Fix yarn berry project gates drifting between modes (#628, #629) - #657
Mikola Lysenko (mikolalysenko) wants to merge 3 commits into
Conversation
Assisted-by: Claude Code:claude-opus-5-5
A berry project whose root package.json mixes CRLF and LF is refused by vendored mode, but hosted mode rewrites it in the majority ending. These tests cover a fresh hosted scan and the vendored-to-hosted takeover (#628). They fail until the gate is shared. Assisted-by: Claude Code:claude-opus-5-5
Hosted and vendored modes each carried their own copy of the yarn berry project refusals (mixed line endings, cacheKey, .yarnrc.yml compressionLevel), and the copies drifted: hosted mode never checked the root package.json, so it silently rewrote a mixed-line-ending manifest that vendored mode refuses (#628). The gates now live once in formats/yarn/berry_gates.rs. The vendored backend and its takeover preflight, the hosted rewriter, the vendored-to-hosted takeover and the hosted restore all call it and keep their existing codes. Hosted mode now refuses a mixed package.json with redirect_yarn_berry_mixed_line_endings before writing or reverting anything (#629). Assisted-by: Claude Code:claude-opus-5-5
853f810 to
759933a
Compare
|
BugBot review Generated by Claude Code |
|
[agent] I don't think this failure is caused by this PR:
PR #596 (open) targets Poetry matrix flakes caused by PyPI and patch-API transport blips, which could explain a failed hosted re-scan. I haven't confirmed that this is the same failure, so I'm not porting #596's change here; the re-run will show whether it reproduces. A re-run of the failed job is refused with 403 while the workflow is still running. I'll re-run it once when the run completes. If it fails again, I'll treat it as real and root-cause it. Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 759933a. Configure here.
Assisted-by: Claude Code:claude-opus-5-5
|
[agent] Ready for review at head
The Slack announcement is pending because no Slack send tool was available in this run. Generated by Claude Code |
|
Codex review of The shared Berry gates preserve the supported cache/compression checks and warning codes. Mixed root manifests are now refused before hosted rewrites, before vendored takeover reverts, and before upstream restore writes. Uniform LF/CRLF behavior and BOM preservation remain covered. Validation:
Fresh CI is clear: 485 successful checks, 7 skipped; 13 successful workflows and 1 skipped. Bugbot is clear on this exact commit, with no unresolved threads or outstanding actionable feedback. The documented pre-existing hosted behavior for unreadable GitHub's normal human approval requirement remains before merge. |
LLM Description written by Claude Code:claude-opus-5-5
Fixes #628
Fixes #629
Summary
Hosted mode now refuses a Yarn Berry project whose root
package.jsonmixes CRLF and LF line endings, usingredirect_yarn_berry_mixed_line_endingsand writing nothing. This is the same decision vendored mode already took withvendor_yarn_berry_mixed_line_endings. Before this change, hosted mode re-rendered the manifest in its majority ending, which silently rewrote lines the user never touched and left rollback with no original bytes to restore. Both modes now run one shared set of berry project gates, so they can't drift apart again.Root cause
Each mode implemented the berry project-level gates itself (mixed line endings,
cacheKey,.yarnrc.ymlcompressionLevel):SUPPORTED_CACHE_KEY,refuse_*, andyarn_berry_vendor_preflightYARN_BERRY_SUPPORTED_CACHE_KEY,berry_cache_key, andpreflight_yarn_berry_hostedHosted mode also imported
yarnrc_compression_levelfromvendor. The copies had drifted. The hosted gate looked only atyarn.lock, although the hosted rewriter also editspackage.json(to addresolutions).Change
