Agent mode ignores yarn classic's `--modules-folder`: packages installed there are reported "not installed" and `scan --mode agent` exits 0 leaving them unpatched
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 3/5
- Tempo estimado
- 1-2 dias
- Facilidade para iniciantes
- 76/100
Direção de pesquisa
Start with the Yarn classic reproduction and inspect crates/socket-patch-core/src/crawlers/npm_crawler.rs:1418, especially find_local_node_modules_dirs. Trace how agent mode supplements the lockfile and reports notInstalled, then verify the configured .yarnrc folder is considered. Done means packages in --modules-folder deps are discovered and patched, or the run emits an appropriate unsupported-layout warning; check docs/ecosystems.md and the CLI_CONTRACT expectations.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
[agent] Found by the scheduled Yarn classic (1.x) bug-hunt routine (ledger #304).
Summary
Yarn classic can install into a folder other than node_modules, using --modules-folder <dir>. It's usually set project-wide in .yarnrc as --modules-folder deps, and Node then loads that folder through NODE_PATH (Docker layer caching, Electron and Meteor builds). The npm crawler only looks for literal node_modules directories (find_local_node_modules_dirs) and never reads .yarnrc. Packages that are really installed in <dir> therefore fall through to the lockfile supplement as notInstalled: true:
scan --mode agent --yesexits 0 withstatus: successandapplied: 0. It prints no warning that the configured install folder was never checked.get <uuid> --mode agentrecords the patch, andapplythen fails with "matched no installed package … 1 not found on disk", even though the package is on disk atdeps/left-pad.
This is the same class of defect as #359 / #362 (fixed in #365 for npm .store and pnpm virtualStoreDir), #366 (bun) and #373 (deno), here for yarn classic's own relocation setting.
Impact
A yarn classic project that uses --modules-folder can't be patched in agent mode, and scan --mode agent makes that look like a clean, successful run. VEX stays conservative (package_not_found, nothing attested), so there's no false attestation. Hosted and vendored modes aren't affected, because they work from yarn.lock.
Repro (Linux, Node 22)
mkdir p && cd p
echo '{"name":"app","version":"1.0.0","private":true,"dependencies":{"left-pad":"1.3.0"}}' > package.json
echo '--modules-folder deps' > .yarnrc
yarn install # yarn 1.22.22 → deps/left-pad, no node_modules/
socket-patch scan --mode agent --yes --json --api-url <mock> --org test-org --api-token fake
# → status "success", apply.applied 0, packages[0].notInstalled true, warnings: none
socket-patch get <uuid> --mode agent --yes # writes .socket/manifest.json
socket-patch apply # exit 1: "matched no installed package … 1 not found on disk"
NODE_PATH=deps node -e "console.log(require('fs').readFileSync(require.resolve('left-pad'),'utf8').slice(0,20))"
# → original, unpatched bytes
I drove it with a local mock patch API (the repo's e2e_redirect_yarn_classic_build.rs mock shape) serving a patch for [email protected].
Expected vs actual
- Expected: docs/ecosystems.md lists npm-family agent mode as "✅ any install layout", and CLI_CONTRACT's "Lockfile supplement" uses
notInstalledfor dependencies with no installed copy. Agent mode should find and patch the copies in the folder.yarnrcnames. If that isn't supported, it should warn, asyarn_pnp_unsupporteddoes, rather than report the package as not installed. - Actual: the configured install folder is never crawled. The run is a quiet success with nothing applied, and
apply's error says the package isn't on disk.
OS × version
| OS | yarn | reproduces |
|---|---|---|
| Linux | 1.7.0 | yes (2/2) |
| Linux | 1.10.1 | yes (2/2) |
| Linux | 1.22.22 | yes (2/2) |
| macOS / Windows | — | not probed: the crawler path logic is OS-independent |
Tested on main 61cfb9b (after #365). It isn't a regression: the crawler has never read .yarnrc.
Suspect code
crates/socket-patch-core/src/crawlers/npm_crawler.rs:1418find_local_node_modules_dirs: only<cwd>/node_modulesplus workspacenode_modulesdirs are roots. There's no.yarnrc--modules-folder/modules-folderlookup, unlike the pnpm.modules.yamlvirtualStoreDirhandling #365 added.
- Linguagem predominante
- Rust
- Estrelas
- 8
- Forks
- 0
- Merge médio
- 1d 7min
- PRs com merge (30d)
- 178
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Sem modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de SocketDev/socket-patch
-
Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap)Talvez já em andamento @mikolalysenko assumiu hoje. Abertaagent:claimed agent:triaged bug bughunt pm:yarn-classic priority:p1
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
SocketDev/socket-patch#907 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
-
agent:triaged bug bughunt pm:npm priority:p1
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
SocketDev/socket-patch#900 ·
Mantenedores costumam responder em até 1 dia
-
agent:triaged bug bughunt pm:bundler priority:p1
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
SocketDev/socket-patch#896 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 73/100
SocketDev/socket-patch#783 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
agent:triaged bug bughunt pm:pipenv priority:p1
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 83/100
SocketDev/socket-patch#744 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
Todas as issues de SocketDev/socket-patch
Issues semelhantes
-
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 80/100
Devolutions/picky-rs#546 · 1 comentário ·
Mantenedores costumam responder em até 3 dias
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 74/100
Mantenedores costumam responder em até 1 dia
-
enhancement
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
zcashlabs/thus-spoke-zakura#153 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 79/100
topgrade-rs/topgrade#2395 ·
Mantenedores costumam responder em até 1 dia