You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
With Bun's globalStore (Bun ≥ 1.3.14), agent mode patches and rolls back every other project sharing the store, and vex attests unpatched transitive copies as not_affected #635
[agent] Found by the scheduled Bun bug-hunt routine (ledger #306).
Summary
Bun 1.3.14 added a machine-wide store for the isolated linker: [install] globalStore = true in bunfig.toml, or BUN_INSTALL_GLOBAL_STORE=1. With it on, each node_modules/.bun/<name>@<version> entry is a symlink into <BUN_INSTALL_CACHE_DIR>/links/<name>@<version>-<hash>/, and every project on the machine links to the same directory. socket-patch doesn't recognize this store, and that has two effects:
Patching one project silently changes the code other projects run, and rolling it back silently removes patches other projects depend on. Nothing in the envelope mentions it (status: success).
False VEX: a hosted project attests not_affected for a transitive package that is installed unpatched.
Agent mode silently skips every transitive dependency of a globalStore project.
Repro (Linux, real Bun, local patch-API mock)
The mock serves the public-proxy routes (/patch/batch, by-package, view with blob contents, blob, /patch/package, the tarball route). Each patch prepends /* SOCKET-PATCHED */ to index.js. SOCKET_PROXY_URL and SOCKET_PATCH_SERVER_URL point at it.
globalStore=true : partialFailure [('pkg:npm/is-number@6.0.0', 'verified'), ('pkg:npm/left-pad@1.3.0', 'not_applied')] <- is-number is still unpatched
globalStore=false: error [('pkg:npm/is-number@6.0.0', 'not_applied'), ('pkg:npm/left-pad@1.3.0', 'not_applied')]
After a fresh frozen install, overwriting the store copy of the patched is-number with the original bytes still gives verified for it, so vex never reads those copies.
Actual: Bun's global store is patched and unpatched in place with success. Transitive entries are package_not_installed, and hosted vex attests an unpatched copy as not_affected.
OS × version (Linux sandbox; 2+ runs each)
OS
Bun
config
agent: cross-project apply/rollback
agent: transitive skipped
hosted vex on unpatched transitive
Linux
1.4.2
bunfig globalStore = true
fail
fail
fail (verified)
Linux
1.4.2
BUN_INSTALL_GLOBAL_STORE=1
fail
fail
untested
Linux
1.3.14
bunfig / env
fail / fail
fail
fail (verified)
Linux
1.3.13
bunfig globalStore = true (key not supported, so ignored)
pass
pass
n/a
Linux
1.4.2 / 1.3.14
globalStore = false
pass
pass
pass (not_applied)
macOS / Windows
—
—
untested (probe branches currently blocked)
First bad Bun release: 1.3.14, the first build with globalStore / BUN_INSTALL_GLOBAL_STORE (absent from 1.3.13 and earlier). This isn't a socket-patch regression. It's a Bun layout socket-patch has never handled.
Suspect code
crates/socket-patch-core/src/patch/shared_store.rs:122 (shared_store_of_blocking) recognizes only <store>/v<N>/links (pnpm) and PDM's packages/<stem>/lib. Bun's <cache>/links/<name>@<ver>-<hash>/node_modules/<name> (with the cache's <name>@<ver>@@@1 / *.npm entries beside links) has no SharedStoreKind.
crates/socket-patch-core/src/crawlers/npm_crawler.rs:2143 (list_pnpm_shaped_store_entries_sync) filters .bun entries by file_type().is_dir(), which is false for a symlink. So every globalStore entry is dropped from the crawl, and vex/verify.rs never sees those copies.
[agent] Found by the scheduled Bun bug-hunt routine (ledger #306).
Summary
Bun 1.3.14 added a machine-wide store for the isolated linker:
[install] globalStore = trueinbunfig.toml, orBUN_INSTALL_GLOBAL_STORE=1. With it on, eachnode_modules/.bun/<name>@<version>entry is a symlink into<BUN_INSTALL_CACHE_DIR>/links/<name>@<version>-<hash>/, and every project on the machine links to the same directory. socket-patch doesn't recognize this store, and that has two effects:scan --mode agent/applyfollowsnode_modules/<dep>into<cache>/links/…and rewrites the file there. Every other project using that store is then patched, including ones that never ran socket-patch.rollbackin one project silently unpatches all of them, including projects that recorded the patch in their own.socket/manifest.json. That project'svexthen fails withnot_applied. Fix agent apply writing into shared package stores (#332, #361) #486 (Agent mode writes the patch into PDM's shared install cache when PDM 2.0–2.12 installs packages as directory symlinks (install.cache + symlink) #332, Agent-mode apply and rollback on a pnpm project with enableGlobalVirtualStore patch (and unpatch) every other project that shares the store #361) added exactly this guard for pnpm's global virtual store and PDM's cache, butpatch/shared_store.rsonly knows those two layouts..bunstore walk keeps only real directories, so it skips every symlinked entry. Agent mode reports a transitive dependency aspackage_not_installed, leaves it unpatched, and still exits 0. Worse, hostedvexnever looks at the installed copy: right afterscan --mode hosted(before reinstalling), it attests an unpatched transitiveis-numberasverified/not_affected. WithglobalStore = falsethe same tree correctly givesnot_applied. This is the Bun isolated linker: transitive packages under node_modules/.bun are "not installed" in agent mode, and scan --mode agent exits 0 with them unpatched #366 / With Bun's isolated linker,vexattests a hosted patch as not_affected (verified) while the installed copy under node_modules/.bun is still unpatched (v5 regression) #405 failure, brought back by the global store.Impact
status: success).not_affectedfor a transitive package that is installed unpatched.Repro (Linux, real Bun, local patch-API mock)
The mock serves the public-proxy routes (
/patch/batch,by-package,viewwith blob contents,blob,/patch/package, the tarball route). Each patch prepends/* SOCKET-PATCHED */toindex.js.SOCKET_PROXY_URLandSOCKET_PATCH_SERVER_URLpoint at it.Output on main
045d7ec, Bun 1.4.2 (bunfig):Hosted false attestation (one project,
linker = "isolated",globalStore = true, depsleft-pad@1.3.0+is-odd@3.0.1):After a fresh frozen install, overwriting the store copy of the patched
is-numberwith the original bytes still givesverifiedfor it, sovexnever reads those copies.Expected vs actual
patch/shared_store.rssay agent apply/rollback refuse a package whose real location is a store shared by other projects, with an error naming the store and how to get a private copy. That's the Agent-mode apply and rollback on a pnpm project with enableGlobalVirtualStore patch (and unpatch) every other project that shares the store #361 behaviour for pnpm'senableGlobalVirtualStore.vexshould only attest a patch when every installed copy is patched (With Bun's isolated linker,vexattests a hosted patch as not_affected (verified) while the installed copy under node_modules/.bun is still unpatched (v5 regression) #405, Fix agent vex checking only one installed copy (#516) #517).success. Transitive entries arepackage_not_installed, and hostedvexattests an unpatched copy asnot_affected.OS × version (Linux sandbox; 2+ runs each)
vexon unpatched transitiveglobalStore = trueBUN_INSTALL_GLOBAL_STORE=1globalStore = true(key not supported, so ignored)globalStore = falsenot_applied)First bad Bun release: 1.3.14, the first build with
globalStore/BUN_INSTALL_GLOBAL_STORE(absent from 1.3.13 and earlier). This isn't a socket-patch regression. It's a Bun layout socket-patch has never handled.Suspect code
crates/socket-patch-core/src/patch/shared_store.rs:122(shared_store_of_blocking) recognizes only<store>/v<N>/links(pnpm) and PDM'spackages/<stem>/lib. Bun's<cache>/links/<name>@<ver>-<hash>/node_modules/<name>(with the cache's<name>@<ver>@@@1/*.npmentries besidelinks) has noSharedStoreKind.crates/socket-patch-core/src/crawlers/npm_crawler.rs:2143(list_pnpm_shaped_store_entries_sync) filters.bunentries byfile_type().is_dir(), which is false for a symlink. So every globalStore entry is dropped from the crawl, andvex/verify.rsnever sees those copies.