Bug hunt ledger: Yarn Berry (2+) #305
Replies: 6 comments
|
[agent] 2026-09-30: Yarn Berry (2+) bug-hunt run Tested: main This is the first run: no earlier ledger, and no Cells
Issues
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Yarn Berry (2+) puts global installs: Berry has no What to check (prove each with a real global install, not by reading source):
Add OS × Yarn Berry (2+) version cells for |
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells (global mode)
Observations not filed
Probe branches
Next
|
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Harness, new this run: the Python patch-API mock now also serves the v5 vendoring service. Re-triage
Cells
Ruled out
Next
|
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells
Ruled out
Harness notes
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Yarn Berry (2+) bug-hunt routine (label pm:yarn-berry).
Last updated: 2026-10-01 (run 5), main
61cfb9b(CLI still reports 4.0.0), latest release 4.0.0 (previous 3.3.0).Harness: yarn bundles come from npm
@yarnpkg/cli-dist@<v>(node package/bin/yarn.js), because corepack's fetch can't use the sandbox proxy. Yarn 4 needsYARN_HTTPS_CA_FILE_PATH; yarn 2/3 needYARN_CA_FILE_PATH. The npm registry has 2.4.2 as the last 2.x in cli-dist. Agent and vendored cells hand-stage.socket/manifest.jsonplus blobs (a marker prepended toindex.js). Hosted cells use a local Python mock of the patch API (batch, by-package,patches/packagewith ayarn-berry-zipyarnBerry10c0artifact,view, and the tarball route). The 10c0 checksum is bootstrapped with a real yarnresolutions: file:install. Every hosted and vendored cell ends in a fresh-checkoutyarn install --immutable. v5: hosted rollback/remove need the mock's/upstream/npm/<uuid>.jsonroute,SOCKET_NPM_REGISTRYpointed at a local registry passthrough (the rustls binary can't use the sandbox proxy CA), and--patch-server-url <mock>so the pins count as hosted. Global (-g) cells use real npm global installs (NPM_CONFIG_PREFIX) and a Python mock of the authenticated API (--api-url <mock> --api-token x --org org; blob route/v0/orgs/org/patches/blob/<sha256>). v5 vendored mode downloads from the vendoring service: the same mock's/patches/packagewith a grantedtarballartifact (real sha512) is enough, and an optional per-patchstatusoverride (for examplepending_build) is supported. Acorepackshim (corepack yarn@X→node <cli-dist X>/bin/yarn.js, setting the CA env itself because the harness scrubsYARN_*) runs the repo's berry e2e suites in the sandbox (SOCKET_PATCH_YARN_E2E_REQUIRED=1,SOCKET_PATCH_YARN_BERRY_VERSION=<v>).setupwas removed in v5. On GH runners, fixture installs needYARN_ENABLE_IMMUTABLE_INSTALLS=false(CI turns immutable on).Coverage matrix
Cells are "pass", "fail #N", "refused (by design)" or "untested". Linker is node-modules unless noted.
redirect_yarn_berry_cache_unsupported.store, real dirs)vendor_yarn_berry_cache_unsupported.store/<slug>/package); repo e2e suites pass**/glob resolution, workspaces, pnpm linker, re-run idempotent,--revert, in-place immutable install. pass on v5: root, workspaces +enableImmutableInstalls: true(--revertandremovebyte-exact), CRLF lock + package.json. Refused (by design): resolve/typescript (patch:builtin), yarn 3. fail #370 (commented compressionLevel). fail #369 (hosted→vendored viascan/get --mode vendored;vendoritself is fixed on v5). fail #468 (vendored→hosted with noyarnBerry10c0)__archiveUrlpins, vendored→hosted takeover (checksum present;pending_buildstays vendored). fail #368 (resolve, typescript, useryarn patch). fail #404 (registry token sent to patch host). fail #369 (hosted→vendored takeover). fail #370. Refused (by design): PnP (yarn_pnp_unsupported), direct + alias merged entry (redirect_yarn_berry_ambiguous_entry)version: 10); fail #368; fail #370; fail #404; fail #468Global (
-g) cells. Berry has no global dir, so these are npm-prefix globals scanned from inside or outside a Berry project:globalscript runs); otherwise pass, no project leak (node-modules, pnpm, PnP)not_appliedafter reinstall, EACCES loud,--global-prefixwith space and unicode).cmdshim not run)Backlog
-g) mode. Linux is covered (see the global table). Remaining: macOS and Windows-gapply/rollback/vex and the hosted refusal (probe), and a version-manager prefix (nvm/volta under$HOME). Full checklist in the 20261001T040000Z entry.vexandrollbackfor a pnpm-linker store-only transitive dep.scan --mode vendored) on macOS and Windows.package.jsonwith a BOM, tabs or 4-space indent,resolutionsround-trip, revert byte-exact.redirect_yarn_berry_entry_not_found, scoped packages); vendored on the pnpm linker and a PnP lock-only checkout on v5.npmRegistryServerplusnpmAlwaysAuth. Re-triagescan -ginside a Yarn Berry project runs the project'sglobalpackage.json script and scans whatever directory it prints as a global install #440 when PR Fix global PM probes spawning bare names from the project (#421, #434, #438, #440) #442 lands.bughunt/yarn-berry/20260930-builtin-patch-takeoverandbughunt/yarn-berry/20261001-global-script: the git proxy refuses deletes (HTTP 403). A maintainer needs to delete them.Known non-bugs
.pnp.cjsare refused in every mode withyarn_pnp_unsupported(documented).resolve,typescript,fsevents) is refused fail-closed withvendor_override_conflict. It's loud and closed, so it isn't filed (the hosted counterpart is Hosted yarn berry redirect of resolve/typescript (yarn builtin compat patch) reports success, then everyyarn install --immutablefails YN0028 #368).npm:alias ("left-pad@npm:1.3.0, lp@npm:[email protected]") withredirect_yarn_berry_ambiguous_entryand exit 1. It's fail-closed and loud; arguably over-broad, but not filed.yarn install --immutablein the same tree doesn't restore unpatched bytes (yarn's install-state), and the setup hook re-patches after a clean install. Standalonevexin agent mode needssetuporsetup.manual(documented).patches-api.socket.devis unreachable from the sandbox; use the mock.yarn install --immutable(YN0028) on its own, because yarn strips the BOM. Not caused by socket-patch.npm:alias-only entry →redirect_yarn_berry_alias_skipped(documented in docs/ecosystems.md).scan <workspace-member-dir>finds 0 packages: hosted/vendored PATHs are project dirs, and members share the root's lock (CLI_CONTRACT "exclude it with ignorePackages, not paths")..pnp.cjs: scan reports 0 packages with a PnP warning (same in 4.0.0). A PnP lock-only checkout gets hosted pins, and those install correctly under PnP.patch.socket.dev(or--patch-server-url) URLs as hosted pins. Without that flag, a mock host reads as "Manifest not found"..pnp.js) and 3.x is detected and gets the loud PnP warning in every mode, exit 0 (same as 4.x).scan -g --mode agent) after a failed apply (EACCES) exits 0 with "already recorded … runsocket-patch apply". This is the designed re-run message;apply -gitself exits 1.scan -gdoesn't mention-g. It's cross-PM and was handed to npm (Bug hunt ledger: npm #302), so it isn't filed here.enableHardenedMode, auto-on for public fork PRs in GitHub Actions) accepts a hosted::__archiveUrl=lock pin, as does--check-resolutions(4.12.0, registry reachable).enableGlobalCache: falsewith.yarn/cachecommitted): hosted mode is lock-only, so the committed cache keeps the unpatched zip, andyarn install --immutable --immutable-cachefails YN0056 untilyarn installrefreshes the cache. It's a docs gap, not filed.compressionLevelset outside the project.yarnrc.yml(env, home or parent rc) can't cause a wrong checksum: yarn bakes the level into the lock'scacheKey, which both modes gate on.All reactions