Repository navigation
Conversation
Multiple content-addressable versions can share a number and platform, one per Ruby ABI, so resolving a deletion by number and platform alone matched an arbitrary variant. find_version! now scopes on ruby_abi (nil by default, preserving behavior for all existing versions) and the deletions API accepts a ruby_abi param to target a variant. Without the param, yanks against ABI variants return 404 rather than deleting an arbitrary one. The gem yank CLI needs a matching option to pass ruby_abi.
|
Hmm I think I need to add a |
Tophat looks good! I agree with your comment we should record the ruby abi on the Deletion. With multiple yanked variants sharing the same version/platform, that makes the deletion rows harder to reason about from an audit perspective. Also I don't know if this script is used at all, buit it calls |
727971c to
d9d5373
Compare
With multiple yanked variants sharing a number and platform, deletion rows and yank events were ambiguous for auditing. Record ruby_abi on Deletion (validated against the version like the other metadata) and include it in the yank, unyank and yank-forbidden event payloads.
script/restore_version resolved versions by number and platform only, so it could not target a yanked ABI-specific variant. Accept an optional RUBY_ABI argument and scope the Deletion lookup by it.
d9d5373 to
852b67e
Compare
@girachawda yep! good catch, I don't think anyone was using it since when I ran it, there were Ruby 4 incompatibilities but for the off chance we need it, I updated the script and it unyanked.
|
31ba205
into
ho/feature-branch-ca-server-changes

rubygems#6674
Problem
Content-addressable gems mean multiple versions can now share the same
numberandplatform— one per Ruby ABI:The deletions API resolves the version to yank via
Rubygem#find_version!(number:, platform:), which usesfind_by!— sogem yank sandworm -v 1.0.0 --platform x86_64-linux-muslwould match both rows and delete whichever the database returned first. A destructive operation should never pick its target arbitrarily.Solution
find_version!now scopes onruby_abi, defaulting tonil, and the deletions API accepts an optionalruby_abiparam:platform+ matchingruby_abiplatform+ruby_abimatching no variantplatformonly, when only ABI variants existplatformonly, when a version supporting multiple Ruby ABIs coexistsruby_abiwithoutplatformruby_abiparam.presence, matchingplatform's existing handling)Testing
Push three real
.gemfiles (ABI 3.2 + 3.4 variants and a version supporting multiple Ruby ABIs, all sharing number + platform) through the full push pipeline with the feature flag enabled, then exercises every yank resolution path, asserting HTTP status, response body, and the indexed state of all three versions after each step.Run from the repo root with the server on
:3000— paste the whole block into your console:Tophat script (single paste)
Output (24 passed, 0 failed)
On admin
