Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
151 changes: 151 additions & 0 deletions crates/socket-patch-cli/tests/e2e_vendor_pnpm_build.rs
Original file line number Diff line number Diff line change
Expand Up @@ -2137,3 +2137,154 @@ fn pnpm_vendor_keeps_user_workspace_overrides_authoritative() {
);
assert_eq!(std::fs::read_to_string(&lock_path).unwrap(), lock_before);
}

/// #957: pnpm 9+ writes a scoped `npm:` alias's target quoted
/// (`version: '@isaacs/string-locale-compare@1.1.0'` in the root
/// importer, `sl: '@isaacs/…@1.1.0'` in a dependent's snapshot). Vendoring
/// can't rewrite that reference, so it must refuse the package — exactly as
/// it refuses the unscoped `npm:left-pad@1.3.0` alias — instead of
/// reporting success over a lock whose frozen install fails with
/// ERR_PNPM_LOCKFILE_MISSING_DEPENDENCY. The lock, package.json and
/// `.socket/vendor` stay untouched, and the untouched lock still
/// frozen-installs.
#[test]
fn pnpm_vendor_refuses_quoted_scoped_alias_references() {
if !has_corepack_pm(PNPM_PRIMARY) {
println!("SKIP: `corepack {PNPM_PRIMARY}` unavailable");
return;
}
let pm = PNPM_PRIMARY;
const SCOPED: &str = "@isaacs/string-locale-compare";
const SCOPED_VERSION: &str = "1.1.0";
let alias = format!("npm:{SCOPED}@{SCOPED_VERSION}");

for shape in ["importer", "snapshot"] {
let tmp = tempfile::tempdir().unwrap();
let proj = tmp.path().join("proj");
std::fs::create_dir_all(&proj).unwrap();
let deps = if shape == "importer" {
serde_json::json!({ "sl": alias })
} else {
// A local tarball dependency that itself aliases the scoped
// package, so the quoted reference lands in its snapshot.
let pkg = tmp.path().join("host").join("package");
std::fs::create_dir_all(&pkg).unwrap();
let host = serde_json::json!({
"name": "host",
"version": "1.0.0",
"dependencies": { "sl": alias },
});
std::fs::write(pkg.join("package.json"), host.to_string()).unwrap();
std::fs::write(pkg.join("index.js"), "module.exports = require('sl');\n").unwrap();
let tar = Command::new("tar")
.args(["-czf"])
.arg(proj.join("host-1.0.0.tgz"))
.arg("package")
.current_dir(tmp.path().join("host"))
.output()
.expect("tar runs");
assert!(tar.status.success(), "{tar:?}");
serde_json::json!({ "host": "file:./host-1.0.0.tgz" })
};
let pkg_doc = serde_json::json!({
"name": "scoped-alias",
"version": "0.0.0",
"private": true,
"dependencies": deps,
});
let pkg_before = format!("{}\n", serde_json::to_string_pretty(&pkg_doc).unwrap());
std::fs::write(proj.join("package.json"), &pkg_before).unwrap();

let store = tmp.path().join("pnpm-store");
let install = corepack(
&proj,
pm,
&["install", "--store-dir", store.to_str().unwrap()],
);
if !install.status.success() {
assert!(!pnpm_required(), "fixture install failed: {install:?}");
println!("SKIP: fixture `pnpm install` failed: {install:?}");
return;
}
let lock_path = proj.join("pnpm-lock.yaml");
let lock_before = std::fs::read_to_string(&lock_path).unwrap();
let quoted = format!("'{SCOPED}@{SCOPED_VERSION}'");
let reference = if shape == "importer" {
format!(" version: {quoted}\n")
} else {
format!(" sl: {quoted}\n")
};
assert!(
lock_before.contains(&reference),
"{shape}: pnpm wrote the quoted alias reference:\n{lock_before}"
);

let installed = if shape == "importer" {
proj.join("node_modules/sl/index.js")
} else {
proj.join(format!(
"node_modules/.pnpm/{}@{SCOPED_VERSION}/node_modules/{SCOPED}/index.js",
SCOPED.replace('/', "+")
))
};
let orig = std::fs::read(&installed)
.unwrap_or_else(|e| panic!("{shape}: installed {}: {e}", installed.display()));
let patched: Vec<u8> = [MARKER.as_bytes(), orig.as_slice()].concat();
let purl = format!("pkg:npm/{SCOPED}@{SCOPED_VERSION}");
stage_patch(&proj, &purl, "package/index.js", &orig, &patched);
let cwd = proj.to_str().unwrap();

let (code, stdout, stderr) =
run_socket(&proj, &["vendor", "--json", "--offline", "--cwd", cwd]);
let env = parse_envelope(&stdout);
assert_ne!(code, 0, "{shape}: the refusal fails the run.\n{env}");
assert_eq!(
env["summary"]["applied"], 0,
"{shape}: a quoted scoped alias must not vendor.\n{env}\nstderr:\n{stderr}"
);
assert!(
stdout.contains("vendor_lock_entry_unsupported") && stdout.contains("aliased"),
"{shape}: the refusal names the aliased reference: {env}"
);
assert_eq!(
std::fs::read_to_string(&lock_path).unwrap(),
lock_before,
"{shape}: lock untouched"
);
assert_eq!(
std::fs::read_to_string(proj.join("package.json")).unwrap(),
pkg_before,
"{shape}: package.json untouched"
);
assert!(
!proj.join(format!(".socket/vendor/npm/{UUID}")).exists(),
"{shape}: a refused vendor leaves no artifact"
);

// The untouched lock still frozen-installs from a fresh checkout.
let fresh = tmp.path().join("fresh");
std::fs::create_dir_all(&fresh).unwrap();
for file in ["package.json", "pnpm-lock.yaml"] {
std::fs::copy(proj.join(file), fresh.join(file)).unwrap();
}
if shape == "snapshot" {
std::fs::copy(proj.join("host-1.0.0.tgz"), fresh.join("host-1.0.0.tgz")).unwrap();
}
let ci = corepack(
&fresh,
pm,
&[
"install",
"--frozen-lockfile",
"--store-dir",
store.to_str().unwrap(),
],
);
assert!(
ci.status.success(),
"{shape}: fresh frozen install of the untouched lock.\nstdout:\n{}\nstderr:\n{}",
String::from_utf8_lossy(&ci.stdout),
String::from_utf8_lossy(&ci.stderr),
);
}
}
9 changes: 4 additions & 5 deletions crates/socket-patch-core/src/crawlers/gradle_cache.rs
Original file line number Diff line number Diff line change
Expand Up @@ -70,8 +70,7 @@ pub fn hash_eq(dir_name: &str, sha1_hex: &str) -> bool {
/// Whether `bytes` are the pristine download Gradle stored in the hash
/// directory `dir_name` (their sha1 names it).
pub fn pristine(dir_name: &str, bytes: &[u8]) -> bool {
use sha1::{Digest, Sha1};
hash_eq(dir_name, &hex::encode(Sha1::digest(bytes)))
hash_eq(dir_name, &crate::utils::digest::sha1_hex_of(bytes))
}

/// Whether `path` is a version directory of a `files-2.1` tree
Expand Down Expand Up @@ -432,8 +431,6 @@ impl DerivedIndex {
/// The [`DerivedCopies`] of the jar `jar_leaf` whose pristine bytes
/// hash to `pristine_sha1`.
pub fn query(&self, jar_leaf: &str, pristine_sha1: &str) -> DerivedCopies {
use sha1::{Digest, Sha1};

let instrumented = format!("instrumented-{jar_leaf}");
let mut out = DerivedCopies {
incomplete: self.incomplete,
Expand All @@ -460,7 +457,9 @@ impl DerivedIndex {
out.stale.push(path.clone());
} else if name == jar_leaf || name == instrumented {
match crate::utils::fs::read_regular_to_bytes_sync(path) {
Ok(bytes) if hash_eq(&hex::encode(Sha1::digest(&bytes)), pristine_sha1) => {
Ok(bytes)
if hash_eq(&crate::utils::digest::sha1_hex_of(&bytes), pristine_sha1) =>
{
out.stale.push(path.clone())
}
Ok(_) => out.unknown.push(path.clone()),
Expand Down
7 changes: 2 additions & 5 deletions crates/socket-patch-core/src/patch/jvm_jar.rs
Original file line number Diff line number Diff line change
Expand Up @@ -25,8 +25,6 @@
use std::collections::HashMap;
use std::path::{Path, PathBuf};

use sha1::Digest as _;

use crate::crawlers::gradle_cache;
use crate::hash::git_sha256::compute_git_sha256_from_bytes;
use crate::manifest::schema::PatchFileInfo;
Expand Down Expand Up @@ -353,12 +351,11 @@ fn unpatched_members(
}

fn sha256_hex(bytes: &[u8]) -> String {
use sha2::Digest as _;
hex::encode(sha2::Sha256::digest(bytes))
crate::utils::digest::sha256_hex_of(bytes)
}

fn sha1_hex(bytes: &[u8]) -> String {
hex::encode(sha1::Sha1::digest(bytes))
crate::utils::digest::sha1_hex_of(bytes)
}

/// `<socket_dir>/jvm-originals/<sha256>.jar`.
Expand Down
4 changes: 1 addition & 3 deletions crates/socket-patch-core/src/patch/sidecars/maven.rs
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,6 @@

use std::path::{Path, PathBuf};

use sha1::Digest as _;

use super::{
SidecarAdvisory, SidecarAdvisoryCode, SidecarError, SidecarFile, SidecarFileAction,
SidecarPayload, SidecarSeverity,
Expand All @@ -44,7 +42,7 @@ impl Algo {

fn digest(self, bytes: &[u8]) -> String {
match self {
Algo::Sha1 => hex::encode(sha1::Sha1::digest(bytes)),
Algo::Sha1 => crate::utils::digest::sha1_hex_of(bytes),
Algo::Md5 => hex::encode(md5(bytes)),
}
}
Expand Down
Loading
Loading