Skip to content

Fix vlt e2e legs failing when api.socket.dev blips - #448

Merged
Mikola Lysenko (mikolalysenko) merged 1 commit into
mainfrom
ci-janitor/vlt-ci-hermetic-allow-scripts
Oct 1, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 1 commit into
mainfrom
ci-janitor/vlt-ci-hermetic-allow-scripts

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

The real-vlt e2e legs depend on api.socket.dev returning 2xx. When it doesn't, whole matrix rows go red with:

Error: Failed to fetch security data
  at #retrieveRemoteData (vlt/chunk-FOJCK57G.js:471:13)
  ...
  [cause]: { response: Response { status: 401, statusText: 'Unauthorized',
             url: 'https://api.socket.dev/v0/purl?alerts=true' } }

Evidence: CI run 36808399029 (PR #365, merged with current main 2463257) had 15 vlt e2e jobs fail in one go around 03:05–03:06 UTC on 2026-10-01: e2e_vlt, e2e_redirect_vlt_build, e2e_vendor_vlt_build and mode_migration_vlt on vlt 1.0.4, 1.0.7, 1.1.1 and 1.2.0, on ubuntu, macOS and Windows (e.g. job 110199311052: vlt_pinned_matrix_agent_reruns_and_vex and ..._persistence_reverted_by_reinstall, 1.2.0 vlt ci failed). None of those failures had anything to do with the PR. It was one incident, but the same dependency is in every vlt ci call the harness makes, so the next API blip or rate limit will fail them all again. It also stops the suites from running offline or behind a proxy.

Root cause

From 1.0.0-rc.24 vlt ci defaults --allow-scripts to :scripts:not(:malware) (rc.12–rc.23: *; vlt install defaults to :not(*)). I checked this in the published tarballs for rc.23, rc.24, rc.26, rc.28, rc.30, rc.31, rc.32, 1.0.4, 1.0.7, 1.1.1 and 1.2.0. When the query has a security selector, reify calls SecurityArchive.start, which POSTs every newly added node to https://api.socket.dev/v0/purl?alerts=true using vlt's public token. Any non-2xx reply throws, and vlt ci exits 1. Packages served by the harness's local registry count as "npm" packages because registries.npm points at that registry, so they are sent to the API too.

Fix

Leg::vlt_with is the one place every harness vlt call goes through. For vlt ≥ rc.24 it now adds --allow-scripts :scripts to vlt ci. That is vlt's own default without the :not(:malware) filter. The harness's packages have no malware alerts, so the set of packages allowed to run scripts stays the same and the API call goes away. An explicit --allow-scripts set by a test is left as is. Older releases and vlt install are untouched. A harness self-test (vlt_e2e_harness_ci_never_queries_the_socket_api) pins the version boundary and the pass-through cases.

This is a root-cause hermeticity fix: no retries, no raised timeouts, no ignored tests.

Proof

I reproduced it locally with vlt 1.2.0, using a sandbox where api.socket.dev returns 403, the same failure class as the 401:

suite (--include-ignored vlt_pinned_matrix, vlt 1.2.0) main this PR
e2e_vlt 7 passed / 2 failed (the same two tests as CI) 9 / 0
e2e_redirect_vlt_build 14 / 24 failed 38 / 0
e2e_vendor_vlt_build 8 / 24 failed 32 / 0
mode_migration_vlt 6 / 8 failed 14 / 0
e2e_safety_vlt 9 / 1 failed 10 / 0

Every failure on main was Failed to fetch security data (138 occurrences). With the fix there were none.

I also ran e2e_vlt and mode_migration_vlt with the fix on vlt 1.0.0-rc.24, 1.0.0-rc.32, 1.0.4 and 1.1.1: all pass (9/9 and 14/14 each), so every pinned release in range accepts the flag. On this PR's CI, every vlt e2e row (0.0.0-16 through 1.2.0, ubuntu/macOS/Windows) and the rest of CI passed.

rustfmt --check is clean on the touched file. cargo clippy -p socket-patch-cli --test e2e_vlt --test mode_migration_vlt --test e2e_safety_vlt --test e2e_redirect_vlt_build -- -D warnings is clean. Clippy on e2e_vendor_vlt_build has 7 needless_borrow errors, all in tests/prebuilt_common/mod.rs and already on main. CI's clippy job doesn't lint tests, so they are left alone here.

Where tests run

Nothing was removed or moved. Job names and required checks are unchanged.

🤖 Generated with Claude Code

https://claude.ai/code/session_018ghbvY52iuzejTo4knpDvq


Generated by Claude Code

From 1.0.0-rc.24 `vlt ci` defaults --allow-scripts to
`:scripts:not(:malware)`. The `:malware` selector makes vlt POST every
newly installed node to api.socket.dev, so the real-vlt e2e legs
depended on that API answering 2xx. A 401 from it at 03:05 UTC on
2026-10-01 failed 15 vlt matrix jobs in one CI run, and with the API
unreachable 59 legs across the five vlt suites fail on vlt 1.2.0.

Pass the same query minus the network filter (`:scripts`) on every
harness `vlt ci` for releases that have the default. The harness's
packages carry no malware alerts, so the set of packages allowed to
run scripts is unchanged; an explicit --allow-scripts is kept.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018ghbvY52iuzejTo4knpDvq
@mikolalysenko Mikola Lysenko (mikolalysenko) added the ci-janitor Opened by the CI janitor routine (flakes, redundant tests, CI perf) label Oct 1, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

bugbot run


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 3a3c625. Configure here.

@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 1, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[burn-down agent] Ready for review on 3a3c625: mergeable, 0 commits behind main.

  • CI: 298/298 check runs green on 3a3c625 (6 skipped by workflow conditions, none failing).
  • Bugbot: reviewed 3a3c625, no findings; 0 unresolved review threads.
  • Reviewer focus: test-harness-only change in crates/socket-patch-cli/tests/vlt_e2e_common/mod.rs — makes the vlt e2e legs hermetic so vlt ci's default --allow-scripts malware query to api.socket.dev can't fail a leg on a transient non-2xx.

Note: Slack announcement could not be sent this run (no Slack send tool available in the agent session); next run will retry.


Generated by Claude Code

@mikolalysenko
Mikola Lysenko (mikolalysenko) merged commit d19bea9 into main Oct 1, 2026
298 checks passed
@mikolalysenko
Mikola Lysenko (mikolalysenko) deleted the ci-janitor/vlt-ci-hermetic-allow-scripts branch October 1, 2026 16:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-janitor Opened by the CI janitor routine (flakes, redundant tests, CI perf) Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants