Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

createResidentRunner().exec() always fails: "Cannot resolve module 'data:text/javascript;base64,...'"

オープン
#280 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
58/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
静か
技術スタック
node.js, typescript
領域
backend, security

調査の方向性

文書化されている NodeRuntime.createResidentRunner() と NodeRuntimeResidentRunner.exec() のフローから始め、影響を受けるパッケージバージョンで提供されたスニペットを使って失敗を再現します。resident runner が送信された data:text/javascript モジュールをどのように解決するかを調査します。繰り返し exec() を呼び出した結果が exitCode 0 になり、stdout に resolver エラーなしでスニペットの出力が含まれれば完了です。

索引モデルが issue の本文から書いたものです。

説明

Summary

NodeRuntime.createResidentRunner() / NodeRuntimeResidentRunner.exec() (documented at https://secureexec.dev/docs/features/resident-runner) fails on every single call, regardless of the code snippet's content. Confirmed reproducible on both the latest (0.3.3) and rc (0.3.4-rc.1) npm dist-tags.

Environment

  • secure-exec versions tested: 0.3.3 (latest) and 0.3.4-rc.1 (rc)
  • Node.js: v24.18.0
  • OS: macOS, darwin-arm64 (@secure-exec/sidecar-darwin-arm64)

Repro

import { NodeRuntime } from "secure-exec";

const runtime = await NodeRuntime.create();
const runner = await runtime.createResidentRunner();

const result = await runner.exec(`console.log("hello");`);
console.log(result);

Expected

Per the docs: "A warm resident evaluation runs in roughly a millisecond" — the snippet should execute successfully (exitCode: 0, stdout containing hello).

Actual

Every call returns exitCode: 1 with the same class of error, e.g.:

{
  stdout: '',
  stderr: "Error: Cannot resolve module 'data:text/javascript;base64,Y29uc29sZS5sb2coImhlbGxvIik7#0' (imported from '/tmp/secure-exec-program-0.mjs'): not found. For a bare package, ensure it is installed in a node_modules directory on an ancestor of the importer (or bundle the entrypoint). If you mounted a host node_modules, point it at a directory that contains every symlink target (e.g. the workspace root): symlinks that escape the mount root are not followed.\n    at /tmp/secure-exec-program-0.mjs:238:65",
  exitCode: 1
}

This happens for:

  • The same snippet repeated 5x in a row
  • 5 distinct/unique snippets in a row
  • A trivial globalThis.counter++-style state test

i.e. it's not content-dependent — every single exec() call on a resident runner fails the same way.

Suspected root cause

The resident runner appears to work by running a small REPL-style loop inside the guest that evaluates each submitted snippet via a dynamic import() of a data:text/javascript;base64,... URL. The guest's module resolver doesn't seem to recognize the data: URL scheme as a special case — the error message ("ensure it is installed in a node_modules directory... ") reads like the resolver is falling through to its bare-specifier/node_modules lookup path instead of treating it as an inline module to evaluate directly. This would explain why the failure is 100% reproducible and independent of the snippet's content.

Given it reproduces identically on both 0.3.3 and 0.3.4-rc.1, this doesn't look like something recently fixed on the rc line.

Impact

This blocks the documented "trusted, repeated evaluation" use case (REPLs, eval loops, per-tenant persistent runtime reuse) that createResidentRunner() is specifically meant for — right now it's unusable for any real workload since 100% of calls fail.

Happy to provide more repro details/logs if useful.

主要言語
TypeScript
スター
1k
フォーク
54
PR マージ指標
30日以内にマージされた PR はありません

環境構築

  • Dockerfile または Docker Compose ファイルあり
  • プルリクエストのテンプレートなし
  • コントリビューションガイドなし

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

rivet-dev/dynamic-apps のほかの issue

rivet-dev/dynamic-apps の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。