[agent] Found by the scheduled Yarn classic (1.x) bug-hunt routine (ledger #304).
Summary
scan -g, scan -g --mode agent, get -g, rollback -g and vex -g find yarn's global packages only by running yarn global dir. That subcommand doesn't exist in yarn 1.0.0–1.0.2: it prints error Invalid subcommand. Try "add, bin, ls, list, remove, upgrade, upgrade-interactive" and exits 1. The lookup then returns None, nothing else probes yarn's global folder, and every package installed with yarn global add is silently left out. Every command exits 0 with status: success.
Yarn 1.1.0 added yarn global dir. I bisected through corepack: 1.0.2 exits 1, while 1.1.0, 1.2.1, 1.3.2, 1.4.0, 1.5.1 and 1.6.0 print the folder. The folder itself (~/.config/yarn/global, or /usr/local/share/.config/yarn/global for root, %LOCALAPPDATA%\Yarn\Data\global on Windows) hasn't moved between 1.0 and 1.1.
Impact
It's a silent miss. On a machine with yarn 1.0.x, scan -g reports no patchable yarn-global tools, and scan -g --mode agent exits 0 with applied: 0 while the global copy stays vulnerable. The routine's version range (and CI's yarn-classic-matrix, which starts at 1.0.2) treats 1.0.x as supported, and docs/ecosystems.md doesn't mention this limitation. Yarn 1.0.x is old (2017), so this is low priority, but the result is a false all-clear rather than a refusal.
Repro (Linux sandbox, main 2463257)
corepack yarn@1.0.2 global add is-number@7.0.0 # lands in /usr/local/share/.config/yarn/global/node_modules (root)
corepack yarn@1.0.2 global dir # error Invalid subcommand … (exit 1)
# with `yarn` on PATH = yarn 1.0.2, mock patch API serving pkg:npm/is-number@7.0.0:
socket-patch scan -g $API --json # status success, packages [] <- miss
socket-patch scan -g --mode agent $API --json # status success, apply.applied 0, exit 0
head -1 /usr/local/share/.config/yarn/global/node_modules/is-number/index.js # still upstream
# same machine, same global folder, `yarn` = 1.1.0:
socket-patch scan -g $API --json # packages ["pkg:npm/is-number@7.0.0"] <- found
Expected vs actual
- Expected: CLI_CONTRACT.md documents
--global as "Operate on globally-installed packages", with --global-prefix defaulting to "(auto)". The global-mode checklist (ledger Bug hunt ledger: Yarn classic (1.x) #304) requires scan -g to find every globally installed package, with none missing. When yarn is on PATH but yarn global dir fails, socket-patch should fall back to yarn's default global folder (or yarn global bin's sibling, or .yarnrc global-folder). Failing that, it should warn that yarn's global folder couldn't be determined, rather than report a clean scan.
- Actual: yarn-global packages are invisible, with exit 0.
OS × yarn matrix (probe run, plus the Linux sandbox)
| OS |
yarn 1.0.2 |
yarn 1.10.1 |
yarn 1.22.22 |
| Linux (sandbox + ubuntu-latest) |
miss (scan_report, agent_apply, vex fail) |
pass |
pass |
| macOS (macos-latest) |
miss |
pass |
pass |
| Windows (windows-latest) |
miss (also #434) |
miss, see #434 |
miss, see #434 |
On Windows every yarn version misses, for a separate reason: the bare yarn spawn never resolves yarn.cmd, which is tracked in #434. 1.0.x would still miss after that fix.
Suspect code
crates/socket-patch-core/src/crawlers/npm_crawler.rs:514: get_yarn_global_prefix_with runs only yarn global dir. None (non-zero exit) is final.
crates/socket-patch-core/src/crawlers/npm_crawler.rs:1151: get_global_node_modules_paths has no yarn fallback. The only fallbacks are the macOS-only npm ones.
Probe run: https://github.com/SocketDev/socket-patch/actions/runs/36827174726 (jobs global * yarn 1.0.2 print global dir: yarn global v1.0.2 … /node_modules and scan_report … result=FAIL).
[agent] Found by the scheduled Yarn classic (1.x) bug-hunt routine (ledger #304).
Summary
scan -g,scan -g --mode agent,get -g,rollback -gandvex -gfind yarn's global packages only by runningyarn global dir. That subcommand doesn't exist in yarn 1.0.0–1.0.2: it printserror Invalid subcommand. Try "add, bin, ls, list, remove, upgrade, upgrade-interactive"and exits 1. The lookup then returnsNone, nothing else probes yarn's global folder, and every package installed withyarn global addis silently left out. Every command exits 0 withstatus: success.Yarn 1.1.0 added
yarn global dir. I bisected through corepack: 1.0.2 exits 1, while 1.1.0, 1.2.1, 1.3.2, 1.4.0, 1.5.1 and 1.6.0 print the folder. The folder itself (~/.config/yarn/global, or/usr/local/share/.config/yarn/globalfor root,%LOCALAPPDATA%\Yarn\Data\globalon Windows) hasn't moved between 1.0 and 1.1.Impact
It's a silent miss. On a machine with yarn 1.0.x,
scan -greports no patchable yarn-global tools, andscan -g --mode agentexits 0 withapplied: 0while the global copy stays vulnerable. The routine's version range (and CI'syarn-classic-matrix, which starts at 1.0.2) treats 1.0.x as supported, and docs/ecosystems.md doesn't mention this limitation. Yarn 1.0.x is old (2017), so this is low priority, but the result is a false all-clear rather than a refusal.Repro (Linux sandbox, main
2463257)Expected vs actual
--globalas "Operate on globally-installed packages", with--global-prefixdefaulting to "(auto)". The global-mode checklist (ledger Bug hunt ledger: Yarn classic (1.x) #304) requiresscan -gto find every globally installed package, with none missing. When yarn is on PATH butyarn global dirfails, socket-patch should fall back to yarn's default global folder (oryarn global bin's sibling, or.yarnrcglobal-folder). Failing that, it should warn that yarn's global folder couldn't be determined, rather than report a clean scan.OS × yarn matrix (probe run, plus the Linux sandbox)
scan_report,agent_apply,vexfail)On Windows every yarn version misses, for a separate reason: the bare
yarnspawn never resolvesyarn.cmd, which is tracked in #434. 1.0.x would still miss after that fix.Suspect code
crates/socket-patch-core/src/crawlers/npm_crawler.rs:514:get_yarn_global_prefix_withruns onlyyarn global dir.None(non-zero exit) is final.crates/socket-patch-core/src/crawlers/npm_crawler.rs:1151:get_global_node_modules_pathshas no yarn fallback. The only fallbacks are the macOS-only npm ones.Probe run: https://github.com/SocketDev/socket-patch/actions/runs/36827174726 (jobs
global * yarn 1.0.2printglobal dir: yarn global v1.0.2 … /node_modulesandscan_report … result=FAIL).