Repository navigation
Commit e2d9633
* Start fix for #749, #751
Assisted-by: Claude Code:claude-opus-5-5
* Follow the gem lock and twin Bundler loads
Hosted mode wired the wrong gem files in two Bundler layouts, so the
scan reported success (and its VEX attested a patch) while Bundler
installed the unpatched gem or frozen installs failed:
- Bundler 4's custom lockfile (BUNDLE_LOCKFILE, env or .bundle/config)
was ignored, so the lock Bundler reads was never pinned (#749). A
lockfile naming anything but the pair's own default lock is now
refused in hosted (redirect_gem_bundle_lockfile_unsupported) and
vendored (gemfile_not_loaded) mode before any write.
- A Gemfile + gems.rb twin always followed Bundler >= 2 and wired
gems.rb, but Bundler 1.x loads the Gemfile (#751). A twin whose locks
say BUNDLED WITH 1.x is now wired through the Gemfile pair, and twin
locks that disagree on the major are refused
(redirect_gem_twin_bundler_versions_diverge).
Assisted-by: Claude Code:claude-opus-5-5
* Add real-Bundler e2e for custom lock and twins
Two host capstones in e2e_redirect_gem_build: a Bundler 4 project with
`lockfile custom.lock` (and a leftover Gemfile.lock) redirects and
attests nothing and still installs frozen (#749), and a Bundler 1.x
Gemfile + gems.rb twin is wired through the Gemfile and a fresh
checkout installs the patched gem (#751). Each skips on the Bundler
line it does not apply to.
Assisted-by: Claude Code:claude-opus-5-5
* Drop CHANGELOG entry from this PR
Release notes are written when a release is cut, from the merged PR
log and the code, so PRs no longer edit CHANGELOG.md.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* Fix vex alias tests broken by store-copy merge
#605 taught the name-keyed npm resolver to probe bundled store
trees, so it now finds aliased copies (node_modules/lp) and a nested
host's store peers itself. Two vex_consumed tests from #738 assumed
that set never held aliases, so main's CI went red after both merged.
The tests now feed the alias-free set explicitly to keep covering
alias expansion, and also check the resolver's own set reaches the
same copies with no duplicates. No production code changes.
Assisted-by: Claude Code:claude-opus-5-5
(cherry picked from commit 40dac07)
* Report gem locks socket-patch cannot read
Lock inventory reads only the lock bundler loads (#736), so a custom
BUNDLE_LOCKFILE, an unsupported BUNDLE_GEMFILE or a Gemfile + gems.rb
twin whose locks disagree on the bundler major left a lockfile-only
scan with no gem entries and no warning: the per-candidate redirect
refusals never ran because there were no gem candidates. Surface the
reason as a gem_lock_unsupported diagnosis on the inventory's existing
layout-refusal channel, which scan and the in-memory engine already
turn into run-level warnings.
An empty BUNDLE_LOCKFILE now shadows the tiers below it, as
Settings#[] does, instead of letting a global custom lock through.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018ULgrJMQMWEBAsiuprY449
* Port #878's digest-helper fix to unbreak coverage
utils::digest's production_digests_go_through_the_helpers fails on
main: three Gradle/JVM files compute digests inline. That makes
`coverage`, `test` and `test-release` red on every PR. #878 routes
them through utils::digest. This is the same change, ported so this
PR's CI is green. It becomes a no-op once #878 lands.
Claude-Session: https://claude.ai/code/session_01LS9AJhpVngXZxng8TRA2Kd
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 4d8cad2)
* Drop stale entries from the digest pending list
The digest guard test is red on main: #955 added
crawlers/gradle_cache.rs, patch/jvm_jar.rs and
patch/sidecars/maven.rs to the pending list, and #690 had already
moved them onto the utils::digest helpers. This ports the same
three-line change as #1016, so it becomes a no-op once #1016 lands.
(cherry picked from commit d65c5c4)
* Refuse an absolute BUNDLE_LOCKFILE on a memory view
The hosted memory engine has no real project root, so it anchored the
BUNDLE_LOCKFILE identity check at `/`. An absolute `/Gemfile.lock` (or
`/gems.locked` beside a gems.rb) then compared equal to the in-project
pair's lock, and the pair was rewritten and confirmed. Bundler opens an
absolute lockfile as is, never the project's own lock, so that confirmed
a pin frozen installs never read. The disk path already refuses it,
because it anchors at the real root.
A rooted BUNDLE_LOCKFILE on a memory view is now
UnsupportedLockfile (redirect_gem_bundle_lockfile_unsupported), like any
other foreign lock.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018ULgrJMQMWEBAsiuprY449
* Refuse every Gemfile + gems.rb twin instead of trusting BUNDLED WITH
#751's fix picked a twin's pair from the locks' BUNDLED WITH: all 1.x
meant the Gemfile pair, otherwise gems.rb. But BUNDLED WITH records
which bundler wrote a lock, not which one installs it. Bundler chooses
the twin's spelling from the running major: 1.x loads the Gemfile,
>= 2 loads gems.rb. So bundler >= 2 installing a 1.x-stamped twin, or
1.x installing a 2.x-stamped one, read the pair the scan never pinned,
while the run (and its VEX) reported the gem redirected. Lock inventory
and VEX discovery used the same selector.
Nothing a scan can read says which bundler runs, so a twin under
default discovery is now refused everywhere, the way vendored mode
already refuses it:
- hosted mode: redirect_gem_twin_manifest_ambiguous (replaces the
unreleased redirect_gem_twin_bundler_versions_diverge), nothing
written or attested;
- lock readers (lock inventory, VEX discovery): no lock, with the
gem_lock_unsupported diagnosis.
BUNDLE_GEMFILE naming either spelling still selects that pair, and a
lone Gemfile or gems.rb pair is unchanged. The BUNDLED WITH parser
this PR added is gone.
Tests: the engine, lock-inventory and hosted_memory_engine twin tests
now expect the refusal for 1.x, 2.x and mixed stamps. #431's
default_discovery_still_prefers_gems_rb now covers a lone gems.rb. The
real-Bundler e2e (gem_hosted_twin_redirects_nothing) runs on every
bundler line and checks the untouched twin still installs frozen.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018ULgrJMQMWEBAsiuprY449
* Count gems.rb only when it is a regular file for BUNDLE_LOCKFILE
The disk path decided whether the project holds a gems.rb with
symlink_metadata().is_ok(), so a directory or a dangling symlink named
gems.rb made gems.locked the "pair's own lock". BUNDLE_LOCKFILE:
gems.locked then passed as a no-op, and Gemfile.lock was rewritten and
attested while bundler 4 (whose File.file? ignores that gems.rb)
installed from gems.locked.
Use the same predicate as Bundler's File.file? and the lock readers'
ProjectView::is_file: a regular file, through symlinks.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018ULgrJMQMWEBAsiuprY449
* Label the setup-php pin in ci.yml with its tag
Upstream moved setup-php's v2 tag, so the "# v2" comment on the
2.37.2 commit pin now fails the Audit GitHub Actions check
(ref-version-mismatch). Same change as #1118.
Assisted-by: Claude Code:claude-opus-5-5
* Refuse a gem twin even if one spelling is unread
A Gemfile + gems.rb twin whose other spelling is a symlink, an
unreadable file or not UTF-8 was not seen as a twin by hosted mode,
so the readable pair was still pinned although Bundler 2+ loads
gems.rb. Lock inventory already counted such a twin and warned
gem_lock_unsupported, so the scan both warned and rewrote. The twin
check now counts every spelling Bundler sees, readable or not.
Found by Bugbot on #768.
Assisted-by: Claude Code:claude-opus-5-5
* Count an unreadable on-disk twin spelling too
A Gemfile + gems.rb twin whose second spelling is a regular file the
scan cannot read (permission denied, I/O error) left no trace in the
read lists, so hosted mode still pinned the readable pair. The twin
check now also asks the project view whether the file exists, the
same File.file? test lock inventory uses.
Found by Bugbot on #768.
Assisted-by: Claude Code:claude-opus-5-5
* Treat a symlinked twin spelling as present
Hosted file-set scans see a git symlink Gemfile or gems.rb as a
symlink marker with no target. Lock inventory took that as absent, so
a Gemfile + gems.rb twin was inventoried from the regular spelling's
lock with no gem_lock_unsupported warning, although Bundler follows
the link and may load the other pair. The twin check now fails closed
on a symlinked spelling.
Found by the security review on #768.
Assisted-by: Claude Code:claude-opus-5-5
---------
Co-authored-by: Claude <noreply@anthropic.com>
1 parent 18c5f81 commit e2d9633
12 files changed
Lines changed: 1248 additions & 81 deletions
File tree
- crates
- socket-patch-cli
- tests
- socket-patch-core/src
- crawlers
- formats/gem
- hosted
- vendor
- lock_inventory
- vex/discover
- docs
Large diffs are not rendered by default.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
457 | 457 | | |
458 | 458 | | |
459 | 459 | | |
| 460 | + | |
| 461 | + | |
| 462 | + | |
| 463 | + | |
| 464 | + | |
| 465 | + | |
| 466 | + | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
460 | 471 | | |
461 | 472 | | |
462 | 473 | | |
| |||
508 | 519 | | |
509 | 520 | | |
510 | 521 | | |
| 522 | + | |
| 523 | + | |
511 | 524 | | |
512 | 525 | | |
513 | 526 | | |
| |||
622 | 635 | | |
623 | 636 | | |
624 | 637 | | |
| 638 | + | |
| 639 | + | |
| 640 | + | |
| 641 | + | |
| 642 | + | |
| 643 | + | |
| 644 | + | |
| 645 | + | |
| 646 | + | |
| 647 | + | |
| 648 | + | |
| 649 | + | |
| 650 | + | |
| 651 | + | |
625 | 652 | | |
626 | 653 | | |
627 | 654 | | |
| |||
975 | 1002 | | |
976 | 1003 | | |
977 | 1004 | | |
| 1005 | + | |
| 1006 | + | |
| 1007 | + | |
| 1008 | + | |
| 1009 | + | |
| 1010 | + | |
| 1011 | + | |
| 1012 | + | |
| 1013 | + | |
| 1014 | + | |
| 1015 | + | |
| 1016 | + | |
| 1017 | + | |
| 1018 | + | |
| 1019 | + | |
| 1020 | + | |
| 1021 | + | |
| 1022 | + | |
| 1023 | + | |
| 1024 | + | |
| 1025 | + | |
978 | 1026 | | |
979 | 1027 | | |
980 | 1028 | | |
| |||
1007 | 1055 | | |
1008 | 1056 | | |
1009 | 1057 | | |
| 1058 | + | |
| 1059 | + | |
1010 | 1060 | | |
1011 | 1061 | | |
1012 | 1062 | | |
| |||
1082 | 1132 | | |
1083 | 1133 | | |
1084 | 1134 | | |
| 1135 | + | |
| 1136 | + | |
| 1137 | + | |
| 1138 | + | |
| 1139 | + | |
| 1140 | + | |
| 1141 | + | |
| 1142 | + | |
| 1143 | + | |
| 1144 | + | |
| 1145 | + | |
| 1146 | + | |
| 1147 | + | |
| 1148 | + | |
| 1149 | + | |
| 1150 | + | |
| 1151 | + | |
| 1152 | + | |
| 1153 | + | |
| 1154 | + | |
| 1155 | + | |
| 1156 | + | |
| 1157 | + | |
| 1158 | + | |
| 1159 | + | |
| 1160 | + | |
| 1161 | + | |
| 1162 | + | |
| 1163 | + | |
1085 | 1164 | | |
1086 | 1165 | | |
1087 | 1166 | | |
| |||
1194 | 1273 | | |
1195 | 1274 | | |
1196 | 1275 | | |
| 1276 | + | |
| 1277 | + | |
1197 | 1278 | | |
1198 | 1279 | | |
1199 | 1280 | | |
| |||
1306 | 1387 | | |
1307 | 1388 | | |
1308 | 1389 | | |
| 1390 | + | |
| 1391 | + | |
| 1392 | + | |
| 1393 | + | |
| 1394 | + | |
| 1395 | + | |
| 1396 | + | |
| 1397 | + | |
| 1398 | + | |
| 1399 | + | |
| 1400 | + | |
| 1401 | + | |
| 1402 | + | |
| 1403 | + | |
| 1404 | + | |
| 1405 | + | |
| 1406 | + | |
| 1407 | + | |
| 1408 | + | |
| 1409 | + | |
| 1410 | + | |
| 1411 | + | |
| 1412 | + | |
| 1413 | + | |
| 1414 | + | |
| 1415 | + | |
| 1416 | + | |
| 1417 | + | |
| 1418 | + | |
| 1419 | + | |
| 1420 | + | |
| 1421 | + | |
| 1422 | + | |
| 1423 | + | |
| 1424 | + | |
| 1425 | + | |
| 1426 | + | |
| 1427 | + | |
| 1428 | + | |
| 1429 | + | |
| 1430 | + | |
| 1431 | + | |
| 1432 | + | |
| 1433 | + | |
| 1434 | + | |
| 1435 | + | |
| 1436 | + | |
| 1437 | + | |
| 1438 | + | |
| 1439 | + | |
1309 | 1440 | | |
1310 | 1441 | | |
1311 | 1442 | | |
| |||
2065 | 2196 | | |
2066 | 2197 | | |
2067 | 2198 | | |
| 2199 | + | |
| 2200 | + | |
| 2201 | + | |
| 2202 | + | |
| 2203 | + | |
| 2204 | + | |
| 2205 | + | |
| 2206 | + | |
| 2207 | + | |
| 2208 | + | |
| 2209 | + | |
| 2210 | + | |
| 2211 | + | |
| 2212 | + | |
| 2213 | + | |
| 2214 | + | |
| 2215 | + | |
| 2216 | + | |
| 2217 | + | |
| 2218 | + | |
| 2219 | + | |
| 2220 | + | |
| 2221 | + | |
| 2222 | + | |
| 2223 | + | |
| 2224 | + | |
| 2225 | + | |
| 2226 | + | |
| 2227 | + | |
| 2228 | + | |
| 2229 | + | |
| 2230 | + | |
| 2231 | + | |
| 2232 | + | |
| 2233 | + | |
| 2234 | + | |
| 2235 | + | |
| 2236 | + | |
| 2237 | + | |
| 2238 | + | |
| 2239 | + | |
| 2240 | + | |
| 2241 | + | |
2068 | 2242 | | |
2069 | 2243 | | |
2070 | 2244 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
991 | 991 | | |
992 | 992 | | |
993 | 993 | | |
| 994 | + | |
| 995 | + | |
| 996 | + | |
| 997 | + | |
| 998 | + | |
| 999 | + | |
| 1000 | + | |
| 1001 | + | |
| 1002 | + | |
| 1003 | + | |
| 1004 | + | |
| 1005 | + | |
| 1006 | + | |
| 1007 | + | |
| 1008 | + | |
| 1009 | + | |
| 1010 | + | |
| 1011 | + | |
| 1012 | + | |
| 1013 | + | |
| 1014 | + | |
| 1015 | + | |
| 1016 | + | |
| 1017 | + | |
| 1018 | + | |
| 1019 | + | |
| 1020 | + | |
| 1021 | + | |
| 1022 | + | |
| 1023 | + | |
| 1024 | + | |
| 1025 | + | |
| 1026 | + | |
| 1027 | + | |
| 1028 | + | |
| 1029 | + | |
| 1030 | + | |
| 1031 | + | |
| 1032 | + | |
| 1033 | + | |
| 1034 | + | |
| 1035 | + | |
| 1036 | + | |
| 1037 | + | |
| 1038 | + | |
| 1039 | + | |
| 1040 | + | |
| 1041 | + | |
| 1042 | + | |
| 1043 | + | |
| 1044 | + | |
| 1045 | + | |
| 1046 | + | |
| 1047 | + | |
| 1048 | + | |
| 1049 | + | |
| 1050 | + | |
| 1051 | + | |
| 1052 | + | |
| 1053 | + | |
| 1054 | + | |
| 1055 | + | |
| 1056 | + | |
| 1057 | + | |
| 1058 | + | |
| 1059 | + | |
| 1060 | + | |
| 1061 | + | |
| 1062 | + | |
| 1063 | + | |
| 1064 | + | |
| 1065 | + | |
| 1066 | + | |
| 1067 | + | |
| 1068 | + | |
| 1069 | + | |
| 1070 | + | |
| 1071 | + | |
| 1072 | + | |
| 1073 | + | |
| 1074 | + | |
| 1075 | + | |
| 1076 | + | |
| 1077 | + | |
| 1078 | + | |
| 1079 | + | |
| 1080 | + | |
| 1081 | + | |
| 1082 | + | |
| 1083 | + | |
| 1084 | + | |
| 1085 | + | |
| 1086 | + | |
| 1087 | + | |
| 1088 | + | |
| 1089 | + | |
| 1090 | + | |
| 1091 | + | |
| 1092 | + | |
| 1093 | + | |
| 1094 | + | |
| 1095 | + | |
| 1096 | + | |
| 1097 | + | |
| 1098 | + | |
| 1099 | + | |
| 1100 | + | |
| 1101 | + | |
| 1102 | + | |
| 1103 | + | |
| 1104 | + | |
| 1105 | + | |
| 1106 | + | |
| 1107 | + | |
| 1108 | + | |
| 1109 | + | |
| 1110 | + | |
| 1111 | + | |
| 1112 | + | |
| 1113 | + | |
| 1114 | + | |
| 1115 | + | |
| 1116 | + | |
| 1117 | + | |
| 1118 | + | |
| 1119 | + | |
| 1120 | + | |
| 1121 | + | |
| 1122 | + | |
| 1123 | + | |
| 1124 | + | |
| 1125 | + | |
| 1126 | + | |
| 1127 | + | |
| 1128 | + | |
| 1129 | + | |
| 1130 | + | |
| 1131 | + | |
| 1132 | + | |
| 1133 | + | |
| 1134 | + | |
| 1135 | + | |
| 1136 | + | |
| 1137 | + | |
994 | 1138 | | |
995 | 1139 | | |
996 | 1140 | | |
| |||
0 commit comments