Commit 06437d2
WS5: one VendoredBackend for vendored apply/revert/repair; cut repair's ledger rebuild (#283)
* Consolidate vendored apply/revert/repair into one VendoredBackend
vendor, scan/get --mode vendored, vendor --revert, rollback's vendored
leg, remove and repair now go through one VendoredBackend { apply,
revert, repair } over the shared engine (vendor_records_reusing,
dispatch_revert_one_opts). The boxed_* scan shims collapse into one
boxed_vendor_step; the engine future stays boxed inside apply for the
Windows 1 MiB main-thread stack.
repair no longer re-synthesizes vendor ledger entries from lockfiles. A
lockfile reference with no ledger entry fails with vendor_ledger_missing
(artifact-level event: uuid + details.{ecosystem,path}); the remedy is
restoring state.json from version control. Missing or corrupt artifacts
are re-vendored through the same engine as vendor, so the patch
service's prebuilt artifact is downloaded first under --vendor-source
auto, with the local build as the fallback. The fingerprint post-verify,
set-aside of corrupt bytes and carried-inventory refresh are kept.
Removed with the rebuild: repair_vendor.rs, gem Gemfile wiring
reconstruction, and registry_fetch::fetch_npm_unverified. The packing
code (npm_pack, pypi_wheel, berry_zip, registry_fetch, prestage) stays:
depscan does not call it (verified against depscan master 784013d6), but
it is the CLI's own --vendor-source build/auto fallback.
Tests for the reconstruction path are replaced by vendor_ledger_missing
pins per flavor; CLI_CONTRACT, README, CHANGELOG and the v5 plan are
updated.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DMhWChtaNX5FJYNDq3NBJa
* Point the vlt coverage map at the renamed repair test
vlt-coverage.json still named vlt_repair_reconstructs_the_ledger_from_the_lock,
and vendor_vlt_lock_out_of_sync lost the only assertion the coverage
check could see when the lock-only reference test switched to
vendor_ledger_missing. vendor_vlt_out_of_sync now asserts the refusal
detail.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DMhWChtaNX5FJYNDq3NBJa
* Drop the ledger-less mirror leg from the bun binary workspace test
native_binary_alias_and_transitive still expected repair to rebuild a
workspace mirror after deleting state.json. Repair now reports that as
vendor_ledger_missing (pinned in native_binary_hosted_vendored_takeover_roundtrip),
so the leg is gone; the missing/corrupt mirror legs keep running and
assert the ledger stays byte-identical.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DMhWChtaNX5FJYNDq3NBJa
* Pass --mode agent to the gated agent-mode get fixtures
get defaults to hosted since 5e5f5ed, which moved the agent-mode
fixtures to --mode agent but missed the #[ignore]d real-toolchain
suites (e2e_vlt, e2e_npm, e2e_pypi, e2e_gem, e2e_safety_pnpm). Their
plain `get <uuid>` now redirects instead of applying in place, so e.g.
vlt_pinned_matrix_agent_get_and_remove saw the copy Absent. This PR
touches the vlt-compatibility path filter, which surfaced it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DMhWChtaNX5FJYNDq3NBJa
* Keep an unpersistable inventory refresh loud, drop reconstruction persist tests
A carried-inventory refresh whose ledger write fails now reports
vendor_inventory_refreshed next to vendor_state_write_failed and keeps
the member-verified rebuild on disk, instead of falling through to
vendor_artifact_rebuild_failed and removing it. The persist-failure
tests for the removed backfill / anchored / soft reconstruction paths
go with them; they only run as non-root, which is why the root sandbox
skipped them.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DMhWChtaNX5FJYNDq3NBJa
* Restore the macOS-only PatchedFixture hash fields
The dead-field clippy fix removed before_hash/after_hash, but the macOS
immutable-flag rollback tests read them, so test (macos-latest) no
longer compiled. Keep the fields and allow dead_code off macOS only.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DMhWChtaNX5FJYNDq3NBJa
* Keep repair on the recorded artifact identity
Review of #283 found two regressions in the shared-engine repair:
- A corrupt artifact was moved aside before staging, so its
afterHash-verified members were no longer harvested: an offline repair
that the previous implementation completed failed with "no local
source". The members are now harvested first and passed as the seed.
- The post-verify reloaded the ledger the re-vendor had just written, so a
service archive with different bytes (same members, new gzip mtime) was
committed as `rebuilt` with a rewired lock and new fingerprint. Repair
now verifies against the original entry; when the result is not the
recorded artifact, that candidate's wiring files and ledger entry are
put back from a pre-run snapshot, and a service copy falls back to a
build-only rebuild. Legitimate backend migrations of a verified rebuild
(the cargo version retag) are kept.
Both reproductions are pinned in repair_vendor_e2e.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DMhWChtaNX5FJYNDq3NBJa
* Make repair's wiring undo FIFO-safe, atomic and symlink-preserving
Bugbot on #283: the identity-undo snapshot read lockfiles with bare
tokio::fs::read (a FIFO at a wiring path blocks open(2)) and skipped
symlinked lockfiles, and the put-back wrote them in place (no
stage+fsync+rename, mode bits dropped).
The snapshot now reads through read_regular_to_bytes and records a
symlinked lockfile's link text; the undo re-links a link that the
engine's rename replaced, then writes the target through
atomic_write_bytes_preserving_mode. Pinned by
repair_identity_undo_follows_a_symlinked_lockfile.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DMhWChtaNX5FJYNDq3NBJa
---------
Co-authored-by: Claude <noreply@anthropic.com>1 parent 686e5fb commit 06437d2
36 files changed
Lines changed: 2855 additions & 6341 deletions
File tree
- .github/workflows
- crates
- socket-patch-cli
- src/commands
- scan
- vendored_backend
- tests
- in_process_vendor
- repair_vendor_flavors_e2e
- socket-patch-core/src/vendor
- docs
- design
- testing
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
46 | | - | |
| 46 | + | |
47 | 47 | | |
48 | 48 | | |
49 | 49 | | |
| |||
75 | 75 | | |
76 | 76 | | |
77 | 77 | | |
78 | | - | |
| 78 | + | |
79 | 79 | | |
80 | 80 | | |
81 | 81 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
37 | 37 | | |
38 | 38 | | |
39 | 39 | | |
40 | | - | |
| 40 | + | |
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
| |||
74 | 74 | | |
75 | 75 | | |
76 | 76 | | |
77 | | - | |
| 77 | + | |
78 | 78 | | |
79 | 79 | | |
80 | 80 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
226 | 226 | | |
227 | 227 | | |
228 | 228 | | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
229 | 253 | | |
230 | 254 | | |
231 | 255 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
476 | 476 | | |
477 | 477 | | |
478 | 478 | | |
479 | | - | |
| 479 | + | |
480 | 480 | | |
481 | 481 | | |
482 | 482 | | |
| |||
497 | 497 | | |
498 | 498 | | |
499 | 499 | | |
500 | | - | |
| 500 | + | |
501 | 501 | | |
502 | 502 | | |
503 | 503 | | |
| |||
1215 | 1215 | | |
1216 | 1216 | | |
1217 | 1217 | | |
1218 | | - | |
| 1218 | + | |
1219 | 1219 | | |
1220 | 1220 | | |
1221 | 1221 | | |
1222 | 1222 | | |
1223 | 1223 | | |
1224 | 1224 | | |
1225 | | - | |
| 1225 | + | |
| 1226 | + | |
| 1227 | + | |
| 1228 | + | |
| 1229 | + | |
1226 | 1230 | | |
1227 | 1231 | | |
1228 | 1232 | | |
| |||
0 commit comments