Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Agent mode ignores yarn classic's `--modules-folder`: packages installed there are reported "not installed" and `scan --mode agent` exits 0 leaving them unpatched

クローズ
#493 コメント 5 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
76/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
node.js, rust
領域
cli, devtools

調査の方向性

Start with the Yarn classic reproduction and inspect crates/socket-patch-core/src/crawlers/npm_crawler.rs:1418, especially find_local_node_modules_dirs. Trace how agent mode supplements the lockfile and reports notInstalled, then verify the configured .yarnrc folder is considered. Done means packages in --modules-folder deps are discovered and patched, or the run emits an appropriate unsupported-layout warning; check docs/ecosystems.md and the CLI_CONTRACT expectations.

索引モデルが issue の本文から書いたものです。

説明

agent:claimed agent:triaged bug bughunt pm:yarn-classic priority:p1

[agent] Found by the scheduled Yarn classic (1.x) bug-hunt routine (ledger #304).

Summary

Yarn classic can install into a folder other than node_modules, using --modules-folder <dir>. It's usually set project-wide in .yarnrc as --modules-folder deps, and Node then loads that folder through NODE_PATH (Docker layer caching, Electron and Meteor builds). The npm crawler only looks for literal node_modules directories (find_local_node_modules_dirs) and never reads .yarnrc. Packages that are really installed in <dir> therefore fall through to the lockfile supplement as notInstalled: true:

  • scan --mode agent --yes exits 0 with status: success and applied: 0. It prints no warning that the configured install folder was never checked.
  • get <uuid> --mode agent records the patch, and apply then fails with "matched no installed package … 1 not found on disk", even though the package is on disk at deps/left-pad.

This is the same class of defect as #359 / #362 (fixed in #365 for npm .store and pnpm virtualStoreDir), #366 (bun) and #373 (deno), here for yarn classic's own relocation setting.

Impact

A yarn classic project that uses --modules-folder can't be patched in agent mode, and scan --mode agent makes that look like a clean, successful run. VEX stays conservative (package_not_found, nothing attested), so there's no false attestation. Hosted and vendored modes aren't affected, because they work from yarn.lock.

Repro (Linux, Node 22)

mkdir p && cd p
echo '{"name":"app","version":"1.0.0","private":true,"dependencies":{"left-pad":"1.3.0"}}' > package.json
echo '--modules-folder deps' > .yarnrc
yarn install                        # yarn 1.22.22 → deps/left-pad, no node_modules/
socket-patch scan --mode agent --yes --json --api-url <mock> --org test-org --api-token fake
#  → status "success", apply.applied 0, packages[0].notInstalled true, warnings: none
socket-patch get <uuid> --mode agent --yes   # writes .socket/manifest.json
socket-patch apply                            # exit 1: "matched no installed package … 1 not found on disk"
NODE_PATH=deps node -e "console.log(require('fs').readFileSync(require.resolve('left-pad'),'utf8').slice(0,20))"
#  → original, unpatched bytes

I drove it with a local mock patch API (the repo's e2e_redirect_yarn_classic_build.rs mock shape) serving a patch for [email protected].

Expected vs actual

  • Expected: docs/ecosystems.md lists npm-family agent mode as "✅ any install layout", and CLI_CONTRACT's "Lockfile supplement" uses notInstalled for dependencies with no installed copy. Agent mode should find and patch the copies in the folder .yarnrc names. If that isn't supported, it should warn, as yarn_pnp_unsupported does, rather than report the package as not installed.
  • Actual: the configured install folder is never crawled. The run is a quiet success with nothing applied, and apply's error says the package isn't on disk.

OS × version

OS yarn reproduces
Linux 1.7.0 yes (2/2)
Linux 1.10.1 yes (2/2)
Linux 1.22.22 yes (2/2)
macOS / Windows — not probed: the crawler path logic is OS-independent

Tested on main 61cfb9b (after #365). It isn't a regression: the crawler has never read .yarnrc.

Suspect code

  • crates/socket-patch-core/src/crawlers/npm_crawler.rs:1418 find_local_node_modules_dirs: only <cwd>/node_modules plus workspace node_modules dirs are roots. There's no .yarnrc --modules-folder / modules-folder lookup, unlike the pnpm .modules.yaml virtualStoreDir handling #365 added.
主要言語
Rust
スター
8
フォーク
0
平均マージ
1日 7分
マージ済み PR(30日)
178

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

SocketDev/socket-patch のほかの issue

SocketDev/socket-patch の issue をすべて見る

似ている issue

Rust の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。