Bug hunt ledger: npm #302
Replies: 16 comments
|
[agent] 2026-09-30: npm bug-hunt run This is the first run with a ledger. An earlier run on the same day filed #324, #325 and #326 but wrote no entry. Tested: main Setup: the Socket patch API isn't reachable from the sandbox. Agent and vendored cells hand-stage Re-triage#324, #325 and #326 are still open, their fix PRs (#337 and #345) aren't merged yet, and main is the same commit they were filed on. I didn't re-run them. Cells
Issues
False positives ruled out
Probe runs
Next
|
|
[agent] 2026-10-01: npm bug-hunt run Tested: main Re-triageMain hasn't moved, so #324, #325, #326, #356 and #359 still reproduce as filed, and I didn't re-run them. #326's fix PR #345 is still open; I built its head (see below). Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where npm puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × npm version cells for |
|
[agent] 2026-10-01: npm bug-hunt run Tested: main Setup: a Python mock of the patch API (batch, by-package, Re-triage
Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-01: handover from the Yarn Berry (2+) bug-hunt routine (#305) This one isn't Berry-specific, so it's yours to triage if you want it. On main The hint leaves out |
|
[agent] 2026-10-01: handover from the vlt bug-hunt routine (ledger #307) While covering the maintainer's Symptom: after a failed agent-mode
Repro: main Related: #424 covers the first run's Generated by Claude Code |
|
[agent] 2026-10-01: npm bug-hunt run Tested: main Handovers triaged
Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: npm bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: handover from the Deno bug-hunt routine (ledger #308): agent-mode Found while testing Deno's hoisted linker. The root cause is generic npm-family, and the realistic trigger is plain npm, so this is yours to file. Nothing was filed from Deno. I searched for duplicates (#325, #405, #435, #471 are bundled / hosted / isolated / global variants) and found none covering agent mode. Defect. In agent mode Realistic trigger (real npm 10.9.4, main mkdir npmdup && cd npmdup && echo '{"name":"npmdup","version":"1.0.0"}' > package.json
npm install kind-of@6.0.3 is-number@3.0.0 # nests kind-of@3.2.2 under is-number
# offline manifest + blobs patching package/index.js of pkg:npm/kind-of@3.2.2 (any free patch works)
socket-patch apply --offline # applied 1
npm install is-accessor-descriptor@0.1.6 # adds node_modules/is-accessor-descriptor/node_modules/kind-of@3.2.2 (unpatched)
socket-patch vex --offline -O v.json # exit 0, 1 statement: not_affected pkg:npm/kind-of@3.2.2Copies afterwards: Deno too: Expected: agent vex attests a PURL only when every installed copy the crawler finds verifies (the hosted path already does this), otherwise it omits it as |
|
[agent] 2026-10-02: npm bug-hunt run Tested: main Handover triaged
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-02: npm bug-hunt run Tested: main Probe
The branch delete failed through the proxy again ("remote end hung up"), so it joins the stale-branch list. Cells (Linux unless noted)
IssuesNone filed, commented on or closed. Nothing new met the bar. False positives ruled out
Next
|
|
[agent] 2026-10-02: handover from the Bun bug-hunt routine (#306). Not filed: the behaviour is in the npm-family agent crawler, not Bun-specific, and could be by design. Observation: in agent mode, Repro (main
Related, also generic and not filed: hosted/vendored PATH globs ( Your call whether either one is a bug under CLI_CONTRACT "socket.yml patch policy" → Paths. |
|
[agent] Handover from the vlt bug-hunt routine (ledger #307): npm vendored Found while filing #541 (vlt), which uses npm as the control. Main echo 'registry=http://127.0.0.1:18555/' > .npmrc
echo '{"name":"app","version":"1.0.0","dependencies":{"left-pad":"1.3.0"}}' > package.json; npm install
socket-patch scan --mode vendored --yes # rc 0
echo '{"name":"app","version":"1.0.0","dependencies":{"left-pad":"1.2.0"}}' > package.json; npm install
socket-patch scan --mode vendored --yes # rc 1, vendor_lock_entry_not_found
socket-patch scan --mode vendored --prune --yes --json # rc 1, gc.revertedVendoredEntries = [] <- npm-specific
socket-patch scan --mode vendored --yes # rc 1 again: stuckOn vlt, the same |
|
[agent] 2026-10-02: npm bug-hunt run Tested: main Handovers checked
Cells (Linux)
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-02: handover from the Bun bug-hunt routine (#306). Not filed: the behaviour lives in the shared npm-family VEX discovery and reproduces identically with npm 10, so it isn't Bun-specific. It might also be by design, since CLI_CONTRACT's vendored row attests from "the committed artifact + lock wiring". Observation: a vendored (and, under A natural way to get there: run vendored (or hosted) scan, then add a workspace member that depends on the same Repro (main # root: is-number@7.0.0, workspaces packages/*; packages/a: is-number@6.0.0
npm install && socket-patch scan --mode vendored --yes # packages/a/node_modules/is-number → file:.socket/vendor/…
# add packages/b with is-number@6.0.0
npm install # packages/b/node_modules/is-number → registry 6.0.0 (unpatched bytes)
socket-patch vex --json --product pkg:npm/app@1.0.0 -O vex.json # verified pkg:npm/is-number@6.0.0 (also with --no-verify)Bun (1.4.2, text v2 workspace lock): the same with Expected (suggestion): treat an unwired registry entry of the same |
|
[agent] Janitor: ledger drift. The coverage matrix still lists these issues as
This is a heads-up only. The janitor never edits ledgers. Generated by Claude Code |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled npm bug-hunt routine (label pm:npm).
Last updated: 2026-10-02 (run 8 with a ledger), main
61cfb9b(v5 + the #324/#325/#326/#359/#454 fixes; the binary still reports 4.0.0), latest release v4.0.0 (previous v3.3.0, both from npm@socketsecurity/socket-patch). v5 makes hosted the default, removessetup, and makes hostedrollbackre-resolve upstream registry entries. Cells marked (v4) were last verified onf6b7fb9.Coverage matrix
Cells are "pass", "fail #N" or "untested". Every cell uses a real npm install. Hosted cells use a local mock of the patch API with
--patch-server-urlpointed at it. Agent and vendored cells use the same mock or a hand-staged.socket/. "Cycle" means scan → freshnpm ci→vex→rollbackbyte-exact. "Suites" meanse2e_redirect_npm_build+e2e_vendor_npm_buildwithSOCKET_PATCH_NPM_E2E_REQUIRED=1.-g(scan report / get+apply / vex / rollback)-g(v4)npm ci→ vex refuses, re-apply, rollback--omit=dev, workspaces, vendored↔hosted takeover, revert byte-exact--omit=dev, workspaces, takeovers, rescan no-opoverrides(flat, alias, nested). fail #432 (alias mirror, npm 6 consumer), #490 (override over a git spec)-g(v4); Node 18 cycle--omit=dev(main), Node 18 cycle61cfb9b; alsonpm ci --omit=dev), #516 (vex, duplicate nested copies). pass: bundled copy (both copies patched + vex)--omit=dev, agent↔vendored takeovers. fail #490npm ci --omit=dev+ vex, shrinkwrappedfile:dep,JSONStream, agent↔hosted takeovers, stale tree, lockfile-only, dry-run, rescan no-op, nested project (loud),registry=mirror,.npmrcvariants,overrides(incl.$ref, nested object), policy (--package,maxNewPatches,ignorePackages,minSeverity), CRLF / BOM / tab / no-newline layout cycle. fail #490, #325 (in-run--vexonly, reopened)--global-prefix,SOCKET_GLOBAL,--mode hostedrefused. fail #464 (report-only hint has no-g).storescoped transitive (11.21, #359 fixed). fail #403 (v4)omit-lockfile-registry-resolved,overrides,install-strategy=linked/nested/shallow--omit=dev, workspaces,removein a workspace, Node 26,repair, BOM+CRLF / tab cycle (12.2.0)install-strategy=linked, Node 26,removein a workspace,allow-remote=allfrom env / user config still persisted, BOM+CRLF / tab cycle (12.2.0), workspace + alias cycle, dual-lock, drift,npm install <pkg>keeps the pin, path-scoped rollback, remove,registry=mirror, CRLF / spaced.npmrc. fail #433.storeapply/vex/rollback (main, #359 fixed). fail #356, #403 (v4)--omit=dev, revert (main).storeapply/vex/rollback (main, #359 fixed). fail #356, #403 (v4)--omit=dev, revert (main).storeapply/vex/rollback (main). fail #403 (v4)--omit=dev, revert (main)--global-prefixworks).storeapply/vex/rollback (main). fail #356, #403 (v4)--omit=dev, revert (main).storeapply/vex/rollback (main)--omit=dev, revert (main)Backlog
rollback/vexwith path policy over nested projects.overridesentry (regression from #345) #490 / Agent-mode npmvexhashes only the first installed copy of a package, so it attests not_affected while another nested copy of the same name@version is unpatched #516 / npm VEX attests not_affected while a bundled (inBundle) copy of the same package@version stays unpatched #325 / Vendored vlt scan exits 1 after the patched dependency is upgraded or uninstalled, and evenscan --pruneexits 1 while it reverts the stale entry #541 re-checks once main moves (PRs Fix agent vex checking only one installed copy (#516) #517, Fix vendored rescans failing on unwired ledger entries (#541) #543 pending); then overrides over URL /file:transitive deps on npm 8–12 ($refand nested objects pass on npm 10).--vexagainst other contested shapes (npm VEX attests not_affected while a bundled (inBundle) copy of the same package@version stays unpatched #325): a git copy only in the shrinkwrap, bundles inside workspace members.vexhashes only the first installed copy of a package, so it attests not_affected while another nested copy of the same name@version is unpatched #516 follow-ups: agentvexwith duplicate copies across workspace members and ininstall-strategy=linked.storepeer variants.-g), still open: npm 6/8/11 on macOS and Windows; an unwritable prefix (root-owned /Program Files); nvm, volta, fnm and Homebrew prefixes on macOS;%APPDATA%\npmonce On Windows,scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 is fixed. Full checklist in the 20261001T040000Z entry.git push --deletefails with "remote end hung up" / "Everything up-to-date"):bughunt/npm/20260930-alias-linked,20260930-win-mac-e2e,20260930-win-old-npm,20261001-crlf-paths,20261001-optional-dep,20261001-v5-hosted-global,20261001-win-global,20261002-v5-agent-vendored-winmac. A maintainer needs to delete them.Known non-bugs
patches-api.socket.devis unreachable from the sandbox. Use hand-staged manifests, a local mock API, or the wiremock suites.scan --mode hostedfrom a workspace member directory finds no packages, because discovery is cwd-scoped. It's loud and writes nothing.allow-remoteother thanallis respected with a loudredirect_npm_allow_remotewarning, and a fresh npm 12 install then fails EALLOWREMOTE (fails closed). This is documented.npm updatere-resolves a hosted or vendored entry back to the registry. That's npm's behaviour;vexthen refuses (redirect_unwired/vendor_unwired).applyskips the package as "managed bysocket-patch vendor" with exit 0 and doesn't take ownership back. That's by design (apply.rsVENDOR_OWNED_MARKER), andvexrefuses.file:directory dependency into the linked directory.build,dist,vendor,tmp,temp,coverageand hidden directories, even when one is an npm workspace member (documented in docs/ecosystems.md).applyfrom a workspace member directory reportsnoManifestwhen.socket/lives at the root (--cwdscoping).lock_heldunless--lock-timeoutis set (documented).rollbackdrops the rolled-back manifest entries and GCs their blobs unless--preserve-stateis set (documented).vexomits patches (ecosystem_not_setup) when there's nosetuphook and nosetup.manual(documented).@idis the raw origin URL for a non-GitHub/GitLab/Bitbucket remote (documented invex --help).npm root -gstdout, soapply -gmisses a global prefix whose path contains a UUID. That's npm's behaviour, it's loud (exit 1), and--global-prefixworks around it. Not filed.SOCKET_PATCH_NPM_E2E_LOCK_WRITER_BIN(an npm ≥ 7 to write the v2 lock). That's a harness requirement.patch.socket.devor the--patch-server-urlorigin are invisible torollback,vex,listandremove(documented). Mock runs must pass--patch-server-url.rollbackcan't reach registry.npmjs.org (the Rust client doesn't trust the proxy CA). UseSOCKET_NPM_REGISTRYpointed at a local passthrough.rollbackre-addsresolvedunderomit-lockfile-registry-resolved=true: hosted keeps no ledger, and npm drops the field on its next install.allow-remote=allin.npmrc: exit 1, the documented mid-flush I/O residual.scanwires only the cwd project's lock. A nested non-workspace project warnsredirect_npm_entry_not_found.scan . subwires both, butrollback/vexfrom the root don't seesub's pins (use--cwd sub).rollback <path>path targets select installed copies, so a workspace member whose dependency is hoisted to the root matches nothing (documented).vexattests from the committed artifact and only warnsvendored_tree_out_of_syncwhen the live tree is stale (documented).scan -gwithout-ealso scans the cargo, pypi and gem global stores (by design).vex -goutside a project needs--product.setup, so the setup-hook cells are retired.rollbackrestoresresolvedtoregistry.npmjs.org(orSOCKET_NPM_REGISTRY) even when the project.npmrcuses aregistry=mirror. That's documented ("default upstream registry entry"), andnpm cistill works because of npm'sreplace-registry-host.--packageandignorePackagesmatch package names and purls, not npm alias dependency keys (lp@npm:left-padis matched byleft-pad, notlp).ALLOW-REMOTE=andallow_remote=keys in.npmrc, so socket-patch appendingallow-remote=allafter them is correct.minSeverityskips patches whose per-package records carry no severity (documented). Mocks must fillvulnerabilitiesinby-package.scan -g --mode agentrun inside a project records the global patch in the cwd.socket/manifest.json, androllback -gdrops it again. The manifest is cwd-scoped; CLI_CONTRACT "Global scope never touches the project's state" only covers hosted pins and the vendor ledger, and says rollback/remove-g"drop their manifest records".left-pad@1.3.0) onto a transitive git copy of the same version, so the lock has a single git entry and theredirect_npm_non_registry_entry_skippedskip is correct.vexomits patches withecosystem_not_setupunlesssetup.manuallists the ecosystem (v4 behaviour). Set it when bisecting vex against v4.vexattests an omitted devDependency (npm ci --omit=dev) from its lock pin: documented ("With nothing installed … attests from that pin").npm install) losesresolvedin the legacydependenciesmirror, because npm's serializer never writes it for afile:resolution. A cold-cache npm 6npm cithen fails closed with EINTEGRITY. That's npm's behaviour; npm-compatibility.md's npm 6 + vendored v2 claim holds only until such a re-save.vexwith a bundled (inBundle) copy refuses to attest (patched_ref_unattributable). In hosted mode the final error reads as "no references found" (exit 2) because a rejected reference keeps nothing alive (documented). Only the diagnostic is misleading.scan --mode agentover hosted pins keeps the pins and warns (redirectState; documented).scan --prune/vendor --revert/removekeep (keptVendoredEntries,vendor_artifact_kept) an entry whose lock entry vanished afternpm uninstallor a version bump. It's the deliberate drift-keep (pinned byscan_prune_reverts_unused_vendored_entry). Whether to reclaim it is an open maintainer question (Vendored vlt scan exits 1 after the patched dependency is upgraded or uninstalled, and evenscan --pruneexits 1 while it reverts the stale entry #541 / PR Fix vendored rescans failing on unwired ledger entries (#541) #543 scope note). The rescan exit 1 is Vendored vlt scan exits 1 after the patched dependency is upgraded or uninstalled, and evenscan --pruneexits 1 while it reverts the stale entry #541.All reactions