You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CLI walk, used only for hosted VEX: npm_alias_copies_reusing,`` with its own BFS, real_subdirs and a 200,000-dir cap (L184). It counts a dir as an alias when its name differs case-sensitively (`if name != key`, L274). `hosted_consumed_copies` then merges its results into the resolver's copies, re-expanding store variants and de-duplicating by canonical path.
Since #605, the resolver's own set already holds the ordinary aliases (see #851). The walk is now a second tree walk per hosted vex run whose only unique output is the drift below.
Proof by execution (a throwaway test in vex_consumed::tests, run twice on 4646693). The fixture is node_modules/Left-Pad holding left-pad@1.3.0 (an alias key differing only by case; npm accepts it as a legacy-valid name), plus a control node_modules/mm holding minimist@1.2.2:
PROBE core left-pad=[] minimist=[".../node_modules/mm"]
PROBE walk left-pad=Some([".../node_modules/Left-Pad"]) minimist=Some([".../node_modules/mm"])
On a case-sensitive file system, agent apply doesn't see the Left-Pad copy, so it reports the package not installed or patches only the plain copy, while hosted VEX does see it. The two paths disagree about which copies exist.
In core alias_copies, replace the case-insensitive skip with "skip the dir the direct probe already returned", compared by path (canonical where the file system folds case). A case-only alias then counts as a copy on case-sensitive file systems, and the same physical dir is still never recorded twice on Windows or macOS.
Delete npm_alias_copies, npm_alias_copies_reusing, real_subdirs and ALIAS_WALK_MAX_DIRS from vex_consumed.rs, along with the alias merge branch of hosted_consumed_copies. npm hosted copies are then the resolver's set, plus the identity fallback.
crawlers/npm_crawler.rs (about 15 lines) and commands/vex_consumed.rs (about −150 production lines; tests ported). No contract change.
Acceptance criteria
Regression test in core: find_by_purls over node_modules/Left-Pad (holding left-pad@1.3.0) returns that dir on Linux, and a plain dir is still reported once where the FS is case-insensitive.
npm_alias_copies_finds_only_alias_installs and npm_alias_copies_walks_every_workspace_members_tree are rewritten against find_manifest_package_copies_reusing with the same expected copies (@me/mm, nested dep/node_modules/deep, workspace-member aliases, --global-prefix), and pass.
hosted_reuses_expanded_npm_copies_and_merges_alias_variants, hosted_expands_alias_only_copies, vlt_alias_is_consumed_through_its_store_copy and the Fix agent mode skipping npm-aliased copies (#356) #738 core alias tests stay green.
vex_consumed.rs contains no node_modules walk.
Dependencies
Blocked by #851, which edits the same tests. Blocks nothing; it makes #852's fix single-sited.
[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: register comment.
Kind: refactor, with one behavior fix. Source: new finding, register E62; child 1 of #855 (E40).
Problem
npm alias discovery ("a real dir whose own
package.jsonnamesname@version, under another key") is written twice, and the copies have drifted:apply,rollbackand the VEX installed lookup:NpmCrawler::alias_copies,added by #738. It runs per importer-tree level ([L1532-L1534](https://github.com/SocketDev/socket-patch/blob/4646693150cf5efca6222b87092e1620e58566f8/crates/socket-patch-core/src/crawlers/npm_crawler.rs#L1532-L1534``)) and skips a dir whose name matches the package case-insensitively (L1601), assuming the direct probe already found it.npm_alias_copies_reusing,`` with its own BFS,real_subdirsand a 200,000-dir cap (L184). It counts a dir as an alias when its name differs case-sensitively (`if name != key`, L274). `hosted_consumed_copies` then merges its results into the resolver's copies, re-expanding store variants and de-duplicating by canonical path.Since #605, the resolver's own set already holds the ordinary aliases (see #851). The walk is now a second tree walk per hosted
vexrun whose only unique output is the drift below.Proof by execution (a throwaway test in
vex_consumed::tests, run twice on4646693). The fixture isnode_modules/Left-Padholdingleft-pad@1.3.0(an alias key differing only by case; npm accepts it as a legacy-valid name), plus a controlnode_modules/mmholdingminimist@1.2.2:On a case-sensitive file system, agent
applydoesn't see theLeft-Padcopy, so it reports the package not installed or patches only the plain copy, while hosted VEX does see it. The two paths disagree about which copies exist.Symptoms
main, because the walk's tests assumed the resolver never returns aliases..store. Fixing that in one place fixes it for apply and VEX together.Proposed change
alias_copies, replace the case-insensitive skip with "skip the dir the direct probe already returned", compared by path (canonical where the file system folds case). A case-only alias then counts as a copy on case-sensitive file systems, and the same physical dir is still never recorded twice on Windows or macOS.npm_alias_copies,npm_alias_copies_reusing,real_subdirsandALIAS_WALK_MAX_DIRSfromvex_consumed.rs, along with the alias merge branch ofhosted_consumed_copies. npm hosted copies are then the resolver's set, plus the identity fallback.npm_identity_fallback*, which covers symlinked importer entries and plain--global, and the rest of Tracking: move vex_consumed's per-ecosystem consumed-copy rules from the CLI into core #855.Size and scope
crawlers/npm_crawler.rs(about 15 lines) andcommands/vex_consumed.rs(about −150 production lines; tests ported). No contract change.Acceptance criteria
find_by_purlsovernode_modules/Left-Pad(holdingleft-pad@1.3.0) returns that dir on Linux, and a plain dir is still reported once where the FS is case-insensitive.npm_alias_copies_finds_only_alias_installsandnpm_alias_copies_walks_every_workspace_members_treeare rewritten againstfind_manifest_package_copies_reusingwith the same expected copies (@me/mm, nesteddep/node_modules/deep, workspace-member aliases,--global-prefix), and pass.hosted_reuses_expanded_npm_copies_and_merges_alias_variants,hosted_expands_alias_only_copies,vlt_alias_is_consumed_through_its_store_copyand the Fix agent mode skipping npm-aliased copies (#356) #738 core alias tests stay green.vex_consumed.rscontains nonode_moduleswalk.Dependencies
Blocked by #851, which edits the same tests. Blocks nothing; it makes #852's fix single-sited.