Repository navigation
Don't read a warning-only yarn install or a recovered checkout as a failure - #393
Merged
Merged
Conversation
…ailure
yarn Berry tags every line -- success, info, warning, error -- with a YNxxxx
code, so node_dependency_install matched YN\d{4} off benign peer-dependency
warnings (YN0002/YN0060/YN0086) even when the install said "YN0000: Done with
warnings". grafana/grafana's lint-knip job (run 29806261731) installed cleanly
and failed on knip and a yarn constraints check, yet was called
node_dependency_install at 0.71 -- handing the maintainer `corepack pnpm
install` (the wrong package manager) to reproduce a working tree. The same log
missed a PR branch in a fork/enterprise dual-checkout (error: pathspec ... did
not match) and fell back to main ("Checkout succeeded, breaking retry loop"),
scoring git_checkout_failure on a checkout that succeeded.
A bare YNxxxx code is now a benign warning that cannot stand once the runner
annotated a failure or the run announced success, and a pathspec miss the log
recovers from no longer witnesses. The run declines to unknown and hands back
the runner's own verdict (Yarn constraints check failed). Genuine yarn install
failures (YN0028 lockfile, ERESOLVE) and genuine checkout failures (a pathspec
miss with no recovery, fatal: reference is not a tree) both still land; the
223-case benchmark is unchanged (top-1 1.0). +regression test from the real log.
Merged
PabloCodes7
added a commit
that referenced
this pull request
Jul 21, 2026
Cut 0.7.4 from main. The last release, 0.7.3 (2026-07-16), predates ten false-positive fixes that are sitting on main and not on PyPI: an installed pytest read as a failing test run (#376), a passing test's title read as a secrets failure (#380), a PHPUnit assertion read as a Composer failure (#378), Flutter's cached Gradle Wrapper (#382), Cabal's dependency resolution read as Maven (#383), Crystal and dune's make targets read as C/C++ (#384, #385), a parenthesized 504 (#391), mypy in a pixi manifest (#390), an unset TERM read as a missing secret (#392), a warning-only yarn install and a recovered checkout (#393), and a verdict held up by invocations alone reporting diagnosis-level confidence (#395). Every one of those is a wrong answer a maintainer gets today from pip install patchrail. Version bumped in the four places that spell it out (pyproject, __init__, README quickstart, uv.lock), CHANGELOG's Unreleased section dated, and the real-world benchmark's release-status paragraph corrected: it no longer claims six fixes are unreleased. Co-authored-by: PabloCodes7 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Two precision false positives surfaced by a real, fresh mainstream log — grafana/grafana's
lint-knipjob (run 29806261731):node_dependency_install(0.71). yarn Berry tags every line — success, info, warning, error — with aYNxxxxcode.node_dependency_installmatchedYN\d{4}off benign peer-dependency warnings (YN0002,YN0060,YN0086) even though the install saidYN0000: Done with warnings. The job actually failed onknip(unused deps) and ayarn constraintscheck. PatchRail handed the maintainercorepack pnpm install— the wrong package manager — to reproduce a working tree.git_checkout_failure. The same log missed a PR branch in a fork/enterprise dual-checkout (error: pathspec '…' did not match) and fell back tomain(Already on 'main'…Checkout succeeded, breaking retry loop) — a checkout that succeeded.Fix
YNxxxxcode joins the benign-warning family: it corroborates but cannot carry a verdict once the runner annotated a failure or the run announced success.pathspec … did not matchline the log then recovers from (git confirms withAlready on/Switched to/HEAD is now at, or a retry wrapper saysCheckout succeeded/checked out) no longer witnesses a failure.The run now declines to
unknownand hands back the runner's own verdict:Both guards are general, not fixture-fit. Genuine failures still land: a yarn frozen-lockfile break (
YN0028→ "lockfile would have been modified",ERESOLVE) staysnode_dependency_install, and a pathspec miss with no recovery (or afatal: reference is not a tree) staysgit_checkout_failure.Verification
patchrail ci benchmark examples/ci-triage: 223/223, top-1 = 1.0 — no fixture changes class (no new FP, no lost TP). All 5 yarn-YNfixtures and the LFS-checkout fixture preserved.ruff check/ruff format --checkclean.tests/test_grafana_yarn_warnings_not_dependency_install.py— regression test distilled from the committed real log, incl. disease-guard cases (real install failure + hard-fail checkout still land).