@@ -1209,8 +1209,10 @@ into the new version's section — see docs/releasing.md.
12091209 a server-side archive build and count against quota, are exactly the
12101210 one-at-a-time loop's (71 on a fresh depscan run, where an earlier
12111211 draft of the look-ahead issued 74). What changes is only their timing:
1212- up to four are in flight at once. ` SOCKET_API_CONCURRENCY=1 ` turns the
1213- look-ahead off entirely.
1212+ they are requested in one batch at the first planned package (see
1213+ "Fewer downloads in vendored runs"), and up to four archives are in
1214+ flight at once. ` SOCKET_API_CONCURRENCY=1 ` turns the look-ahead off
1215+ entirely.
12141216 - A token revoked * mid-run* now costs the authenticated batch endpoint
12151217 the requests already in flight — up to the in-flight cap instead of
12161218 one — before the run downgrades to the public proxy. Their answers are
@@ -1220,6 +1222,21 @@ into the new version's section — see docs/releasing.md.
12201222
12211223### Fixed
12221224
1225+ - ** ` apply ` no longer half-applies a patch that creates a file from a
1226+ diff-only cache.** A diff archive has no delta for a file the patch
1227+ creates, but the source check counted a cached diff archive as covering
1228+ the whole patch: ` apply --offline ` passed it, patched the modified files,
1229+ then failed on the created file's missing blob; online ` apply ` never
1230+ fetched that blob. Coverage is now per file (a diff covers only files
1231+ with a ` beforeHash ` ), so ` apply --offline ` reports the patch as having no
1232+ local source up front and changes nothing, online ` apply ` fetches just
1233+ the created files' blobs, and a default (diff-mode) ` repair ` downloads
1234+ them too. Such a repair's ` --json ` envelope carries a second
1235+ ` downloaded ` (dry-run ` verified ` ) artifact event with ` mode: "file" ` for
1236+ those blobs.
1237+ - ** Hosted ` scan ` resolves more than 500 patches.** The package-reference
1238+ request is sent in chunks of 500 uuids, the endpoint's limit; a larger
1239+ scan used to fail with a 400.
12231240- ** ` rollback ` fetches a before-blob that only a store peer variant
12241241 needs.** The before-blob gate now probes every pnpm and vlt store variant
12251242 copy the rollback restores, so an online rollback no longer fails
@@ -1843,6 +1860,15 @@ into the new version's section — see docs/releasing.md.
18431860
18441861### Changed
18451862
1863+ - ** Fewer downloads in vendored runs.** A vendored run now asks the patch
1864+ service for all of its planned packages' download references in one
1865+ request (in chunks of 500) from the first package it reaches, in place
1866+ of one request per package; an outage costs the same retries as before,
1867+ and a package the service reports still building is asked again at its
1868+ turn. A pypi patch the service serves as an sdist (every patch without a
1869+ file qualifier) is refused from its reference, before its bytes are
1870+ downloaded: ` auto ` still warns ` vendor_prebuilt_unavailable ` and builds
1871+ the wheel locally, ` service ` still refuses.
18461872- ** One owner rule for the patch stores.** ` list ` , ` vex ` , ` scan ` 's
18471873 ` updates[] ` , ` rollback ` and ` remove ` now read the
18481874 manifest and the vendor ledger (plus, in ` vex ` , the hosted records)
@@ -1953,22 +1979,25 @@ into the new version's section — see docs/releasing.md.
19531979 covers the purl (its entry records the record's patch uuid and the
19541980 committed artifact is on disk — a file artifact such as a wheel or
19551981 tarball only while it still hashes to the ledger's ` sha256 ` ; ` --force `
1956- keeps the eager fetch), and for every lockfile-only cargo crate the
1957- registry could fetch and verify (a crates.io ` Cargo.lock ` entry with a
1958- checksum, or the pre-vendor resolution the ledger recovers) while the
1959- patch service is enabled (the cargo backend reads the pristine source
1960- only once ` cargo_service_copy ` falls back to the local build). A git,
1961- path or custom-registry crate is never deferred: it keeps the eager
1962- ladder's ` vendor_fetch_unverifiable ` + ` package_not_installed ` refusal
1963- and is not vendored from the service's crates.io build, and a committed
1982+ keeps the eager fetch), and for every lockfile-only npm, cargo, golang
1983+ or composer package the registry would fetch and verify (a lock entry
1984+ with an integrity, or the pre-vendor resolution the ledger recovers,
1985+ that none of its fetcher's pre-download refusals applies to) while the
1986+ patch service is enabled (those backends read the pristine source only
1987+ once the service falls back to the local build; pypi and gem keep the
1988+ eager fetch, which their installed-variant probe reads). A git, path,
1989+ local-tarball or custom-registry package is never deferred: it keeps the
1990+ eager ladder's ` vendor_fetch_unverifiable ` + ` package_not_installed `
1991+ refusal and is not vendored from the service's registry build, and a committed
19641992 file artifact that no longer matches its pin keeps the eager ladder's
19651993 outcome too. Visible effects: an idempotent re-run
19661994 makes no registry requests and no longer reports ` vendor_fetched_missing `
19671995 for fetches it never needed; with no network (or under ` --offline ` ) the
19681996 re-run of an already-vendored pypi, cargo, go or lockfile-only gem
19691997 project now SUCCEEDS (` already_vendored ` , exit 0) instead of failing
1970- ` vendor_fetch_failed ` / ` package_not_installed ` ; a cargo crate the service
1971- serves is never downloaded from the registry. When a deferred fetch does
1998+ ` vendor_fetch_failed ` / ` package_not_installed ` ; an npm, cargo, golang or
1999+ composer package the service serves is never downloaded from the
2000+ registry. When a deferred fetch does
19722001 happen (a drifted committed copy being rebuilt locally, a service miss),
19732002 its ` vendor_fetched_missing ` warning is recorded just ahead of that
19742003 package's own event instead of in the up-front fetch pass, and a failed,
0 commit comments