Conversation
…lockb print snapshot
"duplicate dependency in optionalDependencies maintains sort order" prints
bun.lockb and normalizes the random verdaccio port with
out.replaceAll(`${port}`, "4873"). That rewrites every occurrence of the
port's digits, including inside the deterministic "--hash:" header line,
so the snapshot fails whenever the port happens to be one of the 15
values that occur in that line (7280 in build 95598). Replace only the
localhost:<port> URLs, the way the rest of the file does, and update the
snapshot's URLs to the shared localhost:1234 placeholder.
|
Warning Review limit reached
Next review available in: 37 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Comment |
|
Status: fix pushed, waiting on CI. Reproduced by forcing |
There was a problem hiding this comment.
LGTM — test-only de-flake that swaps a bare-port replaceAll for the file's established localhost:\d+ normalization.
What was reviewed:
- Confirmed the new regex matches the pattern already used ~20× across
test/cli/install/for lockfile snapshots. - Snapshot diff only rewrites the six
resolvedURLs from:4873to:1234; the--hash:header line is untouched, so the assertion still guards the deterministic hash. - No
src/changes;portwas a shared module-level var, so no dead local left behind.
Extended reasoning...
Overview
One-line change in test/cli/install/bun-install-registry.test.ts (the duplicate dependency in optionalDependencies maintains sort order test) plus the six matching resolved URL lines in its .snap entry. The old normalization did out.replaceAll(${port}, "4873"), which replaced the bare port digits anywhere in the yarn-lockfile output — including inside the deterministic --hash: header — and flaked on ~15 of the 64k possible verdaccio ports. The new normalization uses replaceAll(/localhost:\d+/g, "localhost:1234"), which is the exact idiom already used throughout bun-install-registry.test.ts, bun-lock.test.ts, bun-workspaces.test.ts, and others.
Security risks
None. Test-only; no runtime code, no network, no auth.
Level of scrutiny
Low. This is a mechanical test-normalization fix that converges on an existing convention. The snapshot update is a direct consequence of changing the placeholder from 4873 to 1234; the hash line — the part the flake was corrupting — is byte-identical before and after, so assertion strength is preserved (it still catches sort-order regressions and hash changes).
Other factors
- Grep confirms this was the only remaining bare-port
replaceAllintest/; the PR description's "only one left" claim holds. portis a module-scope variable used elsewhere in the file, so removing this reference leaves no dead code.- No prior reviewer comments to address; the bug-hunting pass found nothing.
|
Review status: the automated review above found nothing to change, and a separate self-review of the diff (checking the premise against the snapshot, the other lockfile snapshots in this file, and whether the CodeRabbit has not reviewed yet (rate limited); nothing pending on this PR from my side. The only red lane on the first CI run was |
There was a problem hiding this comment.
LGTM — test-only de-flake that swaps a bare-port replaceAll for the file's standard localhost:\d+ normalization.
What was reviewed:
- Confirmed the new regex matches the convention already used at 18+ other sites in this test file.
- Snapshot diff touches only the six
resolvedURLs; the port-independent--hash:header line is left intact, which is the point of the fix. - Checked that assertion strength is preserved (still an exact snapshot; only the normalization is narrowed).
Extended reasoning...
Overview
One-line change in test/cli/install/bun-install-registry.test.ts replacing out.replaceAll(\${port}`, "4873")without.replaceAll(/localhost:\d+/g, "localhost:1234"), plus the corresponding six resolved` URL lines in the committed snapshot. No source code touched.
Security risks
None. Test-only, no runtime behavior, no external inputs.
Level of scrutiny
Low. This is a mechanical de-flake that brings the last remaining bare-port normalization in this file into line with the pattern used everywhere else in the same file (verified by grep). The root cause — bare digit substitution corrupting the deterministic hash header when the random port's digits happen to appear in it — is clearly explained and easy to verify against the snapshot content.
Other factors
The PR description demonstrates fail-before/pass-after with forced ports and enumerates the 15 colliding ports. The snapshot's hash line is unchanged, confirming the meta hash is port-independent and the assertion is not being weakened — it's being made more precise (integrity strings and the hash header are now compared verbatim instead of being subject to accidental digit substitution). No outstanding review comments; no prior claude[bot] reviews on this PR.
Problem
test/cli/install/bun-install-registry.test.ts, testduplicate dependency in optionalDependencies maintains sort order, flakes on main depending on which random port verdaccio was started on. Seen on the Windows x64 lane in main build 95598 (passed on retry); the port that run got was 7280 and the snapshot diff was:bun bun.lockband normalizes the port without.replaceAll(${port}, "4873")(bun-install-registry.test.ts:6252). The bare digits are replaced everywhere in the output, not only in theresolvedURLs, so any port whose digits occur in the deterministic--hash:header line corrupts that line before it is compared with the snapshot.randomPort()can return (1024 to 65534) against the committed snapshot: 15 ports break the old assertion (1551, 1728, 2803, 4508, 5517, 6659, 7280, 7915, 8032, 8383, 9155, 9450, 15517, 17280, 28032), all of them through the hash line. About 0.023% of runs of this file, every platform.test/; every other lockfile snapshot in this file and its siblings already usesreplaceAll(/localhost:\d+/g, "localhost:1234").Fix
localhost:<port>URLs, using the same regex andlocalhost:1234placeholder as the other lockfile snapshots in the file, and update the sixresolvedURLs in the snapshot entry accordingly. The hash line in the snapshot is unchanged (it never depended on the port, which is why the test passes for the other 64496 ports).bun bd test test/cli/install/bun-install-registry.test.ts -t "duplicate dependency in optionalDependencies maintains sort order"passes (snapshot matched, not rewritten).registry.portforced to 7280 and the original assertion and snapshot, the same command fails with the exact diff above, on both the debug build and the releasebunon PATH. With this change and the port forced to 7280, 8383 and 1728 it passes.src/diff to stash for a mechanical before/after; the forced-port runs above are the before/after.Background
VerdaccioRegistry(test/harness.ts) starts the fixture npm registry onrandomPort(), so everyresolvedURL thatbun installwrites into the lockfile contains a different port on each run. Snapshot tests of lockfile contents therefore have to normalize the port before comparing.bun <path>.lockbprints a binary lockfile in yarn v1 lockfile format. Its header includes# bun ./bun.lockb --hash: <hex>(src/install/lockfile/printer/Yarn.rs:46), the lockfile's meta hash.generate_meta_hash(src/install/lockfile.rs:2924) hashesname@resolutionlines plus lifecycle scripts, and for npm packages the resolution formats as the bare version (src/install/resolution.rs:767), so the hash never contains the registry port: it is stable across runs and belongs in the snapshot as-is, which is exactly what the old normalization broke.Port enumeration
Takes the committed snapshot as the expected normalized output, substitutes each candidate port into its URLs to reconstruct what
bun bun.lockbwould print, then applies the old and new normalizations.Output against the pre-PR snapshot: