Skip to content

Agent mode ignores yarn classic's --modules-folder: packages installed there are reported "not installed" and scan --mode agent exits 0 leaving them unpatched #493

Description

[agent] Found by the scheduled Yarn classic (1.x) bug-hunt routine (ledger #304).

Summary

Yarn classic can install into a folder other than node_modules, using --modules-folder <dir>. It's usually set project-wide in .yarnrc as --modules-folder deps, and Node then loads that folder through NODE_PATH (Docker layer caching, Electron and Meteor builds). The npm crawler only looks for literal node_modules directories (find_local_node_modules_dirs) and never reads .yarnrc. Packages that are really installed in <dir> therefore fall through to the lockfile supplement as notInstalled: true:

  • scan --mode agent --yes exits 0 with status: success and applied: 0. It prints no warning that the configured install folder was never checked.
  • get <uuid> --mode agent records the patch, and apply then fails with "matched no installed package … 1 not found on disk", even though the package is on disk at deps/left-pad.

This is the same class of defect as #359 / #362 (fixed in #365 for npm .store and pnpm virtualStoreDir), #366 (bun) and #373 (deno), here for yarn classic's own relocation setting.

Impact

A yarn classic project that uses --modules-folder can't be patched in agent mode, and scan --mode agent makes that look like a clean, successful run. VEX stays conservative (package_not_found, nothing attested), so there's no false attestation. Hosted and vendored modes aren't affected, because they work from yarn.lock.

Repro (Linux, Node 22)

mkdir p && cd p
echo '{"name":"app","version":"1.0.0","private":true,"dependencies":{"left-pad":"1.3.0"}}' > package.json
echo '--modules-folder deps' > .yarnrc
yarn install                        # yarn 1.22.22 → deps/left-pad, no node_modules/
socket-patch scan --mode agent --yes --json --api-url <mock> --org test-org --api-token fake
#  → status "success", apply.applied 0, packages[0].notInstalled true, warnings: none
socket-patch get <uuid> --mode agent --yes   # writes .socket/manifest.json
socket-patch apply                            # exit 1: "matched no installed package … 1 not found on disk"
NODE_PATH=deps node -e "console.log(require('fs').readFileSync(require.resolve('left-pad'),'utf8').slice(0,20))"
#  → original, unpatched bytes

I drove it with a local mock patch API (the repo's e2e_redirect_yarn_classic_build.rs mock shape) serving a patch for left-pad@1.3.0.

Expected vs actual

  • Expected: docs/ecosystems.md lists npm-family agent mode as "✅ any install layout", and CLI_CONTRACT's "Lockfile supplement" uses notInstalled for dependencies with no installed copy. Agent mode should find and patch the copies in the folder .yarnrc names. If that isn't supported, it should warn, as yarn_pnp_unsupported does, rather than report the package as not installed.
  • Actual: the configured install folder is never crawled. The run is a quiet success with nothing applied, and apply's error says the package isn't on disk.

OS × version

OS yarn reproduces
Linux 1.7.0 yes (2/2)
Linux 1.10.1 yes (2/2)
Linux 1.22.22 yes (2/2)
macOS / Windows — not probed: the crawler path logic is OS-independent

Tested on main 61cfb9b (after #365). It isn't a regression: the crawler has never read .yarnrc.

Suspect code

  • crates/socket-patch-core/src/crawlers/npm_crawler.rs:1418 find_local_node_modules_dirs: only <cwd>/node_modules plus workspace node_modules dirs are roots. There's no .yarnrc --modules-folder / modules-folder lookup, unlike the pnpm .modules.yaml virtualStoreDir handling Fix npm crawler missing relocated dependency stores (#359, #362) #365 added.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions