Bug hunt ledger: npm #302
Replies: 11 comments
|
[agent] 2026-09-30: npm bug-hunt run This is the first run with a ledger. An earlier run on the same day filed #324, #325 and #326 but wrote no entry. Tested: main Setup: the Socket patch API isn't reachable from the sandbox. Agent and vendored cells hand-stage Re-triage#324, #325 and #326 are still open, their fix PRs (#337 and #345) aren't merged yet, and main is the same commit they were filed on. I didn't re-run them. Cells
Issues
False positives ruled out
Probe runs
Next
|
|
[agent] 2026-10-01: npm bug-hunt run Tested: main Re-triageMain hasn't moved, so #324, #325, #326, #356 and #359 still reproduce as filed, and I didn't re-run them. #326's fix PR #345 is still open; I built its head (see below). Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where npm puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × npm version cells for |
|
[agent] 2026-10-01: npm bug-hunt run Tested: main Setup: a Python mock of the patch API (batch, by-package, Re-triage
Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-01: handover from the Yarn Berry (2+) bug-hunt routine (#305) This one isn't Berry-specific, so it's yours to triage if you want it. On main The hint leaves out |
|
[agent] 2026-10-01: handover from the vlt bug-hunt routine (ledger #307) While covering the maintainer's Symptom: after a failed agent-mode
Repro: main Related: #424 covers the first run's Generated by Claude Code |
|
[agent] 2026-10-01: npm bug-hunt run Tested: main Handovers triaged
Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: npm bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: handover from the Deno bug-hunt routine (ledger #308): agent-mode Found while testing Deno's hoisted linker. The root cause is generic npm-family, and the realistic trigger is plain npm, so this is yours to file. Nothing was filed from Deno. I searched for duplicates (#325, #405, #435, #471 are bundled / hosted / isolated / global variants) and found none covering agent mode. Defect. In agent mode Realistic trigger (real npm 10.9.4, main mkdir npmdup && cd npmdup && echo '{"name":"npmdup","version":"1.0.0"}' > package.json
npm install [email protected] [email protected] # nests [email protected] under is-number
# offline manifest + blobs patching package/index.js of pkg:npm/[email protected] (any free patch works)
socket-patch apply --offline # applied 1
npm install [email protected] # adds node_modules/is-accessor-descriptor/node_modules/[email protected] (unpatched)
socket-patch vex --offline -O v.json # exit 0, 1 statement: not_affected pkg:npm/[email protected]Copies afterwards: Deno too: Expected: agent vex attests a PURL only when every installed copy the crawler finds verifies (the hosted path already does this), otherwise it omits it as |
|
[agent] 2026-10-02: npm bug-hunt run Tested: main Handover triaged
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-02: npm bug-hunt run Tested: main Probe
The branch delete failed through the proxy again ("remote end hung up"), so it joins the stale-branch list. Cells (Linux unless noted)
IssuesNone filed, commented on or closed. Nothing new met the bar. False positives ruled out
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled npm bug-hunt routine (label pm:npm).
Last updated: 2026-10-02 (run 7 with a ledger), main
61cfb9b(v5 + the #324/#325/#326/#359/#454 fixes; the binary still reports 4.0.0), latest release v4.0.0 (previous v3.3.0, both from npm@socketsecurity/socket-patch). v5 makes hosted the default, removessetup, and makes hostedrollbackre-resolve upstream registry entries. Cells marked (v4) were last verified onf6b7fb9.Coverage matrix
Cells are "pass", "fail #N" or "untested". Every cell uses a real npm install. Hosted cells use a local mock of the patch API with
--patch-server-urlpointed at it. Agent and vendored cells use the same mock or a hand-staged.socket/. "Cycle" means scan → freshnpm ci→vex→rollbackbyte-exact. "Suites" meanse2e_redirect_npm_build+e2e_vendor_npm_buildwithSOCKET_PATCH_NPM_E2E_REQUIRED=1.-g(scan report / get+apply / vex / rollback)-g(v4)npm ci→ vex refuses, re-apply, rollback--omit=dev, workspaces, vendored↔hosted takeover, revert byte-exact--omit=dev, workspaces, takeovers, rescan no-opoverrides(flat, alias, nested). fail #432 (alias mirror, npm 6 consumer), #490 (override over a git spec)-g(v4)--omit=dev(main)61cfb9b; alsonpm ci --omit=dev), #516 (vex, duplicate nested copies). pass: bundled copy (both copies patched + vex)--omit=dev, agent↔vendored takeovers. fail #490npm ci --omit=dev+ vex, shrinkwrappedfile:dep,JSONStream, agent↔hosted takeovers, stale tree, lockfile-only, dry-run, rescan no-op, nested project (loud),registry=mirror,.npmrcvariants,overrides, policy (--package,maxNewPatches,ignorePackages,minSeverity), CRLF / BOM / tab / no-newline layout cycle. fail #490, #325 (in-run--vexonly, reopened)--global-prefix,SOCKET_GLOBAL,--mode hostedrefused. fail #464 (report-only hint has no-g).storescoped transitive (11.21, #359 fixed). fail #403 (v4)omit-lockfile-registry-resolved,overrides,install-strategy=linked/nested/shallow--omit=dev, workspaces,removein a workspace, Node 26,repair, BOM+CRLF / tab cycle (12.2.0)install-strategy=linked, Node 26,removein a workspace,allow-remote=allfrom env / user config still persisted, BOM+CRLF / tab cycle (12.2.0), workspace + alias cycle, dual-lock, drift,npm install <pkg>keeps the pin, path-scoped rollback, remove,registry=mirror, CRLF / spaced.npmrc. fail #433.storeapply/vex/rollback (main, #359 fixed). fail #356, #403 (v4)--omit=dev, revert (main).storeapply/vex/rollback (main, #359 fixed). fail #356, #403 (v4)--omit=dev, revert (main).storeapply/vex/rollback (main). fail #403 (v4)--omit=dev, revert (main)--global-prefixworks).storeapply/vex/rollback (main). fail #356, #403 (v4)--omit=dev, revert (main).storeapply/vex/rollback (main)--omit=dev, revert (main)Backlog
overridesentry (regression from #345) #490 / Agent-mode npmvexhashes only the first installed copy of a package, so it attests not_affected while another nested copy of the same name@version is unpatched #516 / npm VEX attests not_affected while a bundled (inBundle) copy of the same package@version stays unpatched #325 re-checks once main moves; then overrides using$refand nested objects over git / URL /file:transitive deps on npm 8–12.--vexagainst other contested shapes (npm VEX attests not_affected while a bundled (inBundle) copy of the same package@version stays unpatched #325): a git copy only in the shrinkwrap, bundles inside workspace members.vexhashes only the first installed copy of a package, so it attests not_affected while another nested copy of the same name@version is unpatched #516 follow-ups: agentvexwith duplicate copies across workspace members and ininstall-strategy=linked.storepeer variants.-g), still open: npm 6/8/11 on macOS and Windows; an unwritable prefix (root-owned /Program Files); nvm, volta, fnm and Homebrew prefixes on macOS;%APPDATA%\npmonce On Windows,scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 is fixed. Full checklist in the 20261001T040000Z entry.git push --deletefails with "remote end hung up" / "Everything up-to-date"):bughunt/npm/20260930-alias-linked,20260930-win-mac-e2e,20260930-win-old-npm,20261001-crlf-paths,20261001-optional-dep,20261001-v5-hosted-global,20261001-win-global,20261002-v5-agent-vendored-winmac. A maintainer needs to delete them.Known non-bugs
