Bug hunt ledger: vlt #307
Replies: 2 comments
|
[agent] 2026-09-30: vlt bug-hunt run Tested: main This is the first run: there was no earlier ledger and no CI status found
Cells
Issues
False positives ruled out
Probe
Next
mock.mjs (registry + patch API;
|
|
[agent] 2026-10-01: vlt bug-hunt run Tested: main Focus this run: v5 regressions. #277 replaced v4's hosted ledger with the upstream restore ( Re-triage
Cells (all pass unless noted)
Issues
False positives ruled out
Infra
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled vlt bug-hunt routine (label pm:vlt).
Last updated: 2026-10-01 (run 2), main
2463257(v5 consolidation, #277), latest release 4.0.0 (no vlt support; previous 3.3.0).Method: real vlt installs (
scripts/install-vlt.sh) against a local Node mock of the npm registry plus the patch API. It's a pure-JS tar writer, so it runs on every OS. The registry is on :18555 and the patch server on :18556 viaSOCKET_PATCH_SERVER_URL; setSOCKET_NPM_REGISTRYto the registry for v5 rollback. The oracle isrequire('left-pad')printingpatched/pristine. The 3-OS probe script is in the run-2 workflow (run 36803186961). CI already runs the capstones and the native backtest on 57 releases × 3 OS.Coverage matrix
warmOrdinary, PR #277 run), root cause blockedconfig.registry3-tuple)tar.brregistriestar.bralternatestar.brBacklog
dist.tarball(Artifactory scoped/-/@scope/name-ver.tgz). The restore rebuilds slot [3] conventionally and takes integrity fromSOCKET_NPM_REGISTRY, not the project registry.remove.scan/rollbackon vlt projects.native (ubuntu, rc.14) hosted-direct warmOrdinaryfailure if it recurs (needs the result artifact, which the sandbox can't download).Known non-bugs
patch.socket.devorSOCKET_PATCH_SERVER_URL. Against a mock without it,rollbacksays "Manifest not found" (documented).config.registryorigin, vlt omits slot [3] on re-save and the pin becomes invisible. That's a mock artifact only.\rthrough scan and rollback.scan <member-dir>in hosted mode scans the member as its own project (contract: "as if it were--cwd"), so a workspace member with no lock redirects nothing (redirect_npm_no_lockfile, rc 0; the human output says "Switched 0").vendor_lock_entry_unsupported). That's loud and fail-closed.registries.npm.vendor_vlt_transitive_unsupportedfor a target that is also a transitive dep is documented and fail-closed.vlt installwith "Integrity check failure" against registries advertisingtar.bralternates (a vlt bug, fixed in 1.3.1).redirect_npm_no_lockfileon vlt projects: it predates vlt support.All reactions