Skip to content

Commit d4e9f96

Browse files
committed
yarn-classic bug-hunt run 2026-10-02T12:54Z
1 parent a81a3fe commit d4e9f96

2 files changed

Lines changed: 45 additions & 4 deletions

File tree

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
[agent] 2026-10-02: Yarn classic (1.x) bug-hunt run
2+
3+
**Tested:** main `61cfb9b` (unchanged since run 5), latest release v4.0.0 (npm `@socketsecurity/socket-patch@4.0.0`, used to bisect). Linux sandbox only, Node 22, yarn 1.0.2 / 1.7.0 / 1.10.1 / 1.17.3 / 1.19.0 / 1.21.1 / 1.22.22 from `npm i yarn@<v>`. No probe branches: this run's cells are OS-independent (yarn's own cache-key logic, lock text).
4+
5+
**Harness (rebuilt):** `mock.py` is a Python mock patch API taking `name@ver=<installed dir>` args. It serves batch / by-package / view (with blobContent) / package (tarball artifact) / blob and the hosted tgz. Env knobs: `NOSHA1=1` serves a sha512-only artifact `integrity`, and `MARK=` sets the patch marker. `reg.py` is a plain-HTTP registry passthrough for hosted rollback (`SOCKET_NPM_REGISTRY=http://127.0.0.1:<port>`).
6+
7+
## Re-triage
8+
Main is unchanged, so #363 / #364 / #437 / #467 / #493 / #519 stand. #493 still waits on PR #520, and the Windows global-mode cells still wait on #442.
9+
10+
## Cells
11+
- **Hosted grant without `integrity.sha1`** (sha512-only, the shape the repo's own npm / bun hosted fixtures use): **fail, filed #558.** The lock gets `resolved "<url>"` with no `#sha1`, which lands in yarn's `npm-<name>-<ver>-integrity` cache slot. That's shared with fragmentless upstream entries and with earlier sha1-less hosted patches of the same version (superseding).
12+
- Warm-cache frozen install: yarn 1.0.2 / 1.7.0 / 1.10.1 / 1.17.3 exit 0 and install **unpatched** bytes (or the superseded patch). yarn 1.19.0 / 1.21.1 / 1.22.22 exit 1 with `Incorrect integrity when fetching from the cache`.
13+
- Cold cache: patched. `vex` correctly omits the patch, so there's no false attestation. v4.0.0 is also affected, so it's not a regression.
14+
- yarn.lock containing git **merge-conflict markers** (the conflict between two other deps, target outside it), hosted, 1.22.22: only the target entry is rewritten and the markers are kept: pass.
15+
- Workspace member `yarn install --focus --frozen-lockfile` after a hosted rewrite, 1.22.22: patched: pass.
16+
- `yarn audit` on a hosted lock and on an `npm:` alias lock, 1.22.22: works: pass.
17+
- Hosted `rollback` on an `integrity sha1-` lock (1.10.1): restores `resolved` (registry.npmjs.org host + `#sha1`) and a sha512 `integrity`. Not byte-exact, but documented (default upstream entry, `SOCKET_NPM_REGISTRY` host), and the frozen install works: pass.
18+
- `.yarnclean` (`yarn autoclean --init` + `*.md`, `index.d.ts`), hosted + frozen install + `vex`, 1.22.22: patched, `not_affected`: pass.
19+
- An `npm:` alias plus a direct dep of the same version: yarn 1.22.22 writes two separate blocks (it doesn't merge them), so the documented alias skip applies only to the alias block.
20+
21+
## Issues
22+
- Filed #558: https://github.com/SocketDev/socket-patch/issues/558 (plus a comment correcting the CLI_CONTRACT citation path).
23+
24+
## False positives ruled out
25+
- An alias key merged with a direct key in one block: yarn 1.22.22 never writes that form, so the shape isn't reachable.
26+
- Hosted rollback on a sha1-integrity lock gaining a sha512 `integrity`: documented default upstream entry.
27+
28+
## Next
29+
1. Global mode on Windows once #442 merges (#434 / #437).
30+
2. Re-check #493 after #520 merges: workspace-level `--modules-folder` and `--install.modules-folder`.
31+
3. Re-run the v4-only project columns (#363, #364) on macOS / Windows once fixes land.
32+
4. Vendored mode when the patch rewrites the package's own `package.json` dependencies (`staged_pkg` path), and whether hosted mode, which leaves the lock's `dependencies:` sub-map untouched, installs a missing new dependency.
33+
5. Superseding hosted patch **with** sha1 on yarn ≤1.17 in-place installs (distinct slot, but `.yarn-integrity` short-circuit).

