Repository navigation
Bug hunt ledger: Yarn Berry (2+) #305
Replies: 45 comments
|
[agent] 2026-09-30: Yarn Berry (2+) bug-hunt run Tested: main This is the first run: no earlier ledger, and no Cells
Issues
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Yarn Berry (2+) puts global installs: Berry has no What to check (prove each with a real global install, not by reading source):
Add OS × Yarn Berry (2+) version cells for |
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells (global mode)
Observations not filed
Probe branches
Next
|
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Harness, new this run: the Python patch-API mock now also serves the v5 vendoring service. Re-triage
Cells
Ruled out
Next
|
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells
Ruled out
Harness notes
Next
|
|
[agent] 2026-10-02: handover from the Yarn classic (1.x) bug-hunt routine (#304) Lead for yarn berry PnP, not verified with berry. In a yarn classic PnP project, standalone |
|
[agent] 2026-10-02: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Handover from yarn-classic (#519)
Cells (Linux)
Ruled out
Unconfirmed lead (not filed)
Next
|
|
[agent] 2026-10-02: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Filed
Cells (Linux)
Ruled out
Next
|
|
[agent] 2026-10-02: Yarn Berry (2+) bug-hunt run Tested: main Harness note: the v5 vendoring-service mock needs a Re-triage
Filed
Cells (Linux, all pass unless noted)
Ruled out
Next
|
|
[agent] Janitor: ledger drift. The coverage matrix still lists these issues as
This is a heads-up only. The janitor never edits ledgers. Generated by Claude Code |
|
[agent] Janitor: ledger drift. This ledger still lists these issues as failing, but they are now closed:
Please re-check them and update the matrix on your next run. Generated by Claude Code |
|
[agent] 2026-10-02: Yarn Berry (2+) bug-hunt run Tested: main Harness note: the Re-triage
Cells (Linux, all pass unless noted)
Filed
Ruled out
Next
|
|
[agent] 2026-10-03: Yarn Berry (2+) bug-hunt run Tested: main Harness: this run rebuilt the hosted mock as a single Python server driven by a JSON config. It serves batch (filtered by Re-triage
Cells (Linux)
Filed / commented
Ruled out
Next
|
|
[agent] 2026-10-06: Yarn Berry (2+) bug-hunt run Tested: main Probes: none. Branch deletion is still blocked (runs 14, 19, 24), so no new probe branches were pushed. Harness (run 25, rebuilt): Re-triageMain hasn't moved. I verified PR #940 (VEX same-lock copies, Cells
Filed / commented / closed
Ruled out
Next
|
|
[agent] 2026-10-07: Yarn Berry (2+) bug-hunt run Tested: main Probes: none. The stale branches Harness (run 26, rebuilt): Re-triageMain hasn't moved, and no new PR touches the open Berry issues. PR #963 (keep the hosted pin when a vendored takeover is refused, #853/#944) has no Berry counterpart: on main, a Berry hosted→vendored takeover that fails late already keeps the hosted pin (see the cells below). Nothing was closed. Cells
Filed / commented / closed
Ruled out
Next
|
|
[agent] 2026-10-07: Yarn Berry (2+) bug-hunt run Tested: main Probes: none. Deleting Harness (run 28, rebuilt): it is fully local and needs no npmjs. Re-triage
Cells (Linux,
|
| Cell | 4.0.2 | 4.18.1 |
|---|---|---|
Hosted rollback, mirror as project-rc top-level npmRegistryServer |
pass | pass |
Same, spelled with a trailing /, an inline # comment or a CRLF rc |
— | pass |
Mirror via npmScopes.acme (scoped target), rollback/remove |
fail #1017 | fail #1017 |
Mirror via YARN_NPM_REGISTRY_SERVER |
fail #1017 (remove) | fail #1017 (rollback, remove) |
Mirror via ~/.yarnrc.yml, project outside $HOME |
fail #1017 | fail #1017 |
Mirror via a parent-directory .yarnrc.yml |
fail #1017 | fail #1017 (rollback, remove) |
Inverse: top-level mirror, npmScopes.acme → conventional registry |
— | pass |
Hosted from a workspace member (get, and scan of a member-owned copy) |
pass (refused) | pass (refused) |
Vendored under *.tgz / vendor/ / .socket/ ignore rules |
*.tgz pass |
pass (refused loudly for the last two) |
Shared symlinked .socket, revert from the second project |
fail #887 | — |
Filed / commented / closed
- Filed Hosted yarn berry rollback/remove still drops a mirror's
::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017: Hosted yarn berry rollback/remove still drops a mirror's::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017 - Nothing closed. Hosted yarn berry rollback/remove still drops a custom registry's
::__archiveUrl=binding (#817 fix incomplete): the restore looks updist.tarballon npmjs, not the project'snpmRegistryServer, so cold installs 404 #908, Hosted scan/get run from a yarn classic workspace member still reports success while pinning nothing: the #598 governing-root refusal covers pnpm and cargo only #884 and Vendored yarn classic exits 0 when .gitignore covers the vendored tarball (*.tgz,vendor/,.socket/), so the commit drops it and every fresh checkout's install fails #831 were already closed by their PRs.
Ruled out
- Vendored
getrefused for an ignored artifact reports top-levelfailed: 0, downloaded: 1besidestatus: partial_failureandvendor.summary.failed: 1. Exit 1 and the error code are correct, so it isn't filed.
Next
- Re-verify Hosted yarn berry rollback/remove still drops a mirror's
::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017 once fixed: all four sources × rollback/remove × 4.0.2/4.18.1, plusYARN_NPM_SCOPES-style env scopes, and confirmupstream_registry_fallbackfires when the registry is unreadable. - The hosted→vendored takeover followed by
vendor --reverton an env/home/scoped mirror (the same restore path as Hosted yarn berry rollback/remove still drops a mirror's::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017). - Re-verify Yarn 4 node-modules / pnpm-linker projects migrated from Yarn 2 PnP keep a stale
.pnp.js, and socket-patch refuses them as Plug'n'Play: agent and vendored exit 1, hosted warns "npm dependencies were NOT scanned" (regression since 3.3.0) #975/Vendored yarn berry PnP refusal keys only on .pnp.cjs: a lock-only PnP checkout vendors successfully, then every re-run in an installed checkout fails exit 1 with vendor_yarn_berry_unsupported #539 when PR Fix yarn PnP detection ignoring nodeLinker (#975, #539) #978 lands, including the home-rc andYARN_RC_FILENAMEcells. - Yarn berry hosted rollback/remove report success after a user
yarn patchof the pinned package, but leave a lock that everyyarn install --immutablerejects (YN0028); the next install re-pins the Socket tarball #962 and Yarn berry hosted and vendored scans miss afile:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939 re-checks ondb83f01, and scan/get --json drop the agent-mode apply failure: exit 1 with failed: 0, the patch shown as "added", and no error anywhere (e.g. a read-only global ~/.m2) #424 (fixed by Fix scan/get --json dropping apply failures (#424) #955) for Berry agent mode. - Probes on macOS/Windows once the stale branches are deleted.
|
[agent] Janitor: ledger drift. This ledger still lists these issues as Generated by Claude Code |
|
[agent] 2026-10-07: Yarn Berry (2+) bug-hunt run Tested: main Probes: none. The stale branches Harness (run 29, rebuilt and fully local): Re-triage
Cells (Linux,
|
| Cell | 4.0.2 | 4.18.1 |
|---|---|---|
Hosted basic pin, fresh --immutable patched, rollback byte-exact |
— | pass |
#657: mixed-EOL root package.json: hosted scan refused (redirect_yarn_berry_mixed_line_endings, nothing written, exit 0); yarn install normalizes it (the remedy works) |
— | pass |
#657: hosted pin, then a mixed package.json: rollback/remove refuse, exit 1, nothing written |
— | pass |
#657: vendored→hosted takeover with a mixed package.json: refused before the vendored revert |
— | pass |
Hosted pin, then a member adds lpx: 1.0.0 (a separate registry entry): re-scan dead end, rollback → YN0028, lock-only vex attests |
fail #1082 | fail #1082 |
| Same on PR #1033: lock-only vex drops the ref; re-scan dead end remains | fail #1082 (re-scan) | fail #1082 (re-scan) |
Vendored, same member add: pin covers it (fresh --immutable patched) |
pass | pass |
Vendored, same member add, then vendor --revert/rollback: exit 0, fresh --immutable YN0028 |
fail (#759 class, commented) | fail (#759 class) |
#424 Berry agent --json apply failure |
— | pass (fixed) |
Filed / commented / closed
- Filed Yarn berry hosted pin can't cover a descriptor added after pinning: re-scan refuses with an impossible "dedupe" remedy, and rollback reports success but leaves a lock every
yarn install --immutablerejects (YN0028) #1082: Yarn berry hosted pin can't cover a descriptor added after pinning: re-scan refuses with an impossible "dedupe" remedy, and rollback reports success but leaves a lock everyyarn install --immutablerejects (YN0028) #1082 - Commented on Yarn berry hosted and vendored scans miss a
file:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939 (merged-main re-check) and Vendored yarn berry revert restores the pre-vendor lock entry verbatim, so after upgrading from yarn 4.0.x it writes back a bare-hex checksum and everyyarn install --immutablefails YN0028 #759 (a new-descriptor symptom of the verbatim restore): Vendored yarn berry revert restores the pre-vendor lock entry verbatim, so after upgrading from yarn 4.0.x it writes back a bare-hex checksum and everyyarn install --immutablefails YN0028 #759 (comment) - Closed: none.
Ruled out
- A hosted rollback refusal on a mixed
package.jsonsuggests "git checkout -- yarn.lock" and the--jsontop-level readsfailed: 0besidehosted.failed[1]. Exit 1 is correct, so both are cosmetic and not filed. - The vendored→hosted refusal prints "server status
redirect_yarn_berry_mixed_line_endings". The wording is odd but the behaviour is correct.
Next
- Yarn berry hosted pin can't cover a descriptor added after pinning: re-scan refuses with an impossible "dedupe" remedy, and rollback reports success but leaves a lock every
yarn install --immutablerejects (YN0028) #1082 neighbours: a transitive dependency addinglpx@~1.0.0(not a member), the pnpm linker,remove, and PnP lock-only. - Re-verify Yarn berry hosted pin can't cover a descriptor added after pinning: re-scan refuses with an impossible "dedupe" remedy, and rollback reports success but leaves a lock every
yarn install --immutablerejects (YN0028) #1082 and the berry half of PR Stop VEX attesting over yarn PnP, pnpm bundled and deno.lock copies #1033 when they land. - Hosted yarn berry rollback/remove still drops a mirror's
::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017 re-verification once fixed. The hosted→vendored takeovervendor --reverton env/home/scoped mirrors. - Yarn 4 node-modules / pnpm-linker projects migrated from Yarn 2 PnP keep a stale
.pnp.js, and socket-patch refuses them as Plug'n'Play: agent and vendored exit 1, hosted warns "npm dependencies were NOT scanned" (regression since 3.3.0) #975/Vendored yarn berry PnP refusal keys only on .pnp.cjs: a lock-only PnP checkout vendors successfully, then every re-run in an installed checkout fails exit 1 with vendor_yarn_berry_unsupported #539 via PR Fix yarn PnP detection ignoring nodeLinker (#975, #539) #978; Yarn berry hosted rollback/remove report success after a useryarn patchof the pinned package, but leave a lock that everyyarn install --immutablerejects (YN0028); the next install re-pins the Socket tarball #962 re-check. - Probes on macOS/Windows once the stale branches are deleted.
|
[agent] 2026-10-08: Yarn Berry (2+) bug-hunt run Tested: main Probes: none. The stale branches Harness (run 30): Re-triage
Cells (Linux,
|
| Cell | yarn says | result |
|---|---|---|
nodeLinker: node-modules / CRLF / home rc / YARN_RC_FILENAME + stale loader |
node-modules | pass |
nodeLinker: pnp / unset, live loader |
pnp | pass (refused) |
nodeLinker: "${L:-node-modules}" |
node-modules | pass |
nodeLinker: "${L:-pnp}", real PnP install, agent apply (4.18.1 ×2, 4.0.2) |
pnp | fail #1100 (exit 0 package_not_installed; release 4.0.0 refuses) |
nodeLinker: "${L}", L=pnp |
pnp | fail #1100 |
Same, lock-only vendor |
pnp | fail #1100 (PnP gate passes) |
Quoted key / next-line value / flow map / lower-case yarn_node_linker env |
node-modules | false PnP refusal (fail-closed; listed on #1100) |
Agent vex on the #1100 tree |
— | pass (package omitted) |
Filed / commented / closed
- Filed Yarn berry PnP refusal misses a live Plug'n'Play project whose
.yarnrc.ymlsetsnodeLinkerthrough${VAR}interpolation: agent apply exits 0 "not installed" and lock-only vendor passes the PnP gate (regression from #978) #1100: Yarn berry PnP refusal misses a live Plug'n'Play project whose.yarnrc.ymlsetsnodeLinkerthrough${VAR}interpolation: agent apply exits 0 "not installed" and lock-only vendor passes the PnP gate (regression from #978) #1100 - Closed: none (Yarn 4 node-modules / pnpm-linker projects migrated from Yarn 2 PnP keep a stale
.pnp.js, and socket-patch refuses them as Plug'n'Play: agent and vendored exit 1, hosted warns "npm dependencies were NOT scanned" (regression since 3.3.0) #975 and Vendored yarn berry PnP refusal keys only on .pnp.cjs: a lock-only PnP checkout vendors successfully, then every re-run in an installed checkout fails exit 1 with vendor_yarn_berry_unsupported #539 were already closed by Fix yarn PnP detection ignoring nodeLinker (#975, #539) #978).
Ruled out
- The hosted lock-only PnP pin under an interpolated linker installs fine under PnP (known non-bug), so the hosted side wasn't filed.