formats/yarn/berry_gates.rs, a pure module with no I/O:SUPPORTED_CACHE_KEYcache_keyextractoryarnrc_compression_level, moved here together with its testscheck(lock, manifest, Yarnrc)and the per-gatecheck_*functions, which return aBerryGate(MixedLineEndings { file },NoMetadata,CacheKey { found },Compression { level },YarnrcUnreadable { error }).BerryGateowns the detail text and the code suffix.refuse_*are now thin wrappers that map aBerryGateto thevendor_yarn_berry_*codes, andNoMetadatatovendor_lockfile_version_unsupported. The codes don't change.preflight_yarn_berry_hosted(lock, manifest, yarnrc)callsberry_gates::checkand maps results to theredirect_yarn_berry_*codes. All three callers now pass the rootpackage.json:scan/hosted.rs, which now refuses before reverting, wet and--dry-runupstream/npm.rs, which already re-rendered that manifestlock_inventory::yarnreadscacheKeythrough the same extractor.YARN_BERRY_SUPPORTED_CACHE_KEY,berry_cache_keyandberry_metadataare deleted, andpatch/redirectno longer imports gate code fromvendor::yarn_berry_lock.CLI_CONTRACT.md(the hosted berry line-endings paragraph and the takeover gates),docs/ecosystems.md, andCHANGELOG.md.Detail text: the two modes' wording is now identical. Vendored mode's wording was kept, and it already names
yarn install. A berry__metadatablock with nocacheKeyline now says(missing)in both modes; vendored mode used to print an empty value.Test evidence
patch::redirect::tests::berry_mixed_root_manifest_is_refused_untouchednothing written: ["package.json", "yarn.lock"])in_process_redirect::scan_redirect_refuses_a_mixed_line_ending_yarn_berry_manifestredirect_yarn_berry_mixed_line_endingswarning)in_process_vendor::berry_takeovers_refuse_before_reverting_the_old_mode, new "mixed package.json" leg (wet and dry)vendored→hosted mixed package.json dry=true: refused with redirect_yarn_berry_mixed_line_endings)vendor::yarn_berry_lock::tests::both_modes_take_the_same_project_gate_decision(table: supported, BOM+CRLF, cacheKey10, no cacheKey,compressionLevel: mixed, mixed lock, mixed manifest; asserts the same suffix and identical detail)formats::yarn::berry_gates::tests::*(4 tests plus the 3 movedyarnrc_compression_leveltests)Local runs:
cargo clippy --workspace --all-features -- -D warnings: okcargo fmt: the new module is rustfmt-clean. Every changed hunk is formatted.mainitself isn'tcargo fmt --checkclean, so I did not reformat files outside this change.cargo test --workspace --all-features --no-fail-fast: 9731 passed, 12 failed. All 12 failures are permission-denial tests:*_state_write_failure_*,*_unremovable*,wire_*failure*,relax_loop_must_not_traverse_symlinked_root,redirect_json_mode_write_failures_*,partial_lockfile_write_failure_*,vlt_heal_invalidation_failure. They depend onchmodtaking effect, and the sandbox runs as root, which ignores it. None of them touch yarn code. After the history cleanup,in_process_vendor(104/104), the coreberry|yarnunit tests (233/233) and thein_process_redirectyarn_berry tests (5/5) were re-run.scripts/yarn-berry-vex-matrix.sh 4.18.0(withCOREPACK_NPM_REGISTRYset):e2e_redirect_yarn_berry_build,e2e_vendor_yarn_berry_build,e2e_yarn4_pnpm_linker_buildande2e_yarn4_workspaces_buildall pass (56 tests) on real yarn 4.18.0. Ine2e_yarn_legacy_cachekey_refusal_buildthe yarn 3 cells pass. Its two yarn 2.4.3 cells couldn't run locally: the sandbox proxy blocks repo.yarnpkg.com, and yarn 2 isn't on the npm registry. CI covers them.CI on 759933a: green. 485 of 491 check runs pass and 6 are skipped. Bugbot found no issues, and there are no review threads. The Poetry backtest
native (ubuntu-latest, 2.0.1)failedrescanIdempotentonce; this PR touches no Poetry code, and its single re-run passed.No wrapper changes are needed:
npm/,pypi/andgem/only dispatch to the binary.Follow-up, not changed here: in hosted mode, an unreadable
.yarnrc.ymlis still treated as absent. The rewriter receives files that were already read, so it can't tell "unreadable" apart from "missing". Vendored mode refuses it withYarnrcUnreadable. The gate now supportsYarnrc::Unreadable, so the hosted takeover could adopt it in a later change.🤖 Generated with Claude Code
Generated by Claude Code