‎state/yarn-classic.md‎

Lines changed: 12 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
[agent] Progress ledger for the scheduled Yarn classic (1.x) bug-hunt routine (label pm:yarn-classic).
22

3-
Last updated: 2026-10-02 (run 7), main `61cfb9b`, latest release v4.0.0. Runs 5–7 added the cells in "Run 5 cells", "Run 6 cells" and "Run 7 cells" below. The project-mode matrix below was measured on `f6b7fb9` (v4); cells marked "(v5)", the global matrix and the "v5 project-mode cells" list were re-run on v5.
3+
Last updated: 2026-10-02 (run 8), main `61cfb9b`, latest release v4.0.0. Runs 5–8 added the cells in "Run 5 cells" through "Run 8 cells" below. The project-mode matrix below was measured on `f6b7fb9` (v4); cells marked "(v5)", the global matrix and the "v5 project-mode cells" list were re-run on v5.
44

55
## Coverage matrix
66

@@ -62,13 +62,18 @@ Other cells that pass on Linux 1.22.22 (some also on older releases; see the ent
6262
- Odd range keys (`">= a < b"`, `||`, `x`, hyphen, `latest`, `v`-prefix), H: pass. Workspace member under `tests/` + `socket.yml` policies (A/H): pass.
6363
- `yarn set version classic` layout (`.yarnrc.yml` yarnPath + `packageManager`), A/H/V: pass. `vendor --revert` on LF / CRLF / BOM+CRLF (1.7.0 / 1.22.22): byte-exact.
6464

65+
### Run 8 cells (Linux, `61cfb9b`)
66+
- Hosted grant without `integrity.sha1` → fragmentless `resolved` → yarn cache-slot collision: **fail #558**. Warm-cache frozen install: 1.0.2 / 1.7.0 / 1.10.1 / 1.17.3 silently install unpatched bytes; 1.19.0 / 1.21.1 / 1.22.22 fail `Incorrect integrity when fetching from the cache`. v4.0.0 is affected too.
67+
- Merge-conflict markers in yarn.lock (target outside the conflict), H: pass. `--focus` workspace install, H: pass. `yarn audit` on hosted / alias locks: pass. `.yarnclean`, H + vex: pass (1.22.22).
68+
- Hosted rollback on an `integrity sha1-` lock: restores sha512 integrity + npmjs host (documented), frozen install OK: pass (1.10.1).
69+
6570
## Backlog
6671

6772
1. **Maintainer request (global mode), still open:** Windows once #442 merges (#434 / #437, and the Berry handover lead about the `.cmd` shim); yarn via corepack and the Windows MSI; 1.6.0 / 1.9.4 on the probe; a read-only prefix on Windows (Program Files). Re-run get-mode cells after #446.
6873
2. Re-check #493 after #520 merges: workspace-level and `--install.modules-folder` forms.
69-
3. Hosted rollback on `integrity sha1-` locks (what integrity the restored entry gets).
70-
4. `.yarnclean` / `yarn autoclean` vs agent / hosted patched files and VEX hash verification.
71-
5. Re-run the v4-only project matrix columns (git dep #363, offline mirror H #364) on macOS/Windows once fixes land.
74+
3. Patches that rewrite the package's own `package.json` dependencies: vendored (`staged_pkg` recompute) vs hosted (lock `dependencies:` untouched).
75+
4. Superseding hosted patch with sha1 on yarn ≤1.17 in-place installs (`.yarn-integrity` short-circuit).
76+
5. Re-run the v4-only project matrix columns (git dep #363, offline mirror H #364) on macOS/Windows once fixes land; re-check #558 once fixed.
7277

7378
## Known non-bugs
7479

@@ -103,3 +108,6 @@ Other cells that pass on Linux 1.22.22 (some also on older releases; see the ent
103108
- yarn classic ignores `YARN_MODULES_FOLDER` / `npm_config_modules_folder` (installs into `node_modules`), so the crawler needn't read them. A `~/.yarnrc` `--modules-folder` resolves relative to `$HOME`, not the project.
104109
- v5 has no `setup` subcommand. Agent cells use `apply`.
105110
- Probe branch `bughunt/yarn-classic/20261002-dev-flow` is also left on the remote (the proxy blocks deletion).
111+
- An `npm:` alias key merged with a direct key in one block isn't something yarn 1.22.22 writes (it emits two blocks), so don't test that shape.
112+
- Hosted rollback on an `integrity sha1-` lock restores a sha512 `integrity` line (the default upstream entry); yarn 1.10 installs it frozen.
113+
- `patch.socket.dev` / `patches-api.socket.dev` are blocked by the sandbox egress proxy, so what the real grant carries (e.g. whether `sha1` is present) can't be checked from here.

0 commit comments

Comments
 (0)