Skip to content
Merged
4 changes: 2 additions & 2 deletions .github/workflows/bun-compatibility.yml
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ on:
- 'crates/socket-patch-cli/src/commands/scan/**'
- 'crates/socket-patch-cli/src/commands/rollback.rs'
- 'crates/socket-patch-cli/src/commands/vendor.rs'
- 'crates/socket-patch-cli/src/commands/repair_vendor.rs'
- 'crates/socket-patch-cli/src/commands/vendored_backend/**'
- 'crates/socket-patch-cli/src/commands/remove.rs'
# Main runs are the only rust-cache writers (save-if below), so a
# path-filtered push trigger is what seeds the cache the PR builds restore
Expand Down Expand Up @@ -75,7 +75,7 @@ on:
- 'crates/socket-patch-cli/src/commands/scan/**'
- 'crates/socket-patch-cli/src/commands/rollback.rs'
- 'crates/socket-patch-cli/src/commands/vendor.rs'
- 'crates/socket-patch-cli/src/commands/repair_vendor.rs'
- 'crates/socket-patch-cli/src/commands/vendored_backend/**'
- 'crates/socket-patch-cli/src/commands/remove.rs'
workflow_dispatch:
inputs:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/vlt-compatibility.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ on:
- 'crates/socket-patch-cli/src/commands/remove.rs'
- 'crates/socket-patch-cli/src/commands/setup.rs'
- 'crates/socket-patch-cli/src/commands/vendor.rs'
- 'crates/socket-patch-cli/src/commands/repair_vendor.rs'
- 'crates/socket-patch-cli/src/commands/vendored_backend/**'
- 'crates/socket-patch-cli/src/commands/get.rs'
- 'crates/socket-patch-cli/src/commands/vlt_preflight.rs'
- 'crates/socket-patch-cli/src/commands/scan/**'
Expand Down Expand Up @@ -74,7 +74,7 @@ on:
- 'crates/socket-patch-cli/src/commands/remove.rs'
- 'crates/socket-patch-cli/src/commands/setup.rs'
- 'crates/socket-patch-cli/src/commands/vendor.rs'
- 'crates/socket-patch-cli/src/commands/repair_vendor.rs'
- 'crates/socket-patch-cli/src/commands/vendored_backend/**'
- 'crates/socket-patch-cli/src/commands/get.rs'
- 'crates/socket-patch-cli/src/commands/vlt_preflight.rs'
- 'crates/socket-patch-cli/src/commands/scan/**'
Expand Down
24 changes: 24 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -226,6 +226,30 @@ into the new version's section — see docs/releasing.md.
(`https://repo.packagist.org`) and `SOCKET_NUGET_URL`
(`https://api.nuget.org`).

- **`repair` no longer rebuilds the vendor ledger from lockfiles.** A
lockfile that references `.socket/vendor/<eco>/<uuid>/` with no entry in
`.socket/vendor/state.json` now fails with `vendor_ledger_missing` (an
artifact-level `failed` event with `uuid` and `details.{ecosystem,path}`;
exit 1) instead of re-synthesizing the entry (`details.ledgerRestored` is
gone). The rewired lockfile cannot supply the pre-vendor originals a
revert needs, so the remedy is restoring `state.json` from version
control (or `git checkout -- <lockfile>` and re-vendoring). The unverified
npm "rebuild from the wired integrity" rung and the gem Gemfile wiring
reconstruction went with it; `rollback`'s missing-ledger error now asks
for `state.json` to be restored instead of naming `repair`.
- **`repair` re-vendors broken artifacts the way `vendor` does.** Missing
or corrupt vendored artifacts go through the same vendored backend as
`vendor` / `scan --mode vendored` / `get --mode vendored`, so under the
default `--vendor-source auto` the patch service's prebuilt artifact is
downloaded again, with a local build as the fallback (and the only
source under `--offline` / `--vendor-source build`). The result is still
verified against the ledger fingerprint before it counts as `rebuilt`.
Failure details are now `vendor`'s own (for example "no installed
package found on disk"), and a drifted installed copy of a gem or pypi
release variant is no longer force-overwritten by repair — it fails the
same installed-variant check `vendor` applies. Internally, `vendor`, `scan`/`get --mode vendored`, `vendor --revert`,
`rollback`'s vendored leg, `remove` and `repair` now share one
`VendoredBackend { apply, revert, repair }`.
- **Vendored runs refuse lock-text failures before downloading them.**
`scan --mode vendored` and `get --mode vendored` evaluate the vendor
backends' pure lock-text gates — pnpm, yarn classic and yarn berry
Expand Down
12 changes: 8 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -476,7 +476,7 @@ need the network and refuse to run with `--offline`.
| [`remove`](#remove) | The single-patch form of `rollback`: restore, unwind, drop the record and GC for one PURL/UUID (a hosted patch is restored to upstream) |
| [`vendor --revert`](#vendor) | **Un-vendors wholesale**: restores the recorded original lockfile fragments byte-for-byte and removes the `.socket/vendor/` artifacts (a package vendored over a hosted pin returns to upstream, not to hosted) |
| [`scan --prune`](#scan) | Agent mode: **reconciles, doesn't reverse** — drops manifest entries for packages that have left the project and garbage-collects orphan blob/diff/archive files |
| [`repair`](#repair) (alias `gc`) | **Restores health, not originals**: re-downloads missing blobs, rebuilds missing/corrupt vendored artifacts, and cleans up unused ones |
| [`repair`](#repair) (alias `gc`) | **Restores health, not originals**: re-downloads missing blobs, re-vendors missing/corrupt vendored artifacts, and cleans up unused ones |

And `setup --remove` reverts the install hooks that `setup` added.

Expand All @@ -497,7 +497,7 @@ And `setup --remove` reverts the install hooks that `setup` added.
| [`setup`](#setup) | Wire install hooks (npm, Python, Bundler, Composer) that re-apply patches after install |
| [`rollback`](#rollback) | Undo patches in every mode: restore original files, unwind vendored lockfile wiring, and restore hosted lockfile entries to upstream |
| [`remove`](#remove) | Remove one patch by PURL or UUID (rolls back first) |
| [`repair`](#repair) | Download missing patch artifacts, rebuild vendored artifacts, clean up unused ones (alias: `gc`) |
| [`repair`](#repair) | Download missing patch artifacts, re-vendor broken vendored artifacts, clean up unused ones (alias: `gc`) |

`socket-patch --update` updates the CLI itself (see [Updating](#updating)).

Expand Down Expand Up @@ -1215,14 +1215,18 @@ socket-patch remove "pkg:npm/lodash@4.17.20" --json

### `repair`

Download missing blobs, rebuild missing or corrupt vendored artifacts, and clean up unused
Download missing blobs, re-vendor missing or corrupt vendored artifacts, and clean up unused
blobs.

Alias: `gc`

`repair` cleans up the `.socket/` directory without running a scan — useful when you've
manually adjusted the manifest, recovered from a partial-failure state, or just want to
free space. It also rebuilds missing or corrupt vendored artifacts. For the combined
free space. It also re-vendors missing or corrupt vendored artifacts the same way `vendor`
does (the patch service's prebuilt artifact first, a local build as the fallback), checked
against `.socket/vendor/state.json`. `repair` does not recreate a lost `state.json`: if a
lockfile points into `.socket/vendor/` and the ledger has no entry for it, `repair` fails with
`vendor_ledger_missing` — restore `state.json` from version control. For the combined
agent-mode workflow (discover + apply + GC in one pass), use `scan --sync` instead.

Like every other mutating command, `repair` takes the `.socket/apply.lock` advisory lock
Expand Down
Loading
Loading