Repository navigation
Bug hunt ledger: Bun #306
Replies: 44 comments
|
[agent] 2026-09-30: Bun bug-hunt run Tested: main Method: the patch API is unreachable from the sandbox ( This is the first run: there was no earlier ledger and no Cells
Issues
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: Bun bug-hunt run Tested: main Method: same as run 1, with the mock rebuilt ( Re-triage (on
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Bun puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × Bun version cells for |
|
[agent] 2026-10-01: Bun bug-hunt run Tested: main Method: real Re-triage (on
|
|
[agent] 2026-10-01: Bun bug-hunt run Tested: main Method: a Python mock of the authenticated patch API ( Re-triage
Cells
Issues
False positives ruled out
Blocked
Next
|
|
[agent] 2026-10-01: Bun bug-hunt run Tested: main No probe branch this run: Method: a Python mock of the patch API ( Re-triage
Cells (Linux)
Issues
False positives ruled out
Blocked
Next
|
|
[agent] 2026-10-02: Bun bug-hunt run Tested: main Method: a fresh Python mock of the org-scoped patch API ( Re-triage
Cells (Linux)
Issues
False positives ruled out
Blocked
Next
|
|
[agent] 2026-10-02: Bun bug-hunt run Tested: main Method: a fresh Python mock of the org-scoped patch API ( Re-triage
Cells (Linux): backlog item 5,
|
|
[agent] 2026-10-02: Bun bug-hunt run Tested: main Method: a fresh Python mock of the org-scoped patch API ( Re-triage
Cells (Linux)
Issues
False positives ruled out
Next
|
|
[agent] Janitor: ledger drift. The coverage matrix still lists these issues as
This is a heads-up only. The janitor never edits ledgers. Generated by Claude Code |
|
[agent] Janitor: ledger drift. The coverage matrix still lists these issues as
This is a heads-up only. The janitor never edits ledgers. Generated by Claude Code |
|
[agent] 2026-10-02: Bun bug-hunt run Tested: main Method: a fresh Python mock of the public proxy ( Re-triage
Cells (Linux)
IssuesFalse positives ruled out
Next
Generated by Claude Code |
|
[agent] 2026-10-03: Bun bug-hunt run Tested: main Method: a fresh Python mock of the public proxy ( Re-triage
Cells (Linux)
IssuesFalse positives ruled out
Next
Generated by Claude Code |
|
[agent] 2026-10-03: Bun bug-hunt run Tested: main Method: a fresh Python mock of the public proxy ( Re-triage
Cells (Linux)
Issues
False positives ruled out
Next
Generated by Claude Code |
|
[agent] 2026-10-03: Bun bug-hunt run Tested: main Method: a fresh Python mock of the public proxy ( Re-triage
Cells (Linux)
Issues
False positives ruled out
Next
Generated by Claude Code |
|
[agent] 2026-10-06: Bun bug-hunt run Tested: main Method: a fresh local mock of the authenticated org API ( Re-triage
Cells (Linux)
Issues
False positives ruled out
Next
Generated by Claude Code |
|
[agent] 2026-10-07: Bun bug-hunt run Tested: main Method: a new fixture with a fake npm registry on its own origin (bunfig Re-triage
Cells (Linux)
Issues
False positives ruled out
Next
Generated by Claude Code |
|
[agent] 2026-10-07: Bun bug-hunt run Tested: main Method: a fresh fixture with a fake npm registry on Re-triage
Cells (Linux)
Issues
False positives ruled out
Next
Generated by Claude Code |
|
[agent] Janitor: ledger drift. This ledger still lists these issues as Generated by Claude Code |
|
[agent] 2026-10-07: Bun bug-hunt run Tested: main Method: a new Python mock: an npm registry on Re-triage
Issues
Passed
False positives ruled out
Next
Generated by Claude Code |
|
[agent] 2026-10-08: Bun bug-hunt run Tested: main Method: a new Python mock of the authenticated patch API (batch, by-package, package grant, view with blobs, blob, the hosted tarball route) for Re-triage
Issues
Passed
False positives ruled out
Next
Generated by Claude Code |
|
[agent] 2026-10-08: Bun bug-hunt run Tested: main Method: a fresh Python mock of the public proxy ( Re-triage
Issues
Passed (#1035 / #1044 on Bun)
False positives ruled out
Next
Generated by Claude Code |
|
[agent] 2026-10-08: Bun bug-hunt run Run 32. Main Filed
Commented
Handed over
Cells
False positives ruled out
Next
|
|
[agent] 2026-10-08: Bun bug-hunt run Run 33. Main FiledNone. No new bugs. Re-triage
Cells
False positives ruled out
Next
|
|
[agent] 2026-10-09: Bun bug-hunt run Run 34. Main FiledNone. No new bugs. Re-triage
Cells
False positives ruled out
Next
|
|
[agent] 2026-10-09: Bun bug-hunt run Run 35. Main Filed
Commented
Re-triage
Cells
False positives ruled out
Next
|
|
[agent] Janitor: drift. #1084 was closed as completed on 2026-10-08 20:12Z by #1085 ( Generated by Claude Code |
|
[agent] 2026-10-09: Bun bug-hunt run Run 37. Main FiledNone. No new bugs. Re-triage
Cells
False positives ruled out
Probe branchesNone. Deleting the run 1–6 probe branches is still refused (auto-mode classifier, "Git Destructive"), so macOS/Windows stay untested. Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Bun bug-hunt routine (label pm:bun).
Last updated: 2026-10-09 (run 37), main
9ab72d4, latest release 5.0.0, latest Bun 1.4.2 (no 1.4.3 stable yet).Method (run 36 note: the authenticated routes work too:
--api-url <mock> --org o --api-token fakeserves/v0/orgs/o/patches/{batch,by-package,package,view}; still setSOCKET_PATCH_SERVER_URLto the mock origin or hosted pins aren't recognized androllbackexitsmanifest_not_found. Run 16 note: the sandbox shell exportsBUN_OPTIONS=--smol, so unset it; run 17 note: on Bun ≥ 1.2,bunfig [install] saveTextLockfile = falsewrites a binarybun.lockb): real Bun installs (npm@oven/bun-*or GitHub release binaries) and a local Python mock of the patch API: batch, by-package, thepatches/packagegrant,patches/viewwith blob contents,blob/<hash>, the hosted tarball route, and a/registry/passthrough forSOCKET_NPM_REGISTRY. SetSOCKET_PATCH_SERVER_URLandSOCKET_PROXY_URLto the mock (run 32: without a token the CLI uses the public-proxy routes/patch/batch,/patch/by-package/<purl>,/patch/view/<uuid>,/patch/blob/<hash>andPOST /patch/package, andpatch.socket.devreturns 403 through the sandbox proxy). Test repos neednode_modules/in.gitignore, or the fresh-clone oracle reads committed store entries. The oracle is the marker bytes after a fresh-checkoutbun install --frozen-lockfilewith an empty cache, plus byte comparison of the lockfiles andnode requirewhere runtime matters. The repo's own matrix (scripts/backtest-bun.py,bun-compatibility.yml) already covers plain hosted and vendored shapes across Bun 0.8.1–1.4.2. It always runs with--ignore-scriptsand never in agent mode, and it never runsvexon an isolated-linker tree. This ledger tracks what it doesn't.Run 35 method note: v5
vendorno longer builds tarballs locally (--vendor-source serviceis the only source), so a hand-staged manifest +vendor --offlinefailsvendor_service_offline_conflict. The mock must servePOST /patch/packagegrants ({"results":{uuid:{"status":"granted","purl","url","artifacts":[{"kind":"tarball","url","integrity":{"sha512":"sha512-…"}}]}}};{"status":"pending_build"}for an unbuilt patch) and the tarball aturl; setSOCKET_VENDOR_URLtoo. Hosted search also needsGET /patch/by-package/<purl>({"patches":[…],"canAccessPaidPatches":false}); without it a hosted scan silently redirects 0.Run 9: #366, #405 (fixed by #496) and #469 (fixed by #472) were verified fixed on Linux. Their cells below now read pass (Linux), and the macOS/Windows cells for them are untested on the fixed main.
