Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Vendored yarn berry misses a parent-scoped user `resolutions` entry (`pkg-a/left-pad`), reports success, and every `yarn install --immutable` fails YN0028

Aperta Adatta ai principianti
#783 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
73/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
rust
Ambito
cli, tooling

Direzione di ricerca

Inizia in crates/socket-patch-core/src/vendor/yarn_berry_lock.rs, in resolutions_gate, e confronta la gestione dei selettori con resolution_selector_target() nello stesso file. Verifica come il gate gestisce un selettore circoscritto a un pacchetto genitore, come pkg-a/left-pad. Il lavoro è completato quando la modalità vendored rifiuta il caso con vendor_override_conflict e non scrive nulla.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

agent:triaged bug bughunt pm:yarn-berry priority:p1

[agent] Found by the scheduled Yarn Berry (2+) bug-hunt routine (ledger #305).

Summary

Vendored mode's user-override gate only recognizes resolutions selectors whose descriptor name is the target (left-pad, left-pad@^1.3.0, left-pad@npm:1.3.0). A parent-scoped selector such as "pkg-a/left-pad": "1.3.0" (or "pkg-a/left-pad@^1.3.0", or "<root-name>/left-pad") is not recognized. Vendored mode then adds its own bare "left-pad": "file:./.socket/vendor/…" pin next to the user's entry, rewrites the lock entry to the file: locator, and reports success.

Yarn applies the more specific parent-scoped resolution first, so it resolves left-pad@npm:1.3.0 for that parent, and the lock socket-patch wrote no longer matches. Every fresh yarn install --immutable fails with YN0028. A plain yarn install silently drops the vendored entry and installs the unpatched registry bytes. vex then correctly attests nothing, but scan had already reported success.

Hosted mode handles the same project correctly: it refuses with redirect_yarn_berry_resolutions_conflict and writes nothing, because it uses resolution_selector_target().

Impact

A monorepo that pins a dependency for one workspace (a common use of yarn's parent/name resolutions) gets a vendored "success" that breaks CI (--immutable), or installs unpatched code on a mutable install.

Repro (yarn 4.18.1, node-modules linker, Linux)
mkdir -p proj/packages/pkg-a && cd proj
echo '{"name":"root","private":true,"workspaces":["packages/*"],"resolutions":{"pkg-a/left-pad":"1.3.0"}}' > package.json
echo '{"name":"pkg-a","version":"1.0.0","dependencies":{"left-pad":"^1.3.0"}}' > packages/pkg-a/package.json
printf 'nodeLinker: node-modules\n' > .yarnrc.yml
yarn install                      # lock: "left-pad@npm:1.3.0"; package.json keeps "pkg-a/left-pad"
socket-patch scan --mode vendored --json --yes --cwd .   # a [email protected] patch is available
#   -> status "success", vendor.summary.applied 1
cat package.json
#   "resolutions": { "pkg-a/left-pad": "1.3.0",
#                    "left-pad": "file:./.socket/vendor/npm/<uuid>/left-pad-1.3.0.tgz" }
rm -rf node_modules .yarn/install-state.gz && yarn install --immutable
#   ➤ YN0028: -"left-pad@file:./.socket/vendor/npm/<uuid>/left-pad-1.3.0.tgz::locator=root%40workspace%3A.":
#   ➤ YN0028: +"left-pad@npm:1.3.0":
#   ➤ YN0028: The lockfile would have been modified by this install, which is explicitly forbidden.
yarn install && head -c 60 node_modules/left-pad/index.js   # unpatched registry bytes

The patch data came from a local mock of the patch API (/v0/orgs/<org>/patches/{batch,by-package,view,package} plus the tarball route), using a patched left-pad 1.3.0 tarball with a marker prepended to index.js. It reproduced on every attempt (more than 10 runs across the cells below).

Expected vs actual
  • Expected: refused with vendor_override_conflict and nothing written. CLI_CONTRACT.md: "vendor_override_conflict … vendor (pnpm/yarn-berry): a user-authored override/resolution for the package already exists." The gate's own doc comment says "Anything else same-name still refuses". Hosted mode refuses the same selector shapes ("bare, ranged or nested", docs/testing/yarn-berry-compatibility.md).
  • Actual: success. The user's entry is kept, a second conflicting pin is added, and the lock is left in a state yarn rejects.
Matrix (Linux; the Windows and macOS probes are blocked, see ledger #305)
user selector yarn 4.0.2 yarn 4.12.0 yarn 4.18.1
pkg-a/left-pad fail (YN0028) fail fail
pkg-a/left-pad@^1.3.0 fail fail fail
<root-name>/left-pad (app/left-pad) n/t n/t fail
left-pad, left-pad@^1.3.0, left-pad@npm:1.3.0 refused (correct) — refused (correct)
hosted mode, any of the above — — refused redirect_yarn_berry_resolutions_conflict (correct)

(**/left-pad: "1.3.0" isn't a useful control: yarn 4 drops that entry from package.json on its own yarn install, before socket-patch runs.)

First bad version: not a regression. Release 4.0.0 (npm @socketsecurity/[email protected]) behaves the same way. Tested on main 045d7ec.

Suspect code

crates/socket-patch-core/src/vendor/yarn_berry_lock.rs:524-528 (resolutions_gate) derives the selector's name with split_pattern(selector), which returns the whole string pkg-a/left-pad (≠ left-pad), so the continue skips it. resolution_selector_target() in the same file (:1471), which hosted (patch/redirect/mod.rs:4058) and vex discovery already use, returns left-pad for parent/left-pad, @scope/parent/left-pad and so on. Using it here would refuse the parent-scoped forms, keeping the bare exact-version takeover (selector == name) as it is.

Lingua principale
Rust
Stelle
8
Fork
0
Merge medio
1g 1h
PR unite (30g)
211

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di SocketDev/socket-patch

Tutte le issue di SocketDev/socket-patch

Issue simili

Altre issue su Rust

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.