Skip to content

Commit eb01114

Browse files
committed
Merge release/v5-prerelease (plan PR landed)
Brings in the squashed staged-rollout plan (#290), the e2e-tier fix (#288: Windows path separators in a scan test, CI cancel rules) and the docs-only design PRs. The plan doc's later edits (two-phase policy selection for the in-memory engine) merge with this branch's implementation notes unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2 parents a5757a1 + 0f2de18 commit eb01114

23 files changed

Lines changed: 4133 additions & 28 deletions

‎.github/workflows/bun-compatibility.yml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -95,11 +95,11 @@ on:
9595
permissions:
9696
contents: read
9797

98-
# Supersede stale PR runs. The `main` guard is load-bearing: main runs are the
99-
# ONLY rust-cache writers (save-if), so they must never be cancelled mid-save.
98+
# Supersede stale PR runs only: main runs are the ONLY rust-cache writers
99+
# (save-if), so push, dispatch and schedule runs are never cancelled mid-save.
100100
concurrency:
101101
group: bun-patch-${{ github.event.pull_request.number || github.ref }}
102-
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
102+
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
103103

104104
env:
105105
CARGO_PROFILE_DEV_DEBUG: '0'

‎.github/workflows/ci.yml‎

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -17,12 +17,13 @@ on:
1717
permissions:
1818
contents: read
1919

20-
# Supersede stale runs on force-push / rapid PR updates. The `main` guard is
21-
# load-bearing: main runs are the ONLY rust-cache writers (save-if), so they
22-
# must never be cancelled mid-save.
20+
# A newer push to the same PR supersedes its older run; nothing else is
21+
# cancelled. Push, dispatch and schedule runs always finish: main runs are
22+
# the ONLY rust-cache writers (save-if) and must not die mid-save, and a
23+
# dispatched base-branch run is the base's only CI verdict.
2324
concurrency:
24-
group: ci-${{ github.ref }}
25-
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
25+
group: ci-${{ github.event.pull_request.number || github.ref }}
26+
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
2627

2728
jobs:
2829
clippy:

‎.github/workflows/go-compatibility.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ permissions:
3030

3131
concurrency:
3232
group: go-compat-${{ github.event.pull_request.number || github.ref }}
33-
cancel-in-progress: true
33+
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
3434

3535
env:
3636
SOCKET_NO_CONFIG: '1'

‎.github/workflows/pdm-compatibility.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ permissions:
4848

4949
concurrency:
5050
group: pdm-compat-${{ github.event.pull_request.number || github.ref }}
51-
cancel-in-progress: true
51+
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
5252

5353
env:
5454
SOCKET_NO_CONFIG: '1'

‎.github/workflows/poetry-compatibility.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ permissions:
4040

4141
concurrency:
4242
group: poetry-compat-${{ github.event.pull_request.number || github.ref }}
43-
cancel-in-progress: true
43+
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
4444

4545
env:
4646
SOCKET_NO_CONFIG: '1'

‎.github/workflows/vlt-compatibility.yml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -117,11 +117,11 @@ on:
117117
permissions:
118118
contents: read
119119

120-
# Supersede stale PR runs; main runs are the only rust-cache writers, so they
121-
# are never cancelled mid-save.
120+
# Supersede stale PR runs only: main runs are the only rust-cache writers, so
121+
# push, dispatch and schedule runs are never cancelled mid-save.
122122
concurrency:
123123
group: vlt-compat-${{ github.event.pull_request.number || github.ref }}
124-
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
124+
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
125125

126126
env:
127127
CARGO_PROFILE_DEV_DEBUG: '0'

‎crates/socket-patch-cli/tests/covgap_commands_scan_mod.rs‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1484,8 +1484,9 @@ async fn scan_hosted_paths_run_once_per_project_directory() {
14841484

14851485
let (code, stdout, stderr) = run_scan_human(tmp.path(), &mock.uri(), &["apps/*"]);
14861486
assert_eq!(code, 0, "stdout={stdout}; stderr={stderr}");
1487-
for app in ["apps/a", "apps/b"] {
1488-
let header = format!("== {} ==", std::path::Path::new(app).display());
1487+
// glob rebuilds matches with the native separator (`apps\a` on Windows).
1488+
for app in ["a", "b"] {
1489+
let header = format!("== {} ==", Path::new("apps").join(app).display());
14891490
assert!(stdout.contains(&header), "missing {header:?}: {stdout}");
14901491
}
14911492
assert_eq!(stdout.matches("Redirected 0 packages").count(), 2, "{stdout}");

‎crates/socket-patch-cli/tests/e2e_nuget_dotnet_build.rs‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -306,7 +306,10 @@ fn fresh_checkout(from: &Path, to: &Path) {
306306
for f in ["app.csproj", "nuget.config", "packages.lock.json"] {
307307
std::fs::copy(from.join(f), to.join(f)).unwrap_or_else(|e| panic!("copy {f}: {e}"));
308308
}
309-
copy_tree(&from.join(".socket"), &to.join(".socket"));
309+
// v5 hosted mode writes no `.socket/`: the lock pins are its whole state.
310+
if from.join(".socket").is_dir() {
311+
copy_tree(&from.join(".socket"), &to.join(".socket"));
312+
}
310313
strip_manifest(to);
311314
let blobs = to.join(".socket/blobs");
312315
if blobs.exists() {

‎docs/design/nuget-vendoring-research/adversarial-env.md‎

Lines changed: 162 additions & 0 deletions
Large diffs are not rendered by default.

‎docs/design/nuget-vendoring-research/adversarial-integrity.md‎

Lines changed: 192 additions & 0 deletions
Large diffs are not rendered by default.

0 commit comments

Comments
 (0)