Agent mode ignores yarn classic's `--modules-folder`: packages installed there are reported "not installed" and `scan --mode agent` exits 0 leaving them unpatched
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 3/5
- Geschätzter Aufwand
- 1-2 Tage
- Anfängerfreundlichkeit
- 76/100
Rechercherichtung
Start with the Yarn classic reproduction and inspect crates/socket-patch-core/src/crawlers/npm_crawler.rs:1418, especially find_local_node_modules_dirs. Trace how agent mode supplements the lockfile and reports notInstalled, then verify the configured .yarnrc folder is considered. Done means packages in --modules-folder deps are discovered and patched, or the run emits an appropriate unsupported-layout warning; check docs/ecosystems.md and the CLI_CONTRACT expectations.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
[agent] Found by the scheduled Yarn classic (1.x) bug-hunt routine (ledger #304).
Summary
Yarn classic can install into a folder other than node_modules, using --modules-folder <dir>. It's usually set project-wide in .yarnrc as --modules-folder deps, and Node then loads that folder through NODE_PATH (Docker layer caching, Electron and Meteor builds). The npm crawler only looks for literal node_modules directories (find_local_node_modules_dirs) and never reads .yarnrc. Packages that are really installed in <dir> therefore fall through to the lockfile supplement as notInstalled: true:
scan --mode agent --yesexits 0 withstatus: successandapplied: 0. It prints no warning that the configured install folder was never checked.get <uuid> --mode agentrecords the patch, andapplythen fails with "matched no installed package … 1 not found on disk", even though the package is on disk atdeps/left-pad.
This is the same class of defect as #359 / #362 (fixed in #365 for npm .store and pnpm virtualStoreDir), #366 (bun) and #373 (deno), here for yarn classic's own relocation setting.
Impact
A yarn classic project that uses --modules-folder can't be patched in agent mode, and scan --mode agent makes that look like a clean, successful run. VEX stays conservative (package_not_found, nothing attested), so there's no false attestation. Hosted and vendored modes aren't affected, because they work from yarn.lock.
Repro (Linux, Node 22)
mkdir p && cd p
echo '{"name":"app","version":"1.0.0","private":true,"dependencies":{"left-pad":"1.3.0"}}' > package.json
echo '--modules-folder deps' > .yarnrc
yarn install # yarn 1.22.22 → deps/left-pad, no node_modules/
socket-patch scan --mode agent --yes --json --api-url <mock> --org test-org --api-token fake
# → status "success", apply.applied 0, packages[0].notInstalled true, warnings: none
socket-patch get <uuid> --mode agent --yes # writes .socket/manifest.json
socket-patch apply # exit 1: "matched no installed package … 1 not found on disk"
NODE_PATH=deps node -e "console.log(require('fs').readFileSync(require.resolve('left-pad'),'utf8').slice(0,20))"
# → original, unpatched bytes
I drove it with a local mock patch API (the repo's e2e_redirect_yarn_classic_build.rs mock shape) serving a patch for [email protected].
Expected vs actual
- Expected: docs/ecosystems.md lists npm-family agent mode as "✅ any install layout", and CLI_CONTRACT's "Lockfile supplement" uses
notInstalledfor dependencies with no installed copy. Agent mode should find and patch the copies in the folder.yarnrcnames. If that isn't supported, it should warn, asyarn_pnp_unsupporteddoes, rather than report the package as not installed. - Actual: the configured install folder is never crawled. The run is a quiet success with nothing applied, and
apply's error says the package isn't on disk.
OS × version
| OS | yarn | reproduces |
|---|---|---|
| Linux | 1.7.0 | yes (2/2) |
| Linux | 1.10.1 | yes (2/2) |
| Linux | 1.22.22 | yes (2/2) |
| macOS / Windows | — | not probed: the crawler path logic is OS-independent |
Tested on main 61cfb9b (after #365). It isn't a regression: the crawler has never read .yarnrc.
Suspect code
crates/socket-patch-core/src/crawlers/npm_crawler.rs:1418find_local_node_modules_dirs: only<cwd>/node_modulesplus workspacenode_modulesdirs are roots. There's no.yarnrc--modules-folder/modules-folderlookup, unlike the pnpm.modules.yamlvirtualStoreDirhandling #365 added.
- Vorherrschende Sprache
- Rust
- Sterne
- 8
- Forks
- 0
- Ø Merge
- 1 T. 1 Std.
- Gemergte PRs (30 T.)
- 211
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus SocketDev/socket-patch
-
arch-audit refactor
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
SocketDev/socket-patch#1011 ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged arch-audit bug priority:p3
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 74/100
SocketDev/socket-patch#982 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap)Evtl. vergeben @mikolalysenko hat das vor 1 Tag übernommen. Offenagent:claimed agent:triaged bug bughunt pm:yarn-classic priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 85/100
SocketDev/socket-patch#907 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:bundler priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 85/100
SocketDev/socket-patch#896 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 73/100
SocketDev/socket-patch#783 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in SocketDev/socket-patch
Ähnliche Issues
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
bmander/geomsolver#118 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
Maintainer antworten meist innerhalb von 1 Tag
-
Three Windows builds are keyed on a later release than their layoutEvtl. vergeben @ero-qt hat das heute übernommen. Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
Maintainer antworten meist innerhalb von 2 Tagen
-
priority:P3 type:docs
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 85/100
sebastian-software/ferroni#253 ·
Maintainer antworten meist innerhalb von 1 Tag