Repository navigation
Commit 203e092
* Start fix for #404
Assisted-by: Claude Code:claude-opus-5-5
* Stop yarn berry pins leaking npm auth tokens
Hosted mode pinned a patched yarn berry package as an npm: locator
(npm:<v>::__archiveUrl=<url>). Yarn fetches npm: locators with its
npm fetcher, which attaches the configured registry token
(npmAuthToken, YARN_NPM_AUTH_TOKEN, npmScopes) to every scoped
package request, and to every request under npmAlwaysAuth, so the
token was sent to the patch server on each cold install.
The lock now pins a plain tarball-URL locator (<name>@<url>). Yarn
fetches it with its tarball fetcher, which sends no registry auth
and builds the same cache zip, so the 10c0 checksum is unchanged and
--immutable still passes. Rollback, VEX and the mode takeovers keep
recognizing the old form, and the next hosted scan re-pins it. An
artifact URL yarn could not fetch as a tarball is refused instead of
written.
Fixes #404
Assisted-by: Claude Code:claude-opus-5-5
* Keep hosted berry pins in the lock inventory
Lock-only discovery skipped a berry entry whose resolution is a
tarball URL, so a package already pinned by hosted mode dropped out of
the inventory. Treat a tarball-URL resolution under npm: descriptor
keys as the registry package. Also refresh the redirect and VEX
goldens and the vendor takeover test for the new pin form.
WIP: yarn's hardened mode rejects this pin form (YN0078), see #465.
Assisted-by: Claude Code:claude-opus-5-5
* Pin yarn berry patches through resolutions
The tarball-URL pin stopped the registry token leak, but yarn's
hardened mode (on by default for public pull request CI) rejects a
tarball resolution under an npm: lock key (YN0078), breaking installs.
Hosted mode now pins a yarn berry package the way yarn itself does for
a root resolutions entry: package.json routes each locked descriptor
(name@npm:<range>) to the hosted tarball, and the lock entry is
re-keyed name@<url>, moved to yarn's sort order. Only that package's
descriptors move; other versions and other files stay untouched.
Rollback rebuilds the original key from those selectors and removes
them. A user-authored resolutions entry for the package, a missing
manifest, or a builtin patch: entry wrapping the same descriptor
refuse the pin instead of overwriting anything.
Other npm flavors are unchanged; package.json is only read beside a
yarn berry lock.
Assisted-by: Claude Code:claude-opus-5-5
* Cover the resolutions pin in goldens and docs
Lock-only inventory now keeps a berry entry keyed by its hosted
tarball, so already-pinned packages stay visible to later scans. The
yarn berry redirect goldens gain a root package.json and expect the
resolutions selectors plus the re-keyed entry; the VEX discovery
golden, the vendor takeover test and the docs, CLI contract and
changelog describe the new pin shape and its refusals.
Assisted-by: Claude Code:claude-opus-5-5
* Address review findings on berry pin
A yarn.lock entry already keyed by a tarball URL is now only treated
as ours when it points at the patch host or names the exact artifact.
A mirror tarball of the same version is left alone and refused as a
user resolution instead of being re-pinned.
VEX discovery no longer reports a hosted patch from a URL-keyed lock
entry unless package.json still routes the package there. A lock that
lost its resolutions entry is flagged as orphaned rather than counted
as patched, and a resolutions value on its own does not confirm a
redirect either.
The orphan refusal now tells users to restore yarn.lock and
package.json from version control, or delete the entry and reinstall.
Assisted-by: Claude Code:claude-opus-5-5
* Match berry lock keys on CRLF locks too
The real-yarn berry suites run on CRLF files on Windows, as yarn
writes them there. The new check that the lock entry is keyed by the
hosted tarball expected an LF right after the key, so it failed on
every Windows run even though the lock was rewritten correctly. The
check now compares whole lines with the CR stripped.
Assisted-by: Claude Code:claude-opus-5-5
* Confirm berry pins only with manifest routing
A hosted yarn berry pin is two edits: the lock entry keyed by the
patch tarball and the package.json resolutions entry that routes the
package to it. If the resolutions entry is removed, yarn no longer
installs the patch, but a rescan still counted the package as
redirected because the tarball URL was in yarn.lock. That fed the
in-run VEX, which then attested not_affected for an unpatched package.
The berry rewriter now reports which packages its lock pins and which
of those pins are complete, and hosted confirmation trusts only that
report for them. An orphaned lock entry is refused as before and is no
longer counted or attested.
Assisted-by: Claude Code:claude-opus-5-5
* Own berry deps only when the lock pins them
The berry rewriter claimed every npm patch as its own before looking
at yarn.lock. A grant without a yarnBerry10c0 checksum, or with a URL
yarn cannot fetch as a tarball, was then left owned but unconfirmed,
so hosted mode stopped counting a package the lock does not pin (and
that another lockfile may have rewritten).
