Skip to content

Commit 907de9c

Browse files
committed
Merge release/v5-prerelease (#283) into v5/one-hosted-engine
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KHZ8uzdXfkG2zH8ZYDG8ju
2 parents 4cabaf1 + 06437d2 commit 907de9c

36 files changed

Lines changed: 2855 additions & 6341 deletions

‎.github/workflows/bun-compatibility.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@ on:
4343
- 'crates/socket-patch-cli/src/commands/scan/**'
4444
- 'crates/socket-patch-cli/src/commands/rollback.rs'
4545
- 'crates/socket-patch-cli/src/commands/vendor.rs'
46-
- 'crates/socket-patch-cli/src/commands/repair_vendor.rs'
46+
- 'crates/socket-patch-cli/src/commands/vendored_backend/**'
4747
- 'crates/socket-patch-cli/src/commands/remove.rs'
4848
# Main runs are the only rust-cache writers (save-if below), so a
4949
# path-filtered push trigger is what seeds the cache the PR builds restore
@@ -75,7 +75,7 @@ on:
7575
- 'crates/socket-patch-cli/src/commands/scan/**'
7676
- 'crates/socket-patch-cli/src/commands/rollback.rs'
7777
- 'crates/socket-patch-cli/src/commands/vendor.rs'
78-
- 'crates/socket-patch-cli/src/commands/repair_vendor.rs'
78+
- 'crates/socket-patch-cli/src/commands/vendored_backend/**'
7979
- 'crates/socket-patch-cli/src/commands/remove.rs'
8080
workflow_dispatch:
8181
inputs:

‎.github/workflows/vlt-compatibility.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ on:
3737
- 'crates/socket-patch-cli/src/commands/remove.rs'
3838
- 'crates/socket-patch-cli/src/commands/setup.rs'
3939
- 'crates/socket-patch-cli/src/commands/vendor.rs'
40-
- 'crates/socket-patch-cli/src/commands/repair_vendor.rs'
40+
- 'crates/socket-patch-cli/src/commands/vendored_backend/**'
4141
- 'crates/socket-patch-cli/src/commands/get.rs'
4242
- 'crates/socket-patch-cli/src/commands/vlt_preflight.rs'
4343
- 'crates/socket-patch-cli/src/commands/scan/**'
@@ -74,7 +74,7 @@ on:
7474
- 'crates/socket-patch-cli/src/commands/remove.rs'
7575
- 'crates/socket-patch-cli/src/commands/setup.rs'
7676
- 'crates/socket-patch-cli/src/commands/vendor.rs'
77-
- 'crates/socket-patch-cli/src/commands/repair_vendor.rs'
77+
- 'crates/socket-patch-cli/src/commands/vendored_backend/**'
7878
- 'crates/socket-patch-cli/src/commands/get.rs'
7979
- 'crates/socket-patch-cli/src/commands/vlt_preflight.rs'
8080
- 'crates/socket-patch-cli/src/commands/scan/**'

‎CHANGELOG.md‎

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -226,6 +226,30 @@ into the new version's section — see docs/releasing.md.
226226
(`https://repo.packagist.org`) and `SOCKET_NUGET_URL`
227227
(`https://api.nuget.org`).
228228

229+
- **`repair` no longer rebuilds the vendor ledger from lockfiles.** A
230+
lockfile that references `.socket/vendor/<eco>/<uuid>/` with no entry in
231+
`.socket/vendor/state.json` now fails with `vendor_ledger_missing` (an
232+
artifact-level `failed` event with `uuid` and `details.{ecosystem,path}`;
233+
exit 1) instead of re-synthesizing the entry (`details.ledgerRestored` is
234+
gone). The rewired lockfile cannot supply the pre-vendor originals a
235+
revert needs, so the remedy is restoring `state.json` from version
236+
control (or `git checkout -- <lockfile>` and re-vendoring). The unverified
237+
npm "rebuild from the wired integrity" rung and the gem Gemfile wiring
238+
reconstruction went with it; `rollback`'s missing-ledger error now asks
239+
for `state.json` to be restored instead of naming `repair`.
240+
- **`repair` re-vendors broken artifacts the way `vendor` does.** Missing
241+
or corrupt vendored artifacts go through the same vendored backend as
242+
`vendor` / `scan --mode vendored` / `get --mode vendored`, so under the
243+
default `--vendor-source auto` the patch service's prebuilt artifact is
244+
downloaded again, with a local build as the fallback (and the only
245+
source under `--offline` / `--vendor-source build`). The result is still
246+
verified against the ledger fingerprint before it counts as `rebuilt`.
247+
Failure details are now `vendor`'s own (for example "no installed
248+
package found on disk"), and a drifted installed copy of a gem or pypi
249+
release variant is no longer force-overwritten by repair — it fails the
250+
same installed-variant check `vendor` applies. Internally, `vendor`, `scan`/`get --mode vendored`, `vendor --revert`,
251+
`rollback`'s vendored leg, `remove` and `repair` now share one
252+
`VendoredBackend { apply, revert, repair }`.
229253
- **Vendored runs refuse lock-text failures before downloading them.**
230254
`scan --mode vendored` and `get --mode vendored` evaluate the vendor
231255
backends' pure lock-text gates — pnpm, yarn classic and yarn berry

