Skip to content

Commit 40957fb

Browse files
Require server artifacts and exact redownload for vendoring (#300)
* Require server artifacts for vendoring Download verified complete packages instead of rebuilding archives from installed files, patch blobs, or registry sources. Repair damaged vendor copies from the exact recorded server artifact without changing lockfile or ledger identity. Retain the N-API crate and hosted in-memory patch application engine for the GitHub App. Consume server-provided upstream Yarn Berry checksums and preserve the latest v5 Maven reactor and Gradle support. Assisted-by: Codex:GPT-6 * Align vendoring coverage and lint metadata Regenerate the vlt matrix after replacing its local-build leg with the service alias. Remove orphaned builder documentation and retain the existing backend argument style for Python distribution downloads. Assisted-by: Codex:gpt-6-astra * Serve artifacts in native Bun compatibility tests Use fixture grants for fresh vendoring and redownload repairs. Match the installed npm version when building fixture archives so a workspace's different top-level version cannot replace its nested dependency. Assisted-by: Codex:gpt-6-astra * Fix download-based vendoring CI and repair Exercise served artifacts across the package-manager fixtures while preserving cold-cache offline install and revert coverage. Repair keeps Bun lockfiles and artifact identities unchanged. Record complete Composer inventories after filter normalization, and use the shared service policy for archive and Go redownload failures. Assisted-by: Codex:gpt-6-astra * Assert exact Composer redownload in capstone Check that restoring modified filter files preserves the complete artifact inventory, lockfile, and ledger without in-place healing. Assisted-by: Codex:gpt-6-astra * Fix: Record file inventory for Composer vendor artifacts (#323) Composer vendors now compute and persist file_inventory at vendor time, matching the behavior of Cargo, Go, gem, and vlt. This enables directory repair and same-UUID vendor restore for Composer packages, preventing redownload::restore from failing on missing inventory data. Co-authored-by: Cursor Agent <cursoragent@cursor.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com>
1 parent ae775fb commit 40957fb

190 files changed

Lines changed: 7803 additions & 17303 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎crates/socket-patch-cli/CLI_CONTRACT.md‎

Lines changed: 35 additions & 145 deletions
Large diffs are not rendered by default.

‎crates/socket-patch-cli/Cargo.toml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,7 @@ docker-e2e = []
5757
# vendor_crash_safety_e2e / vendor_group_commit_e2e crash the binary through
5858
# its failpoints; with this, `cargo test --release` (the test-release job)
5959
# builds them in too. Dev-only: resolver 2 keeps it out of normal builds.
60-
socket-patch-core = { workspace = true, features = ["failpoints"] }
60+
socket-patch-core = { workspace = true, features = ["failpoints", "test-fixtures"] }
6161
sha2 = { workspace = true }
6262
# docker_e2e_vendor_maven's host oracle recomputes the maven2 .jar.sha1 sidecar.
6363
sha1 = { workspace = true }

‎crates/socket-patch-cli/src/args.rs‎

Lines changed: 17 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -161,17 +161,15 @@ pub struct GlobalArgs {
161161
)]
162162
pub download_mode: String,
163163

164-
/// Where `vendor` acquires the installable patched artifact. `auto`
165-
/// (default) downloads the prebuilt archive from the patch.socket.dev
166-
/// vendoring service and silently falls back to a local build on any miss;
167-
/// `service` requires the service and fails closed; `build` always builds
168-
/// locally. Only `vendor` and the vendored modes of `scan`/`get` use
169-
/// this; other subcommands accept it silently.
164+
/// Download installable patched artifacts from the patch service.
165+
/// `service` is the default; `auto` is a compatibility alias. Local
166+
/// artifact building is no longer supported. Healthy committed artifacts
167+
/// can be reused offline; missing or corrupt artifacts require a download.
170168
#[arg(
171169
help_heading = GLOBAL_OPTIONS,
172170
long = "vendor-source",
173171
env = "SOCKET_VENDOR_SOURCE",
174-
default_value = "auto",
172+
default_value = "service",
175173
value_parser = parse_vendor_source,
176174
)]
177175
pub vendor_source: String,
@@ -405,9 +403,9 @@ impl GlobalArgs {
405403
/// empty). The names are validated at parse time, so this is an exact
406404
/// match.
407405
pub(crate) fn ecosystem_selected(&self, eco: Ecosystem) -> bool {
408-
self.ecosystems.as_ref().is_none_or(|list| {
409-
list.is_empty() || list.iter().any(|name| name == eco.cli_name())
410-
})
406+
self.ecosystems
407+
.as_ref()
408+
.is_none_or(|list| list.is_empty() || list.iter().any(|name| name == eco.cli_name()))
411409
}
412410

413411
/// [`Self::ecosystem_selected`] for the ecosystem of `purl`; a purl of
@@ -680,7 +678,7 @@ impl Default for GlobalArgs {
680678
proxy_url: None,
681679
ecosystems: None,
682680
download_mode: "diff".to_string(),
683-
vendor_source: "auto".to_string(),
681+
vendor_source: "service".to_string(),
684682
maven_config: None,
685683
vendor_url: None,
686684
patch_server_url: None,
@@ -937,7 +935,7 @@ mod tests {
937935
assert!(cli.common.ecosystems.is_none());
938936
assert_eq!(cli.common.download_mode, "diff");
939937
assert_eq!(
940-
cli.common.vendor_source, "auto",
938+
cli.common.vendor_source, "service",
941939
"empty SOCKET_VENDOR_SOURCE must fall back to the `auto` default"
942940
);
943941
assert_eq!(cli.common.manifest_path, "keep.json");
@@ -952,7 +950,7 @@ mod tests {
952950
with_clean_socket_env(|| {
953951
// Default when unset.
954952
let cli = TestCli::try_parse_from(["socket-patch"]).unwrap();
955-
assert_eq!(cli.common.vendor_source, "auto");
953+
assert_eq!(cli.common.vendor_source, "service");
956954

957955
// CLI value, case-normalized to the canonical tag.
958956
let cli =
@@ -961,8 +959,7 @@ mod tests {
961959

962960
// Env var honored.
963961
std::env::set_var("SOCKET_VENDOR_SOURCE", "build");
964-
let cli = TestCli::try_parse_from(["socket-patch"]).unwrap();
965-
assert_eq!(cli.common.vendor_source, "build");
962+
assert!(TestCli::try_parse_from(["socket-patch"]).is_err());
966963
std::env::remove_var("SOCKET_VENDOR_SOURCE");
967964

968965
// Garbage is rejected at parse time.
@@ -985,27 +982,20 @@ mod tests {
985982
}
986983
}
987984

988-
/// Regression: scan's vendored flow must build its service config FROM
989-
/// `--vendor-source`, not hardcode build-only. Under the default (`auto`), the config must permit the
990-
/// vendoring service exactly as the `vendor` command's default does —
991-
/// otherwise `scan --mode vendored` silently builds locally while a
992-
/// plain `vendor` service-downloads, and the two commit different bytes /
993-
/// lock integrity for the same patch (lock churn / merge conflicts).
994985
#[test]
995986
fn vendor_service_config_default_source_permits_service() {
996987
let cfg = common_with_source("auto").vendor_service_config(None, false);
997-
assert_eq!(cfg.source, VendorSource::Auto);
988+
assert_eq!(cfg.source, VendorSource::Service);
998989
assert!(
999990
cfg.source.may_use_service(),
1000991
"the default must be able to use the service (matching `vendor`)"
1001992
);
1002-
assert!(!cfg.source.requires_service());
993+
assert!(cfg.source.requires_service());
1003994
assert!(cfg.client.is_none());
1004995
assert!(!cfg.use_public_proxy);
1005996
}
1006997

1007-
/// `--vendor-source service` reaches the fail-closed service path and
1008-
/// `--vendor-source build` never contacts the service.
998+
/// The assembler fails closed even if a caller bypasses argument validation.
1009999
#[test]
10101000
fn vendor_service_config_honors_service_and_build_sources() {
10111001
let cfg = common_with_source("service").vendor_service_config(None, true);
@@ -1017,8 +1007,8 @@ mod tests {
10171007
);
10181008

10191009
let cfg = common_with_source("build").vendor_service_config(None, false);
1020-
assert_eq!(cfg.source, VendorSource::Build);
1021-
assert!(!cfg.source.may_use_service());
1010+
assert_eq!(cfg.source, VendorSource::Service);
1011+
assert!(cfg.source.requires_service());
10221012
}
10231013

10241014
/// The service overrides (`--vendor-url` / `--patch-server-url` /

0 commit comments

Comments
 (0)