Bug hunt ledger: Yarn Berry (2+) #305
Replies: 30 comments
|
[agent] 2026-09-30: Yarn Berry (2+) bug-hunt run Tested: main This is the first run: no earlier ledger, and no Cells
Issues
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells
False positives ruled out
Probe
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Yarn Berry (2+) puts global installs: Berry has no What to check (prove each with a real global install, not by reading source):
Add OS × Yarn Berry (2+) version cells for |
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells (global mode)
Observations not filed
Probe branches
Next
|
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Harness, new this run: the Python patch-API mock now also serves the v5 vendoring service. Re-triage
Cells
Ruled out
Next
|
|
[agent] 2026-10-01: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Cells
Ruled out
Harness notes
Next
|
|
[agent] 2026-10-02: handover from the Yarn classic (1.x) bug-hunt routine (#304) Lead for yarn berry PnP, not verified with berry. In a yarn classic PnP project, standalone |
|
[agent] 2026-10-02: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Handover from yarn-classic (#519)
Cells (Linux)
Ruled out
Unconfirmed lead (not filed)
Next
|
|
[agent] 2026-10-02: Yarn Berry (2+) bug-hunt run Tested: main Re-triage
Filed
Cells (Linux)
Ruled out
Next
|
|
[agent] 2026-10-02: Yarn Berry (2+) bug-hunt run Tested: main Harness note: the v5 vendoring-service mock needs a Re-triage
Filed
Cells (Linux, all pass unless noted)
Ruled out
Next
|
|
[agent] Janitor: ledger drift. The coverage matrix still lists these issues as
This is a heads-up only. The janitor never edits ledgers. Generated by Claude Code |
|
[agent] Janitor: ledger drift. This ledger still lists these issues as failing, but they are now closed:
Please re-check them and update the matrix on your next run. Generated by Claude Code |
|
[agent] 2026-10-02: Yarn Berry (2+) bug-hunt run Tested: main Harness note: the Re-triage
Cells (Linux, all pass unless noted)
Filed
Ruled out
Next
|
|
[agent] 2026-10-03: Yarn Berry (2+) bug-hunt run Tested: main Harness: this run rebuilt the hosted mock as a single Python server driven by a JSON config. It serves batch (filtered by Re-triage
Cells (Linux)
Filed / commented
Ruled out
Next
|
|
[agent] 2026-10-03: Yarn Berry (2+) bug-hunt run Tested: main Probes: none. Deleting the stale Harness: I rebuilt the Python mock. It serves batch, by-package, Re-triage
Cells (Linux, node-modules linker unless noted)Each hosted cell runs scan, then a fresh-checkout
Filed / commented / closedNone. Ruled out
Next
|
|
[agent] 2026-10-03: Yarn Berry (2+) bug-hunt run Tested: main Probes: none. Harness: I rebuilt it from scratch.
Re-triage
Cells (Linux, node-modules linker, yarn 4.18.1 unless noted)
Filed / commented
Ruled out
Next
|
|
[agent] 2026-10-05: handover from the Yarn classic (1.x) bug-hunt routine I filed #831 (#831) for yarn classic. Vendored mode writes
With The tarball backends look like they share this, but I haven't tested yarn-berry. Please check it with a real yarn-berry install (repro shape in #831). If it reproduces, comment on #831 with your matrix rather than filing a duplicate, unless the fix clearly differs. |
|
[agent] 2026-10-06: Yarn Berry (2+) bug-hunt run Tested: main Probes: none. Deleting a stale probe branch was denied by the session permission policy this run, so no new probe branches were pushed (they must be deleted before the run ends). Harness (run 24, rebuilt): Re-triageMain hasn't moved, so nothing new to re-check on main. PR #918 gained only test/CI commits plus 688d77c (npmScopes packages stay on the default lookup), so run 23's verdict on #908 stands. PR #924 (yarn classic #921) touches classic code only. Cells
Filed / commented / closed
Ruled out
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Yarn Berry (2+) bug-hunt routine (label pm:yarn-berry).
Last updated: 2026-10-06 (run 24), main
9c43dfc(unchanged since run 21; CLI still reports 4.0.0), latest release 4.0.0 (previous 3.3.0). Run 23 also tested draft PR #918 head21413f1. Since #465 the hosted berry pin is rootpackage.jsonresolutions(name@npm:<range>→ URL) plus a lock entry re-keyedname@<url>.Harness: yarn bundles come from npm
@yarnpkg/cli-dist@<v>(node package/bin/yarn.js), because corepack's fetch can't use the sandbox proxy. Yarn 4 needsYARN_HTTPS_CA_FILE_PATH; yarn 2/3 needYARN_CA_FILE_PATH. The npm registry has 2.4.2 as the last 2.x in cli-dist. Agent and vendored cells hand-stage.socket/manifest.jsonplus blobs (a marker prepended toindex.js). Hosted cells use a local Python mock (fresh-checkout copies must keep.socket/for vendored cells) of the patch API (batch, by-package,patches/packagewith ayarn-berry-zipyarnBerry10c0artifact,view, and the tarball route). The 10c0 checksum is bootstrapped with a real yarnresolutions: file:install. Every hosted and vendored cell ends in a fresh-checkoutyarn install --immutable. v5: hosted rollback/remove need the mock's/upstream/npm/<uuid>.jsonroute,SOCKET_NPM_REGISTRYpointed at a local registry passthrough (the rustls binary can't use the sandbox proxy CA), and--patch-server-url <mock>so the pins count as hosted. Global (-g) cells use real npm global installs (NPM_CONFIG_PREFIX) and a Python mock of the authenticated API (--api-url <mock> --api-token x --org org; blob route/v0/orgs/org/patches/blob/<sha256>). v5 vendored mode downloads from the vendoring service: the same mock's/patches/packagewith a grantedtarballartifact (real sha512) is enough, and an optional per-patchstatusoverride (for examplepending_build) is supported. Acorepackshim (corepack yarn@X→node <cli-dist X>/bin/yarn.js, setting the CA env itself because the harness scrubsYARN_*) runs the repo's berry e2e suites in the sandbox (SOCKET_PATCH_YARN_E2E_REQUIRED=1,SOCKET_PATCH_YARN_BERRY_VERSION=<v>).setupwas removed in v5. On GH runners, fixture installs needYARN_ENABLE_IMMUTABLE_INSTALLS=false(CI turns immutable on). Run 8: the vendoring-service mock must also return ayarn-berry-zipartifact withintegrity.yarnBerry10c0, or vendor failsapply_failed. Hosted fresh installs from an http mock needYARN_UNSAFE_HTTP_WHITELIST=127.0.0.1. Run 9: the corepack shim must setYARN_HTTPS_CA_FILE_PATHonly for 4.x (yarn 4 rejects an envcaFilePath), and the batch mock must filter bycomponents[].purl. Run 10: one Python mock driven by a JSON config (per-patchhiddenandpublishedAtfor A→B upgrades) also serves/upstream/npm/<uuid>.jsonand a/registry/npmjs passthrough forSOCKET_NPM_REGISTRY. Never runpkill -f mock.pyfrom the shell that runs it. Run 12: the harness was rebuilt asmkpatch.py(patched tgz, bootstrap checksum, original registry checksum; never patchpackage.json) plus one mock that also logsAuthorization. Standalonevexagainst the mock needs--patch-server-url <mock>and the API flags. Run 14: harness rebuilt (y,mkpatch.py,mock.py,addorig.py,run.sh,survey.py); the mock must unquote by-package purls repeatedly (scoped purls arrive as%2540).survey.pydiffsnpm:vs tarball-URL lock entry bodies to find pin-render mismatches. Run 16: harness rebuilt (y,mkpatch.sh,mock.py,lib.sh); the/registry/passthrough must quote withsafe='@/', and a checksum bootstrapped on yarn 4.0.x is bare hex, so prefix it with10c0/. Run 17: v5vendor --offlineno longer builds locally, so vendored cells need the vendoring-service mock (POST /v0/orgs/org/patches/package, tarball + yarn-berry-zip) even with a hand-staged manifest. Run 13: also run every fresh install withYARN_ENABLE_HARDENED_MODE=1(it implies--refresh-lockfile, which re-resolves tarball pins from the tarball manifest). Run 18: harness rebuilt (y,mkpatch.sh,stage.py,mock.py,hmock.py,reg.py,lib.sh);reg.pyis an npmjs passthrough with non-conventional tarball URLs (forces::__archiveUrl=lock entries) that also serves/<name>/<version>forSOCKET_NPM_REGISTRY; cold-cache checks need a freshYARN_GLOBAL_FOLDER. Run 19:reg.pymust 404 the conventional/-/tarball path (as a real non-conventional mirror does), or yarn's error is a misleading "socket hang up". Run 20: harness rebuilt (y,mkpatch.sh→p/cfg.json, onemock.pywith viewblobContent+/upstream/npm/<uuid>.json,reg.py,lib.sh); a barescandefaults to hosted, so pass--mode agent; vendored takeovers of hosted pins need--patch-server-url; the release 4.0.0 binary ispackage/socket-patch. Run 21: hosted rollback/remove needSOCKET_NPM_REGISTRYpointed at thereg.pypassthrough, or they fail "error sending request" (sandbox artifact). Run 22: harness rebuilt (y,mkpatch.sh,mock.py,reg.py, plusreg2.py, a non-conventional mirror on :8792, andreg3.py, an npmjs stand-in on :8793 whosedist.tarballis conventional under its own base). When the restoreddist.tarballhost matters, setSOCKET_NPM_REGISTRYtoreg3.py, never to the project's own mirror (that hid #908). Run 23: harness rebuilt (y,reg.py <port> conv|nonconv [prefix],mock.py+cfg.json,mkpatch.sh,run.sh <bin> <scenario> …);rollbacktakes no--mode. Run 24: harness rebuilt (ywithYV=<v>,mock.py <scratch> <port> <checksum>,run.sh <yarn> tgz|dir|url hosted|vendoredfor the #939 matrix). Run 11: the view route can carryblobContent/beforeBlobContent, so agent-modescanworks against the mock without hand-staging; stop the mock through a pidfile.Coverage matrix
Cells are "pass", "fail #N", "refused (by design)" or "untested". Linker is node-modules unless noted.
redirect_yarn_berry_cache_unsupported.store, real dirs), apply/vex/rollback byte-exactvendor_yarn_berry_cache_unsupported.storetransitive dep pass (#495 fixed); repo e2e suites pass (90/90);removeblob GC fail #559nmMode: hardlinks-globalpass after #486. Run 8 on 61cfb9b:nmMode: hardlinks-globalpass (only this project's link broken; rollback byte-exact),nmHoistingLimits: workspacespass (every copy). fail #559 (removesweeps the other patches' before blobs; also releases 4.0.0, 3.3.0). pass on f6b7fb9 (node-modules and pnpm linkers, rollback byte-exact). On 61cfb9b: pass for direct deps (pnpm linker, root and scoped) and hoisted transitive deps; fail #495 (pnpm-linker transitive dep only in.store/<slug>/package); repo e2e suites pass--revertbyte-exact), merged 3-descriptor entry (--revertbyte-exact),catalog:(default and named), root locator encoding (nameless root,()!~'*, space, unicode,+&=#), concurrent vendor (lock),repairof a deleted tgz. Two versions →vendor_override_conflict(correct).removeblob GC: fail #559. pass on 61cfb9b: pnpm linker (in-place + fresh--check-cache,--revertbyte-exact); PnP lock-only checkout vendors and loads patched bytes, but re-run after install fails #539 (also 4.0.2, 4.18.1); zero-install committed cache → YN0056 (docs gap). package.json tab / 4-space / BOM / CRLF+tab / no trailing newline / existing or emptyresolutions(fresh immutable +--revertbyte-exact); mixed-EOL yarn.lock refused loudly (vendor_yarn_berry_mixed_line_endings). pass on f6b7fb9: root, scoped root name, scoped target,**/glob resolution, workspaces, pnpm linker, re-run idempotent,--revert, in-place immutable install. pass on v5: root, workspaces +enableImmutableInstalls: true(--revertandremovebyte-exact), CRLF lock + package.json. Refused (by design): resolve/typescript (patch:builtin), yarn 3. fail #370 (commented compressionLevel). fail #369 (hosted→vendored viascan/get --mode vendored;vendoritself is fixed on v5). fail #468 (vendored→hosted with noyarnBerry10c0)packageExtensions-added dep, root peer + dev,=1.3.0/v1.3.0,portal:transitive,dependenciesMeta, workspace named like the target (each with fresh immutable and byte-exact rollback; vendored forpackageExtensions/portal:too); tarball-URL descriptor refused (correct);compressionLevel: mixedrefused in both modes. run 10 on 045d7ec:catalog:(default, named, workspace) fail #632 (regression from #465; release 4.0.0 passes); vendored→hosted takeover of a catalog dep also hits #632. Pass: A→B upgrade (re-pin, fresh immutable B, rollback byte-exact), pin survivesyarn add/dedupe/up, descriptor change → re-scan re-pins (vex attests nothing meanwhile),--cwdnested separate project (outer untouched). run 9 on 203e092 (resolutions pin, #465): pass for basic, workspaces merged entry, transitive, 7 range spellings (latest,>=1.3.0 <2,||,1.x,*,npm:forms), scoped, two versions, hardened mode × 3 linkers, package.json tab/4-space/CRLF/BOM/no-EOL/other resolutions (rollback byte-exact), CRLF lock +enableImmutableInstalls, scoped rollback/remove with two pins, hosted↔vendored takeovers, mixed vendored+hosted unwind, legacy__archiveUrlpin migration from release 4.0.0,compressionLevel: "0"and0 # c(#370 fixed), lock-only vex (orphan refused). #368 fixed (refusesresolve, nothing written). Interrupted (SIGKILL) vendor: recoverable. Earlier: pass: left-pad, pnpm linker + vex, rollback byte-exact; run 8:catalog:dep (fresh immutable patched); 61cfb9b: rollback and remove byte-exact fornpm:^1.3.0, dev-only and optional-only descriptors; v5 main:npm:1.3.0/npm:^1.3.0descriptors, dev-only and optional-only deps, mixed-case nameJSONStream(case-kept purl, also on 4.18.1), mixed-EOL lock refused loudly, scoped, CRLF, workspaces merged-range, re-scan idempotent, manifest-less rollback/remove/list byte-exact, PnP lock-only checkout, upgrade path (uuid A→B re-pin, then rollback byte-exact), hardened mode accepts__archiveUrlpins, vendored→hosted takeover (checksum present;pending_buildstays vendored). #368, #404, #369 and #370 are fixed on 203e092. Refused (by design): PnP (yarn_pnp_unsupported), direct + alias merged entry (redirect_yarn_berry_ambiguous_entry). PnP stale.pnp.cjs+ hosted pin → standalonevexattests unpatched copy: fail #519 (yarn-classic issue; berry evidence commented, also 4.0.2 and 4.18.1)patch:-descriptor package pass. Run 11: workspaces withnmMode: hardlinks-local+nmHoistingLimits: workspacespass (both copies patched, rollback restores both). Run 9 on 203e092: pnpm linker.storepass (#495 fixed); repo e2e suites pass (90/90); fail #559catalog:pass (bare-name pin). Run 8: namedcatalog:legacypass. pass on f6b7fb9 (CRLF-respelled lock + package.json); v5: fail #468; PnP lock-only: fail #539 (re-run)packageExtensions, peer + dev,=1.3.0pass. Run 10 on 045d7ec:catalog:fail #632; A→B upgrade,yarn add/dedupe/up, nested--cwdpass. Run 9: resolutions pin passes hardened mode × 3 linkers. Earlier: pass (left-pad, scoped, lockversion: 10); #368, #370, #404 and #468 fixed on 203e092"left-pad": "1.3.0", mixed-case JSONStream, three linked packages (also 4.0.2) with per-package rollback, default global cache +--check-cache,workspaces focus --production, prereleasems@3.0.0-canary.1,--checkon a tampered tgz.bin:+conditions:(ios-deploy) fail #697/#718 (passes on PR #719).vendor --checkwiring drift (resolutionsdropped, lock restored) exit 0: #725 class (commented; PR #730 fixes it). run 16: parent-scoped userresolutions(pkg-a/left-pad,pkg-a/left-pad@^1.3.0,<root>/left-pad) fail #783 (vendored adds its own pin; every fresh--immutablefails YN0028; 4.0.2, 4.12.0, 4.18.1; also release 4.0.0). Exact-name user keys refused (correct). A→B re-vendor across a 4.0.2 → 4.18.1 upgrade pass (revert is #759). Workspaces globs*/**, self-aliasnpm:left-pad@…descriptors (revert byte-exact), defaultcompressionLevelspellings: pass. run 15: yarn upgrade 4.0.2 → 4.12.0/4.18.1 after vendoring, thenrollback/vendor --revert: fail #759 (bare-hex checksum restored; also release 4.0.0). Without a revert: pass.checksumBehaviorignore/update/reset: pass. run 14: native-addon packages (implicitnode-gyp: "npm:latest": nan, bufferutil) fail #737 on every fresh--immutable(4.0.2, 4.12.0, 4.18.1; also PR #719 head). Workspaces × node-modules/pnpm and packages with ownpeerDependencies: pass, plain and hardened. run 13: package whose tarballbin:differs from the registry metadata (uuid, acorn) fail #718: every fresh--immutablefails YN0028 (4.0.2, 4.12.0, 4.18.1). run 12: platform-conditional entries (conditions:) fail #697 (checksum afterconditions:; every conditional entry; also release 4.0.0).yarn removethen rollback: fail (#665, Berry evidence commented). Symlinkedyarn.lock/package.jsonreplaced: fail (#627, commented). Pass:yarn add/up/dedupeafter vendoring, then--revertkeeps the user's addresolutionsrefused correctly (redirect_yarn_berry_resolutions_conflict). Self-aliasnpm:left-pad@…descriptors: pin, fresh and rollback byte-exact. PR #763 head verified for #632 (5 catalog shapes + takeover, rollback byte-exact). run 14: native-addon packages (nan, bufferutil): fail #737 under hardened mode (4.0.2, 4.12.0, 4.18.1; PR #719 head too); regression from #465 (release 4.0.0 passes). Workspaces (merged entry + scoped) × node-modules/pnpm, ownpeerDependencies(fdir, use-sync-external-store): pass, hardened. nan rollback byte-exact. run 13: tarballbin:≠ registrybin:(uuid, acorn): fail #718 under hardened mode /--refresh-lockfile(4.0.2, 4.12.0, 4.18.1); regression from #465 (release 4.0.0 passes); plain--immutablepasses. run 12: conditional entry with deps and no checksum (@img/sharp-*) fail #697; esbuild (no deps) andsupportedArchitecturespass. Pass: two versions both patched (scoped rollback, byte-exact),debug(deps + peerDependenciesMeta),npmAlwaysAuth+ token (no auth to patch host, hardened), userpatch:descriptor refused, symlinked lock/package.json refused--revertbyte-exact); member-levelresolutionsand object-formworkspacespassrollback/removefail #817 (drops::__archiveUrl=, cold-cache install YN0001).gitignorecovers the vendored tgz:*.tgz,vendor/,.socket/)--immutableYN0001, warm cache too;--checkexits 0 under.socket/)vendor --revert)npm:original instate.json)patch:typescript/fsevents beside the target)pnpmStoreFolderrelocated).cache/.store:package_not_installedexit 0;store: refused as first-party source, exit 1; also release 4.0.0). Direct deps and a workspace member's direct dep pass (rollback restores). Defaultnode_modules/.storecontrol passes4646693(run 20 re-verification)yarn removethen rollback)@esbuild/linux-x64transitive), #817 takeover variant: fixed; pre-#719 pins heal on re-run; vendored→hosted takeover of abin:package pass. #737 and #759 still fail9c43dfc(run 21)pnpmStoreFolder(YARN_PNPM_STORE_FOLDER,~/.yarnrc.yml): direct deps refused as first-party, exit 1 (commented on #859). Env-onlyYARN_NODE_LINKER=pnpmwith the default store: pass.socketshared by two projects: fail #887 (unwind in one deletes the other's tgz +state.json; 4.0.2, 4.18.1, node-modules + pnpm). Linked.socket/vendor[/npm]refused (pass). Symlinkedyarn.lock/package.jsonrefused (#627 fixed).vendor --checkdrift (#725) fixed. Scoped stringbin(@babel/parser): passget <uuid>, andscanwhen the member owns a copy, exit 0 withredirected: 0. #632 fixed on main (4 catalog selectors, hardened fresh, rollback byte-exact). Scoped stringbin: pass9c43dfc(run 22).socket: fail (#887, agent evidence commented). Project reached through a symlinked path: pass--cwd): pass. Hosted→vendored takeover thenvendor --reverton a non-conventional mirror: fail #908npmRegistryServermirror withSOCKET_NPM_REGISTRYunset: rollback/remove fail #908 (bare locator, cold--immutableYN0035; #817 fix incomplete; byte-exact only whenSOCKET_NPM_REGISTRYis the mirror). Symlinked project path: pass9c43dfcand PR #91821413f1(run 23)npmRegistryServerfails on main (#908) and passes on PR #918;npmScopes.<scope>.npmRegistryServer(scoped target), envYARN_NPM_REGISTRY_SERVERand~/.yarnrc.ymlfail on both (commented on #908). Conventional mirror with a path base: pass on both9c43dfc(run 24)lp2other-namefile:copy: pass (both copies patched, rollback restores both)"lp2": file:tgz / dir / registry URL): fail #939 (no warning; lock-onlyvexand post-installvexattestnot_affected). Same-namefile:copy refused (vendor_override_conflict, pass)lp2shapes: fail #939 (no warning; lock-onlyvexattests; post-installvexdeclines). Same-namefile:copy refused (unsupported_protocol+shared_descriptor, pass)10c0/, fresh hardened--immutablepass.checksumBehaviorignore/update/reset: pass.Global (
-g) cells. Berry has no global dir, so these are npm-prefix globals scanned from inside or outside a Berry project:globalscript ran); otherwise pass, no project leak (node-modules, pnpm, PnP)not_appliedafter reinstall, EACCES loud,--global-prefixwith space and unicode).cmdshim not run)Backlog
send-pack: unexpected disconnect/remote end hung up; runs 14, 19 and 24: denied by the session permission policy), so no new probes. The stale branchesbughunt/yarn-berry/20260930-builtin-patch-takeoverandbughunt/yarn-berry/20261001-global-scriptneed deleting by hand. After that, probe the resolutions pin on macOS and Windows (CRLF), plus Vendored yarn berry PnP refusal keys only on .pnp.cjs: a lock-only PnP checkout vendors successfully, then every re-run in an installed checkout fails exit 1 with vendor_yarn_berry_unsupported #539, Agent mode misses transitive packages in Yarn's pnpm-linker store whenpnpmStoreFoldermoves it out ofnode_modules: skipped aspackage_not_installed, or refused as "first-party source" #859, Vendored mode still writes and deletes through a symlinked.socketdir: the #664 guard checks.socket/vendorand below only, so rollback in one yarn berry project wipes another project's vendored tarball and ledger #887 (a.socketjunction on Windows).file:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939 (all 12 cells plus agent), Hosted yarn berry rollback/remove still drops a custom registry's::__archiveUrl=binding (#817 fix incomplete): the restore looks updist.tarballon npmjs, not the project'snpmRegistryServer, so cold installs 404 #908 (draft PR Fix npm-family restore ignoring project registry (#908, #521) #918 fixes only the project-rc top-level key; re-check all four registry sources (project rc,npmScopes, env, home rc) plus a parent-dir rc and the takeover +vendor --revertpath), Vendored mode still writes and deletes through a symlinked.socketdir: the #664 guard checks.socket/vendorand below only, so rollback in one yarn berry project wipes another project's vendored tarball and ledger #887 (vendored and agent), Hosted scan/get run from a yarn classic workspace member still reports success while pinning nothing: the #598 governing-root refusal covers pnpm and cargo only #884 (Berry), Agent mode misses transitive packages in Yarn's pnpm-linker store whenpnpmStoreFoldermoves it out ofnode_modules: skipped aspackage_not_installed, or refused as "first-party source" #859 (plus the env/home variant), Vendored yarn classic exits 0 when .gitignore covers the vendored tarball (*.tgz,vendor/,.socket/), so the commit drops it and every fresh checkout's install fails #831 (Berry), Vendored yarn berry misses a parent-scoped userresolutionsentry (pkg-a/left-pad), reports success, and everyyarn install --immutablefails YN0028 #783 (then@scope/parent/name, a scoped target, the hosted→vendored takeover), Vendored yarn berry revert restores the pre-vendor lock entry verbatim, so after upgrading from yarn 4.0.x it writes back a bare-hex checksum and everyyarn install --immutablefails YN0028 #759, Yarn berry vendored and hosted pins of native-addon packages (nan, bufferutil, utf-8-validate, node-addon-api) keep the registry entry's implicitnode-gyp: "npm:latest"dependency, so vendored installs and hardened hosted installs fail YN0028 #737, Vendored yarn berry PnP refusal keys only on .pnp.cjs: a lock-only PnP checkout vendors successfully, then every re-run in an installed checkout fails exit 1 with vendor_yarn_berry_unsupported #539, Hosted yarn berry rewrites a mixed-line-ending package.json that vendored mode refuses #628/Share the yarn berry project gates between hosted and vendored modes #629. Fixed and verified: Hosted yarn berry pin of acatalog:dependency keysresolutionsby the resolvednpm:range, so everyyarn install --immutablefails YN0028 (regression from #465) #632 (run 21 on main),vendor --checksays "committed artifact and wiring verified" (exit 0) afterpipenv lockdrops the vendored reference, so a freshpipenv install --deployinstalls the unpatched wheel while vex says vendor_unwired #725 and Vendored yarn classic replaces a symlinked yarn.lock with a regular file (hosted refuses the same lock), leaving the link's target unpatched; rollback never restores the link #627 (run 21), Yarn berry vendored and hosted pins putchecksum:out of yarn's field order on platform-conditional lock entries (conditions: os=…), so everyyarn install --immutablefails YN0028 #697, Yarn berry vendored and hosted pins copy the registry entry'sbin:paths, but yarn re-reads them from the tarball (./dist/bin/uuid), so vendored installs and hardened hosted installs fail YN0028 for packages like uuid and acorn #718, Hosted yarn berry rollback/remove rebuilds the lock entry as a barename@npm:<version>locator and drops the registry's::__archiveUrl=binding, so projects on registries with non-conventional tarball URLs can't install after a revert #817, Afteryarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665 Berry (run 20). Hosted yarn berry redirect of resolve/typescript (yarn builtin compat patch) reports success, then everyyarn install --immutablefails YN0028 #368, Hosted → vendored takeover on yarn berry reverts the hosted redirect before a per-package vendor refusal, leaving the package unpatched in both modes #369, Yarn berry vendored and hosted modes refusecompressionLevel: 0 # commentin .yarnrc.yml as a non-default compression level #370, Hosted yarn berry redirect makes yarn send the project's npm registry auth token to the patch host #404,scan -ginside a Yarn Berry project runs the project'sglobalpackage.json script and scans whatever directory it prints as a global install #440, Vendored → hosted takeover on yarn berry deletes the vendored patch, then skips the hosted rewrite when the grant has no yarnBerry10c0 checksum, and still exits 0 "fully hosted" #468, Yarn 4 pnpm linker: transitive packages that live only in node_modules/.store are "not installed" in agent mode and stay unpatched #495 andremove <purl>garbage-collects the beforeHash blobs of every other patch still in the manifest, so a later offline rollback of those patches fails missing_blob #559 are closed.::__archiveUrl=binding (#817 fix incomplete): the restore looks updist.tarballon npmjs, not the project'snpmRegistryServer, so cold installs 404 #908 neighbours (run 23 coverednpmScopes, env, home and the path-base mirror): left are a parent-directory.yarnrc.yml, and the inverse case (top-level mirror,npmScopespointing a scope at npmjs) on PR Fix npm-family restore ignoring project registry (#908, #521) #918.3b. Yarn berry hosted and vendored scans miss a
file:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939 neighbours: agit/github:copy under another name, aportal:/link:to an unpatched checkout of the same version, and the pnpm linker.yarn.lock, not in the parent'sworkspaces); object-formworkspaces; yarn 2/3 members.pnpmStoreFoldermoves it out ofnode_modules: skipped aspackage_not_installed, or refused as "first-party source" #859 neighbours:pnpmStoreFolderoutside the project (../shared) shared by two projects.*.tgz,vendor/,.socket/), so the commit drops it and every fresh checkout's install fails #831 follow-ups once fixed: the<uuid>/.gitignore!*re-include under*.tgz, and the hosted→vendored takeover under an ignore rule.-g) on macOS/Windows, and a version-manager prefix (nvm/volta). Full checklist in the 20261001T040000Z entry.pkg:npm/jsonstream@1.3.5) for a mixed-case package, and every mode misses it. File it (cross-PM) only if the real API is shown to lower-case.package/, hosted skips it withnpm_manifest_unavailable(exit 0). File it only if the real service does that.Known non-bugs
.pnp.cjsare refused in every mode withyarn_pnp_unsupported(documented).resolve,typescript,fsevents) is refused fail-closed withvendor_override_conflict. It's loud and closed, so it isn't filed (the hosted counterpart is Hosted yarn berry redirect of resolve/typescript (yarn builtin compat patch) reports success, then everyyarn install --immutablefails YN0028 #368).npm:alias ("left-pad@npm:1.3.0, lp@npm:left-pad@1.3.0") withredirect_yarn_berry_ambiguous_entryand exit 1. It's fail-closed and loud; arguably over-broad, but not filed.yarn install --immutablein the same tree doesn't restore unpatched bytes (yarn's install-state), and the setup hook re-patches after a clean install. Standalonevexin agent mode needssetuporsetup.manual(documented).patches-api.socket.devis unreachable from the sandbox; use the mock.yarn install --immutable(YN0028) on its own, because yarn strips the BOM. Not caused by socket-patch.npm:alias-only entry →redirect_yarn_berry_alias_skipped(documented in docs/ecosystems.md).Superseded in run 21: after Hosted scan/get run from a pnpm workspace member (or withscan <workspace-member-dir>finds 0 packageslockfile-dir=..) ignores the parent pnpm-lock.yaml and reports success while pinning nothing #590/Fix hosted scan from a workspace member pinning nothing or the wrong files (#590, #417) #598, the hosted run from a member is a bug (Hosted scan/get run from a yarn classic workspace member still reports success while pinning nothing: the #598 governing-root refusal covers pnpm and cargo only #884, Berry evidence commented). A hoisted member scan still finds 0 packages, butget <uuid>and member-owned copies report success while pinning nothing..pnp.cjs: scan reports 0 packages with a PnP warning (same in 4.0.0). A PnP lock-only checkout gets hosted pins, and those install correctly under PnP.patch.socket.dev(or--patch-server-url) URLs as hosted pins. Without that flag, a mock host reads as "Manifest not found"..pnp.js) and 3.x is detected and gets the loud PnP warning in every mode, exit 0 (same as 4.x).scan -g --mode agent) after a failed apply (EACCES) exits 0 with "already recorded … runsocket-patch apply". This is the designed re-run message;apply -gitself exits 1.scan -gdoesn't mention-g. It's cross-PM and was handed to npm (Bug hunt ledger: npm #302), so it isn't filed here.enableHardenedMode, auto-on for public fork PRs in GitHub Actions) accepts a hosted::__archiveUrl=lock pin, as does--check-resolutions(4.12.0, registry reachable).enableGlobalCache: falsewith.yarn/cachecommitted): hosted mode is lock-only, so the committed cache keeps the unpatched zip, andyarn install --immutable --immutable-cachefails YN0056 untilyarn installrefreshes the cache. Vendored mode behaves the same way (thefile:entry has no cache zip; no warning). It's a docs gap, not filed.compressionLevelset outside the project.yarnrc.yml(env, home or parent rc) can't cause a wrong checksum: yarn bakes the level into the lock'scacheKey, which both modes gate on.yarn patch(patch:descriptor) withvendor_override_conflict, plus an alias-only dependency (root or workspace member) withvendor_lock_entry_not_found, a merged direct + alias entry, and a user-authoredresolutionskey for the target. All are loud and closed with nothing written, so none are filed.yarn.lockis refused by vendored (vendor_yarn_berry_mixed_line_endings) and hosted (redirect_yarn_berry_mixed_line_endings). That's correct: yarn itself fails YN0028 on such a lock.rollbackdrops the patch's manifest entry, so a laterapplyis a no-op (designed).package.json. Vendored snapshots the post-install bytes and reverts to them byte-exactly.left-pad@1.2.0alongside the patched 1.3.0) withvendor_override_conflict, because the name-keyedresolutionswould move both. That's correct and loud.repairrefuses (vendor_artifact_redownload_failed, nothing written) when the service now serves different bytes for a uuid whose integrity is pinned in the ledger. That's correct.vendor --cwd <workspace member>fails loudly withvendor_lockfile_missing(the lock lives at the root).virtual:entries for peer-dependent packages, so the hosted/vendored rewrite has no virtual locator to keep in sync.package.jsonto 2-space and drops a user-authored empty"resolutions": {}. Yarn's own next install writes exactly the same bytes, so it isn't filed.redirect_yarn_berry_shared_descriptor,redirect_yarn_berry_ambiguous_entry,cache_unsupported) exit 0 withredirected: 0and nothing written. With--vexand nothing to attest, the run exits 1.resolutionsentry targeting the patched package (bare or scoped selector) withredirect_yarn_berry_resolutions_conflict. It's documented and loud.vendor --revertremoves the orphan, andvexrefuses.rollbackandrepairfail withmanifest_not_foundin that state.yarn add left-pad@1.3.0) leaves a staleresolutionsselector.rollbackin that state refuses loudly and tells you to re-runscan --mode hosted, which re-pins correctly. It's fail-closed and gives a remedy, so it isn't filed.left-pad@https://…tgz) is refused withredirect_yarn_berry_unsupported_protocol, exit 0, nothing written. That's correct.compressionLevel: mixed(cacheKey10) is refused by hosted (redirect_yarn_berry_cache_unsupported, exit 0) and vendored (vendor_yarn_berry_cache_unsupported, exit 1). Both are documented.patch:descriptor independenciesis refused (redirect_yarn_berry_unsupported_protocol+redirect_yarn_berry_shared_descriptor), nothing written. That's correct. The hint suggests--mode vendored, which also refuses it;--mode agentworks.checksum:for a platform-conditional entry reached only throughoptionalDependencies, and strips one on its next mutable install. A hosted pin's checksum on such an entry therefore doesn't surviveyarn add;vexstill attests from the installed tree. That's yarn's policy. The misplaced-line part is Yarn berry vendored and hosted pins putchecksum:out of yarn's field order on platform-conditional lock entries (conditions: os=…), so everyyarn install --immutablefails YN0028 #697.bin:differs from the tarball's passes a plainyarn install --immutableand a later mutable install (yarn trusts the locked entry). Only hardened mode or--refresh-lockfilefails, and that is Yarn berry vendored and hosted pins copy the registry entry'sbin:paths, but yarn re-reads them from the tarball (./dist/bin/uuid), so vendored installs and hardened hosted installs fail YN0028 for packages like uuid and acorn #718.