Bug hunt ledger: Yarn classic (1.x) #304
Replies: 5 comments
|
[agent] 2026-09-30: Yarn classic (1.x) bug-hunt run This is the first run, so the ledger started empty and there were no Tested: main Setup: I used a hold-open Python mock of the patch API (batch / by-package / package / view with Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-01: Yarn classic (1.x) bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out / findings that aren't bugs
Probe branches
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Yarn classic (1.x) puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × Yarn classic (1.x) version cells for |
|
[agent] 2026-10-01: Yarn classic (1.x) bug-hunt run Tested: main Setup notes for the next run (v5 changed them): Re-triage
Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-01: handover from the Yarn Berry (2+) bug-hunt routine (#305) Lead for yarn classic on Windows, not verified with classic. The global discovery shells out with |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Yarn classic (1.x) bug-hunt routine (label pm:yarn-classic).
Last updated: 2026-10-01 (run 3), main
2463257(the v5 consolidation, #277), latest release v4.0.0. The project-mode matrix below was measured onf6b7fb9(v4); only the cells marked "(v5)" and the global matrix were re-run on v5.Coverage matrix
Cells are "pass", "fail #N", "n/a", "CI" or "untested". H = hosted, V = vendored, A = agent (
scan --apply+setup). Each H/V cell ends with a real fresh-checkoutyarn install --frozen-lockfile, using a local mock patch API. CI'syarn-classic-matrix(1.0.2, 1.6.0, 1.7.0, 1.9.4, 1.10.1, 1.22.22) covers the plain single-dep H/V flows plus VEX on Linux.git+…)file:tarballs)--offline)--offline)Couldn't find the binary git)Global mode (
-g) on v52463257Report =
scan -greport-only + no leakage; refusal =scan -g/--global-prefix/SOCKET_GLOBAL --mode hostedexits 2; A = agent apply + import +vex -g+rollback -gbyte-exact; get-mode =get -g --mode hosted|vendored/scan -g --mode vendored; RO = read-only global folder fails loudly.Other cells that pass on Linux 1.22.22 (some also on older releases; see the entries): spaces + unicode project paths (also macOS and Windows),
npm:alias (H skipped as documented, V rewired),resolutions, aresolvedwithout the#sha1fragment /integrity, a localfile:tarball dep, a non-deduplicated lock, a superseding patch on re-scan,remove/repair, VEX (installed and lock-only, afteryarn upgrade),yarn addthen a frozen reinstall (1.7.0 too),yarn check --integrity/--verify-tree, in-place reinstalls on 1.7–1.22, concurrent scans (lock_held), the GitHub shorthand dep on all 3 OSes.Backlog
scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 is fixed; yarn via corepack and the Windows MSI; 1.6.0 / 1.9.4 on the probe; a read-only prefix on Windows (Program Files).npm:alias, offline mirror,vendor --check,repair).vendor --revert(upstream-restore based) on CRLF locks and 1.9-style locks withoutintegrity: frozen-installable, CRLF preserved?packageManager,.yarnrc yarn-path) in vendored mode;socket.ymlfilters and--max-new-patcheson a yarn workspace.--dry-runbyte-identity on CRLF / BOM locks..yarnrc--install.frozen-lockfile true,--pure-lockfile,yarn importlocks;optionalDependencies/ platform-skipped packages in both modes and VEX.Known non-bugs
patches-api.socket.devisn't used here. Use a local mock API (--api-url). The mock must match purls with an unencoded@for scoped packages, and vendored runs need--vendor-source buildplusblobContentin the view stub. For hostedvexon lock-only checkouts, pass--patch-server-url <mock>(CLI_CONTRACT "Patch hosts"); otherwisepackage_not_foundis expected.file:tarball lock entries and offline-mirror installs, even without socket-patch. Bisected in run 2: Node 10.24.1 / 14.21.3 / 16.20.2 / 22 all behave the same, and 1.7.0 works on all of them. The cause is in yarn, not Node or socket-patch, which is why CI reportsKNOWN LIMITATIONfor vendored ≤ 1.6. Not in docs/ecosystems.md.npm:alias entry is left unpatched in hosted mode withredirect_yarn_classic_alias_skipped(documented), andvexomits the package.entry_not_found. Yarn always writes the header, so this is synthetic.file:directory andlink:deps are skipped by design. (file:tarball deps are rewired and work.)owner/repo#taglocks as a codeload tarball and is correctly rewired; onlygit+…patterns are Hosted and vendored yarn classic modes rewire git-sourced yarn.lock entries, so every later yarn install fails while scan and VEX report success #363.scanfrom a workspace member dir: vendored →vendor_lockfile_missing(exit 1); hosted → exit 0,redirected: 0,redirect_npm_no_lockfile(npm-only wording). This is the documented hosted refusal posture.hosted_wiring_retained/vendored_ownership_retained), as documented.lock_held(intended).bughunt/yarn-classic/20260930-mirror-git,bughunt/yarn-classic/20261001-win-crlf-git.rollback/removeneed the npm registry. In the sandbox the CLI's rustls client rejects the TLS-intercepting proxy CA (error sending request for url (https://registry.npmjs.org/…)). That's a sandbox artifact. Use a local plain-HTTP registry passthrough withenv -u HTTPS_PROXY -u https_proxy SOCKET_NPM_REGISTRY=http://127.0.0.1:<port>. WithSOCKET_NPM_REGISTRYset, the restoredresolvedusesdist.tarballverbatim (registry.npmjs.org), not registry.yarnpkg.com. That's by design (npm.rsyarn_classic_tarball).--vendor-source buildis rejected). The mock must serve atarballartifact fromPOST …/patches/package.scan -galso reports npm's own bundled deps (npm global root), e.g.@isaacs/string-locale-compare. That's correct global discovery.bughunt/yarn-classic/20261001-global-modeis also left on the remote (the proxy blocks deletion).All reactions