Match Composer patch versions like Composer does - #270
Conversation
A composer patch's base purl can carry the padded version Socket's SBOM ingestion stores (pkg:composer/psr/log@3.0.2.0), while the project's installed.json and composer.lock say 3.0.2 or v3.0.2. The CLI compared those as strings after stripping a leading v, so such a patch was "not found" by apply and vendor, refused by the hosted redirect as a version mismatch, rejected by VEX discovery, and deleted by scan --prune. Compare composer versions the way Composer does. The new utils::composer_version ports composer/semver 3.4.4 VersionParser::normalize (padding, v tags, stability spellings such as -rc.1 and RC1, +build, x-dev branches); a spelling Composer rejects only matches itself. purl_eq, the crawler, the vendor lock lookup, the hosted lock rewriter, the redirect ledger, VEX discovery and sources, scan discovery and the prune step now use it for composer purls. Stored spellings (manifest keys, vendored leaf dirs, ledger keys) are unchanged. The shared vector file tests/fixtures/composer-version-vectors.json is generated from real Composer 2.10.3 and is byte-identical to depscan's copy, so the CLI and the server agree on every case; the port also matches Composer on 12,129 fuzzed inputs. New tests cover the crawler, lock lookup, ledger, VEX leaf, prune, a padded-version redirect golden, and apply, vendor (with VEX) and hosted runs against a mock API that serves only the padded spelling. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Composer patching was only proven on Ubuntu against three floating releases, so a regression on macOS, Windows, or a specific 2.x line (2.9 still falls back to the git source; 2.10 does not) went unseen. composer-compatibility.yml runs the real vendored and hosted capstones plus the composer VEX cells against checksum-pinned 1.10.28, 2.0.14, 2.1.14, 2.2.30, 2.5.8, 2.8.12, 2.9.8 and 2.10.3 phars on Ubuntu, and the 1.10/2.2/2.9/2.10 lines on Windows and macOS. A Docker job runs the vendored Docker capstone on exact 2.2.30 and 2.10.3 images. The capstones can now run a given composer.phar through php, which is also what makes them work on Windows. Dockerfile.composer installs an exact, checksum-verified Composer instead of the latest one, and the ci.yml comment on the git-source fallback is corrected. Assisted-by: Claude Code:claude-opus-5-5
Hosted redirects now remove a patched package's source wherever it sits in its composer.lock entry, and strip dist mirrors. Before, a failed or skipped hosted download let Composer 1 through 2.9 quietly install the unpatched upstream code from git. Locks that an older CLI or the GitHub app already redirected are healed on the next run. Vendored copies no longer lose files when installed. Composer's path mirror skipped anything matched by the copy's .gitignore (Composer 1 to 2.1), .hgignore (Composer 1) or .gitattributes export-ignore rules (every version), so a patched file could silently go missing. Those rules are now neutralized in the copy, and re-runs heal copies vendored earlier. A patch that edits one of those files is refused. vendor, scan and get now tell users to run composer install, and to remove the package directory first on Composer 1, which does not reinstall a changed package. Real-Composer tests cover the new cases on 1.10 through 2.10, and docs/testing/composer-compatibility.md records what each version does. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Vendoring a Composer patch (vendor, scan --mode vendored, get --mode vendored) rewrote a CRLF composer.lock, as a Windows or core.autocrlf checkout has, with LF line endings. The commit diff covered every line instead of the patched entry, and vendor --revert also wrote LF, so it did not restore the original bytes. Both writes now keep the line endings of the lock they replace, as the hosted mode already did. A CRLF lock now round-trips byte for byte through vendor and vendor --revert. Unit tests and a binary e2e cover vendor, scan --vendor and get --mode vendored on a CRLF lock. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Socket's SBOM pads every numeric Composer version to four parts, so a date release locked as 20231001 reaches the CLI as 20231001.0.0.0. Composer rejects that spelling (a 6+ digit major is only valid as a date), so the version key fell back to the raw text and never matched the lock: apply, vendor, hosted redirect and VEX reported the patch as not found for its own package. A 2-4 part numeric spelling Composer rejects is now normalized with its trailing .0 parts dropped. The shared vector file, copied from depscan, gains the padded date cases checked against Composer 2.10.3. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A dist that lists mirrors before its url had the mirrors' url rewritten instead of the dist's own, and a dist whose only url is a mirror is now refused with redirect_composer_no_dist_url. Also drop the dead composer_source_before_dist helper. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Vendoring rewrote the whole composer.lock through serde_json, so a lock with \/ escapes, \uXXXX escapes or mixed line endings did not revert byte for byte. Splice only the patched entry's text, keeping the lock's indentation, line endings and escaping. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Vendored ownership checks compared composer purls as exact strings, so a ledger keyed pkg:composer/psr/log@3.0.2.0 never covered the lock's @3.0.2 and apply, rollback, gc and scan treated a live vendored patch as foreign or dead. Match composer purls by release identity. The vendor hint now reads composer.lock only when this run wired composer, and never blocks on a special file. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Composer installs from source first when preferred-install resolves to source for the package, or when it is auto with a dev version on a Composer 1 or 2.0 lock. A leftover source entry then means pristine bytes, so VEX no longer reports those entries as fixed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
After a hosted redirect that removed no source entry, Composer 2 keeps an existing vendor/ copy, so the hint now names the vendor directory to remove on every Composer version. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The composer compatibility workflow now also runs for vendor, patch, manifest, lockfile and command changes. Docker composer tests fail instead of skipping when SOCKET_PATCH_DOCKER_E2E_REQUIRED=1, and the source-fallback test disables autocrlf so Windows compares LF bytes. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The source-install veto read composer.json directly, which the VEX discovery rules forbid: every extractor reads through DiscoverCtx so unreadable files are diagnosed and Socket identities are recognized. Also add the golden entries for the dist-mirrors-before-url fixture. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The in-place composer.lock rewrite oracle now also generates locks with dist mirrors listed before the url or as the only url, a source member placed before name, and patched versions spelled padded or v-prefixed. Every randomized lock is also checked to revert byte for byte when each recorded fragment is undone, newest first, the way the ledger reverts it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…anges The Composer crawler is now a directory module with its equivalence oracle, and vendored Composer lock writes go through the per-run group commit and the durable writer, so changes to any of them run the exact release matrix too. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
791848d to
68c8c82
Compare
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Resolve the scan/hosted.rs next-steps conflict by keeping both sides: the Composer reinstall hint from this branch and main's vlt ci line (#269). Update the vlt next-steps test for the edits argument. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Adopt depscan's final shared vectors (4ecd8543d3) byte for byte. A date release (6+ digit major) now drops its trailing .0 parts from its identity, since SBOM padding erases whether the lock said X, X.0 or X.0.0. Versions Composer rejects key into their own space, matching depscan's composerVersionIdentityKey, so purl identity keys cannot collide with a normalized one. Also point the drop_superseded_purl composer test at the real redirect_composer_dist edit kind: main's unknown-kind guard (#269) correctly refuses the made-up kind it used. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.
Bugbot Autofix prepared a fix for the issue found in the latest run.
- ✅ Fixed: Filter conflict misses package-prefixed keys
- Added normalize_file_path() call to strip 'package/' prefix from patch keys before comparing against filter file names, ensuring conflicts are properly detected.
Or push these changes by commenting:
@cursor push 3446b3ea64
Preview (3446b3ea64)
diff --git a/crates/socket-patch-cli/src/commands/get.rs b/crates/socket-patch-cli/src/commands/get.rs
--- a/crates/socket-patch-cli/src/commands/get.rs
+++ b/crates/socket-patch-cli/src/commands/get.rs
@@ -7272,8 +7272,11 @@
let installed = |name: &str, body: &[u8]| {
let dist = site.path().join(format!("{name}-1.0.0.dist-info"));
std::fs::create_dir_all(&dist).unwrap();
- std::fs::write(dist.join("METADATA"), format!("Name: {name}\nVersion: 1.0.0\n"))
- .unwrap();
+ std::fs::write(
+ dist.join("METADATA"),
+ format!("Name: {name}\nVersion: 1.0.0\n"),
+ )
+ .unwrap();
std::fs::write(site.path().join(format!("{name}.py")), body).unwrap();
compute_git_sha256_from_bytes(body)
};
@@ -7317,7 +7320,10 @@
mount(uuid("bs"), "beta_sdist.py".into(), "0".repeat(64), 0).await;
for n in ["gw", "gs"] {
Mock::given(method("GET"))
- .and(wm_path(format!("/v0/orgs/test-org/patches/view/{}", uuid(n))))
+ .and(wm_path(format!(
+ "/v0/orgs/test-org/patches/view/{}",
+ uuid(n)
+ )))
.respond_with(ResponseTemplate::new(500))
.expect(0)
.mount(&server)
diff --git a/crates/socket-patch-cli/src/commands/scan/discovery.rs b/crates/socket-patch-cli/src/commands/scan/discovery.rs
--- a/crates/socket-patch-cli/src/commands/scan/discovery.rs
+++ b/crates/socket-patch-cli/src/commands/scan/discovery.rs
@@ -2094,8 +2094,12 @@
"pkg:npm/lockonly@1.0.0",
std::path::PathBuf::from("/nonexistent"),
),
- crawled_pkg("alpha", "pkg:npm/alpha@1.0.0", installed("alpha", "alpha.js")),
crawled_pkg(
+ "alpha",
+ "pkg:npm/alpha@1.0.0",
+ installed("alpha", "alpha.js"),
+ ),
+ crawled_pkg(
"embedded",
"pkg:npm/embedded@1.0.0",
installed("embedded", "embedded.js"),
diff --git a/crates/socket-patch-cli/src/commands/setup.rs b/crates/socket-patch-cli/src/commands/setup.rs
--- a/crates/socket-patch-cli/src/commands/setup.rs
+++ b/crates/socket-patch-cli/src/commands/setup.rs
@@ -247,8 +247,7 @@
}
let mut hooked = Vec::new();
for loc in found.files.iter().filter(|loc| !loc.is_root) {
- if let Ok(content) = socket_patch_core::utils::fs::read_regular_to_string(&loc.path).await
- {
+ if let Ok(content) = socket_patch_core::utils::fs::read_regular_to_string(&loc.path).await {
let status = is_setup_configured_str(&content);
if status.postinstall_configured || status.dependencies_configured {
hooked.push(loc.path.clone());
diff --git a/crates/socket-patch-cli/src/commands/update.rs b/crates/socket-patch-cli/src/commands/update.rs
--- a/crates/socket-patch-cli/src/commands/update.rs
+++ b/crates/socket-patch-cli/src/commands/update.rs
@@ -159,7 +159,11 @@
/// The result line after a successful install, naming the same action as
/// [`confirm_prompt`].
-fn installed_message(current: &semver::Version, target: &semver::Version, path: &std::path::Path) -> String {
+fn installed_message(
+ current: &semver::Version,
+ target: &semver::Version,
+ path: &std::path::Path,
+) -> String {
let path = path.display();
if target < current {
format!("Downgraded socket-patch {current} \u{2192} {target} ({path})")
@@ -500,9 +504,18 @@
#[test]
fn cancel_and_result_lines_match_the_prompt() {
- assert_eq!(cancelled_message(&v("4.0.0"), &v("9.9.9")), "Update cancelled.");
- assert_eq!(cancelled_message(&v("4.0.0"), &v("3.0.0")), "Downgrade cancelled.");
- assert_eq!(cancelled_message(&v("4.0.0"), &v("4.0.0")), "Reinstall cancelled.");
+ assert_eq!(
+ cancelled_message(&v("4.0.0"), &v("9.9.9")),
+ "Update cancelled."
+ );
+ assert_eq!(
+ cancelled_message(&v("4.0.0"), &v("3.0.0")),
+ "Downgrade cancelled."
+ );
+ assert_eq!(
+ cancelled_message(&v("4.0.0"), &v("4.0.0")),
+ "Reinstall cancelled."
+ );
let p = std::path::Path::new("/opt/sp/socket-patch");
assert_eq!(
installed_message(&v("4.0.0"), &v("9.9.9"), p),
diff --git a/crates/socket-patch-cli/src/commands/vendor.rs b/crates/socket-patch-cli/src/commands/vendor.rs
--- a/crates/socket-patch-cli/src/commands/vendor.rs
+++ b/crates/socket-patch-cli/src/commands/vendor.rs
@@ -3864,7 +3864,11 @@
.unwrap();
let packages = [
("pkg:composer/psr/cache@1.0.0", "psr/cache", UUID_A),
- ("pkg:composer/psr/http-message@1.1.0", "psr/http-message", UUID_B),
+ (
+ "pkg:composer/psr/http-message@1.1.0",
+ "psr/http-message",
+ UUID_B,
+ ),
("pkg:composer/psr/log@3.0.2", "psr/log", UUID_C),
];
let mut all_packages: Vec<(String, StagedSource)> = Vec::new();
diff --git a/crates/socket-patch-cli/src/hosted_memory/redirect.rs b/crates/socket-patch-cli/src/hosted_memory/redirect.rs
--- a/crates/socket-patch-cli/src/hosted_memory/redirect.rs
+++ b/crates/socket-patch-cli/src/hosted_memory/redirect.rs
@@ -19,8 +19,7 @@
NPMRC_REL,
};
use socket_patch_core::patch::redirect::{
- rewrite_registry_redirect_withholding_vlt, DepOverride, FileEdit, RewriteResult,
- RewriteWarning,
+ rewrite_registry_redirect_withholding_vlt, DepOverride, FileEdit, RewriteResult, RewriteWarning,
};
use socket_patch_core::utils::purl::{purl_parts, strip_purl_qualifiers};
use socket_patch_core::vendor::lock_inventory::{MemoryEntry, MemoryProject};
diff --git a/crates/socket-patch-cli/tests/apply_network.rs b/crates/socket-patch-cli/tests/apply_network.rs
--- a/crates/socket-patch-cli/tests/apply_network.rs
+++ b/crates/socket-patch-cli/tests/apply_network.rs
@@ -1075,10 +1075,7 @@
v["summary"]["applied"], 1,
"the drifted nested copy must be warn-overwritten.\nstdout={v:#}"
);
- assert_eq!(
- v["summary"]["failed"], 0,
- "no copy may fail.\nstdout={v:#}"
- );
+ assert_eq!(v["summary"]["failed"], 0, "no copy may fail.\nstdout={v:#}");
// The nested copy's blob was fetched on demand…
let requests = mock.received_requests().await.unwrap();
diff --git a/crates/socket-patch-cli/tests/cli_config_fallback.rs b/crates/socket-patch-cli/tests/cli_config_fallback.rs
--- a/crates/socket-patch-cli/tests/cli_config_fallback.rs
+++ b/crates/socket-patch-cli/tests/cli_config_fallback.rs
@@ -59,8 +59,7 @@
let mut cmd = Command::new(BINARY);
// Human mode: core's proxy advisory (the oracle below) is muted under
// `--json`/`--silent`.
- cmd.args(["scan", "-e", "npm", "--cwd"])
- .arg(project);
+ cmd.args(["scan", "-e", "npm", "--cwd"]).arg(project);
for (key, _) in std::env::vars_os() {
let name = key.to_string_lossy();
if name.starts_with("SOCKET_") {
@@ -298,7 +297,9 @@
json_cmd.arg("--json");
let json_out = run(json_cmd);
assert!(
- json_out.stderr.contains("could not parse socket-cli config"),
+ json_out
+ .stderr
+ .contains("could not parse socket-cli config"),
"the parse warning must reach stderr under --json too; got:\n{}",
json_out.stderr
);
diff --git a/crates/socket-patch-cli/tests/cli_parse_list.rs b/crates/socket-patch-cli/tests/cli_parse_list.rs
--- a/crates/socket-patch-cli/tests/cli_parse_list.rs
+++ b/crates/socket-patch-cli/tests/cli_parse_list.rs
@@ -1202,7 +1202,10 @@
assert_eq!(v["error"]["code"], "manifest_not_found", "envelope={v}");
let warnings = v["warnings"].as_array().expect("warnings[] present");
assert_eq!(warnings.len(), 1, "envelope={v}");
- assert_eq!(warnings[0]["code"], "redirect_ledger_corrupt", "envelope={v}");
+ assert_eq!(
+ warnings[0]["code"], "redirect_ledger_corrupt",
+ "envelope={v}"
+ );
assert!(
out.stderr.is_empty(),
"--json must keep stderr clean: {}",
@@ -1214,7 +1217,10 @@
let stderr = String::from_utf8_lossy(&out.stderr);
assert_eq!(out.status.code(), Some(1));
assert!(stderr.contains("Warning: "), "stderr={stderr}");
- assert!(stderr.contains("Error: Manifest not found at "), "stderr={stderr}");
+ assert!(
+ stderr.contains("Error: Manifest not found at "),
+ "stderr={stderr}"
+ );
}
#[test]
diff --git a/crates/socket-patch-cli/tests/cli_parse_rollback.rs b/crates/socket-patch-cli/tests/cli_parse_rollback.rs
--- a/crates/socket-patch-cli/tests/cli_parse_rollback.rs
+++ b/crates/socket-patch-cli/tests/cli_parse_rollback.rs
@@ -378,7 +378,11 @@
/// relied on the rejection get a test-visible flip instead of a silent one.
#[test]
fn multiple_targets_parse_in_order() {
- let args = parse_rollback(&["pkg:npm/foo@1", "packages/api/**", "b0630680-4da6-45f9-bba8-b888e0ffd58c"]);
+ let args = parse_rollback(&[
+ "pkg:npm/foo@1",
+ "packages/api/**",
+ "b0630680-4da6-45f9-bba8-b888e0ffd58c",
+ ]);
assert_eq!(
args.targets,
vec![
diff --git a/crates/socket-patch-cli/tests/coverage_fix_apply_silent_mute_exit.rs b/crates/socket-patch-cli/tests/coverage_fix_apply_silent_mute_exit.rs
--- a/crates/socket-patch-cli/tests/coverage_fix_apply_silent_mute_exit.rs
+++ b/crates/socket-patch-cli/tests/coverage_fix_apply_silent_mute_exit.rs
@@ -150,7 +150,9 @@
);
let chatter = stderr_chatter(&stderr);
assert!(
- chatter.iter().any(|l| l.contains("could not be downloaded")),
+ chatter
+ .iter()
+ .any(|l| l.contains("could not be downloaded")),
"--silent must keep the download-failure error (errors only, \
never nothing); stderr was: {stderr:?}"
);
diff --git a/crates/socket-patch-cli/tests/coverage_fix_repair_vendor_predelete.rs b/crates/socket-patch-cli/tests/coverage_fix_repair_vendor_predelete.rs
--- a/crates/socket-patch-cli/tests/coverage_fix_repair_vendor_predelete.rs
+++ b/crates/socket-patch-cli/tests/coverage_fix_repair_vendor_predelete.rs
@@ -234,12 +234,9 @@
let gemfile_wired = std::fs::read(tmp.path().join("Gemfile")).unwrap();
std::fs::remove_file(tmp.path().join(".socket/vendor/state.json")).unwrap();
- std::fs::remove_file(
- tmp.path()
- .join(format!(
- "vendor/bundle/ruby/3.4.0/gems/{GEM_NAME}-{GEM_VERSION}/lib/padlock.rb"
- )),
- )
+ std::fs::remove_file(tmp.path().join(format!(
+ "vendor/bundle/ruby/3.4.0/gems/{GEM_NAME}-{GEM_VERSION}/lib/padlock.rb"
+ )))
.unwrap();
mount_blob(&mock).await;
@@ -280,8 +277,11 @@
&std::fs::read_to_string(tmp.path().join(".socket/vendor/state.json")).unwrap(),
)
.unwrap();
- assert_eq!(state["entries"][GEM_PURL]["uuid"], GEM_UUID, "state={state}");
assert_eq!(
+ state["entries"][GEM_PURL]["uuid"], GEM_UUID,
+ "state={state}"
+ );
+ assert_eq!(
std::fs::read(tmp.path().join("Gemfile")).unwrap(),
gemfile_wired,
"the wired Gemfile is untouched"
diff --git a/crates/socket-patch-cli/tests/covgap_commands_update.rs b/crates/socket-patch-cli/tests/covgap_commands_update.rs
--- a/crates/socket-patch-cli/tests/covgap_commands_update.rs
+++ b/crates/socket-patch-cli/tests/covgap_commands_update.rs
@@ -10,10 +10,10 @@
//! self_update_e2e.rs / interactive_prompts_e2e.rs (do not edit those
//! files).
