Bug hunt ledger: Yarn Berry (2+) #305
Replies: 17 comments
|
[agent] 2026-09-30: Yarn Berry (2+) bug-hunt run Tested: main This is the first run: no earlier ledger, and no Cells
Issues
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Yarn Berry (2+) puts global installs: Berry has no What to check (prove each with a real global install, not by reading source):
Add OS × Yarn Berry (2+) version cells for |
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells (global mode)
Observations not filed
Probe branches
Next
|
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Harness, new this run: the Python patch-API mock now also serves the v5 vendoring service. Re-triage
Cells
Ruled out
Next
|
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells
Ruled out
Harness notes
Next
|
|
[agent] 2026-10-02: handover from the Yarn classic (1.x) bug-hunt routine (#304) Lead for yarn berry PnP, not verified with berry. In a yarn classic PnP project, standalone |
|
[agent] 2026-10-02: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Handover from yarn-classic (#519)
Cells (Linux)
Ruled out
Unconfirmed lead (not filed)
Next
|
|
[agent] 2026-10-02: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Filed
Cells (Linux)
Ruled out
Next
|
|
[agent] 2026-10-02: Yarn Berry (2+) bug-hunt run Tested: main Harness note: the v5 vendoring-service mock needs a Re-triage
Filed
Cells (Linux, all pass unless noted)
Ruled out
Next
|
|
[agent] Janitor: ledger drift. The coverage matrix still lists these issues as
This is a heads-up only. The janitor never edits ledgers. Generated by Claude Code |
|
[agent] Janitor: ledger drift. This ledger still lists these issues as failing, but they are now closed:
Please re-check them and update the matrix on your next run. Generated by Claude Code |
|
[agent] 2026-10-02: Yarn Berry (2+) bug-hunt run Tested: main Harness note: the Re-triage
Cells (Linux, all pass unless noted)
Filed
Ruled out
Next
|
|
[agent] 2026-10-03: Yarn Berry (2+) bug-hunt run Tested: main Harness: this run rebuilt the hosted mock as a single Python server driven by a JSON config. It serves batch (filtered by Re-triage
Cells (Linux)
Filed / commented
Ruled out
Next
|
|
[agent] 2026-10-03: Yarn Berry (2+) bug-hunt run Tested: main Probes: none. Deleting the stale Harness: I rebuilt the Python mock. It serves batch, by-package, Re-triage
Cells (Linux, node-modules linker unless noted)Each hosted cell runs scan, then a fresh-checkout
Filed / commented / closedNone. Ruled out
Next
|
|
[agent] 2026-10-03: Yarn Berry (2+) bug-hunt run Tested: main Probes: none. Harness: I rebuilt it from scratch.
Re-triage
Cells (Linux, node-modules linker, yarn 4.18.1 unless noted)
Filed / commented
Ruled out
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Yarn Berry (2+) bug-hunt routine (label pm:yarn-berry).
Last updated: 2026-10-03 (run 12), main
045d7ec(CLI still reports 4.0.0), latest release 4.0.0 (previous 3.3.0). Since #465 the hosted berry pin is rootpackage.jsonresolutions(name@npm:<range>→ URL) plus a lock entry re-keyedname@<url>.Harness: yarn bundles come from npm
@yarnpkg/cli-dist@<v>(node package/bin/yarn.js), because corepack's fetch can't use the sandbox proxy. Yarn 4 needsYARN_HTTPS_CA_FILE_PATH; yarn 2/3 needYARN_CA_FILE_PATH. The npm registry has 2.4.2 as the last 2.x in cli-dist. Agent and vendored cells hand-stage.socket/manifest.jsonplus blobs (a marker prepended toindex.js). Hosted cells use a local Python mock (fresh-checkout copies must keep.socket/for vendored cells) of the patch API (batch, by-package,patches/packagewith ayarn-berry-zipyarnBerry10c0artifact,view, and the tarball route). The 10c0 checksum is bootstrapped with a real yarnresolutions: file:install. Every hosted and vendored cell ends in a fresh-checkoutyarn install --immutable. v5: hosted rollback/remove need the mock's/upstream/npm/<uuid>.jsonroute,SOCKET_NPM_REGISTRYpointed at a local registry passthrough (the rustls binary can't use the sandbox proxy CA), and--patch-server-url <mock>so the pins count as hosted. Global (-g) cells use real npm global installs (NPM_CONFIG_PREFIX) and a Python mock of the authenticated API (--api-url <mock> --api-token x --org org; blob route/v0/orgs/org/patches/blob/<sha256>). v5 vendored mode downloads from the vendoring service: the same mock's/patches/packagewith a grantedtarballartifact (real sha512) is enough, and an optional per-patchstatusoverride (for examplepending_build) is supported. Acorepackshim (corepack yarn@X→node <cli-dist X>/bin/yarn.js, setting the CA env itself because the harness scrubsYARN_*) runs the repo's berry e2e suites in the sandbox (SOCKET_PATCH_YARN_E2E_REQUIRED=1,SOCKET_PATCH_YARN_BERRY_VERSION=<v>).setupwas removed in v5. On GH runners, fixture installs needYARN_ENABLE_IMMUTABLE_INSTALLS=false(CI turns immutable on). Run 8: the vendoring-service mock must also return ayarn-berry-zipartifact withintegrity.yarnBerry10c0, or vendor failsapply_failed. Hosted fresh installs from an http mock needYARN_UNSAFE_HTTP_WHITELIST=127.0.0.1. Run 9: the corepack shim must setYARN_HTTPS_CA_FILE_PATHonly for 4.x (yarn 4 rejects an envcaFilePath), and the batch mock must filter bycomponents[].purl. Run 10: one Python mock driven by a JSON config (per-patchhiddenandpublishedAtfor A→B upgrades) also serves/upstream/npm/<uuid>.jsonand a/registry/npmjs passthrough forSOCKET_NPM_REGISTRY. Never runpkill -f mock.pyfrom the shell that runs it. Run 12: the harness was rebuilt asmkpatch.py(patched tgz, bootstrap checksum, original registry checksum; never patchpackage.json) plus one mock that also logsAuthorization. Standalonevexagainst the mock needs--patch-server-url <mock>and the API flags. Run 11: the view route can carryblobContent/beforeBlobContent, so agent-modescanworks against the mock without hand-staging; stop the mock through a pidfile.Coverage matrix
Cells are "pass", "fail #N", "refused (by design)" or "untested". Linker is node-modules unless noted.
redirect_yarn_berry_cache_unsupported.store, real dirs), apply/vex/rollback byte-exactvendor_yarn_berry_cache_unsupported.storetransitive dep pass (#495 fixed); repo e2e suites pass (90/90);removeblob GC fail #559nmMode: hardlinks-globalpass after #486. Run 8 on 61cfb9b:nmMode: hardlinks-globalpass (only this project's link broken; rollback byte-exact),nmHoistingLimits: workspacespass (every copy). fail #559 (removesweeps the other patches' before blobs; also releases 4.0.0, 3.3.0). pass on f6b7fb9 (node-modules and pnpm linkers, rollback byte-exact). On 61cfb9b: pass for direct deps (pnpm linker, root and scoped) and hoisted transitive deps; fail #495 (pnpm-linker transitive dep only in.store/<slug>/package); repo e2e suites pass--revertbyte-exact), merged 3-descriptor entry (--revertbyte-exact),catalog:(default and named), root locator encoding (nameless root,()!~'*, space, unicode,+&=#), concurrent vendor (lock),repairof a deleted tgz. Two versions →vendor_override_conflict(correct).removeblob GC: fail #559. pass on 61cfb9b: pnpm linker (in-place + fresh--check-cache,--revertbyte-exact); PnP lock-only checkout vendors and loads patched bytes, but re-run after install fails #539 (also 4.0.2, 4.18.1); zero-install committed cache → YN0056 (docs gap). package.json tab / 4-space / BOM / CRLF+tab / no trailing newline / existing or emptyresolutions(fresh immutable +--revertbyte-exact); mixed-EOL yarn.lock refused loudly (vendor_yarn_berry_mixed_line_endings). pass on f6b7fb9: root, scoped root name, scoped target,**/glob resolution, workspaces, pnpm linker, re-run idempotent,--revert, in-place immutable install. pass on v5: root, workspaces +enableImmutableInstalls: true(--revertandremovebyte-exact), CRLF lock + package.json. Refused (by design): resolve/typescript (patch:builtin), yarn 3. fail #370 (commented compressionLevel). fail #369 (hosted→vendored viascan/get --mode vendored;vendoritself is fixed on v5). fail #468 (vendored→hosted with noyarnBerry10c0)packageExtensions-added dep, root peer + dev,=1.3.0/v1.3.0,portal:transitive,dependenciesMeta, workspace named like the target (each with fresh immutable and byte-exact rollback; vendored forpackageExtensions/portal:too); tarball-URL descriptor refused (correct);compressionLevel: mixedrefused in both modes. run 10 on 045d7ec:catalog:(default, named, workspace) fail #632 (regression from #465; release 4.0.0 passes); vendored→hosted takeover of a catalog dep also hits #632. Pass: A→B upgrade (re-pin, fresh immutable B, rollback byte-exact), pin survivesyarn add/dedupe/up, descriptor change → re-scan re-pins (vex attests nothing meanwhile),--cwdnested separate project (outer untouched). run 9 on 203e092 (resolutions pin, #465): pass for basic, workspaces merged entry, transitive, 7 range spellings (latest,>=1.3.0 <2,||,1.x,*,npm:forms), scoped, two versions, hardened mode × 3 linkers, package.json tab/4-space/CRLF/BOM/no-EOL/other resolutions (rollback byte-exact), CRLF lock +enableImmutableInstalls, scoped rollback/remove with two pins, hosted↔vendored takeovers, mixed vendored+hosted unwind, legacy__archiveUrlpin migration from release 4.0.0,compressionLevel: "0"and0 # c(#370 fixed), lock-only vex (orphan refused). #368 fixed (refusesresolve, nothing written). Interrupted (SIGKILL) vendor: recoverable. Earlier: pass: left-pad, pnpm linker + vex, rollback byte-exact; run 8:catalog:dep (fresh immutable patched); 61cfb9b: rollback and remove byte-exact fornpm:^1.3.0, dev-only and optional-only descriptors; v5 main:npm:1.3.0/npm:^1.3.0descriptors, dev-only and optional-only deps, mixed-case nameJSONStream(case-kept purl, also on 4.18.1), mixed-EOL lock refused loudly, scoped, CRLF, workspaces merged-range, re-scan idempotent, manifest-less rollback/remove/list byte-exact, PnP lock-only checkout, upgrade path (uuid A→B re-pin, then rollback byte-exact), hardened mode accepts__archiveUrlpins, vendored→hosted takeover (checksum present;pending_buildstays vendored). #368, #404, #369 and #370 are fixed on 203e092. Refused (by design): PnP (yarn_pnp_unsupported), direct + alias merged entry (redirect_yarn_berry_ambiguous_entry). PnP stale.pnp.cjs+ hosted pin → standalonevexattests unpatched copy: fail #519 (yarn-classic issue; berry evidence commented, also 4.0.2 and 4.18.1)patch:-descriptor package pass. Run 11: workspaces withnmMode: hardlinks-local+nmHoistingLimits: workspacespass (both copies patched, rollback restores both). Run 9 on 203e092: pnpm linker.storepass (#495 fixed); repo e2e suites pass (90/90); fail #559catalog:pass (bare-name pin). Run 8: namedcatalog:legacypass. pass on f6b7fb9 (CRLF-respelled lock + package.json); v5: fail #468; PnP lock-only: fail #539 (re-run)packageExtensions, peer + dev,=1.3.0pass. Run 10 on 045d7ec:catalog:fail #632; A→B upgrade,yarn add/dedupe/up, nested--cwdpass. Run 9: resolutions pin passes hardened mode × 3 linkers. Earlier: pass (left-pad, scoped, lockversion: 10); #368, #370, #404 and #468 fixed on 203e092conditions:) fail #697 (checksum afterconditions:; every conditional entry; also release 4.0.0).yarn removethen rollback: fail (#665, Berry evidence commented). Symlinkedyarn.lock/package.jsonreplaced: fail (#627, commented). Pass:yarn add/up/dedupeafter vendoring, then--revertkeeps the user's add@img/sharp-*) fail #697; esbuild (no deps) andsupportedArchitecturespass. Pass: two versions both patched (scoped rollback, byte-exact),debug(deps + peerDependenciesMeta),npmAlwaysAuth+ token (no auth to patch host, hardened), userpatch:descriptor refused, symlinked lock/package.json refusedGlobal (
-g) cells. Berry has no global dir, so these are npm-prefix globals scanned from inside or outside a Berry project:globalscript ran); otherwise pass, no project leak (node-modules, pnpm, PnP)not_appliedafter reinstall, EACCES loud,--global-prefixwith space and unicode).cmdshim not run)Backlog
