Global mode never finds yarn 1.0.x global packages: `yarn global dir` doesn't exist before yarn 1.1.0, and there's no fallback
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Anfängerfreundlichkeit
- 68/100
Rechercherichtung
Start in crates/socket-patch-core/src/crawlers/npm_crawler.rs at lines 514 and 1151, then review the existing global-mode tests and yarn-classic-matrix coverage. Reproduce the yarn 1.0.2 case from the issue and compare it with yarn 1.1.0. Done means supported yarn 1.0.x global packages are found or the scan warns instead of reporting a clean success, without regressing the existing matrix.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
[agent] Found by the scheduled Yarn classic (1.x) bug-hunt routine (ledger #304).
Summary
scan -g, scan -g --mode agent, get -g, rollback -g and vex -g find yarn's global packages only by running yarn global dir. That subcommand doesn't exist in yarn 1.0.0–1.0.2: it prints error Invalid subcommand. Try "add, bin, ls, list, remove, upgrade, upgrade-interactive" and exits 1. The lookup then returns None, nothing else probes yarn's global folder, and every package installed with yarn global add is silently left out. Every command exits 0 with status: success.
Yarn 1.1.0 added yarn global dir. I bisected through corepack: 1.0.2 exits 1, while 1.1.0, 1.2.1, 1.3.2, 1.4.0, 1.5.1 and 1.6.0 print the folder. The folder itself (~/.config/yarn/global, or /usr/local/share/.config/yarn/global for root, %LOCALAPPDATA%\Yarn\Data\global on Windows) hasn't moved between 1.0 and 1.1.
Impact
It's a silent miss. On a machine with yarn 1.0.x, scan -g reports no patchable yarn-global tools, and scan -g --mode agent exits 0 with applied: 0 while the global copy stays vulnerable. The routine's version range (and CI's yarn-classic-matrix, which starts at 1.0.2) treats 1.0.x as supported, and docs/ecosystems.md doesn't mention this limitation. Yarn 1.0.x is old (2017), so this is low priority, but the result is a false all-clear rather than a refusal.
Repro (Linux sandbox, main 2463257)
corepack [email protected] global add [email protected] # lands in /usr/local/share/.config/yarn/global/node_modules (root)
corepack [email protected] global dir # error Invalid subcommand … (exit 1)
# with `yarn` on PATH = yarn 1.0.2, mock patch API serving pkg:npm/[email protected]:
socket-patch scan -g $API --json # status success, packages [] <- miss
socket-patch scan -g --mode agent $API --json # status success, apply.applied 0, exit 0
head -1 /usr/local/share/.config/yarn/global/node_modules/is-number/index.js # still upstream
# same machine, same global folder, `yarn` = 1.1.0:
socket-patch scan -g $API --json # packages ["pkg:npm/[email protected]"] <- found
Expected vs actual
- Expected: CLI_CONTRACT.md documents
--globalas "Operate on globally-installed packages", with--global-prefixdefaulting to "(auto)". The global-mode checklist (ledger #304) requiresscan -gto find every globally installed package, with none missing. When yarn is on PATH butyarn global dirfails, socket-patch should fall back to yarn's default global folder (oryarn global bin's sibling, or.yarnrcglobal-folder). Failing that, it should warn that yarn's global folder couldn't be determined, rather than report a clean scan. - Actual: yarn-global packages are invisible, with exit 0.
OS × yarn matrix (probe run, plus the Linux sandbox)
| OS | yarn 1.0.2 | yarn 1.10.1 | yarn 1.22.22 |
|---|---|---|---|
| Linux (sandbox + ubuntu-latest) | miss (scan_report, agent_apply, vex fail) |
pass | pass |
| macOS (macos-latest) | miss | pass | pass |
| Windows (windows-latest) | miss (also #434) | miss, see #434 | miss, see #434 |
On Windows every yarn version misses, for a separate reason: the bare yarn spawn never resolves yarn.cmd, which is tracked in #434. 1.0.x would still miss after that fix.
Suspect code
crates/socket-patch-core/src/crawlers/npm_crawler.rs:514:get_yarn_global_prefix_withruns onlyyarn global dir.None(non-zero exit) is final.crates/socket-patch-core/src/crawlers/npm_crawler.rs:1151:get_global_node_modules_pathshas no yarn fallback. The only fallbacks are the macOS-only npm ones.
Probe run: https://github.com/SocketDev/socket-patch/actions/runs/36827174726 (jobs global * yarn 1.0.2 print global dir: yarn global v1.0.2 … /node_modules and scan_report … result=FAIL).
- Vorherrschende Sprache
- Rust
- Sterne
- 8
- Forks
- 0
- Ø Merge
- 15 Std. 39 Min.
- Gemergte PRs (30 T.)
- 104
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus SocketDev/socket-patch
-
agent:triaged bug bughunt pm:cargo priority:p2
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
SocketDev/socket-patch#651 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:claimed agent:triaged arch-audit bug pm:hatch priority:p1
Schwierigkeit 2/5 Ein halber Tag Anfängerfreundlichkeit 88/100
SocketDev/socket-patch#613 · 3 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:claimed agent:triaged arch-audit bug priority:p3
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
SocketDev/socket-patch#571 · 5 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:composer priority:p2
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 90/100
SocketDev/socket-patch#515 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:npm priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
SocketDev/socket-patch#464 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in SocketDev/socket-patch
Ähnliche Issues
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 92/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
rust-windowing/winit#4731 ·
Maintainer antworten meist innerhalb von 2 Tagen
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
Maintainer antworten meist innerhalb von 1 Tag
-
area:cli bug priority:high
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 85/100
rtk-ai/rtk#4439 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
component:sight
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
agentic-os-org/ANOLISA#4622 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag