Skip to content

fix(module): canonicalize embedded module suffix keys - #120

Merged
steipete merged 3 commits into
mainfrom
claude/fix-embedded-module-suffix-keys
Oct 5, 2026
Merged

steipete merged 3 commits into
mainfrom
claude/fix-embedded-module-suffix-keys

Conversation

@steipete

@steipete steipete commented Oct 5, 2026 •

Copy link
Copy Markdown

Query and fragment imports of modules embedded by bun build --compile can produce suffixed registry keys absent from the executable's module table, then fall through to an ENOENT filesystem read of the virtual path.

Canonicalize the key only when the standalone graph confirms that the resolved path is embedded. Filesystem imports retain separate suffix identities. The non-ASCII regression checks six path/URL spellings, namespace identity, and single evaluation. The resolve-once loader boundary from oven-sh#44473 is unchanged.

Refreshed head 810c32c9160f2b2ebdd41a2d553e524dd1944e55 includes current main bb8e07fa4a3b578b12a5b032a72f1ba659da7568. The original runtime fix is unchanged. All existing changelog bytes are retained as a prefix, with the owned entry appended.

Validation on this head:

  • macOS arm64 release build and all 55 surrounding module/resolver/plugin files pass, plus both installs (57/57 rows). Both the old embedded-query regression and the new Unicode case fail with ENOENT on the unmodified baseline and pass with the fix. Node 24.21 passes the raw-source control with four distinct filesystem identities/evaluations.
  • Fork CI passes Linux x64 (16/16 rows) and Darwin arm64 (12/12). Its executed merge tree 3692f38a6f7de9a8092d75964390a5bd59948810 equals the reviewed head tree. P2 review, formatting, source lints, and JavaScript lint pass.
  • Exact-source Windows qualification passes on its first attempt: build, unsigned packaging, native smoke, all 32 compatibility rows including import-query.test.ts, and manifest validation. The separate frozen test-only pipeline builds this PR's exact SHA and verifies revision, architecture, source, and executable hashes before/after. Windows executable SHA-256: 2301f877523897105a94479e77103ce8d930a77be5ee672f68b16c5705bdff95.
  • The frozen broader macOS selection completes 46/47 rows. Its only failure is the same two networking reconnect assertions on the untouched baseline, which report additional ECONNRESET events. No assertion, deadline, or skip was changed. Earlier filesystem timing and VM RSS observations remain recorded separately; both files pass in this exact-head aggregate. This is baseline comparison evidence, not a 47/47 success claim.
Historical Windows and OpenClaw consumer evidence retained from the original implementation

Query and fragment imports of modules embedded by bun build --compile can produce suffixed registry keys that are absent from the executable's embedded module table, then fall through to an ENOENT filesystem read of the virtual path.

Canonicalize those keys at the shared module-key construction boundary. Drop a suffix only when the active standalone graph confirms the resolved path is an embedded module. Ordinary filesystem imports retain their distinct suffix identities. Add a non-ASCII filename regression that checks values, namespace identity, and single evaluation.

The existing native Windows regression and stock macOS regression fail before the change. Node 24 loads the raw-source control's five spellings. P2 review is scoped-clean, C++ and scoped JavaScript formatting pass, and the combined Windows x64 build succeeds. No WebKit change is needed; upstream searches found no additional matching fix.

Native Windows Server 2022 x64 proof used matched source and verified binaries: the resolver runner improved from 37/42 test files passing on fork main d2d2a26ef973cdd97b37953f5dba58052acad74f to 42/42 passing, with both dependency-install steps also successful. The passing executable was built from local integration 03aa23b6adea8e12235339d8650cae41fa1ea80d (tree 1c5084c96b361801cd9f595795774ec41e81e250), combining four independent fixes. This branch's production and test files are byte-identical in that integration. Executable SHA-256: cbd65560d2f8651dc82722d1d957803651e2803f0a1a66ae039b946d3b53b156.

Exact-head fork CI passes both required lanes: Linux x64 (14/14 selected and compatibility test files) and macOS arm64 (10/10); both dependency-install steps also pass in each lane. Native Windows proof is recorded above because this PR workflow has no Windows test lane.

Final native Windows proof uses local integration 9a2e4b08f3b3f2e17e05a23c35aeade9c6da06f3, executable SHA-256 19453c39dbb599eff57c1544a1c117dbc7bde7947ba2d41c9829cee9f20b10e0. The maintained module selection passes 2/2 files, the resolver selection 42/42, and broad compatibility 29/29; each run also passes both install steps. Source and executable guards pass before and after. Both Node 24 and the fork pass the complete 12-step installed OpenClaw path, including real update, foreground Gateway, plugins, a verified mock-provider turn, sustained readiness and Doctor. Foreground cleanup uses taskkill. No Windows build is published or signed.

The full 186-file/32-envelope comparison on identical OpenClaw deb44a7f20b774769104ab4262c8ada438d4fc8e reports all 3,184 assertions on each runtime: Node 2,896 pass / 13 fail / 275 skip (30 successful envelope exits), fork 2,891 pass / 16 fail / 277 skip (29 successful exits), with no missing reports, unhandled errors or suite failures. The three extra fork failures are shared Windows path limits reproduced with equal-length Node/fork/stock controls; the raw totals are preserved. All three shared timing failures pass isolated on Node and fork under unchanged deadlines (92 pass / 5 skip each). Runtime-specific conditional skips remain explicit. The original d2d2 runtime also passes the six-file/two-envelope OpenClaw consumer control (220 pass / 3 skip); these selected consumers provide non-regression evidence. The installed-update proof separately exercises the native-addon failure.

The three affected OpenClaw fixture files are fully revalidated on Node 24 and the fork: frozen before deb44a7f20b774769104ab4262c8ada438d4fc8e gives 40 pass / 13 fail / 3 skip on each; the corrected private fixture commit 96222ca4829457295a7fa3b00324b9d96b989291 and exact public head 343017e1202b579274fe87d51f6491ba8eeeeee4 each give 53 pass / 3 existing skips on both runtimes. All 56 cases are accounted for, every one of the 13 before-failures now explicitly passes, and the skip set is unchanged. This is complete three-file before/after and public-head proof, not a rerun of the full 32-envelope matrices. The verified public proof archive SHA-256 is 504d7ef2308d3c0a48d4b26135c233cdc720e8dc10c6e6061ddbe4d79e0c9f7a. The fixture correction openclaw/openclaw#165577 was merged from that exact tested public head as 8bc338dbed0ddf5c35b2178eb624ffc88ccef7e7. Its inherited-CI exception is recorded on the OpenClaw PR; no CI rerun or tested-head change was used for this proof.

@steipete
steipete merged commit 073be5e into main Oct 5, 2026
7 checks passed
@steipete
steipete deleted the claude/fix-embedded-module-suffix-keys branch October 5, 2026 18:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant