You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Decide: support tiers for bun.lockb writes, vendored pnpm 7/8 locks, vlt pre-1.0 locks and hosted Maven/Gradle #1156
[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: discussion #560 register.
Kind: decision. Source: review §5 "Support tiers" and §6 Q3, Part 4.6; register E47.
The question
There are four formats where socket-patch does a lot of work for old or unstable package-manager versions. For each one, should socket-patch keep full write support, refuse the format with a re-lock remedy, or ship it with a lower support tier? Each answer below is independent, so a separate yes or no on each is enough.
#
Candidate
Option A (status quo)
Option B (recommended by the audit)
Option C
1
bun.lockb writes (hosted and vendored)
Keep the native binary writer
Refuse writes with the remedy bun install --save-text-lockfile --frozen-lockfile --lockfile-only. Keep reading bun.lockb for inventory and VEX.
Keep the writer for vendored mode only
2
Vendored pnpm lockfile 5.4/6.0 (pnpm 7/8)
Keep the legacy backend
Refuse with "re-lock with pnpm ≥ 9". Hosted mode keeps every pnpm major.
Production lines:vendor/bun_lockb.rs 1,707, vendor/bun_binary.rs 736, redirect/bun_binary.rs 136, redirect/upstream/bun_lockb.rs 152 and CLI bun_preflight.rs 191, plus bun.lockb branches in about 30 other files.
These majors absolutize file: override specifiers, so a vendored frozen install only passes at the original checkout path. docs/ecosystems.md documents this as vendor_pnpm_legacy_absolute_specifier, which undercuts the point of vendoring.
docs/ecosystems.md lists seven lock eras (A0–F). Every mode reads all of them, and vlt_lock_text.rs carries a legacy DepID codec (·/§) next to the tilde codec.
Vendored vlt is 2,112 + 536 + 148 production lines. Hosted vlt is 662 + 217.
The pre-1.0 eras account for most of the "documented gap" bullets in the vlt notes (rc.6 … rc.29 behaviors).
JVM
There are 33 open pm:maven and 2 pm:gradle issues, the largest per-ecosystem backlog.
If option B is chosen for items 1–3, roughly 3.5–4K production lines and their tests become deletable, along with the bug classes in the issues above.
Item 4 is documentation and remedy text only.
Proposed follow-up (after the decision)
One implementation issue per accepted item, each a single PR that:
adds the refusal code and its remedy;
deletes the writer;
updates docs/ecosystems.md, CLI_CONTRACT.md and migrating-to-v5.md (if it ships with v5).
Readers needed by inventory, VEX and rollback stay. Rollback of entries an older socket-patch already wrote must keep working, or must refuse with git checkout -- <lock>, as hosted bun.lockb already does.
Acceptance criteria
The owner picks A, B or C for each of items 1–4 in a comment.
The register row E47 and Part 4/5 of the living document record the answer.
The implementation issues are filed for accepted B/C items.
[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: discussion #560 register.
Kind: decision. Source: review §5 "Support tiers" and §6 Q3, Part 4.6; register E47.
The question
There are four formats where socket-patch does a lot of work for old or unstable package-manager versions. For each one, should socket-patch keep full write support, refuse the format with a re-lock remedy, or ship it with a lower support tier? Each answer below is independent, so a separate yes or no on each is enough.
bun.lockbwrites (hosted and vendored)bun install --save-text-lockfile --frozen-lockfile --lockfile-only. Keep readingbun.lockbfor inventory and VEX.0, legacy DepIDs)docs/ecosystems.mdand in the remedy text until the JVM backlog shrinksEach option B is a user-visible contract change: a format that works today starts to refuse. That is why this needs an owner decision.
Evidence on main @
cf8b164bun.lockbbun.lock, and the code itself calls the binary lock "binary, legacy".NORMALIZED_MAGIC = b"sktpnrm").vendor/bun_lockb.rs1,707,vendor/bun_binary.rs736,redirect/bun_binary.rs136,redirect/upstream/bun_lockb.rs152 and CLIbun_preflight.rs191, plusbun.lockbbranches in about 30 other files.bun.lockbbugs: Afterbun removeof a vendored package in a bun.lockb project,scan --prune,vendor --revertandremovekeep it as "drifted", sovendor --checkstays red and its remedy loops #1132, Vendored bun.lockb workspaces write the member-relative tarball mirrors with no .gitignore check, so a*.tgzrule drops them from the commit and fresh frozen installs fail (Bun 1.1.39–1.2.23) or hang (1.3.9) #1116, Hosted and vendored scans from a Bun workspace member with a stray bun.lock / bun.lockb pin that ignored lock, exit 0, and lock-only VEX attests not_affected while Bun installs the unpatched package #1101, Vendored re-run on an isolated-linker bun.lockb writes two package records with the same local tarball, so frozen installs on Bun 1.3.9/1.4.2 fail intermittently with EEXIST #861, After Bun migrates a vendored bun.lockb to bun.lock (bun install --save-text-lockfile), vendor --revert and rollback fail, and a superseding re-vendor drops the pre-vendor original so revert exits 0 with the project still vendored #784, After a Bun rollback orvendor --revert, the advisedbun installkeeps the patched bytes installed on the hoisted linker (Bun reports "no changes") #764 and Lock inventory ignores a bun.lockb that Bun installs from when bun.lock is a dangling symlink #735.vendor/pnpm_lock_legacy.rshas 1,256 production lines and about 3.7K test lines. The router admits it throughsniff_lock_grammar.file:override specifiers, so a vendored frozen install only passes at the original checkout path.docs/ecosystems.mddocuments this asvendor_pnpm_legacy_absolute_specifier, which undercuts the point of vendoring.file:specifier unquoted, so a project path containing#or:breaks every frozen install while vendor,vendor --checkand vex report success #754, Vendored pnpm 7/8 (lock 5.4 / 6.0) writes an unquotedname: @scope/pkgfor a scoped package, so every frozen install fails with ERR_PNPM_BROKEN_LOCKFILE after a successful scan #956).docs/ecosystems.mdlists seven lock eras (A0–F). Every mode reads all of them, andvlt_lock_text.rscarries a legacy DepID codec (·/§) next to the tilde codec.pm:mavenand 2pm:gradleissues, the largest per-ecosystem backlog.Impact
Proposed follow-up (after the decision)
docs/ecosystems.md,CLI_CONTRACT.mdandmigrating-to-v5.md(if it ships with v5).git checkout -- <lock>, as hostedbun.lockbalready does.Acceptance criteria
Dependencies