Bug hunt ledger: pnpm #303
Replies: 3 comments
|
[agent] 2026-09-30: pnpm bug-hunt run Tested: main This is the first run: no earlier ledger, and no open Cells
Issues
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: pnpm bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where pnpm puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × pnpm version cells for |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled pnpm bug-hunt routine (label pm:pnpm).
Last updated: 2026-10-01 (run 2), main
f6b7fb9, latest release 4.0.0 (previous 3.3.0).Method: real pnpm installs. Agent and vendored modes use a hand-staged
.socket/manifest.jsonplus both blobs. Hosted mode uses a local Python mock of the patch API (batch, by-package, package grant, view) and the hosted tarball route. The oracle is a marker prepended toleft-pad/index.jsafter a fresh--frozen-lockfileinstall against a dead registry. The repo's pinned matrix (.github/workflows/pnpm-compatibility.yml) already covers plain hosted and vendored installs on pnpm 1–12. This ledger tracks what it doesn't.Coverage matrix
.pnpm"Edge shapes" means a whole-document flow mapping, a
...document end, and quoted orkey :top-level keys.Backlog
-g) mode for hosted patches on Linux, macOS and Windows across every major pnpm version.scan -gmust report exactly the global installs that have hosted patches;-g --mode hostedmust refuse loudly;-gapply, rollback and vex must hit the real global copy. Full checklist in the 20261001T040000Z entry on this discussion.bughunt/pnpm/20260930-virtual-store. Run 1 failed through the git proxy, and run 2 was denied by the session permission policy, so a maintainer needs to do it. Until deletion works, new probe branches can't be cleaned up, so macOS and Windows cells are on hold.--frozen-lockfile --offlinewith a warm store holding the upstream tarball, on pnpm 9–12. Check thatvexdoesn't attest unpatched installed bytes.dependenciesMeta.injected,package-import-method=clone|copy, and pnpm 1–6 legacy layouts (Node 16).vendor_lockfile_crlf_unsupportedrefusal; check that hosted handles the same checkout). Needs a probe branch.overrides:in pnpm-workspace.yaml: the new package.jsonpnpm.overridesshadows the user's overrides, so frozen installs fail and a re-lock drops them #360–Agent mode ignores pnpm's virtualStoreDir: transitive dependencies are reported package_not_installed with a custom virtualStoreDir or the global virtual store #362 (PR Fix npm crawler missing relocated dependency stores (#359, #362) #365) and Hosted trustLockfile and vendored overrides appends corrupt a flow-style or...-terminated pnpm-workspace.yaml while reporting success #400–pnpm-workspace.yaml edits miss quoted or space-before-colon top-level keys, append a duplicatetrustLockfile/overrideskey, and break every install #402 when fixes land.Known non-bugs
patches-api.socket.devis blocked by the sandbox proxy. Stage.socket/locally or mock the API.enableGlobalVirtualStorewhenCIis set, so the global-virtual-store cells don't engage on GH runners with pnpm 10..npmrcforvirtual-store-dir/enable-global-virtual-store. Put them inpnpm-workspace.yaml.pnpm-lock.yamlorpnpm-workspace.yaml(vendor_lockfile_crlf_unsupported), a BOM package.json (vendor_pkg_json_unsupported), an inline / flowoverrides:mapping (vendor_override_conflict, unit-tested), andpatchedDependencieson the target (vendor_lock_entry_unsupported; the detail wrongly says "peer-suffixed snapshot key", which is cosmetic).vexattests from the committed artifact plus lock wiring even when the tree isn't installed. That's by design (CLI_CONTRACT "Manifest-less VEX")..socket/blobs, so fixtures must stage both blobs (missing_blobotherwise). VEX needssetup.manual: ["npm"]or a setup hook (ecosystem_not_setup).rollbackgarbage-collects.socket/blobs. A later vendored run in a mock harness that serves no blob content then fails, and that's a fixture artifact.package.jsoncomes back 2-space-indented after vendor + rollback. There's no indent to detect, and indented files round-trip byte-exactly, so it's cosmetic.rollback <purl>of the only hosted purl removestrustLockfilecorrectly (whole-ledger replay). The leftover in Hosted→vendored takeover leavestrustLockfile: truein pnpm-workspace.yaml, andvendor --revertnever removes it #401 is specific to the vendored takeover.vex --output /dev/stdouthang when stdout is a pipe is not pnpm-specific.All reactions