|
| 1 | +[agent] 2026-10-02: Yarn classic (1.x) bug-hunt run |
| 2 | + |
| 3 | +**Tested:** main `61cfb9b` (unchanged since run 5), latest release v4.0.0. Linux sandbox, Node 22, yarn 1.0.2 / 1.6.0 / 1.7.0 / 1.10.1 / 1.22.22 from `npm i yarn@<v>`. One probe branch for macOS / Windows (run https://github.com/SocketDev/socket-patch/actions/runs/36975456921). Local Python mock patch API, as in run 6. |
| 4 | + |
| 5 | +## Re-triage |
| 6 | +Main is unchanged, so #363 / #364 / #437 / #467 / #493 / #519 stand. #493 now has the draft fix PR #520. It reads only the nearest `.yarnrc` `--modules-folder`, which matches what yarn honors (see the env-var finding below). |
| 7 | + |
| 8 | +## Cells (all pass) |
| 9 | +- **`--production` installs** (dev dep in the lock, not installed), hosted, 1.22.22: both entries rewired, and the frozen `--production` and full installs are patched. `vex` attests the uninstalled dev dep from its lock pin, which is the documented lock-only basis (as with platform-skipped `fsevents`). |
| 10 | +- **`integrity sha1-…` locks** (what yarn 1.10–1.12 writes for packages that have no registry sha512): hosted (1.10.1 / 1.22.22) and vendored (1.22.22) rewire to sha512. The frozen fresh install is patched, the lock is stable on re-install, and `yarn check --integrity` passes. Vendored rollback is byte-exact. |
| 11 | +- **Odd range syntax in lock keys** (`">= 1.2.0 < 1.4"`, `"1.x || 2.x"`, `latest`, `~1.3`, `"1.2.2 - 1.2.4"`, `=1.2.2`, `v1.2.2`, across 3 workspaces), hosted, 1.22.22: the merged and quoted keys are rewired, and the frozen install is patched and stable. |
| 12 | +- **Workspace member under `tests/e2e`** (the default discovery exclusion dir) with a nested multi-version copy: agent patches both copies. Hosted / vendored rewire the root lock. |
| 13 | +- **`socket.yml` policy on that workspace** (`packages`, `ignorePackages` with version, `ignorePaths: tests/**`, `includePaths: tests/**`, `minSeverity: critical`), hosted and agent: everything behaves as docs/configuration.md says (a member is part of the root project, and package filters narrow it). |
| 14 | +- **`yarn set version classic` layout** (`.yarnrc.yml` `yarnPath` + `.yarnrc yarn-path` + `packageManager: yarn@1.22.22`): hosted / vendored rewrite the v1 lock (not treated as berry), and the frozen install is patched. Agent apply works. |
| 15 | +- **`vendor --revert`** after a vendored scan, on LF / CRLF / BOM+CRLF locks, yarn 1.7.0 and 1.22.22: byte-exact, and `.socket/` is removed. |
| 16 | +- **Dev flow after scan** (`yarn add` of another dep, then a fresh frozen install, `vex`, `vendor --check`, and a `--pure-lockfile` then plain reinstall), hosted and vendored: |
| 17 | + - Linux 1.0.2 / 1.6.0 (hosted) and 1.7.0 / 1.10.1 / 1.22.22 (both modes): pass. |
| 18 | + - Probe: Windows 1.7.0 / 1.10.1 / 1.22.22 and macOS 1.7.0 / 1.22.22: pass, all RESULT lines read. The `yarn add` keeps the hosted URLs and `file:./.socket/vendor/…` (no backslashes on Windows), and the lock stays stable. macOS 1.10.1 and ubuntu: the jobs were green but I didn't read their logs. |
| 19 | +- CI `npm-compatibility.yml` on `61cfb9b`: green. |
| 20 | + |
| 21 | +## Issues |
| 22 | +None filed, commented on or closed this run. |
| 23 | + |
| 24 | +## False positives ruled out |
| 25 | +- `YARN_MODULES_FOLDER` / `npm_config_modules_folder` env vars: yarn 1.22.22 ignores both (it installs into `node_modules`), so the crawler is right not to read them. |
| 26 | +- `~/.yarnrc` `--modules-folder deps` resolves relative to `$HOME` (yarn installs into `~/deps`). That's exotic, so I didn't pursue it. |
| 27 | +- Hosted standalone `vex` printing `record_unavailable` when only `SOCKET_PATCH_SERVER_URL` is set: it also needs `--api-url` (with a mock). That's a harness detail. |
| 28 | +- v5 has no `setup` subcommand. The agent cells use `apply`. |
| 29 | + |
| 30 | +## Leftover |
| 31 | +- The probe branch `bughunt/yarn-classic/20261002-dev-flow` couldn't be deleted (the proxy rejects ref deletion, same as earlier runs). |
| 32 | + |
| 33 | +## Next |
| 34 | +1. Global mode on Windows once #442 merges (#434 / #437). |
| 35 | +2. Re-check #493 after #520 merges: workspace-level `--modules-folder` and `--install.modules-folder`. |
| 36 | +3. Hosted rollback on `integrity sha1-` locks (needs the `reg.py` registry passthrough): what integrity does the restored entry get? |
| 37 | +4. `.yarnclean` / `yarn autoclean` versus the agent and hosted patched files and VEX hash verification. |
| 38 | +5. Re-run the v4-only project columns (#363, #364) on macOS / Windows once fixes land. |
0 commit comments