Skip to content

Commit beb7629

Browse files
committed
Merge release/v5-prerelease (#280 ledger-free hosted) into v5/remove-setup-and-ui
Conflicts resolved toward #280's model: no hosted ledger, rollback/remove/ vendor restore hosted pins via patch::redirect::upstream. This branch's changes stay on top: `setup` removed, human text says "hosted" and drops warning codes, one numbered Next steps block, empty `list` exits 0 (the contested-wiring error from #280 still exits 1), shared cancel line. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj
2 parents c4f3625 + 686e5fb commit beb7629

191 files changed

Lines changed: 23305 additions & 21282 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.gitattributes‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,13 @@ crates/socket-patch-core/tests/fixtures/redirect/** -text
66

77
crates/socket-patch-core/tests/fixtures/pdm-native/*.lock -text
88

9+
# Poetry and Pipenv locks are real `poetry lock` / `pipenv lock` output: the
10+
# upstream restore and VEX tests round-trip them byte for byte and derive
11+
# their CRLF variants from the LF bytes themselves.
12+
crates/socket-patch-core/tests/fixtures/poetry/** -text
13+
crates/socket-patch-core/tests/fixtures/pipenv/** -text
14+
crates/socket-patch-core/tests/fixtures/pipenv-shapes/** -text
15+
916
# The captured pnpm 1-12 locks are byte-real: the hosted/vendored rewriters
1017
# refuse CRLF by design (vendor_lockfile_crlf_unsupported), and the tests
1118
# derive their CRLF variants from the LF bytes themselves.

‎.github/workflows/ci.yml‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -215,7 +215,9 @@ jobs:
215215
matrix:
216216
os: [ubuntu-latest, macos-latest, windows-latest]
217217
runs-on: ${{ matrix.os }}
218-
timeout-minutes: 35
218+
# Windows runs the same suite ~1.6x slower than macOS: on the base
219+
# branch it already took 34m40s of a flat 35m budget.
220+
timeout-minutes: ${{ matrix.os == 'windows-latest' && 50 || 35 }}
219221
steps:
220222
- name: Checkout
221223
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

‎CHANGELOG.md‎

Lines changed: 211 additions & 39 deletions
Large diffs are not rendered by default.

‎README.md‎

Lines changed: 137 additions & 86 deletions
Large diffs are not rendered by default.

‎crates/socket-patch-cli/CLI_CONTRACT.md‎

Lines changed: 149 additions & 124 deletions
Large diffs are not rendered by default.

‎crates/socket-patch-cli/src/args.rs‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -427,7 +427,7 @@ impl GlobalArgs {
427427
}
428428

429429
/// The project root whose `.socket/` state stores — manifest, vendor
430-
/// ledger, redirect ledger — belong together: the RESOLVED manifest's
430+
/// ledger — belong together: the RESOLVED manifest's
431431
/// directory, stepping out of a standard `.socket/` layout when the
432432
/// manifest lives in one. For the default `<cwd>/.socket/manifest.json`
433433
/// this is exactly `cwd`; for a `--manifest-path` into another project

‎crates/socket-patch-cli/src/commands/get.rs‎

Lines changed: 29 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -541,8 +541,8 @@ pub struct GetArgs {
541541
/// [default: hosted; agent with `--save-only` or `--global`]
542542
// agent = record in .socket/manifest.json + blobs and apply in place;
543543
// hosted = rewrite lockfiles so the patched deps resolve to Socket's
544-
// hosted patch server (no manifest, no blobs; state lives in the
545-
// redirect ledger); vendored = commit patched artifacts under
544+
// hosted patch server (no manifest, no blobs, no ledger: the lockfile
545+
// is the record); vendored = commit patched artifacts under
546546
// .socket/vendor/ and rewire the lockfile (no manifest, no blobs; the
547547
// vendor ledger carries the records). Hosted/vendored runs produce the
548548
// same on-disk result as `scan --mode hosted|vendored` selecting the
@@ -1218,6 +1218,9 @@ pub struct DownloadParams {
12181218
/// `false`: their patch content is staged in memory and the committed
12191219
/// artifact is the patch — nothing should land in `.socket/blobs`.
12201220
pub persist_blobs: bool,
1221+
/// `--patch-server-url`: the extra origin whose URLs count as hosted
1222+
/// when lockfile discovery reads the project's hosted pins.
1223+
pub patch_server_url: Option<String>,
12211224
}
12221225

