Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Hosted pnpm rollback drops the upstream `tarball:` URL from locks written with `lockfileIncludeTarballUrl`, so the restore isn't byte-exact

Đang mở
#557 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
78/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
rust
Lĩnh vực
cli

Hướng nghiên cứu

Start at crates/socket-patch-core/src/formats/pnpm/grammar.rs:203, especially Resolution::restore, and review the pnpm compatibility property in docs/testing/pnpm-compatibility.md. Reproduce the hosted pin and rollback with lockfileIncludeTarballUrl enabled, then verify rollback restores the tarball URL when it was present and preserves its absence otherwise, with byte-exact lockfile output.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

bug bughunt pm:pnpm

[agent] Found by the scheduled pnpm bug-hunt routine (ledger #303).

Summary

With pnpm's lockfile-include-tarball-url=true (.npmrc) or lockfileIncludeTarballUrl: true (pnpm-workspace.yaml), pnpm records every resolution as {integrity: …, tarball: https://registry.npmjs.org/<name>/-/<name>-<ver>.tgz}. The hosted pin itself works: integrity and tarball are both replaced, and a fresh frozen install is patched. But rollback restores only {integrity: …}, so the lock no longer matches what pnpm wrote and the project setting asks for. pnpm doesn't re-add the field: a plain pnpm install afterwards leaves the lock unchanged ("up to date"), so the tarball URL stays lost until someone re-resolves.

Impact

Low. Installs still work, because pnpm derives the URL from the configured registry. But rollback isn't byte-exact, which docs/testing/pnpm-compatibility.md lists as a covered property. It also gives a spurious lock diff in projects that rely on recorded tarball URLs (mirrors, air-gapped tooling, audits).

Repro (Linux; local patch-API mock with SOCKET_PATCH_SERVER_URL / SOCKET_NPM_REGISTRY pointed at it)

mkdir app && cd app
echo '{"name":"app","version":"1.0.0","dependencies":{"is-number":"7.0.0"}}' > package.json
echo lockfile-include-tarball-url=true > .npmrc          # pnpm 12: lockfileIncludeTarballUrl: true in pnpm-workspace.yaml
pnpm install && cp pnpm-lock.yaml before.yaml
socket-patch scan --mode hosted --json --yes …           # success, redirected 1
socket-patch rollback --json --yes                       # success
diff before.yaml pnpm-lock.yaml
# -    resolution: {integrity: sha512-41Cifkg6…, tarball: https://registry.npmjs.org/is-number/-/is-number-7.0.0.tgz}
# +    resolution: {integrity: sha512-41Cifkg6…}
pnpm install && diff before.yaml pnpm-lock.yaml          # still differs; pnpm doesn't re-add it

Expected vs actual

  • Expected: CLI_CONTRACT ("Unwinding hosted state", npm family) says rollback restores the "resolution + integrity … from the npm registry's version document", and that document carries dist.tarball. When the pre-pin entry had a tarball: field (or the project sets lockfileIncludeTarballUrl), rollback should write the registry dist.tarball back. When it didn't, rollback should keep omitting it.
  • Actual: tarball is always omitted.

Matrix (Linux, each run twice)

pnpm hosted pin + fresh frozen install rollback byte-exact
9.15.9 (.npmrc) pass fail
10.34.5 (.npmrc) pass not run
12.8.1 (workspace setting) pass fail

Suspect code

crates/socket-patch-core/src/formats/pnpm/grammar.rs:203 – Resolution::restore drops tarball unconditionally ("pnpm omits tarball for a package the configured registry serves"), which isn't true under this setting.

Tested on main 61cfb9b (CLI 4.0.0).

Ngôn ngữ chính
Rust
Star
8
Fork
0
Merge trung bình
18 giờ 4 phút
Pull request đã merge (30 ngày)
70

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của SocketDev/socket-patch

Tất cả issue của SocketDev/socket-patch

Issue tương tự

Thêm issue về Rust

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.