Hosted pnpm rollback drops the upstream `tarball:` URL from locks written with `lockfileIncludeTarballUrl`, so the restore isn't byte-exact
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 78/100
Hướng nghiên cứu
Start at crates/socket-patch-core/src/formats/pnpm/grammar.rs:203, especially Resolution::restore, and review the pnpm compatibility property in docs/testing/pnpm-compatibility.md. Reproduce the hosted pin and rollback with lockfileIncludeTarballUrl enabled, then verify rollback restores the tarball URL when it was present and preserves its absence otherwise, with byte-exact lockfile output.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
[agent] Found by the scheduled pnpm bug-hunt routine (ledger #303).
Summary
With pnpm's lockfile-include-tarball-url=true (.npmrc) or lockfileIncludeTarballUrl: true (pnpm-workspace.yaml), pnpm records every resolution as {integrity: …, tarball: https://registry.npmjs.org/<name>/-/<name>-<ver>.tgz}. The hosted pin itself works: integrity and tarball are both replaced, and a fresh frozen install is patched. But rollback restores only {integrity: …}, so the lock no longer matches what pnpm wrote and the project setting asks for. pnpm doesn't re-add the field: a plain pnpm install afterwards leaves the lock unchanged ("up to date"), so the tarball URL stays lost until someone re-resolves.
Impact
Low. Installs still work, because pnpm derives the URL from the configured registry. But rollback isn't byte-exact, which docs/testing/pnpm-compatibility.md lists as a covered property. It also gives a spurious lock diff in projects that rely on recorded tarball URLs (mirrors, air-gapped tooling, audits).
Repro (Linux; local patch-API mock with SOCKET_PATCH_SERVER_URL / SOCKET_NPM_REGISTRY pointed at it)
mkdir app && cd app
echo '{"name":"app","version":"1.0.0","dependencies":{"is-number":"7.0.0"}}' > package.json
echo lockfile-include-tarball-url=true > .npmrc # pnpm 12: lockfileIncludeTarballUrl: true in pnpm-workspace.yaml
pnpm install && cp pnpm-lock.yaml before.yaml
socket-patch scan --mode hosted --json --yes … # success, redirected 1
socket-patch rollback --json --yes # success
diff before.yaml pnpm-lock.yaml
# - resolution: {integrity: sha512-41Cifkg6…, tarball: https://registry.npmjs.org/is-number/-/is-number-7.0.0.tgz}
# + resolution: {integrity: sha512-41Cifkg6…}
pnpm install && diff before.yaml pnpm-lock.yaml # still differs; pnpm doesn't re-add it
Expected vs actual
- Expected: CLI_CONTRACT ("Unwinding hosted state", npm family) says rollback restores the "resolution + integrity … from the npm registry's version document", and that document carries
dist.tarball. When the pre-pin entry had atarball:field (or the project setslockfileIncludeTarballUrl), rollback should write the registrydist.tarballback. When it didn't, rollback should keep omitting it. - Actual:
tarballis always omitted.
Matrix (Linux, each run twice)
| pnpm | hosted pin + fresh frozen install | rollback byte-exact |
|---|---|---|
9.15.9 (.npmrc) |
pass | fail |
10.34.5 (.npmrc) |
pass | not run |
| 12.8.1 (workspace setting) | pass | fail |
Suspect code
crates/socket-patch-core/src/formats/pnpm/grammar.rs:203 – Resolution::restore drops tarball unconditionally ("pnpm omits tarball for a package the configured registry serves"), which isn't true under this setting.
Tested on main 61cfb9b (CLI 4.0.0).
- Ngôn ngữ chính
- Rust
- Star
- 8
- Fork
- 0
- Merge trung bình
- 18 giờ 4 phút
- Pull request đã merge (30 ngày)
- 70
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của SocketDev/socket-patch
-
agent:triaged bug bughunt pm:composer priority:p2
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 90/100
SocketDev/socket-patch#515 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged bug bughunt pm:npm priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
SocketDev/socket-patch#464 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged bug bughunt pm:npm priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
SocketDev/socket-patch#433 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged bug bughunt pm:uv priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
SocketDev/socket-patch#408 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
SocketDev/socket-patch#370 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của SocketDev/socket-patch
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày