Fix vlt e2e legs failing when api.socket.dev blips - #448
Merged
Mikola Lysenko (mikolalysenko) merged 1 commit intoOct 1, 2026
Merged
Mikola Lysenko (mikolalysenko) merged 1 commit into
Mikola Lysenko (mikolalysenko) merged 1 commit into
Conversation
From 1.0.0-rc.24 `vlt ci` defaults --allow-scripts to `:scripts:not(:malware)`. The `:malware` selector makes vlt POST every newly installed node to api.socket.dev, so the real-vlt e2e legs depended on that API answering 2xx. A 401 from it at 03:05 UTC on 2026-10-01 failed 15 vlt matrix jobs in one CI run, and with the API unreachable 59 legs across the five vlt suites fail on vlt 1.2.0. Pass the same query minus the network filter (`:scripts`) on every harness `vlt ci` for releases that have the default. The harness's packages carry no malware alerts, so the set of packages allowed to run scripts is unchanged; an explicit --allow-scripts is kept. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ghbvY52iuzejTo4knpDvq
Collaborator
Author
|
bugbot run Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 3a3c625. Configure here.
Collaborator
Author
|
[burn-down agent] Ready for review on
Note: Slack announcement could not be sent this run (no Slack send tool available in the agent session); next run will retry. Generated by Claude Code |
Wenxin Jiang (Wenxin-Jiang)
approved these changes
Oct 1, 2026
Mikola Lysenko (mikolalysenko)
deleted the
ci-janitor/vlt-ci-hermetic-allow-scripts
branch
October 1, 2026 16:50
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The real-vlt e2e legs depend on
api.socket.devreturning 2xx. When it doesn't, whole matrix rows go red with:Evidence: CI run 36808399029 (PR #365, merged with current main
2463257) had 15 vlte2ejobs fail in one go around 03:05–03:06 UTC on 2026-10-01:e2e_vlt,e2e_redirect_vlt_build,e2e_vendor_vlt_buildandmode_migration_vlton vlt 1.0.4, 1.0.7, 1.1.1 and 1.2.0, on ubuntu, macOS and Windows (e.g. job 110199311052:vlt_pinned_matrix_agent_reruns_and_vexand..._persistence_reverted_by_reinstall,1.2.0 vlt ci failed). None of those failures had anything to do with the PR. It was one incident, but the same dependency is in every vltcicall the harness makes, so the next API blip or rate limit will fail them all again. It also stops the suites from running offline or behind a proxy.Root cause
From 1.0.0-rc.24
vlt cidefaults--allow-scriptsto:scripts:not(:malware)(rc.12–rc.23:*;vlt installdefaults to:not(*)). I checked this in the published tarballs for rc.23, rc.24, rc.26, rc.28, rc.30, rc.31, rc.32, 1.0.4, 1.0.7, 1.1.1 and 1.2.0. When the query has a security selector,reifycallsSecurityArchive.start, which POSTs every newly added node tohttps://api.socket.dev/v0/purl?alerts=trueusing vlt's public token. Any non-2xx reply throws, andvlt ciexits 1. Packages served by the harness's local registry count as "npm" packages becauseregistries.npmpoints at that registry, so they are sent to the API too.Fix
Leg::vlt_withis the one place every harnessvltcall goes through. For vlt ≥ rc.24 it now adds--allow-scripts :scriptstovlt ci. That is vlt's own default without the:not(:malware)filter. The harness's packages have no malware alerts, so the set of packages allowed to run scripts stays the same and the API call goes away. An explicit--allow-scriptsset by a test is left as is. Older releases andvlt installare untouched. A harness self-test (vlt_e2e_harness_ci_never_queries_the_socket_api) pins the version boundary and the pass-through cases.This is a root-cause hermeticity fix: no retries, no raised timeouts, no ignored tests.
Proof
I reproduced it locally with vlt 1.2.0, using a sandbox where
api.socket.devreturns 403, the same failure class as the 401:--include-ignored vlt_pinned_matrix, vlt 1.2.0)e2e_vlte2e_redirect_vlt_builde2e_vendor_vlt_buildmode_migration_vlte2e_safety_vltEvery failure on main was
Failed to fetch security data(138 occurrences). With the fix there were none.I also ran
e2e_vltandmode_migration_vltwith the fix on vlt 1.0.0-rc.24, 1.0.0-rc.32, 1.0.4 and 1.1.1: all pass (9/9 and 14/14 each), so every pinned release in range accepts the flag. On this PR's CI, every vlte2erow (0.0.0-16 through 1.2.0, ubuntu/macOS/Windows) and the rest of CI passed.rustfmt --checkis clean on the touched file.cargo clippy -p socket-patch-cli --test e2e_vlt --test mode_migration_vlt --test e2e_safety_vlt --test e2e_redirect_vlt_build -- -D warningsis clean. Clippy one2e_vendor_vlt_buildhas 7needless_borrowerrors, all intests/prebuilt_common/mod.rsand already on main. CI's clippy job doesn't lint tests, so they are left alone here.Where tests run
Nothing was removed or moved. Job names and required checks are unchanged.
🤖 Generated with Claude Code
https://claude.ai/code/session_018ghbvY52iuzejTo4knpDvq
Generated by Claude Code