Repository navigation
Resolve VEX npm alias copies through the core resolver and delete vex_consumed's second alias walk #856
Description
Activity
- addedpm:npmnpmnpmarch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)Filed by a scheduled architecture audit routine (see the architecture review discussion)refactorStructural change: duplicated code or logic, missing abstraction, layering, dead codeStructural change: duplicated code or logic, missing abstraction, layering, dead code
on Oct 5, 2026 mikolalysenko commented
on Oct 5, 2026 CollaboratorAuthorMore actions[agent] Triage: priority:p1. npm (npm-family). Child of #855. It includes a behaviour fix (drifted alias rules between the core resolver and vex_consumed), so it is tiered by ecosystem. Related to #852 (npm alias copies) but a different code path: #852 is the linked-strategy store entry named after the alias.
Generated by Claude Code
mikolalysenko commented
on Oct 7, 2026 CollaboratorAuthorMore actions[agent] Re-checked on main @
db83f01, after #987 (npm linked-store aliases, #852) merged. The duplication is still there and the code has moved.- Fix npm linked-store alias copies left unpatched (#852) #987 extended only the core resolver.
NpmCrawler::alias_copiesnow also runs over npm linked-store entries (L1692-L1696). It still skips a dir whose name matches case-insensitively (L1771). - The CLI walk,
npm_alias_copies_reusing, is unchanged. It still compares exactly (name != key, L274), so the case-only drift described above still holds. - Fix npm linked-store alias copies left unpatched (#852) #987 also added a third alias test, in the store fan-out:
dir_key != full_name, L3101. That one is exact as well.
The proposed change still stands: VEX should take alias copies from the core resolver, and the CLI walk should be deleted. The acceptance criteria should now also cover the linked-store alias case from #852.
Generated by Claude Code
- Fix npm linked-store alias copies left unpatched (#852) #987 extended only the core resolver.
mikolalysenko commented
on Oct 7, 2026 CollaboratorAuthorMore actionsBeing fixed in draft PR #1008 (batch fix for open
pm:npmissues).
[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: register comment.
Kind: refactor, with one behavior fix. Source: new finding, register E62; child 1 of #855 (E40).
Problem
npm alias discovery ("a real dir whose own
package.jsonnamesname@version, under another key") is written twice, and the copies have drifted:apply,rollbackand the VEX installed lookup:NpmCrawler::alias_copies,added by #738. It runs per importer-tree level ([L1532-L1534](https://github.com/SocketDev/socket-patch/blob/4646693150cf5efca6222b87092e1620e58566f8/crates/socket-patch-core/src/crawlers/npm_crawler.rs#L1532-L1534``)) and skips a dir whose name matches the package case-insensitively (L1601), assuming the direct probe already found it.npm_alias_copies_reusing,`` with its own BFS,real_subdirsand a 200,000-dir cap (L184). It counts a dir as an alias when its name differs case-sensitively (`if name != key`, L274). `hosted_consumed_copies` then merges its results into the resolver's copies, re-expanding store variants and de-duplicating by canonical path.Since #605, the resolver's own set already holds the ordinary aliases (see #851). The walk is now a second tree walk per hosted
vexrun whose only unique output is the drift below.Proof by execution (a throwaway test in
vex_consumed::tests, run twice on4646693). The fixture isnode_modules/Left-Padholdingleft-pad@1.3.0(an alias key differing only by case; npm accepts it as a legacy-valid name), plus a controlnode_modules/mmholdingminimist@1.2.2:On a case-sensitive file system, agent
applydoesn't see theLeft-Padcopy, so it reports the package not installed or patches only the plain copy, while hosted VEX does see it. The two paths disagree about which copies exist.Symptoms
main, because the walk's tests assumed the resolver never returns aliases..store. Fixing that in one place fixes it for apply and VEX together.Proposed change
alias_copies, replace the case-insensitive skip with "skip the dir the direct probe already returned", compared by path (canonical where the file system folds case). A case-only alias then counts as a copy on case-sensitive file systems, and the same physical dir is still never recorded twice on Windows or macOS.npm_alias_copies,npm_alias_copies_reusing,real_subdirsandALIAS_WALK_MAX_DIRSfromvex_consumed.rs, along with the alias merge branch ofhosted_consumed_copies. npm hosted copies are then the resolver's set, plus the identity fallback.npm_identity_fallback*, which covers symlinked importer entries and plain--global, and the rest of Tracking: move vex_consumed's per-ecosystem consumed-copy rules from the CLI into core #855.Size and scope
crawlers/npm_crawler.rs(about 15 lines) andcommands/vex_consumed.rs(about −150 production lines; tests ported). No contract change.Acceptance criteria
find_by_purlsovernode_modules/Left-Pad(holdingleft-pad@1.3.0) returns that dir on Linux, and a plain dir is still reported once where the FS is case-insensitive.npm_alias_copies_finds_only_alias_installsandnpm_alias_copies_walks_every_workspace_members_treeare rewritten againstfind_manifest_package_copies_reusingwith the same expected copies (@me/mm, nesteddep/node_modules/deep, workspace-member aliases,--global-prefix), and pass.hosted_reuses_expanded_npm_copies_and_merges_alias_variants,hosted_expands_alias_only_copies,vlt_alias_is_consumed_through_its_store_copyand the Fix agent mode skipping npm-aliased copies (#356) #738 core alias tests stay green.vex_consumed.rscontains nonode_moduleswalk.Dependencies
Blocked by #851, which edits the same tests. Blocks nothing; it makes #852's fix single-sited.
Backlog review — 2026-10-08
Priority: P1 → P2. The reported case-only npm alias edge concerns resolver disagreement; preserve it in #1008 but lower the priority of this narrow supported-name case.