You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[agent] Found by the scheduled Yarn classic (1.x) bug-hunt routine (ledger #304).
Summary
Yarn classic can install into a folder other than node_modules, using --modules-folder <dir>. It's usually set project-wide in .yarnrc as --modules-folder deps, and Node then loads that folder through NODE_PATH (Docker layer caching, Electron and Meteor builds). The npm crawler only looks for literal node_modules directories (find_local_node_modules_dirs) and never reads .yarnrc. Packages that are really installed in <dir> therefore fall through to the lockfile supplement as notInstalled: true:
scan --mode agent --yes exits 0 with status: success and applied: 0. It prints no warning that the configured install folder was never checked.
get <uuid> --mode agent records the patch, and apply then fails with "matched no installed package … 1 not found on disk", even though the package is on disk at deps/left-pad.
This is the same class of defect as #359 / #362 (fixed in #365 for npm .store and pnpm virtualStoreDir), #366 (bun) and #373 (deno), here for yarn classic's own relocation setting.
Impact
A yarn classic project that uses --modules-folder can't be patched in agent mode, and scan --mode agent makes that look like a clean, successful run. VEX stays conservative (package_not_found, nothing attested), so there's no false attestation. Hosted and vendored modes aren't affected, because they work from yarn.lock.
Repro (Linux, Node 22)
mkdir p &&cd p
echo'{"name":"app","version":"1.0.0","private":true,"dependencies":{"left-pad":"1.3.0"}}'> package.json
echo'--modules-folder deps'> .yarnrc
yarn install # yarn 1.22.22 → deps/left-pad, no node_modules/
socket-patch scan --mode agent --yes --json --api-url <mock> --org test-org --api-token fake
# → status "success", apply.applied 0, packages[0].notInstalled true, warnings: none
socket-patch get <uuid> --mode agent --yes # writes .socket/manifest.json
socket-patch apply # exit 1: "matched no installed package … 1 not found on disk"
NODE_PATH=deps node -e "console.log(require('fs').readFileSync(require.resolve('left-pad'),'utf8').slice(0,20))"# → original, unpatched bytes
I drove it with a local mock patch API (the repo's e2e_redirect_yarn_classic_build.rs mock shape) serving a patch for left-pad@1.3.0.
Expected vs actual
Expected: docs/ecosystems.md lists npm-family agent mode as "✅ any install layout", and CLI_CONTRACT's "Lockfile supplement" uses notInstalled for dependencies with no installed copy. Agent mode should find and patch the copies in the folder .yarnrc names. If that isn't supported, it should warn, as yarn_pnp_unsupported does, rather than report the package as not installed.
Actual: the configured install folder is never crawled. The run is a quiet success with nothing applied, and apply's error says the package isn't on disk.
OS × version
OS
yarn
reproduces
Linux
1.7.0
yes (2/2)
Linux
1.10.1
yes (2/2)
Linux
1.22.22
yes (2/2)
macOS / Windows
—
not probed: the crawler path logic is OS-independent
Tested on main 61cfb9b (after #365). It isn't a regression: the crawler has never read .yarnrc.
Suspect code
crates/socket-patch-core/src/crawlers/npm_crawler.rs:1418find_local_node_modules_dirs: only <cwd>/node_modules plus workspace node_modules dirs are roots. There's no .yarnrc--modules-folder / modules-folder lookup, unlike the pnpm .modules.yamlvirtualStoreDir handling Fix npm crawler missing relocated dependency stores (#359, #362) #365 added.
[agent] Found by the scheduled Yarn classic (1.x) bug-hunt routine (ledger #304).
Summary
Yarn classic can install into a folder other than
node_modules, using--modules-folder <dir>. It's usually set project-wide in.yarnrcas--modules-folder deps, and Node then loads that folder throughNODE_PATH(Docker layer caching, Electron and Meteor builds). The npm crawler only looks for literalnode_modulesdirectories (find_local_node_modules_dirs) and never reads.yarnrc. Packages that are really installed in<dir>therefore fall through to the lockfile supplement asnotInstalled: true:scan --mode agent --yesexits 0 withstatus: successandapplied: 0. It prints no warning that the configured install folder was never checked.get <uuid> --mode agentrecords the patch, andapplythen fails with "matched no installed package … 1 not found on disk", even though the package is on disk atdeps/left-pad.This is the same class of defect as #359 / #362 (fixed in #365 for npm
.storeand pnpmvirtualStoreDir), #366 (bun) and #373 (deno), here for yarn classic's own relocation setting.Impact
A yarn classic project that uses
--modules-foldercan't be patched in agent mode, andscan --mode agentmakes that look like a clean, successful run. VEX stays conservative (package_not_found, nothing attested), so there's no false attestation. Hosted and vendored modes aren't affected, because they work fromyarn.lock.Repro (Linux, Node 22)
I drove it with a local mock patch API (the repo's
e2e_redirect_yarn_classic_build.rsmock shape) serving a patch forleft-pad@1.3.0.Expected vs actual
notInstalledfor dependencies with no installed copy. Agent mode should find and patch the copies in the folder.yarnrcnames. If that isn't supported, it should warn, asyarn_pnp_unsupporteddoes, rather than report the package as not installed.apply's error says the package isn't on disk.OS × version
Tested on main
61cfb9b(after #365). It isn't a regression: the crawler has never read.yarnrc.Suspect code
crates/socket-patch-core/src/crawlers/npm_crawler.rs:1418find_local_node_modules_dirs: only<cwd>/node_modulesplus workspacenode_modulesdirs are roots. There's no.yarnrc--modules-folder/modules-folderlookup, unlike the pnpm.modules.yamlvirtualStoreDirhandling Fix npm crawler missing relocated dependency stores (#359, #362) #365 added.