Repository navigation
Read berry restore registry like yarn does (#1017) - #1323
Merged
Mikola Lysenko (mikolalysenko) merged 4 commits intoOct 10, 2026
Merged
Conversation
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Hosted yarn berry rollback, remove and the takeover restore read
only the project .yarnrc.yml's top-level npmRegistryServer. A
mirror set through npmScopes, YARN_NPM_REGISTRY_SERVER, a
parent-directory or home .yarnrc.yml, or a ${VAR:-default} value
was ignored. The restore then dropped the mirror's __archiveUrl
binding without a warning, and the next cold immutable install
failed YN0035.
The restore now resolves each package's registry the way yarn
merges its settings, and warns upstream_registry_fallback when
the registry cannot be determined.
Fixes #1017
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko)
marked this pull request as ready for review
October 9, 2026 17:57
Collaborator
Author
|
BugBot review |
Mikola Lysenko (mikolalysenko)
enabled auto-merge
October 9, 2026 17:57
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.
Bugbot Autofix is ON. A cloud agent has been kicked off to fix the reported issues.
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit d1221ab. Configure here.
A checked-in .yarnrc.yml could name any variable of the socket-patch process (a token) in npmRegistryServer. The restore would then request, and on a failed lookup print, a URL carrying it. A reference to a variable that is set is now treated as an undeterminable registry. The restore falls back to the default registry with upstream_registry_fallback, as the Bun and pnpm settings readers already do. An unset variable's default is still read the way yarn reads it. The hosted-unwind test runner also clears YARN_NPM_REGISTRY_SERVER and YARN_RC_FILENAME, so an ambient value can't steer the fixtures. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Tanmay Singla (Tanmay182003)
approved these changes
Oct 9, 2026
Mikola Lysenko (mikolalysenko)
disabled auto-merge
October 9, 2026 19:55
Collaborator
Author
|
Ready for review at
Labeled Generated by Claude Code |
Resolve conflicts with #1131 (restored berry entry takes the registry's bin spelling back): keep the per-package registry lookup for the locator and feed it to the bin re-render; keep both rollback tests; merge the CLI_CONTRACT npm-family paragraph (berry registry chain + #1131 + #1276 Bun user config) and take main's uv override wording. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko)
enabled auto-merge
October 10, 2026 13:22
Mikola Lysenko (mikolalysenko)
deleted the
agent/v5-berry-registry-sources
branch
October 10, 2026 13:38
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

LLM Description written by Claude Code:claude-opus-5-5
Fixes #1017
Summary
Hosted yarn berry
rollback,removeand the takeover restore now read each package's registry the way yarn resolves it. Before, they only read the project.yarnrc.yml's top-levelnpmRegistryServer. A mirror configured anywhere else was ignored: the restore read npmjs (orSOCKET_NPM_REGISTRY), wrote a barename@npm:<v>locator with no warning, and the next coldyarn install --immutablefailedYN0035 … 404against the mirror.The registry sources the restore now reads:
npmScopes.<scope>.npmRegistryServer(the scope's own server wins; a scope without one falls through to the default server)YARN_NPM_REGISTRY_SERVERnpmRegistryServerfrom the closest.yarnrc.yml(orYARN_RC_FILENAME) that sets it: the lock's directory, then every parent directory up to the filesystem root, then the home directory${VAR-default}and${VAR:-default}in those values: a reference to an unset variable is read as its default, as yarn'sreplaceEnvVariablesreads it. A reference to a variable that is set is never expanded, because a checked-in rc file must not choose which of the process's variables (a token, say) lands in a URL the restore requests and may print. It gets the fallback below instead, like the Bun and pnpm settings readers (Bugbot security review).When yarn's registry can't be known, the restore falls back to the default registry and now warns
