Skip to content

Don't read a warning-only yarn install or a recovered checkout as a failure - #393

Merged
PabloCodes7 merged 1 commit into
mainfrom
fix/node-install-and-checkout-fp
Jul 21, 2026
Merged

PabloCodes7 merged 1 commit into
mainfrom
fix/node-install-and-checkout-fp

Conversation

@PabloCodes7

Copy link
Copy Markdown
Contributor

What

Two precision false positives surfaced by a real, fresh mainstream log — grafana/grafana's lint-knip job (run 29806261731):

  1. Warning-only yarn install → node_dependency_install (0.71). yarn Berry tags every line — success, info, warning, error — with a YNxxxx code. node_dependency_install matched YN\d{4} off benign peer-dependency warnings (YN0002, YN0060, YN0086) even though the install said YN0000: Done with warnings. The job actually failed on knip (unused deps) and a yarn constraints check. PatchRail handed the maintainer corepack pnpm install — the wrong package manager — to reproduce a working tree.
  2. Recovered checkout → git_checkout_failure. The same log missed a PR branch in a fork/enterprise dual-checkout (error: pathspec '…' did not match) and fell back to main (Already on 'main' … Checkout succeeded, breaking retry loop) — a checkout that succeeded.

Fix

  • A bare YNxxxx code joins the benign-warning family: it corroborates but cannot carry a verdict once the runner annotated a failure or the run announced success.
  • A pathspec … did not match line the log then recovers from (git confirms with Already on / Switched to / HEAD is now at, or a retry wrapper says Checkout succeeded / checked out) no longer witnesses a failure.

The run now declines to unknown and hands back the runner's own verdict:

$ patchrail ci explain --log grafana-lint-29806261731.log
failure_class: unknown  (0.15)
runner_errors: ["Yarn constraints check failed. Run 'yarn constraints --fix' ..."]

Both guards are general, not fixture-fit. Genuine failures still land: a yarn frozen-lockfile break (YN0028 → "lockfile would have been modified", ERESOLVE) stays node_dependency_install, and a pathspec miss with no recovery (or a fatal: reference is not a tree) stays git_checkout_failure.

Verification

  • patchrail ci benchmark examples/ci-triage: 223/223, top-1 = 1.0 — no fixture changes class (no new FP, no lost TP). All 5 yarn-YN fixtures and the LFS-checkout fixture preserved.
  • Full suite 1002 passed (Python 3.12); ruff check / ruff format --check clean.
  • +tests/test_grafana_yarn_warnings_not_dependency_install.py — regression test distilled from the committed real log, incl. disease-guard cases (real install failure + hard-fail checkout still land).

…ailure

yarn Berry tags every line -- success, info, warning, error -- with a YNxxxx
code, so node_dependency_install matched YN\d{4} off benign peer-dependency
warnings (YN0002/YN0060/YN0086) even when the install said "YN0000: Done with
warnings". grafana/grafana's lint-knip job (run 29806261731) installed cleanly
and failed on knip and a yarn constraints check, yet was called
node_dependency_install at 0.71 -- handing the maintainer `corepack pnpm
install` (the wrong package manager) to reproduce a working tree. The same log
missed a PR branch in a fork/enterprise dual-checkout (error: pathspec ... did
not match) and fell back to main ("Checkout succeeded, breaking retry loop"),
scoring git_checkout_failure on a checkout that succeeded.

A bare YNxxxx code is now a benign warning that cannot stand once the runner
annotated a failure or the run announced success, and a pathspec miss the log
recovers from no longer witnesses. The run declines to unknown and hands back
the runner's own verdict (Yarn constraints check failed). Genuine yarn install
failures (YN0028 lockfile, ERESOLVE) and genuine checkout failures (a pathspec
miss with no recovery, fatal: reference is not a tree) both still land; the
223-case benchmark is unchanged (top-1 1.0). +regression test from the real log.
@PabloCodes7
PabloCodes7 merged commit d9d0d85 into main Jul 21, 2026
5 checks passed
@PabloCodes7
PabloCodes7 deleted the fix/node-install-and-checkout-fp branch July 21, 2026 08:40
@PabloCodes7 PabloCodes7 mentioned this pull request Jul 21, 2026
PabloCodes7 added a commit that referenced this pull request Jul 21, 2026
Cut 0.7.4 from main. The last release, 0.7.3 (2026-07-16), predates ten
false-positive fixes that are sitting on main and not on PyPI: an installed
pytest read as a failing test run (#376), a passing test's title read as a
secrets failure (#380), a PHPUnit assertion read as a Composer failure (#378),
Flutter's cached Gradle Wrapper (#382), Cabal's dependency resolution read as
Maven (#383), Crystal and dune's make targets read as C/C++ (#384, #385), a
parenthesized 504 (#391), mypy in a pixi manifest (#390), an unset TERM read as
a missing secret (#392), a warning-only yarn install and a recovered checkout
(#393), and a verdict held up by invocations alone reporting diagnosis-level
confidence (#395). Every one of those is a wrong answer a maintainer gets today
from pip install patchrail.

Version bumped in the four places that spell it out (pyproject, __init__,
README quickstart, uv.lock), CHANGELOG's Unreleased section dated, and the
real-world benchmark's release-status paragraph corrected: it no longer claims
six fixes are unreleased.

Co-authored-by: PabloCodes7 <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant