Bug hunt ledger: Bundler (RubyGems) #316
Replies: 2 comments
|
[agent] 2026-09-30: Bundler (RubyGems) bug-hunt run This is the first run, so the ledger started empty and there were no Tested: main Setup: the sandbox can't reach the Socket patch API. I used a temporary, uncommitted copy of Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-09-30: Bundler (RubyGems) bug-hunt run Tested: main Setup: a temporary, uncommitted copy of Cells
Issues
False positives ruled out
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Bundler (RubyGems) bug-hunt routine (label pm:bundler).
Last updated: 2026-09-30 (run 2), main
f6b7fb9, latest release 4.0.0.Coverage matrix
Cells are "pass", "fail #N" or "untested". Hosted and vendored cells use a local mock of the patch API (the sandbox blocks the real one) around real
gem buildfixtures, followed by a realbundle installon a fresh checkout. The repo's own e2e suites (e2e_redirect_gem_build.rs,e2e_vendor_gem_build.rs,e2e_redirect_gem_stale_install.rs) already cover the plain single-line Gemfile cells across 1.17 → 4.x. This ledger tracks what they don't.setupplugin (install, fresh clone)bundle pristinehealedifmodifiergroupblockBUNDLE_GEMFILEin.bundle/configGemfileonlygems.rb+Gemfiletwingems.rbonlyBUNDLED WITH)Gemfile+gems.rb)Backlog
BUNDLE_GEMFILEin.bundle/config: confirm it shares the Gem hosted redirect andsetupignoreBUNDLE_GEMFILEfrom.bundle/config, so they wireGemfilewhile bundler loads the configured manifest unpatched (VEX andsetup --checkstill pass) #390 gap, and comment on Gem hosted redirect andsetupignoreBUNDLE_GEMFILEfrom.bundle/config, so they wireGemfilewhile bundler loads the configured manifest unpatched (VEX andsetup --checkstill pass) #390.setupignoreBUNDLE_GEMFILEfrom.bundle/config, so they wireGemfilewhile bundler loads the configured manifest unpatched (VEX andsetup --checkstill pass) #390 on Bundler 2.2–2.6, and theBUNDLE_GEMFILEenv-only form withsetup.bundler/gems/<name>-<sha>): hosted redirect and agent patch targets, and the plugin'spatch_target_files.BUNDLE_PATHwith a drive letter or spaces,vendor/bundledeployment mode, and pluginDir.globonx64-mingw-ucrtplatform gems.scanfrom a subdirectory of a bundler project.Known non-bugs
patches-api.socket.dev/api.socket.devare blocked from the sandbox. Use a local mock API (--api-url); a hold-open copy ofe2e_redirect_gem_build.rsworks well.no_local_sourceunless you pass--vendor-source buildand thepatches/viewstub includesblobContent. That's a mock artifact.gems.rb-only project can't vendor. It's documented, and the refusal isno Gemfile at …/Gemfile(run 1'spackage_not_installedcame from the platform/mock setup).redirect_gem_no_checksums_section+redirect_gem_frozen_installand needs one unfrozenbundle install. Documented.-x86_64-linux) on a CHECKSUMS-less lock is redirected, and the next install switches to the patched ruby-platform gem. It's intended, and patched bytes load. With CHECKSUMS it fails closed (redirect_gem_platform_unsupported).bundle install --deploymentexits 15 on Bundler 4 (the flag was removed). UseBUNDLE_DEPLOYMENT=true/--frozen.sourceblock inside agroup … doblock dedents it. Cosmetic; bundler installs the patched gem.setup --jsonreports"packageManager": "npm"on a Bundler-only project. Documented in CLI_CONTRACT.setupprobes the machine bundler, so the 1.x refusal needs aBUNDLED WITH 1.xlock. Intended.BUNDLED WITH.All reactions