Commit 4d5ba3d
fix: correctness bug sweep + hardening tests across crawlers, patch, and vex (#106)
* fix: correctness bug sweep + hardening tests across crawlers, patch, and vex
Fixes a broad set of correctness, security, and atomicity bugs surfaced by
a line-by-line review, each paired with regression tests:
- crawlers: single-quote TOML parsing, case canonicalization, vendor/project
gate ordering, PnP detection, NuGet legacy/local-mode gating, Maven skip-
section boundaries, Python layout/metadata fallbacks
- patch: path-escape guards (cargo/go redirect, rollback, sidecars), atomic
writes for user manifests (go.mod, Cargo.toml, .cargo/config.toml,
package.json, pyproject/requirements), bsdiff header validation, copy_tree
symlink chmod, cow hardlink is_file guard, lock timeout overflow
- vex: single-quote product detection, schema/verify hardening
- api/client: fetch_binary auth error classification, token/slug validation
- misc: purl subpath strip, manifest deterministic serialization, severity
color ordering, cleanup_blobs orphan handling, pth_hook detection fixes
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(ci): green the test/clippy jobs broken by the sweep
Three CI-blocking fixes surfaced by the failing checks (clippy + test on
all OSes + coverage + test-release):
- clippy: `map_or(true, ..)` -> `is_none_or(..)` in manifest/schema.rs
(clippy 1.93 `unnecessary_map_or`, denied via `-D warnings`).
- rollback_dispatch_branch_golang: the sweep added a project-local go
redirect rollback backend. In local mode go rolls back by dropping the
`replace` redirect and leaves the module cache pristine, so it never
restores cache bytes (verified: local mode reports success without
touching the file; global mode genuinely restores). The dispatch test's
byte-restore contract only holds on the in-place/global path — the go
analog of the cargo test's `vendor/` in-place layout — so drive that one
fixture in `--global` mode.
- output_helpers_e2e: the sweep's severity-colour-inversion fix flipped
critical->bright-red(91)/high->red(31) and updated the in-crate unit
tests, but this integration file still asserted the old swapped codes.
cargo test is fail-fast, so it aborted on the golang failure before ever
reaching this binary in CI; surfaced via a local `--no-fail-fast` run.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(test): make manifest-unreadable list test cross-platform
`manifest_path_through_regular_file_reports_unreadable_via_binary` nested
the manifest under a regular file (`<file>/manifest.json`), assuming the OS
rejects the read with a non-absence error. That holds on Unix (ENOTDIR) but
NOT on Windows, where traversing through a file is `ERROR_PATH_NOT_FOUND`
(NotFound) — legitimately classified as `manifest_not_found`, failing the
assertion on windows-latest.
Point the manifest path at a directory instead: reading it fails with a
non-NotFound error on every platform (Unix `IsADirectory`, Windows
`PermissionDenied`), so the "present-but-unreadable → manifest_unreadable"
contract is exercised portably. Renamed accordingly.
This was masked on the first push: cargo test is fail-fast and the Windows
run aborted at this binary (sorts before the now-fixed golang/output tests).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(test): windows path separator in nested-workspace find test
`test_find_recurses_into_nested_workspace` matched walked filesystem paths
with `str::ends_with("packages/inner/package.json")`, which fails on Windows
where `WalkDir` yields `\`-separated paths. Match on the `PathBuf` via
`Path::ends_with`, which compares whole components and accepts `/` in the
pattern on every platform (Windows treats both `/` and `\` as separators).
This is the only walked-real-path assertion that used a forward-slash string
literal; the CLI/manifest path assertions elsewhere operate on
forward-slash-normalized manifest keys (echoed verbatim) and are unaffected.
Surfaced by fail-fast: the Windows run aborted here (socket-patch-core --lib)
only after the previously-fixed cli_parse_list binary passed.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>1 parent b004f6a commit 4d5ba3d
79 files changed
Lines changed: 7832 additions & 331 deletions
File tree
- crates
- socket-patch-cli
- src
- commands
- tests
- socket-patch-core
- src
- api
- cargo_setup
- composer_setup
- crawlers
- gem_setup
- go_setup
- hash
- manifest
- package_json
- patch
- sidecars
- pth_hook
- utils
- vex
- tests
- socket-patch-guard/src
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
578 | 578 | | |
579 | 579 | | |
580 | 580 | | |
| 581 | + | |
| 582 | + | |
| 583 | + | |
| 584 | + | |
| 585 | + | |
| 586 | + | |
| 587 | + | |
| 588 | + | |
| 589 | + | |
| 590 | + | |
| 591 | + | |
| 592 | + | |
| 593 | + | |
| 594 | + | |
| 595 | + | |
| 596 | + | |
| 597 | + | |
| 598 | + | |
| 599 | + | |
| 600 | + | |
| 601 | + | |
| 602 | + | |
| 603 | + | |
| 604 | + | |
| 605 | + | |
| 606 | + | |
| 607 | + | |
| 608 | + | |
| 609 | + | |
| 610 | + | |
| 611 | + | |
| 612 | + | |
| 613 | + | |
| 614 | + | |
| 615 | + | |
| 616 | + | |
| 617 | + | |
| 618 | + | |
| 619 | + | |
| 620 | + | |
| 621 | + | |
| 622 | + | |
| 623 | + | |
| 624 | + | |
| 625 | + | |
| 626 | + | |
| 627 | + | |
| 628 | + | |
| 629 | + | |
| 630 | + | |
| 631 | + | |
| 632 | + | |
| 633 | + | |
| 634 | + | |
| 635 | + | |
| 636 | + | |
| 637 | + | |
| 638 | + | |
| 639 | + | |
| 640 | + | |
| 641 | + | |
| 642 | + | |
| 643 | + | |
| 644 | + | |
| 645 | + | |
| 646 | + | |
| 647 | + | |
| 648 | + | |
| 649 | + | |
| 650 | + | |
| 651 | + | |
| 652 | + | |
| 653 | + | |
| 654 | + | |
| 655 | + | |
| 656 | + | |
| 657 | + | |
| 658 | + | |
| 659 | + | |
| 660 | + | |
| 661 | + | |
| 662 | + | |
581 | 663 | | |
582 | 664 | | |
583 | 665 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1235 | 1235 | | |
1236 | 1236 | | |
1237 | 1237 | | |
| 1238 | + | |
| 1239 | + | |
| 1240 | + | |
| 1241 | + | |
| 1242 | + | |
| 1243 | + | |
| 1244 | + | |
| 1245 | + | |
| 1246 | + | |
| 1247 | + | |
| 1248 | + | |
| 1249 | + | |
| 1250 | + | |
| 1251 | + | |
| 1252 | + | |
| 1253 | + | |
| 1254 | + | |
| 1255 | + | |
| 1256 | + | |
1238 | 1257 | | |
1239 | 1258 | | |
1240 | 1259 | | |
1241 | 1260 | | |
1242 | 1261 | | |
1243 | 1262 | | |
1244 | 1263 | | |
| 1264 | + | |
| 1265 | + | |
| 1266 | + | |
| 1267 | + | |
1245 | 1268 | | |
1246 | | - | |
1247 | | - | |
1248 | | - | |
1249 | | - | |
1250 | | - | |
1251 | | - | |
1252 | | - | |
1253 | | - | |
1254 | | - | |
1255 | | - | |
1256 | | - | |
| 1269 | + | |
| 1270 | + | |
| 1271 | + | |
| 1272 | + | |
| 1273 | + | |
| 1274 | + | |
1257 | 1275 | | |
1258 | 1276 | | |
1259 | 1277 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
103 | 103 | | |
104 | 104 | | |
105 | 105 | | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
106 | 113 | | |
107 | 114 | | |
108 | 115 | | |
| |||
1928 | 1935 | | |
1929 | 1936 | | |
1930 | 1937 | | |
| 1938 | + | |
| 1939 | + | |
| 1940 | + | |
| 1941 | + | |
| 1942 | + | |
| 1943 | + | |
| 1944 | + | |
| 1945 | + | |
| 1946 | + | |
| 1947 | + | |
| 1948 | + | |
| 1949 | + | |
| 1950 | + | |
| 1951 | + | |
| 1952 | + | |
| 1953 | + | |
| 1954 | + | |
| 1955 | + | |
| 1956 | + | |
| 1957 | + | |
| 1958 | + | |
| 1959 | + | |
| 1960 | + | |
| 1961 | + | |
| 1962 | + | |
| 1963 | + | |
| 1964 | + | |
| 1965 | + | |
| 1966 | + | |
| 1967 | + | |
| 1968 | + | |
| 1969 | + | |
| 1970 | + | |
| 1971 | + | |
| 1972 | + | |
| 1973 | + | |
| 1974 | + | |
| 1975 | + | |
| 1976 | + | |
| 1977 | + | |
| 1978 | + | |
| 1979 | + | |
| 1980 | + | |
| 1981 | + | |
| 1982 | + | |
| 1983 | + | |
| 1984 | + | |
| 1985 | + | |
| 1986 | + | |
| 1987 | + | |
| 1988 | + | |
| 1989 | + | |
| 1990 | + | |
| 1991 | + | |
| 1992 | + | |
| 1993 | + | |
| 1994 | + | |
| 1995 | + | |
| 1996 | + | |
| 1997 | + | |
| 1998 | + | |
| 1999 | + | |
| 2000 | + | |
| 2001 | + | |
| 2002 | + | |
| 2003 | + | |
| 2004 | + | |
| 2005 | + | |
| 2006 | + | |
| 2007 | + | |
| 2008 | + | |
| 2009 | + | |
| 2010 | + | |
| 2011 | + | |
| 2012 | + | |
| 2013 | + | |
| 2014 | + | |
| 2015 | + | |
| 2016 | + | |
| 2017 | + | |
| 2018 | + | |
| 2019 | + | |
| 2020 | + | |
| 2021 | + | |
| 2022 | + | |
| 2023 | + | |
| 2024 | + | |
| 2025 | + | |
1931 | 2026 | | |
1932 | 2027 | | |
1933 | 2028 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
96 | 96 | | |
97 | 97 | | |
98 | 98 | | |
99 | | - | |
100 | | - | |
101 | | - | |
102 | | - | |
103 | | - | |
104 | | - | |
105 | | - | |
106 | | - | |
107 | | - | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
108 | 107 | | |
109 | 108 | | |
110 | 109 | | |
| |||
170 | 169 | | |
171 | 170 | | |
172 | 171 | | |
173 | | - | |
174 | | - | |
175 | | - | |
176 | | - | |
177 | | - | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
178 | 182 | | |
179 | 183 | | |
180 | 184 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
104 | 104 | | |
105 | 105 | | |
106 | 106 | | |
107 | | - | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
108 | 115 | | |
109 | 116 | | |
110 | 117 | | |
| |||
192 | 199 | | |
193 | 200 | | |
194 | 201 | | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
195 | 212 | | |
196 | 213 | | |
197 | 214 | | |
| |||
492 | 509 | | |
493 | 510 | | |
494 | 511 | | |
| 512 | + | |
| 513 | + | |
| 514 | + | |
| 515 | + | |
| 516 | + | |
| 517 | + | |
| 518 | + | |
| 519 | + | |
| 520 | + | |
| 521 | + | |
| 522 | + | |
| 523 | + | |
| 524 | + | |
| 525 | + | |
| 526 | + | |
| 527 | + | |
| 528 | + | |
| 529 | + | |
| 530 | + | |
| 531 | + | |
495 | 532 | | |
496 | 533 | | |
497 | 534 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
295 | 295 | | |
296 | 296 | | |
297 | 297 | | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
298 | 308 | | |
299 | | - | |
| 309 | + | |
300 | 310 | | |
301 | 311 | | |
302 | 312 | | |
| |||
0 commit comments