Run 10: #599 still reproduces on
045d7ec. New: #635 (Bun ≥ 1.3.14globalStore).Run 11 (main unchanged at
045d7ec): #599 still reproduces. No new bugs. All the new cells pass: the run 11 section below, and the vendored row of theglobalStoretable.Run 12 (main unchanged at
045d7ec, so no re-triage): no new bugs. Bun 1.1.39, the oldest release in range, is now covered and passes. All the new cells pass: the run 12 section below.Run 13 (main unchanged at
045d7ec, so no re-triage): new #720. Lockfile-only discovery can't see hosted pins, so a hosted re-run in CI never picks up a superseding patch, andscan --mode vendoredskips the takeover. Both report success. The other new cells pass: the run 13 section below.Run 14 (main unchanged at
045d7ec, so no re-triage): new #739. Abun.lockbholdingX@1.0.0+X@1.0.0-beta.1is refused as a metadata-hash mismatch, and hosted exits 0 with nothing patched (a regression since 4.0.0). Bun cells added to #626 (agent mode overwrites first-party workspace members). The other new cells pass: the run 14 section below.Run 15 (main unchanged at
045d7ec, so no re-triage): new #764. Afterrollback/vendor --revert, the advisedbun installkeeps the patched bytes on the hoisted linker. The other new cells pass: the run 15 section below.Run 16 (main unchanged at
045d7ec, so no re-triage): new #784. A vendoredbun.lockbmigrated bybun install --save-text-lockfilecan't be reverted or rolled back, and a superseding re-vendor on it drops the pre-vendor original.removeadded to #764. The other new cells pass: the run 16 section below.Run 17 (main unchanged at
045d7ec, so no re-triage): new #803. A hosted or vendored workspacebun.lockbmigrated to text by Bun 1.4.2 carries socket-patch's path-normalized workspace literals, so frozen installs fail and the unfrozen install drops the pins. The other new cells pass: the run 17 section below.Run 18 (main unchanged at
045d7ec, so no re-triage): no new bugs. #764 is confirmed on a Bun 1.2.23 hoisted workspace. A member-levelbun adddropping that member's hosted pins is Bun behaviour (see Known non-bugs). The other new cells pass: the run 18 section below.Run 19 (main unchanged at
045d7ec, so no re-triage): no new issue. The yarn-classic handover #831 reproduces on Bun: a vendored tarball covered by.gitignore(*.tgz,vendor/,.socket/) exits 0, the commit drops it, and fresh frozen installs fail. That holds on text v1/v2,bun.lockband an isolated workspace, and the Bun matrix is commented on #831.bun cireproduces #803. The other new cells pass: the run 19 section below.Run 20 (new main
6811b4e): #803, #739 and #720 were fixed by #811, #741 and #722, closed by the maintainers, and verified on Linux (#803 heal: hosted + vendored re-run; #720: lockfile-onlybun.lockbsupersede + vendored takeover). #599 and #497 still reproduce, and #497 also gives a falsenot_affectedfrom lockfile-only defaultvex(commented). New: #861. A vendored re-run after a new dependent duplicates abun.lockbtarball record, and isolated frozen installs fail EEXIST intermittently on 1.3.9/1.4.2. The other new cells pass: the run 20 section below.Run 21 (new main
9c43dfc): #861 still reproduces. No new issue. The isolated-workspace member-run shape (hostedscanfrom a member:success, nothing pinned) is now tracked on #884 (commented), and is no longer a known non-bug. Three generic npm-family findings were handed to npm. The other new cells pass: the run 21 section below.Run 22 (main unchanged at
9c43dfc, so no re-triage): no new bugs. All the new cells pass: multi-package and large-tree (express)bun.lockbhosted / vendored / takeover by writers 1.1.45–1.4.2, two versions of one patched package (nested + direct, and per workspace member), and scopedrollback/removeof one of two same-name pins. See the run 22 section below.Run 23 (main unchanged at
9c43dfc, so no re-triage): no new issue. #861 also reproduces whenbun addruns inside an existing member (commented). All the new cells pass: a vendoredbun.lockbupgraded from binary format 2 to 3 by a newer Bun,bun.lockbtakeovers by writers 1.1.39 / 1.3.4 / 1.3.10,globalStore+ hosted workspace, and BOM / no-final-newline text locks. See the run 23 section below.Run 24 (main unchanged at
9c43dfc, so no re-triage): no new bugs. The Bun 1.3.10 text-lock row is now covered (agent hoisted + isolated, hosted, rollback byte-exact). A hosted 1.2.0 workspacebun.lockbupgraded to format 3 by 1.4.2 picks up a superseding uuid. Concurrent and SIGKILLed vendored runs, mixed-case names (JSONStream) and catalogs all pass. See the run 24 section below.Run 25 (main unchanged at
9c43dfc, so no re-triage): no new bugs. Mixed per-package modes (vendored ⇄ one package hosted, on text andbun.lockb, single and workspace, 1.2.23 / 1.3.9 / 1.4.2) pass, as doglobalStore+ vendored workspace lockb,overrides/resolutionsand Bun lock re-serializations. #861 also reproduces underglobalStore.bun removeof a vendored package leavesvendor --checkred with a no-op remedy; it's generic, so it was handed to npm (related #900). See the run 25 section below.Run 26 (main unchanged at
9c43dfc, so no re-triage): no new bugs. ExplicittrustedDependenciesandbun pm truston hosted / vendored packages with a postinstall keep the script running (text +bun.lockb, single + workspace, 1.2.23 / 1.3.9 / 1.4.2). Mixed per-package modes plus a superseding uuid, re-run in each mode, pass.bun install --filterfrozen installs on rewired workspaces pass. Probe-branch deletion is still refused (now by the sandbox's permission classifier). See the run 26 section below.Run 27 (main unchanged at
9c43dfc, so no re-triage): new #992. Hostedbun.lockrollback/remove/ hosted→vendored→vendor --revertwrite""into the registry slot, and Bun 1.1.39–1.3.6 resolve""against npmjs, ignoring the bunfig registry. Custom-registry projects then fail cold frozen installs (404), or silently bypass their mirror. Bun's own boundary is 1.3.7. Also passing:preinstall/install/postinstallon a scoped package with abinand an unscoped preinstall-only package (hosted / vendored × text /bun.lockb× single / workspace × 1.2.23 / 1.3.9 / 1.4.2). In untrusted projects, rewiring doesn't start running scripts.bun pm trustand--filterwork on 1.2.23. Plain re-installs leave a rewrittenbun.lockbbyte-identical. Bun 1.4.3-canary.1 passes hosted / vendored / agent, the takeover chain and rollback. Packages with only a sha1shasumrewire fine. See the run 27 section below.Run 28 (new main
db83f01): #992 and #861 still reproduce (the fix is pending in draft #1009). Verified on Linux: #367 (#873, registry-keyedbun patchkept, text +bun.lockb), #884 (#901, loud member refusal), #831 (#837, Bun*.tgz/.socket/ignores) and #963 (a refused vendored takeover keeps the Bun hosted pins). New: #1019. On Bun 1.4, abun patchmade after rewiring is keyedname@<hosted URL | vendor path>, which the #873 guard doesn't match, so superseding re-runs, takeovers, rollback and revert silently drop it. See the run 28 section below.Run 29 (new main
05ecc6e): #992 still reproduces (fix pending in draft #1009). New: #1084. On the isolated linker, after an agent A → hosted B (superseding) migration and abun install,rollback/removeexit 0 and drop record A and its blobs. #934'srollback_record_supersededskip ignores the orphaned.bun/<pkg>@<ver>store entry, which still holds A's bytes, and the advisedbun installrelinks it (first bad04885c3). The agent → vendored takeover leaves the same A-patched orphan behind after a revert, which was commented on #764. #934 on hoisted text locks passes. See the run 29 section below.Run 30 (new main
fe8455d; no Bun code changes since05ecc6e, so #992 / #1084 weren't re-run, and their fixes are still pending in draft #1009): new #1101. A hosted or vendored scan /getrun from a Bun workspace member that holds a straybun.lock/bun.lockbpins that lock, which Bun never reads. It exits 0, andvexattestsnot_affectedwhile Bun installs unpatched (the Bun variant of #1094; PR #1095 explicitly keeps Bun's own-lock shortcut, verified on its headcddf38d). Bun 1.1.39–1.2.23 ignore!workspace patterns (1.3.0+ honour them), so #1097's negation half reproduces on old Bun (commented). #1073's brace / class /**/ object-form member refusals pass on 1.4.2. A symlinkedbun.lock/bun.lockbdry run vs wet run passes (backlog 10). See the run 30 section below.Run 31 (new main
829d0af: #1035 superseded-generation remove/rollback, #1044 governing-lock table, #1038, #1042, #1033): new #1116. Vendoredbun.lockbworkspaces write member-relative tarball mirrors (packages/<m>/.socket/vendor/...) with no.gitignoreprobe and no!*re-include, so a stock*.tgzrule drops them from the commit. Fresh frozen installs then fail with ENOENT (1.1.39–1.2.23) or hang (1.3.9) when the member resolves its own copy, and on 1.4.2vendor --check/vexfail in every clone. #1101 and #1084 still reproduce. #1101 also reproduces under a rootbun.lockbwith a stray memberbun.lock/bun.lockb, where lockfile-onlyvexattests (commented). #1035 on Bun passes: hosted and vendored supersede A→B thenremove B/rollback B, cross-mode takeovers, the #999 shape, hosted A + agent B, and an alias of the same release (text + lockb, single + workspace, 1.2.23 / 1.3.9 / 1.4.2; the text lock is byte-exact). See the run 31 section below.Run 32 (new main
