Skip to content

Let contained yarn on Windows skip the rc files in the real home - #156

Open
fstubner wants to merge 1 commit into
mainfrom
fix/yarn-home-rc-in-windows-sandbox
Open

fstubner wants to merge 1 commit into
mainfrom
fix/yarn-home-rc-in-windows-sandbox

Conversation

@fstubner

@fstubner fstubner commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Defect

On Windows, yarn classic fails inside the sandbox in a project under the user profile when the user has a ~/.yarnrc or ~/.npmrc. yarn reads those files from every directory up to the drive root. The sandbox refuses the ones in the real home on purpose, and yarn treats the EPERM as fatal.

Measured with yarn 1.22.22 under Node 22.23.3: EPERM: operation not permitted, open 'C:\Users\<name>\.yarnrc'. Once that was answered, the same error followed for ~/.npmrc.

Fix

The walk-up preload (sandbox_walkup_shim.js) now reports ENOENT for a refused read (readFileSync, readFile, promises.readFile) of .yarnrc, .npmrc or their .yml forms directly inside an ancestor of the working directory or home. It also reports such a file as absent to fs.exists and fs.existsSync when it cannot be opened, because yarn checks fs.exists before reading ~/.npmrc and the sandbox answers true there. A file that can be opened still exists. Every other refused read keeps its EPERM. Nothing becomes readable, only the error code changes.

I kept the rule to these rc names because they are the only files yarn looks for in the home chain. A rule for any file in an ancestor would hide refusals nobody asked to hide. No yarn 1 flag skips only the home rc (--no-default-rc also drops the project's own).

Tests

  • TestWalkUpShimHidesRefusedRcFilesOnlyInCoveredAncestors runs node outside a container with the fs calls refusing, and checks the rewrite and its limits. It fails on the old preload and fails if the ancestor check is removed.
  • TestWalkUpShimHidesRefusedRcFileInContainer (NVX_PROBE=1) does the same inside an AppContainer.
  • go test ./internal/nvx, go vet on windows, linux and darwin, and gofmt are clean.

yarn classic reads .yarnrc and .npmrc from every directory between the
project and the drive root. In a project under the user profile that
includes the real home, which the sandbox refuses on purpose. yarn
rethrows the EPERM, so install failed with
EPERM: operation not permitted, open 'C:\Users\<name>\.yarnrc'.

The walk-up preload now reports ENOENT for a refused read of .yarnrc,
.npmrc or their .yml forms directly inside an ancestor of the working
directory or home, and reports such a file as not existing to
fs.exists. yarn checks fs.exists before it reads ~/.npmrc, and the
sandbox answers true there. Every other refused read keeps its EPERM.
Nothing becomes readable.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant