Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap)

Chiusa Adatta ai principianti
#907 2 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Una pull request collegata è già stata integrata.

  • #917 di @mikolalysenko — integrata

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
85/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
rust
Ambito
cli

Direzione di ricerca

Inizia individuando l’avviso esistente yarn_classic_berry_migration_risk in crates/socket-patch-core/src/vendor/mod.rs e i suoi attuali punti di chiamata in crates/socket-patch-cli/src/commands/vendor.rs. Aggiungi chiamate equivalenti a questo avviso nei flussi di scansione/recupero in modalità hosted e in rewrite_yarn_classic in crates/socket-patch-core/src/patch/redirect/mod.rs. Poi esegui i passaggi di riproduzione forniti per confermare che le scansioni hosted emettano l’avviso quando non è presente un pin packageManager: yarn@1…. Il lavoro è completato quando la modalità hosted produce lo stesso avviso sul rischio di migrazione della modalità vendored per stati identici del file di lock.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

agent:claimed agent:triaged bug bughunt pm:yarn-classic priority:p1

[agent] Found by the scheduled Yarn classic (1.x) bug-hunt routine (ledger #304).

Summary

When yarn 2+ (berry) installs over a classic (v1) yarn.lock, it migrates the lock and re-resolves every entry from the registry. Socket-patch knows about this trap. Vendored mode emits yarn_classic_berry_migration_risk (crates/socket-patch-core/src/vendor/mod.rs:177) unless package.json pins packageManager: yarn@1…. Hosted mode pins the same lock, and berry drops that pin the same way, but hosted never runs the probe. scan --mode hosted and get <uuid> --mode hosted report success, redirected: 1 and no warning. This holds even when package.json already declares "packageManager": "[email protected]", where the next non-immutable install is certain to discard the pin.

Impact

A developer runs scan --mode hosted on a v1 lock that is mid-migration to berry (or unpinned) and commits the result. The next yarn install under berry quietly rewrites the lock to left-pad@npm:1.3.0 and installs the upstream, unpatched bytes, with nothing printed by either tool. vex correctly fails closed afterwards (the pin is gone, so manifest_not_found / exit 2), so nothing is falsely attested. The patch is lost silently, though, which is exactly the outcome the vendored warning exists to prevent. Under --immutable (berry's CI default), the same install fails YN0028 instead. That's loud, but there's still no hint that socket-patch's pin is the cause.

Repro

# mock patch API on 127.0.0.1:8787 serving a free [email protected] patch (run-18 mock from the #304 ledger)
export SOCKET_PATCH_SERVER_URL=http://127.0.0.1:8787
API="--api-url http://127.0.0.1:8787 --org o --api-token x"
mkdir p && cd p
echo '{"name":"p","version":"1.0.0","private":true,"dependencies":{"left-pad":"1.3.0"}}' > package.json
[email protected] install                      # v1 lock
# mid-migration: the project now declares berry
echo '{"name":"p","version":"1.0.0","private":true,"packageManager":"[email protected]","dependencies":{"left-pad":"1.3.0"}}' > package.json
socket-patch scan --mode hosted --json --yes $API
#   status "success", redirect.redirected 1, redirect.warnings [] , top-level warnings []
grep resolved yarn.lock                   # http://127.0.0.1:8787/artifacts/…/left-pad-1.3.0.tgz#81960ff…
rm -rf node_modules
printf 'nodeLinker: node-modules\nenableGlobalCache: false\n' > .yarnrc.yml
YARN_ENABLE_IMMUTABLE_INSTALLS=0 [email protected] install   # exit 0, migrates the lock
grep -A3 '"left-pad@' yarn.lock           # resolution: "left-pad@npm:1.3.0"  (pin gone)
head -1 node_modules/left-pad/index.js    # upstream bytes, no patch marker

# control: identical flow with --mode vendored
#   warnings: [yarn_classic_berry_migration_risk]  ("…installing with yarn 2+ (berry) migrates the lockfile and silently drops them…")

Expected vs actual

  • Expected: hosted pins in a classic lock are subject to the same migration loss the vendored probe describes ("installing with yarn 2+ (berry) migrates the lockfile and silently drops them — packages install unpatched from the registry"), so hosted should emit the same advisory (yarn_classic_berry_migration_risk, or a redirect_* twin). It should be suppressed by a packageManager: yarn@1… pin, and fire when there's no pin or when a non-1 yarn is declared. CLI_CONTRACT's hosted section says a dep counts as redirected only when its pin "actually landed in a project file". Here it lands, but the project's own declared package manager discards it on the next install with no signal.
  • Actual: hosted exits 0 success with no warning, while vendored on the same project warns.

OS × version

Linux, main 9c43dfc, each cell run at least once; the 1.22.22 scan cells twice. Berry is yarn 4.18.1 (@yarnpkg/cli-dist), nodeLinker: node-modules.

lock written by command packageManager socket-patch result berry install pin kept / installed patched
yarn 1.7.0 scan --mode hosted none success, redirected 1, no warning exit 0, migrated no / no
yarn 1.7.0 scan --mode hosted [email protected] success, redirected 1, no warning exit 0, migrated no / no
yarn 1.7.0 get <uuid> --mode hosted none / [email protected] success, redirected 1, no warning exit 0, migrated no / no
yarn 1.10.1 scan / get --mode hosted none / [email protected] success, redirected 1, no warning exit 0, migrated no / no
yarn 1.22.22 scan / get --mode hosted none / [email protected] (×2) success, redirected 1, no warning exit 0, migrated no / no
yarn 1.22.22 scan --mode vendored (control) none / [email protected] (×2) success + yarn_classic_berry_migration_risk exit 0, migrated no / no
yarn 1.22.22 scan --mode hosted, packageManager: [email protected] pinned success, no warning (correct) n/a (corepack would refuse berry) —
yarn 1.22.22 hosted, then berry install --immutable none success, no warning YN0028, lockfile would be modified —

macOS / Windows weren't probed. The behaviour is in the shared engine, not OS-specific code. No bisect: hosted mode has never called the probe.

Suspect code

  • crates/socket-patch-core/src/vendor/mod.rs:177 yarn_classic_berry_migration_risk only looks for .socket/vendor/ wiring (lock.contains(".socket/vendor/")), so it can't see a hosted pin.
  • crates/socket-patch-cli/src/commands/vendor.rs:689 note_classic_migration_risk is called only from the vendor paths (vendor.rs:949, vendor.rs:1600, scan/vendor_flow.rs:371). The hosted flow and rewrite_yarn_classic (crates/socket-patch-core/src/patch/redirect/mod.rs:3217) have no equivalent.
Lingua principale
Rust
Stelle
8
Fork
0
Merge medio
22h 30m
PR unite (30g)
329

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di SocketDev/socket-patch

Tutte le issue di SocketDev/socket-patch

Issue simili

Altre issue su Rust

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.