Repository navigation
On Windows, scan -g / get -g / vex -g find no global npm packages because npm root -g is spawned as bare npm, which never resolves to npm.cmd #434
Description
Activity
- addedbugSomething isn't workingSomething isn't workingbughuntFound by a scheduled package-manager bug-hunt agentFound by a scheduled package-manager bug-hunt agentpm:npmnpmnpm
on Oct 1, 2026 mikolalysenko commented
on Oct 1, 2026 CollaboratorAuthorMore actions[agent] The Yarn classic (1.x) bug-hunt routine (ledger #304) confirms the same miss on the yarn probe (
get_yarn_global_prefix_with→ bareyarn, soyarn.cmdis never found).Probe https://github.com/SocketDev/socket-patch/actions/runs/36827174726 ran on main
2463257, with yarn installed vianpm i -g yarn@<v>and a mock patch API servingpkg:npm/left-pad@1.3.0:yarn global add left-pad@1.3.0 is-number@7.0.0 yarn global dir # C:\Users\runneradmin\AppData\Local\Yarn\Data\global (packages present) socket-patch scan -g … # left-pad / is-number not reported -> scan_report FAIL socket-patch scan -g --mode agent … # exit 0, global copy left unpatched -> agent_apply FAIL SOCKET_GLOBAL=1 socket-patch scan --mode agent … -> FAIL socket-patch vex -g … # exit 2, nothing attested -> FAIL
windows-latest scan -g agent apply vex -g SOCKET_GLOBAL=1yarn 1.10.1 FAIL FAIL FAIL FAIL yarn 1.22.22 FAIL FAIL FAIL FAIL The identical script passes on ubuntu-latest and macos-latest for yarn 1.10.1 and 1.22.22. A fix through
resolve_toolshould cover theyarn(andpnpm/bun) probes innpm_crawler.rsas well asnpm. Yarn 1.0.x has a separate, non-Windows problem (noyarn global dirsubcommand), filed as #437.
Generated by Claude Code
mikolalysenko commented
on Oct 1, 2026 CollaboratorAuthorMore actions[agent] Shares root cause with #421, #438, #440: the global package-manager probes go through
SystemCommandRunner::run, which spawns the bare tool name withCommand::new(bin)(no PATHEXT, sogem.cmd/npm.cmd/yarn.cmd/composer.batare never found on Windows) and inherits the project cwd (so a Berry project'sglobalscript runs). Will be fixed together. Triage: priority:p1 (npm-family).[agent] Claiming this issue (with #421, #438, #440; shared root cause: global PM probes spawn the bare tool name from the project cwd via SystemCommandRunner). Branch: agent/fix-global-probe-tool-spawn. Claim-ID: 2026-10-01T07:21:08Z-824845
Generated by Claude Code
mikolalysenko commented
on Oct 1, 2026 CollaboratorAuthorMore actions- added a commit that references this issue
on Oct 1, 2026 mikolalysenko commented
on Oct 1, 2026 CollaboratorAuthorMore actions[agent] New data from the Bun bug-hunt routine (ledger #306): the Bun probe hits the same failure, now confirmed with a real install.
On windows-latest I ran
npm install -g --prefix <dir> bun@<ver>, so PATH holds only the npm shims (bun,bun.cmd,bun.ps1) and nobun.exe. Thenbun add -g semver@7.6.0 is-number@7.0.0into$BUN_INSTALL:scan -g --jsongivessuccesswithpackages: [], andscan -g --mode agentexits 0 with "No patches available".get -gexits 1, andvex -ghas nothing to attest.- That holds on Bun 1.3.14 and 1.4.2. The same layout passes on ubuntu-latest and macos-latest.
- A standalone Bun install (
bun.exeon PATH) passes on Windows. So it's only the npm-shim case, which fits the bareCommand::new("bun")inget_bun_global_prefix_with(npm_crawler.rs:567).
Run: https://github.com/SocketDev/socket-patch/actions/runs/36830650075 (cell
npm_installed_bun).There's a separate Bun bug that #442 doesn't cover: the
bun pm bin -g→../install/global/node_modulesderivation is wrong wheneverBUN_INSTALL_BIN/BUN_INSTALL_GLOBAL_DIRis set. That's filed as #443.
Generated by Claude Code
- added a commit that references this issue
on Oct 2, 2026
[agent] Found by the scheduled npm bug-hunt routine (ledger #302).
Summary
On Windows, global mode never finds a globally installed npm package. This holds for the default prefix and for a custom
npm_config_prefix, on npm 10 and 12, from Git Bash and from PowerShell. Only an explicit--global-prefix <dir>works.scan -g -e npmprints "No global packages found." and exits 0successwithscannedPackages: 0, even thoughnpm root -glists the package.get <uuid> -greturnspartial_failure(exit 1) and patches nothing.vex -gomits the patch aspackage_not_found.SOCKET_GLOBAL=1behaves the same way.It's the same mechanism as #421 (RubyGems /
gem.cmd), but on the npm path.Root cause
get_npm_global_prefix_with(crates/socket-patch-core/src/crawlers/npm_crawler.rs:487) runsrunner.run("npm", &["root", "-g"])throughSystemCommandRunner. That callsstd::process::Command::new("npm")on the bare name (crates/socket-patch-core/src/utils/process.rs:138). On Windows,stdresolves a bare program name to.exeonly, so thenpm.cmdshim is never found. The spawn fails,get_global_node_modules_paths(npm_crawler.rs:1145) adds nothing, and there's no Windows fallback (only macOS has hard-coded fallbacks). Thepnpm,yarnandbunprobes next to it use the same bare spawn.The repo already has the right helper:
resolve_tool/command_forinutils/process.rs, which honoursPATHEXTand spawns.cmdshims safely.Impact
This is a silent miss on the most common Windows setup. The maintainer checklist for global mode requires that
scan -g"must find every globally installed npm package that has a hosted patch: none missing". Instead, a Windows user (or Windows CI) runningscan -gis told there's nothing to patch, with exit 0.get -gfails, and a VEX for global tools can't be produced. Linux and macOS pass the identical probe.Repro (probe runs on GitHub Actions)
The patch API is a local mock serving a free patch for
pkg:npm/left-pad@1.3.0.SPA="--api-url http://127.0.0.1:8765 --org o --api-token fake --patch-server-url http://127.0.0.1:8765".Same result from
pwshwithsocket-patch.exe scan -g -e npm … --json:scannedPackages: 0.Expected vs actual
--global/-gas "Operate on globally-installed packages", with--global-prefixdefaulting to "(auto)", i.e. discovered vianpm root -g. Auto-detection should findC:\npm\prefix\node_modules(or%APPDATA%\npm\node_modules), just as it does on Linux and macOS. If it can't determine the prefix, it should say so loudly instead of reporting a clean, empty scan.Matrix (main
2463257, Node 24.15.0)scan -g(default prefix)scan -g(customnpm_config_prefix)get -gvex -g--global-prefixscan / get / rollbackProbe runs: https://github.com/SocketDev/socket-patch/actions/runs/36825128447 (3 OS × npm 10/12, the hosted cycle plus global mode) and https://github.com/SocketDev/socket-patch/actions/runs/36826141655 (Windows-focused: default prefix, custom prefix, explicit prefix, PowerShell).