Bug hunt ledger: Yarn classic (1.x) #304
Replies: 7 comments
|
[agent] 2026-09-30: Yarn classic (1.x) bug-hunt run This is the first run, so the ledger started empty and there were no Tested: main Setup: I used a hold-open Python mock of the patch API (batch / by-package / package / view with Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-01: Yarn classic (1.x) bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out / findings that aren't bugs
Probe branches
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Yarn classic (1.x) puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × Yarn classic (1.x) version cells for |
|
[agent] 2026-10-01: Yarn classic (1.x) bug-hunt run Tested: main Setup notes for the next run (v5 changed them): Re-triage
Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-01: handover from the Yarn Berry (2+) bug-hunt routine (#305) Lead for yarn classic on Windows, not verified with classic. The global discovery shells out with |
|
[agent] 2026-10-01: Yarn classic (1.x) bug-hunt run Tested: main Harness for the next run (v5): a Python mock that serves Re-triage
Cells (Linux, v5
|
|
[agent] 2026-10-01: Yarn classic (1.x) bug-hunt run Tested: main Harness: Re-triage
Cells (Linux,
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Yarn classic (1.x) bug-hunt routine (label pm:yarn-classic).
Last updated: 2026-10-01 (run 5), main
61cfb9b, latest release v4.0.0. Run 5 added the cells in "Run 5 cells" below. The project-mode matrix below was measured onf6b7fb9(v4); cells marked "(v5)", the global matrix and the "v5 project-mode cells" list were re-run on v5.Coverage matrix
Cells are "pass", "fail #N", "n/a", "CI" or "untested". H = hosted, V = vendored, A = agent (
scan --apply+setup). Each H/V cell ends with a real fresh-checkoutyarn install --frozen-lockfile, using a local mock patch API. CI'syarn-classic-matrix(1.0.2, 1.6.0, 1.7.0, 1.9.4, 1.10.1, 1.22.22) covers the plain single-dep H/V flows plus VEX on Linux.git+…)file:tarballs)--offline)--offline)Couldn't find the binary git)Global mode (
-g) on v52463257Report =
scan -greport-only + no leakage; refusal =scan -g/--global-prefix/SOCKET_GLOBAL --mode hostedexits 2; A = agent apply + import +vex -g+rollback -gbyte-exact; get-mode =get -g --mode hosted|vendored/scan -g --mode vendored; RO = read-only global folder fails loudly.Other cells that pass on Linux 1.22.22 (some also on older releases; see the entries): spaces + unicode project paths (also macOS and Windows),
npm:alias (H skipped as documented, V rewired),resolutions, aresolvedwithout the#sha1fragment /integrity, a localfile:tarball dep, a non-deduplicated lock, a superseding patch on re-scan,remove/repair, VEX (installed and lock-only, afteryarn upgrade),yarn addthen a frozen reinstall (1.7.0 too),yarn check --integrity/--verify-tree, in-place reinstalls on 1.7–1.22, concurrent scans (lock_held), the GitHub shorthand dep on all 3 OSes.v5 project-mode cells (Linux, run 4)
--dry-runbyte-identity (H / V / A / rollback) on CRLF / BOM / mixed, pass.npm:alias, vex /vendor --check/repair/ frozen offline / rollback, pass (1.22.22).integrity(1.7-style) locks, H and V: pass (1.7.0 / 1.22.22). Tarball-URL dep, H and V: pass.file:dir dep, H: pass.repair/ re-scan).Run 5 cells (Linux,
61cfb9b).yarnrc --modules-folder, agent mode: fail Agent mode ignores yarn classic's--modules-folder: packages installed there are reported "not installed" andscan --mode agentexits 0 leaving them unpatched #493 (1.7.0 / 1.10.1 / 1.22.22).nohoist, A/H/V + frozen install + vex: pass (1.22.22).--max-new-patcheson a workspace, A/H/V + re-run + frozen install: pass (1.22.22)..yarnrc registry, hosted rewire + rollback: pass (rollback usesSOCKET_NPM_REGISTRY, as documented).Backlog
scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 / Global mode never finds yarn 1.0.x global packages:yarn global dirdoesn't exist before yarn 1.1.0, and there's no fallback #437, and the Berry handover lead about the.cmdshim); yarn via corepack and the Windows MSI; 1.6.0 / 1.9.4 on the probe; a read-only prefix on Windows (Program Files). Re-run get-mode cells after Fix -g touching the cwd project's state (#436, #445) #446.optionalDependencies/ platform-skipped packages in both modes and vex.--modules-folderin hosted / vendored modes and at workspace level.yarn importlocks and--pure-lockfile; asocket.ymlpatchespolicy on a workspace member path.Known non-bugs
patches-api.socket.devisn't used here. Use a local mock API (--api-url). The mock must match purls with an unencoded@for scoped packages, and vendored runs need--vendor-source buildplusblobContentin the view stub. For hostedvexon lock-only checkouts, pass--patch-server-url <mock>(CLI_CONTRACT "Patch hosts"); otherwisepackage_not_foundis expected.yarn 1.0.2 – 1.6.x install nothing (exit 0, empty node_modules) for
file:tarball lock entries and offline-mirror installs, even without socket-patch. Bisected in run 2: Node 10.24.1 / 14.21.3 / 16.20.2 / 22 all behave the same, and 1.7.0 works on all of them. The cause is in yarn, not Node or socket-patch, which is why CI reportsKNOWN LIMITATIONfor vendored ≤ 1.6. Not in docs/ecosystems.md.An
npm:alias entry is left unpatched in hosted mode withredirect_yarn_classic_alias_skipped(documented), andvexomits the package.A BOM plus no yarn header comment makes the first entry
entry_not_found. Yarn always writes the header, so this is synthetic.file:directory andlink:deps are skipped by design. (file:tarball deps are rewired and work.)The GitHub shorthand
owner/repo#taglocks as a codeload tarball and is correctly rewired; onlygit+…patterns are Hosted and vendored yarn classic modes rewire git-sourced yarn.lock entries, so every later yarn install fails while scan and VEX report success #363.Running
scanfrom a workspace member dir: vendored →vendor_lockfile_missing(exit 1); hosted → exit 0,redirected: 0,redirect_npm_no_lockfile(npm-only wording). This is the documented hosted refusal posture.hosted→agent / vendored→agent keep the existing wiring (
hosted_wiring_retained/vendored_ownership_retained), as documented.Concurrent scans: the extras fail with
lock_held(intended).Probe branches can't be deleted from the sandbox (the git proxy rejects ref deletion). Leftovers:
bughunt/yarn-classic/20260930-mirror-git,bughunt/yarn-classic/20261001-win-crlf-git.v5 hosted
rollback/removeneed the npm registry. In the sandbox the CLI's rustls client rejects the TLS-intercepting proxy CA (error sending request for url (https://registry.npmjs.org/…)). That's a sandbox artifact. Use a local plain-HTTP registry passthrough withenv -u HTTPS_PROXY -u https_proxy SOCKET_NPM_REGISTRY=http://127.0.0.1:<port>. WithSOCKET_NPM_REGISTRYset, the restoredresolvedusesdist.tarballverbatim (registry.npmjs.org), not registry.yarnpkg.com. That's by design (npm.rsyarn_classic_tarball).v5 vendored mode has no local build (
--vendor-source buildis rejected). The mock must serve atarballartifact fromPOST …/patches/package.scan -galso reports npm's own bundled deps (npm global root), e.g.@isaacs/string-locale-compare. That's correct global discovery.Probe branch
bughunt/yarn-classic/20261001-global-modeis also left on the remote (the proxy blocks deletion).Hosted pins are recognized only on
patch.socket.devor the--patch-server-url/SOCKET_PATCH_SERVER_URLorigin. With a mock at another origin and no such setting,rollbacksaysManifest not found(truly-empty project). SetSOCKET_PATCH_SERVER_URL=<mock>.Hosted rollback of a lock without
integritylines (yarn < 1.10) addsintegritylines. That's the "default upstream entry", and yarn 1.7 still installs it frozen.Vendored mode on yarn ≤ 1.6 installs nothing. The harness asserts this as a KNOWN LIMITATION (
tests/common/yarn_classic_vex.rs:89); it's not in the user docs.A tarball-URL dependency of the patched name@version is rewired in both modes (it installs patched). Whether a URL "fork" should be refused, as vlt does, is a design question.
A SIGKILL can leave the lock wired with no
vendor/state.json.rollbackthen refuses with a remedy, andrepair/ a re-scan rebuild the ledger. That's intended crash handling.Hosted rollback ignores the
.yarnrcregistryand queriesSOCKET_NPM_REGISTRY(default registry.npmjs.org). That's documented (CLI_CONTRACT Hosted unwind / env table). SetSOCKET_NPM_REGISTRYbehind a private registry.A nested non-workspace project (its own
yarn.lockunder the root) in hosted mode from the root:redirect_yarn_classic_entry_not_found, because hosted reads only the root lock. That's the documented one-project model (run with--cwdper project).A stale
node_modulesleft beside an active--modules-folder: Node loadsnode_modulesfirst, so agent patching it is correct.All reactions