Fix yarn berry hosted pin of catalog deps (#632) - #763
Mikola Lysenko (mikolalysenko) wants to merge 4 commits into
Conversation
Assisted-by: Claude Code:claude-opus-5-5
A dependency declared "catalog:" in package.json was never patched by scan --mode hosted: the resolutions entry was keyed by the lock's expanded npm: range, but yarn matches resolutions before it expands the catalog. The scan reported success, then yarn install --immutable failed (YN0028) and a plain yarn install kept the unpatched release. Also route name@catalog: / name@catalog:<named> for every .yarnrc.yml catalog that maps the package to a pinned range. A re-run adds the selector to a pin written by an earlier release. Fixes #632 Assisted-by: Claude Code:claude-opus-5-5
Add a real-yarn check that a fresh checkout of a hosted-pinned catalog dependency installs the patched bytes under --immutable, an in-process scan + rollback round trip, and document catalog pins in the yarn berry hosted notes. Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
cargo fmt --all also reformatted 127 files this fix doesn't touch (main isn't rustfmt-clean). Restore them and the untouched hunks of the edited files to main, so the PR only carries the catalog fix, its tests and the docs note. Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 55dc0cb. Configure here.
|
One CI check failed on 55dc0cb: I don't think this PR caused it:
I don't have a fix to port, because I haven't found a root cause in the PDM path. I've re-run the failed job once. If it fails again, I'll treat it as a real failure and dig in. Generated by Claude Code |
|
Ready for review at
Generated by Claude Code |
LLM Description written by Claude Code:claude-opus-5-5
Fixes #632
Summary
scan --mode hostednow pins yarn berry dependencies declared through a yarn catalog ("left-pad": "catalog:"). Before this, the scan reportedredirected: 1, but the nextyarn install --immutablefailed with YN0028 and a plainyarn installsilently installed the unpatched release. This was a regression from #465.Root cause
Since #465 the hosted yarn berry pin routes the lock entry's descriptors to the hosted tarball through root
package.jsonresolutions, keyedname@npm:<range>. Those keys come from the lock key's expanded ranges inberry_resolutions_pin. Yarn matchesresolutionsagainst the manifest descriptor before it expands the catalog, soleft-pad@npm:^1.3.0never matches a dependency declaredcatalog:orcatalog:<named>.Fix
berry_resolutions_pinreads the.yarnrc.ymlcatalog:/catalogs:tables through the newberry_catalog_selectors(serde-saphyr). Some catalogs give the package a range that, normalized to yarn'snpm:form, is one of the pinned ranges. For each of those, the pin also routesname@catalog:orname@catalog:<named>to the hosted tarball.npm:selectors stay: transitive dependents still ask for the expanded range, and rollback rebuilds the lock key from them.npm:selector) adds the missing catalog selector and leaves the lock alone.npm:ones; a new test covers this.name@catalog:resolution still refuses withredirect_yarn_berry_resolutions_conflict.Checked by hand with real yarn 4.12.0:
{"left-pad@npm:^1.3.0": X, "left-pad@catalog:": X}installs the patched bytes for acatalog:dependency, and--immutablepasses.catalog:selector is harmless: the install gets the patched bytes and--immutablepasses.Per-issue checklist
catalog:dependency keysresolutionsby the resolvednpm:range, so everyyarn install --immutablefails YN0028 (regression from #465) #632, default catalog:yarn_berry_pin_routes_a_default_catalog_dependency(LF, and BOM + CRLF.yarnrc.yml, quotednpm:value)catalog:dependency keysresolutionsby the resolvednpm:range, so everyyarn install --immutablefails YN0028 (regression from #465) #632, workspace with default + named catalog in one merged entry:yarn_berry_pin_routes_every_catalog_locking_the_entry. Catalogs with another range, another package, or apatch:protocol are ignored.catalog:dependency keysresolutionsby the resolvednpm:range, so everyyarn install --immutablefails YN0028 (regression from #465) #632, re-run loop:yarn_berry_catalog_pin_rerun_is_stable_and_heals_an_old_pin. A re-run is a no-op, and a pin written before this fix gets healed.catalog:dependency keysresolutionsby the resolvednpm:range, so everyyarn install --immutablefails YN0028 (regression from #465) #632, rollback:in_process_redirect::yarn_berry_catalog_dependency_is_pinned_and_rolled_back. package.json comes back byte-identical, and the lock gets itsnpm:key back.catalog:dependency keysresolutionsby the resolvednpm:range, so everyyarn install --immutablefails YN0028 (regression from #465) #632, real install:e2e_redirect_yarn_berry_build::berry_redirect_catalog_dependency_fresh_checkout_installs(real yarn 4.12.0). A freshyarn install --immutable --check-cacheinstalls the patched bytes. On yarn < 4.10 the test prints a note and returns, because catalogs don't exist there.Test evidence
left-pad@catalog:selector). With the fix, all pass:cargo test -p socket-patch-core --lib -- yarn_berrygives 99 passed.cargo test -p socket-patch-cli --test in_process_redirect -- yarn_berry: 5 passed.SOCKET_PATCH_YARN_E2E_REQUIRED=1 cargo test -p socket-patch-cli --test e2e_redirect_yarn_berry_build: 15 passed against real yarn 4.12.0.cargo fmt --all -- --checkalso flags pre-existing files on main).cargo clippy --workspace --all-features -- -D warningsis clean.cargo test --workspace --all-features --no-fail-fastlocally: 9728 passed, 14 failed. All 14 failures come from the sandbox:mode_migration_npmberry takeover fixtures. Their setup downloads from registry.npmjs.org with a client that rejects the sandbox proxy's TLS certificate.cargo fmt --allhad also reformatted 127 files this PR doesn't touch, because main is not rustfmt-clean. The diff is now just the 4 files above. The targeted tests and clippy were re-run after the backout and pass (results above).native (ubuntu-latest, 2.8.2)failed once (optional hosted,rescanIdempotent) and passed when re-run. Bugbot reviewed 55dc0cb and found no issues.🤖 Generated with Claude Code
https://claude.ai/code/session_01DPHxnE5P1rkfCpHFFCwzFR
Generated by Claude Code