9472be4: #1050 one in-use verdict for the vendored prune GC, #1029 CI gates and hostedredirect.patches[]): new #1132. Afterbun removeof a vendored package in abun.lockbproject,scan --prune,vendor --revertandremoveall keep the entry as "drifted" (bun_binary.rs:526), sovendor --checkstays red and its--pruneremedy loops (1.1.39–1.4.2, single + workspace). Textbun.lockreverts cleanly. Orphaned.bunstore entries after an upgrade or removal make a vendoredscanexit 1, put anunpinnedrow in hostedredirect.patches[], and get patched and attested in agent mode (commented on #599). Upgrading a vendored package loops the same way on every npm-family lock (handed to npm). #1116 still reproduces. The #1050 prune GC on live vendored projects passes across 1.2.23 / 1.3.9 / 1.4.2 × text / lockb × single / workspace × hoisted / isolated. See the run 32 section below.Run 33 (new main
a845bf9: #1039 staged, atomic vendored → hosted takeover, #1043, #1021): no new bugs. The #1039 takeover passes on Bun: a partial takeover where hosted refuses one purl (grantdenied, or no sha512 →redirect_bun_missing_sha512) keeps that purl vendored byte for byte (redirect_takeover_kept_vendored, artifact and member mirrors intact) and takes over the rest, the dry run predicts it exactly and writes nothing, and a later re-run completes the takeover (text + lockb, single + workspace, 1.1.39 / 1.2.23 / 1.3.9 / 1.3.10 / 1.4.2). A hosted takeover also rescues a #1116-broken clone. A SIGKILL sweep found only PRE / POST / journal-recoverable states; a kill between the commit and the deferred artifact deletions leaves inert orphan artifacts (Known non-bugs). #1132 and #1116 still reproduce. See the run 33 section below.Run 34 (new main
793edd4: #1147 vendored revert of a removed dependency, #1051 / #580 bun-lock spec-first bundled check, #1058 hosted pin decision through discovery, #815 line terminators, #905 BOM handling, #1027 JSON error objects, #1031): no new bugs. #1132 verified fixed (lockbbun remove→ prune reverts,vendor --checkgreen; 1.1.39 / 1.2.23 / 1.4.2). The lockb upgrade variant is also fixed, while Bun's textbun.lockupgrade still loops (commented on #1155, which draft #1187 covers). #1101 still reproduces (PR #1161 unmerged). Passing: 4-patch hosted / vendored on text + lockb, CRLF / BOMbun.lockand BOMpackage.json(1.2.23 / 1.4.2, rollback and revert byte-exact), a superseding uuid during the vendored → hosted takeover (full, and with B missing sha512 so A stays vendored; 1.1.39 / 1.2.23 / 1.3.9 / 1.4.2), write-failure injection (chattr +i) on a bun.lock + package-lock.json hosted run and on the journaled takeover (nothing changed),apply --checkon agent trees (hoisted / isolated / workspace, 1.2.23 / 1.3.9 / 1.4.2), and a symlinkedbun.lockb(refused up front, dry and wet). See the run 34 section below.Run 37 (new main
9ab72d4: release 5.0.0, #1034 target grammar, #989 shared vendored revert; no Bun fix): no new bugs. Verified fixed on Linux: #1101 (#1161: member with a stray lock refusesredirect_workspace_lockfile_elsewhere), #861, #784, #599, #735, #443, #635 (agent refuses the global store), #371 (documented*_bun_default_trust_lostwarning) and #764 (*_bun_reinstall_required, andbun install --forcerestores the bytes). Passing: #1034 names / version-less purls / two pinned versions,get <uuid> --mode vendoredon lockb workspaces, a vendored → hosted (superseding) → vendored → revert chain, unicode / space paths, dev / optional deps with--production, warm shared caches, and concurrent runs (lock_held). #1276 / #1243 fixes are in open PRs #1283 / #1247. See the run 37 section below.Coverage matrix
bun patchvex: isolated linkerbun.lockbtakeover ⇄ revertglobalStore; fail #626 (first-party workspace member)bun patchmade after rewiringbun remove→ prune/revert: pass (#1132 fixed by #1147, lockb 1.1.39 / 1.2.23 / 1.4.2; run 34); upgrade → prune: pass on lockb, fail #1155 on text (run 34)Isolated-store edge cases after #496 (run 9, Linux)
+<hash>entries--backend=symlinkvexfresh clonevexafter in-place frozen reinstall (orphaned.bunentries)vexafter in-place reinstallvendored_tree_out_of_sync(#599)Bun
globalStore(machine-wide isolated store, Bun ≥ 1.3.14; run 10, Linux).bunentries patchedvexon stale/unpatched transitiveglobalStore = truevexverified, no false out-of-sync)BUN_INSTALL_GLOBAL_STORE=1globalStore = true, hosted isolated workspacenot_affected; after rollbackvexrefuses)Hosted pins and registry credentials (run 10, Linux)
No
Authorizationheader reaches the hosted tarball host for any of: bunfig default-registry token or basic auth,.npmrchost_authToken, global_authToken,always-auth, scoped.npmrc,[install.scopes]token,NPM_CONFIG_TOKEN. That holds on 1.4.2, 1.3.14, 1.2.23 and 1.1.45, cold-cache frozen installs: pass. Control: the same configs sendBearerto the configured registry.Platform-specific optional deps (run 10, Linux)
os/cpumeta (fsevents, @esbuild/darwin-arm64, @esbuild/linux-x64). The hosted rewrite keeps the meta, and Linux frozen installs fetch only linux-x64 (patched), on 1.1.45 v0 + lockb, 1.2.23, 1.3.14, 1.4.2 text + lockb: pass. Hosted rollback is byte-exact (1.4.2): pass.minimumReleaseAgewith hosted pins (1.4.2): pass.Run 26 cells (Linux, main
9c43dfc)Fixture: a fake registry on its own origin (bunfig
[install] registry) servinghookpkg@1.0.0(apostinstallthat writes a file),plainpkgandotherpkg, plus the patch-API mock on a second origin. Oracle: fresh clone, coldbun install --frozen-lockfile(scripts enabled), the marker bytes, the postinstall's output file,bun pm untrusted, andvex.trustedDependencies: ["hookpkg"], hosted, text / lockb × single / workspacevendor_bun_workspace_unsupported, documented)bun pm trust hookpkg, hosted + vendored × text / lockb (single)vexattests)get plainpkg --mode hosted→ both hookpkg and plainpkg superseded →scan --mode vendoredtwiceredirect_revert_failed(documented: "workspace dependency behaviors it normalized … checkout remedy"),vexattests only the 2 vendoredscan --mode hostedtwice--filter m1/--filter proj/--filter '!m1'/--filter './packages/*'on hosted + vendored workspaces (text + lockb)In every superseding cell the cold frozen install had the new markers, the postinstall ran,
vexnamed the new uuids,vendor --checkwas clean, the stale artifacts were removed and the second re-run was a no-op. Aftervendor --revert+rollbackthe frozen install was unpatched; the lock differs from the pre-vendor one only by""in the registry slot of entries that went through hosted mode (the custom-registry case in Known non-bugs).Run 25 cells (Linux, main
9c43dfc)get <purl> --mode hostedfor one package: cold frozen,vex(vendored + redirected),vendor --check,vendor --revertkeeps the hosted pin,rollbackget <purl> --mode vendoredfor one package: cold frozen,vex,rollbackunwinds bothglobalStore = true+ vendored isolated workspace lockb: cold frozen,vex,vendor --checkoverrides/resolutionsforcing the patched version: hosted + vendoredbun install --lockfile-only,--force,bun add <present>,bun remove <other>bun remove <vendored pkg>→vendor --checkget --mode agenton a vendored package → scopedrollback→bun installvexhonestRun 24 cells (Linux, main
9c43dfc)bun.lockbwritten by 1.2.0 (format 2),bun addby 1.4.2 (format 3), superseding uuid, lockfile-only hosted re-run, cold frozen install,vexupdatesnames the new uuid, MARK2 installed,vexattests the new record's vuln; 1.2.0 can't read format 3, same as a socket-patch-free control)rollbackrollbackbyte-exactvendor --revertbyte-exactscans (text v2)lock_held, the others serialize;vendor --checkclean)bun.lockbscan SIGKILLed at 5–60 ms: cold frozen install, re-run,vendor --check,vendor --revert(bun pm hash-stringequals the original)JSONStream@1.3.5: hosted, vendored,vex,vendor --revert, agent +rollback, on text v2 +bun.lockbcatalog:+ namedcatalog:old) in an isolated v2 workspace: vendored, vendored → hosted takeover,rollbackbyte-exact--dry-runhosted / vendored on an isolated workspacebun.lockb(no writes);get <purl> --mode vendored(member copies written, only that package wired)get <purl> --mode hostedfor one package)Run 23 cells (Linux, main
9c43dfc)bun.lockbformat 2, upgraded to format 3 by a 1.4.2bun add: re-run,vendor --revert, scopedrollback/remove, vendored → hostedbun.lockbhosted, hosted → vendored, vendored → hosted,vendor→vendor --revertglobalStore = true+ hosted isolated workspace: sibling project, in-placevex,rollbackbun.lockwith a UTF-8 BOM, or with no final newline: hosted, rollback, vendored, revert (byte-exact)bun addinside an existing member1.4.2-canary.20261005.1Run 22 cells (Linux, main
9c43dfc)bun.lockb(5 patches, scoped + nestedms): hosted, vendored,vex, semanticvendor --revertms@2.1.2+ directms@2.1.3, both patched: text v2 + lockb × hoisted + isolated × hosted + vendored; hostedrollback pkg:npm/ms@2.1.2keeps the other pinvendor --revertbun adda new dependent → vendored re-run → 4× cold frozenms@2.0.0/ms@2.1.3): hosted lockb, vendored lockb, vendored text v2, hosted text v1remove pkg:npm/ms@2.0.0on those vendored workspace lockbs: member copies removed, other version kept,vendor --checkbun install --force→vexrefuses →applyre-patchesRun 21 cells (Linux, main
9c43dfc)+<hash>×2): apply, no cache write-through,vex,rollback; a new peer variant →vexrefuses →applypatches only itbun.lock/bun.lockb0664 (hosted + vendored); agent bin file 0755 / 0777 through apply + rollbackrollbackbyte-exact + frozen install, text v1 single + workspacebun.lockbhosted → vendored → revert; vendored → hosted → rollback refusal; single + workspacebun.lock+ stalebun.lockb: hosted / vendored,vex,vendor --check, frozenbun.lockb/bun.lock, vendoredscan/get --mode hostedfrom an isolated workspace memberbun.lock+package-lock.jsonvendored →vendor --checkbun.lockwired + stalepackage-lock.jsonwithout the package → lockfile-onlyvexRun 20 cells (Linux, main
6811b4e)bun.lockb→ new member depending on the patched pkg →bun install→ vendored re-run → fresh frozen installpackages/*/*, dir with space/ü/#, peer workspace edge, nameless root, dir ≠ namecatalog:+ namedcatalogs:workspacebun.lockb: hosted, frozen by each readerbun.lockb: frozen,vex, byte-exact revert; deleted member mirror →vendor --check/vexfail closed →repairbun.lockbhosted supersede; lockfile-only vendored takeovernode_modules)vexRun 19 cells (Linux)
.gitignore*.tgz/vendor//.socket/→ commit → fresh-clone frozen installbun.lockb, 1.2.23 text v1, 1.1.45bun.lockb, 1.4.2 v2 isolated workspacevendor --check0 undervendor//.socket/;vexfails closed)bun cion the #803 shape (workspacebun.lockb+workspace:*, hosted, migrated to text by 1.4.2)bun.lockbre-serialized by a rootbun add; fresh frozen install;vexcore.autocrlf=true: frozen,vendor --check,vex,vendor --revert, post-revert installcore.autocrlf=true: frozen,vex,rollback(CRLF kept), post-rollback installRun 18 cells (Linux)
--max-new-patches 1over 2 hidden pinsbun.lockbwithout inter-workspace deps →--save-text-lockfileby 1.4.2 → fresh frozen installrollback→bun install, workspace (hoisted default)bun addinside a workspace member after hostedbun.lockbvex(Known non-bugs)bun.lock, hostedredirect_symlinked_file_unsupported, nothing written)rollback <purl>with 2 hosted pins → frozen install; then fullrollbackbyte-exactbun.lockbre-serialized bybun addRun 17 cells (Linux)
bun.lockb→--save-text-lockfile→ hosted → vendored takeover → fresh frozen install →vendor --revertbun.lockb→--save-text-lockfile→ fresh frozen installbun.lockb→--save-text-lockfile→ fresh frozen installget <purl> --mode hostedpicks up a superseding uuid; frozen install;rollbackRun 16 cells (Linux)
bun.lockb→bun install --save-text-lockfile: pins kept, install patched,list,rollback, fresh frozen installbun.lockb→--save-text-lockfile:vendor --revert/rollback/ hosted takeovervendor --revert→bun install--filter <name>/--filter ./path/--productionremove <purl>→ advised frozen install, hoisted, hosted + vendoredRun 15 cells (Linux)
bun.lockbmeta hash, numeric/alphanumeric prerelease pairs (beta.2/beta.10,1/alpha,rc.1/rc.1.0,x.9/x.10/x.100): hosted + frozen installsoptionalPeers,optionalDependencies,bin; npm aliases beside the direct copy: hosted, frozen install,vexvex/apply/rollbackrollback/vendor --revert→ advised in-placebun installrestores upstream bytes, hoistedRun 14 cells (Linux)
+) / legacy-uppercase / scoped dotted names: hosted, vendored, agent (isolated),vex, rollback,vendor --revertbun.lockb: hosted, frozen installs by each reader, hosted → vendored → revertX@1.0.0-beta.1+ nestedX@1.0.0(also under a scoped parent), text lockbun.lockb(patch on any package)link:target matching a patchedname@versionfile:passes, hosted / vendored safe)Run 13 cells (Linux)
bun.lockbnode_modules: pass)scan --mode vendoredover hosted pins (takeover)bun.lockbvendorcommand: pass)vex, exact heal)applyor a--jsonre-run)repairon a vendoredbun.lockbisolated workspace (deleted / corrupt artifact)bun ciand--productionfrozen installs with hosted pinsRun 12 cells (Linux)
bun.lockb: hosted / vendored scan, frozen installs,vex, idempotent re-run, rollback / revert; agent scan →vex→ rollbackbun.lockbwithoverrides+trustedDependencies, hosted and vendoreda b üandc#d, scoped patched dep: hosted, hosted → vendored, byte-exactvendor --revert, scopedremovegetby CVE / GHSA / UUID / PURL / scoped name, hosted + vendoredscan(hosted, vendored), midrollback, midvendor --revert; then re-runvexskip →repairrebuilds--offline/--prefer-offlinewith hosted pins + warm registry cache--offlinefails closed)yarn.lockscan --mode hostedheals it (same aspackage-lock.json)pnpm-lock.yamlIntegrityCheckFailed(see Known non-bugs)bun add→ re-run re-pins; lockfile-onlyvexattests nothing without a pinignorePathsover workspace members (hosted + agent)includePaths,minSeverityflag > file,!/tests/)Run 11 cells (Linux)
bin(semver): meta kept,.binlinked after frozen installbun.lockb(1.1.45 writer) withbin+ scoped packages, frozen install by each readerbun updatedrops hosted pins;vexthen refuses (manifest_not_found), no false attestationrollback/vendor --revertafter the migration"left-pad": "npm:is-number@6.0.0"), hosted + vendoredvendor --revert(byte-exact pre-hosted lock)bun.lockbworkspace with nested version keys, hosted (writers 1.1.45 and 1.4.2)lock_held); lockfile-only hostedvexpackage-lock.jsonscan --mode hostedheals it (see Known non-bugs)Global mode (
-g, agent; run 3)BUN_INSTALL_BINsetBUN_INSTALL_GLOBAL_DIRset-g --mode hostedrefusalbun.cmd)bun add -gfailed in the probe's space+unicode temp path)Untested: a non-writable global dir, a symlinked
BUN_INSTALL, and Bun 1.0.x.Bundled dependencies (
bundled: truelock entries; run 4)vexvexvex --no-verifynot_applied)Non-registry copies of a patched
name@version(run 5, Linux)vexvexvex --no-verifynot_applied)file:tgz)bun.lockb(URL tgz; run 6)github:tuplessocket.ymlpolicy and staged rollout (run 6, Linux)maxNewPatches: 1advancemaxNewPatches: 1advanceignorePackageskeeps pinenabled: falsewrites nothingsocket.ymlacross several independent Bun projects in one repo (run 7, Linux)includePaths(hosted, PATH glob)maxNewPatchesacross dirsminSeverityflag > env > fileignorePathskeeps pins byte-identical!/tests/re-include**/bun.lockbmarkerAgent mode applies path policy only at the scan root, so nested independent projects are always patched. That's generic, not Bun-specific: handed to npm (
entries/npm/20261002T072532Z-from-bun.md).Workspace members under ignored paths, and growth after a scan (run 8, Linux)
tests/member: agenttests/member: hosted (frozen patched)ignorePathsover members keeps them (agent / hosted / vendored)package-lock.json+bun.lockhosted.npmrcremoved)Between a scan and its re-run, an unwired registry copy of a patched
name@versionin the same lock is still attested by vendoredvexand by hostedvex --no-verify. npm does the same, so it's handed to npm (entries/npm/20261002T133747Z-from-bun.md), not filed as a Bun bug.Also passing in run 6: a dual-lock checkout (
bun.lock+ a stalebun.lockb, where Bun ≥ 1.2 readsbun.lockand hosted rewrites only it), and global mode with a symlinkedBUN_INSTALL(1.4.2: agent scan,vex -g,rollback -g).Lock-shape edge cases (run 5, Linux)
bun.lock+ CRLFpackage.json(1.1.45 v0, 1.3.14, 1.4.2): hosted scan → frozen install →rollback, and vendored →vendor --revert. Both byte-exact: pass.bun install --yarn(siblingyarn.lock), on 1.1.45 lockb, 1.2.23 and 1.4.2: hosted rewires both locks; lockbrollbackrefuses and touches neither file: pass.[install.scopes]custom-registry scope (1.3.14, 1.4.2): hosted rewrite and byte-exact rollback: pass.vexis correct: pass.bun addafter hosted (all four versions; the pins survive) and after vendored (digest-less re-save on < 1.3.10, healed by the re-run): pass.Takeovers and vendored VEX (run 4, Linux)
vendored_tree_out_of_syncis missing (1.4.2): fail, under With Bun's isolated linker,vexattests a hosted patch as not_affected (verified) while the installed copy under node_modules/.bun is still unpatched (v5 regression) #405 (comment). Hoisted control: pass.Other passes (Linux, 1.4.2 unless noted):
scan --global, and the (pre-v5)setuphook.SOCKET_GLOBAL=1≡-g;SOCKET_GLOBAL_PREFIX/--global-prefixscan only that dir;scan -ginside a project with a bunfig settingglobalDirdoesn't leak project dirs;vexwithout-gignores global copies.remove,repairandliston hosted pins.bun.lockbidempotency,--dry-run, and the rollback refusal.catalog:andoverrides.package.json.Run 27 (Linux, main
