Commit 40957fb
Require server artifacts and exact redownload for vendoring (#300)
* Require server artifacts for vendoring
Download verified complete packages instead of rebuilding archives from
installed files, patch blobs, or registry sources. Repair damaged vendor
copies from the exact recorded server artifact without changing lockfile
or ledger identity.
Retain the N-API crate and hosted in-memory patch application engine for
the GitHub App. Consume server-provided upstream Yarn Berry checksums and
preserve the latest v5 Maven reactor and Gradle support.
Assisted-by: Codex:GPT-6
* Align vendoring coverage and lint metadata
Regenerate the vlt matrix after replacing its local-build leg with the
service alias. Remove orphaned builder documentation and retain the
existing backend argument style for Python distribution downloads.
Assisted-by: Codex:gpt-6-astra
* Serve artifacts in native Bun compatibility tests
Use fixture grants for fresh vendoring and redownload repairs. Match the
installed npm version when building fixture archives so a workspace's
different top-level version cannot replace its nested dependency.
Assisted-by: Codex:gpt-6-astra
* Fix download-based vendoring CI and repair
Exercise served artifacts across the package-manager fixtures while
preserving cold-cache offline install and revert coverage. Repair keeps
Bun lockfiles and artifact identities unchanged.
Record complete Composer inventories after filter normalization, and
use the shared service policy for archive and Go redownload failures.
Assisted-by: Codex:gpt-6-astra
* Assert exact Composer redownload in capstone
Check that restoring modified filter files preserves the complete
artifact inventory, lockfile, and ledger without in-place healing.
Assisted-by: Codex:gpt-6-astra
* Fix: Record file inventory for Composer vendor artifacts (#323)
Composer vendors now compute and persist file_inventory at vendor time,
matching the behavior of Cargo, Go, gem, and vlt. This enables directory
repair and same-UUID vendor restore for Composer packages, preventing
redownload::restore from failing on missing inventory data.
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>1 parent ae775fb commit 40957fb
190 files changed
Lines changed: 7803 additions & 17303 deletions
File tree
- crates
- socket-patch-cli
- src
- commands
- scan
- vendored_backend
- tests
- common
- docker_vendor_common
- e2e_vex_build
- e2e_vex_lockfile
- get
- in_process_vendor_bun_takeover
- in_process_vendor
- prebuilt_common
- repair
- scan
- vendor_ecosystem_fixtures
- vendor
- vex_e2e_common
- vex_pdm_hatch_common
- vex_pipenv_pip_common
- vex_pipenv_pip_real
- vex_pypi_real_common
- vlt_hosted_common
- vlt_vendor_common
- socket-patch-core
- src
- api
- patch
- redirect
- upstream
- sidecars
- utils
- vendor
- composer_lock
- jvm
- fixtures/repack
- lock_inventory
- test_support
- vex
- tests
- docs
- design
- testing
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Large diffs are not rendered by default.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
57 | 57 | | |
58 | 58 | | |
59 | 59 | | |
60 | | - | |
| 60 | + | |
61 | 61 | | |
62 | 62 | | |
63 | 63 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
161 | 161 | | |
162 | 162 | | |
163 | 163 | | |
164 | | - | |
165 | | - | |
166 | | - | |
167 | | - | |
168 | | - | |
169 | | - | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
170 | 168 | | |
171 | 169 | | |
172 | 170 | | |
173 | 171 | | |
174 | | - | |
| 172 | + | |
175 | 173 | | |
176 | 174 | | |
177 | 175 | | |
| |||
405 | 403 | | |
406 | 404 | | |
407 | 405 | | |
408 | | - | |
409 | | - | |
410 | | - | |
| 406 | + | |
| 407 | + | |
| 408 | + | |
411 | 409 | | |
412 | 410 | | |
413 | 411 | | |
| |||
680 | 678 | | |
681 | 679 | | |
682 | 680 | | |
683 | | - | |
| 681 | + | |
684 | 682 | | |
685 | 683 | | |
686 | 684 | | |
| |||
937 | 935 | | |
938 | 936 | | |
939 | 937 | | |
940 | | - | |
| 938 | + | |
941 | 939 | | |
942 | 940 | | |
943 | 941 | | |
| |||
952 | 950 | | |
953 | 951 | | |
954 | 952 | | |
955 | | - | |
| 953 | + | |
956 | 954 | | |
957 | 955 | | |
958 | 956 | | |
| |||
961 | 959 | | |
962 | 960 | | |
963 | 961 | | |
964 | | - | |
965 | | - | |
| 962 | + | |
966 | 963 | | |
967 | 964 | | |
968 | 965 | | |
| |||
985 | 982 | | |
986 | 983 | | |
987 | 984 | | |
988 | | - | |
989 | | - | |
990 | | - | |
991 | | - | |
992 | | - | |
993 | | - | |
994 | 985 | | |
995 | 986 | | |
996 | 987 | | |
997 | | - | |
| 988 | + | |
998 | 989 | | |
999 | 990 | | |
1000 | 991 | | |
1001 | 992 | | |
1002 | | - | |
| 993 | + | |
1003 | 994 | | |
1004 | 995 | | |
1005 | 996 | | |
1006 | 997 | | |
1007 | | - | |
1008 | | - | |
| 998 | + | |
1009 | 999 | | |
1010 | 1000 | | |
1011 | 1001 | | |
| |||
1017 | 1007 | | |
1018 | 1008 | | |
1019 | 1009 | | |
1020 | | - | |
1021 | | - | |
| 1010 | + | |
| 1011 | + | |
1022 | 1012 | | |
1023 | 1013 | | |
1024 | 1014 | | |
| |||
0 commit comments