Repository navigation
Retire berry resolutions left by yarn remove (#1203) - #1321
Open
Mikola Lysenko (mikolalysenko) wants to merge 4 commits into
Open
Mikola Lysenko (mikolalysenko) wants to merge 4 commits into
Mikola Lysenko (mikolalysenko) wants to merge 4 commits into
Conversation
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
After `yarn remove` or `yarn up` of a hosted-pinned yarn berry package, the root package.json keeps the Socket `resolutions` selector. That selector read as contested hosted wiring, so rollback, remove and list failed forever with hosted_wiring_contested, and re-running the hosted scan (the printed remedy) did not help. Discovery now records a hosted selector that no live berry lock entry resolves, and that matches no lock descriptor, as a stale selector. HostedInventory excuses it from contested wiring. rollback and remove retire it from package.json with a hosted_resolution_orphaned warning and leave yarn.lock alone. list succeeds and warns. Fixes #1203 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko)
force-pushed
the
agent/v5-berry-leftover-resolutions
branch
from
October 9, 2026 17:29
c78c0fa to
b81ea11
Compare
Mikola Lysenko (mikolalysenko)
marked this pull request as ready for review
October 9, 2026 17:40
Collaborator
Author
|
BugBot review |
Mikola Lysenko (mikolalysenko)
enabled auto-merge
October 9, 2026 17:40
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
Bugbot Autofix is ON. A cloud agent has been kicked off to fix the reported issue.
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit b81ea11. Configure here.
The list and restore warnings for a leftover berry selector named the patch uuid and the hosted URL, which carries the grant token. CodeQL flagged the uuid as cleartext logging. Name the file, the purl and the selector instead, as the contested refusal names files. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The hosted_resolution_orphaned list warning suggested an unscoped rollback, which also restores every other hosted pin and vendored entry. Name `socket-patch remove <purl>`, which retires only the leftover selector. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Tanmay Singla (Tanmay182003)
approved these changes
Oct 9, 2026
Mikola Lysenko (mikolalysenko)
disabled auto-merge
October 9, 2026 19:55
This was referenced Oct 9, 2026
Collaborator
Author
|
Ready for review at
Labeled Generated by Claude Code |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

LLM Description written by Claude Code:claude-opus-5-5
Fixes #1203
Summary
After
yarn remove(oryarn upto an unpatched version) of a hosted-pinned yarn berry package, the rootpackage.jsonkeeps the Socketresolutionsselector, because yarn never editsresolutions. That selector used to read as contested hosted wiring, sorollback,removeandlistexited 1 every time withhosted_wiring_contested, and the printed remedy (re-running the hosted scan) changed nothing.Now the selector counts as Socket's own leftover pin:
listsucceeds and lists the live pins. It warnshosted_resolution_orphanedand names the commands that remove the selector.rollback(unscoped, or scoped to the purl) andremove <uuid|purl>delete the selector frompackage.jsonand warnhosted_resolution_orphaned. They drop an emptiedresolutionsobject and leaveyarn.lockuntouched. The other hosted pins are restored as before.Root cause
Lockfile discovery reads the root
package.jsonand recognizes every Socket identity in it (rule 11).HostedInventory::of(crates/socket-patch-core/src/patch/redirect/upstream/mod.rs) marked any recognized hosted uuid that no lock pin attributes as contested. It did not separate "no lock entry resolves this selector any more" from "the lockfiles disagree". The berry restore only walks lock pins, so nothing ever removed such a selector.The fix
vendor::lock_inventory::yarn::berry_selector_routes_nothingholds the one staleness rule. A selector is leftover only when no live berry lock entry resolves its URL (as a tarball locator or an older__archiveUrl=binding) and no live lock entry is keyed by a descriptor it matches: the exactname@rangefor a ranged selector, any descriptor of the package for a range-less one. A selector that still matches a descriptor the lock resolves elsewhere means the manifest and lock disagree, so it stays contested. Discovery only looks at a berry lock that exists.Discovery::stale_selectors(vex/discover/yarn.rs). It only does this when the URL's leaf names the package version, which gives the purl. The selectors are not refs and are never attested.HostedInventoryexposes them asstalepins (files:package.json). Their URL's uuids are excused from contested wiring in that manifest.HostedInventory::unwindable()(pins + stale) is whatrollbackandremoveact on.liststill listspinsonly.restore_upstreamgains apackage.jsonformat (npm::retire_stale_selectors). It runs after the yarn.lock restore over the same staged view, re-checks each selector against the sibling berry lock, and removes it. A pin it cannot find a selector for is refused as before.scan --mode hosted --pruneis unchanged: hosted mode runs no GC, and the contract documents the flag as ignored there withredirect_prune_ignored. The selector no longer blocks anything, androllback/removeretire it.Tests (red → green)
yarn removeis stale, not contested (with and without another live pin)crates/socket-patch-core/tests/hosted_inventory.rs::berry_selector_left_by_yarn_remove_is_stale_not_contested…::berry_selector_is_only_retired_against_a_berry_lock…::restore_retires_a_leftover_berry_selectorlistexits 0 withhosted_resolution_orphaned(washosted_wiring_contested, exit 1)crates/socket-patch-cli/tests/in_process_rollback_hosted.rs::berry_selector_left_by_yarn_remove_is_listed_aroundrollbackexits 0 and retires it; a laterlistis clean…::rollback_retires_a_berry_selector_left_by_yarn_removeremove <uuid>andremove <purl>exit 0 and retire it (wasnot_found)…::remove_retires_a_berry_selector_left_by_yarn_removeBefore the fix, the core tests don't compile (
HostedInventoryhas nostale), and the CLI cells reproduce the issue's table (exit 1,hosted_wiring_contested/not_found).CLI_CONTRACT.md documents the new behaviour and the
hosted_resolution_orphanedcode.Commands run (local, macOS)
cargo fmt --all -- --check(only files this PR touches)cargo clippy --workspace --all-features -- -D warnings: cleancargo test -p socket-patch-core --no-fail-fast: all green (lib 6109 passed, every integration binary green, discovery goldens unchanged)cargo test -p socket-patch-cli --lib --test in_process_rollback_hosted --test in_process_redirect --test mode_migration_npm --test in_process_vendor: 915 + 38 + 137 + 21 + 131 passed, 0 failed🤖 Generated with Claude Code
Note
Medium Risk
Changes hosted-inventory classification and manifest edits for Yarn Berry
resolutions; incorrect staleness detection could retire a selector that still matters or miss a true contested case.Overview
Fixes #1203: Yarn Berry projects no longer get stuck in
hosted_wiring_contestedwhenyarn remove/yarn updrops the lock entry but leaves a Socketresolutionsselector in rootpackage.json.Discovery now records those selectors as
stale_selectorsandHostedInventory::stalewhenberry_selector_routes_nothingsays nothing in the live berry lock still resolves the hosted URL or matches the selector’s descriptor. Their patch UUIDs are excused from contested wiring;rollbackandremoveact onunwindable()(live pins + stale) and runretire_stale_selectorsto remove only the orphanedresolutionsentries (and drop an emptyresolutionsobject), withyarn.lockunchanged.liststill shows live pins and emitshosted_resolution_orphanedwith remediation hints instead of failing.CLI_CONTRACT.md documents the behavior and the new warning code on
list,rollback, andremove.Reviewed by Cursor Bugbot for commit b81ea11. Configure here.
Generated by Claude Code