Bug hunt ledger: Yarn Berry (2+) #305
Replies: 4 comments
|
[agent] 2026-09-30: Yarn Berry (2+) bug-hunt run Tested: main This is the first run: no earlier ledger, and no Cells
Issues
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Yarn Berry (2+) puts global installs: Berry has no What to check (prove each with a real global install, not by reading source):
Add OS × Yarn Berry (2+) version cells for |
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells (global mode)
Observations not filed
Probe branches
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Yarn Berry (2+) bug-hunt routine (label pm:yarn-berry).
Last updated: 2026-10-01 (run 3), main
2463257(v5 consolidation #277; CLI still reports 4.0.0), latest release 4.0.0 (previous 3.3.0).Harness: yarn bundles come from npm
@yarnpkg/cli-dist@<v>(node package/bin/yarn.js), because corepack's fetch can't use the sandbox proxy. Yarn 4 needsYARN_HTTPS_CA_FILE_PATH; yarn 2/3 needYARN_CA_FILE_PATH. The npm registry has 2.4.2 as the last 2.x in cli-dist. Agent and vendored cells hand-stage.socket/manifest.jsonplus blobs (a marker prepended toindex.js). Hosted cells use a local Python mock of the patch API (batch, by-package,patches/packagewith ayarn-berry-zipyarnBerry10c0artifact,view, and the tarball route). The 10c0 checksum is bootstrapped with a real yarnresolutions: file:install. Every hosted and vendored cell ends in a fresh-checkoutyarn install --immutable. v5: hosted rollback/remove need the mock's/upstream/npm/<uuid>.jsonroute,SOCKET_NPM_REGISTRYpointed at a local registry passthrough (the rustls binary can't use the sandbox proxy CA), and--patch-server-url <mock>so the pins count as hosted. Global (-g) cells use real npm global installs (NPM_CONFIG_PREFIX) and a Python mock of the authenticated API (--api-url <mock> --api-token x --org org; blob route/v0/orgs/org/patches/blob/<sha256>). v5 vendored mode downloads from a vendoring service (--vendor-url); that mock isn't built yet.setupwas removed in v5. On GH runners, fixture installs needYARN_ENABLE_IMMUTABLE_INSTALLS=false(CI turns immutable on).Coverage matrix
Cells are "pass", "fail #N", "refused (by design)" or "untested". Linker is node-modules unless noted.
redirect_yarn_berry_cache_unsupportedvendor_yarn_berry_cache_unsupported**/glob resolution, workspaces, pnpm linker, re-run idempotent,--revert, in-place immutable install. Refused (by design): resolve/typescript (patch:builtin), yarn 3. fail #370 (commented compressionLevel)yarn patch). fail #404 (registry token sent to patch host). fail #369 (hosted→vendored takeover). fail #370. Refused (by design): PnP (yarn_pnp_unsupported), direct + alias merged entry (redirect_yarn_berry_ambiguous_entry)version: 10); fail #368; fail #370; fail #404Global (
-g) cells. Berry has no global dir, so these are npm-prefix globals scanned from inside or outside a Berry project:globalscript runs); otherwise pass, no project leak (node-modules, pnpm, PnP)not_appliedafter reinstall, EACCES loud,--global-prefixwith space and unicode).cmdshim not run)Backlog
-g) mode. Linux is covered (see the global table). Remaining: macOS and Windows-gapply/rollback/vex and the hosted refusal (probe), and a version-manager prefix (nvm/volta under$HOME). Full checklist in the 20261001T040000Z entry.--vendor-url) and re-run the v5 vendored cells, Hosted → vendored takeover on yarn berry reverts the hosted redirect before a per-package vendor refusal, leaving the package unpatched in both modes #369 and the takeovers (Hosted → vendored takeover on yarn berry reverts the hosted redirect before a per-package vendor refusal, leaving the package unpatched in both modes #369 hasn't been re-checked on v5).npmRegistryServerset to a private registry plusnpmAlwaysAuth./upstreammetadata..yarn/cacheafter hosted/rollback (stale zips,--immutable-cache).compressionLevelfromYARN_COMPRESSION_LEVEL/~/.yarnrc.yml/ a parent rc; a quoted key.enableImmutableInstalls: truewith rollback/remove on workspaces.bughunt/yarn-berry/20260930-builtin-patch-takeoverandbughunt/yarn-berry/20261001-global-script: the git proxy refuses deletes (HTTP 403). A maintainer needs to delete them.Known non-bugs
.pnp.cjsare refused in every mode withyarn_pnp_unsupported(documented).resolve,typescript,fsevents) is refused fail-closed withvendor_override_conflict. It's loud and closed, so it isn't filed (the hosted counterpart is Hosted yarn berry redirect of resolve/typescript (yarn builtin compat patch) reports success, then everyyarn install --immutablefails YN0028 #368).npm:alias ("left-pad@npm:1.3.0, lp@npm:[email protected]") withredirect_yarn_berry_ambiguous_entryand exit 1. It's fail-closed and loud; arguably over-broad, but not filed.yarn install --immutablein the same tree doesn't restore unpatched bytes (yarn's install-state), and the setup hook re-patches after a clean install. Standalonevexin agent mode needssetuporsetup.manual(documented).patches-api.socket.devis unreachable from the sandbox; use the mock.yarn install --immutable(YN0028) on its own, because yarn strips the BOM. Not caused by socket-patch.npm:alias-only entry →redirect_yarn_berry_alias_skipped(documented in docs/ecosystems.md).scan <workspace-member-dir>finds 0 packages: hosted/vendored PATHs are project dirs, and members share the root's lock (CLI_CONTRACT "exclude it with ignorePackages, not paths")..pnp.cjs: scan reports 0 packages with a PnP warning (same in 4.0.0). A PnP lock-only checkout gets hosted pins, and those install correctly under PnP.patch.socket.dev(or--patch-server-url) URLs as hosted pins. Without that flag, a mock host reads as "Manifest not found"..pnp.js) and 3.x is detected and gets the loud PnP warning in every mode, exit 0 (same as 4.x).scan -g --mode agent) after a failed apply (EACCES) exits 0 with "already recorded … runsocket-patch apply". This is the designed re-run message;apply -gitself exits 1.scan -gdoesn't mention-g. It's cross-PM and was handed to npm (Bug hunt ledger: npm #302), so it isn't filed here.All reactions