Skip to content

Commit 156710f

Browse files
committed
Merge release/v5-prerelease (#292) into W3
#292 fixes created-file coverage for diff archives and has pypi refuse non-wheel references before downloading. Conflicts, resolved against this branch's removal of .socket/packages and the shared service policy: - fetch_stage: keep #292's per-file coverage check (a diff covers only files that exist before the patch), without the package-archive arm. - repair: take #292's download_pass helper and its created-file blob top-up; SourcePaths and PatchSources lose the packages path. - pypi: keep ServicePolicy; add #292's PYPI_NOT_A_WHEEL refusal (warns under auto, refuses under service) and its shared constant. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2 parents 3b5cdb2 + a7b0d00 commit 156710f

16 files changed

Lines changed: 1449 additions & 169 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 41 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1209,8 +1209,10 @@ into the new version's section — see docs/releasing.md.
12091209
a server-side archive build and count against quota, are exactly the
12101210
one-at-a-time loop's (71 on a fresh depscan run, where an earlier
12111211
draft of the look-ahead issued 74). What changes is only their timing:
1212-
up to four are in flight at once. `SOCKET_API_CONCURRENCY=1` turns the
1213-
look-ahead off entirely.
1212+
they are requested in one batch at the first planned package (see
1213+
"Fewer downloads in vendored runs"), and up to four archives are in
1214+
flight at once. `SOCKET_API_CONCURRENCY=1` turns the look-ahead off
1215+
entirely.
12141216
- A token revoked *mid-run* now costs the authenticated batch endpoint
12151217
the requests already in flight — up to the in-flight cap instead of
12161218
one — before the run downgrades to the public proxy. Their answers are
@@ -1220,6 +1222,21 @@ into the new version's section — see docs/releasing.md.
12201222

12211223
### Fixed
12221224

1225+
- **`apply` no longer half-applies a patch that creates a file from a
1226+
diff-only cache.** A diff archive has no delta for a file the patch
1227+
creates, but the source check counted a cached diff archive as covering
1228+
the whole patch: `apply --offline` passed it, patched the modified files,
1229+
then failed on the created file's missing blob; online `apply` never
1230+
fetched that blob. Coverage is now per file (a diff covers only files
1231+
with a `beforeHash`), so `apply --offline` reports the patch as having no
1232+
local source up front and changes nothing, online `apply` fetches just
1233+
the created files' blobs, and a default (diff-mode) `repair` downloads
1234+
them too. Such a repair's `--json` envelope carries a second
1235+
`downloaded` (dry-run `verified`) artifact event with `mode: "file"` for
1236+
those blobs.
1237+
- **Hosted `scan` resolves more than 500 patches.** The package-reference
1238+
request is sent in chunks of 500 uuids, the endpoint's limit; a larger
1239+
scan used to fail with a 400.
12231240
- **`rollback` fetches a before-blob that only a store peer variant
12241241
needs.** The before-blob gate now probes every pnpm and vlt store variant
12251242
copy the rollback restores, so an online rollback no longer fails
@@ -1843,6 +1860,15 @@ into the new version's section — see docs/releasing.md.
18431860

18441861
### Changed
18451862

1863+
- **Fewer downloads in vendored runs.** A vendored run now asks the patch
1864+
service for all of its planned packages' download references in one
1865+
request (in chunks of 500) from the first package it reaches, in place
1866+
of one request per package; an outage costs the same retries as before,
1867+
and a package the service reports still building is asked again at its
1868+
turn. A pypi patch the service serves as an sdist (every patch without a
1869+
file qualifier) is refused from its reference, before its bytes are
1870+
downloaded: `auto` still warns `vendor_prebuilt_unavailable` and builds
1871+
the wheel locally, `service` still refuses.
18461872
- **One owner rule for the patch stores.** `list`, `vex`, `scan`'s
18471873
`updates[]`, `rollback` and `remove` now read the
18481874
manifest and the vendor ledger (plus, in `vex`, the hosted records)
@@ -1953,22 +1979,25 @@ into the new version's section — see docs/releasing.md.
19531979
covers the purl (its entry records the record's patch uuid and the
19541980
committed artifact is on disk — a file artifact such as a wheel or
19551981
tarball only while it still hashes to the ledger's `sha256`; `--force`
1956-
keeps the eager fetch), and for every lockfile-only cargo crate the
1957-
registry could fetch and verify (a crates.io `Cargo.lock` entry with a
1958-
checksum, or the pre-vendor resolution the ledger recovers) while the
1959-
patch service is enabled (the cargo backend reads the pristine source
1960-
only once `cargo_service_copy` falls back to the local build). A git,
1961-
path or custom-registry crate is never deferred: it keeps the eager
1962-
ladder's `vendor_fetch_unverifiable` + `package_not_installed` refusal
1963-
and is not vendored from the service's crates.io build, and a committed
1982+
keeps the eager fetch), and for every lockfile-only npm, cargo, golang
1983+
or composer package the registry would fetch and verify (a lock entry
1984+
with an integrity, or the pre-vendor resolution the ledger recovers,
1985+
that none of its fetcher's pre-download refusals applies to) while the
1986+
patch service is enabled (those backends read the pristine source only
1987+
once the service falls back to the local build; pypi and gem keep the
1988+
eager fetch, which their installed-variant probe reads). A git, path,
1989+
local-tarball or custom-registry package is never deferred: it keeps the
1990+
eager ladder's `vendor_fetch_unverifiable` + `package_not_installed`
1991+
refusal and is not vendored from the service's registry build, and a committed
19641992
file artifact that no longer matches its pin keeps the eager ladder's
19651993
outcome too. Visible effects: an idempotent re-run
19661994
makes no registry requests and no longer reports `vendor_fetched_missing`
19671995
for fetches it never needed; with no network (or under `--offline`) the
19681996
re-run of an already-vendored pypi, cargo, go or lockfile-only gem
19691997
project now SUCCEEDS (`already_vendored`, exit 0) instead of failing
1970-
`vendor_fetch_failed` / `package_not_installed`; a cargo crate the service
1971-
serves is never downloaded from the registry. When a deferred fetch does
1998+
`vendor_fetch_failed` / `package_not_installed`; an npm, cargo, golang or
1999+
composer package the service serves is never downloaded from the
2000+
registry. When a deferred fetch does
19722001
happen (a drifted committed copy being rebuilt locally, a service miss),
19732002
its `vendor_fetched_missing` warning is recorded just ahead of that
19742003
package's own event instead of in the up-front fetch pass, and a failed,

‎Cargo.lock‎

Lines changed: 1 addition & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)