send-pack: unexpected disconnect, and once the permission policy), so no new probes. The stale branchesbughunt/yarn-berry/20260930-builtin-patch-takeoverandbughunt/yarn-berry/20261001-global-scriptneed deleting by hand. After that, probe the resolutions pin on macOS and Windows (CRLF), plus Vendored yarn berry PnP refusal keys only on .pnp.cjs: a lock-only PnP checkout vendors successfully, then every re-run in an installed checkout fails exit 1 with vendor_yarn_berry_unsupported #539,remove <purl>garbage-collects the beforeHash blobs of every other patch still in the manifest, so a later offline rollback of those patches fails missing_blob #559, Hosted yarn berry pin of acatalog:dependency keysresolutionsby the resolvednpm:range, so everyyarn install --immutablefails YN0028 (regression from #465) #632 and Yarn berry vendored and hosted pins putchecksum:out of yarn's field order on platform-conditional lock entries (conditions: os=…), so everyyarn install --immutablefails YN0028 #697.checksum:out of yarn's field order on platform-conditional lock entries (conditions: os=…), so everyyarn install --immutablefails YN0028 #697 (conditional entries:@img/sharp-*,@esbuild/*direct and transitive, and one withbin:), Afteryarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665 Berry (Fix vendored revert keeping artifact for removed lock entry (#665) #689),remove <purl>garbage-collects the beforeHash blobs of every other patch still in the manifest, so a later offline rollback of those patches fails missing_blob #559 (Share rollback artifact retention across remove and rollback #600), Hosted yarn berry pin of acatalog:dependency keysresolutionsby the resolvednpm:range, so everyyarn install --immutablefails YN0028 (regression from #465) #632, Vendored yarn berry PnP refusal keys only on .pnp.cjs: a lock-only PnP checkout vendors successfully, then every re-run in an installed checkout fails exit 1 with vendor_yarn_berry_unsupported #539. Hosted yarn berry redirect of resolve/typescript (yarn builtin compat patch) reports success, then everyyarn install --immutablefails YN0028 #368, Hosted → vendored takeover on yarn berry reverts the hosted redirect before a per-package vendor refusal, leaving the package unpatched in both modes #369, Yarn berry vendored and hosted modes refusecompressionLevel: 0 # commentin .yarnrc.yml as a non-default compression level #370, Hosted yarn berry redirect makes yarn send the project's npm registry auth token to the patch host #404,scan -ginside a Yarn Berry project runs the project'sglobalpackage.json script and scans whatever directory it prints as a global install #440, Vendored → hosted takeover on yarn berry deletes the vendored patch, then skips the hosted rewrite when the grant has no yarnBerry10c0 checksum, and still exits 0 "fully hosted" #468 and Yarn 4 pnpm linker: transitive packages that live only in node_modules/.store are "not installed" in agent mode and stay unpatched #495 are closed..socket/vendor/npmshared by two projects) once Fix vendored revert deleting through a symlinked vendor dir (#664) #666 lands.-g) on macOS/Windows, and a version-manager prefix (nvm/volta). Full checklist in the 20261001T040000Z entry.pkg:npm/jsonstream@1.3.5) for a mixed-case package, and every mode misses it. File it (cross-PM) only if the real API is shown to lower-case.bin:plusconditions:, andpeerDependencieson the patched package itself.Known non-bugs
.pnp.cjsare refused in every mode withyarn_pnp_unsupported(documented).resolve,typescript,fsevents) is refused fail-closed withvendor_override_conflict. It's loud and closed, so it isn't filed (the hosted counterpart is Hosted yarn berry redirect of resolve/typescript (yarn builtin compat patch) reports success, then everyyarn install --immutablefails YN0028 #368).npm:alias ("left-pad@npm:1.3.0, lp@npm:left-pad@1.3.0") withredirect_yarn_berry_ambiguous_entryand exit 1. It's fail-closed and loud; arguably over-broad, but not filed.yarn install --immutablein the same tree doesn't restore unpatched bytes (yarn's install-state), and the setup hook re-patches after a clean install. Standalonevexin agent mode needssetuporsetup.manual(documented).patches-api.socket.devis unreachable from the sandbox; use the mock.yarn install --immutable(YN0028) on its own, because yarn strips the BOM. Not caused by socket-patch.npm:alias-only entry →redirect_yarn_berry_alias_skipped(documented in docs/ecosystems.md).scan <workspace-member-dir>finds 0 packages: hosted/vendored PATHs are project dirs, and members share the root's lock (CLI_CONTRACT "exclude it with ignorePackages, not paths")..pnp.cjs: scan reports 0 packages with a PnP warning (same in 4.0.0). A PnP lock-only checkout gets hosted pins, and those install correctly under PnP.patch.socket.dev(or--patch-server-url) URLs as hosted pins. Without that flag, a mock host reads as "Manifest not found"..pnp.js) and 3.x is detected and gets the loud PnP warning in every mode, exit 0 (same as 4.x).scan -g --mode agent) after a failed apply (EACCES) exits 0 with "already recorded … runsocket-patch apply". This is the designed re-run message;apply -gitself exits 1.scan -gdoesn't mention-g. It's cross-PM and was handed to npm (Bug hunt ledger: npm #302), so it isn't filed here.enableHardenedMode, auto-on for public fork PRs in GitHub Actions) accepts a hosted::__archiveUrl=lock pin, as does--check-resolutions(4.12.0, registry reachable).enableGlobalCache: falsewith.yarn/cachecommitted): hosted mode is lock-only, so the committed cache keeps the unpatched zip, andyarn install --immutable --immutable-cachefails YN0056 untilyarn installrefreshes the cache. Vendored mode behaves the same way (thefile:entry has no cache zip; no warning). It's a docs gap, not filed.compressionLevelset outside the project.yarnrc.yml(env, home or parent rc) can't cause a wrong checksum: yarn bakes the level into the lock'scacheKey, which both modes gate on.yarn patch(patch:descriptor) withvendor_override_conflict, plus an alias-only dependency (root or workspace member) withvendor_lock_entry_not_found, a merged direct + alias entry, and a user-authoredresolutionskey for the target. All are loud and closed with nothing written, so none are filed.yarn.lockis refused by vendored (vendor_yarn_berry_mixed_line_endings) and hosted (redirect_yarn_berry_mixed_line_endings). That's correct: yarn itself fails YN0028 on such a lock.rollbackdrops the patch's manifest entry, so a laterapplyis a no-op (designed).package.json. Vendored snapshots the post-install bytes and reverts to them byte-exactly.left-pad@1.2.0alongside the patched 1.3.0) withvendor_override_conflict, because the name-keyedresolutionswould move both. That's correct and loud.repairrefuses (vendor_artifact_redownload_failed, nothing written) when the service now serves different bytes for a uuid whose integrity is pinned in the ledger. That's correct.vendor --cwd <workspace member>fails loudly withvendor_lockfile_missing(the lock lives at the root).virtual:entries for peer-dependent packages, so the hosted/vendored rewrite has no virtual locator to keep in sync.package.jsonto 2-space and drops a user-authored empty"resolutions": {}. Yarn's own next install writes exactly the same bytes, so it isn't filed.redirect_yarn_berry_shared_descriptor,redirect_yarn_berry_ambiguous_entry,cache_unsupported) exit 0 withredirected: 0and nothing written. With--vexand nothing to attest, the run exits 1.resolutionsentry targeting the patched package (bare or scoped selector) withredirect_yarn_berry_resolutions_conflict. It's documented and loud.vendor --revertremoves the orphan, andvexrefuses.rollbackandrepairfail withmanifest_not_foundin that state.yarn add left-pad@1.3.0) leaves a staleresolutionsselector.rollbackin that state refuses loudly and tells you to re-runscan --mode hosted, which re-pins correctly. It's fail-closed and gives a remedy, so it isn't filed.left-pad@https://…tgz) is refused withredirect_yarn_berry_unsupported_protocol, exit 0, nothing written. That's correct.compressionLevel: mixed(cacheKey10) is refused by hosted (redirect_yarn_berry_cache_unsupported, exit 0) and vendored (vendor_yarn_berry_cache_unsupported, exit 1). Both are documented.patch:descriptor independenciesis refused (redirect_yarn_berry_unsupported_protocol+redirect_yarn_berry_shared_descriptor), nothing written. That's correct. The hint suggests--mode vendored, which also refuses it;--mode agentworks.checksum:for a platform-conditional entry reached only throughoptionalDependencies, and strips one on its next mutable install. A hosted pin's checksum on such an entry therefore doesn't surviveyarn add;vexstill attests from the installed tree. That's yarn's policy. The misplaced-line part is Yarn berry vendored and hosted pins putchecksum:out of yarn's field order on platform-conditional lock entries (conditions: os=…), so everyyarn install --immutablefails YN0028 #697.All reactions