upstream_registry_fallbackinstead of staying silent. That covers a reference to an unset variable with no default (yarn itself refuses to run then), a reference to a set variable (see above) and annpmScopeswritten as a flow mapping, which this reader doesn't follow.The per-package registry also decides whether the restored locator keeps its
::__archiveUrl=binding. Before, a scoped package was compared against the top-level registry.Root cause
berry_lookup_registryandrestore_berry(crates/socket-patch-core/src/patch/redirect/upstream/npm.rs) read only the project rc's top-level key. They returned the default registry for every scoped name once annpmScopesblock existed, and they ignored env, parent-directory rc files, the home rc and interpolation.The fix
BerryRegistrySettings::readcollects the rc chain as yarn finds it (lock directory → ancestors → home, closest first, home skipped when it is already in the chain) plusYARN_NPM_REGISTRY_SERVER.berry_lookup_registry(rcs, env, name, var)is a pure resolver. It reads nested block mappings with a small path reader (yaml_path_value) and expands references withyarn_expand_env.restore_berryresolves once per package name, passes the result tofetch_dists_onandberry_registry_locator, and warns onErr.YARN_NPM_SCOPES(an env override of the whole scope map) isn't read. The issue's cells don't use it, and yarn's env form for a map setting is unusual.Tests (red → green)
YARN_NPM_REGISTRY_SERVER, parent-dir rc,~/.yarnrc.yml(project outside home),${VAR:-mirror}in the project rc: rollback keeps the mirror's::__archiveUrl=binding byte-exactlycrates/socket-patch-cli/tests/in_process_redirect.rs::yarn_berry_rollback_reads_the_registry_from_every_yarn_sourceupstream_registry_fallback…::yarn_berry_rollback_warns_when_the_registry_cannot_be_knownnpmScopesscoped / unscoped / scope without a server, scope vs env vs rc precedence, layered rc files, flow-style refusalnpm.rsunitberry_reads_the_registry_from_every_yarn_settings_source${A-d},${A:-d}, empty vs unset, unset with no default, a set variable refused)npm.rsunitberry_registry_values_expand_env_references_like_yarnnpm.rsunitberry_scopes_probe_reads_past_one_bom_only(updated: a scoped name now gets its scope's registry, which the old test pinned as the default registry)Red: with the resolver cut back to the old sources (project rc only, no env), the CLI cell fails at
Env: rollback keeps the mirror's __archiveUrl binding. Green with the fix. The #908 control (yarn_berry_rollback_reads_the_tarball_from_the_project_registry) still passes.CLI_CONTRACT.md documents the sources and the new fallback cases.
Commands run (local, macOS)
cargo fmt --all -- --check(files touched by this PR)cargo clippy --workspace --all-features -- -D warnings: cleancargo test -p socket-patch-core --no-fail-fast: 0 failurescargo test -p socket-patch-cli --lib --test in_process_rollback_hosted --test in_process_redirect --test mode_migration_npm --test in_process_vendor: 915 + 139 + 35 + 131 + 21 passed, 0 failedOverlap: open PR #1283 (Bun user registry config) also edits
upstream/npm.rs, in the Bun section only. No textual overlap is expected beyond imports.🤖 Generated with Claude Code
Note
Medium Risk
Changes upstream lockfile restore behavior for Yarn Berry hosted pins; incorrect resolution could still produce wrong tarball URLs, though fallbacks are now warned and heavily tested.
Overview
Fixes hosted Yarn Berry rollback/remove restoring lock entries against the wrong npm registry when the mirror is not on the project
.yarnrc.ymltop-levelnpmRegistryServer.Registry resolution now mirrors Yarn: scoped
npmScopes.<scope>.npmRegistryServer, thenYARN_NPM_REGISTRY_SERVER, then the nearest.yarnrc.ymlin the lock directory → parents → home, with${VAR}/${VAR:-default}expansion. Each package’s resolved registry drives version-document fetches and whether the restored locator keeps::__archiveUrl=. When the registry cannot be determined (unset env ref with no default, flow-stylenpmScopes), restore falls back to the default registry and emitsupstream_registry_fallbackinstead of silently writing a bare locator that breaks immutable installs against mirrors.CLI contract and integration/unit tests cover env, parent/home rc, interpolation, and the new warning path.
Reviewed by Cursor Bugbot for commit d1221ab. Configure here.
Generated by Claude Code