Skip to content

Commit 2f49451

Browse files
committed
Merge remote-tracking branch 'origin/release/v5-prerelease' into v5/nuget-vendoring
# Conflicts: # crates/socket-patch-cli/tests/covgap_commands_rollback.rs
2 parents e3665ef + 686e5fb commit 2f49451

191 files changed

Lines changed: 23293 additions & 21277 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.gitattributes‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,13 @@ crates/socket-patch-core/tests/fixtures/redirect/** -text
66

77
crates/socket-patch-core/tests/fixtures/pdm-native/*.lock -text
88

9+
# Poetry and Pipenv locks are real `poetry lock` / `pipenv lock` output: the
10+
# upstream restore and VEX tests round-trip them byte for byte and derive
11+
# their CRLF variants from the LF bytes themselves.
12+
crates/socket-patch-core/tests/fixtures/poetry/** -text
13+
crates/socket-patch-core/tests/fixtures/pipenv/** -text
14+
crates/socket-patch-core/tests/fixtures/pipenv-shapes/** -text
15+
916
# The captured pnpm 1-12 locks are byte-real: the hosted/vendored rewriters
1017
# refuse CRLF by design (vendor_lockfile_crlf_unsupported), and the tests
1118
# derive their CRLF variants from the LF bytes themselves.

‎.github/workflows/ci.yml‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -237,7 +237,9 @@ jobs:
237237
matrix:
238238
os: [ubuntu-latest, macos-latest, windows-latest]
239239
runs-on: ${{ matrix.os }}
240-
timeout-minutes: 35
240+
# Windows runs the same suite ~1.6x slower than macOS: on the base
241+
# branch it already took 34m40s of a flat 35m budget.
242+
timeout-minutes: ${{ matrix.os == 'windows-latest' && 50 || 35 }}
241243
steps:
242244
- name: Checkout
243245
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

‎CHANGELOG.md‎

Lines changed: 209 additions & 37 deletions
Large diffs are not rendered by default.

‎README.md‎

Lines changed: 134 additions & 84 deletions
Large diffs are not rendered by default.

‎crates/socket-patch-cli/CLI_CONTRACT.md‎

Lines changed: 149 additions & 124 deletions
Large diffs are not rendered by default.

‎crates/socket-patch-cli/src/args.rs‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -427,7 +427,7 @@ impl GlobalArgs {
427427
}
428428

429429
/// The project root whose `.socket/` state stores — manifest, vendor
430-
/// ledger, redirect ledger — belong together: the RESOLVED manifest's
430+
/// ledger — belong together: the RESOLVED manifest's
431431
/// directory, stepping out of a standard `.socket/` layout when the
432432
/// manifest lives in one. For the default `<cwd>/.socket/manifest.json`
433433
/// this is exactly `cwd`; for a `--manifest-path` into another project

‎crates/socket-patch-cli/src/commands/get.rs‎

Lines changed: 29 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -541,8 +541,8 @@ pub struct GetArgs {
541541
/// [default: hosted; agent with `--save-only` or `--global`]
542542
// agent = record in .socket/manifest.json + blobs and apply in place;
543543
// hosted = rewrite lockfiles so the patched deps resolve to Socket's
544-
// hosted patch server (no manifest, no blobs; state lives in the
545-
// redirect ledger); vendored = commit patched artifacts under
544+
// hosted patch server (no manifest, no blobs, no ledger: the lockfile
545+
// is the record); vendored = commit patched artifacts under
546546
// .socket/vendor/ and rewire the lockfile (no manifest, no blobs; the
547547
// vendor ledger carries the records). Hosted/vendored runs produce the
548548
// same on-disk result as `scan --mode hosted|vendored` selecting the
@@ -1222,6 +1222,9 @@ pub struct DownloadParams {
12221222
/// `false`: their patch content is staged in memory and the committed
12231223
/// artifact is the patch — nothing should land in `.socket/blobs`.
12241224
pub persist_blobs: bool,
1225+
/// `--patch-server-url`: the extra origin whose URLs count as hosted
1226+
/// when lockfile discovery reads the project's hosted pins.
1227+
pub patch_server_url: Option<String>,
12251228
}
12261229

12271230
impl DownloadParams {
@@ -1851,10 +1854,9 @@ type LockRefusals = HashMap<String, (&'static str, String)>;
18511854
/// classic / yarn berry gates and cargo's locked-version gate), over the
18521855
/// patches the phase would otherwise fetch a view for — past the Bun
18531856
/// refusal and the ledger's idempotency skip, which take precedence in the
1854-
/// fetch loop. A purl the hosted redirect ledger claims is left to the
1855-
/// vendor loop: its takeover reverts the hosted lock edits first, and the
1856-
/// revert rewrites the very text the gates read. A redirect ledger that
1857-
/// cannot be read leaves every purl to the loop.
1857+
/// fetch loop. A purl the lockfiles pin hosted is left to the vendor loop:
1858+
/// its takeover restores the upstream lock entry first, and the restore
1859+
/// rewrites the very text the gates read.
18581860
///
18591861
/// Only a package the vendor loop would hand to its backend is refused
18601862
/// here (see [`crate::commands::vendor::lock_refusals_reaching_backend`]):
@@ -1872,11 +1874,23 @@ async fn lock_text_refusals_for(
18721874
) -> LockRefusals {
18731875
let cwd = params.cwd.as_path();
18741876
let claimed: Vec<String> =
1875-
match socket_patch_core::patch::redirect::load_redirect_state(cwd).await {
1876-
Ok(Some(state)) => state.records.keys().map(|k| canonical_purl(k)).collect(),
1877-
Ok(None) => Vec::new(),
1878-
Err(_) => return HashMap::new(),
1879-
};
1877+
socket_patch_core::patch::redirect::upstream::HostedPin::all(
1878+
&socket_patch_core::vex::discover_patched_refs_with(
1879+
cwd,
1880+
&socket_patch_core::vex::DiscoverOptions {
1881+
patch_server_origins: params
1882+
.patch_server_url
1883+
.iter()
1884+
.filter(|url| !url.trim().is_empty())
1885+
.cloned()
1886+
.collect(),
1887+
},
1888+
)
1889+
.await,
1890+
)
1891+
.into_iter()
1892+
.map(|pin| canonical_purl(&pin.purl))
1893+
.collect();
18801894
let candidates: Vec<(&str, &str)> = selected
18811895
.iter()
18821896
.filter(|sr| bun_refusal.filter(|r| r.applies_to(&sr.purl)).is_none())
@@ -3663,12 +3677,13 @@ fn get_download_params(args: &GetArgs, save_only: bool, persist_blobs: bool) ->
36633677
strict: args.common.strict,
36643678
ecosystems: args.common.ecosystems.clone(),
36653679
persist_blobs,
3680+
patch_server_url: args.common.patch_server_url.clone(),
36663681
}
36673682
}
36683683

36693684
/// `get … --mode hosted`: hand the selected (purl, uuid) pairs to scan's
36703685
/// hosted engine ([`super::scan::boxed_run_redirect_selected`]) — lockfile
3671-
/// rewrite + redirect ledger, no manifest, no blobs — so the on-disk result
3686+
/// rewrite only, no manifest, no blobs, no ledger — so the on-disk result
36723687
/// matches `scan --mode hosted` selecting the same patches. The engine owns
36733688
/// all output (and honors `--dry-run` internally); in JSON mode it nests its
36743689
/// `redirect` block into the get base envelope passed as `scan_result`.
@@ -5223,6 +5238,7 @@ mod tests {
52235238
strict: false,
52245239
ecosystems: None,
52255240
persist_blobs: false,
5241+
patch_server_url: None,
52265242
}
52275243
}
52285244

@@ -5891,6 +5907,7 @@ mod tests {
58915907
ecosystems: None,
58925908
// The vendor-detached posture this fn exists for.
58935909
persist_blobs: false,
5910+
patch_server_url: None,
58945911
}
58955912
}
58965913

0 commit comments

Comments
 (0)