Fix hosted scan from a workspace member pinning nothing or the wrong files (#590, #417) - #598
Conversation
Assisted-by: Claude Code:claude-opus-5-5
Hosted scan and get read locks only in --cwd. Run from a pnpm workspace member (or a project whose lockfile-dir puts pnpm-lock.yaml elsewhere), they pinned nothing and still reported success, so pnpm kept installing the unpatched package (#590). Run from a cargo workspace member, they rewrote the member as a lockless project and broke every build of the workspace (#417). Both layouts are now refused before any takeover or write, exit 1, naming the directory to run from: redirect_pnpm_lockfile_elsewhere for pnpm, and the vendored cargo_manifest_not_workspace_root check, now shared, for cargo. Assisted-by: Claude Code:claude-opus-5-5
Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
|
[agent] CI note:
Generated by Claude Code |
A workspace root can move pnpm-lock.yaml with lockfileDir, and the key may be written quoted in pnpm-workspace.yaml. Hosted runs from a member of such a workspace, or of one with a quoted key, still reported success while pinning nothing. Both are now refused like any other member whose lock lives elsewhere. Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
|
[burn-down agent] Labeled Ready for review at
Generated by Claude Code |
|
Review updated for The original guard missed root The correction reads the nearest workspace's settings with native precedence (YAML, then member Validation passed: eight governing-root tests, all 16 pnpm CLI tests, and the Cargo member refusal test. Three new CLI regressions fail on the original head and pass with the fix. Native pnpm 10.34.5 offline installs verify inherited settings, path resolution, and precedence. Independent review of the final correction found no remaining issue; it merges cleanly with current main. No remaining code finding from this review. The Ready label has been restored after all checks completed on the corrected commit. |
|
bugbot run |
Release notes are written when a release is cut, from the merged PR log and the code, so PRs no longer edit CHANGELOG.md. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…stor-workspace-lock # Conflicts: # crates/socket-patch-cli/tests/in_process_redirect.rs
|
BugBot review Generated by Claude Code |
#605 taught the name-keyed npm resolver to probe bundled store trees, so it now finds aliased copies (node_modules/lp) and a nested host's store peers itself. Two vex_consumed tests from #738 assumed that set never held aliases, so main's CI went red after both merged. The tests now feed the alias-free set explicitly to keep covering alias expansion, and also check the resolver's own set reaches the same copies with no duplicates. No production code changes. Assisted-by: Claude Code:claude-opus-5-5
|
[agent] Merged Generated by Claude Code |
|
BugBot review Generated by Claude Code |
A pnpm-workspace.yaml saved with a UTF-8 BOM, or one that sets lockfileDir twice, could hide a relocated lock from the member check, so a hosted run from a member still reported success while pinning nothing. The reader now skips the BOM and uses the last assignment. Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 7f0ed18. Configure here.
|
Burn-down agent: Ready for review at
Generated by Claude Code |
LLM Description written by Claude Code:claude-opus-5-5
Final-head CI is complete: 479 successful checks, 6 skipped; no failures or pending checks. Bugbot passed, there are no unresolved review threads, and the PR is mergeable.
Fixes #590 and #417. Hosted
scanandgetrun from a pnpm or Cargo workspace member can otherwise report success while reading only the member directory: pnpm pins nothing, and Cargo may rewrite member manifests as a lockless project, breaking workspace builds.The hosted path now refuses these layouts before takeover or writes, including dry runs. Cargo shares the existing vendored workspace-root check and reports
cargo_manifest_not_workspace_root. A pnpm candidate with no local npm-family lock reportsredirect_pnpm_lockfile_elsewherewhen its governing lock exists elsewhere, naming that lock and returning exit 1.pnpm resolution follows native configuration controls: the nearest workspace YAML takes precedence over member
.npmrc, which takes precedence over root.npmrc. Configured relativelockfileDir/lockfile-dirpaths resolve from the invocation directory; without an override, the lock is sought at the workspace root. Existing local locks and Rush bypass this ancestor check, and the nearest workspace bounds lookup. The disk check is shared by hosted scan/get; in-memory projects have no ancestor directory to inspect.Validation:
.npmrc, inherited relative YAML directory, and YAML precedence over member.npmrc. Refused runs preserve project and lock bytes.unused_variablesallowance), and the fixed commit merges cleanly with current main.93c3e32b.Other package managers' workspace-member rules remain outside this pnpm/Cargo change.
Note
Medium Risk
Changes hosted-mode entry preconditions for pnpm/Cargo workspaces; refused runs write nothing, but successful runs from members that previously appeared to succeed will now error until run from the governing root.
Overview
Hosted
scanandget --mode hostednow fail closed when--cwdis a workspace member whose governing lock or Cargo workspace root lives outside that directory, instead of exiting successfully while pinning nothing (pnpm) or rewriting member manifests and breaking builds (Cargo).A new
hosted::governing_rootpre-check runs on disk projects before any takeover or writes (dry runs included). pnpm/npm candidates with no local npm-family lock resolve the governingpnpm-lock.yamlusing native-style config precedence (pnpm-workspace.yamllockfileDir, then member/root.npmrclockfile-dir, default workspace root) and returnredirect_pnpm_lockfile_elsewherewith the directory to run from. Cargo reuses the vendoredworkspace_root_refusalpath with a hosted-specific hint andcargo_manifest_not_workspace_root.CLI_CONTRACT.mddocuments the new top-level error codes. Integration and regression tests cover pnpm workspace variants, inherited lock paths, Cargo member refusal, and smallvex_consumedadjustments for the #605 resolver.Reviewed by Cursor Bugbot for commit 7f0ed18. Configure here.
Generated by Claude Code