Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

Agent mode ignores yarn classic's `--modules-folder`: packages installed there are reported "not installed" and `scan --mode agent` exits 0 leaving them unpatched

Fechada
#493 5 comentários 0 reações 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 1 dia

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
3/5
Tempo estimado
1-2 dias
Facilidade para iniciantes
76/100
Tipo de issue
Bug
Clareza
Claramente especificada
Status de atividade
Ativa
Stack de tecnologia
node.js, rust
Domínio
cli, devtools

Direção de pesquisa

Start with the Yarn classic reproduction and inspect crates/socket-patch-core/src/crawlers/npm_crawler.rs:1418, especially find_local_node_modules_dirs. Trace how agent mode supplements the lockfile and reports notInstalled, then verify the configured .yarnrc folder is considered. Done means packages in --modules-folder deps are discovered and patched, or the run emits an appropriate unsupported-layout warning; check docs/ecosystems.md and the CLI_CONTRACT expectations.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

agent:claimed agent:triaged bug bughunt pm:yarn-classic priority:p1

[agent] Found by the scheduled Yarn classic (1.x) bug-hunt routine (ledger #304).

Summary

Yarn classic can install into a folder other than node_modules, using --modules-folder <dir>. It's usually set project-wide in .yarnrc as --modules-folder deps, and Node then loads that folder through NODE_PATH (Docker layer caching, Electron and Meteor builds). The npm crawler only looks for literal node_modules directories (find_local_node_modules_dirs) and never reads .yarnrc. Packages that are really installed in <dir> therefore fall through to the lockfile supplement as notInstalled: true:

  • scan --mode agent --yes exits 0 with status: success and applied: 0. It prints no warning that the configured install folder was never checked.
  • get <uuid> --mode agent records the patch, and apply then fails with "matched no installed package … 1 not found on disk", even though the package is on disk at deps/left-pad.

This is the same class of defect as #359 / #362 (fixed in #365 for npm .store and pnpm virtualStoreDir), #366 (bun) and #373 (deno), here for yarn classic's own relocation setting.

Impact

A yarn classic project that uses --modules-folder can't be patched in agent mode, and scan --mode agent makes that look like a clean, successful run. VEX stays conservative (package_not_found, nothing attested), so there's no false attestation. Hosted and vendored modes aren't affected, because they work from yarn.lock.

Repro (Linux, Node 22)

mkdir p && cd p
echo '{"name":"app","version":"1.0.0","private":true,"dependencies":{"left-pad":"1.3.0"}}' > package.json
echo '--modules-folder deps' > .yarnrc
yarn install                        # yarn 1.22.22 → deps/left-pad, no node_modules/
socket-patch scan --mode agent --yes --json --api-url <mock> --org test-org --api-token fake
#  → status "success", apply.applied 0, packages[0].notInstalled true, warnings: none
socket-patch get <uuid> --mode agent --yes   # writes .socket/manifest.json
socket-patch apply                            # exit 1: "matched no installed package … 1 not found on disk"
NODE_PATH=deps node -e "console.log(require('fs').readFileSync(require.resolve('left-pad'),'utf8').slice(0,20))"
#  → original, unpatched bytes

I drove it with a local mock patch API (the repo's e2e_redirect_yarn_classic_build.rs mock shape) serving a patch for [email protected].

Expected vs actual

  • Expected: docs/ecosystems.md lists npm-family agent mode as "✅ any install layout", and CLI_CONTRACT's "Lockfile supplement" uses notInstalled for dependencies with no installed copy. Agent mode should find and patch the copies in the folder .yarnrc names. If that isn't supported, it should warn, as yarn_pnp_unsupported does, rather than report the package as not installed.
  • Actual: the configured install folder is never crawled. The run is a quiet success with nothing applied, and apply's error says the package isn't on disk.

OS × version

OS yarn reproduces
Linux 1.7.0 yes (2/2)
Linux 1.10.1 yes (2/2)
Linux 1.22.22 yes (2/2)
macOS / Windows — not probed: the crawler path logic is OS-independent

Tested on main 61cfb9b (after #365). It isn't a regression: the crawler has never read .yarnrc.

Suspect code

  • crates/socket-patch-core/src/crawlers/npm_crawler.rs:1418 find_local_node_modules_dirs: only <cwd>/node_modules plus workspace node_modules dirs are roots. There's no .yarnrc --modules-folder / modules-folder lookup, unlike the pnpm .modules.yaml virtualStoreDir handling #365 added.
Linguagem predominante
Rust
Estrelas
8
Forks
0
Merge médio
1d 7min
PRs com merge (30d)
178

Preparar o ambiente

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de SocketDev/socket-patch

Todas as issues de SocketDev/socket-patch

Issues semelhantes

Mais issues de Rust

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.