Skip to content

Commit 2e0040f

Browse files
mikolalysenkoclaude
andcommitted
Fix the Maven <3.9.2 tamper probe and Windows snapshot keys (#973)
The host capstone's tamper probe re-resolved against a local repository that step 3 had already warmed with the suffixed artifact, so Maven 3.6 and 3.8 served the cached copy and never re-read the checksumPolicy=fail fallback repository. Drop the cached suffixed version first (a cold re-resolve, as the docker twin and the pre-#973 test do). tree_snapshot keyed files by the OS path, so the planner unit test's removal of .socket/vendor/state.json missed on Windows. Key it with '/'. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
1 parent fa0383c commit 2e0040f

2 files changed

Lines changed: 13 additions & 1 deletion

File tree

‎crates/socket-patch-cli/tests/e2e_vendor_maven_build.rs‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -405,7 +405,15 @@ fn maven_vendor_fresh_checkout_install_and_manifestless_vex() {
405405
// `maven.repo.local.tail` tree, a local repository Maven does not
406406
// checksum, so the tampered jar is what builds; there the gate is the
407407
// committed tree's review and VEX, which never attests it (below).
408+
// A COLD re-resolve: step 3 cached the suffixed artifact in the local
409+
// repository, which Maven serves without re-reading (or re-checksumming)
410+
// any remote, so the cached copy is dropped first. Central's pristine
411+
// 1.10.0 stays warm (it cannot shadow the suffixed version).
408412
std::fs::write(&sidecar, &good_sidecar).unwrap();
413+
let cached = repo_dir(&m2, SV);
414+
if cached.exists() {
415+
std::fs::remove_dir_all(&cached).unwrap();
416+
}
409417
let out = mvn.copy_dependencies(&fresh, &m2, &settings, "target/tamper");
410418
if mvn.numeric() >= vec![3, 9, 2] {
411419
assert!(ok(&out), "{}", dump(&out));

‎crates/socket-patch-core/src/vendor/test_support.rs‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -458,8 +458,12 @@ pub(crate) fn tree_snapshot(root: &Path) -> std::collections::BTreeMap<String, V
458458
if p.is_dir() {
459459
walk(base, &p, out);
460460
} else {
461+
// `/`-separated keys on every OS, so a caller can name one.
461462
out.insert(
462-
p.strip_prefix(base).unwrap().to_string_lossy().into_owned(),
463+
p.strip_prefix(base)
464+
.unwrap()
465+
.to_string_lossy()
466+
.replace('\\', "/"),
463467
std::fs::read(&p).unwrap(),
464468
);
465469
}

0 commit comments

Comments
 (0)