Skip to content

Global mode never finds yarn 1.0.x global packages: yarn global dir doesn't exist before yarn 1.1.0, and there's no fallback #437

Description

[agent] Found by the scheduled Yarn classic (1.x) bug-hunt routine (ledger #304).

Summary

scan -g, scan -g --mode agent, get -g, rollback -g and vex -g find yarn's global packages only by running yarn global dir. That subcommand doesn't exist in yarn 1.0.0–1.0.2: it prints error Invalid subcommand. Try "add, bin, ls, list, remove, upgrade, upgrade-interactive" and exits 1. The lookup then returns None, nothing else probes yarn's global folder, and every package installed with yarn global add is silently left out. Every command exits 0 with status: success.

Yarn 1.1.0 added yarn global dir. I bisected through corepack: 1.0.2 exits 1, while 1.1.0, 1.2.1, 1.3.2, 1.4.0, 1.5.1 and 1.6.0 print the folder. The folder itself (~/.config/yarn/global, or /usr/local/share/.config/yarn/global for root, %LOCALAPPDATA%\Yarn\Data\global on Windows) hasn't moved between 1.0 and 1.1.

Impact

It's a silent miss. On a machine with yarn 1.0.x, scan -g reports no patchable yarn-global tools, and scan -g --mode agent exits 0 with applied: 0 while the global copy stays vulnerable. The routine's version range (and CI's yarn-classic-matrix, which starts at 1.0.2) treats 1.0.x as supported, and docs/ecosystems.md doesn't mention this limitation. Yarn 1.0.x is old (2017), so this is low priority, but the result is a false all-clear rather than a refusal.

Repro (Linux sandbox, main 2463257)

corepack yarn@1.0.2 global add is-number@7.0.0   # lands in /usr/local/share/.config/yarn/global/node_modules (root)
corepack yarn@1.0.2 global dir                    # error Invalid subcommand …   (exit 1)
# with `yarn` on PATH = yarn 1.0.2, mock patch API serving pkg:npm/is-number@7.0.0:
socket-patch scan -g $API --json                  # status success, packages []           <- miss
socket-patch scan -g --mode agent $API --json     # status success, apply.applied 0, exit 0
head -1 /usr/local/share/.config/yarn/global/node_modules/is-number/index.js   # still upstream
# same machine, same global folder, `yarn` = 1.1.0:
socket-patch scan -g $API --json                  # packages ["pkg:npm/is-number@7.0.0"]  <- found

Expected vs actual

  • Expected: CLI_CONTRACT.md documents --global as "Operate on globally-installed packages", with --global-prefix defaulting to "(auto)". The global-mode checklist (ledger Bug hunt ledger: Yarn classic (1.x) #304) requires scan -g to find every globally installed package, with none missing. When yarn is on PATH but yarn global dir fails, socket-patch should fall back to yarn's default global folder (or yarn global bin's sibling, or .yarnrc global-folder). Failing that, it should warn that yarn's global folder couldn't be determined, rather than report a clean scan.
  • Actual: yarn-global packages are invisible, with exit 0.

OS × yarn matrix (probe run, plus the Linux sandbox)

OS yarn 1.0.2 yarn 1.10.1 yarn 1.22.22
Linux (sandbox + ubuntu-latest) miss (scan_report, agent_apply, vex fail) pass pass
macOS (macos-latest) miss pass pass
Windows (windows-latest) miss (also #434) miss, see #434 miss, see #434

On Windows every yarn version misses, for a separate reason: the bare yarn spawn never resolves yarn.cmd, which is tracked in #434. 1.0.x would still miss after that fix.

Suspect code

  • crates/socket-patch-core/src/crawlers/npm_crawler.rs:514: get_yarn_global_prefix_with runs only yarn global dir. None (non-zero exit) is final.
  • crates/socket-patch-core/src/crawlers/npm_crawler.rs:1151: get_global_node_modules_paths has no yarn fallback. The only fallbacks are the macOS-only npm ones.

Probe run: https://github.com/SocketDev/socket-patch/actions/runs/36827174726 (jobs global * yarn 1.0.2 print global dir: yarn global v1.0.2 … /node_modules and scan_report … result=FAIL).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions