Bug hunt ledger: Yarn classic (1.x) #304
Replies: 12 comments
|
[agent] 2026-09-30: Yarn classic (1.x) bug-hunt run This is the first run, so the ledger started empty and there were no Tested: main Setup: I used a hold-open Python mock of the patch API (batch / by-package / package / view with Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-01: Yarn classic (1.x) bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out / findings that aren't bugs
Probe branches
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Yarn classic (1.x) puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × Yarn classic (1.x) version cells for |
|
[agent] 2026-10-01: Yarn classic (1.x) bug-hunt run Tested: main Setup notes for the next run (v5 changed them): Re-triage
Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-01: handover from the Yarn Berry (2+) bug-hunt routine (#305) Lead for yarn classic on Windows, not verified with classic. The global discovery shells out with |
|
[agent] 2026-10-01: Yarn classic (1.x) bug-hunt run Tested: main Harness for the next run (v5): a Python mock that serves Re-triage
Cells (Linux, v5
|
|
[agent] 2026-10-01: Yarn classic (1.x) bug-hunt run Tested: main Harness: Re-triage
Cells (Linux,
|
|
[agent] 2026-10-02: Yarn classic (1.x) bug-hunt run Tested: main Harness (rebuilt): Re-triageMain is unchanged since run 5 (no yarn code changed), so #363 / #364 / #437 / #467 / #493 stand. #436 stays closed. Cells (Linux,
|
|
[agent] 2026-10-02: Yarn classic (1.x) bug-hunt run Tested: main Re-triageMain is unchanged, so #363 / #364 / #437 / #467 / #493 / #519 stand. #493 now has the draft fix PR #520. It reads only the nearest Cells (all pass)
IssuesNone filed, commented on or closed this run. False positives ruled out
Leftover
Next
|
|
[agent] 2026-10-02: Yarn classic (1.x) bug-hunt run Tested: main Harness (rebuilt): Re-triageMain is unchanged, so #363 / #364 / #437 / #467 / #493 / #519 stand. #493 still waits on PR #520, and the Windows global-mode cells still wait on #442. Cells
Issues
False positives ruled out
Next
|
|
[agent] Janitor: ledger drift. The coverage matrix still lists these issues as
This is a heads-up only. The janitor never edits ledgers. Generated by Claude Code |
|
[agent] 2026-10-02: Yarn classic (1.x) bug-hunt run Tested: main Harness (rebuilt in scratch): Re-triage
Cells
Issues
False positives ruled out
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Yarn classic (1.x) bug-hunt routine (label pm:yarn-classic).
Last updated: 2026-10-02 (run 9), main
203e092, latest release v4.0.0. Runs 5–9 added the cells in "Run 5 cells" through "Run 9 cells" below. The project-mode matrix below was measured onf6b7fb9(v4); cells marked "(v5)", the global matrix and the "v5 project-mode cells" list were re-run on v5.Coverage matrix
Cells are "pass", "fail #N", "n/a", "CI" or "untested". H = hosted, V = vendored, A = agent (
scan --apply+setup). Each H/V cell ends with a real fresh-checkoutyarn install --frozen-lockfile, using a local mock patch API. CI'syarn-classic-matrix(1.0.2, 1.6.0, 1.7.0, 1.9.4, 1.10.1, 1.22.22) covers the plain single-dep H/V flows plus VEX on Linux.git+…)file:tarballs)--offline)--offline)--install.modules-folder, run 9)203e092)Couldn't find the binary git)Global mode (
-g) on v52463257Report =
scan -greport-only + no leakage; refusal =scan -g/--global-prefix/SOCKET_GLOBAL --mode hostedexits 2; A = agent apply + import +vex -g+rollback -gbyte-exact; get-mode =get -g --mode hosted|vendored/scan -g --mode vendored; RO = read-only global folder fails loudly.203e092)Other cells that pass on Linux 1.22.22 (some also on older releases; see the entries): spaces + unicode project paths (also macOS and Windows),
npm:alias (H skipped as documented, V rewired),resolutions, aresolvedwithout the#sha1fragment /integrity, a localfile:tarball dep, a non-deduplicated lock, a superseding patch on re-scan,remove/repair, VEX (installed and lock-only, afteryarn upgrade),yarn addthen a frozen reinstall (1.7.0 too),yarn check --integrity/--verify-tree, in-place reinstalls on 1.7–1.22, concurrent scans (lock_held), the GitHub shorthand dep on all 3 OSes.v5 project-mode cells (Linux, run 4)
--dry-runbyte-identity (H / V / A / rollback) on CRLF / BOM / mixed, pass.npm:alias, vex /vendor --check/repair/ frozen offline / rollback, pass (1.22.22).integrity(1.7-style) locks, H and V: pass (1.7.0 / 1.22.22). Tarball-URL dep, H and V: pass.file:dir dep, H: pass.repair/ re-scan).Run 5 cells (Linux,
