Yarn berry vendored and hosted modes refuse `compressionLevel: 0 # comment` in .yarnrc.yml as a non-default compression level
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 82/100
Línea de trabajo
Comienza en crates/socket-patch-core/src/vendor/yarn_berry_lock.rs:1307, en yarnrc_compression_level, y ejecuta la reproducción proporcionada de Yarn Berry con los entry points vendored y hosted. Verifica que un comentario YAML final quede excluido del nivel de compresión, mientras que compressionLevel: 0 siga siendo aceptado y ambos modos finalicen correctamente.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
[agent] Found by the scheduled Yarn Berry (2+) bug-hunt routine (ledger #305).
Summary
Suppose .yarnrc.yml sets compressionLevel: 0 with a trailing YAML comment, for example compressionLevel: 0 # keep yarn default. Yarn reads this as 0: yarn config get compressionLevel prints 0, and the lock's cacheKey is 10c0. socket-patch's flat-line reader takes the whole rest of the line, 0 # keep yarn default, as the value. So both vendored and hosted mode refuse the project as if it used a non-default compression level. The message contradicts itself:
vendor_yarn_berry_cache_unsupported: .yarnrc.yml sets `compressionLevel: 0 # keep yarn default`, which changes berry's cache checksums; only compressionLevel 0 (the yarn 4 default) is supported
redirect_yarn_berry_cache_unsupported: .yarnrc.yml sets `compressionLevel: 0 # keep yarn default`, …
Impact
A refusal fires on a supported configuration. vendor / scan --mode vendored / scan --mode hosted exit 1 and patch nothing for every npm purl in the project. Low severity, because it fails closed, but the only workaround is deleting the comment.
Repro (Linux, yarn 4.12.0 and 4.18.1)
echo '{"name":"app","version":"1.0.0","dependencies":{"left-pad":"1.3.0"}}' > package.json
printf 'nodeLinker: node-modules\nenableGlobalCache: false\ncompressionLevel: 0 # keep yarn default\n' > .yarnrc.yml
touch yarn.lock && yarn install
yarn config get compressionLevel # -> 0
grep cacheKey yarn.lock # -> cacheKey: 10c0
# stage .socket/manifest.json + blob for pkg:npm/[email protected]
socket-patch vendor --json --offline # -> exit 1, vendor_yarn_berry_cache_unsupported
socket-patch scan --mode hosted … # -> exit 1, redirect_yarn_berry_cache_unsupported (mock API)
Without the comment, the same project vendors, and passes a fresh yarn install --immutable with the patched bytes.
Expected vs actual
- Expected: docs/testing/yarn-berry-compatibility.md says cacheKey
10c0/compressionLevel: 0is supported, and the reader's doc comment says it should read the knob "the way yarn's YAML parser" does. A YAML comment isn't part of the scalar. - Actual: the comment is read as part of the value, and the supported config is refused.
Matrix
| OS | yarn | vendored | hosted |
|---|---|---|---|
| Linux (sandbox) | 4.12.0 | fails | fails |
| Linux (sandbox) | 4.18.1 | not run | fails |
The parser is OS-independent. Release 4.0.0 behaves the same (vendored checked).
Suspect code
crates/socket-patch-core/src/vendor/yarn_berry_lock.rs:1307 (yarnrc_compression_level: rest.trim().trim_matches(['\'', '"']) doesn't strip a #… comment). The hosted gate shares it.
- Lenguaje dominante
- Rust
- Estrellas
- 8
- Forks
- 0
- Merge medio
- 18 h 4 min
- PR fusionados (30 d)
- 70
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de SocketDev/socket-patch
-
agent:triaged bug bughunt pm:composer priority:p2
Dificultad 2/5 1-3 horas Aptitud para principiantes 90/100
SocketDev/socket-patch#515 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
agent:triaged bug bughunt pm:npm priority:p1
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
SocketDev/socket-patch#464 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
agent:triaged bug bughunt pm:npm priority:p1
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
SocketDev/socket-patch#433 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
agent:triaged bug bughunt pm:uv priority:p1
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
SocketDev/socket-patch#408 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Hosted Gradle snippet is always Groovy DSL, so pasting it into a build.gradle.kts fails to compileAbiertoagent:triaged bug bughunt pm:gradle priority:p3
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
SocketDev/socket-patch#348 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de SocketDev/socket-patch
Issues similares
-
tech-debt
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
Los mantenedores suelen responder en 1 día
-
Broken links in the docsAbiertodocumentation
Dificultad 1/5 Menos de una hora Aptitud para principiantes 85/100
Los mantenedores suelen responder en 1 día
-
discover: `sudo RTK_DISABLED=$VAR …` is not detected as a bypass when `sudo` is a transparent prefixAbiertoarea:cli bug good first issue priority:medium
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
rtk-ai/rtk#4412 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
[review-skill] Unresolved review threads need paginated GraphQL; first:100 silently truncatesAbiertoskill:code-review
Dificultad 1/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
component:sight
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
agentic-os-org/ANOLISA#4115 · 1 comentario ·
Los mantenedores suelen responder en 1 día