9c43dfc)preinstall/install/postinstall+bin, and an unscoped preinstall-only package;trustedDependencies; cold frozen install runs the same scripts, links.bin, is patched,vexatteststrustedDependencies): no scripts run before or after the rewirebun pm trustafter rewiring;--frozen-lockfile --filter(m1,proj,!m1,./packages/*)bun installon a rewrittenbun.lockbleaves it byte-identical (samebun pm hash)shasum, nointegrity): hosted / vendored rewire + frozen install""diff)Run 28 (Linux, main
db83f01)bun.lockbworkspace, vendored re-run after a new memberbun patch(plain + scoped) then hosted / vendoredbun patchmade after a hosted or vendored rewire (keyname@<url or vendor path>), then a superseding re-run / takeover / rollback / revertbun patch --commitcrashes on URL-resolved packages)scanfrom a workspace memberredirect_workspace_lockfile_elsewhere, exit 1, nothing written)*.tgz/.socket/in.gitignore*.tgzkept via nested negation;.socket/fails closed)scan --mode vendoredRun 29 (Linux, main
05ecc6e)bun install→ rollback / remove, hoisted text lockrollback_record_superseded, exit 0, fresh frozen install ORIGINAL; a failed registry fetch → exit 1, and the retry heals)bun.lockbgit checkout -- bun.lockbremedy; record A droppedRun 30 (Linux, main
fe8455d)scan/get <uuid>and vendoredscanfrom a workspace member holding a straybun.lock/bun.lockb(the rootbun.lockgoverns)vexnot_affected from a hoisted or lockfile-only member)cddf38dscanfrom a member, object-formworkspaces.packages=packages/{a,b}/packages/[a-c]/packages/**/./packages/a/redirect_workspace_lockfile_elsewhere)!packages/anegation: Bun's member seta; 1.3.0 / 1.3.4 / 1.3.9 / 1.4.2 exclude itscan/getfrom that negated memberredirected: 0,redirect_npm_no_lockfile(×2); 1.1.39 / 1.2.23 hoistedget: samepackages/@(a|b)bun installrejects the package.json)bun.lockb/bun.lock, vendored--dry-runvs wet, plus hosted wetwould_refuse vendor_bun_lockb_invalid; text dry run:vendor_would_refuse_symlinked_file; wet runs exit 1 with the link and its target untouched; hostedredirect_symlinked_file_unsupported)Run 31 (Linux, main
829d0af)remove B/rollback, textbun.lockbhosted_revert_failed(git checkout remedy)remove B, text + lockbremove B/rollback Bremove Bget B --mode agent,remove Bgetwarns "vendored at A but the manifest now records B",vexattests A only)remove B/rollback B, hoisted + isolatedhosted_pins_matchingunpins A)left-pad+lp: npm:left-pad@1.3.0), hosted / vendored supersede + removebun.lock/bun.lockb+ leftoverpackage-lock.json(#1044 table)vendor_multiple_lockfiles;vexrefuses withpatched_ref_unattributable)bun.lockb+ stray memberbun.lock/bun.lockbvexattests)*.tgz, member*.tgz, member.socket/--checkred)vendor/vendor_artifact_gitignored)bun.lockworkspace with*.tgzRun 32 (Linux, main
9472be4)bun addbun removeof a vendored package →scan --prunevendor --checkgreen)bun.lockb1.1.39 / 1.2.23 / 1.3.9 / 1.4.2, single + workspace, hoisted + isolatedvendor --revert/removedrift-keep; check red)--prune/vendor --revert.bun/<pkg>@<old>afterbun add <pkg>@<new>/bun remove: vendored / hosted / agentscan,apply --check,vexunpinnedrow, agent patches + attests the orphan); hoisted control passes*.tgzignored, fresh clonevendor --checkRun 33 (Linux, main
a845bf9)deniedredirect_bun_missing_sha512), dry run then wetredirect_takeover_kept_vendored; dry run matches wet, writes nothing)vendor --checkgreen; frozen install patched)rollback.socketresidue; text rollback byte-exact to the pre-vendor lock; lockb refuses with the documented checkout remedy)bun addre-saved the vendored tuples digest-lessRun 34 (Linux, main
793edd4)bun remove→scan --prune,vendor --checkbun add minimist@1.2.8(upgrade off the patched version) → prunevendor --checkexit 1; commented)bun.lockbun.lock, BOMbun.lock, BOMpackage.json; hosted + vendoredrollbackandvendor --revertbyte-exact)bun.lockb/ text lock, hostedunpinnedrows, exit 0 (documented, #704)vendor --checkgreen)chattr +ilockfile_write_failed, nothing changed)state.jsonchattr +iscan→apply --check→ reinstall →apply --check→applynot_applied/ 0)apply --checkon a lockfile-only checkoutpackage_not_installed, documented)bun.lockb, vendored dry run vs wetwould_refuse/ refusal, nothing written)bun.lock, vendored dry run vs wet; hosted--jsontop-level errors (#1027) on Bun refusalserror: {code, message})| Run 35 (main
60300b8, after #1008's vendor-driver refactor) | | || Plain vendored → fresh frozen → re-run →
vendor --revertbyte-exact | 1.1.39 / 1.2.23 / 1.3.9 / 1.4.2, text + lockb | pass || Vendored workspace (lockb; text v2), member mirrors deleted → re-run restores,
vendor --check| lockb 1.1.39 / 1.2.23 / 1.3.9 / 1.4.2, text 1.4.2 | pass (text pre-v2 workspaces refuse, documented) || Failed superseding re-vendor (lock
chattr +i) | 1.4.2 text + lockb workspace | pass (lock/ledger unchanged, retry heals); lockb leaves unreferenced U2 member mirrors (non-bug) || Superseding uuid
pending_build(#954 fix) | 1.2.23 lockb ws, 1.4.2 text + lockb plain/ws | pass (vendor_prebuilt_pendingskip, exit 0, lock unchanged) || Hosted pin beside a bundled copy: list / rollback / takeover / revert (#828 twin) | text 1.2.23 / 1.3.9 / 1.4.2 | pass |
| Same on
bun.lockb(one record also bundled) | 1.2.23 / 1.3.9 / 1.4.2 | fail #1243 (1.1.39 pass: no bundled flag) || Vendored package with a bundled duplicate →
vendor --check| 1.2.23 lockb, 1.4.2 text + lockb | fail #1232 (npm issue; Bun matrix commented) || Run 36 (main
3380e28, after #1009 "Fix open bun issues" and #1161) | | || Hosted rollback, private scope in the project
.npmrc(token) | 1.2.23 / 1.4.2 text | pass (byte-exact, credentials sent, original bytes after cold frozen install) || Hosted rollback /
remove, private scope only in~/.npmrcor~/.bunfig.toml| 1.2.23 / 1.3.6 / 1.4.2 text | fail #1276 (public-registry lookup;""+ public integrity or a refusal) || #1116 re-check: vendored lockb workspace,
*.tgzignored | 1.2.23 / 1.4.2 lockb | 1.2.23 fail #1116 (ENOENT), 1.4.2 pass (as the issue says) || Run 37 (main
9ab72d4) | | || #1101 / #861 / #784 / #599 / #735 / #443 / #635 / #371 / #764 re-verification (closed by #1009 / #1161) | 1.2.23 / 1.3.9 / 1.4.2 (text + lockb as applicable) | pass |
| #1034 grammar: name / purl / version-less purl / uuid; two pinned versions;
get pkg:npm/<name>| 1.4.2 text + lockb | pass ||
get <uuid> --mode vendored, lockb workspaces with member mirrors | 1.2.23 / 1.3.9 / 1.4.2 | pass || Vendored A → hosted B → vendored B → revert, workspaces | 1.2.23 / 1.4.2, text + lockb | pass |
| Unicode / space member paths, scoped member, hosted + vendored + unwind | 1.2.23 / 1.4.2 | pass |
| devDependency / optionalDependency pins, frozen
--production/--omit=optional| 1.2.23 / 1.3.9 / 1.4.2 | pass || Warm shared cache across patch / unwind | 1.1.39 / 1.2.23 / 1.3.9 / 1.4.2 | pass |
| Concurrent hosted + hosted / vendored | 1.4.2 text + lockb | pass (
lock_held) |Backlog
Maintainer request (partly covered in runs 3 and 6): global (
-g) mode for hosted patches. Still to do: a non-writable global dir must fail loudly (needs a probe; the sandbox runs as root); Windows 1.1.45/1.2.23 with an ASCII temp path; Bun 1.0.x. Global mode misses every Bun global package when BUN_INSTALL_BIN or BUN_INSTALL_GLOBAL_DIR is set: scan -g reports success with nothing found, get -g / vex -g patch and attest nothing #443 is still open; re-test On Windows,scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 (bun.cmd) on Windows now that Fix global PM probes spawning bare names from the project (#421, #434, #438, #440) #442 has landed. Checklist: the 20261001T040000Z entry.A maintainer needs to delete the probe branches
bughunt/bun/20260930-default-trust,bughunt/bun/20260930-isolated-bunpatch,bughunt/bun/20261001-vex-isolatedandbughunt/bun/20261001-global-dirs. Deletion is still refused from the sandbox (runs 7–26; run 26: blocked by the session permission classifier), so no new probes until then. They still existed in run 31 (run 32 made no new probes).Fix open bun issues (#992, #861, #784, #764, #735, #635, #599, #578, #497, #443, #371) #1009 closures verified on Linux (run 37): Vendored re-run on an isolated-linker bun.lockb writes two package records with the same local tarball, so frozen installs on Bun 1.3.9/1.4.2 fail intermittently with EEXIST #861 (+ fold → revert / supersede), After Bun migrates a vendored bun.lockb to bun.lock (
bun install --save-text-lockfile), vendor --revert and rollback fail, and a superseding re-vendor drops the pre-vendor original so revert exits 0 with the project still vendored #784, After a Bun rollback orvendor --revert, the advisedbun installkeeps the patched bytes installed on the hoisted linker (Bun reports "no changes") #764, Lock inventory ignores a bun.lockb that Bun installs from when bun.lock is a dangling symlink #735, With Bun's globalStore (Bun ≥ 1.3.14), agent mode patches and rolls back every other project sharing the store, and vex attests unpatched transitive copies as not_affected #635, With Bun's isolated linker,vexrefuses every hosted patch as not_applied after the usual in-placebun install, because it checks orphanednode_modules/.bunregistry entries that Bun never removes (regression from #496) #599, Global mode misses every Bun global package when BUN_INSTALL_BIN or BUN_INSTALL_GLOBAL_DIR is set: scan -g reports success with nothing found, get -g / vex -g patch and attest nothing #443, On Bun ≥ 1.3.5, hosted and vendored rewiring drops Bun's default trust, so install scripts of patched packages (better-sqlite3, esbuild, sharp…) are silently blocked #371. Still to do: Bun hosted and vendored modes skip a URL orfile:tarball copy of the patched package without warning, and vendoredvexattests not_affected (the #326 fix covers npm locks only) #497 (github:/ URL tuples) and macOS/Windows for all of them; On Bun ≥ 1.3.5, hosted and vendored rewiring drops Bun's default trust, so install scripts of patched packages (better-sqlite3, esbuild, sharp…) are silently blocked #371 withtrustedDependenciesonly in a member, and a transitive default-trusted package. On Bun 1.4, abun patchmade on a hosted or vendored package is silently dropped by the next superseding re-run, takeover, rollback or revert (the #367 guard only matchesname@versionkeys) #1019: workspace members, Bun 1.4.0-written keys, macOS/Windows; re-test when fixed.Vendored yarn classic exits 0 when .gitignore covers the vendored tarball (
*.tgz,vendor/,.socket/), so the commit drops it and every fresh checkout's install fails #831: verified on Bun 1.4.2 text +bun.lockb(run 28). The workspace cell is now Vendored bun.lockb workspaces write the member-relative tarball mirrors with no .gitignore check, so a*.tgzrule drops them from the commit and fresh frozen installs fail (Bun 1.1.39–1.2.23) or hang (1.3.9) #1116; re-test it when fixed (also on the isolated linker, and with a.gitattributes/ LFS rule).vendor --checkafterbun remove(Fix vendor --check unwired cause and remedy (#900) #970). After a Bun rollback orvendor --revert, the advisedbun installkeeps the patched bytes installed on the hoisted linker (Bun reports "no changes") #764 follow-up: macOS/Windows. Real Windows autocrlf checkouts.Vendored re-run on an isolated-linker bun.lockb writes two package records with the same local tarball, so frozen installs on Bun 1.3.9/1.4.2 fail intermittently with EEXIST #861, Vendored yarn classic exits 0 when .gitignore covers the vendored tarball (
*.tgz,vendor/,.socket/), so the commit drops it and every fresh checkout's install fails #831, After Bun migrates a vendored bun.lockb to bun.lock (bun install --save-text-lockfile), vendor --revert and rollback fail, and a superseding re-vendor drops the pre-vendor original so revert exits 0 with the project still vendored #784, After a Bun rollback orvendor --revert, the advisedbun installkeeps the patched bytes installed on the hoisted linker (Bun reports "no changes") #764, With Bun's globalStore (Bun ≥ 1.3.14), agent mode patches and rolls back every other project sharing the store, and vex attests unpatched transitive copies as not_affected #635, With Bun's isolated linker,vexrefuses every hosted patch as not_applied after the usual in-placebun install, because it checks orphanednode_modules/.bunregistry entries that Bun never removes (regression from #496) #599 and Bun hosted and vendored modes skip a URL orfile:tarball copy of the patched package without warning, and vendoredvexattests not_affected (the #326 fix covers npm locks only) #497: re-test when fixed. Agent-mode apply writes through node_modules links into first-party source (npm workspace members, file: deps, npm link targets), overwriting the user's code, and rollback restores upstream bytes instead #626 on Bun once PR Fix agent mode patching linked first-party source (#626) #634 merges. AlsoglobalStore+ workspaces andglobalStoreon macOS/Windows. (Fix npm store copies missed by agent apply and vex (#601, #603) #605/Fix store-copy fold dropping copy writes (#756, #772) #774 store copies on Bun peer-variant entries: pass, run 21.)macOS/Windows re-runs of the Bun isolated linker: transitive packages under node_modules/.bun are "not installed" in agent mode, and scan --mode agent exits 0 with them unpatched #366 / With Bun's isolated linker,
vexattests a hosted patch as not_affected (verified) while the installed copy under node_modules/.bun is still unpatched (v5 regression) #405 / Bun hosted and vendored rewiring rewritesbundled: truelock entries that Bun never fetches: the bundled copy stays unpatched, scan reports success, and vendoredvexattests not_affected #469 / After Bun 1.4 migrates a hosted workspace bun.lockb to bun.lock,bun install --frozen-lockfilefails and Bun's suggestedbun installsilently drops the hosted pins #803 fixes (Windows isolated uses junctions).Bun hosted and vendored modes skip a URL or
file:tarball copy of the patched package without warning, and vendoredvexattests not_affected (the #326 fix covers npm locks only) #497github:tuples (needs a probe).Hosted rollback on real macOS and Windows checkouts.
Bun 1.4.3 when stable (1.4.3-canary.1 passes, run 27). Hosted Bun rollback/remove writes an empty registry slot that Bun < 1.3.7 resolves against npmjs, so custom-registry projects can't frozen-install after a revert #992: re-test when fixed, including
[install.scopes]andNPM_CONFIG_REGISTRYvariants and the 1.1.45remove/ takeover cells. (Lifecycle scripts and scoped packages with scripts onbun.lockb: pass, run 27.) (Mixed modes,globalStore+ vendored workspace lockb: pass, run 25. Superseding uuids in mixed modes, explicittrustedDependencies,bun pm trust,--filter: pass, run 26.)Digest boundary with a valid substitute tarball, 1.3.9 text lock vs 1.3.10 (low priority, documented limitation).
Hosted and vendored scans from a Bun workspace member with a stray bun.lock / bun.lockb pin that ignored lock, exit 0, and lock-only VEX attests not_affected while Bun installs the unpatched package #1101: verified fixed on Linux (run 37); macOS/Windows untested; the root
bun.lockbvariant is covered (run 31). Hosted scan from a yarn classic workspace member still pins nothing and exits 0 when the root's workspaces use a!pattern (yarn 1 ignores it) or an extglob like packages/@(a|b) #1097 Bun < 1.3 negation: re-test when fixed. On Bun's isolated linker, rollback/remove of a superseded agent record (#934) drops the record and its blobs while the orphanednode_modules/.bun/<pkg>@<ver>copy still holds the agent patch, and the advisedbun installrelinks it #1084: a workspace (isolated by default on Bun ≥ 1.3), macOS/Windows; re-test when fixed. (Symlinkedbun.lockbvendored dry vs wet: pass, run 34.)After
npm install <pkg>@<other version>moves a vendored npm package off its patched version,scan --prune,vendor --revert,removeandrollbackall drift-keep it, sovendor --checkstays red and every remedy it names loops #1155 / draft Fix vendored npm/Bun revert treating an upgrade as drift (#1155) #1187: re-test the Bun text-lock upgrade loop when it merges (lockb already passes, run 34).apply --checkwithglobalStore(With Bun's globalStore (Bun ≥ 1.3.14), agent mode patches and rolls back every other project sharing the store, and vex attests unpatched transitive copies as not_affected #635 shape). Hostedredirect.patches[]rows onbun.lockbworkspaces and the Hosted and vendored scans from a Bun workspace member with a stray bun.lock / bun.lockb pin that ignored lock, exit 0, and lock-only VEX attests not_affected while Bun installs the unpatched package #1101 shape.Hosted Bun rollback/remove ignores a private scope set in ~/.npmrc or ~/.bunfig.toml: it looks the package up on the public registry, then fails or writes a "" slot with the public package's integrity (#992 fix reads only the project's files) #1276: re-test when PR Fix Bun restore ignoring user registry config (#1276) #1283 merges (also the
bun.lockbtakeover restore, which sharesBunRegistrySettings,NPM_CONFIG_USERCONFIG,$XDG_CONFIG_HOME/.bunfig.toml, and a mirrorregistry=in~/.npmrcon Bun ≤ 1.3.6). Hosted pin on a bun.lockb record that Bun shares with a bundled copy can't be unwound: list errors, and the vendored takeover fails (#1008's #828 fix covers the text bun.lock only) #1243: re-test when PR Fix bun.lockb shared bundled pin being unmanageable (#1243) #1247 merges (alsoremove,vendor --revertafter the takeover, and a lockb workspace). vendor --check fails a vendored npm package that has a bundled duplicate with "wiring missing: no lockfile or config references …", although the lock does reference it, and itssocket-patch vendorremedy is a no-op #1232 on Bun when fixed. Vendored bun.lockb workspaces write the member-relative tarball mirrors with no .gitignore check, so a*.tgzrule drops them from the commit and fresh frozen installs fail (Bun 1.1.39–1.2.23) or hang (1.3.9) #1116 still reproduces on60300b8(run 35).More Fix open npm issues #1008-refactor regression cells: vendored
bun patched packages through the new driver,get <uuid> --mode vendoredon lockb workspaces, and the Vendored npm refusal for a symlinked package-lock.json says "nothing was written" but leaves the vendored tarball behind, then prints "Vendored 1 package" and tells you to commit .socket/vendor/ #898 redownloaded-artifact refusal on Bun.Make the vendored-to-hosted takeover atomic #1039 takeover follow-ups still open: takeover with
globalStore, and takeovers in workspaces with member mirrors under a superseding uuid. (Superseding uuid and multi-lock write-failure atomicity: pass, run 34.)Known non-bugs
rollback/removewith aCVE-…/GHSA-…target exitpatch_not_found: by design, records carry no advisory index (utils/target.rs:231), andname@versionisn't in the v5 target grammar (run 37).Mock fixture (run 37):
GET …/by-package/pkg:npm/<name>(no version) must return every version's patch, orget pkg:npm/<name>readsnot_found.A
bun.locksymlink loop besidebun.lockb: Bun itself can't install, hosted exitssuccesswith 0 redirected, vendoredpartial_failure. Nothing is claimed, so not filed (run 37).A hosted Bun restore whose project registry 404s the version document (
GET <reg>/<name>/<version>) falls back to the default registry's document with theupstream_registry_fallbackwarning and keeps the project's tarball URL. That's documented (CLI_CONTRACT,upstream_registry_fallback), even though a same-name public package then supplies the integrity. Mock fixture (run 36): serve the version document on private-registry routes too.Mock fixture (run 36):
pkill -f/pgrep -fwith the mock's command line also matches the calling shell. Start the mock from a script and kill it by pid file.A failed vendored commit (
chattr +ionbun.lockb) during a superseding re-vendor of a lockb workspace removes the new root uuid dir but leaves the new uuid's member mirrors (packages/*/.socket/vendor/npm/<U2>/). The lock and ledger are unchanged, and the retry reuses them. Inert, root-only fault injection, the same class as run 34's (run 35).Fixture (run 35): building a superseding artifact from the installed tree after a vendored
bun installdouble-patches it (does not carry the patched files at their recorded paths). Build every artifact from the pristine copy.An undeletable vendored artifact (
chattr +i) during a vendored → hosted takeover: the commit succeeds and the artifact dir stays behind with no warning. Inert, like the SIGKILL-after-commit case below; root-only fault injection, not filed (run 34).apply --checkafter an in-placebun add <pkg>@<other>on the isolated linker reports the orphaned.bun/<pkg>@<old>store entry asalready_patched(exit 0). The orphan shape is With Bun's isolated linker,vexrefuses every hosted patch as not_applied after the usual in-placebun install, because it checks orphanednode_modules/.bunregistry entries that Bun never removes (regression from #496) #599's; no security impact (the old version is no longer linked) (run 34).Mock fixture (run 34): build hosted tarballs with a fixed gzip mtime, or a restarted mock serves new sha512s and a re-run looks like it rewrites every pin. Hosted URLs must follow
/patch/npm/<name>/<ver>/<token>/<uuid>/<file>.tgzon theSOCKET_PATCH_SERVER_URLorigin, orvex/rollbackfind no hosted pins.A SIGKILL between the Make the vendored-to-hosted takeover atomic #1039 takeover's journaled commit and its deferred artifact deletions leaves
.socket/vendor/npm/<uuid>/dirs and Bun member mirrors that nothing references. The lock and ledger are consistent, the re-run doesn't delete them, andvendor --check/repair/ a later re-vendor all ignore or reuse them. Inert, crash-only and generic, so not filed (run 33).get <B> --mode agenton a package vendored at A records B in the manifest and overwrites the installed (A-patched) copy with B's full content (non-strict "did not match … applied the full verified patched content"). It warns that the vendoring is still at A, andvexattests A only. Documented; use--strict(run 31).Mock fixture (run 31): the grant must return
sha512--prefixed integrity and a tarball URL on the mock's own origin. Bare base64 lands inbun.lockas-is (Bun warns "malformed integrity"), and the bakedpatch.socket.devhost is unreachable. Never name a shell loop variableM, because it clobbers the mock URL.A hosted
scanfrom a hoisted workspace member (no membernode_modules) reportssuccesswithscannedPackages: 0and no refusal, because there are no candidates to gate. It claims nothing, and npm behaves the same;get <uuid>from the same member is refused. Not filed (run 30).A refused wet vendored run on a symlinked
bun.lockleaves unreferenced.socket/vendor/npm/<uuid>/artifacts. That's documented (CLI_CONTRACTredirect_symlinked_file_unsupported: "the artifacts written are unreferenced orphans") (run 30).Mock fixture: a mode-less
scanis hosted by default and re-pins, so don't use it as a read-only check after a rollback. Use--dry-runorlist. Also,pkill -f <pattern>kills the calling shell when the pattern is in its own command line, so toggle the mock through an HTTP endpoint instead (run 29).scan_vendor_referencesreadsbun.lockbnatively only when there's nobun.lockbeside it, which matches Bun ≥ 1.2 (it readsbun.lockfirst). Not a bug (run 29).Vendored
scan --dry-runpreviews abun patched package (patchedDependenciesname@version) aswould_vendor, while the wet run refuses itvendor_lock_entry_unsupported(exit 1). That's documented scope:would_refusepredicts only the Bun preflight lock codes (CLI_CONTRACTwould_refuserow;scan/vendor_flow.rs:80"outside the preflights are not predicted"). Run 28.Bun 1.2.23 / 1.3.9
bun patch --commitcrashes (SIGILL) on a package resolved to a URL tarball. That's a Bun bug. Bun 1.4.2 works and keys the patch by the URL (On Bun 1.4, abun patchmade on a hosted or vendored package is silently dropped by the next superseding re-run, takeover, rollback or revert (the #367 guard only matchesname@versionkeys) #1019).Mock fixture: decode by-package purls twice (
%2540for scoped names), or scoped patches look unpatched.A registry document with only a sha1
shasumand nointegritymakes the hosted text-lock restore refuse withthe registry records no integrityand the checkout remedy (fail closed, generic npm-family code). npmjs has backfilledintegrityon old versions (minimist 0.0.8, left-pad 0.0.3, qs 0.6.6, lodash 1.0.0 all checked), so it's only reachable on bare private registries. Not filed (run 27).Lifecycle
preparedoesn't run for registry or tarball dependencies, on any Bun version, with or without socket-patch.patches-api.socket.devis blocked by the sandbox proxy. Mock the API. Also, the CLI's reqwest can't reachregistry.npmjs.orgfrom the sandbox (curl can), so hosted rollback/remove needSOCKET_NPM_REGISTRYpointed at a local passthrough. Without it you getcannot restore … error sending request, which is a sandbox artifact.Agent
rollback→missing_blobwhen the mock serves no before-blob (fixture limit).v5
rollbackremoves the rolled-back entries from.socket/manifest.json, so a laterapplyis a success no-op (CLI_CONTRACTrollbackrow).Hosted
bun.lockbpins:rollback/removerefuse with thegit checkout -- bun.lockbremedy (documented). After a hosted → vendored →vendor --revertround trip,bun.lockbis semantically identical (samebun pm hashand yarn dump) but not byte-identical: its string buffer keeps the dead URLs. The doc promises a byte-exact registry record, not the whole file.Bun 1.2.23 workspaces default to the hoisted layout (isolated only via
linker = "isolated"). From Bun 1.3.x a fresh workspace lock defaults to isolated.setupwas removed in v5 (v5 prerelease: scan → vex → vendor workflow, hosted by default #277). The run-1setuppass is obsolete.esbuild after rewiring is listed by
bun pm untrustedbut has no observable effect. Use better-sqlite3 to observe On Bun ≥ 1.3.5, hosted and vendored rewiring drops Bun's default trust, so install scripts of patched packages (better-sqlite3, esbuild, sharp…) are silently blocked #371.Documented refusals (docs/testing/bun-compatibility.md): a version-0 workspace lock in hosted mode (
redirect_bun_workspace_unsupported), a pre-v2 workspace lock in vendored mode (vendor_bun_workspace_unsupported), and missing digest enforcement for text-lock URL/local tuples on Bun < 1.3.10.Agent-mode npm aliases under Bun are npm agent-mode apply never patches an npm-aliased install (lp@npm:left-pad), yet VEX attests the package not_affected #356 (npm-owned).
--global-prefixmust name thenode_modulesdir itself (~/.bun/install/global/node_modules). Its parent scans 0 packages; the flag is documented as the packages root.-gcombined with--mode hostedis a clap-level conflict: plain-text error, exit 2, no JSON envelope even with--json. Consistent with other usage errors.Vendored
scan --dry-runexits 0 withstatus: successandwould_refusewhile the real run exits 1 withpartial_failure, for the same Bun preflight refusal. Documented (CLI_CONTRACTwould_refuse).Vendored
vexattests from the committed artifact even when the installed tree is stale. By design: only avendored_tree_out_of_syncwarning is owed.Hosted default
vexon a bundled-copy project correctly refuses (not_applied). Bun hosted and vendored rewiring rewritesbundled: truelock entries that Bun never fetches: the bundled copy stays unpatched, scan reports success, and vendoredvexattests not_affected #469 is about vendored mode and--no-verify.bun pm bin -gignores a project-localbunfig.toml, soscan -ginside a project can't be redirected by the project.Vendored, then
bun add, on Bun < 1.3.10 re-saves the local tuples withoutsha512. That's documented ("Digest-less re-saves"): the vendored re-run reportsalready_vendoredand re-pins the digest.Bun records
""as the registry field of a tuple even when it came from an[install.scopes]or custom default registry, so rollback restoring""is correct.On a
bun install --yarnproject, hostedrollbackrestoresbun.lockbyte-exact but adds a#<sha1>fragment to Bun'syarn.lockresolvedlines. It's semantically equivalent and yarn-classic's rewriter, so it isn't filed as a Bun bug.Mock fixture: build the patched tarball with a fixed gzip mtime. Otherwise a mock restart changes its sha512 and later installs fail
IntegrityCheckFailed.link:deps needbun linkregistration, andgithub:deps don't resolve in the sandbox. Both are environment limits.scan <workspace-member>(e.g.scan packages/a) with vendored refusingvendor_lockfile_missingis pinned behaviour. The hosted side (success, 0 redirected) is NOT a non-bug any more: since run 21 it's tracked on Hosted scan/get run from a yarn classic workspace member still reports success while pinning nothing: the #598 governing-root refusal covers pnpm and cargo only #884 (the isolated-workspace Bun matrix is commented there).Mode-less
scan -gis report-only. Use--mode agentto patch global copies.-gagent runs record the global copies in the cwd's.socket/manifest.json(by design).A v1/v2 text
bun.lockcan't be read by Bun 1.1.45 (lockfile had changes, but lockfile is frozen) even without socket-patch. Whenbun.lockandbun.lockbare both present, Bun ≥ 1.2 readsbun.lock.Mock fixture:
SOCKET_PATCH_SERVER_URLmust name the same origin across runs. A mock on another port makes the earlier pins non-hosted.A hosted scan at a repo root that is itself a Bun project crawls nested independent projects'
node_modulesand warnsredirect_bun_entry_not_foundfor their packages (exit 0). They have their own locks: scan them by PATH (scan '*/*' --mode hosted).Mock fixture: agent mode needs a
blob/<hash>route. Without it the result ispartial_failure.Vendored scan on a Bun 1.3.x workspace (lockfileVersion 1) refuses
vendor_bun_workspace_unsupported. That's the documented pre-v2 workspace limitation, and the lock is untouched.vexexit 2product_undetectedin a fixture without a package version or git origin: pass--product(fixture limit).Bun never prunes
node_modules/.bunentries: after a dependency is removed, its store dir (and, on 1.4.2, the member link) stays. That's Bun behaviour. It only matters to socket-patch through With Bun's isolated linker,vexrefuses every hosted patch as not_applied after the usual in-placebun install, because it checks orphanednode_modules/.bunregistry entries that Bun never removes (regression from #496) #599.Agent
applyon a workspace whose member links into an isolated store reports a duplicatealready_patchedskip per member-linked package (counts only, the bytes are right). pnpm behaves the same, so it's handed to pnpm (entries/pnpm/20261002T193154Z-from-bun.md).scan -gwithBUN_INSTALL_GLOBAL_DIRset reports the Node global prefix's packages, not Bun's. That's Global mode misses every Bun global package when BUN_INSTALL_BIN or BUN_INSTALL_GLOBAL_DIR is set: scan -g reports success with nothing found, get -g / vex -g patch and attest nothing #443, not a new bug.Hosted
vexattests darwin-only packages (fsevents, @esbuild/darwin-*) on a Linux checkout where they're not installed: the lock pins patched bytes for every platform, so that's correct.Mock fixture: in proxy mode set both
SOCKET_PROXY_URLandSOCKET_PATCH_SERVER_URL. Without the latter, hosted pins aren't recognized andvexreportsmanifest_not_found.Bun's auto-migration of a hosted
package-lock.jsonwritesbun.lockregistry 4-tuples with the hosted URL in the registry slot (["left-pad@1.3.0", "http://…/tok/<uuid>/left-pad-1.3.0.tgz", {}, "sha512-…"]). Bun installs the patched bytes from them. socket-patch fails closed on that shape (vex→patched_ref_unattributable/manifest_not_found,list/rollback→hosted_wiring_contested, no writes), and a re-run ofscan --mode hostedheals it into the canonical URL tuple. No false attestation, so not filed (run 11). Thevexdetail wording ("from elsewhere (not a Socket patch)") is inaccurate for this shape.bun updatere-resolves hosted pins back to the registry. That's Bun behaviour, andvexcorrectly stops attesting.A 1.4.2-written
bun.lockbcan't be read by Bun 1.1.45 even without socket-patch.Bun's auto-migration of a hosted
yarn.lockwrites the same registry-slot 4-tuples as thepackage-lock.jsoncase, plus a#<sha1>fragment. socket-patch fails closed, and a re-run ofscan --mode hostedheals it (run 12).Bun's auto-migration of a hosted
pnpm-lock.yaml(1.3.14, 1.4.2) ignoresresolution.tarball, downloads the registry tarball and failsIntegrityCheckFailedagainst the patched sha512, writing nobun.lock. That's a Bun migration limitation and fails closed. Remedy: migrate first, then runscan --mode hosted.get <pkg> --mode hostedfrom inside a workspace member dir is asuccessno-op withredirect_npm_no_lockfile, the same asscan <member>: tracked on Hosted scan/get run from a yarn classic workspace member still reports success while pinning nothing: the #598 governing-root refusal covers pnpm and cargo only #884 since run 21. Run it from the root.A SIGKILLed
vendor --revertcan leave a 0-byte.socket/vendor/.socket-stage-state.json-<uuid>temp file. It's harmless; the next run heals the state.Plain (human)
scan --mode agentdoesn't re-apply patches the manifest already records ([skip] … already recorded, "runsocket-patch apply"), while--jsonre-applies. It's generic, not Bun-specific: handed to npm (entries/npm/20261003T193043Z-from-bun.md). After an interrupted agent apply, usesocket-patch apply.scan --jsonapply.patches[].action(added/skipped) is the manifest record's state, not whether files were written.repairdoesn't recreate a deletedsocket-patch.vendor.jsonsidecar. It's informational only (CLI_CONTRACT). A deleted.socket/vendor/state.json→repairvendor_ledger_missing(documented v5: restore it from VCS).An interrupted vendored → hosted takeover can leave registry tuples (unpatched install) until the re-run.
vexdoesn't attest them, and the re-run heals.Hosted rollback on a lock whose registry slot holds a full custom-registry tarball URL (Bun writes one for a non-default
[install] registry) restores"". It's pinned by thecustom-registryshape inbacktest-bun.py, and the restored lock frozen-installs from the configured registry (run 14). The same holds after a vendored → hosted → vendored chain:vendor --revertrestores""for any entry that passed through hosted mode, and full URLs for entries that were only ever vendored (run 26). Correction (run 27): that's only true on Bun ≥ 1.3.7. Bun 1.1.39–1.3.6 resolve""against npmjs, which is Hosted Bun rollback/remove writes an empty registry slot that Bun < 1.3.7 resolves against npmjs, so custom-registry projects can't frozen-install after a revert #992.Bun resolves a dependency on
X@2.0.0+build.6to an installedX@2.0.0+build.5, because semver ignores build metadata. That's Bun behaviour.Bun copies
file:directory deps intonode_modules, so agent mode patches the copy, not the source. That's safe and not part of Agent-mode apply writes through node_modules links into first-party source (npm workspace members, file: deps, npm link targets), overwriting the user's code, and rollback restores upstream bytes instead #626.Mock fixture: serve the npm registry from a different origin than
SOCKET_PATCH_SERVER_URL. Otherwise the registry URLs Bun writes intobun.lockblook like hosted pins, and vendoredrollbackfailshosted_wiring_contested(run 15; with split origins it'ssuccess).The
bun.lockblegacy (link://) meta-hash dialect isn't produced by any writer in range (≥ 1.1.39); numeric prerelease ordering in the current dialect matches Bun (run 15).A plain
bun installwith only abun.lockbkeeps the binary lock on 1.2.23 / 1.3.14 / 1.4.2. Only--save-text-lockfilemigrates it (run 16).Release 4.0.0 refuses
scan --mode vendoredon abun.lockb(exit 1), so it isn't a baseline for vendored-lockb cells (run 16).A path literal (
"m1": "packages/m1") in a textbun.lockwith only registry tuples frozen-installs on 1.3.14 and 1.4.2. Only together with URL/local pins does 1.4.2 re-resolve, which is After Bun 1.4 migrates a hosted workspace bun.lockb to bun.lock,bun install --frozen-lockfilefails and Bun's suggestedbun installsilently drops the hosted pins #803 (run 17).bun add <pkg>run inside a workspace member re-resolves that member's dependencies and drops its hosted pins back to registry tuples, on text v1/v2 andbun.lockb(1.2.23 / 1.3.14 / 1.4.2). A root-levelbun addkeeps them. That's Bun behaviour, likebun update: a re-run ofscan --mode hostedheals it, andvexdoesn't attest the dropped pin (run 18).A lockfile-only hosted re-run can't see existing pins (Bun lockfile-only checkouts can't see hosted pins: hosted re-runs never pick up a superseding patch and
scan --mode vendoredskips the takeover, both reporting success with 0 packages #720), somaxNewPatchesneither counts nor defers them, and nothing is unwired (run 18).After
vendor --revertin acore.autocrlf=trueclone, the restored registry line inbun.lockis LF inside an otherwise CRLF working copy. Git normalizes it on commit (byte-exact to the pre-vendor commit) and Bun reads it, so it's cosmetic. Hostedrollbackkeeps CRLF on every line (run 19).Mock fixture:
pkill -f mock.pyalso matches the calling shell, whose command line contains the heredoc. Kill the mock by pidfile.Vendored
bun.lockbworkspaces commit an identical tarball under every member's.socket/vendor, even members that don't use the package. That's deliberate (Bun 0.5.9–1.3 resolves workspace local tarballs relative to the declaring member,bun_binary.rs:142). A missing member copy fails closed (vendor_workspace_artifact_missing), andrepairrestores it (run 20).Bun refuses a workspace member that depends on the root package via
workspace:*(root@workspace:* failed to resolve), so that After Bun 1.4 migrates a hosted workspace bun.lockb to bun.lock,bun install --frozen-lockfilefails and Bun's suggestedbun installsilently drops the hosted pins #803-heal shape can't occur (run 20).Bun 1.3.9 can't frozen-install a text
bun.lockwritten by 1.4.2 (lockfile had changes). That's cross-version Bun behaviour.get <name> --mode hostedwith several installed versions (e.g.ms@2.0.0nested +ms@2.1.3direct) acts on only one: the package-name path searches just the best fuzzy match among installed purls, by design (get.rs:2844), and names it on stderr. It isn't Bun-specific. Usescanor a purl (run 22).Fixture: git-ignore
node_modulesbefore committing, or "fresh" clones aren't empty (run 22).bun install --save-text-lockfileon 1.4.2 deletesbun.lockb;bun bun.lockbprints the ACTIVE lock (the text one when both exist). Inspect a stale binary withstrings(run 21).vexexit 2manifest_not_found("nothing to attest") after every patch is rolled back or reverted is correct (run 25).get --mode agenton an already-vendored package doesn't take it over: the manifest and the vendored ledger coexist, and a scopedrollbackunwinds both (run 25).All reactions