Skip to content

Commit 174e203

Browse files
committed
yarn-classic: run 7 ledger
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XC6sHMUQ5jKSbFDeJ92RYb
1 parent 7b0ceee commit 174e203

2 files changed

Lines changed: 51 additions & 4 deletions

File tree

Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
[agent] 2026-10-02: Yarn classic (1.x) bug-hunt run
2+
3+
**Tested:** main `61cfb9b` (unchanged since run 5), latest release v4.0.0. Linux sandbox, Node 22, yarn 1.0.2 / 1.6.0 / 1.7.0 / 1.10.1 / 1.22.22 from `npm i yarn@<v>`. One probe branch for macOS / Windows (run https://github.com/SocketDev/socket-patch/actions/runs/36975456921). Local Python mock patch API, as in run 6.
4+
5+
## Re-triage
6+
Main is unchanged, so #363 / #364 / #437 / #467 / #493 / #519 stand. #493 now has the draft fix PR #520. It reads only the nearest `.yarnrc` `--modules-folder`, which matches what yarn honors (see the env-var finding below).
7+
8+
## Cells (all pass)
9+
- **`--production` installs** (dev dep in the lock, not installed), hosted, 1.22.22: both entries rewired, and the frozen `--production` and full installs are patched. `vex` attests the uninstalled dev dep from its lock pin, which is the documented lock-only basis (as with platform-skipped `fsevents`).
10+
- **`integrity sha1-…` locks** (what yarn 1.10–1.12 writes for packages that have no registry sha512): hosted (1.10.1 / 1.22.22) and vendored (1.22.22) rewire to sha512. The frozen fresh install is patched, the lock is stable on re-install, and `yarn check --integrity` passes. Vendored rollback is byte-exact.
11+
- **Odd range syntax in lock keys** (`">= 1.2.0 < 1.4"`, `"1.x || 2.x"`, `latest`, `~1.3`, `"1.2.2 - 1.2.4"`, `=1.2.2`, `v1.2.2`, across 3 workspaces), hosted, 1.22.22: the merged and quoted keys are rewired, and the frozen install is patched and stable.
12+
- **Workspace member under `tests/e2e`** (the default discovery exclusion dir) with a nested multi-version copy: agent patches both copies. Hosted / vendored rewire the root lock.
13+
- **`socket.yml` policy on that workspace** (`packages`, `ignorePackages` with version, `ignorePaths: tests/**`, `includePaths: tests/**`, `minSeverity: critical`), hosted and agent: everything behaves as docs/configuration.md says (a member is part of the root project, and package filters narrow it).
14+
- **`yarn set version classic` layout** (`.yarnrc.yml` `yarnPath` + `.yarnrc yarn-path` + `packageManager: yarn@1.22.22`): hosted / vendored rewrite the v1 lock (not treated as berry), and the frozen install is patched. Agent apply works.
15+
- **`vendor --revert`** after a vendored scan, on LF / CRLF / BOM+CRLF locks, yarn 1.7.0 and 1.22.22: byte-exact, and `.socket/` is removed.
16+
- **Dev flow after scan** (`yarn add` of another dep, then a fresh frozen install, `vex`, `vendor --check`, and a `--pure-lockfile` then plain reinstall), hosted and vendored:
17+
- Linux 1.0.2 / 1.6.0 (hosted) and 1.7.0 / 1.10.1 / 1.22.22 (both modes): pass.
18+
- Probe: Windows 1.7.0 / 1.10.1 / 1.22.22 and macOS 1.7.0 / 1.22.22: pass, all RESULT lines read. The `yarn add` keeps the hosted URLs and `file:./.socket/vendor/…` (no backslashes on Windows), and the lock stays stable. macOS 1.10.1 and ubuntu: the jobs were green but I didn't read their logs.
19+
- CI `npm-compatibility.yml` on `61cfb9b`: green.
20+
21+
## Issues
22+
None filed, commented on or closed this run.
23+
24+
## False positives ruled out
25+
- `YARN_MODULES_FOLDER` / `npm_config_modules_folder` env vars: yarn 1.22.22 ignores both (it installs into `node_modules`), so the crawler is right not to read them.
26+
- `~/.yarnrc` `--modules-folder deps` resolves relative to `$HOME` (yarn installs into `~/deps`). That's exotic, so I didn't pursue it.
27+
- Hosted standalone `vex` printing `record_unavailable` when only `SOCKET_PATCH_SERVER_URL` is set: it also needs `--api-url` (with a mock). That's a harness detail.
28+
- v5 has no `setup` subcommand. The agent cells use `apply`.
29+
30+
## Leftover
31+
- The probe branch `bughunt/yarn-classic/20261002-dev-flow` couldn't be deleted (the proxy rejects ref deletion, same as earlier runs).
32+
33+
## Next
34+
1. Global mode on Windows once #442 merges (#434 / #437).
35+
2. Re-check #493 after #520 merges: workspace-level `--modules-folder` and `--install.modules-folder`.
36+
3. Hosted rollback on `integrity sha1-` locks (needs the `reg.py` registry passthrough): what integrity does the restored entry get?
37+
4. `.yarnclean` / `yarn autoclean` versus the agent and hosted patched files and VEX hash verification.
38+
5. Re-run the v4-only project columns (#363, #364) on macOS / Windows once fixes land.

‎state/yarn-classic.md‎

Lines changed: 13 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
[agent] Progress ledger for the scheduled Yarn classic (1.x) bug-hunt routine (label pm:yarn-classic).
22

3-
Last updated: 2026-10-02 (run 6), main `61cfb9b`, latest release v4.0.0. Runs 5 and 6 added the cells in "Run 5 cells" and "Run 6 cells" below. The project-mode matrix below was measured on `f6b7fb9` (v4); cells marked "(v5)", the global matrix and the "v5 project-mode cells" list were re-run on v5.
3+
Last updated: 2026-10-02 (run 7), main `61cfb9b`, latest release v4.0.0. Runs 5–7 added the cells in "Run 5 cells", "Run 6 cells" and "Run 7 cells" below. The project-mode matrix below was measured on `f6b7fb9` (v4); cells marked "(v5)", the global matrix and the "v5 project-mode cells" list were re-run on v5.
44

55
## Coverage matrix
66

@@ -56,12 +56,18 @@ Other cells that pass on Linux 1.22.22 (some also on older releases; see the ent
5656
- Uppercase names (`JSONStream`), A/H/V + frozen + vex + rollback: pass. `yarn import` locks, H/V: pass.
5757
- Hosted pin `Authorization` leakage (6 `.npmrc` auth configs): none on 1.0.2 / 1.6.0 / 1.9.4 / 1.12.3 / 1.17.3 / 1.22.22: pass.
5858

59+
### Run 7 cells (`61cfb9b`)
60+
- Dev flow after scan (`yarn add`, then a frozen fresh install, `vex`, `vendor --check`, `--pure-lockfile` reinstall), H and V: pass on Linux 1.0.2 / 1.6.0 (H) and 1.7.0 / 1.10.1 / 1.22.22, Windows 1.7.0 / 1.10.1 / 1.22.22, macOS 1.7.0 / 1.22.22 (probe).
61+
- `--production` install, hosted + vex: pass (1.22.22). `integrity sha1-` locks, H / V + rollback: pass (1.10.1 / 1.22.22).
62+
- Odd range keys (`">= a < b"`, `||`, `x`, hyphen, `latest`, `v`-prefix), H: pass. Workspace member under `tests/` + `socket.yml` policies (A/H): pass.
63+
- `yarn set version classic` layout (`.yarnrc.yml` yarnPath + `packageManager`), A/H/V: pass. `vendor --revert` on LF / CRLF / BOM+CRLF (1.7.0 / 1.22.22): byte-exact.
64+
5965
## Backlog
6066

6167
1. **Maintainer request (global mode), still open:** Windows once #442 merges (#434 / #437, and the Berry handover lead about the `.cmd` shim); yarn via corepack and the Windows MSI; 1.6.0 / 1.9.4 on the probe; a read-only prefix on Windows (Program Files). Re-run get-mode cells after #446.
62-
2. `--modules-folder` at workspace level and via env (`YARN_MODULES_FOLDER`, `npm_config_modules_folder`).
63-
3. `--production` installs: hosted vex on devDependencies that are locked but not installed.
64-
4. `socket.yml` `patches` policy on a workspace member path; `--pure-lockfile` dev flows.
68+
2. Re-check #493 after #520 merges: workspace-level and `--install.modules-folder` forms.
69+
3. Hosted rollback on `integrity sha1-` locks (what integrity the restored entry gets).
70+
4. `.yarnclean` / `yarn autoclean` vs agent / hosted patched files and VEX hash verification.
6571
5. Re-run the v4-only project matrix columns (git dep #363, offline mirror H #364) on macOS/Windows once fixes land.
6672

6773
## Known non-bugs
@@ -94,3 +100,6 @@ Other cells that pass on Linux 1.22.22 (some also on older releases; see the ent
94100
- `scan --vex` in a PnP project exits 1 `manifest_not_found` only because there is nothing to attest. Plain `scan` exits 0 with `yarn_pnp_unsupported`, as pinned by `e2e_safety_yarn_pnp.rs`.
95101
- A platform-skipped optional dep (`fsevents` on Linux) is rewired and attested from the lock pin in hosted mode: the documented lock-only basis, and it installs patched on macOS.
96102
- The mock harness must exclude `node_modules` relative to the package dir, or it serves empty tarballs (a harness bug, not socket-patch).
103+
- yarn classic ignores `YARN_MODULES_FOLDER` / `npm_config_modules_folder` (installs into `node_modules`), so the crawler needn't read them. A `~/.yarnrc` `--modules-folder` resolves relative to `$HOME`, not the project.
104+
- v5 has no `setup` subcommand. Agent cells use `apply`.
105+
- Probe branch `bughunt/yarn-classic/20261002-dev-flow` is also left on the remote (the proxy blocks deletion).

0 commit comments

Comments
 (0)