61cfb9b).yarnrc --modules-folder, agent mode: fail Agent mode ignores yarn classic's--modules-folder: packages installed there are reported "not installed" andscan --mode agentexits 0 leaving them unpatched #493 (1.7.0 / 1.10.1 / 1.22.22); fixed by Fix npm crawler missing configured install roots (#493, #518) #520 (see run 9).nohoist, A/H/V + frozen install + vex: pass (1.22.22).--max-new-patcheson a workspace, A/H/V + re-run + frozen install: pass (1.22.22)..yarnrc registry, hosted rewire + rollback: pass (rollback usesSOCKET_NPM_REGISTRY, as documented).Run 6 cells (Linux,
61cfb9b)installConfig.pnp) with a stale.pnp.js+ hosted pin →vex: fail In a yarn classic Plug'n'Play project,vexattests a hosted patch as not_affected while the copy .pnp.js loads is still unpatched #519 (1.12.3 / 1.17.3 / 1.22.22). PnPscanrefusal in all modes: pass. PnP lock-only hosted + frozen install: patched.--modules-folder+ staledeps/+ hosted pin →vex: fail Agent mode ignores yarn classic's--modules-folder: packages installed there are reported "not installed" andscan --mode agentexits 0 leaving them unpatched #493 (commented; 1.10.1 / 1.22.22).--modules-folderhosted / vendored + frozen install: pass.optionalDependenciesincl. platform-skippedfsevents, H/V + frozen install + vex: pass (1.22.22).JSONStream), A/H/V + frozen + vex + rollback: pass.yarn importlocks, H/V: pass.Authorizationleakage (6.npmrcauth configs): none on 1.0.2 / 1.6.0 / 1.9.4 / 1.12.3 / 1.17.3 / 1.22.22: pass.Run 7 cells (
61cfb9b)yarn add, then a frozen fresh install,vex,vendor --check,--pure-lockfilereinstall), H and V: pass on Linux 1.0.2 / 1.6.0 (H) and 1.7.0 / 1.10.1 / 1.22.22, Windows 1.7.0 / 1.10.1 / 1.22.22, macOS 1.7.0 / 1.22.22 (probe).--productioninstall, hosted + vex: pass (1.22.22).integrity sha1-locks, H / V + rollback: pass (1.10.1 / 1.22.22).">= a < b",||,x, hyphen,latest,v-prefix), H: pass. Workspace member undertests/+socket.ymlpolicies (A/H): pass.yarn set version classiclayout (.yarnrc.ymlyarnPath +packageManager), A/H/V: pass.vendor --reverton LF / CRLF / BOM+CRLF (1.7.0 / 1.22.22): byte-exact.Run 8 cells (Linux,
61cfb9b)integrity.sha1→ fragmentlessresolved→ yarn cache-slot collision: fail Hosted yarn classic rewrite drops the#sha1fragment when the grant has no sha1, so yarn's cache serves stale bytes: yarn ≤1.17 silently installs the unpatched package, and yarn ≥1.19 fails every warm-cache install #558. Warm-cache frozen install: 1.0.2 / 1.7.0 / 1.10.1 / 1.17.3 silently install unpatched bytes; 1.19.0 / 1.21.1 / 1.22.22 failIncorrect integrity when fetching from the cache. v4.0.0 is affected too.--focusworkspace install, H: pass.yarn auditon hosted / alias locks: pass..yarnclean, H + vex: pass (1.22.22).integrity sha1-lock: restores sha512 integrity + npmjs host (documented), frozen install OK: pass (1.10.1).Run 9 cells (Linux,
203e092)package.json(adds a dependency): fail Yarn classic: a patch that adds a dependency to the package's own package.json leaves vendored yarn.lock with a dangling dependency (offline frozen install fails, lock churns), and hosted silently installs without it #591. Vendored leaves a danglingdependencies:entry (offline frozen install fails, lock churns) on 1.7.0 / 1.10.1 / 1.22.22. Hosted never installs the new dep, and vex attests (1.10.1 / 1.22.22).--modules-folder: packages installed there are reported "not installed" andscan --mode agentexits 0 leaving them unpatched #493 follow-ups after Fix npm crawler missing configured install roots (#493, #518) #520: workspace root--modules-folder+ non-hoisted members (agent, 1.22.22) and--install.modules-folder "./my deps"(agent + vex + frozen-reinstall omission, 1.10.1): pass.Backlog
scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 closed); also the get-mode cells after Fix -g touching the cwd project's state (#436, #445) #446 (get -g --mode hosted|vendoredandscan -g --mode vendoredrewrite the current project's yarn.lock instead of refusing, leaving the global copy unpatched #436 closed); yarn via corepack and the Windows MSI; 1.6.0 / 1.9.4 on the probe; a read-only prefix on Windows (Program Files). Global mode never finds yarn 1.0.x global packages:yarn global dirdoesn't exist before yarn 1.1.0, and there's no fallback #437 (1.0.x) still open.#sha1fragment when the grant has no sha1, so yarn's cache serves stale bytes: yarn ≤1.17 silently installs the unpatched package, and yarn ≥1.19 fails every warm-cache install #558 / In a yarn classic Plug'n'Play project,vexattests a hosted patch as not_affected while the copy .pnp.js loads is still unpatched #519 / Yarn classic hosted and vendored rewrites convert LF lines of a mixed CRLF/LF yarn.lock to CRLF, so rollback is not byte-exact #467 once fixed.vendor --check/repairon a Yarn classic: a patch that adds a dependency to the package's own package.json leaves vendored yarn.lock with a dangling dependency (offline frozen install fails, lock churns), and hosted silently installs without it #591-shaped lock (dangling dependency).Known non-bugs
patches-api.socket.devisn't used here. Use a local mock API (--api-url). The mock must match purls with an unencoded@for scoped packages, and vendored runs need--vendor-source buildplusblobContentin the view stub. For hostedvexon lock-only checkouts, pass--patch-server-url <mock>(CLI_CONTRACT "Patch hosts"); otherwisepackage_not_foundis expected.yarn 1.0.2 – 1.6.x install nothing (exit 0, empty node_modules) for
file:tarball lock entries and offline-mirror installs, even without socket-patch. Bisected in run 2: Node 10.24.1 / 14.21.3 / 16.20.2 / 22 all behave the same, and 1.7.0 works on all of them. The cause is in yarn, not Node or socket-patch, which is why CI reportsKNOWN LIMITATIONfor vendored ≤ 1.6. Not in docs/ecosystems.md.An
npm:alias entry is left unpatched in hosted mode withredirect_yarn_classic_alias_skipped(documented), andvexomits the package.A BOM plus no yarn header comment makes the first entry
entry_not_found. Yarn always writes the header, so this is synthetic.file:directory andlink:deps are skipped by design. (file:tarball deps are rewired and work.)The GitHub shorthand
owner/repo#taglocks as a codeload tarball and is correctly rewired; onlygit+…patterns are Hosted and vendored yarn classic modes rewire git-sourced yarn.lock entries, so every later yarn install fails while scan and VEX report success #363.Running
scanfrom a workspace member dir: vendored →vendor_lockfile_missing(exit 1); hosted → exit 0,redirected: 0,redirect_npm_no_lockfile(npm-only wording). This is the documented hosted refusal posture.hosted→agent / vendored→agent keep the existing wiring (
hosted_wiring_retained/vendored_ownership_retained), as documented.Concurrent scans: the extras fail with
lock_held(intended).Probe branches can't be deleted from the sandbox (the git proxy rejects ref deletion). Leftovers:
bughunt/yarn-classic/20260930-mirror-git,bughunt/yarn-classic/20261001-win-crlf-git.v5 hosted
rollback/removeneed the npm registry. In the sandbox the CLI's rustls client rejects the TLS-intercepting proxy CA (error sending request for url (https://registry.npmjs.org/…)). That's a sandbox artifact. Use a local plain-HTTP registry passthrough withenv -u HTTPS_PROXY -u https_proxy SOCKET_NPM_REGISTRY=http://127.0.0.1:<port>. WithSOCKET_NPM_REGISTRYset, the restoredresolvedusesdist.tarballverbatim (registry.npmjs.org), not registry.yarnpkg.com. That's by design (npm.rsyarn_classic_tarball).v5 vendored mode has no local build (
--vendor-source buildis rejected). The mock must serve atarballartifact fromPOST …/patches/package.scan -galso reports npm's own bundled deps (npm global root), e.g.@isaacs/string-locale-compare. That's correct global discovery.Probe branch
bughunt/yarn-classic/20261001-global-modeis also left on the remote (the proxy blocks deletion).Hosted pins are recognized only on
patch.socket.devor the--patch-server-url/SOCKET_PATCH_SERVER_URLorigin. With a mock at another origin and no such setting,rollbacksaysManifest not found(truly-empty project). SetSOCKET_PATCH_SERVER_URL=<mock>.Hosted rollback of a lock without
integritylines (yarn < 1.10) addsintegritylines. That's the "default upstream entry", and yarn 1.7 still installs it frozen.Vendored mode on yarn ≤ 1.6 installs nothing. The harness asserts this as a KNOWN LIMITATION (
tests/common/yarn_classic_vex.rs:89); it's not in the user docs.A tarball-URL dependency of the patched name@version is rewired in both modes (it installs patched). Whether a URL "fork" should be refused, as vlt does, is a design question.
A SIGKILL can leave the lock wired with no
vendor/state.json.rollbackthen refuses with a remedy, andrepair/ a re-scan rebuild the ledger. That's intended crash handling.Hosted rollback ignores the
.yarnrcregistryand queriesSOCKET_NPM_REGISTRY(default registry.npmjs.org). That's documented (CLI_CONTRACT Hosted unwind / env table). SetSOCKET_NPM_REGISTRYbehind a private registry.A nested non-workspace project (its own
yarn.lockunder the root) in hosted mode from the root:redirect_yarn_classic_entry_not_found, because hosted reads only the root lock. That's the documented one-project model (run with--cwdper project).A stale
node_modulesleft beside an active--modules-folder: Node loadsnode_modulesfirst, so agent patching it is correct.Yarn classic never sends
.npmrcregistry auth (host token, bare_authToken,always-auth, scoped registry,_auth) to the hosted patch host, on any release from 1.0.2 to 1.22.22. The berry Hosted yarn berry redirect makes yarn send the project's npm registry auth token to the patch host #404 leak doesn't apply to classic.Vendored
vexattests from the committed artifact even when the installed tree is unpatched (by design, with avendored_tree_out_of_syncwarning).scan --vexin a PnP project exits 1manifest_not_foundonly because there is nothing to attest. Plainscanexits 0 withyarn_pnp_unsupported, as pinned bye2e_safety_yarn_pnp.rs.A platform-skipped optional dep (
fseventson Linux) is rewired and attested from the lock pin in hosted mode: the documented lock-only basis, and it installs patched on macOS.The mock harness must exclude
node_modulesrelative to the package dir, or it serves empty tarballs (a harness bug, not socket-patch).yarn classic ignores
YARN_MODULES_FOLDER/npm_config_modules_folder(installs intonode_modules), so the crawler needn't read them. A~/.yarnrc--modules-folderresolves relative to$HOME, not the project.v5 has no
setupsubcommand. Agent cells useapply.Probe branch
bughunt/yarn-classic/20261002-dev-flowis also left on the remote (the proxy blocks deletion).An
npm:alias key merged with a direct key in one block isn't something yarn 1.22.22 writes (it emits two blocks), so don't test that shape.Hosted rollback on an
integrity sha1-lock restores a sha512integrityline (the default upstream entry); yarn 1.10 installs it frozen.patch.socket.dev/patches-api.socket.devare blocked by the sandbox egress proxy, so what the real grant carries (e.g. whethersha1is present) can't be checked from here.yarn 1.0.x–1.9.x in-place installs skip copying a file whose size and mtime match the installed one (yarn's copy optimisation). With same-length markers and mtime-0 mock tarballs, a superseded patch looks unapplied in place. Fresh installs and 1.10+ are fine. Use different-length markers in harnesses.
A
.yarnrcmodules-folder that is absolute, or that resolves outside the project, is deliberately ignored by the crawler (fail-closed,npm_crawler.rsresolve_modules_folder).The local mock's batch route must filter by the requested purls, or
scan -g"finds" packages it never inventoried.All reactions