Vendored yarn berry misses a parent-scoped user `resolutions` entry (`pkg-a/left-pad`), reports success, and every `yarn install --immutable` fails YN0028
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
調査の方向性
crates/socket-patch-core/src/vendor/yarn_berry_lock.rs の resolutions_gate から始め、同じファイル内の resolution_selector_target() とセレクターの処理を比較してください。pkg-a/left-pad のような親スコープ付きセレクターを gate がどのように処理するか確認してください。このケースで vendored モードが vendor_override_conflict を返して拒否し、何も書き込まないことをもって完了とします。
索引モデルが issue の本文から書いたものです。
説明
[agent] Found by the scheduled Yarn Berry (2+) bug-hunt routine (ledger #305).
Summary
Vendored mode's user-override gate only recognizes resolutions selectors whose descriptor name is the target (left-pad, left-pad@^1.3.0, left-pad@npm:1.3.0). A parent-scoped selector such as "pkg-a/left-pad": "1.3.0" (or "pkg-a/left-pad@^1.3.0", or "<root-name>/left-pad") is not recognized. Vendored mode then adds its own bare "left-pad": "file:./.socket/vendor/…" pin next to the user's entry, rewrites the lock entry to the file: locator, and reports success.
Yarn applies the more specific parent-scoped resolution first, so it resolves left-pad@npm:1.3.0 for that parent, and the lock socket-patch wrote no longer matches. Every fresh yarn install --immutable fails with YN0028. A plain yarn install silently drops the vendored entry and installs the unpatched registry bytes. vex then correctly attests nothing, but scan had already reported success.
Hosted mode handles the same project correctly: it refuses with redirect_yarn_berry_resolutions_conflict and writes nothing, because it uses resolution_selector_target().
Impact
A monorepo that pins a dependency for one workspace (a common use of yarn's parent/name resolutions) gets a vendored "success" that breaks CI (--immutable), or installs unpatched code on a mutable install.
Repro (yarn 4.18.1, node-modules linker, Linux)
mkdir -p proj/packages/pkg-a && cd proj
echo '{"name":"root","private":true,"workspaces":["packages/*"],"resolutions":{"pkg-a/left-pad":"1.3.0"}}' > package.json
echo '{"name":"pkg-a","version":"1.0.0","dependencies":{"left-pad":"^1.3.0"}}' > packages/pkg-a/package.json
printf 'nodeLinker: node-modules\n' > .yarnrc.yml
yarn install # lock: "left-pad@npm:1.3.0"; package.json keeps "pkg-a/left-pad"
socket-patch scan --mode vendored --json --yes --cwd . # a [email protected] patch is available
# -> status "success", vendor.summary.applied 1
cat package.json
# "resolutions": { "pkg-a/left-pad": "1.3.0",
# "left-pad": "file:./.socket/vendor/npm/<uuid>/left-pad-1.3.0.tgz" }
rm -rf node_modules .yarn/install-state.gz && yarn install --immutable
# ➤ YN0028: -"left-pad@file:./.socket/vendor/npm/<uuid>/left-pad-1.3.0.tgz::locator=root%40workspace%3A.":
# ➤ YN0028: +"left-pad@npm:1.3.0":
# ➤ YN0028: The lockfile would have been modified by this install, which is explicitly forbidden.
yarn install && head -c 60 node_modules/left-pad/index.js # unpatched registry bytes
The patch data came from a local mock of the patch API (/v0/orgs/<org>/patches/{batch,by-package,view,package} plus the tarball route), using a patched left-pad 1.3.0 tarball with a marker prepended to index.js. It reproduced on every attempt (more than 10 runs across the cells below).
Expected vs actual
- Expected: refused with
vendor_override_conflictand nothing written. CLI_CONTRACT.md: "vendor_override_conflict… vendor (pnpm/yarn-berry): a user-authored override/resolution for the package already exists." The gate's own doc comment says "Anything else same-name still refuses". Hosted mode refuses the same selector shapes ("bare, ranged or nested", docs/testing/yarn-berry-compatibility.md). - Actual:
success. The user's entry is kept, a second conflicting pin is added, and the lock is left in a state yarn rejects.
Matrix (Linux; the Windows and macOS probes are blocked, see ledger #305)
| user selector | yarn 4.0.2 | yarn 4.12.0 | yarn 4.18.1 |
|---|---|---|---|
pkg-a/left-pad |
fail (YN0028) | fail | fail |
pkg-a/left-pad@^1.3.0 |
fail | fail | fail |
<root-name>/left-pad (app/left-pad) |
n/t | n/t | fail |
left-pad, left-pad@^1.3.0, left-pad@npm:1.3.0 |
refused (correct) | — | refused (correct) |
| hosted mode, any of the above | — | — | refused redirect_yarn_berry_resolutions_conflict (correct) |
(**/left-pad: "1.3.0" isn't a useful control: yarn 4 drops that entry from package.json on its own yarn install, before socket-patch runs.)
First bad version: not a regression. Release 4.0.0 (npm @socketsecurity/[email protected]) behaves the same way. Tested on main 045d7ec.
Suspect code
crates/socket-patch-core/src/vendor/yarn_berry_lock.rs:524-528 (resolutions_gate) derives the selector's name with split_pattern(selector), which returns the whole string pkg-a/left-pad (≠ left-pad), so the continue skips it. resolution_selector_target() in the same file (:1471), which hosted (patch/redirect/mod.rs:4058) and vex discovery already use, returns left-pad for parent/left-pad, @scope/parent/left-pad and so on. Using it here would refuse the parent-scoped forms, keeping the bare exact-version takeover (selector == name) as it is.
- 主要言語
- Rust
- スター
- 8
- フォーク
- 0
- 平均マージ
- 1日 31分
- マージ済み PR(30日)
- 151
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
SocketDev/socket-patch のほかの issue
-
agent:triaged bug bughunt pm:pipenv priority:p1
難易度 2/5 1〜3時間 初心者へのやさしさ 83/100
SocketDev/socket-patch#744 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
agent:triaged bug bughunt pm:cargo priority:p2
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
SocketDev/socket-patch#651 · コメント 3 件 ·
メンテナーはふだん 1 日以内に返信
-
agent:triaged bug bughunt pm:composer priority:p2
難易度 2/5 1〜3時間 初心者へのやさしさ 90/100
SocketDev/socket-patch#515 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
A report-only `scan -g` tells you to run `socket-patch scan --mode agent [PATHS]` without `-g`, so following the hint scans the cwd project instead of the global install対応中かも このイシューにリンクされたプルリクエストがオープン中、またはマージ済みです。 オープンagent:triaged bug bughunt pm:npm priority:p1
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
SocketDev/socket-patch#464 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
agent:triaged bug bughunt pm:npm priority:p1
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
SocketDev/socket-patch#433 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
SocketDev/socket-patch の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
[Bug]: Bedrock request metadata forwarding does not work for /embeddings対応中かも このイシューにリンクされたプルリクエストがオープン中、またはマージ済みです。 オープンbug llm translation
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
pytest plugin: a crashed xdist worker aborts the whole session with INTERNALERROR対応中かも @hazelxue が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
メンテナーはふだん 1 日以内に返信
-
skillfs: one malformed chat-log line aborts the entire skill-usage analysis (skill_usage_from_chat_logs.py)対応中かも @zjncs が今日担当しました。 オープンcomponent:skillfs
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
agentic-os-org/ANOLISA#6116 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信