@@ -541,8 +541,8 @@ pub struct GetArgs {
541541 /// [default: hosted; agent with `--save-only` or `--global`]
542542 // agent = record in .socket/manifest.json + blobs and apply in place;
543543 // hosted = rewrite lockfiles so the patched deps resolve to Socket's
544- // hosted patch server (no manifest, no blobs; state lives in the
545- // redirect ledger ); vendored = commit patched artifacts under
544+ // hosted patch server (no manifest, no blobs, no ledger: the lockfile
545+ // is the record ); vendored = commit patched artifacts under
546546 // .socket/vendor/ and rewire the lockfile (no manifest, no blobs; the
547547 // vendor ledger carries the records). Hosted/vendored runs produce the
548548 // same on-disk result as `scan --mode hosted|vendored` selecting the
@@ -1222,6 +1222,9 @@ pub struct DownloadParams {
12221222 /// `false`: their patch content is staged in memory and the committed
12231223 /// artifact is the patch — nothing should land in `.socket/blobs`.
12241224 pub persist_blobs : bool ,
1225+ /// `--patch-server-url`: the extra origin whose URLs count as hosted
1226+ /// when lockfile discovery reads the project's hosted pins.
1227+ pub patch_server_url : Option < String > ,
12251228}
12261229
12271230impl DownloadParams {
@@ -1851,10 +1854,9 @@ type LockRefusals = HashMap<String, (&'static str, String)>;
18511854/// classic / yarn berry gates and cargo's locked-version gate), over the
18521855/// patches the phase would otherwise fetch a view for — past the Bun
18531856/// refusal and the ledger's idempotency skip, which take precedence in the
1854- /// fetch loop. A purl the hosted redirect ledger claims is left to the
1855- /// vendor loop: its takeover reverts the hosted lock edits first, and the
1856- /// revert rewrites the very text the gates read. A redirect ledger that
1857- /// cannot be read leaves every purl to the loop.
1857+ /// fetch loop. A purl the lockfiles pin hosted is left to the vendor loop:
1858+ /// its takeover restores the upstream lock entry first, and the restore
1859+ /// rewrites the very text the gates read.
18581860///
18591861/// Only a package the vendor loop would hand to its backend is refused
18601862/// here (see [`crate::commands::vendor::lock_refusals_reaching_backend`]):
@@ -1872,11 +1874,23 @@ async fn lock_text_refusals_for(
18721874) -> LockRefusals {
18731875 let cwd = params. cwd . as_path ( ) ;
18741876 let claimed: Vec < String > =
1875- match socket_patch_core:: patch:: redirect:: load_redirect_state ( cwd) . await {
1876- Ok ( Some ( state) ) => state. records . keys ( ) . map ( |k| canonical_purl ( k) ) . collect ( ) ,
1877- Ok ( None ) => Vec :: new ( ) ,
1878- Err ( _) => return HashMap :: new ( ) ,
1879- } ;
1877+ socket_patch_core:: patch:: redirect:: upstream:: HostedPin :: all (
1878+ & socket_patch_core:: vex:: discover_patched_refs_with (
1879+ cwd,
1880+ & socket_patch_core:: vex:: DiscoverOptions {
1881+ patch_server_origins : params
1882+ . patch_server_url
1883+ . iter ( )
1884+ . filter ( |url| !url. trim ( ) . is_empty ( ) )
1885+ . cloned ( )
1886+ . collect ( ) ,
1887+ } ,
1888+ )
1889+ . await ,
1890+ )
1891+ . into_iter ( )
1892+ . map ( |pin| canonical_purl ( & pin. purl ) )
1893+ . collect ( ) ;
18801894 let candidates: Vec < ( & str , & str ) > = selected
18811895 . iter ( )
18821896 . filter ( |sr| bun_refusal. filter ( |r| r. applies_to ( & sr. purl ) ) . is_none ( ) )
@@ -3663,12 +3677,13 @@ fn get_download_params(args: &GetArgs, save_only: bool, persist_blobs: bool) ->
36633677 strict : args. common . strict ,
36643678 ecosystems : args. common . ecosystems . clone ( ) ,
36653679 persist_blobs,
3680+ patch_server_url : args. common . patch_server_url . clone ( ) ,
36663681 }
36673682}
36683683
36693684/// `get … --mode hosted`: hand the selected (purl, uuid) pairs to scan's
36703685/// hosted engine ([`super::scan::boxed_run_redirect_selected`]) — lockfile
3671- /// rewrite + redirect ledger , no manifest, no blobs — so the on-disk result
3686+ /// rewrite only , no manifest, no blobs, no ledger — so the on-disk result
36723687/// matches `scan --mode hosted` selecting the same patches. The engine owns
36733688/// all output (and honors `--dry-run` internally); in JSON mode it nests its
36743689/// `redirect` block into the get base envelope passed as `scan_result`.
@@ -5223,6 +5238,7 @@ mod tests {
52235238 strict : false ,
52245239 ecosystems : None ,
52255240 persist_blobs : false ,
5241+ patch_server_url : None ,
52265242 }
52275243 }
52285244
@@ -5891,6 +5907,7 @@ mod tests {
58915907 ecosystems : None ,
58925908 // The vendor-detached posture this fn exists for.
58935909 persist_blobs : false ,
5910+ patch_server_url : None ,
58945911 }
58955912 }
58965913
0 commit comments