%2540purls (run 14).lockfileFilenamein.yarnrc.ymlis rejected by yarn 4 ("Unrecognized or legacy configuration settings"). It only exists in yarn 2/3, which hosted/vendored refuse anyway.checksumBehavior(ignore/update/reset) doesn't change what yarn writes to the lock. Hosted and vendored pins pass under all three (run 15).**/nameresolution is dropped frompackage.jsonby yarn 4's own install, so a hosted pin that seems to replace it isn't socket-patch's doing (run 16).compressionLevel:with its value on the next line (a multi-line YAML scalar) is refused by both modes. It's loud and unrealistic, so it isn't filed (run 16).vexon a tree whosenode_modulesstill holds unpatched bytes (wiring pulled without a reinstall) attestsnot_affectedfrom the committed artifact and warnsvendored_tree_out_of_sync. That's by design (run 17).vendor --checkreporting wiring verified after the Berry wiring drifts isvendor --checksays "committed artifact and wiring verified" (exit 0) afterpipenv lockdrops the vendored reference, so a freshpipenv install --deployinstalls the unpatched wheel while vex says vendor_unwired #725 (cross-PM root cause, Berry evidence commented in run 17). Don't re-file it.yarn install --mode=update-lockfile(Renovate) still writeschecksum:lines on yarn 4.0.2 and 4.18.1, so there are no checksum-less target entries to test (run 18).npm:<v>locator where yarn wrote::__archiveUrl=passes hardened mode and--refresh-lockfile. The breakage is only the fetch (Hosted yarn berry rollback/remove rebuilds the lock entry as a barename@npm:<version>locator and drops the registry's::__archiveUrl=binding, so projects on registries with non-conventional tarball URLs can't install after a revert #817).scan --mode agent --jsonreporting an apply failure asaction: "added",failed: 0with no error is scan/get --json drop the agent-mode apply failure: exit 1 with failed: 0, the patch shown as "added", and no error anywhere (e.g. a read-only global ~/.m2) #424 (cross-PM, open). Don't re-file it (run 20).pnpmStoreFolder("Unrecognized or legacy configuration settings"), so Agent mode misses transitive packages in Yarn's pnpm-linker store whenpnpmStoreFoldermoves it out ofnode_modules: skipped aspackage_not_installed, or refused as "first-party source" #859 cells start at 4.1+ (run 20).yarn.lock/package.json(Fix vendored mode replacing symlinked lockfiles (#627) #802) leaves.socket/vendor/npm/<uuid>/behind despite saying "nothing was written". It's benign (vexrefuses,vendor --checksees nothing, the re-run is clean), so it isn't filed (run 21).SOCKET_NPM_REGISTRY(run 21).--cwdthrough a link, as macOS/tmpis) works in agent, vendored and hosted modes (run 22).npmRegistryServer: http://host/api/npm/npm-remote) restores bare and byte-exact after a hosted rollback (run 23).name@npm:<version>locator and drops the registry's::__archiveUrl=binding, so projects on registries with non-conventional tarball URLs can't install after a revert #817 runs 18–20 "fixed" verdicts held only withSOCKET_NPM_REGISTRYpointed at the project's mirror. The realistic config is Hosted yarn berry rollback/remove still drops a custom registry's::__archiveUrl=binding (#817 fix incomplete): the restore looks updist.tarballon npmjs, not the project'snpmRegistryServer, so cold installs 404 #908, so don't re-verify Hosted yarn berry rollback/remove rebuilds the lock entry as a barename@npm:<version>locator and drops the registry's::__archiveUrl=binding, so projects on registries with non-conventional tarball URLs can't install after a revert #817 that way.file:directory/tarball copy of the patched package ("left-pad": "file:…") is refused by hosted (redirect_yarn_berry_unsupported_protocol+redirect_yarn_berry_shared_descriptor) and vendored (vendor_override_conflict), nothing written. That's correct; the other-name copy is Yarn berry hosted and vendored scans miss afile:/URL copy of the patched package locked under another dependency name, so lockfile VEX (and vendored VEX after install) attests not_affected while that copy installs unpatched #939 (run 24).All reactions