vendor --revert with a lost vendor ledger tells you to "run socket-patch repair to re-adopt them into the ledger", but repair refuses because it never rebuilds the ledger, so the advice loops and the vendored npm packages can't be reverted
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 2/5
- Tempo estimado
- 1-3 horas
- Facilidade para iniciantes
- 75/100
Direção de pesquisa
Leia crates/socket-patch-cli/src/commands/vendor.rs por volta da linha 4071 e crates/socket-patch-cli/src/commands/vendored_backend/repair.rs por volta da linha 184 para comparar o aviso com a recusa de repair. Execute os testes existentes relevantes para o aviso de reversão de vendor. O trabalho estará concluído quando o aviso não recomendar mais uma ação que não possa corrigir a ausência de um ledger e um teste cobrir esse comportamento.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
[agent] Found by the scheduled npm bug-hunt routine (ledger #302).
Summary
When .socket/vendor/state.json is lost (deleted, or dropped by a bad merge) while package-lock.json still wires the vendored tarballs, socket-patch vendor --revert keeps the artifacts, which is the correct fail-safe. It then warns vendor_orphan_still_wired with this remedy:
a project lockfile still points at .socket/vendor/npm/, which no ledger entry owns; the artifacts were kept (run
socket-patch repairto re-adopt them into the ledger, then revert again)
repair can't do that. It exits 1 with:
Cannot repair vendored artifact … the vendor ledger (.socket/vendor/state.json) has no entry for it, and repair does not rebuild the ledger from lockfiles; restore state.json from version control …
After repair, vendor --revert prints the same warning again ("Reverted 0 vendored packages.", exit 0). Following the advice goes round in a loop, and the project stays vendored.
Impact
Low severity, but it's a dead end for a user who doesn't have state.json in version control. The fail-safe parts all hold: in every step below, a cold-cache npm ci still installs patched bytes, and no artifact is deleted. Only the remedy is wrong. It contradicts CLI_CONTRACT.md (repair: "redownload missing/corrupt vendored artifacts (never re-synthesizing a lost ledger)"). It's in the same family as #900 and #977 (a suggested remedy that is a no-op).
Repro (Linux, npm 10.9.4, local mock of the patch API serving free patches for [email protected] and [email protected])
mkdir p && cd p
echo '{"name":"p","version":"1.0.0","dependencies":{"left-pad":"1.3.0","ms":"2.1.3"}}' > package.json
npm install
socket-patch scan --mode vendored --yes $API # exit 0, both vendored
rm .socket/vendor/state.json # ledger lost
socket-patch vendor --revert --yes $API
# Warning: … which no ledger entry owns; the artifacts were kept (run `socket-patch repair` to re-adopt them into the ledger, then revert again)
# Reverted 0 vendored packages. exit 0
socket-patch repair --yes $API
# Error: Cannot repair vendored artifact … repair does not rebuild the ledger from lockfiles … exit 1
socket-patch vendor --revert --yes $API # same warning again, exit 0
Expected vs actual
- Expected: a remedy that works here. Either the one
repair,rollbackandscan --prunealready give ("restore .socket/vendor/state.json from version control, or restore the lockfile withgit checkout -- <lockfile>"), or arepairthat actually re-adopts the entry, as the warning promises. - Actual: the warning points at
repair, which by contract and by its own message refuses this exact state.
Every other command reports this state consistently (main 05ecc6e, run twice):
| command | exit | message |
|---|---|---|
vendor --revert |
0 | vendor_orphan_still_wired → "run socket-patch repair to re-adopt" (wrong) |
repair |
1 | "repair does not rebuild the ledger … restore state.json" |
rollback |
1 | "restore .socket/vendor/state.json from version control …" |
scan --mode vendored --prune |
1 | "restore .socket/vendor/state.json from version control" |
vendor --check |
1 | vendor_ledger_missing … "restore state.json" |
OS × version
| OS | npm | result |
|---|---|---|
| Linux | 10.9.4 (Node 22.22) | fail (x2) |
macOS and Windows weren't probed. The message is built in shared CLI code, so it isn't OS-dependent, and probably not npm-specific either (sweep_orphan_vendor_dirs is ecosystem-generic). Not bisected.
Suspect code
crates/socket-patch-cli/src/commands/vendor.rs:4071(thevendor_orphan_still_wiredtext) vscrates/socket-patch-cli/src/commands/vendored_backend/repair.rs:184(repair's refusal).
Backlog review — 2026-10-08
Priority: P1 → P3. Missing-ledger recovery advice loops, but artifacts are retained and fresh installs remain patched. The report explicitly says only the remedy is wrong.
- Linguagem predominante
- Rust
- Estrelas
- 8
- Forks
- 0
- Merge médio
- 22h 30min
- PRs com merge (30d)
- 329
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Sem modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de SocketDev/socket-patch
-
agent:triaged bug bughunt pm:pipenv priority:p1
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
SocketDev/socket-patch#1219 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
agent:triaged bug bughunt pm:npm priority:p2
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
SocketDev/socket-patch#1127 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
agent:triaged bug bughunt pm:bundler priority:p1
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
SocketDev/socket-patch#1125 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
scan exits 1 in human output but 0 with --json when every patch query returns nothingTalvez já em andamento Um pull request vinculado a esta issue está aberto ou já foi mesclado. Abertaagent:triaged arch-audit bug priority:p3
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
SocketDev/socket-patch#1062 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
Hosted gem `rollback` / `remove` strips the `DEPENDENCIES` `!` of a gem the user declared inside a `source "https://rubygems.org" do` block, so every frozen install fails after the unwindTalvez já em andamento Um pull request vinculado a esta issue está aberto ou já foi mesclado. Abertaagent:triaged bug bughunt pm:bundler priority:p1
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 80/100
SocketDev/socket-patch#1056 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
Todas as issues de SocketDev/socket-patch
Issues semelhantes
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 62/100
Mantenedores costumam responder em até 1 dia
-
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 90/100
chroma-core/chroma#7879 ·
Mantenedores costumam responder em até 1 dia
-
priority middle
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 72/100
KATO-Hiro/AtCoderClans#12838 ·
Mantenedores costumam responder em até 1 dia
-
clap_complete env (PowerShell): values after a space don't complete in Windows PowerShell 5.1Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
Mantenedores costumam responder em até 1 dia
-
enhancement
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 74/100
Mantenedores costumam responder em até 1 dia