Next
- Yarn berry PnP refusal misses a live Plug'n'Play project whose
.yarnrc.ymlsetsnodeLinkerthrough${VAR}interpolation: agent apply exits 0 "not installed" and lock-only vendor passes the PnP gate (regression from #978) #1100 neighbours:${}in otheryarnrc_scalarsettings (compressionLevel,enableGlobalCache,pnpStoreFolder,npmRegistryServer). - Yarn berry hosted pin can't cover a descriptor added after pinning: re-scan refuses with an impossible "dedupe" remedy, and rollback reports success but leaves a lock every
yarn install --immutablerejects (YN0028) #1082 neighbours (transitivelpx@~1.0.0, the pnpm linker,remove, PnP lock-only). - Hosted yarn berry rollback/remove still drops a mirror's
::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017 re-verification once fixed. - Probes on macOS/Windows once the stale branches are deleted.
|
[agent] 2026-10-08: Yarn Berry (2+) bug-hunt run Tested: main Probes: none. The stale branches Harness (run 31): rebuilt in the scratchpad: Re-triage
Cells (Linux,
|
| Cell | 4.0.2 | 4.18.1 |
|---|---|---|
Hosted A → hosted B re-pin, then rollback / rollback B (byte-exact, fresh immutable unpatched) |
pass | pass |
Vendored A → hosted B (takeover), then remove B / rollback |
pass | pass |
Hosted A → vendored B, then vendor --revert / remove B / rollback |
pass | pass |
Vendored A → vendored B, then --revert |
pass | pass |
remove <superseded uuid A> after a move to B |
— | refused, exit 1, B left wired (correct) |
Vendored A, then scan --mode agent with B published |
— | vendored_ownership_retained (by design) |
Leftover package-lock.json, hosted (both locks pinned; rollback restores all 3 files byte-exact) |
— | pass |
Leftover package-lock.json, vendored (vendor_multiple_lockfiles warning; VEX declines via patched_ref_unattributable; revert byte-exact) |
— | pass |
npmRegistryServer: "${REG:-<mirror>}", hosted rollback/remove |
fail (remove) | fail (rollback ×2, remove). Warns upstream_registry_fallback, writes a bare locator, cold --immutable YN0035. Commented on #1017 |
compressionLevel: "${CL:-0}" |
false refusal (hosted exit 0, vendored exit 1) | same. Commented on #1100 |
Filed / commented / closed
- Filed: none.
- Commented: Yarn berry hosted pin can't cover a descriptor added after pinning: re-scan refuses with an impossible "dedupe" remedy, and rollback reports success but leaves a lock every
yarn install --immutablerejects (YN0028) #1082 (re-triage), Hosted yarn berry rollback/remove still drops a mirror's::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017 (${}mirror, Hosted yarn berry rollback/remove still drops a mirror's::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017 (comment)), Yarn berry PnP refusal misses a live Plug'n'Play project whose.yarnrc.ymlsetsnodeLinkerthrough${VAR}interpolation: agent apply exits 0 "not installed" and lock-only vendor passes the PnP gate (regression from #978) #1100 (${}compressionLevel, Yarn berry PnP refusal misses a live Plug'n'Play project whose.yarnrc.ymlsetsnodeLinkerthrough${VAR}interpolation: agent apply exits 0 "not installed" and lock-only vendor passes the PnP gate (regression from #978) #1100 (comment)). - Closed: none.
Ruled out
- The A→B "re-pin skipped" result (
unsupported_protocol+entry_not_found) came from the mock's tarball leaf. It passes once the leaf islpx-1.0.0.tgz. - The vendored
apply_failedresult came from the mock's plain-sha256 hashes. - Leftover
package-lock.jsonis a documentedvendor_multiple_lockfileswarning, not a bug.
Next
- Yarn berry PnP refusal misses a live Plug'n'Play project whose
.yarnrc.ymlsetsnodeLinkerthrough${VAR}interpolation: agent apply exits 0 "not installed" and lock-only vendor passes the PnP gate (regression from #978) #1100 / Hosted yarn berry rollback/remove still drops a mirror's::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017 interpolation neighbours:pnpmStoreFolder: "${X:-…}"(agent, Agent mode misses transitive packages in Yarn's pnpm-linker store whenpnpmStoreFoldermoves it out ofnode_modules: skipped aspackage_not_installed, or refused as "first-party source" #859 class) andnpmScopesvalues with${}. - Yarn berry hosted pin can't cover a descriptor added after pinning: re-scan refuses with an impossible "dedupe" remedy, and rollback reports success but leaves a lock every
yarn install --immutablerejects (YN0028) #1082 neighbours (transitivelpx@~1.0.0, pnpm linker, PnP lock-only), plus a re-verify once a fix lands. - Re-verify Hosted yarn berry rollback/remove still drops a mirror's
::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017, Yarn berry hosted rollback/remove report success after a useryarn patchof the pinned package, but leave a lock that everyyarn install --immutablerejects (YN0028); the next install re-pins the Socket tarball #962, Yarn berry hosted and vendored scans miss afile:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939, Vendored mode still writes and deletes through a symlinked.socketdir: the #664 guard checks.socket/vendorand below only, so rollback in one yarn berry project wipes another project's vendored tarball and ledger #887, Agent mode misses transitive packages in Yarn's pnpm-linker store whenpnpmStoreFoldermoves it out ofnode_modules: skipped aspackage_not_installed, or refused as "first-party source" #859, Vendored yarn berry misses a parent-scoped userresolutionsentry (pkg-a/left-pad), reports success, and everyyarn install --immutablefails YN0028 #783, Vendored yarn berry revert restores the pre-vendor lock entry verbatim, so after upgrading from yarn 4.0.x it writes back a bare-hex checksum and everyyarn install --immutablefails YN0028 #759, Yarn berry vendored and hosted pins of native-addon packages (nan, bufferutil, utf-8-validate, node-addon-api) keep the registry entry's implicitnode-gyp: "npm:latest"dependency, so vendored installs and hardened hosted installs fail YN0028 #737 when fixes land. - Leftover
pnpm-lock.yamlin a berry project (pnpm wins the precedence table): check that vendored warns, and that hosted rewrites both locks and rolls back byte-exact. - Probes on macOS/Windows once the stale branches are deleted.
|
[agent] 2026-10-08: Yarn Berry (2+) bug-hunt run Tested: main Probes: none (still blocked; the stale branches Harness (run 32): Re-triage
Cells (Linux,
|
| Cell | Result |
|---|---|
#1050 scan --mode vendored --prune --json on live vendored entries: root, workspace member, catalog:, pnpm linker, CRLF lock, 4.0.2 |
pass (nothing reverted; vendor --check ok) |
| #1057 hosted pin + fresh immutable + rollback: plain, CRLF lock + package.json | pass (byte-exact) |
| BOM / no-trailing-newline lock | control fails --immutable on its own (known non-bug) |
Vendored on CRLF lock, --revert |
pass (byte-exact) |
| Yarn 3.8.7 / 2.4.2 cacheKey gates after #1057 | pass (refused, nothing written) |
#1029 agent apply --check: patched, reinstalled (drift → exit 1), nmHoistingLimits 2 copies + one reverted (exit 1), version mix 1.2.0/1.3.0, pnpm linker, PnP (fail-closed) |
pass |
#1029 hosted JSON for an alias-only entry (unpinned / redirect_unconfirmed row plus alias warning) |
pass |
Interpolated pnpmStoreFolder: "${STORE:-node_modules/.store}", transitive dep, agent |
pass |
Leftover pnpm-lock.yaml (with and without packageManager: yarn@4.18.1) |
vendored wires pnpm with vendor_multiple_lockfiles (same in 4.0.0, documented); hosted pins both, rollback byte-exact |
uuid bin: vendored + --revert (4.0.2, 4.18.1) |
pass |
uuid / prettier hosted rollback, remove, takeover + vendor --revert |
fail #1131: restore keeps the tarball bin: (./dist/bin/uuid), hardened --immutable YN0028 (4.0.2, 4.18.1; also ea09714; release 4.0.0 not affected) |
Filed / commented / closed
- Filed: Hosted yarn berry rollback/remove keep the pin's tarball-form
bin:paths (./dist/bin/uuid) on the restorednpm:entry, so hardenedyarn install --immutablefails YN0028 for packages like uuid and prettier #1131 Hosted yarn berry rollback/remove keep the pin's tarball-formbin:paths (./dist/bin/uuid) on the restorednpm:entry, so hardenedyarn install --immutablefails YN0028 for packages like uuid and prettier #1131 - Commented and closed: Vendored mode still writes and deletes through a symlinked
.socketdir: the #664 guard checks.socket/vendorand below only, so rollback in one yarn berry project wipes another project's vendored tarball and ledger #887.
Ruled out
- A single CRLF rollback exit 1 didn't reproduce in three re-runs (byte-exact each time).
- uuid rollback "no valid upstream Berry checksum" was the mock missing
yarnBerry10c0; a bare-hexregck(from a 4.0.2 lock) fails the same way. - The leftover
pnpm-lock.yamlrouting is a documented warning, unchanged since 4.0.0.
Next
- Hosted yarn berry rollback/remove keep the pin's tarball-form
bin:paths (./dist/bin/uuid) on the restorednpm:entry, so hardenedyarn install --immutablefails YN0028 for packages like uuid and prettier #1131 neighbours (other Fix yarn berry pin entry rendering (#697, #718) #719-rendered fields, scoped./bin, pnpm linker), then re-verify when fixed. - Yarn berry PnP refusal misses a live Plug'n'Play project whose
.yarnrc.ymlsetsnodeLinkerthrough${VAR}interpolation: agent apply exits 0 "not installed" and lock-only vendor passes the PnP gate (regression from #978) #1100 / Hosted yarn berry rollback/remove still drops a mirror's::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017 interpolation neighbours:npmScopesvalues with${}. - Yarn berry hosted pin can't cover a descriptor added after pinning: re-scan refuses with an impossible "dedupe" remedy, and rollback reports success but leaves a lock every
yarn install --immutablerejects (YN0028) #1082 neighbours (transitivelpx@~1.0.0, pnpm linker, PnP lock-only). - Re-verify Hosted yarn berry rollback/remove still drops a mirror's
::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017, Yarn berry hosted rollback/remove report success after a useryarn patchof the pinned package, but leave a lock that everyyarn install --immutablerejects (YN0028); the next install re-pins the Socket tarball #962, Yarn berry hosted and vendored scans miss afile:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939, Agent mode misses transitive packages in Yarn's pnpm-linker store whenpnpmStoreFoldermoves it out ofnode_modules: skipped aspackage_not_installed, or refused as "first-party source" #859, Vendored yarn berry misses a parent-scoped userresolutionsentry (pkg-a/left-pad), reports success, and everyyarn install --immutablefails YN0028 #783, Vendored yarn berry revert restores the pre-vendor lock entry verbatim, so after upgrading from yarn 4.0.x it writes back a bare-hex checksum and everyyarn install --immutablefails YN0028 #759, Yarn berry vendored and hosted pins of native-addon packages (nan, bufferutil, utf-8-validate, node-addon-api) keep the registry entry's implicitnode-gyp: "npm:latest"dependency, so vendored installs and hardened hosted installs fail YN0028 #737 when fixes land. - Probes on macOS/Windows once the stale branches are deleted.
|
[agent] Janitor: drift. These cells still say Generated by Claude Code |
|
[agent] 2026-10-08: Yarn Berry (2+) bug-hunt run Tested: main Probes: none. Deleting the stale branches Re-triage
Cells (Linux,
|
| Cell | Result |
|---|---|
Takeover dry run, one purl retracted (no yarnBerry10c0) |
pass (tree byte-identical, would_revert + kept_vendored) |
| Takeover wet, partial retraction (either package), LF and CRLF | pass (refused purl stays vendored byte for byte; other pinned; CRLF kept; fresh --immutable plain + hardened patched) |
| Takeover, all retracted | pass (byte-identical) |
Workspaces (member ^1.3.0 + 1.3.0), partial retraction |
pass (both selectors pinned, fresh immutable) |
get <uuid> --mode hosted over a vendored package (kept / migrated) |
pass |
compressionLevel: mixed after vendoring |
pass (both kept vendored, nothing written) |
| PnP switch after vendoring | pass (pins + yarn_pnp_unsupported; PnP fresh + hardened loads patched) |
Alias lp: npm:left-pad@1.3.0 added after vendoring |
documented redirect_yarn_berry_alias_skipped |
Write fault (chattr +i yarn.lock / package.json / .socket/vendor/state.json), with and without a takeover |
pass (exit 1, "nothing was changed", tree identical) |
| Rollback after a partial takeover (hosted + vendored mix), 4.18.1 CRLF and 4.0.2 | pass (4.0.2 byte-exact with bare hex; .socket/vendor removed) |
vex / scan --vex over a partial takeover |
pass |
pnpmStoreFolder: ../shared shared by two projects, agent apply |
patches the other project's copy too; documented (relocated berry store not containing the project is patched as usual), not filed |
Filed / commented / closed
None. No new bug met the filing bar.
Ruled out
- A workspace takeover "YN0028" was the harness: the fresh-checkout copy lacked
packages/. - A CRLF "left-pad not vendored" was the mock serving no
yarn-berry-zipartifact at vendor time (vendored needs it). - The repo's
mode_migration_npmberry takeover test can't run in the sandbox (its in-process reqwest to registry.npmjs.org fails TLS through the proxy).
Next
- Make the vendored-to-hosted takeover atomic #1039 neighbours: SIGKILL during the journaled takeover commit, pnpm linker,
catalog:dep retraction, a retraction caused by a userresolutionsentry added after vendoring. - Hosted yarn berry rollback/remove keep the pin's tarball-form
bin:paths (./dist/bin/uuid) on the restorednpm:entry, so hardenedyarn install --immutablefails YN0028 for packages like uuid and prettier #1131 neighbours (scoped./bin, pnpm linker), then re-verify when fixed. - Yarn berry PnP refusal misses a live Plug'n'Play project whose
.yarnrc.ymlsetsnodeLinkerthrough${VAR}interpolation: agent apply exits 0 "not installed" and lock-only vendor passes the PnP gate (regression from #978) #1100 / Hosted yarn berry rollback/remove still drops a mirror's::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017 interpolation neighbours (npmScopeswith${}). - Re-verify Hosted yarn berry rollback/remove still drops a mirror's
::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017, Yarn berry hosted rollback/remove report success after a useryarn patchof the pinned package, but leave a lock that everyyarn install --immutablerejects (YN0028); the next install re-pins the Socket tarball #962, Yarn berry hosted and vendored scans miss afile:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939, Agent mode misses transitive packages in Yarn's pnpm-linker store whenpnpmStoreFoldermoves it out ofnode_modules: skipped aspackage_not_installed, or refused as "first-party source" #859, Vendored yarn berry misses a parent-scoped userresolutionsentry (pkg-a/left-pad), reports success, and everyyarn install --immutablefails YN0028 #783, Vendored yarn berry revert restores the pre-vendor lock entry verbatim, so after upgrading from yarn 4.0.x it writes back a bare-hex checksum and everyyarn install --immutablefails YN0028 #759, Yarn berry vendored and hosted pins of native-addon packages (nan, bufferutil, utf-8-validate, node-addon-api) keep the registry entry's implicitnode-gyp: "npm:latest"dependency, so vendored installs and hardened hosted installs fail YN0028 #737, Yarn berry hosted pin can't cover a descriptor added after pinning: re-scan refuses with an impossible "dedupe" remedy, and rollback reports success but leaves a lock everyyarn install --immutablerejects (YN0028) #1082 when fixes land. - Probes on macOS/Windows once the stale branches are deleted.
|
[agent] 2026-10-09: Yarn Berry (2+) bug-hunt run Tested: main Probes: none. Deleting the stale branches Re-triage
Cells (Linux,
|
| Cell | Result |
|---|---|
#1058 hosted pin + re-scan (already counted, nothing rewritten) + fresh plain/hardened --immutable + rollback byte-exact: workspaces (merged ^1.3.0/1.3.0 + scoped member dep), catalog: default + named, transitive + npm: alias of another version, pnpm linker |
pass |
Leftover package-lock.json / pnpm-lock.yaml beside the berry lock: pin, re-scan already, rollback byte-exact (.npmrc removed) |
pass |
Legacy release-4.0.0 __archiveUrl pins (root, workspaces, transitive) re-scanned by main: migrated to the resolutions pin, fresh hardened patched; rollback byte-exact both before and after the migration |
pass |
Vendored, then yarn remove one package: vendor --check names it (exit 1), scan --vendored --prune, vendor --revert, rollback, remove <uuid> retire it, --immutable passes |
pass |
Hosted, then yarn remove (4.0.2, 4.18.1) or yarn up to an unpatched version |
fail #1203 (leftover resolutions selector → rollback/list/remove exit 1 forever with hosted_wiring_contested; the remedy scan is a no-op; release 4.0.0 not affected) |
Filed / commented / closed
- Filed After
yarn removeof a hosted-pinned yarn berry package, its leftoverresolutionspin makes rollback, remove and list fail forever with hosted_wiring_contested, and the remedy they print (re-run the hosted scan) changes nothing #1203 (Afteryarn removeof a hosted-pinned yarn berry package, its leftoverresolutionspin makes rollback, remove and list fail forever with hosted_wiring_contested, and the remedy they print (re-run the hosted scan) changes nothing #1203) and commented with theyarn upvariant.
Ruled out
- A
lo-npm"classic migration risk" warning plus a non-byte-exact rollback came from the harness:npm install --package-lock-onlyrewrites an existingyarn.lockas classic v1. With the berry lock restored, the cell passes. npm_manifest_unavailable("hosted tarball does not match its published sha512") for uuid came from the mock: packages withbinneed the real sha512 of the patched tgz in thetarballartifact.
Next
- After
yarn removeof a hosted-pinned yarn berry package, its leftoverresolutionspin makes rollback, remove and list fail forever with hosted_wiring_contested, and the remedy they print (re-run the hosted scan) changes nothing #1203 neighbours: removal from a workspace member while another member keeps the dep, acatalog:dep removed,yarn removeof a scoped package; re-verify when fixed (rollback, remove, list,--prune). - Decide whether a hosted patch is pinned through lockfile discovery alone #1058 gate (
redirect_unattributable) on berry shapes:portal:/link:lp2copies (Yarn berry hosted and vendored scans miss afile:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939), member-level registry copies, takeover + gate. - Make the vendored-to-hosted takeover atomic #1039 neighbours (SIGKILL during the takeover commit, pnpm linker,
catalog:retraction). - Hosted yarn berry rollback/remove keep the pin's tarball-form
bin:paths (./dist/bin/uuid) on the restorednpm:entry, so hardenedyarn install --immutablefails YN0028 for packages like uuid and prettier #1131 neighbours (scoped./bin, pnpm linker); Yarn berry PnP refusal misses a live Plug'n'Play project whose.yarnrc.ymlsetsnodeLinkerthrough${VAR}interpolation: agent apply exits 0 "not installed" and lock-only vendor passes the PnP gate (regression from #978) #1100/Hosted yarn berry rollback/remove still drops a mirror's::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017 interpolation neighbours. - Probes on macOS/Windows once the stale branches are deleted.
|
[agent] 2026-10-09: Yarn Berry (2+) bug-hunt run Tested: main Probes: none (the stale probe branches still need deleting by hand; see the backlog). Re-triage
Cells (Linux,
|
| Cell | Result |
|---|---|
| Repo berry e2e suites (vendor, redirect, workspaces, pnpm linker, PnP safety) on 4.18.1 (187/187) and 4.0.2 (147/147) | pass |
Refactored vendored driver, two packages: node-modules (--revert), pnpm linker (rollback), 4.0.2 (remove <uuid> ×2), workspaces, catalog: default + named. Fresh cold --immutable is patched, vendor --check passes, and the unwind is byte-exact |
pass |
Write fault (chattr +i) on yarn.lock / package.json during vendor: exit 1, both failed vendor_commit_failed, nothing written, no artifacts or ledger left (#898/#1005) |
pass |
Write fault on yarn.lock during vendor --revert / rollback / remove: exit 1, wiring intact, --check passes, retry is byte-exact |
pass |
Vendored generation A→B (manifest swap, vendor): vendor_stale_artifact_removed, fresh install loads B, --revert byte-exact (4.18.1, 4.0.2) |
pass |
Hosted→vendored takeover via vendor, then vendor --revert lands on the pristine registry lock (4.18.1, 4.0.2 bare hex) |
pass |
#1039 neighbours: vendored→hosted takeover with one purl retracted (redirect_yarn_berry_missing_checksum → redirect_takeover_kept_vendored) on the pnpm linker and on catalog: deps. Fresh install patched, rollback pristine |
pass |
SIGKILL during the vendored→hosted takeover commit, then rollback |
fail #1241: killed after the journal is durable but before any file is replaced, the next rollback replays the journal and exits 0 having restored nothing (hosted pins left). remove says "No patch found". 4.18.1 and 4.0.2. Kills elsewhere in the window recover correctly; a second rollback restores the project |
Filed / commented / closed
- Filed After a vendored-to-hosted takeover is interrupted once its commit journal is written, the next
rollbackreplays the journal, then exits 0 having restored nothing, and the project stays hosted-patched (removesays "No patch found") #1241 (After a vendored-to-hosted takeover is interrupted once its commit journal is written, the nextrollbackreplays the journal, then exits 0 having restored nothing, and the project stays hosted-patched (removesays "No patch found") #1241). It's cross-PM CLI ordering:rollback.rs/remove.rsdiscover hosted pins beforeacquire_or_emitreplays the journal.
Ruled out
- An early SIGKILL loop "showed" rollback misbehaving, but
kill -9 $!on a shell function only kills the wrapper subshell; the binary kept running. Exec the binary directly. - A kill before the journal is renamed into place (only
.socket-stage-.commit-journal.json-*exists) isn't a bug: nothing was committed, androllbackunwinds the vendored state byte-exact. The stray stage file stays untracked under.socket/vendor/. It's benign, so not filed. - Orphaned
.socket/vendor/npm/<uuid>/dirs after a journal replay are A vendored-to-hosted takeover interrupted after its commit journal is written leaves the vendored artifact directory behind for good: recovery finishes the files but not the deferred deletions, and no GC can reclaim it once the ledger is gone #1157 (pnpm), not re-filed.
Next
- Re-verify After a vendored-to-hosted takeover is interrupted once its commit journal is written, the next
rollbackreplays the journal, then exits 0 having restored nothing, and the project stays hosted-patched (removesays "No patch found") #1241 when fixed (rollback and remove after a replayed takeover journal; 4.0.2 and 4.18.1), and checklist/repairin the same state. - After
yarn removeof a hosted-pinned yarn berry package, its leftoverresolutionspin makes rollback, remove and list fail forever with hosted_wiring_contested, and the remedy they print (re-run the hosted scan) changes nothing #1203 neighbours (member-level removal,catalog:, scoped); Decide whether a hosted patch is pinned through lockfile discovery alone #1058redirect_unattributablegate onportal:/link:copies. - Hosted yarn berry rollback/remove keep the pin's tarball-form
bin:paths (./dist/bin/uuid) on the restorednpm:entry, so hardenedyarn install --immutablefails YN0028 for packages like uuid and prettier #1131 neighbours (scoped./bin, pnpm linker); Yarn berry PnP refusal misses a live Plug'n'Play project whose.yarnrc.ymlsetsnodeLinkerthrough${VAR}interpolation: agent apply exits 0 "not installed" and lock-only vendor passes the PnP gate (regression from #978) #1100/Hosted yarn berry rollback/remove still drops a mirror's::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017 interpolation neighbours. - Vendored-driver refactor follow-ups:
repairof a deleted tgz,vendor --dry-runparity, CRLF lock + package.json through the new driver. - Probes on macOS/Windows once the stale branches are deleted.
|
[agent] 2026-10-09: Yarn Berry (2+) bug-hunt run Tested: main Probes: none. Deleting the stale probe branches was denied again by the session permission policy, so they still need deleting by hand. Re-triage
Cells (Linux,
|
| Cell | Result |
|---|---|
Agent scan --mode agent packages/a in a berry workspace: pnpm linker (member link) / node-modules (hoisted to the root) |
pass / out of scope by contract |
nmMode: hardlinks-local + nmHoistingLimits: workspaces: apply patches all 3 copies; rollback packages/a restores all 3 with out_of_scope_copies_restored; unscoped rollback |
pass |
Vendored driver: scan --mode vendored --dry-run writes nothing; repair redownloads a deleted tgz (--check 1 → 0); CRLF yarn.lock; fresh cold --immutable (plain and hardened) is patched; --revert / rollback byte-exact |
pass |
Vendored→hosted takeover SIGKILLed at the package.json / yarn.lock rename (LD_PRELOAD shim), then rollback |
fail #1241: exit 0 with nothing restored, or exit 1 hosted_wiring_contested; hosted-pinned either way. remove <uuid> reports "No patch found" |
Hosted→vendored takeover SIGKILLed at the package.json / yarn.lock / state.json rename, then rollback |
fail (#1241 root cause, commented): either a false Cannot restore … no hosted wiring exit 1 after the replay, or a pre-lock refusal (orphaned resolutions; "vendor ledger is missing, restore state.json from version control", a file that was never committed) that never replays the journal |
First vendoring SIGKILLed at the yarn.lock / state.json rename, then rollback |
fail: pre-lock "ledger missing" refusal, and the journal stays pending (commented on #809: #809 (comment)) |
Plain hosted scan SIGKILLed between the package.json and yarn.lock renames |
half-pinned. No journal by design; rollback refuses with a working remedy and a re-scan heals it (not filed) |
Filed / commented / closed
- No new issues. Commented on After a vendored-to-hosted takeover is interrupted once its commit journal is written, the next
rollbackreplays the journal, then exits 0 having restored nothing, and the project stays hosted-patched (removesays "No patch found") #1241 (still open in substance, both takeover directions) and on vendor --check and vex misreport a crashed vendored run whose commit journal is pending, because only lock-taking commands replay it #809 (rollback doesn't replay either).
Ruled out
- Hoisted member deps under agent
scan PATH: out of scope by contract. - A crash in a non-takeover hosted commit: journal-less by design.
.socket-stage-*litter after a SIGKILL: already noted on vendor --check and vex misreport a crashed vendored run whose commit journal is pending, because only lock-taking commands replay it #809.
Next
- Re-verify After a vendored-to-hosted takeover is interrupted once its commit journal is written, the next
rollbackreplays the journal, then exits 0 having restored nothing, and the project stays hosted-patched (removesays "No patch found") #1241 (both takeover directions, plus the first-vendoring rollback) when a fix lands, using the rename shim. Also tryvendor --revertandrepairfrom each kill point. - Shim-driven kills during unwinds:
vendor --revert,rollbackandremovekilled mid-commit on berry, then re-run. - After
yarn removeof a hosted-pinned yarn berry package, its leftoverresolutionspin makes rollback, remove and list fail forever with hosted_wiring_contested, and the remedy they print (re-run the hosted scan) changes nothing #1203 neighbours (member-level removal,catalog:, scoped); Hosted yarn berry rollback/remove keep the pin's tarball-formbin:paths (./dist/bin/uuid) on the restorednpm:entry, so hardenedyarn install --immutablefails YN0028 for packages like uuid and prettier #1131 neighbours (scoped./bin, pnpm linker). - Yarn berry PnP refusal misses a live Plug'n'Play project whose
.yarnrc.ymlsetsnodeLinkerthrough${VAR}interpolation: agent apply exits 0 "not installed" and lock-only vendor passes the PnP gate (regression from #978) #1100/Hosted yarn berry rollback/remove still drops a mirror's::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017 interpolation neighbours; 4.0.2 legs of this run's cells. - macOS/Windows probes once the stale branches are deleted.
|
[agent] 2026-10-09: Yarn Berry (2+) bug-hunt run Tested: main Probes: none (the stale probe branches still need deleting by hand). Re-triage
Cells (Linux,
|
| Cell | Result |
|---|---|
Hosted + vendored basic (left-pad + ms), 4.0.2 and 4.18.1: pin, fresh --immutable patched, rollback byte-exact |
pass |
#1180 on berry: hosted pin, then yarn add lp@npm:left-pad@1.3.0; scan --mode hosted --vex, standalone vex |
pass (alias copy warned, nothing attested) |
#1180: alias at another version (lp/@x/lp → npm:left-pad@1.1.3) beside a pinned ^1.3.0 |
pass (in-run VEX attests; fresh patched) |
| Vendored → hosted takeover with an alias added after vendoring | pass (alias warned, no retraction needed: the alias block was never vendored) |
#1034 target grammar, hosted and vendored rollback/remove: name, upper-case name, versionless purl, versioned purl, uuid (also upper-case), @scope/name, is beside @sindresorhus/is (full name wins, by design) |
pass. name@version, CVE and GHSA select nothing (documented) |
get <name> / get <uuid> / get pkg:npm/x@v → hosted pin |
pass. A versionless purl is sent to the API verbatim; the mock has no versionless route, so this is unverified |
#989 vendored unwinds: vendor --revert, rollback, remove <name>, rollback <name>, remove <uuid> with two vendored packages |
pass (the others are kept; fresh --immutable correct) |
SIGKILL (rename shim) during vendored vendor --revert/rollback/remove at the package.json / 2nd yarn.lock / state.json renames, then re-run |
pass (re-run completes; pristine and byte-exact). Stage-file litter only (#809) |
SIGKILL during hosted rollback/remove between the package.json and yarn.lock renames |
half-unwound: the re-run refuses patched_ref_invalid (orphaned lock pin), and the printed "re-run the hosted scan" remedy is a no-op. yarn install heals it. Known journal-less residual (not filed) |
BOM'd .yarnrc.yml (nodeLinker: pnp, LF/CRLF) lock-only vendored |
pass (refused as PnP) |
BOM'd .yarnrc.yml with nodeLinker: node-modules, lock-only vendored + revert |
pass |
BOM'd project-rc npmRegistryServer (non-conventional mirror), hosted rollback |
pass (byte-exact ::__archiveUrl=) |
Path-scoped rollback packages/a (hosted and vendored) on workspaces: pnpm linker / node-modules (hoisted) |
pass / path_glob_no_match exit 1 (contract: hoisted copy is not under the path) |
| Yarn 3.8.7 and 2.4.2: hosted/vendored refusal (nothing written), agent apply + rollback | pass |
Hosted pin, then a member left-pad@1.3.0 or an alias lp: npm:left-pad@1.3.0, then rollback / remove left-pad |
fail (#1082 regression, commented) |
Vendored, then lp: npm:left-pad@1.3.0, then vendor --revert / rollback / remove left-pad |
fail (same unmerged-block cause; on #1082, #759 class) |
Filed / commented / closed
- No new issues. Commented on Yarn berry hosted pin can't cover a descriptor added after pinning: re-scan refuses with an impossible "dedupe" remedy, and rollback reports success but leaves a lock every
yarn install --immutablerejects (YN0028) #1082 (regression bisected tof3c6313a).
Ruled out
- The rollback hint "use ./left-pad@1.3.0" for
name@version: the grammar has noname@version(documented). rollback ischoosingisover@sindresorhus/is: the full name beats a last-segment match by design (utils/target.rs).- Hoisted member deps under
rollback packages/a: out of scope by contract (the wording "patches for uninstalled packages" is a bit misleading). - An upper-case UUID passed to
getreaches the API unchanged; my mock is case-sensitive, so this isn't confirmed against the real API (cross-PM if real).
Next
- Re-verify Yarn berry hosted pin can't cover a descriptor added after pinning: re-scan refuses with an impossible "dedupe" remedy, and rollback reports success but leaves a lock every
yarn install --immutablerejects (YN0028) #1082 when a fix lands: plain member, root/member alias,remove, vendored alias revert; 4.0.2 and 4.18.1. Other npm hosted pin next to a bundled copy can't be unwound: rollback/remove refuse it, and the vendored takeover skips the restore, so vendor --revert lands back on hosted and allow-remote=all stays #828shadowedshapes on berry: afile:/portal:sibling block (Yarn berry hosted and vendored scans miss afile:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939), plus the hosted→vendored takeover over a shadowed berry pin. - Kill hosted
rollbackmid-commit with three or more pins (the lock written first?), and a hosted→vendored takeover killed mid-unwind. - After
yarn removeof a hosted-pinned yarn berry package, its leftoverresolutionspin makes rollback, remove and list fail forever with hosted_wiring_contested, and the remedy they print (re-run the hosted scan) changes nothing #1203 neighbours (member-level removal,catalog:, scoped); Hosted yarn berry rollback/remove keep the pin's tarball-formbin:paths (./dist/bin/uuid) on the restorednpm:entry, so hardenedyarn install --immutablefails YN0028 for packages like uuid and prettier #1131 neighbours. - Yarn berry PnP refusal misses a live Plug'n'Play project whose
.yarnrc.ymlsetsnodeLinkerthrough${VAR}interpolation: agent apply exits 0 "not installed" and lock-only vendor passes the PnP gate (regression from #978) #1100/Hosted yarn berry rollback/remove still drops a mirror's::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017 interpolation neighbours. - macOS/Windows probes once the stale branches are deleted.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Yarn Berry (2+) bug-hunt routine (label pm:yarn-berry).
Last updated: 2026-10-09 (run 37), main
9ab72d4(CLI 5.0.0; release commit merged, npm still has 4.0.0), previous release 4.0.0 (before that 3.3.0). Main was force-pushed and the clone is shallow; usegit fetch --deepen=400 origin mainfor older SHAs. Run 36 testeda80b89e. Run 35 testedf3c6313. Run 34 tested03b9418. Run 33 testedcf8b164. Run 32 testede2d9633. Run 31 testedea09714. Run 30 testede61a845. Run 29 also tested PR #1033 head314038b. Run 27 also tested PR #978 head59eac7e; run 25 tested PR #940 head980b7b6; run 23 tested draft PR #918 head21413f1. Since #465 the hosted berry pin is rootpackage.jsonresolutions(name@npm:<range>→ URL) plus a lock entry re-keyedname@<url>.Harness: yarn bundles come from npm
@yarnpkg/cli-dist@<v>(node package/bin/yarn.js), because corepack's fetch can't use the sandbox proxy. Yarn 4 needsYARN_HTTPS_CA_FILE_PATH; yarn 2/3 needYARN_CA_FILE_PATH. The npm registry has 2.4.2 as the last 2.x in cli-dist. Agent and vendored cells hand-stage.socket/manifest.jsonplus blobs (a marker prepended toindex.js). Hosted cells use a local Python mock (fresh-checkout copies must keep.socket/for vendored cells) of the patch API (batch, by-package,patches/packagewith ayarn-berry-zipyarnBerry10c0artifact,view, and the tarball route). The 10c0 checksum is bootstrapped with a real yarnresolutions: file:install. Every hosted and vendored cell ends in a fresh-checkoutyarn install --immutable. v5: hosted rollback/remove need the mock's/upstream/npm/<uuid>.jsonroute,SOCKET_NPM_REGISTRYpointed at a local registry passthrough (the rustls binary can't use the sandbox proxy CA), and--patch-server-url <mock>so the pins count as hosted. Global (-g) cells use real npm global installs (NPM_CONFIG_PREFIX) and a Python mock of the authenticated API (--api-url <mock> --api-token x --org org; blob route/v0/orgs/org/patches/blob/<sha256>). v5 vendored mode downloads from the vendoring service: the same mock's/patches/packagewith a grantedtarballartifact (real sha512) is enough, and an optional per-patchstatusoverride (for examplepending_build) is supported. Acorepackshim (corepack yarn@X→node <cli-dist X>/bin/yarn.js, setting the CA env itself because the harness scrubsYARN_*) runs the repo's berry e2e suites in the sandbox (SOCKET_PATCH_YARN_E2E_REQUIRED=1,SOCKET_PATCH_YARN_BERRY_VERSION=<v>).setupwas removed in v5. On GH runners, fixture installs needYARN_ENABLE_IMMUTABLE_INSTALLS=false(CI turns immutable on). Run 8: the vendoring-service mock must also return ayarn-berry-zipartifact withintegrity.yarnBerry10c0, or vendor failsapply_failed. Hosted fresh installs from an http mock needYARN_UNSAFE_HTTP_WHITELIST=127.0.0.1. Run 9: the corepack shim must setYARN_HTTPS_CA_FILE_PATHonly for 4.x (yarn 4 rejects an envcaFilePath), and the batch mock must filter bycomponents[].purl. Run 10: one Python mock driven by a JSON config (per-patchhiddenandpublishedAtfor A→B upgrades) also serves/upstream/npm/<uuid>.jsonand a/registry/npmjs passthrough forSOCKET_NPM_REGISTRY. Never runpkill -f mock.pyfrom the shell that runs it. Run 12: the harness was rebuilt asmkpatch.py(patched tgz, bootstrap checksum, original registry checksum; never patchpackage.json) plus one mock that also logsAuthorization. Standalonevexagainst the mock needs--patch-server-url <mock>and the API flags. Run 14: harness rebuilt (y,mkpatch.py,mock.py,addorig.py,run.sh,survey.py); the mock must unquote by-package purls repeatedly (scoped purls arrive as%2540).survey.pydiffsnpm:vs tarball-URL lock entry bodies to find pin-render mismatches. Run 16: harness rebuilt (y,mkpatch.sh,mock.py,lib.sh); the/registry/passthrough must quote withsafe='@/', and a checksum bootstrapped on yarn 4.0.x is bare hex, so prefix it with10c0/. Run 17: v5vendor --offlineno longer builds locally, so vendored cells need the vendoring-service mock (POST /v0/orgs/org/patches/package, tarball + yarn-berry-zip) even with a hand-staged manifest. Run 13: also run every fresh install withYARN_ENABLE_HARDENED_MODE=1(it implies--refresh-lockfile, which re-resolves tarball pins from the tarball manifest). Run 18: harness rebuilt (y,mkpatch.sh,stage.py,mock.py,hmock.py,reg.py,lib.sh);reg.pyis an npmjs passthrough with non-conventional tarball URLs (forces::__archiveUrl=lock entries) that also serves/<name>/<version>forSOCKET_NPM_REGISTRY; cold-cache checks need a freshYARN_GLOBAL_FOLDER. Run 19:reg.pymust 404 the conventional/-/tarball path (as a real non-conventional mirror does), or yarn's error is a misleading "socket hang up". Run 20: harness rebuilt (y,mkpatch.sh→p/cfg.json, onemock.pywith viewblobContent+/upstream/npm/<uuid>.json,reg.py,lib.sh); a barescandefaults to hosted, so pass--mode agent; vendored takeovers of hosted pins need--patch-server-url; the release 4.0.0 binary ispackage/socket-patch. Run 21: hosted rollback/remove needSOCKET_NPM_REGISTRYpointed at thereg.pypassthrough, or they fail "error sending request" (sandbox artifact). Run 22: harness rebuilt (y,mkpatch.sh,mock.py,reg.py, plusreg2.py, a non-conventional mirror on :8792, andreg3.py, an npmjs stand-in on :8793 whosedist.tarballis conventional under its own base). When the restoreddist.tarballhost matters, setSOCKET_NPM_REGISTRYtoreg3.py, never to the project's own mirror (that hid #908). Run 23: harness rebuilt (y,reg.py <port> conv|nonconv [prefix],mock.py+cfg.json,mkpatch.sh,run.sh <bin> <scenario> …);rollbacktakes no--mode. Run 24: harness rebuilt (ywithYV=<v>,mock.py <scratch> <port> <checksum>,run.sh <yarn> tgz|dir|url hosted|vendoredfor the #939 matrix). Run 25: harness rebuilt (y,mock.py,reg.py,fx.sh,fresh.sh,yp.sh). The mock's/upstream/npm/<uuid>.jsonmust return{name, version, integrity (registry sha512), yarnBerry10c0 (registry checksum)}. Yarn 4.18 needsapprovedGitRepositories: ["**"]forgithub:deps. Run 26: harness rebuilt (y,mock.py <scratch> <port> <patched 10c0> <registry 10c0> <registry sha512>with a<scratch>/modefile (badsha/pending) for late vendored failures,reg.py,lib.sh,pnpjs.sh);chattr +ion a file is a working write-fault injector even as root. Run 27: acorepackshim withBH_HOME(yarn-onlyHOMEoverride) runs the repo's e2e capstones unchanged against main and a PR worktree (CARGO_TARGET_DIR=target-pr); a hand-staged.socket/+vendor --offlineshows which gate fires (main stops at "needs the network"). Run 29: harness rebuilt fully local (mkpkg.pysyntheticlpx,reg.py 8793,mock.py 8790reading checksums fromcfg.json,spwrapper,fresh DIR); shell helpers must not clobber caller variables. Run 30:stage.py(stubdummypkg + manifest + blob),case.sh(diffs realyarn config get nodeLinkeragainst socket-patch's PnP decision per rc/env shape),interp.sh <name> <nodeLinker value>(real PnP install, agent apply, lock-only vendor); offlinerollbackneeds the before blob staged. Run 31: harness rebuilt (mkpkg.py,reg.py <port> conv|nonconv,mock.pywith a per-uuidhiddenflag +hide.sh A|B,gen.shgeneration cells). The hosted tarball URL leaf MUST be<name>-<version>.tgz(hosted_url_names), or the existing pin reads as a foreignhttp:entry. The view hashes are git-blob sha256, or vendor failsapply_failed. The corepack shim also needsYARN_HTTPS_PROXY=$HTTPS_PROXY. Run 32: harness rebuilt (bin/y,mock.py:8790 left-pad, genericmock2.py:8791 driven bymkpatch.sh NAME VER UUID→pk2/<name>@<ver>/withck,regshaand a hand-addedregck(must carry10c0/;/upstreamneedsyarnBerry10c0or rollback refuses),reg.py:8793 npmjs passthrough forSOCKET_NPM_REGISTRY). Run 33: harness rebuilt (h/mock.py <dir> 8790driven bycfg.jsonwith per-packageck(null = noyarn-berry-zipartifact, which makes hosted refuseredirect_yarn_berry_missing_checksum, the easiest way to force a #1039 takeover retraction),h/mkpatch.py(patched tgz + bootstrapped 10c0 + registryregck/regsha),h/stage.py(manifest + blobs),h/fresh.sh(copiespackages/too for workspaces),h/reg.py 8793). Vendoring needs theyarn-berry-zipartifact present (ckset) or it fails. The safety check blocksrm -rf $VARinside loops; use fresh directory names. Run 34: harness rebuilt (bin/y,h/mkpatch.sh NAME VER UUID→pk/<name>@<ver>/withck/regck/regsha/before/after/file,h/mock.py <pk> 8790serving everypk/*package (thetarballartifact must carry the patched tgz's real sha512, or packages withbinskip withnpm_manifest_unavailable),h/reg.py 8793npmjs passthrough,h/lib.shwithhs/sp/fresh). Never runnpm install --package-lock-onlynext to a berry lock: npm rewritesyarn.lockas classic v1. Run 35: harness rebuilt (bin/corepackshim +bin/y,h/mkpatch.sh NAME VER UUID→pk/<uuid>/{patched.tgz,meta.json},h/addreg.sh <uuid>addsregck/regshafor the/upstream/npm/<uuid>.jsonroute,h/mock.py <pk> 8790(batch, by-package, view, package, artifacts, upstream),h/reg.py 8793,h/stage.py,h/mkfx.sh,h/cell.sh). For SIGKILL timing, exec the binary directly ($SP … & p=$!);kill -9on a shell-function wrapper kills only the subshell. The takeover commit window on this harness is ~0.04–0.05 s after start. Run 36: harness rebuilt (bin/ywithYV=<v>,h/mkpatch.sh NAME VER UUID→pk/<uuid>/{patched.tgz,meta.json}withck/regck/regshaand view blobs,h/mock.py <pk> 8790(batch, by-package, view, package, artifacts, upstream,/v0/organizations),h/reg.py 8793npmjs passthrough,h/lib.shwithsp/fresh). Deterministic crash injection:shim.so, anLD_PRELOADrename/renameat2hook that SIGKILLs when the target path ends with$KILL_ON(/package.json,/yarn.lock,/state.json); sleep-timed kills no longer land (the commit window is under 5 ms). Run 37: harness rebuilt (bin/ywithYV=<v>and the yarn 2/3YARN_CA_FILE_PATH,h/mkpatch.sh NAME VER UUID [FILE]→pk/<uuid>/{patched.tgz,meta.json}(bootstrapsck/regckwith real yarn installs),h/mock.py <pk> 8790(proxy + org routes, view with blob contents, package, upstream,/registry/npmjs passthrough, and a non-conventional mirror at/mirror/whose tarballs live under/mirror-dl/),h/lib.sh(spwith--api-url/--proxy-url/--patch-server-url,fresh,mkfx),h/shim.sorename killer (KILL_ON,KILL_NTH,KILL_AFTER),h/bis.sh BINfor the #1082 cell). Without a token,--proxy-urlis what routes to the mock.vex -ois--org; use-O. Run 11: the view route can carryblobContent/beforeBlobContent, so agent-modescanworks against the mock without hand-staging; stop the mock through a pidfile.Coverage matrix
Cells are "pass", "fail #N", "refused (by design)" or "untested". Linker is node-modules unless noted.
redirect_yarn_berry_cache_unsupported.store, real dirs), apply/vex/rollback byte-exactvendor_yarn_berry_cache_unsupported.storetransitive dep pass (#495 fixed); repo e2e suites pass (90/90);removeblob GC fail #559nmMode: hardlinks-globalpass after #486. Run 8 on 61cfb9b:nmMode: hardlinks-globalpass (only this project's link broken; rollback byte-exact),nmHoistingLimits: workspacespass (every copy). fail #559 (removesweeps the other patches' before blobs; also releases 4.0.0, 3.3.0). pass on f6b7fb9 (node-modules and pnpm linkers, rollback byte-exact). On 61cfb9b: pass for direct deps (pnpm linker, root and scoped) and hoisted transitive deps; fail #495 (pnpm-linker transitive dep only in.store/<slug>/package); repo e2e suites pass--revertbyte-exact), merged 3-descriptor entry (--revertbyte-exact),catalog:(default and named), root locator encoding (nameless root,()!~'*, space, unicode,+&=#), concurrent vendor (lock),repairof a deleted tgz. Two versions →vendor_override_conflict(correct).removeblob GC: fail #559. pass on 61cfb9b: pnpm linker (in-place + fresh--check-cache,--revertbyte-exact); PnP lock-only checkout vendors and loads patched bytes, but re-run after install fails #539 (also 4.0.2, 4.18.1); zero-install committed cache → YN0056 (docs gap). package.json tab / 4-space / BOM / CRLF+tab / no trailing newline / existing or emptyresolutions(fresh immutable +--revertbyte-exact); mixed-EOL yarn.lock refused loudly (vendor_yarn_berry_mixed_line_endings). pass on f6b7fb9: root, scoped root name, scoped target,**/glob resolution, workspaces, pnpm linker, re-run idempotent,--revert, in-place immutable install. pass on v5: root, workspaces +enableImmutableInstalls: true(--revertandremovebyte-exact), CRLF lock + package.json. Refused (by design): resolve/typescript (patch:builtin), yarn 3. fail #370 (commented compressionLevel). fail #369 (hosted→vendored viascan/get --mode vendored;vendoritself is fixed on v5). fail #468 (vendored→hosted with noyarnBerry10c0)packageExtensions-added dep, root peer + dev,=1.3.0/v1.3.0,portal:transitive,dependenciesMeta, workspace named like the target (each with fresh immutable and byte-exact rollback; vendored forpackageExtensions/portal:too); tarball-URL descriptor refused (correct);compressionLevel: mixedrefused in both modes. run 10 on 045d7ec:catalog:(default, named, workspace) fail #632 (regression from #465; release 4.0.0 passes); vendored→hosted takeover of a catalog dep also hits #632. Pass: A→B upgrade (re-pin, fresh immutable B, rollback byte-exact), pin survivesyarn add/dedupe/up, descriptor change → re-scan re-pins (vex attests nothing meanwhile),--cwdnested separate project (outer untouched). run 9 on 203e092 (resolutions pin, #465): pass for basic, workspaces merged entry, transitive, 7 range spellings (latest,>=1.3.0 <2,||,1.x,*,npm:forms), scoped, two versions, hardened mode × 3 linkers, package.json tab/4-space/CRLF/BOM/no-EOL/other resolutions (rollback byte-exact), CRLF lock +enableImmutableInstalls, scoped rollback/remove with two pins, hosted↔vendored takeovers, mixed vendored+hosted unwind, legacy__archiveUrlpin migration from release 4.0.0,compressionLevel: "0"and0 # c(#370 fixed), lock-only vex (orphan refused). #368 fixed (refusesresolve, nothing written). Interrupted (SIGKILL) vendor: recoverable. Earlier: pass: left-pad, pnpm linker + vex, rollback byte-exact; run 8:catalog:dep (fresh immutable patched); 61cfb9b: rollback and remove byte-exact fornpm:^1.3.0, dev-only and optional-only descriptors; v5 main:npm:1.3.0/npm:^1.3.0descriptors, dev-only and optional-only deps, mixed-case nameJSONStream(case-kept purl, also on 4.18.1), mixed-EOL lock refused loudly, scoped, CRLF, workspaces merged-range, re-scan idempotent, manifest-less rollback/remove/list byte-exact, PnP lock-only checkout, upgrade path (uuid A→B re-pin, then rollback byte-exact), hardened mode accepts__archiveUrlpins, vendored→hosted takeover (checksum present;pending_buildstays vendored). #368, #404, #369 and #370 are fixed on 203e092. Refused (by design): PnP (yarn_pnp_unsupported), direct + alias merged entry (redirect_yarn_berry_ambiguous_entry). PnP stale.pnp.cjs+ hosted pin → standalonevexattests unpatched copy: fail #519 (yarn-classic issue; berry evidence commented, also 4.0.2 and 4.18.1)patch:-descriptor package pass. Run 11: workspaces withnmMode: hardlinks-local+nmHoistingLimits: workspacespass (both copies patched, rollback restores both). Run 9 on 203e092: pnpm linker.storepass (#495 fixed); repo e2e suites pass (90/90); fail #559catalog:pass (bare-name pin). Run 8: namedcatalog:legacypass. pass on f6b7fb9 (CRLF-respelled lock + package.json); v5: fail #468; PnP lock-only: fail #539 (re-run)packageExtensions, peer + dev,=1.3.0pass. Run 10 on 045d7ec:catalog:fail #632; A→B upgrade,yarn add/dedupe/up, nested--cwdpass. Run 9: resolutions pin passes hardened mode × 3 linkers. Earlier: pass (left-pad, scoped, lockversion: 10); #368, #370, #404 and #468 fixed on 203e092"left-pad": "1.3.0", mixed-case JSONStream, three linked packages (also 4.0.2) with per-package rollback, default global cache +--check-cache,workspaces focus --production, prereleasems@3.0.0-canary.1,--checkon a tampered tgz.bin:+conditions:(ios-deploy) fail #697/#718 (passes on PR #719).vendor --checkwiring drift (resolutionsdropped, lock restored) exit 0: #725 class (commented; PR #730 fixes it). run 16: parent-scoped userresolutions(pkg-a/left-pad,pkg-a/left-pad@^1.3.0,<root>/left-pad) fail #783 (vendored adds its own pin; every fresh--immutablefails YN0028; 4.0.2, 4.12.0, 4.18.1; also release 4.0.0). Exact-name user keys refused (correct). A→B re-vendor across a 4.0.2 → 4.18.1 upgrade pass (revert is #759). Workspaces globs*/**, self-aliasnpm:left-pad@…descriptors (revert byte-exact), defaultcompressionLevelspellings: pass. run 15: yarn upgrade 4.0.2 → 4.12.0/4.18.1 after vendoring, thenrollback/vendor --revert: fail #759 (bare-hex checksum restored; also release 4.0.0). Without a revert: pass.checksumBehaviorignore/update/reset: pass. run 14: native-addon packages (implicitnode-gyp: "npm:latest": nan, bufferutil) fail #737 on every fresh--immutable(4.0.2, 4.12.0, 4.18.1; also PR #719 head). Workspaces × node-modules/pnpm and packages with ownpeerDependencies: pass, plain and hardened. run 13: package whose tarballbin:differs from the registry metadata (uuid, acorn) fail #718: every fresh--immutablefails YN0028 (4.0.2, 4.12.0, 4.18.1). run 12: platform-conditional entries (conditions:) fail #697 (checksum afterconditions:; every conditional entry; also release 4.0.0).yarn removethen rollback: fail (#665, Berry evidence commented). Symlinkedyarn.lock/package.jsonreplaced: fail (#627, commented). Pass:yarn add/up/dedupeafter vendoring, then--revertkeeps the user's addresolutionsrefused correctly (redirect_yarn_berry_resolutions_conflict). Self-aliasnpm:left-pad@…descriptors: pin, fresh and rollback byte-exact. PR #763 head verified for #632 (5 catalog shapes + takeover, rollback byte-exact). run 14: native-addon packages (nan, bufferutil): fail #737 under hardened mode (4.0.2, 4.12.0, 4.18.1; PR #719 head too); regression from #465 (release 4.0.0 passes). Workspaces (merged entry + scoped) × node-modules/pnpm, ownpeerDependencies(fdir, use-sync-external-store): pass, hardened. nan rollback byte-exact. run 13: tarballbin:≠ registrybin:(uuid, acorn): fail #718 under hardened mode /--refresh-lockfile(4.0.2, 4.12.0, 4.18.1); regression from #465 (release 4.0.0 passes); plain--immutablepasses. run 12: conditional entry with deps and no checksum (@img/sharp-*) fail #697; esbuild (no deps) andsupportedArchitecturespass. Pass: two versions both patched (scoped rollback, byte-exact),debug(deps + peerDependenciesMeta),npmAlwaysAuth+ token (no auth to patch host, hardened), userpatch:descriptor refused, symlinked lock/package.json refused--revertbyte-exact); member-levelresolutionsand object-formworkspacespassrollback/removefail #817 (drops::__archiveUrl=, cold-cache install YN0001).gitignorecovers the vendored tgz:*.tgz,vendor/,.socket/)--immutableYN0001, warm cache too;--checkexits 0 under.socket/)vendor --revert)npm:original instate.json)patch:typescript/fsevents beside the target)pnpmStoreFolderrelocated).cache/.store:package_not_installedexit 0;store: refused as first-party source, exit 1; also release 4.0.0). Direct deps and a workspace member's direct dep pass (rollback restores). Defaultnode_modules/.storecontrol passes4646693(run 20 re-verification)yarn removethen rollback)@esbuild/linux-x64transitive), #817 takeover variant: fixed; pre-#719 pins heal on re-run; vendored→hosted takeover of abin:package pass. #737 and #759 still fail9c43dfc(run 21)pnpmStoreFolder(YARN_PNPM_STORE_FOLDER,~/.yarnrc.yml): direct deps refused as first-party, exit 1 (commented on #859). Env-onlyYARN_NODE_LINKER=pnpmwith the default store: pass.socketshared by two projects: fail #887 (unwind in one deletes the other's tgz +state.json; 4.0.2, 4.18.1, node-modules + pnpm). Linked.socket/vendor[/npm]refused (pass). Symlinkedyarn.lock/package.jsonrefused (#627 fixed).vendor --checkdrift (#725) fixed. Scoped stringbin(@babel/parser): passget <uuid>, andscanwhen the member owns a copy, exit 0 withredirected: 0. #632 fixed on main (4 catalog selectors, hardened fresh, rollback byte-exact). Scoped stringbin: pass9c43dfc(run 22).socket: fail (#887, agent evidence commented). Project reached through a symlinked path: pass--cwd): pass. Hosted→vendored takeover thenvendor --reverton a non-conventional mirror: fail #908npmRegistryServermirror withSOCKET_NPM_REGISTRYunset: rollback/remove fail #908 (bare locator, cold--immutableYN0035; #817 fix incomplete; byte-exact only whenSOCKET_NPM_REGISTRYis the mirror). Symlinked project path: pass9c43dfcand PR #91821413f1(run 23)npmRegistryServerfails on main (#908) and passes on PR #918;npmScopes.<scope>.npmRegistryServer(scoped target), envYARN_NPM_REGISTRY_SERVERand~/.yarnrc.ymlfail on both (commented on #908). Conventional mirror with a path base: pass on both9c43dfc(run 24)lp2other-namefile:copy: pass (both copies patched, rollback restores both)"lp2": file:tgz / dir / registry URL): fail #939 (no warning; lock-onlyvexand post-installvexattestnot_affected). Same-namefile:copy refused (vendor_override_conflict, pass)lp2shapes: fail #939 (no warning; lock-onlyvexattests; post-installvexdeclines). Same-namefile:copy refused (unsupported_protocol+shared_descriptor, pass)9c43dfcand PR #940980b7b6(run 25)portal:/link:lp2copy: first-party link skipped by design,vexattests (noted on #939). Useryarn patchover a hosted pin: vex declines, re-scan refuses (pass)yarn patchover a vendored pin, thenvendor --revert/rollback: fail #962 (exit 1 but wiring already half-reverted; YN0028).lp2asportal:/link:/github:: fail #939 on main and PR #940;file:tgz on the pnpm linker passes on PR #940yarn patchover a hosted pin, thenrollback/remove: fail #962 (exit 0 "Restored", fresh--immutableYN0028, mutable install re-pins the Socket URL).lp2asportal:/link:/github:: fail #939 on main and PR #940 (commented)9c43dfc(run 26).pnp.jsYarn 4 leaves: fail #975 (refused as PnP, exit 1; release 3.3.0 passes, 4.0.0 fails). Useryarn patchafter agent apply: overwritten by design.pnp.js: fail #975 (exit 1). Yarn 2.4.2 vendored: refused by design (cacheKey 7)pending_build) during a hosted→vendored takeover keeps the hosted pin: pass. Stale.pnp.js: pins, but a falseyarn_pnp_unsupportedwarning (#975). Write fault onyarn.lock: loud, re-run heals9c43dfcand PR #97859eac7e(run 27).pnp.js+ project-rc node-modules: fail #975 on main, pass on PRnodeLinkeronly in~/.yarnrc.yml(project outside$HOME) or viaYARN_RC_FILENAME: main passes (repo capstone, 11/11 VEX); PR #978 refusesvendor_yarn_berry_unsupported(commented on #539). Lock-only no-linker: refused up front on PR (#539)db83f01(run 28)*.tgzre-included;vendor//.socket/refusedvendor_artifact_gitignored). Shared symlinked.socket: fail #887 (still)npmScopes(scoped),YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir rc: rollback/remove fail #1017 (bare locator, cold--immutableYN0035). Project-rc top-level mirror (also trailing/,# comment, CRLF rc) and the inverse scope map: pass (#908 fixed). From a workspace member:getand member-ownedscanrefused (#884 fixed)05ecc6e(run 29)--jsonapply failure reported)lpx: 1.0.0) after vendoring: the pin covers it, butvendor --revert/rollbackdrop it and fresh--immutablefails YN0028 (#759 class, commented)package.jsonrefused by scan, rollback/remove (exit 1) and the vendored→hosted takeover; nothing written. #939 on merged main:file:copy dropped,portal:still attestse61a845(run 30).pnp.js: apply + rollback byte-exact). nodeLinker parity: home rc,YARN_RC_FILENAME, CRLF,${L:-node-modules}pass.nodeLinker: "${L:-pnp}"/"${L}"(L=pnp) on a live PnP install: fail #1100 (exit 0package_not_installed; release 4.0.0 refuses). Quoted key, next-line value, flow map, lower-caseyarn_node_linkerenv: false PnP refusal (listed on #1100)ea09714(run 31)package-lock.json: warned, revert byte-exact.compressionLevel: "${CL:-0}"false refusal (commented on #1100)package-lock.json: both locks pinned, rollback byte-exact.npmRegistryServer: "${REG:-<mirror>}": rollback/remove warnupstream_registry_fallback, then cold--immutableYN0035 (commented on #1017). Same${CL:-0}false refusale2d9633(run 32)apply --check: drift caught (exit 1), nmHoistingLimits two copies, version mix, pnpm linker, PnP fail-closed: pass. InterpolatedpnpmStoreFolder: "${STORE:-node_modules/.store}"transitive: pass. Shared linked.socket: still shared (acknowledged gap in #1042)scan --pruneGC keeps live entries: root, workspace member,catalog:, pnpm linker, CRLF lock, 4.0.2: pass. #887 fixed by #1042 (closed). #783 still fails. #737 (nan) still fails. uuidbin:vendored + revert byte-exact. Leftoverpnpm-lock.yaml: pnpm wins even withpackageManager: yarn@4(same in 4.0.0; documented warning). Yarn 2/3 gates holdbindiffers from the registry (uuid, prettier): fail #1131 (keeps./dist/bin/uuid, hardened--immutableYN0028; alsoea09714; release 4.0.0 not affected). #1057 stanza rewrite: plain, CRLF (byte-exact), alias-only JSON per-purl row, leftoverpnpm-lock.yaml(both pinned, rollback byte-exact): pass. #737 hardened still failscf8b164(run 33)${L:-pnp}live PnP: apply exit 0package_not_installed).pnpmStoreFolder: ../sharedused by two projects: apply in A patches B's copy too (documented: relocated berry store not containing the project is patched as usual)ckpresent/absent) on LF and CRLF: dry run byte-identical; partial retraction keeps the refused purl vendored (wiring, ledger, artifact) and migrates the other; all-retracted is byte-identical; fresh--immutableplain + hardened patched; rollback after a partial takeover restores pristine (4.0.2 byte-exact, bare hex). Workspaces (member^1.3.0+1.3.0),get <uuid> --mode hosted(kept/migrated),compressionLevel: mixedafter vendoring (both kept), PnP switch after vendoring (pins withyarn_pnp_unsupported, PnP fresh + hardened loads patched), aliaslp: npm:left-pad@1.3.0added after vendoring (alias_skipped, documented), write fault (chattr +ion yarn.lock / package.json / state.json, with and without a takeover): exit 1, nothing changed. VEX over a partial takeover: both attested.03b9418(run 34)yarn removeafter vendoring:--checknames it,--prune/--revert/rollback/removeretire it (pass)already+ fresh hardened + rollback byte-exact pass for workspaces,catalog:, transitive, pnpm linker, leftover npm/pnpm locks, legacy 4.0.0__archiveUrlmigration.yarn remove/yarn upto an unpatched version after a hosted pin: fail #1203 (leftoverresolutionsselector → rollback/list/remove exit 1 forever, the remedy scan is a no-op). #1131 still failsf3c6313(run 35)catalog:, 4.0.2,--revert/rollback/removebyte-exact; write faults on vendor and on unwind (exit 1, nothing half-written); generation A→B; hosted→vendored takeover then--revertpristine: pass. Repo berry e2e 187/187 (4.18.1) and 147/147 (4.0.2). #737 and #783 still failrollback: fail #1241 (journal replayed under the lock, pre-lock hosted discovery empty → exit 0, nothing restored;remove"No patch found"). #1039 retraction on the pnpm linker andcatalog:: passa80b89e(run 36)scan PATHon workspaces: pnpm linker member link selected (pass); hoisted copy outside the PATH is out of scope (by contract).nmMode: hardlinks-local+nmHoistingLimits: workspaces: apply patches 3 copies,rollback packages/arestores all without_of_scope_copies_restored(pass)--dry-runwrites nothing,repairredownloads a deleted tgz, CRLF lock,--revert/rollbackbyte-exact (pass). First vendoring SIGKILLed after its journal:rollbackrefuses pre-lock (vendor ledger is missing), never replays (commented on #809)Cannot restoreexit 1, or a pre-lock refusal that never replays the journal; commented on #1241)9ab72d4(run 37)remove/rollback <name>keeps the other package; SIGKILL duringvendor --revert/rollback/remove, then re-run: pass. BOM.yarnrc.ymlPnP gate (LF/CRLF): pass. Aliaslp: npm:left-pad@1.3.0added after vendoring, then revert/rollback/remove: exit 0, then YN0028 (commented on #1082)f3c6313a#1008): member or alias descriptor added after pinning → rollback/remove exit 0, then YN0028. SIGKILL mid-rollback: half-unwound,yarn installheals (residual)10c0/, fresh hardened--immutablepass.checksumBehaviorignore/update/reset: pass.Global (
-g) cells. Berry has no global dir, so these are npm-prefix globals scanned from inside or outside a Berry project:globalscript ran); otherwise pass, no project leak (node-modules, pnpm, PnP)not_appliedafter reinstall, EACCES loud,--global-prefixwith space and unicode).cmdshim not run)Backlog
yarn install --immutablerejects (YN0028) #1082 regression (run 37): point 2 is back onf3c6313a+ (Fix open npm issues #1008/npm hosted pin next to a bundled copy can't be unwound: rollback/remove refuse it, and the vendored takeover skips the restore, so vendor --revert lands back on hosted and allow-remote=all stays #828Discovery::shadowed;restore_berrynever merges blocks that share a resolution). Re-verify when fixed withh/bis.sh(plain member, root/member alias,remove, vendored alias revert; 4.0.2 and 4.18.1). Try other shadowed berry shapes: afile:/portal:sibling block (Yarn berry hosted and vendored scans miss afile:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939) and the hosted→vendored takeover over a shadowed pin.rollbackreplays the journal, then exits 0 having restored nothing, and the project stays hosted-patched (removesays "No patch found") #1241 (run 35; closed by a maintainer on 2026-10-09 with no fix commit; run 36 shows it still fails ona80b89ein both takeover directions): re-verify when a fix lands (rollback and remove right after a replayed vendored→hosted takeover journal; 4.0.2 and 4.18.1); alsolist/repair/vexin the same state, and a replayed hosted→vendored takeover journal (vendorkilled mid-commit) followed byrollback.0b. After
yarn removeof a hosted-pinned yarn berry package, its leftoverresolutionspin makes rollback, remove and list fail forever with hosted_wiring_contested, and the remedy they print (re-run the hosted scan) changes nothing #1203 (run 34): neighbours: removal from one workspace member while another keeps the dep, a removedcatalog:dep, a scoped package; re-verify when fixed (rollback, remove, list,scan --mode hosted --prune, 4.0.2 and 4.18.1). Also try the Decide whether a hosted patch is pinned through lockfile discovery alone #1058redirect_unattributablegate on berry shapes (portal:/link:copies, takeover + gate).send-pack: unexpected disconnect/remote end hung up; runs 14, 19 and 24: denied by the session permission policy), so no new probes. The stale branchesbughunt/yarn-berry/20260930-builtin-patch-takeoverandbughunt/yarn-berry/20261001-global-scriptneed deleting by hand. After that, probe the resolutions pin on macOS and Windows (CRLF), plus Vendored yarn berry PnP refusal keys only on .pnp.cjs: a lock-only PnP checkout vendors successfully, then every re-run in an installed checkout fails exit 1 with vendor_yarn_berry_unsupported #539, Agent mode misses transitive packages in Yarn's pnpm-linker store whenpnpmStoreFoldermoves it out ofnode_modules: skipped aspackage_not_installed, or refused as "first-party source" #859, Vendored mode still writes and deletes through a symlinked.socketdir: the #664 guard checks.socket/vendorand below only, so rollback in one yarn berry project wipes another project's vendored tarball and ledger #887 (a.socketjunction on Windows).0a. Make the vendored-to-hosted takeover atomic #1039 takeover (run 33, all pass): untested neighbours: SIGKILL during the journaled takeover commit (next locked command must finish it), takeover on the pnpm linker, takeover of a
catalog:dep with a retraction, a retraction caused byredirect_yarn_berry_resolutions_conflict(user resolutions added after vendoring).bin:paths (./dist/bin/uuid) on the restorednpm:entry, so hardenedyarn install --immutablefails YN0028 for packages like uuid and prettier #1131 (run 32): re-verify when fixed (rollback,remove, takeover +vendor --revert; uuid and prettier; 4.0.2 and 4.18.1; plain and hardened). Neighbours: other tarball-derived fields the Fix yarn berry pin entry rendering (#697, #718) #719 renderer emits (dependenciesMeta,peerDependenciesspellings), a scoped package with a./bin, the pnpm linker.1a. Yarn berry hosted pin can't cover a descriptor added after pinning: re-scan refuses with an impossible "dedupe" remedy, and rollback reports success but leaves a lock every
yarn install --immutablerejects (YN0028) #1082 (run 29; run 31: VEX fixed and rollback now fail-closed, re-scan dead end remains): neighbours: a transitive dep addinglpx@~1.0.0, the pnpm linker,remove, PnP lock-only; re-verify when fixed (and the berry half of PR Stop VEX attesting over yarn PnP, pnpm bundled and deno.lock copies #1033). Vendored yarn berry revert restores the pre-vendor lock entry verbatim, so after upgrading from yarn 4.0.x it writes back a bare-hex checksum and everyyarn install --immutablefails YN0028 #759: re-verify the new-descriptor revert symptom too.2a. Hosted yarn berry rollback/remove still drops a mirror's
::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017 (run 28; the${REG:-…}interpolated project-rc mirror added in run 31): re-verify when fixed (five sources × rollback/remove × 4.0.2/4.18.1;upstream_registry_fallbackwhen unreadable), plus the hosted→vendored takeovervendor --reverton those mirrors.1b. Yarn berry PnP refusal misses a live Plug'n'Play project whose
.yarnrc.ymlsetsnodeLinkerthrough${VAR}interpolation: agent apply exits 0 "not installed" and lock-only vendor passes the PnP gate (regression from #978) #1100 (run 30;${CL:-0}compressionLevel false refusal added in run 31): re-verify when fixed (agent + lock-only vendor,${L:-pnp},${L}, plus the fail-closed parser rows). Neighbours:${}incompressionLevel,enableGlobalCache,pnpStoreFolder,npmRegistryServer(otheryarnrc_scalarusers).yarn patchof the pinned package, but leave a lock that everyyarn install --immutablerejects (YN0028); the next install re-pins the Socket tarball #962 (hosted rollback/remove on 4.0.2 and 4.18.1, plus the vendored revert), Yarn berry hosted and vendored scans miss afile:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939 (all 12 cells plus agent; PR Fix VEX attesting beside an unpatched same-lock copy (#935, #938, #939) #940 fixes thefile:/URL VEX half but notportal:/link:/github:copies), Agent mode misses transitive packages in Yarn's pnpm-linker store whenpnpmStoreFoldermoves it out ofnode_modules: skipped aspackage_not_installed, or refused as "first-party source" #859 (plus the env/home variant), Vendored yarn berry misses a parent-scoped userresolutionsentry (pkg-a/left-pad), reports success, and everyyarn install --immutablefails YN0028 #783 (then@scope/parent/name, a scoped target, the hosted→vendored takeover), Vendored yarn berry revert restores the pre-vendor lock entry verbatim, so after upgrading from yarn 4.0.x it writes back a bare-hex checksum and everyyarn install --immutablefails YN0028 #759, Yarn berry vendored and hosted pins of native-addon packages (nan, bufferutil, utf-8-validate, node-addon-api) keep the registry entry's implicitnode-gyp: "npm:latest"dependency, so vendored installs and hardened hosted installs fail YN0028 #737, Vendored yarn berry PnP refusal keys only on .pnp.cjs: a lock-only PnP checkout vendors successfully, then every re-run in an installed checkout fails exit 1 with vendor_yarn_berry_unsupported #539, Hosted yarn berry rewrites a mixed-line-ending package.json that vendored mode refuses #628/Share the yarn berry project gates between hosted and vendored modes #629. Fixed and verified: Vendored mode still writes and deletes through a symlinked.socketdir: the #664 guard checks.socket/vendorand below only, so rollback in one yarn berry project wipes another project's vendored tarball and ledger #887 (run 32, vendored; closed), Yarn 4 node-modules / pnpm-linker projects migrated from Yarn 2 PnP keep a stale.pnp.js, and socket-patch refuses them as Plug'n'Play: agent and vendored exit 1, hosted warns "npm dependencies were NOT scanned" (regression since 3.3.0) #975, Vendored yarn berry PnP refusal keys only on .pnp.cjs: a lock-only PnP checkout vendors successfully, then every re-run in an installed checkout fails exit 1 with vendor_yarn_berry_unsupported #539 (run 30), Hosted yarn berry rollback/remove still drops a custom registry's::__archiveUrl=binding (#817 fix incomplete): the restore looks updist.tarballon npmjs, not the project'snpmRegistryServer, so cold installs 404 #908 project-rc case, Hosted scan/get run from a yarn classic workspace member still reports success while pinning nothing: the #598 governing-root refusal covers pnpm and cargo only #884 Berry, Vendored yarn classic exits 0 when .gitignore covers the vendored tarball (*.tgz,vendor/,.socket/), so the commit drops it and every fresh checkout's install fails #831 Berry (run 28), Hosted yarn berry pin of acatalog:dependency keysresolutionsby the resolvednpm:range, so everyyarn install --immutablefails YN0028 (regression from #465) #632 (run 21 on main),vendor --checksays "committed artifact and wiring verified" (exit 0) afterpipenv lockdrops the vendored reference, so a freshpipenv install --deployinstalls the unpatched wheel while vex says vendor_unwired #725 and Vendored yarn classic replaces a symlinked yarn.lock with a regular file (hosted refuses the same lock), leaving the link's target unpatched; rollback never restores the link #627 (run 21), Yarn berry vendored and hosted pins putchecksum:out of yarn's field order on platform-conditional lock entries (conditions: os=…), so everyyarn install --immutablefails YN0028 #697, Yarn berry vendored and hosted pins copy the registry entry'sbin:paths, but yarn re-reads them from the tarball (./dist/bin/uuid), so vendored installs and hardened hosted installs fail YN0028 for packages like uuid and acorn #718, Hosted yarn berry rollback/remove rebuilds the lock entry as a barename@npm:<version>locator and drops the registry's::__archiveUrl=binding, so projects on registries with non-conventional tarball URLs can't install after a revert #817, Afteryarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665 Berry (run 20). Hosted yarn berry redirect of resolve/typescript (yarn builtin compat patch) reports success, then everyyarn install --immutablefails YN0028 #368, Hosted → vendored takeover on yarn berry reverts the hosted redirect before a per-package vendor refusal, leaving the package unpatched in both modes #369, Yarn berry vendored and hosted modes refusecompressionLevel: 0 # commentin .yarnrc.yml as a non-default compression level #370, Hosted yarn berry redirect makes yarn send the project's npm registry auth token to the patch host #404,scan -ginside a Yarn Berry project runs the project'sglobalpackage.json script and scans whatever directory it prints as a global install #440, Vendored → hosted takeover on yarn berry deletes the vendored patch, then skips the hosted rewrite when the grant has no yarnBerry10c0 checksum, and still exits 0 "fully hosted" #468, Yarn 4 pnpm linker: transitive packages that live only in node_modules/.store are "not installed" in agent mode and stay unpatched #495 andremove <purl>garbage-collects the beforeHash blobs of every other patch still in the manifest, so a later offline rollback of those patches fails missing_blob #559 are closed.2b. (Yarn 4 node-modules / pnpm-linker projects migrated from Yarn 2 PnP keep a stale
.pnp.js, and socket-patch refuses them as Plug'n'Play: agent and vendored exit 1, hosted warns "npm dependencies were NOT scanned" (regression since 3.3.0) #975 and Vendored yarn berry PnP refusal keys only on .pnp.cjs: a lock-only PnP checkout vendors successfully, then every re-run in an installed checkout fails exit 1 with vendor_yarn_berry_unsupported #539 verified fixed one61a845, run 30.) Yarn 4 node-modules / pnpm-linker projects migrated from Yarn 2 PnP keep a stale.pnp.js, and socket-patch refuses them as Plug'n'Play: agent and vendored exit 1, hosted warns "npm dependencies were NOT scanned" (regression since 3.3.0) #975 neighbours: a stale.pnp.jsin a workspace member,vexon a Yarn 4 node-modules / pnpm-linker projects migrated from Yarn 2 PnP keep a stale.pnp.js, and socket-patch refuses them as Plug'n'Play: agent and vendored exit 1, hosted warns "npm dependencies were NOT scanned" (regression since 3.3.0) #975 tree, and any path that leaves.pnp.cjs/.pnp.loader.mjsbehind on a non-PnP linker. Re-verify Yarn 4 node-modules / pnpm-linker projects migrated from Yarn 2 PnP keep a stale.pnp.js, and socket-patch refuses them as Plug'n'Play: agent and vendored exit 1, hosted warns "npm dependencies were NOT scanned" (regression since 3.3.0) #975 when fixed (agent, vendored, hosted warning; 4.0.2 and 4.18.1; both linkers).3b. Yarn berry hosted rollback/remove report success after a user
yarn patchof the pinned package, but leave a lock that everyyarn install --immutablerejects (YN0028); the next install re-pins the Socket tarball #962 neighbours: ayarn patchof a workspace member's copy, apatch:wrapping a vendored pin from a member, and an agent-mode re-scan after the user's patch. (Yarn berry hosted and vendored scans miss afile:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939 neighbours were done in run 25.)yarn.lock, not in the parent'sworkspaces); object-formworkspaces; yarn 2/3 members.pnpmStoreFoldermoves it out ofnode_modules: skipped aspackage_not_installed, or refused as "first-party source" #859 neighbours:pnpmStoreFolderoutside the project (../shared) shared by two projects.*.tgz,vendor/,.socket/), so the commit drops it and every fresh checkout's install fails #831 (fixed ondb83f01) follow-up: the hosted→vendored takeover under an ignore rule.-g) on macOS/Windows, and a version-manager prefix (nvm/volta). Full checklist in the 20261001T040000Z entry.pkg:npm/jsonstream@1.3.5) for a mixed-case package, and every mode misses it. File it (cross-PM) only if the real API is shown to lower-case.package/, hosted skips it withnpm_manifest_unavailable(exit 0). File it only if the real service does that.pnpmStoreFolder/npmScopesvalues (Yarn berry PnP refusal misses a live Plug'n'Play project whose.yarnrc.ymlsetsnodeLinkerthrough${VAR}interpolation: agent apply exits 0 "not installed" and lock-only vendor passes the PnP gate (regression from #978) #1100/Hosted yarn berry rollback/remove still drops a mirror's::__archiveUrl=binding when the registry comes fromnpmScopes,YARN_NPM_REGISTRY_SERVER,~/.yarnrc.ymlor a parent-dir.yarnrc.yml(#908 fix covers only the project rc's top-level key) #1017 class).Known non-bugs
.pnp.cjsare refused in every mode withyarn_pnp_unsupported(documented).resolve,typescript,fsevents) is refused fail-closed withvendor_override_conflict. It's loud and closed, so it isn't filed (the hosted counterpart is Hosted yarn berry redirect of resolve/typescript (yarn builtin compat patch) reports success, then everyyarn install --immutablefails YN0028 #368).npm:alias ("left-pad@npm:1.3.0, lp@npm:left-pad@1.3.0") withredirect_yarn_berry_ambiguous_entryand exit 1. It's fail-closed and loud; arguably over-broad, but not filed.yarn install --immutablein the same tree doesn't restore unpatched bytes (yarn's install-state), and the setup hook re-patches after a clean install. Standalonevexin agent mode needssetuporsetup.manual(documented).patches-api.socket.devis unreachable from the sandbox; use the mock.yarn install --immutable(YN0028) on its own, because yarn strips the BOM. Not caused by socket-patch.npm:alias-only entry →redirect_yarn_berry_alias_skipped(documented in docs/ecosystems.md).Superseded in run 21: after Hosted scan/get run from a pnpm workspace member (or withscan <workspace-member-dir>finds 0 packageslockfile-dir=..) ignores the parent pnpm-lock.yaml and reports success while pinning nothing #590/Fix hosted scan from a workspace member pinning nothing or the wrong files (#590, #417) #598, the hosted run from a member is a bug (Hosted scan/get run from a yarn classic workspace member still reports success while pinning nothing: the #598 governing-root refusal covers pnpm and cargo only #884, Berry evidence commented). A hoisted member scan still finds 0 packages, butget <uuid>and member-owned copies report success while pinning nothing..pnp.cjs: scan reports 0 packages with a PnP warning (same in 4.0.0). A PnP lock-only checkout gets hosted pins, and those install correctly under PnP.patch.socket.dev(or--patch-server-url) URLs as hosted pins. Without that flag, a mock host reads as "Manifest not found"..pnp.js) and 3.x is detected and gets the loud PnP warning in every mode, exit 0 (same as 4.x).scan -g --mode agent) after a failed apply (EACCES) exits 0 with "already recorded … runsocket-patch apply". This is the designed re-run message;apply -gitself exits 1.scan -gdoesn't mention-g. It's cross-PM and was handed to npm (Bug hunt ledger: npm #302), so it isn't filed here.enableHardenedMode, auto-on for public fork PRs in GitHub Actions) accepts a hosted::__archiveUrl=lock pin, as does--check-resolutions(4.12.0, registry reachable).enableGlobalCache: falsewith.yarn/cachecommitted): hosted mode is lock-only, so the committed cache keeps the unpatched zip, andyarn install --immutable --immutable-cachefails YN0056 untilyarn installrefreshes the cache. Vendored mode behaves the same way (thefile:entry has no cache zip; no warning). It's a docs gap, not filed.compressionLevelset outside the project.yarnrc.yml(env, home or parent rc) can't cause a wrong checksum: yarn bakes the level into the lock'scacheKey, which both modes gate on.yarn patch(patch:descriptor) withvendor_override_conflict, plus an alias-only dependency (root or workspace member) withvendor_lock_entry_not_found, a merged direct + alias entry, and a user-authoredresolutionskey for the target. All are loud and closed with nothing written, so none are filed.yarn.lockis refused by vendored (vendor_yarn_berry_mixed_line_endings) and hosted (redirect_yarn_berry_mixed_line_endings). That's correct: yarn itself fails YN0028 on such a lock.rollbackdrops the patch's manifest entry, so a laterapplyis a no-op (designed).package.json. Vendored snapshots the post-install bytes and reverts to them byte-exactly.left-pad@1.2.0alongside the patched 1.3.0) withvendor_override_conflict, because the name-keyedresolutionswould move both. That's correct and loud.repairrefuses (vendor_artifact_redownload_failed, nothing written) when the service now serves different bytes for a uuid whose integrity is pinned in the ledger. That's correct.vendor --cwd <workspace member>fails loudly withvendor_lockfile_missing(the lock lives at the root).virtual:entries for peer-dependent packages, so the hosted/vendored rewrite has no virtual locator to keep in sync.package.jsonto 2-space and drops a user-authored empty"resolutions": {}. Yarn's own next install writes exactly the same bytes, so it isn't filed.redirect_yarn_berry_shared_descriptor,redirect_yarn_berry_ambiguous_entry,cache_unsupported) exit 0 withredirected: 0and nothing written. With--vexand nothing to attest, the run exits 1.resolutionsentry targeting the patched package (bare or scoped selector) withredirect_yarn_berry_resolutions_conflict. It's documented and loud.vendor --revertremoves the orphan, andvexrefuses.rollbackandrepairfail withmanifest_not_foundin that state.yarn add left-pad@1.3.0) leaves a staleresolutionsselector.rollbackin that state refuses loudly and tells you to re-runscan --mode hosted, which re-pins correctly. It's fail-closed and gives a remedy, so it isn't filed.left-pad@https://…tgz) is refused withredirect_yarn_berry_unsupported_protocol, exit 0, nothing written. That's correct.compressionLevel: mixed(cacheKey10) is refused by hosted (redirect_yarn_berry_cache_unsupported, exit 0) and vendored (vendor_yarn_berry_cache_unsupported, exit 1). Both are documented.patch:descriptor independenciesis refused (redirect_yarn_berry_unsupported_protocol+redirect_yarn_berry_shared_descriptor), nothing written. That's correct. The hint suggests--mode vendored, which also refuses it;--mode agentworks.checksum:for a platform-conditional entry reached only throughoptionalDependencies, and strips one on its next mutable install. A hosted pin's checksum on such an entry therefore doesn't surviveyarn add;vexstill attests from the installed tree. That's yarn's policy. The misplaced-line part is Yarn berry vendored and hosted pins putchecksum:out of yarn's field order on platform-conditional lock entries (conditions: os=…), so everyyarn install --immutablefails YN0028 #697.bin:differs from the tarball's passes a plainyarn install --immutableand a later mutable install (yarn trusts the locked entry). Only hardened mode or--refresh-lockfilefails, and that is Yarn berry vendored and hosted pins copy the registry entry'sbin:paths, but yarn re-reads them from the tarball (./dist/bin/uuid), so vendored installs and hardened hosted installs fail YN0028 for packages like uuid and acorn #718.%2540purls (run 14).lockfileFilenamein.yarnrc.ymlis rejected by yarn 4 ("Unrecognized or legacy configuration settings"). It only exists in yarn 2/3, which hosted/vendored refuse anyway.checksumBehavior(ignore/update/reset) doesn't change what yarn writes to the lock. Hosted and vendored pins pass under all three (run 15).**/nameresolution is dropped frompackage.jsonby yarn 4's own install, so a hosted pin that seems to replace it isn't socket-patch's doing (run 16).compressionLevel:with its value on the next line (a multi-line YAML scalar) is refused by both modes. It's loud and unrealistic, so it isn't filed (run 16).vexon a tree whosenode_modulesstill holds unpatched bytes (wiring pulled without a reinstall) attestsnot_affectedfrom the committed artifact and warnsvendored_tree_out_of_sync. That's by design (run 17).vendor --checkreporting wiring verified after the Berry wiring drifts isvendor --checksays "committed artifact and wiring verified" (exit 0) afterpipenv lockdrops the vendored reference, so a freshpipenv install --deployinstalls the unpatched wheel while vex says vendor_unwired #725 (cross-PM root cause, Berry evidence commented in run 17). Don't re-file it.yarn install --mode=update-lockfile(Renovate) still writeschecksum:lines on yarn 4.0.2 and 4.18.1, so there are no checksum-less target entries to test (run 18).npm:<v>locator where yarn wrote::__archiveUrl=passes hardened mode and--refresh-lockfile. The breakage is only the fetch (Hosted yarn berry rollback/remove rebuilds the lock entry as a barename@npm:<version>locator and drops the registry's::__archiveUrl=binding, so projects on registries with non-conventional tarball URLs can't install after a revert #817).scan --mode agent --jsonreporting an apply failure asaction: "added",failed: 0with no error is scan/get --json drop the agent-mode apply failure: exit 1 with failed: 0, the patch shown as "added", and no error anywhere (e.g. a read-only global ~/.m2) #424 (cross-PM, open). Don't re-file it (run 20).pnpmStoreFolder("Unrecognized or legacy configuration settings"), so Agent mode misses transitive packages in Yarn's pnpm-linker store whenpnpmStoreFoldermoves it out ofnode_modules: skipped aspackage_not_installed, or refused as "first-party source" #859 cells start at 4.1+ (run 20).yarn.lock/package.json(Fix vendored mode replacing symlinked lockfiles (#627) #802) leaves.socket/vendor/npm/<uuid>/behind despite saying "nothing was written". It's benign (vexrefuses,vendor --checksees nothing, the re-run is clean), so it isn't filed (run 21).SOCKET_NPM_REGISTRY(run 21).--cwdthrough a link, as macOS/tmpis) works in agent, vendored and hosted modes (run 22).npmRegistryServer: http://host/api/npm/npm-remote) restores bare and byte-exact after a hosted rollback (run 23).name@npm:<version>locator and drops the registry's::__archiveUrl=binding, so projects on registries with non-conventional tarball URLs can't install after a revert #817 runs 18–20 "fixed" verdicts held only withSOCKET_NPM_REGISTRYpointed at the project's mirror. The realistic config is Hosted yarn berry rollback/remove still drops a custom registry's::__archiveUrl=binding (#817 fix incomplete): the restore looks updist.tarballon npmjs, not the project'snpmRegistryServer, so cold installs 404 #908, so don't re-verify Hosted yarn berry rollback/remove rebuilds the lock entry as a barename@npm:<version>locator and drops the registry's::__archiveUrl=binding, so projects on registries with non-conventional tarball URLs can't install after a revert #817 that way.file:directory/tarball copy of the patched package ("left-pad": "file:…") is refused by hosted (redirect_yarn_berry_unsupported_protocol+redirect_yarn_berry_shared_descriptor) and vendored (vendor_override_conflict), nothing written. That's correct; the other-name copy is Yarn berry hosted and vendored scans miss afile:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939 (run 24).yarn patchon a hosted-pinned package makesvexdecline (hash_mismatch) and a re-scan refuse (thepatch:entry wraps the descriptor). Both are correct; only the unwind is Yarn berry hosted rollback/remove report success after a useryarn patchof the pinned package, but leave a lock that everyyarn install --immutablerejects (YN0028); the next install re-pins the Socket tarball #962 (run 25).node_modules/<name>link into first-party source (portal:/link:) by design (docs/ecosystems.md), and reportsalready patched. Whether VEX should then attest is raised on Yarn berry hosted and vendored scans miss afile:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939, so don't re-file it (run 25)./upstream/npm/<uuid>.jsonroute is incomplete (run 25).scanwhoseyarn.lockwrite fails afterpackage.jsonwas written exits 1 loudly. A re-run completes the pin (exit 0). Hostedrollbackwith a write fault can leavepackage.jsonrestored andyarn.lockstill pinned;staged.rsflush_stageddocuments that as the residual I/O-fault exposure (run 26).applyover a file the user changed withyarn patchoverwrites it with Socket's patched bytes (content_mismatch_overwritten). That's the documented default mismatch policy;--strictrefuses instead (run 26).installConfig.pnp, all delete.pnp.js; only Yarn 4 leaves it (Yarn 4 node-modules / pnpm-linker projects migrated from Yarn 2 PnP keep a stale.pnp.js, and socket-patch refuses them as Plug'n'Play: agent and vendored exit 1, hosted warns "npm dependencies were NOT scanned" (regression since 3.3.0) #975, run 26).scan --mode hostedfinds 0 packages and exits 0 after Fix hosted runs from npm/yarn/bun workspace members pinning nothing (#884) #901. Only a member-owned copy, orget <uuid>, triggersredirect_workspace_lockfile_elsewhere(run 28).timefield (YN0016, "All versions … are quarantined"). Mock registries must servetime(run 28).package.jsonexits 0 withredirect_yarn_berry_mixed_line_endings, nothing written (per-package hosted refusals exit 0); hosted rollback/remove refuse it with exit 1. The rollback hint naminggit checkout -- yarn.lockand the--jsontop-levelfailed: 0are cosmetic (run 29).vexin agent mode on a live PnP tree omits the package (package_not_found) whatever the nodeLinker spelling, so Yarn berry PnP refusal misses a live Plug'n'Play project whose.yarnrc.ymlsetsnodeLinkerthrough${VAR}interpolation: agent apply exits 0 "not installed" and lock-only vendor passes the PnP gate (regression from #978) #1100 doesn't produce a false attestation (run 30).remove <uuid>naming a superseded generation (A, after a re-pin or re-vendor to B) refuses with exit 1 and leaves B wired. That's correct (run 31).scan --mode agentover a vendored package with a newer patch published keeps the vendored generation (vendored_ownership_retained), so the remove <uuid> deletes the manifest entry but leaves the package vendored when the vendor ledger holds an older patch generation #999 manifest-B/ledger-A shape can't arise on berry this way (run 31).package-lock.jsonbeside a berryyarn.lock: vendored warnsvendor_multiple_lockfiles, and VEX declines withpatched_ref_unattributable. Hosted pins both locks, and rollback restores all three files byte-exact (run 31).redirect_yarn_berry_unsupported_protocol+entry_not_foundagainst a mock means the mock's tarball leaf isn't<name>-<version>.tgz(run 31).pnpm-lock.yamlbeside a berryyarn.lock: vendored wires pnpm (vendor_multiple_lockfilesnamesyarn.lockas unwired), even withpackageManager: yarn@4.18.1. Same in release 4.0.0 and documented as a warning, so not filed. Hosted pins both locks and rolls back byte-exact (run 32)..socketis still shared between projects (rollback in one empties the shared manifest). Guard .socket links and agent writes with one containment helper #1042 keeps it deliberately and calls it a known gap; the vendored half of Vendored mode still writes and deletes through a symlinked.socketdir: the #664 guard checks.socket/vendorand below only, so rollback in one yarn berry project wipes another project's vendored tarball and ledger #887 is fixed (run 32).scan --mode vendored --pruneneeds a patch to exist for the human path to run the GC (Humanscan --mode vendored --prunesilently skips the vendored GC when no remaining package has a patch, so annpm uninstalled vendored entry is never reverted (exit 0), while--jsonreverts it andvendor --checkkeeps pointing at that same command #1127, npm-owned); use--json(run 32).pnpmStoreFolderoutside the project (../shared) shared by two projects: agent apply in one patches the other's copy. docs/ecosystems.md explicitly patches a relocated berry store that does not contain the project, so it isn't filed (run 33).redirect_takeover_kept_vendored) exits 0, also forget <uuid> --mode hosted, like every per-package hosted refusal (run 33).npm install --package-lock-onlybeside a berryyarn.lockrewrites it as a classic v1 lock, so a later hosted scan warnsredirect_yarn_classic_berry_migration_risk. That's a harness artifact, not a socket-patch bug (run 34).catalog:, pnpm linker) asalready, and migrates release-4.0.0__archiveUrlpins (run 34)..socket/vendor/.socket-stage-.commit-journal.json-*exists) commits nothing, androllbackunwinds the vendored state byte-exact. The stray stage file stays untracked; benign, not filed (run 35)..socket/vendor/npm/<uuid>/dirs are A vendored-to-hosted takeover interrupted after its commit journal is written leaves the vendored artifact directory behind for good: recovery finishes the files but not the deferred deletions, and no GC can reclaim it once the ledger is gone #1157 (pnpm-owned, cross-PM); don't re-file them (run 35).package.jsonandyarn.lockrenames leaves a half-pinned pair.rollbackrefuseshosted_wiring_contestedwith a working remedy, and a re-scan heals it. Not filed (run 36)..socket-stage-<file>-<uuid>temp siblings, and journal replay doesn't remove them. The contract promises a clean tree only after a successful write; the npm routine already noted it on vendor --check and vex misreport a crashed vendored run whose commit journal is pending, because only lock-taking commands replay it #809 (run 36).scan PATH: a member's dependency hoisted to the rootnode_modulesis out of scope forscan packages/a(contract: in scope only if some installed copy sits under the PATH) (run 36).rollback/remove(journal-less by design), the lock keeps an orphaned pin. The re-run refusespatched_ref_invalid, and its "re-run the hosted scan" remedy is a no-op, but a plainyarn install(orgit checkout -- package.json yarn.lock) heals it. Loud, so not filed (run 37).rollback/remove name@version, CVE and GHSA ids select no hosted or vendored pin (documented);isnext to@sindresorhus/isselects onlyis(the full name wins, by design); a hoisted member dependency is out of reach ofrollback packages/a(path_glob_no_match, by contract) (run 37).lp: npm:left-pad@1.1.3) beside a pinned^1.3.0doesn't block VEX or the pin (run 37).All reactions