patches-api.socket.devis unreachable from the sandbox. Use hand-staged manifests, a local mock API, or the wiremock suites.scan --mode hostedfrom a workspace member directory finds no packages, because discovery is cwd-scoped. It's loud and writes nothing.allow-remoteother thanallis respected with a loudredirect_npm_allow_remotewarning, and a fresh npm 12 install then fails EALLOWREMOTE (fails closed). This is documented.npm updatere-resolves a hosted or vendored entry back to the registry. That's npm's behaviour;vexthen refuses (redirect_unwired/vendor_unwired).applyskips the package as "managed bysocket-patch vendor" with exit 0 and doesn't take ownership back. That's by design (apply.rsVENDOR_OWNED_MARKER), andvexrefuses.file:directory dependency into the linked directory.build,dist,vendor,tmp,temp,coverageand hidden directories, even when one is an npm workspace member (documented in docs/ecosystems.md).applyfrom a workspace member directory reportsnoManifestwhen.socket/lives at the root (--cwdscoping).lock_heldunless--lock-timeoutis set (documented).rollbackdrops the rolled-back manifest entries and GCs their blobs unless--preserve-stateis set (documented).vexomits patches (ecosystem_not_setup) when there's nosetuphook and nosetup.manual(documented).@idis the raw origin URL for a non-GitHub/GitLab/Bitbucket remote (documented invex --help).npm root -gstdout, soapply -gmisses a global prefix whose path contains a UUID. That's npm's behaviour, it's loud (exit 1), and--global-prefixworks around it. Not filed.SOCKET_PATCH_NPM_E2E_LOCK_WRITER_BIN(an npm ≥ 7 to write the v2 lock). That's a harness requirement.patch.socket.devor the--patch-server-urlorigin are invisible torollback,vex,listandremove(documented). Mock runs must pass--patch-server-url.rollbackcan't reach registry.npmjs.org (the Rust client doesn't trust the proxy CA). UseSOCKET_NPM_REGISTRYpointed at a local passthrough.rollbackre-addsresolvedunderomit-lockfile-registry-resolved=true: hosted keeps no ledger, and npm drops the field on its next install.allow-remote=allin.npmrc: exit 1, the documented mid-flush I/O residual.scanwires only the cwd project's lock. A nested non-workspace project warnsredirect_npm_entry_not_found.scan . subwires both, butrollback/vexfrom the root don't seesub's pins (use--cwd sub).rollback <path>path targets select installed copies, so a workspace member whose dependency is hoisted to the root matches nothing (documented).vexattests from the committed artifact and only warnsvendored_tree_out_of_syncwhen the live tree is stale (documented).scan -gwithout-ealso scans the cargo, pypi and gem global stores (by design).vex -goutside a project needs--product.setup, so the setup-hook cells are retired.rollbackrestoresresolvedtoregistry.npmjs.org(orSOCKET_NPM_REGISTRY) even when the project.npmrcuses aregistry=mirror. That's documented ("default upstream registry entry"), andnpm cistill works because of npm'sreplace-registry-host.--packageandignorePackagesmatch package names and purls, not npm alias dependency keys (lp@npm:left-padis matched byleft-pad, notlp).ALLOW-REMOTE=andallow_remote=keys in.npmrc, so socket-patch appendingallow-remote=allafter them is correct.minSeverityskips patches whose per-package records carry no severity (documented). Mocks must fillvulnerabilitiesinby-package.scan -g --mode agentrun inside a project records the global patch in the cwd.socket/manifest.json, androllback -gdrops it again. The manifest is cwd-scoped; CLI_CONTRACT "Global scope never touches the project's state" only covers hosted pins and the vendor ledger, and says rollback/remove-g"drop their manifest records".[email protected]) onto a transitive git copy of the same version, so the lock has a single git entry and theredirect_npm_non_registry_entry_skippedskip is correct.vexomits patches withecosystem_not_setupunlesssetup.manuallists the ecosystem (v4 behaviour). Set it when bisecting vex against v4.vexattests an omitted devDependency (npm ci --omit=dev) from its lock pin: documented ("With nothing installed … attests from that pin").npm install) losesresolvedin the legacydependenciesmirror, because npm's serializer never writes it for afile:resolution. A cold-cache npm 6npm cithen fails closed with EINTEGRITY. That's npm's behaviour; npm-compatibility.md's npm 6 + vendored v2 claim holds only until such a re-save.vexwith a bundled (inBundle) copy refuses to attest (patched_ref_unattributable). In hosted mode the final error reads as "no references found" (exit 2) because a rejected reference keeps nothing alive (documented). Only the diagnostic is misleading.scan --mode agentover hosted pins keeps the pins and warns (redirectState; documented).All reactions