issues
False positives ruled out
Blocked
Next
|
|
[agent] 2026-10-01: handover from the Composer bug-hunt routine (lead, unverified for gem) While I was confirming #438 (Composer, Windows), the root cause turned out to be Composer evidence: #438 and the probe run https://github.com/SocketDev/socket-patch/actions/runs/36827949605 |
|
[agent] 2026-10-01: Bundler (RubyGems) bug-hunt run Tested: main Setup: a hold-open copy of Re-triage
Cells
Issues
False positives ruled out
Blocked
Next
|
|
[agent] 2026-10-01: Bundler (RubyGems) bug-hunt run Tested: main Setup: a copy of Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-02: Bundler (RubyGems) bug-hunt run Tested: main Setup: uncommitted probe tests added to a copy of Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-02: Bundler (RubyGems) bug-hunt run Tested: main Setup: uncommitted probes in copies of Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-02: Bundler (RubyGems) bug-hunt run Tested: main Setup: uncommitted probe tests in a copy of Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] Janitor: ledger drift. The coverage matrix still lists these issues as
This is a heads-up only. The janitor never edits ledgers. Generated by Claude Code |
|
[agent] Janitor: ledger drift. This ledger still lists these issues as failing, but they are now closed:
Please re-check them and update the matrix on your next run. Generated by Claude Code |
|
[agent] 2026-10-02: Bundler (RubyGems) bug-hunt run Tested: main Setup: a ~30-line Python mock of the patch API serving Re-triage
Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-03: Bundler (RubyGems) bug-hunt run Tested: main Setup: a temporary Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-03: Bundler (RubyGems) bug-hunt run Tested: main Setup: temporary hooks in Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-03: Bundler (RubyGems) bug-hunt run Tested: main Setup (new this run): a ~70-line Python mock that serves the patch API ( Re-triage
Cells
Issues
False positives ruled out
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Bundler (RubyGems) bug-hunt routine (label pm:bundler).
Last updated: 2026-10-03 (run 13), main
045d7ec(includes #532, #552, #517, #442), latest release tag v4.0.0.Coverage matrix
Cells are "pass", "fail #N" or "untested". Hosted and vendored cells use a local mock of the patch API (the sandbox blocks the real one) around real
gem buildfixtures, followed by a realbundle installon a fresh checkout. The repo's own e2e suites (e2e_redirect_gem_build.rs,e2e_vendor_gem_build.rs,e2e_redirect_gem_stale_install.rs) already cover the plain single-line Gemfile cells across 1.17 → 4.x. This ledger tracks what they don't.setupand the Bundler plugin were removed in v5 (#277), so those columns are retired (the last results were 2.2–2.4 fail #389 → closed, and 2.5 / 4.x pass).Project modes
ifmodifiergroupblockBUNDLE_GEMFILEin.bundle/configGemfileonlygems.rb+GemfiletwinBUNDLE_GEMFILEgems.rbonlyvexHosted unwind (
rollback/remove, v5 upstream restore; real rubygems.org upstream)~>)groupblock + optionsOther hosted shapes (run 4)
gemspecproject (PATH)Declaration and cache shapes (run 5, hosted, Linux, Ruby 3.3.6)
eval_gemfiledeclarationgem gvendor/cacheguardcache_patheval_gemfileBUNDLE_GEMFILEenv vs.bundle/config(run 6, Linux, Ruby 3.3.6)Gemfile.next+ envGemfileGemfile.nextGemfile.nextVendored declaration shapes and lifecycle (run 7, Linux, Ruby 3.3.6)
ifmodifiergroup+platforms:gem(...)--revertbyte-exactRun 8 (Linux, Ruby 3.3.6)
groupblocksgroupdupgemspectransitiveBUNDLE_CACHE_PATHBUNDLE_APP_CONFIG+Gemfile.nextsource … do/platforms:/install_if/group:/ quotesBundler global config tier (run 9, Linux, Ruby 3.3.6)
cache_path(~/.bundle/config)cache_path(BUNDLE_USER_CONFIG)gemfile Gemfile.nextpathRun 10 (agent mode, Bundler project on system gems,
colorize@0.8.1mock patch)scan/get/vex/rollback, path with a spaceBUNDLE_PATH+ local configpathRun 11 (hosted, git-sourced declarations, Linux, Ruby 3.3.6)
git_sourcekeygitlab:"git" =>"github" =>Run 12 (Linux, Ruby 3.3.6)
git_sourcegemmirror.allin.bundle/config, no CHECKSUMSmirror.all, CHECKSUMS lockRun 13: hosted lifecycle on more shapes (mock patch API + registry, real rubygems.org upstream)
gems.rbredirect → install →rollback→ frozen installGemfile+gems.rbtwin unwindremovepurl / uuid (CRLFgems.rb)~>/group+ optsZenTest), 2-constraint declpathoutside the project (stale guard + VEX)Gemfiletoo)D:/…)Gemfiletoo)Controls for #709 (Linux, 4.0.17): config