12231226
impl DownloadParams {
@@ -1847,10 +1850,9 @@ type LockRefusals = HashMap<String, (&'static str, String)>;
18471850
/// classic / yarn berry gates and cargo's locked-version gate), over the
18481851
/// patches the phase would otherwise fetch a view for — past the Bun
18491852
/// refusal and the ledger's idempotency skip, which take precedence in the
1850-
/// fetch loop. A purl the hosted redirect ledger claims is left to the
1851-
/// vendor loop: its takeover reverts the hosted lock edits first, and the
1852-
/// revert rewrites the very text the gates read. A redirect ledger that
1853-
/// cannot be read leaves every purl to the loop.
1853+
/// fetch loop. A purl the lockfiles pin hosted is left to the vendor loop:
1854+
/// its takeover restores the upstream lock entry first, and the restore
1855+
/// rewrites the very text the gates read.
18541856
///
18551857
/// Only a package the vendor loop would hand to its backend is refused
18561858
/// here (see [`crate::commands::vendor::lock_refusals_reaching_backend`]):
@@ -1868,11 +1870,23 @@ async fn lock_text_refusals_for(
18681870
) -> LockRefusals {
18691871
let cwd = params.cwd.as_path();
18701872
let claimed: Vec<String> =
1871-
match socket_patch_core::patch::redirect::load_redirect_state(cwd).await {
1872-
Ok(Some(state)) => state.records.keys().map(|k| canonical_purl(k)).collect(),
1873-
Ok(None) => Vec::new(),
1874-
Err(_) => return HashMap::new(),
1875-
};
1873+
socket_patch_core::patch::redirect::upstream::HostedPin::all(
1874+
&socket_patch_core::vex::discover_patched_refs_with(
1875+
cwd,
1876+
&socket_patch_core::vex::DiscoverOptions {
1877+
patch_server_origins: params
1878+
.patch_server_url
1879+
.iter()
1880+
.filter(|url| !url.trim().is_empty())
1881+
.cloned()
1882+
.collect(),
1883+
},
1884+
)
1885+
.await,
1886+
)
1887+
.into_iter()
1888+
.map(|pin| canonical_purl(&pin.purl))
1889+
.collect();
18761890
let candidates: Vec<(&str, &str)> = selected
18771891
.iter()
18781892
.filter(|sr| bun_refusal.filter(|r| r.applies_to(&sr.purl)).is_none())
@@ -3669,12 +3683,13 @@ fn get_download_params(args: &GetArgs, save_only: bool, persist_blobs: bool) ->
36693683
strict: args.common.strict,
36703684
ecosystems: args.common.ecosystems.clone(),
36713685
persist_blobs,
3686+
patch_server_url: args.common.patch_server_url.clone(),
36723687
}
36733688
}
36743689

36753690
/// `get … --mode hosted`: hand the selected (purl, uuid) pairs to scan's
36763691
/// hosted engine ([`super::scan::boxed_run_redirect_selected`]) — lockfile
3677-
/// rewrite + redirect ledger, no manifest, no blobs — so the on-disk result
3692+
/// rewrite only, no manifest, no blobs, no ledger — so the on-disk result
36783693
/// matches `scan --mode hosted` selecting the same patches. The engine owns
36793694
/// all output (and honors `--dry-run` internally); in JSON mode it nests its
36803695
/// `redirect` block into the get base envelope passed as `scan_result`.
@@ -5229,6 +5244,7 @@ mod tests {
52295244
strict: false,
52305245
ecosystems: None,
52315246
persist_blobs: false,
5247+
patch_server_url: None,
52325248
}
52335249
}
52345250

@@ -5875,6 +5891,7 @@ mod tests {
58755891
ecosystems: None,
58765892
// The vendor-detached posture this fn exists for.
58775893
persist_blobs: false,
5894+
patch_server_url: None,
58785895
}
58795896
}
58805897

0 commit comments

Comments
 (0)