Bug hunt ledger: Yarn Berry (2+) #305
Replies: 9 comments
|
[agent] 2026-09-30: Yarn Berry (2+) bug-hunt run Tested: main This is the first run: no earlier ledger, and no Cells
Issues
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Yarn Berry (2+) puts global installs: Berry has no What to check (prove each with a real global install, not by reading source):
Add OS × Yarn Berry (2+) version cells for |
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells (global mode)
Observations not filed
Probe branches
Next
|
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Harness, new this run: the Python patch-API mock now also serves the v5 vendoring service. Re-triage
Cells
Ruled out
Next
|
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells
Ruled out
Harness notes
Next
|
|
[agent] 2026-10-02: handover from the Yarn classic (1.x) bug-hunt routine (#304) Lead for yarn berry PnP, not verified with berry. In a yarn classic PnP project, standalone |
|
[agent] 2026-10-02: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Handover from yarn-classic (#519)
Cells (Linux)
Ruled out
Unconfirmed lead (not filed)
Next
|
|
[agent] 2026-10-02: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Filed
Cells (Linux)
Ruled out
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Yarn Berry (2+) bug-hunt routine (label pm:yarn-berry).
Last updated: 2026-10-02 (run 7), main
61cfb9b(CLI still reports 4.0.0), latest release 4.0.0 (previous 3.3.0).Harness: yarn bundles come from npm
@yarnpkg/cli-dist@<v>(node package/bin/yarn.js), because corepack's fetch can't use the sandbox proxy. Yarn 4 needsYARN_HTTPS_CA_FILE_PATH; yarn 2/3 needYARN_CA_FILE_PATH. The npm registry has 2.4.2 as the last 2.x in cli-dist. Agent and vendored cells hand-stage.socket/manifest.jsonplus blobs (a marker prepended toindex.js). Hosted cells use a local Python mock (fresh-checkout copies must keep.socket/for vendored cells) of the patch API (batch, by-package,patches/packagewith ayarn-berry-zipyarnBerry10c0artifact,view, and the tarball route). The 10c0 checksum is bootstrapped with a real yarnresolutions: file:install. Every hosted and vendored cell ends in a fresh-checkoutyarn install --immutable. v5: hosted rollback/remove need the mock's/upstream/npm/<uuid>.jsonroute,SOCKET_NPM_REGISTRYpointed at a local registry passthrough (the rustls binary can't use the sandbox proxy CA), and--patch-server-url <mock>so the pins count as hosted. Global (-g) cells use real npm global installs (NPM_CONFIG_PREFIX) and a Python mock of the authenticated API (--api-url <mock> --api-token x --org org; blob route/v0/orgs/org/patches/blob/<sha256>). v5 vendored mode downloads from the vendoring service: the same mock's/patches/packagewith a grantedtarballartifact (real sha512) is enough, and an optional per-patchstatusoverride (for examplepending_build) is supported. Acorepackshim (corepack yarn@X→node <cli-dist X>/bin/yarn.js, setting the CA env itself because the harness scrubsYARN_*) runs the repo's berry e2e suites in the sandbox (SOCKET_PATCH_YARN_E2E_REQUIRED=1,SOCKET_PATCH_YARN_BERRY_VERSION=<v>).setupwas removed in v5. On GH runners, fixture installs needYARN_ENABLE_IMMUTABLE_INSTALLS=false(CI turns immutable on).Coverage matrix
Cells are "pass", "fail #N", "refused (by design)" or "untested". Linker is node-modules unless noted.
redirect_yarn_berry_cache_unsupported.store, real dirs), apply/vex/rollback byte-exactvendor_yarn_berry_cache_unsupported.store/<slug>/package); repo e2e suites pass--check-cache,--revertbyte-exact); PnP lock-only checkout vendors and loads patched bytes, but re-run after install fails #539 (also 4.0.2, 4.18.1); zero-install committed cache → YN0056 (docs gap). package.json tab / 4-space / BOM / CRLF+tab / no trailing newline / existing or emptyresolutions(fresh immutable +--revertbyte-exact); mixed-EOL yarn.lock refused loudly (vendor_yarn_berry_mixed_line_endings). pass on f6b7fb9: root, scoped root name, scoped target,**/glob resolution, workspaces, pnpm linker, re-run idempotent,--revert, in-place immutable install. pass on v5: root, workspaces +enableImmutableInstalls: true(--revertandremovebyte-exact), CRLF lock + package.json. Refused (by design): resolve/typescript (patch:builtin), yarn 3. fail #370 (commented compressionLevel). fail #369 (hosted→vendored viascan/get --mode vendored;vendoritself is fixed on v5). fail #468 (vendored→hosted with noyarnBerry10c0)npm:^1.3.0, dev-only and optional-only descriptors; v5 main:npm:1.3.0/npm:^1.3.0descriptors, dev-only and optional-only deps, mixed-case nameJSONStream(case-kept purl, also on 4.18.1), mixed-EOL lock refused loudly, scoped, CRLF, workspaces merged-range, re-scan idempotent, manifest-less rollback/remove/list byte-exact, PnP lock-only checkout, upgrade path (uuid A→B re-pin, then rollback byte-exact), hardened mode accepts__archiveUrlpins, vendored→hosted takeover (checksum present;pending_buildstays vendored). fail #368 (resolve, typescript, useryarn patch). fail #404 (registry token sent to patch host). fail #369 (hosted→vendored takeover). fail #370. Refused (by design): PnP (yarn_pnp_unsupported), direct + alias merged entry (redirect_yarn_berry_ambiguous_entry). PnP stale.pnp.cjs+ hosted pin → standalonevexattests unpatched copy: fail #519 (yarn-classic issue; berry evidence commented, also 4.0.2 and 4.18.1)version: 10); fail #368; fail #370; fail #404; fail #468Global (
-g) cells. Berry has no global dir, so these are npm-prefix globals scanned from inside or outside a Berry project:globalscript runs); otherwise pass, no project leak (node-modules, pnpm, PnP)not_appliedafter reinstall, EACCES loud,--global-prefixwith space and unicode).cmdshim not run)Backlog
bughunt/yarn-berry/20260930-builtin-patch-takeoverandbughunt/yarn-berry/20261001-global-scriptneed deleting by hand. After that, probe Yarn 4 pnpm linker: transitive packages that live only in node_modules/.store are "not installed" in agent mode and stay unpatched #495 (Windows junctions), Vendored → hosted takeover on yarn berry deletes the vendored patch, then skips the hosted rewrite when the grant has no yarnBerry10c0 checksum, and still exits 0 "fully hosted" #468, Hosted → vendored takeover on yarn berry reverts the hosted redirect before a per-package vendor refusal, leaving the package unpatched in both modes #369 and Vendored yarn berry PnP refusal keys only on .pnp.cjs: a lock-only PnP checkout vendors successfully, then every re-run in an installed checkout fails exit 1 with vendor_yarn_berry_unsupported #539 on macOS/Windows.compressionLevel: 0 # commentin .yarnrc.yml as a non-default compression level #370), Fix yarn berry hosted pin leaking npm auth (#404) #465 (Hosted yarn berry redirect makes yarn send the project's npm registry auth token to the patch host #404), Fix global PM probes spawning bare names from the project (#421, #434, #438, #440) #442 (scan -ginside a Yarn Berry project runs the project'sglobalpackage.json script and scans whatever directory it prints as a global install #440), Fix npm crawler missing Bun, Deno and Yarn 4 stores (#366, #373, #405, #495) #496 (Yarn 4 pnpm linker: transitive packages that live only in node_modules/.store are "not installed" in agent mode and stay unpatched #495). Hosted yarn berry redirect of resolve/typescript (yarn builtin compat patch) reports success, then everyyarn install --immutablefails YN0028 #368 and Vendored yarn berry PnP refusal keys only on .pnp.cjs: a lock-only PnP checkout vendors successfully, then every re-run in an installed checkout fails exit 1 with vendor_yarn_berry_unsupported #539 have no PR yet.-g) mode. Linux is covered (see the global table). Remaining: macOS and Windows-gapply/rollback/vex and the hosted refusal (probe), and a version-manager prefix (nvm/volta under$HOME). Full checklist in the 20261001T040000Z entry.pkg:npm/jsonstream@1.3.5) for a mixed-case package is missed by every mode (agent skips with exit 1; hosted/vendored*_entry_not_found). File it (cross-PM, npm crawler) only if the real API is shown to lower-case.npmRegistryServerplusnpmAlwaysAuthfor hosted (Hosted yarn berry redirect makes yarn send the project's npm registry auth token to the patch host #404 follow-up).Known non-bugs
.pnp.cjsare refused in every mode withyarn_pnp_unsupported(documented).resolve,typescript,fsevents) is refused fail-closed withvendor_override_conflict. It's loud and closed, so it isn't filed (the hosted counterpart is Hosted yarn berry redirect of resolve/typescript (yarn builtin compat patch) reports success, then everyyarn install --immutablefails YN0028 #368).npm:alias ("left-pad@npm:1.3.0, lp@npm:left-pad@1.3.0") withredirect_yarn_berry_ambiguous_entryand exit 1. It's fail-closed and loud; arguably over-broad, but not filed.yarn install --immutablein the same tree doesn't restore unpatched bytes (yarn's install-state), and the setup hook re-patches after a clean install. Standalonevexin agent mode needssetuporsetup.manual(documented).patches-api.socket.devis unreachable from the sandbox; use the mock.yarn install --immutable(YN0028) on its own, because yarn strips the BOM. Not caused by socket-patch.npm:alias-only entry →redirect_yarn_berry_alias_skipped(documented in docs/ecosystems.md).scan <workspace-member-dir>finds 0 packages: hosted/vendored PATHs are project dirs, and members share the root's lock (CLI_CONTRACT "exclude it with ignorePackages, not paths")..pnp.cjs: scan reports 0 packages with a PnP warning (same in 4.0.0). A PnP lock-only checkout gets hosted pins, and those install correctly under PnP.patch.socket.dev(or--patch-server-url) URLs as hosted pins. Without that flag, a mock host reads as "Manifest not found"..pnp.js) and 3.x is detected and gets the loud PnP warning in every mode, exit 0 (same as 4.x).scan -g --mode agent) after a failed apply (EACCES) exits 0 with "already recorded … runsocket-patch apply". This is the designed re-run message;apply -gitself exits 1.scan -gdoesn't mention-g. It's cross-PM and was handed to npm (Bug hunt ledger: npm #302), so it isn't filed here.enableHardenedMode, auto-on for public fork PRs in GitHub Actions) accepts a hosted::__archiveUrl=lock pin, as does--check-resolutions(4.12.0, registry reachable).enableGlobalCache: falsewith.yarn/cachecommitted): hosted mode is lock-only, so the committed cache keeps the unpatched zip, andyarn install --immutable --immutable-cachefails YN0056 untilyarn installrefreshes the cache. Vendored mode behaves the same way (thefile:entry has no cache zip; no warning). It's a docs gap, not filed.compressionLevelset outside the project.yarnrc.yml(env, home or parent rc) can't cause a wrong checksum: yarn bakes the level into the lock'scacheKey, which both modes gate on.yarn patch(patch:descriptor) withvendor_override_conflict, plus an alias-only dependency (root or workspace member) withvendor_lock_entry_not_found, a merged direct + alias entry, and a user-authoredresolutionskey for the target. All are loud and closed with nothing written, so none are filed.yarn.lockis refused by vendored (vendor_yarn_berry_mixed_line_endings) and hosted (redirect_yarn_berry_mixed_line_endings). That's correct: yarn itself fails YN0028 on such a lock.rollbackdrops the patch's manifest entry, so a laterapplyis a no-op (designed).package.json. Vendored snapshots the post-install bytes and reverts to them byte-exactly.All reactions