Repository navigation
Fix Yarn lockfile matching for ranges containing spaces - #16367
Open
jtlopezdev wants to merge 4 commits into
Open
jtlopezdev wants to merge 4 commits into
jtlopezdev wants to merge 4 commits into
Conversation
When multiple lockfile entries exist for a package, the range scan stops at whitespace and cannot find OR or comparator requirements. Compare complete descriptors while preserving the single-entry fallback. Exercise the public lockfile lookup with existing fixtures and cover scoped names, unmatched ranges, and composite descriptor separators.
Cover incomplete range prefixes and bare descriptors with spaces through the public lookup API. Document complete-descriptor matching and the fixture dependency on multiple candidates, and restore the ignored parser spec's original type sigil. Validate 631 focused examples with no failures and one existing pending example. Confirm both new regressions fail with the pre-fix matcher; run RuboCop and production Sorbet checking against checked-in RBIs.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What are you trying to accomplish?
Fix Yarn lockfile lookup when a package has multiple entries and the requested range contains spaces. The existing
yarn_berry/no_lockfile_changefixture contains separateaprobaentries for^1.0.3and^1.0.3 || ^2.0.0; looking up the latter currently returns no match instead of the locked version2.0.0.Compare complete descriptors instead of extracting a range only up to its first whitespace character. This also fixes comparator ranges such as
>= 1.5.0 < 2in composite lockfile keys and prevents a short requirement from falsely matching the prefix of a longer range.Related context: #4701. This fixes Yarn descriptor lookup when several lockfile entries exist; it does not resolve the broader multi-version aggregation/update behavior discussed there.
Anything you want to highlight for special attention from reviewers?
The change is limited to Yarn lockfile lookup and parser specs. It preserves the single-entry fallback and supports both bare and
npm:descriptors. Four examples use unchanged repository lockfile fixtures to cover OR ranges, comparator ranges, scoped names, and lookup of the second descriptor in a composite key. Two small helper-result examples cover rejection of incomplete descriptor prefixes and bare descriptors containing spaces. The fixture comments explain why multiple candidate entries must remain present.How will you know you've accomplished your goal?
Verified in an isolated Linux Docker checkout with networking disabled and seed
16367:sorbet-static0.6.13449 binary,sorbet/config, and the checked-in RBIs. This checks production types; it does not run the workflow's RBI regeneration/coverage steps.The full repository/ecosystem suite is outside this verification scope. Upstream workflows have started for the current head; full CI verification remains in progress. The earlier reviewed commit reported
action_required.Checklist