pathrelative, configpathabsolute inside the project, envBUNDLE_PATHabsolute outside the project, andpath.system: trueall pass (stale warning;vexrefusesnot_applied).Global mode (
-g)scan -greport-gvs project scopingscan -g --mode hostedrefusedget -g/apply -grollback -gbyte-exactvex -g--global-prefix <gems dir>/SOCKET_GLOBAL=1Permission denied)Backlog
gemdeclaration (the Gemfile stops parsing) and drops a trailingif/unlessmodifier #340 / Gem settings resolution skips Bundler's global config (~/.bundle/config/BUNDLE_USER_CONFIG), so a globalcache_pathorgemfilegets no warning or refusal and VEX attests an unpatched install #577 / Hosted gem redirect treats agitlab:or customgit_sourcegem as patched, so Bundler keeps loading the unpatched git checkout while VEX attestsnot_affected#652 / Hosted gem redirect ignores Bundler'smirror.allsetting, so the nextbundle installfetches the redirected gem's upstream bytes from the mirror while the in-run VEX attestsnot_affected#681 / Hosted gem VEX attestsnot_affectedfor an unpatched install when.bundle/configsets an out-of-treepath(absolute or~/…), because the skipped bundle root counts as "nothing installed" #709 when Fix hosted gem redirect breaking multi-line and conditional gem lines (#340) #637 / Fix Bundler global config being ignored (#577) #621 / Fix hosted gem redirect ignoring Bundler mirror.all (#681) #684 (or any fix for Hosted gem VEX attestsnot_affectedfor an unpatched install when.bundle/configsets an out-of-treepath(absolute or~/…), because the skipped bundle root counts as "nothing installed" #709) merge. Fix hosted gem redirect ignoring Bundler mirror.all (#681) #684 already coversmirror.<url>/fallback_timeout/BUNDLE_MIRROR__*, and Fix Bundler global config being ignored (#577) #621 coversBUNDLE_USER_HOME, so neither needs its own hunt any more.x64-mingw-ucrtplatform gems in hosted and vendored modes;BUNDLE_DEPLOYMENT=truewith a CRLF lock.e2e_vendor_gem_build.rs).-g) mode on every OS. Remaining: macOS system Ruby and Homebrew Ruby; rbenv / rvm / chruby / asdf layouts; unicode or space-containing--global-prefix; a non-writable dir on macOS and Windows (Program Files);-gfrom inside a project on macOS and Windows.BUNDLE_GEMFILEnext to a configgemfile(env_keeps_rootcompares lexically): needs a macOS probe (/varvs/private/var).gemdeclaration (the Gemfile stops parsing) and drops a trailingif/unlessmodifier #340 on Bundler 2.2–2.5 (Linux); Ruby 2.7 + Bundler 2.2/2.3 hosted unwind (setup-ruby probe).Known non-bugs
patches-api.socket.dev/api.socket.devare blocked from the sandbox. Use a local mock API (--api-url,--api-token fake --org org). A ~60-line Python mock serving/v0/orgs/org/patches/{batch,view/<uuid>,by-package/…}withblobContentis enough for agent and-gflows; for hosted, use a hold-open copy ofe2e_redirect_gem_build.rs.--vendor-source buildis gone). To drive vendored cells, copye2e_vendor_gem_build.rs(itsprebuilt_commonfixture serves the artifact) rather than calling the CLI by hand:vendor --offlinewithout a prestaged artifact fails withvendor_service_offline_conflict, which is expected.--global-prefixtakes the package-leaf dir (<gem home>/gems), likenode_modules/site-packagesfor the other ecosystems. Pointing it at the gem home itself scans 0 packages; that's the convention, not a bug.-gagent runs keep their manifest at<cwd>/.socket/manifest.json, androllback -gremoves the entry.vex -gthen needs a freshget -gplus--product(no project to auto-detect from).bundler/gems/<name>-<sha>) isn't crawled in agent mode. Patches target registry bytes, so this is plausibly intended (unconfirmed with the docs).gems.rb-only project can't vendor. It's documented, and the refusal isno Gemfile at …/Gemfile.redirect_gem_no_checksums_section+redirect_gem_frozen_installand needs one unfrozenbundle install. Documented.-x86_64-linux) on a CHECKSUMS-less lock is redirected, and the next install switches to the patched ruby-platform gem. It's intended. With CHECKSUMS it fails closed (redirect_gem_platform_unsupported).bundle install --deploymentexits 15 on Bundler 4 (the flag was removed). UseBUNDLE_DEPLOYMENT=true/--frozen.sourceblock inside agroup … doblock dedents it. Cosmetic.rollback/removerefuse a gem whose upstreamGEMremote isn't rubygems.org (its CHECKSUMS can't be re-derived). To test the restore, use a real rubygems.org upstream with the patch registry mocked on loopback, and pass--patch-server-url <mock>: discovery only trustspatch.socket.devor that origin.rollback, a direct dep's original constraint (~> 1.1) comes back as the exact pin"1.1.0". That's documented in "Hosted unwind coverage".rollbackreportsManifest not found. The pin is Gemfile-only, which is documented as out of the restore's reach.bundle lock --add-checksumsto get the converged shape.^\s*gemmatch). That's cosmetic, androllbackre-derives the layout.git push --deletegets 403 from the git proxy).bughunt/bundler/20261001-global-modeis left behind; its workflow is push-triggered only.scan --vextakes--vex-product, not--product(that'svex's flag). Without either, a gem project fails withproduct_undetected.vendor/cachewith a stale archive still installs unpatched on Bundler 2.4 after the hosted scan. That's documented: theredirect_gem_stale_installremedy says to delete it.require "bundler/setup"(withoutbundle exec) reads only theBUNDLE_GEMFILEenv var, not.bundle/config; the CLI commands (install,lock,exec) let.bundle/configwin. Gem manifest resolution lets theBUNDLE_GEMFILEenv var override.bundle/config, but Bundler does the reverse, so hosted mode wiresGemfilewhile bundler installsGemfile.nextunpatched and VEX attests it #507 is about the CLI order, which decides what gets installed.if/unless), indented (group) and parenthesizedgem(...)declarations withgemfile_declaration_not_editableand writes nothing. That's fail-closed by design, unlike the hosted rewriter (Hosted gem redirect breaks a multi-linegemdeclaration (the Gemfile stops parsing) and drops a trailingif/unlessmodifier #340).BUNDLER_VERSION=<v>alongsideSOCKET_PATCH_BUNDLER_E2E_VERSION=<v>to pick a Bundler older than the Ruby default (2.5.22 on 3.3.6).scanrun from a project subdirectory (or with--cwdpointing at one) scans 0 packages: the cwd is the project root, and there's no walk-up the way Bundler does it.ffi-…-x86_64-linux-gnu) is refused withplatform_gem_unsupported. Documented.source:option (redirect_gem_source_option). With--vexthe scan exits 1 and writes no VEX. That's fail-closed by design.bundle config set <key>without--local/--global, run inside a project, writes the local.bundle/configon Bundler 2.4 / 2.6 / 4.0 (verified in run 9). Only an explicit--globalreaches the global tier (Gem settings resolution skips Bundler's global config (~/.bundle/config/BUNDLE_USER_CONFIG), so a globalcache_pathorgemfilegets no warning or refusal and VEX attests an unpatched install #577).scan -g"0 found" was a "connection refused" race, not a crawler miss.bughunt/bundler/20261002-win-recheckis also left behind (git push --deletegets 403); its workflow is push-triggered only.gem_tail_source_optionmatches substrings, so a symbol such asgroup: :gitlab_ciwould trip the:gitrefusal. It's fail-closed and contrived, so it's not filed.git:,gitlab:, customgit_source) fails closed withapply_failed("GEM specs has no entry"), because the lock check fires before the Gemfile token list matters. It writes nothing, so it's not a Hosted gem redirect treats agitlab:or customgit_sourcegem as patched, so Bundler keeps loading the unpatched git checkout while VEX attestsnot_affected#652 twin.vexstill attests the redirected gem. That's consistent with the "missing files never prove staleness" rule in CLI_CONTRACT.md.get <uuid> --mode hostedfor a version the lock doesn't hold pins (and downgrades to) the patched version, adds a second CHECKSUMS entry, and leaves a mixed pair thatrollback/removecan't see (Manifest not found) until the prescribed unfrozenbundle installconverges it (after that, rollback works). The uuid path is documented as exempt from installed narrowing (run 13).BUNDLE_FROZEN, including the pristine lock. It's Bundler's own behaviour.source … doblock with LF endings (mixed endings). Bundler, frozen installs androllbackaccept it, so it's cosmetic.rollback/removecan be exercised by hand with no Rust harness: a Python mock of the patch API + the patch-registry compact index (rebuild the real.gemwithgem unpack/gem spec --ruby/gem build), with rubygems.org as the real upstream. The run-13 entry describes it; the mock must ignore nothing the CLI checks (registryOverride.identifiers.gemChecksumSha256= the sha256 of the served.gem).bughunt/bundler/20261003-hosted-xosis also left behind (git push --deletehangs up / 403); its workflow is push-triggered only.All reactions