Conversation
yarn classic reads .yarnrc and .npmrc from every directory between the project and the drive root. In a project under the user profile that includes the real home, which the sandbox refuses on purpose. yarn rethrows the EPERM, so install failed with EPERM: operation not permitted, open 'C:\Users\<name>\.yarnrc'. The walk-up preload now reports ENOENT for a refused read of .yarnrc, .npmrc or their .yml forms directly inside an ancestor of the working directory or home, and reports such a file as not existing to fs.exists. yarn checks fs.exists before it reads ~/.npmrc, and the sandbox answers true there. Every other refused read keeps its EPERM. Nothing becomes readable.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Defect
On Windows, yarn classic fails inside the sandbox in a project under the user profile when the user has a
~/.yarnrcor~/.npmrc. yarn reads those files from every directory up to the drive root. The sandbox refuses the ones in the real home on purpose, and yarn treats the EPERM as fatal.Measured with yarn 1.22.22 under Node 22.23.3:
EPERM: operation not permitted, open 'C:\Users\<name>\.yarnrc'. Once that was answered, the same error followed for~/.npmrc.Fix
The walk-up preload (
sandbox_walkup_shim.js) now reports ENOENT for a refused read (readFileSync,readFile,promises.readFile) of.yarnrc,.npmrcor their.ymlforms directly inside an ancestor of the working directory or home. It also reports such a file as absent tofs.existsandfs.existsSyncwhen it cannot be opened, because yarn checksfs.existsbefore reading~/.npmrcand the sandbox answers true there. A file that can be opened still exists. Every other refused read keeps its EPERM. Nothing becomes readable, only the error code changes.I kept the rule to these rc names because they are the only files yarn looks for in the home chain. A rule for any file in an ancestor would hide refusals nobody asked to hide. No yarn 1 flag skips only the home rc (
--no-default-rcalso drops the project's own).Tests
TestWalkUpShimHidesRefusedRcFilesOnlyInCoveredAncestorsruns node outside a container with the fs calls refusing, and checks the rewrite and its limits. It fails on the old preload and fails if the ancestor check is removed.TestWalkUpShimHidesRefusedRcFileInContainer(NVX_PROBE=1) does the same inside an AppContainer.go test ./internal/nvx,go veton windows, linux and darwin, and gofmt are clean.