‎README.md‎

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -476,7 +476,7 @@ need the network and refuse to run with `--offline`.
476476
| [`remove`](#remove) | The single-patch form of `rollback`: restore, unwind, drop the record and GC for one PURL/UUID (a hosted patch is restored to upstream) |
477477
| [`vendor --revert`](#vendor) | **Un-vendors wholesale**: restores the recorded original lockfile fragments byte-for-byte and removes the `.socket/vendor/` artifacts (a package vendored over a hosted pin returns to upstream, not to hosted) |
478478
| [`scan --prune`](#scan) | Agent mode: **reconciles, doesn't reverse** — drops manifest entries for packages that have left the project and garbage-collects orphan blob/diff/archive files |
479-
| [`repair`](#repair) (alias `gc`) | **Restores health, not originals**: re-downloads missing blobs, rebuilds missing/corrupt vendored artifacts, and cleans up unused ones |
479+
| [`repair`](#repair) (alias `gc`) | **Restores health, not originals**: re-downloads missing blobs, re-vendors missing/corrupt vendored artifacts, and cleans up unused ones |
480480
481481
And `setup --remove` reverts the install hooks that `setup` added.
482482
@@ -497,7 +497,7 @@ And `setup --remove` reverts the install hooks that `setup` added.
497497
| [`setup`](#setup) | Wire install hooks (npm, Python, Bundler, Composer) that re-apply patches after install |
498498
| [`rollback`](#rollback) | Undo patches in every mode: restore original files, unwind vendored lockfile wiring, and restore hosted lockfile entries to upstream |
499499
| [`remove`](#remove) | Remove one patch by PURL or UUID (rolls back first) |
500-
| [`repair`](#repair) | Download missing patch artifacts, rebuild vendored artifacts, clean up unused ones (alias: `gc`) |
500+
| [`repair`](#repair) | Download missing patch artifacts, re-vendor broken vendored artifacts, clean up unused ones (alias: `gc`) |
501501
502502
`socket-patch --update` updates the CLI itself (see [Updating](#updating)).
503503
@@ -1215,14 +1215,18 @@ socket-patch remove "pkg:npm/lodash@4.17.20" --json
12151215
12161216
### `repair`
12171217
1218-
Download missing blobs, rebuild missing or corrupt vendored artifacts, and clean up unused
1218+
Download missing blobs, re-vendor missing or corrupt vendored artifacts, and clean up unused
12191219
blobs.
12201220
12211221
Alias: `gc`
12221222
12231223
`repair` cleans up the `.socket/` directory without running a scan — useful when you've
12241224
manually adjusted the manifest, recovered from a partial-failure state, or just want to
1225-
free space. It also rebuilds missing or corrupt vendored artifacts. For the combined
1225+
free space. It also re-vendors missing or corrupt vendored artifacts the same way `vendor`
1226+
does (the patch service's prebuilt artifact first, a local build as the fallback), checked
1227+
against `.socket/vendor/state.json`. `repair` does not recreate a lost `state.json`: if a
1228+
lockfile points into `.socket/vendor/` and the ledger has no entry for it, `repair` fails with
1229+
`vendor_ledger_missing` — restore `state.json` from version control. For the combined
12261230
agent-mode workflow (discover + apply + GC in one pass), use `scan --sync` instead.
12271231
12281232
Like every other mutating command, `repair` takes the `.socket/apply.lock` advisory lock

0 commit comments

Comments
 (0)