Global mode never finds yarn 1.0.x global packages: `yarn global dir` doesn't exist before yarn 1.1.0, and there's no fallback
Les mainteneurs répondent en général sous 1 jour
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Accessibilité débutants
- 68/100
Piste de recherche
Start in crates/socket-patch-core/src/crawlers/npm_crawler.rs at lines 514 and 1151, then review the existing global-mode tests and yarn-classic-matrix coverage. Reproduce the yarn 1.0.2 case from the issue and compare it with yarn 1.1.0. Done means supported yarn 1.0.x global packages are found or the scan warns instead of reporting a clean success, without regressing the existing matrix.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
[agent] Found by the scheduled Yarn classic (1.x) bug-hunt routine (ledger #304).
Summary
scan -g, scan -g --mode agent, get -g, rollback -g and vex -g find yarn's global packages only by running yarn global dir. That subcommand doesn't exist in yarn 1.0.0–1.0.2: it prints error Invalid subcommand. Try "add, bin, ls, list, remove, upgrade, upgrade-interactive" and exits 1. The lookup then returns None, nothing else probes yarn's global folder, and every package installed with yarn global add is silently left out. Every command exits 0 with status: success.
Yarn 1.1.0 added yarn global dir. I bisected through corepack: 1.0.2 exits 1, while 1.1.0, 1.2.1, 1.3.2, 1.4.0, 1.5.1 and 1.6.0 print the folder. The folder itself (~/.config/yarn/global, or /usr/local/share/.config/yarn/global for root, %LOCALAPPDATA%\Yarn\Data\global on Windows) hasn't moved between 1.0 and 1.1.
Impact
It's a silent miss. On a machine with yarn 1.0.x, scan -g reports no patchable yarn-global tools, and scan -g --mode agent exits 0 with applied: 0 while the global copy stays vulnerable. The routine's version range (and CI's yarn-classic-matrix, which starts at 1.0.2) treats 1.0.x as supported, and docs/ecosystems.md doesn't mention this limitation. Yarn 1.0.x is old (2017), so this is low priority, but the result is a false all-clear rather than a refusal.
Repro (Linux sandbox, main 2463257)
corepack [email protected] global add [email protected] # lands in /usr/local/share/.config/yarn/global/node_modules (root)
corepack [email protected] global dir # error Invalid subcommand … (exit 1)
# with `yarn` on PATH = yarn 1.0.2, mock patch API serving pkg:npm/[email protected]:
socket-patch scan -g $API --json # status success, packages [] <- miss
socket-patch scan -g --mode agent $API --json # status success, apply.applied 0, exit 0
head -1 /usr/local/share/.config/yarn/global/node_modules/is-number/index.js # still upstream
# same machine, same global folder, `yarn` = 1.1.0:
socket-patch scan -g $API --json # packages ["pkg:npm/[email protected]"] <- found
Expected vs actual
- Expected: CLI_CONTRACT.md documents
--globalas "Operate on globally-installed packages", with--global-prefixdefaulting to "(auto)". The global-mode checklist (ledger #304) requiresscan -gto find every globally installed package, with none missing. When yarn is on PATH butyarn global dirfails, socket-patch should fall back to yarn's default global folder (oryarn global bin's sibling, or.yarnrcglobal-folder). Failing that, it should warn that yarn's global folder couldn't be determined, rather than report a clean scan. - Actual: yarn-global packages are invisible, with exit 0.
OS × yarn matrix (probe run, plus the Linux sandbox)
| OS | yarn 1.0.2 | yarn 1.10.1 | yarn 1.22.22 |
|---|---|---|---|
| Linux (sandbox + ubuntu-latest) | miss (scan_report, agent_apply, vex fail) |
pass | pass |
| macOS (macos-latest) | miss | pass | pass |
| Windows (windows-latest) | miss (also #434) | miss, see #434 | miss, see #434 |
On Windows every yarn version misses, for a separate reason: the bare yarn spawn never resolves yarn.cmd, which is tracked in #434. 1.0.x would still miss after that fix.
Suspect code
crates/socket-patch-core/src/crawlers/npm_crawler.rs:514:get_yarn_global_prefix_withruns onlyyarn global dir.None(non-zero exit) is final.crates/socket-patch-core/src/crawlers/npm_crawler.rs:1151:get_global_node_modules_pathshas no yarn fallback. The only fallbacks are the macOS-only npm ones.
Probe run: https://github.com/SocketDev/socket-patch/actions/runs/36827174726 (jobs global * yarn 1.0.2 print global dir: yarn global v1.0.2 … /node_modules and scan_report … result=FAIL).
- Langage dominant
- Rust
- Étoiles
- 8
- Forks
- 0
- Merge moyen
- 15 h 39 min
- PR mergées (30 j)
- 104
Préparer son environnement
- Aucun Dockerfile ni fichier Docker Compose
- Aucun modèle de pull request
- Lire le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de SocketDev/socket-patch
-
agent:triaged bug bughunt pm:pipenv priority:p1
Difficulté 2/5 1-3 heures Accessibilité débutants 83/100
SocketDev/socket-patch#744 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
-
agent:triaged bug bughunt pm:cargo priority:p2
Difficulté 2/5 1-3 heures Accessibilité débutants 84/100
SocketDev/socket-patch#651 · 3 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
Vendored Hatch runs a `hatch` executable planted in the scanned projectPeut-être pris @mikolalysenko l’a pris il y a 1 jour. Ouverteagent:claimed agent:triaged arch-audit bug pm:hatch priority:p1
Difficulté 2/5 Une demi-journée Accessibilité débutants 88/100
SocketDev/socket-patch#613 · 3 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
Patch blob and diff downloads buffer the whole response body with no size capPeut-être pris @mikolalysenko l’a pris il y a 1 jour. Ouverteagent:claimed agent:triaged arch-audit bug priority:p3
Difficulté 2/5 1-3 heures Accessibilité débutants 84/100
SocketDev/socket-patch#571 · 5 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
agent:triaged bug bughunt pm:composer priority:p2
Difficulté 2/5 1-3 heures Accessibilité débutants 90/100
SocketDev/socket-patch#515 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
Toutes les issues de SocketDev/socket-patch
Issues similaires
-
contribution
Difficulté 2/5 1-3 heures Accessibilité débutants 76/100
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 2/5 1-3 heures Accessibilité débutants 82/100
tree-sitter/tree-sitter#6005 ·
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 2/5 1-3 heures Accessibilité débutants 90/100
-
Difficulté 2/5 1-3 heures Accessibilité débutants 74/100
maplibre/maplibre-tile-spec#1844 ·
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 2/5 1-3 heures Accessibilité débutants 92/100
Les mainteneurs répondent en général sous 1 jour