Ownership is now taken only once the lock is known to pin the
package version. The checksum is required only when the entry has to
be rewritten, so a rescan with a checksumless grant still confirms a
pin an earlier run completed.
Assisted-by: Claude Code:claude-opus-5-5
* Harden berry pin writes and refused locks
A patch server URL containing "$" was expanded as a regex capture
reference when written into the berry lock entry, corrupting its
resolution and checksum lines. The URL is now written literally.
When the berry preflight refuses a lock (mixed line endings, an
unsupported cacheKey), packages that lock pins are still decided by
the berry rewriter, and left unconfirmed. Before, a URL from an
earlier run in such a lock could confirm the package through the
hosted text probe.
Assisted-by: Claude Code:claude-opus-5-5
* Clarify when the berry pin edits package.json
The npm lock rewriter now also reads the root package.json (#490), so
the contract says the berry pin is the one that edits it, not the only
reader.
Assisted-by: Claude Code:claude-opus-5-5
* Leave yarn berry fork aliases untouched
A lock entry keyed `left-pad@npm:other@^1.3.0` installs the package
`other` under the left-pad name. If that fork happened to be at the
patched version, the hosted rewrite re-keyed it to the left-pad
tarball, replacing the user's fork with the patched package. Fork
aliases are now skipped and do not make the real entry ambiguous.
Assisted-by: Claude Code:claude-opus-5-5
---------
Co-authored-by: Claude <noreply@anthropic.com>
1 parent 9d81139 commit 203e092
49 files changed
Lines changed: 2677 additions & 514 deletions
File tree
- crates
- socket-patch-cli
- src/commands/scan
- tests
- yarn_berry_common
- socket-patch-core
- src
- hosted
- patch/redirect
- upstream
- vendor
- lock_inventory
- vex/discover
- tests
- equivalence
- fixtures
- redirect/npm/yarn-berry
- basic
- expected
- input
- cachekey-mismatch-refusal/input
- existing-archive-url
- expected
- input
- missing-berry-checksum/input
- multi-descriptor-key
- expected
- input
- multiple-versions
- expected
- input
- rerun-noop/input
- scoped-package
- expected
- input
- yarnrc-compression-refusal/input
- vex-discover-golden
- docs
- testing
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
169 | 169 | | |
170 | 170 | | |
171 | 171 | | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
172 | 181 | | |
173 | 182 | | |
174 | 183 | | |
| |||
Large diffs are not rendered by default.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4343 | 4343 | | |
4344 | 4344 | | |
4345 | 4345 | | |
| 4346 | + | |
| 4347 | + | |
| 4348 | + | |
| 4349 | + | |
| 4350 | + | |
| 4351 | + | |
| 4352 | + | |
| 4353 | + | |
| 4354 | + | |
| 4355 | + | |
| 4356 | + | |
| 4357 | + | |
| 4358 | + | |
| 4359 | + | |
| 4360 | + | |
| 4361 | + | |
| 4362 | + | |
| 4363 | + | |
| 4364 | + | |
| 4365 | + | |
| 4366 | + | |
| 4367 | + | |
| 4368 | + | |
| 4369 | + | |
| 4370 | + | |
| 4371 | + | |
4346 | 4372 | | |
4347 | 4373 | | |
4348 | 4374 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1467 | 1467 | | |
1468 | 1468 | | |
1469 | 1469 | | |
| 1470 | + | |
| 1471 | + | |
| 1472 | + | |
1470 | 1473 | | |
1471 | 1474 | | |
1472 | 1475 | | |
1473 | 1476 | | |
1474 | | - | |
1475 | | - | |
1476 | | - | |
| 1477 | + | |
| 1478 | + | |
| 1479 | + | |
1477 | 1480 | | |
1478 | | - | |
1479 | | - | |
| 1481 | + | |
| 1482 | + | |
1480 | 1483 | | |
1481 | 1484 | | |
1482 | 1485 | | |
| |||
1497 | 1500 | | |
1498 | 1501 | | |
1499 | 1502 | | |
1500 | | - | |
| 1503 | + | |
1501 | 1504 | | |
1502 | 1505 | | |
1503 | 1506 | | |
| |||
1582 | 1585 | | |
1583 | 1586 | | |
1584 | 1587 | | |
1585 | | - | |
| 1588 | + | |
| 1589 | + | |
| 1590 | + | |
| 1591 | + | |
| 1592 | + | |
| 1593 | + | |
1586 | 1594 | | |
1587 | 1595 | | |
1588 | 1596 | | |
| |||
1600 | 1608 | | |
1601 | 1609 | | |
1602 | 1610 | | |
1603 | | - | |
| 1611 | + | |
| 1612 | + | |
1604 | 1613 | | |
| 1614 | + | |
1605 | 1615 | | |
1606 | 1616 | | |
1607 | 1617 | | |
| |||
Lines changed: 103 additions & 15 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
6 | | - | |
7 | | - | |
| 6 | + | |
| 7 | + | |
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
20 | 20 | | |
21 | | - | |
| 21 | + | |
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
26 | | - | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
27 | 30 | | |
28 | | - | |
| 31 | + | |
29 | 32 | | |
30 | 33 | | |
31 | 34 | | |
| |||
267 | 270 | | |
268 | 271 | | |
269 | 272 | | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
270 | 276 | | |
271 | 277 | | |
272 | 278 | | |
| |||
286 | 292 | | |
287 | 293 | | |
288 | 294 | | |
289 | | - | |
| 295 | + | |
290 | 296 | | |
291 | 297 | | |
292 | 298 | | |
| |||
347 | 353 | | |
348 | 354 | | |
349 | 355 | | |
| 356 | + | |
350 | 357 | | |
351 | 358 | | |
352 | 359 | | |
| |||
549 | 556 | | |
550 | 557 | | |
551 | 558 | | |
552 | | - | |
| 559 | + | |
| 560 | + | |
| 561 | + | |
553 | 562 | | |
554 | | - | |
555 | 563 | | |
556 | | - | |
557 | | - | |
| 564 | + | |
| 565 | + | |
| 566 | + | |
| 567 | + | |
| 568 | + | |
| 569 | + | |
| 570 | + | |
| 571 | + | |
| 572 | + | |
| 573 | + | |
| 574 | + | |
| 575 | + | |
| 576 | + | |
| 577 | + | |
| 578 | + | |
| 579 | + | |
| 580 | + | |
| 581 | + | |
| 582 | + | |
| 583 | + | |
| 584 | + | |
| 585 | + | |
558 | 586 | | |
559 | 587 | | |
560 | 588 | | |
| |||
579 | 607 | | |
580 | 608 | | |
581 | 609 | | |
| 610 | + | |
582 | 611 | | |
583 | 612 | | |
584 | 613 | | |
| |||
598 | 627 | | |
599 | 628 | | |
600 | 629 | | |
601 | | - | |
| 630 | + | |
| 631 | + | |
| 632 | + | |
| 633 | + | |
| 634 | + | |
602 | 635 | | |
603 | 636 | | |
604 | 637 | | |
| |||
619 | 652 | | |
620 | 653 | | |
621 | 654 | | |
| 655 | + | |
| 656 | + | |
| 657 | + | |
| 658 | + | |
| 659 | + | |
| 660 | + | |
| 661 | + | |
622 | 662 | | |
623 | 663 | | |
624 | 664 | | |
625 | 665 | | |
626 | 666 | | |
| 667 | + | |
| 668 | + | |
| 669 | + | |
| 670 | + | |
| 671 | + | |
| 672 | + | |
| 673 | + | |
| 674 | + | |
| 675 | + | |
| 676 | + | |
| 677 | + | |
| 678 | + | |
| 679 | + | |
| 680 | + | |
| 681 | + | |
| 682 | + | |
| 683 | + | |
| 684 | + | |
| 685 | + | |
| 686 | + | |
| 687 | + | |
| 688 | + | |
| 689 | + | |
| 690 | + | |
| 691 | + | |
| 692 | + | |
| 693 | + | |
| 694 | + | |
| 695 | + | |
| 696 | + | |
| 697 | + | |
| 698 | + | |
| 699 | + | |
| 700 | + | |
| 701 | + | |
| 702 | + | |
| 703 | + | |
| 704 | + | |
| 705 | + | |
| 706 | + | |
| 707 | + | |
| 708 | + | |
| 709 | + | |
| 710 | + | |
627 | 711 | | |
628 | 712 | | |
629 | 713 | | |
630 | 714 | | |
631 | 715 | | |
632 | 716 | | |
633 | 717 | | |
634 | | - | |
| 718 | + | |
| 719 | + | |
| 720 | + | |
| 721 | + | |
635 | 722 | | |
636 | 723 | | |
637 | 724 | | |
| |||
698 | 785 | | |
699 | 786 | | |
700 | 787 | | |
| 788 | + | |
701 | 789 | | |
702 | 790 | | |
703 | 791 | | |
| |||
706 | 794 | | |
707 | 795 | | |
708 | 796 | | |
709 | | - | |
| 797 | + | |
710 | 798 | | |
711 | 799 | | |
712 | 800 | | |
| |||
740 | 828 | | |
741 | 829 | | |
742 | 830 | | |
743 | | - | |
| 831 | + | |
744 | 832 | | |
745 | 833 | | |
746 | 834 | | |
| |||
0 commit comments