fix(resolve): defer inline entry package scope validation - #91
Merged
Merged
Conversation
This was referenced Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stdin and eval scripts currently reject malformed ancestor package metadata before executing, so a bootstrap cannot produce its own JSON diagnostic. Fork #86 added the eager post-resolution scope check. Exempt the actual inline source path, defer runtime package-parser diagnostics, and preserve Node's CommonJS parent-scope check when
require()actually resolves a request. Bun's stdin environment and PATH setup remain intact.The regression covers explicit stdin, eval,
bun run -, and implicit Node-alias stdin, including builtins, script-owned rejection, relative CJS resolution, JS imports, CJS imports, and a nearer valid package scope. All 48 cases fail on unpatched main and pass patched. The exact source programs match Node 24.21.0. Linux CLI/resolver suites pass 309 tests with zero failures; all 12 Rust targets pass with no skips.The final Linux W96 944 metadata + 376 package-map + 14 scope cases show zero baseline changes and zero Node outcome/code/message differences. Linux OpenClaw
crabbox-untrusted-bootstrap.test.tsimproves from 24/25 to 25/25; Node 24 passes 25/25. Both local and committed-branch P2 reviews are scoped-clean. Exact-head fork CI: https://github.com/openclaw/bun/actions/runs/37117626781.Upstream searches found no inline-entry fix. The correction was added to the existing Node 24 package-validation submission, oven-sh#44512, at
f6d56a01d83895fd8fcf147abfdcf8bdaf83178c, preserving its concurrent built-in import fixes. That upstream build passes 337 tests and all 1,334 oracle cases without differences.