Skip to content

Commit aefbe5f

Browse files
mikolalysenkoclaude
andcommitted
fix(test): extend the hosted gem pin for production's first merged activestorage 6.0.3 patch
`gem_bundler_hosted_install_proof` went red on this branch AND on main (run 34239904191) on 2026-09-08: the server-ranked selection now wires 01019627-b481-4bae-bc09-e93b5a5e4481, which is not in the GEM_UUIDS any-of set. Production published it 2026-09-04T21:23Z as the first MERGED patch — one artifact covering GHSA-w749-p3v6-hccq / CVE-2022-21831, GHSA-r4mg-4433-c7g3 / CVE-2025-24293 and GHSA-xr9x-r78c-5hrm / CVE-2026-66066 — so the merge rung in api::ranking prefers it over the five single-advisory patches. Live-verified before pinning: the served activestorage-6.0.3.gem sha256 matches the registry /info checksum; exactly four files differ from stock rubygems (image_processing_transformer.rb, engine.rb, active_storage.rb, new vips.rb), each carrying the Socket Community Patch header naming this UUID; metadata and every other file are byte-identical. Also refreshes the merge-state canary's doc comment (production now publishes merged patches) and the docs/testing UUID table, which had not been updated for the fifth UUID either. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
1 parent 6eb2e31 commit aefbe5f

2 files changed

Lines changed: 17 additions & 5 deletions

File tree

‎crates/socket-patch-cli/tests/e2e_hosted_production.rs‎

Lines changed: 16 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@
3535
//! |-----------|------|------------|----------|
3636
//! | npm | `pkg:npm/minimist@1.2.2` | `80630680-4da6-45f9-bba8-b888e0ffd58c` | GHSA-xvch-5gv4-984h (CVE-2021-44906) |
3737
//! | PyPI | `pkg:pypi/urllib3@1.26.18` | *any of three* (see [`PYPI_UUIDS`]) | GHSA-gm62-xv2j-4w53 &co |
38-
//! | gem | `pkg:gem/activestorage@6.0.3` | *any of* [`GEM_UUIDS`] (five today) | GHSA-m42x-37p3-fv5w (CVE-2020-8162), GHSA-w749-p3v6-hccq (CVE-2022-21831), GHSA-9xrj-h377-fr87 (CVE-2026-33195), GHSA-r4mg-4433-c7g3 (CVE-2025-24293), GHSA-xr9x-r78c-5hrm (CVE-2026-66066) |
38+
//! | gem | `pkg:gem/activestorage@6.0.3` | *any of* [`GEM_UUIDS`] (six today; the sixth merges three advisories) | GHSA-m42x-37p3-fv5w (CVE-2020-8162), GHSA-w749-p3v6-hccq (CVE-2022-21831), GHSA-9xrj-h377-fr87 (CVE-2026-33195), GHSA-r4mg-4433-c7g3 (CVE-2025-24293), GHSA-xr9x-r78c-5hrm (CVE-2026-66066) |
3939
//!
4040
//! `docs/testing/hosted-production-e2e.md` explains how these were chosen and
4141
//! how to re-pick one if it is ever withdrawn.
@@ -165,6 +165,17 @@ const GEM_UUIDS: &[&str] = &[
165165
// Community Patch header and git-blob-sha256-match their manifest
166166
// afterHash entries.
167167
"9c2b4925-b413-4a3a-bb3a-9990440fb446",
168+
// MERGED patch — the first one production has published for any pinned
169+
// purl: GHSA-w749-p3v6-hccq / CVE-2022-21831 + GHSA-r4mg-4433-c7g3 /
170+
// CVE-2025-24293 + GHSA-xr9x-r78c-5hrm / CVE-2026-66066 in one artifact
171+
// (image_processing_transformer.rb allowlist + unsupported-method guard,
172+
// engine.rb + active_storage.rb config plumbing, NEW vips.rb libvips
173+
// backport). Published 2026-09-04T21:23Z; the server-ranked selection
174+
// (merge rung) now wires this one. Served .gem live-verified 2026-09-08:
175+
// sha256 matches the registry /info checksum, all four touched files
176+
// carry the Socket Community Patch header naming this UUID, metadata and
177+
// every other file are byte-identical to stock rubygems 6.0.3.
178+
"01019627-b481-4bae-bc09-e93b5a5e4481",
168179
];
169180

170181
/// Header the patch service injects into patched npm / PyPI source files.
@@ -778,9 +789,10 @@ async fn preflight_required_patches_are_published() {
778789
/// anywhere.
779790
///
780791
/// This asserts only that the signal EXISTS (every patch names >= 1
781-
/// advisory), never how many. Production publishes no merged patches today —
782-
/// all patches sampled cover exactly one advisory — and the day that changes
783-
/// is not a regression, so a count of >= 2 must not fail this test.
792+
/// advisory), never how many. Production published its first merged patch on
793+
/// 2026-09-04 (the activestorage 6.0.3 artifact covering three advisories,
794+
/// see [`GEM_UUIDS`]); a count of >= 2 is expected, not a regression, and
795+
/// must never fail this test.
784796
#[tokio::test(flavor = "multi_thread")]
785797
#[ignore = "live production API: contacts patches-api.socket.dev. Run with --ignored."]
786798
async fn canary_patches_name_advisories_so_merge_state_is_inferable() {

‎docs/testing/hosted-production-e2e.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ from the child environment.
4040
|-----------|------|------------|----------|---------|
4141
| npm | `pkg:npm/minimist@1.2.2` | `80630680-4da6-45f9-bba8-b888e0ffd58c` | GHSA-xvch-5gv4-984h / CVE-2021-44906 | all five npm-family legs |
4242
| PyPI | `pkg:pypi/urllib3@1.26.18` | `de58c8b8-796c-4b6d-8a48-539b5563db76`, `26242e35-f867-4da8-8789-f0d2ea49e0f1`, `e828efa5-5c6d-43f3-9909-03f5ac232b98` | GHSA-38jv-5279-wg99, GHSA-2xpw-w6gg-jr37, GHSA-gm62-xv2j-4w53 | requirements.txt, uv.lock |
43-
| RubyGems | `pkg:gem/activestorage@6.0.3` | any of `15e960b5-f432-4b6c-b8aa-534a2b419323` (GHSA-m42x-37p3-fv5w / CVE-2020-8162), `6c4141c5-1535-4fd2-9db1-b5f8e4834bdb` (GHSA-w749-p3v6-hccq / CVE-2022-21831, published 2026-08-19), `eeb6bf9f-96c0-4963-a0f1-2e88f91f8b1a` (GHSA-9xrj-h377-fr87 / CVE-2026-33195, published 2026-08-20), `c1a1cd3c-b670-4e44-b4fa-1a63ecd42db6` (GHSA-r4mg-4433-c7g3 / CVE-2025-24293, published 2026-08-20) | see UUID column | bundler leg |
43+
| RubyGems | `pkg:gem/activestorage@6.0.3` | any of `15e960b5-f432-4b6c-b8aa-534a2b419323` (GHSA-m42x-37p3-fv5w / CVE-2020-8162), `6c4141c5-1535-4fd2-9db1-b5f8e4834bdb` (GHSA-w749-p3v6-hccq / CVE-2022-21831, published 2026-08-19), `eeb6bf9f-96c0-4963-a0f1-2e88f91f8b1a` (GHSA-9xrj-h377-fr87 / CVE-2026-33195, published 2026-08-20), `c1a1cd3c-b670-4e44-b4fa-1a63ecd42db6` (GHSA-r4mg-4433-c7g3 / CVE-2025-24293, published 2026-08-20), `9c2b4925-b413-4a3a-bb3a-9990440fb446` (GHSA-xr9x-r78c-5hrm / CVE-2026-66066, published 2026-08-21), `01019627-b481-4bae-bc09-e93b5a5e4481` (MERGED: CVE-2022-21831 + CVE-2025-24293 + CVE-2026-66066, published 2026-09-04) | see UUID column | bundler leg |
4444

4545
urllib3 1.26.18 carries **three** distinct free patches, one per advisory. Which
4646
one the resolver returns is a server-side ordering detail, so the suite accepts

0 commit comments

Comments
 (0)