Skip to content

fix(nm): prefer direct dependency binaries - #7216

Merged
larixer merged 1 commit into
yarnpkg:masterfrom
ychampion:fix-direct-bin-precedence
Jul 17, 2026
Merged

fix(nm): prefer direct dependency binaries#7216
larixer merged 1 commit into
yarnpkg:masterfrom
ychampion:fix-direct-bin-precedence

Conversation

@ychampion

Copy link
Copy Markdown
Contributor

What's the problem this PR addresses?

Closes #7215.

With the node-modules linker, packages that export the same binary currently overwrite each other in traversal order. A transitive alias can therefore replace a direct dependency binary, as in the TypeScript 6/7 setup where .bin/tsc points to @typescript/old.

How did you fix it?

Bin collection now keeps the first target for a name, preserving the direct dependency encountered before its transitive dependency.

The regression uses aliased fixture packages and checks both the persisted root bin target and the generated .bin executable.

Validation

  • corepack yarn build:cli
  • corepack yarn workspace acceptance-tests test:integration --runTestsByPath "$PWD/packages/acceptance-tests/pkg-tests-specs/sources/node-modules.test.ts" --runInBand (63 passed, 2 platform-specific skipped)
  • corepack yarn test:lint
  • corepack yarn typecheck:all
  • corepack yarn constraints
  • corepack yarn version check

Checklist

  • I have read the Contributing Guide.
  • I have set the packages that need to be released for my changes to be effective.
  • I will check that all automated PR checks pass before the PR gets reviewed.

Constraint: Preserve stable traversal order while preventing transitive bin overwrites.
Confidence: high
Scope-risk: narrow
Tested: node-modules acceptance tests; yarn test:lint; yarn typecheck:all; yarn constraints; yarn version check
Not-tested: Windows-specific shim execution locally

@larixer larixer left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you! Looks good!

@ychampion

Copy link
Copy Markdown
Contributor Author

Thanks for the review!

@AndrewMax

Copy link
Copy Markdown

Hello,

Many thanks to @ychampion for the fix! Any plans to make a release anytime soon?

I'm pretty sure that the issue is currently blocking many Yarn users from being able to use TypeScript 7 with TS6 API bridge.
Thank you!

CC @larixer

@larixer
larixer enabled auto-merge July 17, 2026 05:01
@larixer

larixer commented Jul 17, 2026

Copy link
Copy Markdown
Member

@AndrewMax I don't have power to make Yarn releases, I can only review and merge PRs if they pass required tests.

@larixer
larixer added this pull request to the merge queue Jul 17, 2026
Merged via the queue into yarnpkg:master with commit d6836a6 Jul 17, 2026
83 of 87 checks passed
arcanis added a commit to yarnpkg/zpm that referenced this pull request Aug 15, 2026
## What's the problem this PR addresses?

A review of recent Berry PRs identified several fixes and regression
tests that also apply to zpm. This PR backports them in one batch.

## How did I fix it?

**Bug fixes (the ported regression tests reproduced each of these before
the fix):**

- yarnpkg/berry#7205 — `*` now resolves to prereleases when a package
has no stable version. The fallback only applies to a literal `*` range
(not the internal `>=0.0.0-0` any-range), and `--check-resolutions`
accepts the resulting prerelease pins.
- yarnpkg/berry#7216 — the nm linker now prefers direct dependency
binaries over transitively-hoisted aliases when two packages expose the
same bin name, instead of resolving collisions by ident order.
- yarnpkg/berry#7209 — commands that need an npm OTP now fail with a
`--otp` hint when not attached to an interactive terminal, instead of
blocking forever on a prompt.
- yarnpkg/berry#7255 — `yarn npm audit --recursive --environment
production` no longer reports advisories only reachable through a nested
workspace's devDependencies.
- yarnpkg/berry#7253 — `yarn info --virtuals` now reports base
descriptors alongside virtual locators (zpm had the mirror image of
Berry's bug: correct locators, virtualized descriptors).
- yarnpkg/berry#7206 — a failed Algolia auto-types lookup no longer
aborts `yarn add`; it degrades to a warning (with the `enableAutoTypes`
escape hatch) and the lookup is bounded by a 10s per-request timeout.

**Feature:**

- yarnpkg/berry#7243 — `supportedArchitectures` additionally accepts a
list of explicit os/cpu/libc combinations (matched per-entry, no
cross-product), with the same config syntax as Berry.

**Tests only (zpm's behavior was already correct):**

- yarnpkg/berry#7250 / yarnpkg/berry#7257 — gate bypass for packages
without release-time metadata, plus the `no-time-deps` fixture and
registry-mock support.
- yarnpkg/berry#7214 — scoped-gate inheritance tests, adapted to zpm's
`packageRules`/`sourceRules` model (zpm's Option-based overrides make
Berry's default-shadowing bug structurally impossible).

**Artifact sync:**

- Re-ran `scripts/import-artifacts.mjs` against Berry master, picking up
yarnpkg/berry#7232 and the extensions hunk of yarnpkg/berry#7228 (8 new
package extensions: 5 Volar `typescript` peers,
`vite-plugin-vue-devtools`, 2 Parcel entries) along with forward-only
PnP hook/patch updates.

## Checklist

- [x] I have read the [Contributing
Guide](https://yarnpkg.com/advanced/contributing).
- [x] I have checked that all the impacted tests pass: the touched
acceptance suites (npmMinimalAgeGate, prunedNativeDeps, protocols/npm,
npm/audit, info, publish, node-modules, packageExtensions,
checkResolutions, add) pass 215/218 (3 skipped), plus `cargo test` for
zpm-config (7) and zpm-semver (108). The only remaining local failures
reproduce identically on a pristine `main` build (venv/Python
environment, one live-Algolia-data test, `path_iterators` and two
lazyInstalls focus-coverage tests).

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Touches core install resolution, architecture filtering, and audit
traversal; behavior changes are intentional but affect many installs and
multi-arch fetches.
> 
> **Overview**
> Backports a batch of Berry fixes and tests into zpm, covering install
resolution, CLI behavior, configuration, and artifact sync.
> 
> **Resolution & install:** Literal `*` ranges can resolve to
prereleases when no stable versions exist, with matching
`--check-resolutions` acceptance. Algolia auto-`@types` lookup is capped
at 10s, warns instead of failing `yarn add`, and respects
`enableAutoTypes`. HTTP requests gain a per-request `.timeout()` bounded
by `httpTimeout`.
> 
> **Commands & linkers:** `npm publish` errors with a `--otp` hint when
not on an interactive TTY. Recursive production `npm audit` skips nested
workspaces’ devDependencies. `yarn info --virtuals` shows physical
descriptors with virtual locators. Node-modules bin symlinks prefer
direct dependencies over hoisted aliases.
> 
> **`supportedArchitectures`:** Schema becomes a `oneOrMany` list of
entries with `ArchitectureFilter` fields (`null` = any). Legacy
single-object YAML still works; project config replaces (not merges)
user entries. Matching uses `SystemSet` / `supported_systems()` with
per-entry validation instead of a flat cross-product of all systems.
> 
> **Artifacts:** `builtin-extensions.json` gains Volar, Vite devtools,
and Parcel peer entries; package manager pin updated.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
4aaf6a1. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug?]: node_modules/.bin/tsc not linked to the correct package when ts7 and ts6 are installed using aliases

3 participants