+#[path = "common/mod.rs"]
+mod common;
#[path = "common/pty_io.rs"]
mod pty_io;
-#[path = "common/mod.rs"]
-mod common;
#[path = "common/update_fixture.rs"]
mod update_fixture;
@@ -275,9 +275,8 @@
let mut child = pair.slave.spawn_command(cmd).expect("spawn in PTY");
drop(pair.slave);
- let reader_handle = crate::pty_io::PtyOutput::spawn(
- pair.master.try_clone_reader().expect("clone reader"),
- );
+ let reader_handle =
+ crate::pty_io::PtyOutput::spawn(pair.master.try_clone_reader().expect("clone reader"));
let mut killer = child.clone_killer();
std::thread::spawn(move || {
@@ -345,7 +344,8 @@
"a declined update exits 1 (codebase convention); got: {output}"
);
assert!(
- !output.contains("Updated socket-patch") && !output.contains("Reinstalled socket-patch"),
+ !output.contains("Updated socket-patch")
+ && !output.contains("Reinstalled socket-patch"),
"a declined update must not report a swap; got: {output}"
);
diff --git a/crates/socket-patch-cli/tests/covgap_commands_vex.rs b/crates/socket-patch-cli/tests/covgap_commands_vex.rs
--- a/crates/socket-patch-cli/tests/covgap_commands_vex.rs
+++ b/crates/socket-patch-cli/tests/covgap_commands_vex.rs
@@ -544,14 +544,24 @@
])
.output()
.expect("invoke vex");
- assert!(out.status.success(), "{}", String::from_utf8_lossy(&out.stderr));
+ assert!(
+ out.status.success(),
+ "{}",
+ String::from_utf8_lossy(&out.stderr)
+ );
let env: Value = serde_json::from_slice(&out.stdout).expect("envelope JSON on stdout");
let w = env["warnings"]
.as_array()
- .and_then(|ws| ws.iter().find(|w| w["code"] == "product_multiple_manifests"))
+ .and_then(|ws| {
+ ws.iter()
+ .find(|w| w["code"] == "product_multiple_manifests")
+ })
.unwrap_or_else(|| panic!("product_multiple_manifests warning expected: {env}"));
assert!(
- w["detail"].as_str().unwrap().contains("Multiple project manifests"),
+ w["detail"]
+ .as_str()
+ .unwrap()
+ .contains("Multiple project manifests"),
"{w}"
);
let stderr = String::from_utf8_lossy(&out.stderr);
diff --git a/crates/socket-patch-cli/tests/covgap_ecosystem_dispatch.rs b/crates/socket-patch-cli/tests/covgap_ecosystem_dispatch.rs
--- a/crates/socket-patch-cli/tests/covgap_ecosystem_dispatch.rs
+++ b/crates/socket-patch-cli/tests/covgap_ecosystem_dispatch.rs
@@ -254,8 +254,11 @@
.unwrap_or_else(|e| panic!("rollback envelope must parse ({e}); stdout={stdout}"));
let code = out.status.code().unwrap_or(-1);
- assert_eq!(code, 0, "rollback --ecosystems=deno: expected exit 0; env={env}");
assert_eq!(
+ code, 0,
+ "rollback --ecosystems=deno: expected exit 0; env={env}"
+ );
+ assert_eq!(
env["status"], "success",
"rollback --ecosystems=deno: expected success; env={env}"
);
@@ -295,7 +298,8 @@
// The decisive check: the on-disk bytes are restored to ORIGINAL.
let restored = std::fs::read(&verify_file).unwrap();
assert_eq!(
- restored, ORIGINAL,
+ restored,
+ ORIGINAL,
"rollback --ecosystems=deno: {} was not restored to its original bytes",
verify_file.display()
);
diff --git a/crates/socket-patch-cli/tests/covgap_output.rs b/crates/socket-patch-cli/tests/covgap_output.rs
--- a/crates/socket-patch-cli/tests/covgap_output.rs
+++ b/crates/socket-patch-cli/tests/covgap_output.rs
@@ -173,9 +173,8 @@
.expect("spawn socket-patch in PTY");
drop(pair.slave);
- let reader_handle = crate::pty_io::PtyOutput::spawn(
- pair.master.try_clone_reader().expect("clone reader"),
- );
+ let reader_handle =
+ crate::pty_io::PtyOutput::spawn(pair.master.try_clone_reader().expect("clone reader"));
// Watchdog: detached kill after `timeout`; a no-op if the child exits
// naturally first.
@@ -266,7 +265,10 @@
"\n",
Duration::from_secs(15),
);
- assert_eq!(code, 0, "remove with bare Enter must succeed; got: {output}");
+ assert_eq!(
+ code, 0,
+ "remove with bare Enter must succeed; got: {output}"
+ );
// The interactive confirm MUST have run — otherwise this test passes
// vacuously against a regression that drops the TTY gate and
// auto-proceeds. Match the distinctive prompt verbatim (the loose
diff --git a/crates/socket-patch-cli/tests/covgap_setup_composer_mod.rs b/crates/socket-patch-cli/tests/covgap_setup_composer_mod.rs
--- a/crates/socket-patch-cli/tests/covgap_setup_composer_mod.rs
+++ b/crates/socket-patch-cli/tests/covgap_setup_composer_mod.rs
@@ -126,7 +126,10 @@
write(&cwd.join("composer.json"), MALFORMED_COMPOSER_JSON);
let (code, v) = run_json(cwd, &["setup", "--remove", "--yes", "--json"]);
- assert_eq!(code, 1, "remove on a malformed composer.json must fail: {v}");
+ assert_eq!(
+ code, 1,
+ "remove on a malformed composer.json must fail: {v}"
+ );
assert_eq!(v["status"], "error", "{v}");
assert_eq!(v["removed"], 0, "{v}");
assert_eq!(v["errors"], 1, "{v}");
diff --git a/crates/socket-patch-cli/tests/covgap_setup_gem_mod.rs b/crates/socket-patch-cli/tests/covgap_setup_gem_mod.rs
--- a/crates/socket-patch-cli/tests/covgap_setup_gem_mod.rs
+++ b/crates/socket-patch-cli/tests/covgap_setup_gem_mod.rs
@@ -71,7 +71,10 @@
&["setup", "--yes", "--json", "--ecosystems", "gem"],
&[],
);
- assert_eq!(code, 0, "gem setup must succeed.\nstdout:\n{stdout}\nstderr:\n{stderr}");
+ assert_eq!(
+ code, 0,
+ "gem setup must succeed.\nstdout:\n{stdout}\nstderr:\n{stderr}"
+ );
let v = common::parse_json_envelope(&stdout);
assert_eq!(v["status"], "success", "{v}");
assert!(
@@ -110,7 +113,14 @@
// Step 3: unwire with BUNDLE_APP_CONFIG set (child-only env injection).
let (code, stdout, stderr) = common::run_with_env(
root,
- &["setup", "--remove", "--yes", "--json", "--ecosystems", "gem"],
+ &[
+ "setup",
+ "--remove",
+ "--yes",
+ "--json",
+ "--ecosystems",
+ "gem",
+ ],
&[("BUNDLE_APP_CONFIG", "bundle-config")],
);
assert_eq!(
diff --git a/crates/socket-patch-cli/tests/covgap_setup_pypi_detect.rs b/crates/socket-patch-cli/tests/covgap_setup_pypi_detect.rs
--- a/crates/socket-patch-cli/tests/covgap_setup_pypi_detect.rs
+++ b/crates/socket-patch-cli/tests/covgap_setup_pypi_detect.rs
@@ -45,7 +45,10 @@
fn write_pm_shim(bin_dir: &Path, name: &str, log: &Path) {
use std::os::unix::fs::PermissionsExt;
std::fs::create_dir_all(bin_dir).expect("create shim dir");
- let body = format!("#!/bin/sh\nprintf '%s\\n' \"$*\" >> '{}'\nexit 0\n", log.display());
+ let body = format!(
+ "#!/bin/sh\nprintf '%s\\n' \"$*\" >> '{}'\nexit 0\n",
+ log.display()
+ );
let p = bin_dir.join(name);
std::fs::write(&p, body).expect("write shim");
std::fs::set_permissions(&p, std::fs::Permissions::from_mode(0o755)).expect("chmod shim");
@@ -80,11 +83,7 @@
/// through the shared hermetic runner (the seed-then-scrub of the ambient
/// `SOCKET_*` surface is load-bearing: SOCKET_DRY_RUN=true would fake every
/// edit, SOCKET_ECOSYSTEMS=npm would hide the Python branch entirely).
-fn run_setup_with_shims(
- cwd: &Path,
- bin_dir: &Path,
- extra: &[&str],
-) -> (i32, serde_json::Value) {
+fn run_setup_with_shims(cwd: &Path, bin_dir: &Path, extra: &[&str]) -> (i32, serde_json::Value) {
let path_env = format!(
"{}:{}",
bin_dir.display(),
diff --git a/crates/socket-patch-cli/tests/e2e_cargo.rs b/crates/socket-patch-cli/tests/e2e_cargo.rs
--- a/crates/socket-patch-cli/tests/e2e_cargo.rs
+++ b/crates/socket-patch-cli/tests/e2e_cargo.rs
@@ -209,8 +209,7 @@
"Expected human scan to report exactly 'Found 2 packages (2 cargo)', got:\n{combined}"
);
assert!(
- !combined.contains("No packages found")
- && !combined.contains("No packages found"),
+ !combined.contains("No packages found") && !combined.contains("No packages found"),
"scan reported no packages despite a populated registry:\n{combined}"
);
@@ -267,8 +266,7 @@
"Expected human scan to report exactly 'Found 1 package (1 cargo)', got:\n{combined}"
);
assert!(
- !combined.contains("No packages found")
- && !combined.contains("No packages found"),
+ !combined.contains("No packages found") && !combined.contains("No packages found"),
"scan reported no packages despite a populated vendor dir:\n{combined}"
);
diff --git a/crates/socket-patch-cli/tests/e2e_maven.rs b/crates/socket-patch-cli/tests/e2e_maven.rs
--- a/crates/socket-patch-cli/tests/e2e_maven.rs
+++ b/crates/socket-patch-cli/tests/e2e_maven.rs
@@ -182,8 +182,7 @@
// the word "packages", which is exactly what let the old assertion
// pass when discovery was disabled.
assert!(
- !combined.contains("No packages found")
- && !combined.contains("No packages found"),
+ !combined.contains("No packages found") && !combined.contains("No packages found"),
"scan reported zero packages — Maven discovery did not run:\n{combined}"
);
assert!(
diff --git a/crates/socket-patch-cli/tests/e2e_nuget.rs b/crates/socket-patch-cli/tests/e2e_nuget.rs
--- a/crates/socket-patch-cli/tests/e2e_nuget.rs
+++ b/crates/socket-patch-cli/tests/e2e_nuget.rs
@@ -232,7 +232,8 @@
// masked.
assert!(
!combined.contains("No packages found")
- && !combined.contains("No packages found") && !combined.contains("No global packages found"),
+ && !combined.contains("No packages found")
+ && !combined.contains("No global packages found"),
"scan failed to discover the fake global cache:\n{combined}"
);
// Exactly the two packages we planted (Newtonsoft.Json, System.Text.Json),
@@ -291,7 +292,8 @@
);
assert!(
!combined.contains("No packages found")
- && !combined.contains("No packages found") && !combined.contains("No global packages found"),
+ && !combined.contains("No packages found")
+ && !combined.contains("No global packages found"),
"scan failed to discover the legacy packages/ layout:\n{combined}"
);
// Exactly the single legacy package we planted (Newtonsoft.Json.13.0.3),
diff --git a/crates/socket-patch-cli/tests/get_edge_cases_e2e.rs b/crates/socket-patch-cli/tests/get_edge_cases_e2e.rs
--- a/crates/socket-patch-cli/tests/get_edge_cases_e2e.rs
+++ b/crates/socket-patch-cli/tests/get_edge_cases_e2e.rs
@@ -508,8 +508,16 @@
// parseable (scripts get that explicit error) but is not advertised.
assert!(!stdout.contains("--one-off"), "{stdout}");
// Help text is for users: no implementation notes from the source.
- for leak in ["value_parser", "parse_bool_flag", "No env binding", "locally- installed"] {
- assert!(!stdout.contains(leak), "get --help leaks {leak:?}: {stdout}");
+ for leak in [
+ "value_parser",
+ "parse_bool_flag",
+ "No env binding",
+ "locally- installed",
+ ] {
+ assert!(
+ !stdout.contains(leak),
+ "get --help leaks {leak:?}: {stdout}"
+ );
}
}
diff --git a/crates/socket-patch-cli/tests/global_packages_e2e.rs b/crates/socket-patch-cli/tests/global_packages_e2e.rs
--- a/crates/socket-patch-cli/tests/global_packages_e2e.rs
+++ b/crates/socket-patch-cli/tests/global_packages_e2e.rs
@@ -211,8 +211,11 @@
r["skipped"], "package_not_installed",
"a no-op rollback may carry only not-installed markers; envelope={v}"
);
- assert!(r["path"].is_null(), "marker path must be null; envelope={v}");
assert!(
+ r["path"].is_null(),
+ "marker path must be null; envelope={v}"
+ );
+ assert!(
r.get("success").is_none() && r.get("error").is_none(),
"markers carry no success/error keys; envelope={v}"
);
diff --git a/crates/socket-patch-cli/tests/help_text_hygiene.rs b/crates/socket-patch-cli/tests/help_text_hygiene.rs
--- a/crates/socket-patch-cli/tests/help_text_hygiene.rs
+++ b/crates/socket-patch-cli/tests/help_text_hygiene.rs
@@ -61,7 +61,11 @@
names.extend(cmd.get_subcommands().map(|s| s.get_name().to_string()));
let mut failures = Vec::new();
for name in &names {
- let path: Vec<&str> = if name.is_empty() { vec![] } else { vec![name.as_str()] };
+ let path: Vec<&str> = if name.is_empty() {
+ vec![]
+ } else {
+ vec![name.as_str()]
+ };
let text = long_help(&path);
let found = leaks(&text);
if !found.is_empty() {
@@ -166,8 +170,10 @@
"{text}"
);
assert!(
- text.lines().any(|l| l
- == " repair Download missing patch artifacts and clean up unused ones [aliases: gc]"),
+ text.lines().any(|l| {
+ l
+ == " repair Download missing patch artifacts and clean up unused ones [aliases: gc]"
+ }),
"{text}"
);
let repair = long_help(&["repair"]);
diff --git a/crates/socket-patch-cli/tests/hosted_memory_engine.rs b/crates/socket-patch-cli/tests/hosted_memory_engine.rs
--- a/crates/socket-patch-cli/tests/hosted_memory_engine.rs
+++ b/crates/socket-patch-cli/tests/hosted_memory_engine.rs
@@ -963,7 +963,8 @@
.and_then(|w| w["detail"].as_str())
.expect("the preflight warning is reported");
assert!(
- detail.contains("/patch/npm/<redacted>/") && detail.contains(": offline; nothing was written"),
+ detail.contains("/patch/npm/<redacted>/")
+ && detail.contains(": offline; nothing was written"),
"the offline refusal quotes the redacted URL"
);
assert!(output.changed_files.is_empty());
diff --git a/crates/socket-patch-cli/tests/in_process_redirect/vlt.rs b/crates/socket-patch-cli/tests/in_process_redirect/vlt.rs
--- a/crates/socket-patch-cli/tests/in_process_redirect/vlt.rs
+++ b/crates/socket-patch-cli/tests/in_process_redirect/vlt.rs
@@ -335,11 +335,15 @@
let detail = warning_detail(&doc, UNVERIFIABLE);
let redacted = url.replace(&format!("/{TOKEN}/"), "/<redacted>/");
assert!(
- detail.starts_with(&format!("vlt would fail to verify {redacted}: fetch error "))
- && detail.ends_with(&format!("; nothing was written for {PURL}")),
+ detail.starts_with(&format!(
+ "vlt would fail to verify {redacted}: fetch error "
+ )) && detail.ends_with(&format!("; nothing was written for {PURL}")),
"the fetch-error refusal quotes the redacted URL"
);
- assert!(!detail.contains(TOKEN), "the grant token never reaches the warning");
+ assert!(
+ !detail.contains(TOKEN),
+ "the grant token never reaches the warning"
+ );
}
async fn redirect_chain(hops: usize) -> (Value, tempfile::TempDir) {
diff --git a/crates/socket-patch-cli/tests/in_process_redirect_pdm.rs b/crates/socket-patch-cli/tests/in_process_redirect_pdm.rs
--- a/crates/socket-patch-cli/tests/in_process_redirect_pdm.rs
+++ b/crates/socket-patch-cli/tests/in_process_redirect_pdm.rs
@@ -109,7 +109,9 @@
.mount(server)
.await;
Mock::given(method("GET"))
- .and(path_regex(format!("^/v0/orgs/{ORG}/patches/by-package/.+$")))
+ .and(path_regex(format!(
+ "^/v0/orgs/{ORG}/patches/by-package/.+$"
+ )))
.respond_with(ResponseTemplate::new(200).set_body_json(serde_json::json!({
"patches": [{
"uuid": UUID, "purl": RECORD_PURL,
@@ -337,8 +339,10 @@
PYPROJECT,
"pyproject untouched"
);
- let ledger: serde_json::Value =
- serde_json::from_str(&read(&tmp.path().join(".socket/vendor/redirect-state.json"))).unwrap();
+ let ledger: serde_json::Value = serde_json::from_str(&read(
+ &tmp.path().join(".socket/vendor/redirect-state.json"),
+ ))
+ .unwrap();
assert!(
ledger["records"][RECORD_PURL].is_object(),
"ledger keyed by the artifact-qualified purl: {ledger}"
@@ -363,7 +367,11 @@
// 2. Idempotent re-scan: no further edits, lock byte-identical.
let code = run(hosted_args(tmp.path(), server.uri(), None)).await;
assert_eq!(code, 0);
- assert_eq!(read(&lock_path), redirected, "re-scan must not touch the lock");
+ assert_eq!(
+ read(&lock_path),
+ redirected,
+ "re-scan must not touch the lock"
+ );
// 3. The committed state, manifest-less, attests (and only while wired).
assert_manifestless_vex(tmp.path(), LOCK);
@@ -422,8 +430,10 @@
pyproject,
"pyproject untouched"
);
- let ledger: serde_json::Value =
- serde_json::from_str(&read(&tmp.path().join(".socket/vendor/redirect-state.json"))).unwrap();
+ let ledger: serde_json::Value = serde_json::from_str(&read(
+ &tmp.path().join(".socket/vendor/redirect-state.json"),
+ ))
+ .unwrap();
assert!(
ledger["records"][RECORD_PURL].is_object(),
"the pdm redirect must be confirmed and recorded despite the hatch backend: {ledger}"
@@ -443,7 +453,11 @@
})
.await;
assert_eq!(code, 0, "rollback must succeed");
- assert_eq!(read(&lock_path), LOCK, "rollback must restore the pristine lock");
+ assert_eq!(
+ read(&lock_path),
+ LOCK,
+ "rollback must restore the pristine lock"
+ );
}
/// The legacy `[metadata.files]` lock (lock_version 2) redirects the package
@@ -461,8 +475,10 @@
assert_eq!(code, 0);
let redirected = read(&lock_path);
assert!(redirected.contains(HOSTED_URL), "{redirected}");
- let ledger: serde_json::Value =
- serde_json::from_str(&read(&tmp.path().join(".socket/vendor/redirect-state.json"))).unwrap();
+ let ledger: serde_json::Value = serde_json::from_str(&read(
+ &tmp.path().join(".socket/vendor/redirect-state.json"),
+ ))
+ .unwrap();
assert_eq!(
ledger["edits"].as_array().unwrap().len(),
2,
diff --git a/crates/socket-patch-cli/tests/in_process_redirect_pipenv.rs b/crates/socket-patch-cli/tests/in_process_redirect_pipenv.rs
--- a/crates/socket-patch-cli/tests/in_process_redirect_pipenv.rs
+++ b/crates/socket-patch-cli/tests/in_process_redirect_pipenv.rs
@@ -54,7 +54,8 @@
const LOCK: &str =
include_str!("../../socket-patch-core/tests/fixtures/pipenv/2026.8.0/Pipfile.lock");
-const PIPFILE: &str = include_str!("../../socket-patch-core/tests/fixtures/pipenv/2026.8.0/Pipfile");
+const PIPFILE: &str =
+ include_str!("../../socket-patch-core/tests/fixtures/pipenv/2026.8.0/Pipfile");
/// The upstream and patched bytes of the record's one file, so the venv
/// tests can materialize a real `Ready` (upstream) install.
@@ -118,7 +119,9 @@
.mount(server)
.await;
Mock::given(method("GET"))
- .and(path_regex(format!("^/v0/orgs/{ORG}/patches/by-package/.+$")))
+ .and(path_regex(format!(
+ "^/v0/orgs/{ORG}/patches/by-package/.+$"
+ )))
.respond_with(ResponseTemplate::new(200).set_body_json(serde_json::json!({
"patches": [{
"uuid": UUID, "purl": RECORD_PURL,
@@ -308,7 +311,10 @@
serde_json::json!([format!("sha256:{}", sha256())]),
"{redirected}"
);
- assert!(entry.get("version").is_none() && entry.get("index").is_none(), "{entry}");
+ assert!(
+ entry.get("version").is_none() && entry.get("index").is_none(),
+ "{entry}"
+ );
assert_eq!(
entry["markers"],
urllib3_entry(LOCK)["markers"],
@@ -316,11 +322,19 @@
);
let before: serde_json::Value = serde_json::from_str(LOCK).unwrap();
let after: serde_json::Value = serde_json::from_str(&redirected).unwrap();
- assert_eq!(after["_meta"], before["_meta"], "the Pipfile content hash stays");
- assert_eq!(read(&tmp.path().join("Pipfile")), PIPFILE, "Pipfile untouched");
- let ledger: serde_json::Value =
- serde_json::from_str(&read(&tmp.path().join(".socket/vendor/redirect-state.json")))
- .unwrap();
+ assert_eq!(
+ after["_meta"], before["_meta"],
+ "the Pipfile content hash stays"
+ );
+ assert_eq!(
+ read(&tmp.path().join("Pipfile")),
+ PIPFILE,
+ "Pipfile untouched"
+ );
+ let ledger: serde_json::Value = serde_json::from_str(&read(
+ &tmp.path().join(".socket/vendor/redirect-state.json"),
+ ))
+ .unwrap();
assert!(
ledger["records"][RECORD_PURL].is_object(),
"ledger keyed by the artifact-qualified purl: {ledger}"
@@ -340,17 +354,34 @@
let vex: serde_json::Value = serde_json::from_str(&read(&vex_path)).unwrap();
let statements = vex["statements"].as_array().expect("statements");
assert_eq!(statements.len(), 1, "{vex}");
- assert_eq!(statements[0]["vulnerability"]["name"].as_str(), Some(GHSA), "{vex}");
- assert_eq!(statements[0]["status"].as_str(), Some("not_affected"), "{vex}");
+ assert_eq!(
+ statements[0]["vulnerability"]["name"].as_str(),
+ Some(GHSA),
+ "{vex}"
+ );
+ assert_eq!(
+ statements[0]["status"].as_str(),
+ Some("not_affected"),
+ "{vex}"
+ );
// 2. Idempotent re-scan: no further edits, lock byte-identical.
let code = run(hosted_args(tmp.path(), server.uri(), None)).await;
assert_eq!(code, 0);
- assert_eq!(read(&lock_path), redirected, "re-scan must not touch the lock");
... diff truncated: showing 800 of 2236 linesYou can send follow-ups to the cloud agent here.
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 185f91a. Configure here.
The conflict check compared patch file keys to `.gitignore` / `.hgignore` / `.gitattributes` verbatim, but API records key files as `package/<path>`, so a patch rewriting a filter file slipped past it and neutralization broke the patched file's afterHash. Normalize the key first. Read the copy's filter files through the FIFO-safe `read_regular_to_bytes` instead of a bare `tokio::fs::read`, so a FIFO at the path is skipped instead of wedging the vendor run. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Windows test runs today took 25-32 minutes when green, and slower runners cut off three #270 runs and a release/v5-prerelease run at the 35-minute limit with every test still passing. The build step alone ran 4-5 minutes longer than usual, which left no headroom. Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko)
left a comment
There was a problem hiding this comment.
v5 review at 8b885839 — this is a worthwhile correctness prerequisite for hosted mode. Composer version identity, removing source fallback, and checking actual installer behavior belong in v5. The two earlier Bugbot findings have fixes at this head; I am not reopening them, and I did not independently confirm a new blocker in this PR.
For integration/simplification:
- Land the Composer identity/installer behavior once, then make #281's Composer model and #280's upstream restoration reuse it. Otherwise padded-version equivalence, source removal and mirror handling will drift across three implementations.
- The hosted rewrite still leaves
dist.referenceat the upstream identity, and the new hints compensate by telling users to remove installed directories. Investigate using the patch UUID as the hosted dist reference, as vendored mode already does. Verify initial install, A→B patch updates, and rollback on the supported Composer matrix before relying on it; retain only guidance that remains necessary, including Composer 1 behavior. - Prefer one byte-span-aware Composer entry model for hosted/vendored/discovery/VEX. The expanded hosted scanner still has positional assumptions (
name/distorder); valid JSON should either be handled consistently or produce one explicit refusal through that model. - Keep the real Composer install tests and shared identity vectors. This is compatibility evidence worth preserving; the simplification target is duplicated parsing and orchestration.
I reviewed the code/diff and current CI results; I did not rerun the Composer toolchain matrix locally.
1a8608b
into
main


LLM Description written by Claude Code:claude-opus-5-5
The CLI now matches Composer patches by release version the way Composer does. Composer patches stay installed, and VEX reports them fixed, on every Composer version from 1.10 to 2.10 on Linux, macOS and Windows.
The depscan counterparts are SocketDev/depscan#26866 (implementation) and SocketDev/depscan#26864 (fixtures), which replace #26854.
Version matching
A Composer patch's base purl can carry the padded version Socket's SBOM ingestion stores (
pkg:composer/psr/log@3.0.2.0), whilecomposer.lockandinstalled.jsonsay3.0.2orv3.0.2. The CLI compared the two as strings after strippingv, so it failed in four ways:applyandvendorreported the patch "not found";scan --prunedeleted it.What changed:
utils::composer_versionports composer/semver 3.4.4VersionParser::normalize.purl_eq, vendor lock lookup, hosted rewriter, redirect ledger, VEX discovery and sources, scan discovery, prune and gc, and the vendored ownership checks in apply, rollback and scan.origin/main(afa72533, the in-memory hosted engine) with a plain merge commit; it had no conflicts.hosted_memorydoes not copy the composer rewriter. It calls core'srewrite_registry_redirect_with_pipenv_version, socomposer_sourceandcomposer_versionreach it through core. Its vendored-takeover check only covers cargo, npm and golang purls, so composer ownership by identity doesn't apply there.tests/fixtures/composer-version-vectors.jsonwas generated from real Composer 2.10.3 and is byte-identical to depscan's copy.Making sure patches are actually installed
sourcewherever it sits in the entry, not only right beforedist, because Composer 1.x–2.9 silently fall back to the pristine git source;dist.mirrors, including a list placed beforeurl;.gitignoreandexport-ignorerules, which make Composer's path mirror drop files. Vendoring refuses when a patched file would be dropped.composer.lockis edited. CRLF, mixed line endings,\/escapes and indentation survive, andvendor --revertis byte-identical.source. That happens whenpreferred-installresolves to source, or when it'sautowith a dev version on a 1.x/2.0 lock.composer install, with Composer 1 and dist-only reinstall guidance naming thevendor/dir to remove.CI
composer-compatibility.ymlcovers Composer 1.10.28, 2.0.14, 2.1.14, 2.2.30, 2.5.8, 2.8.12, 2.9.8 and 2.10.3.Dockerfile.composerinstalls an exact, checksum-verified Composer.ci.ymlcomment on the git-source fallback is corrected.Rebased onto main after #257
Rebased onto
8c381ecf(#257's concurrent, parallel-crawl, single-pass rewriters). Every #270 behavior sits on #257's paths:composer_versions_equivalentis used at every call site, including Speed up hosted and vendored scans: concurrent API requests, parallel crawl, single-pass rewriters #257's composer crawler oracle (crawlers/composer_crawler/oracle.rs) and the hosted rewriter oracle (patch/redirect/composer_equivalence_tests.rs). Both had encoded the oldv-strip compare, so they now use Match Composer patch versions like Composer does #270's semantics.sourceand mirrors: the rewriter keeps Speed up hosted and vendored scans: concurrent API requests, parallel crawl, single-pass rewriters #257's walk and in-place splice: test the name first, walk bytes,replace_rangeper edit.composer_source::apply_dist_editdoes the splice, and its recorded edit spans the dist plus the removedsourcewherever it sits, so the fragment revert stays byte-exact. Speed up hosted and vendored scans: concurrent API requests, parallel crawl, single-pass rewriters #257's source-before-dist block (composer_source_before_dist,redirect_composer_source_keptfor a non-adjacent source) is gone.redirect_composer_no_dist_url),sourcebeforename, and padded orv-prefixed patch versions.lock_text::replace_entryoutput goes throughatomic_write_bytes_preserving_mode, which is both the per-run group commit and the durable writer. The parse memo is re-seeded only when the written bytes equal the doc's canonical render; otherwise it is invalidated. A unit test covers this.ComposerPreludenow carries the lock text it parsed.composer.jsonthroughctx.read_text.purl_keys_coverand friends are merged with Speed up hosted and vendored scans: concurrent API requests, parallel crawl, single-pass rewriters #257's concurrent scan, discovery and vendor imports.composer-compatibility.ymlalso triggers oncrawlers/composer_crawler/**,utils/group_commit.rsandutils/durability.rs.composer-version-vectors.jsonis byte-identical (cmp) to depscan'sworkspaces/lib/src/composer/patch-identity-vectors.jsonon SocketDev/depscan#26866 (4ecd8543d3).Synced with main after #268 and #269
origin/main(b32711f7: Fix four vendored/hosted correctness bugs found while profiling #268 correctness fixes and Support vlt in hosted, vendored and agent modes #269 vlt) with a plain, signed merge commit. The only conflict was thescan/hosted.rsnext-step hints, which keep both the Composercomposer installhint and vlt'svlt ciline.4ecd8543d3) byte for byte. That ports the rule that a date release (a major of 6+ digits, like20200101) drops its trailing.0parts from its identity, because SBOM padding erases whether the lock saidX,X.0orX.0.0. Versions Composer rejects get their own\u{1}key space, matching depscan'scomposerVersionIdentityKey, so they can't collide with a normalized version.drop_superseded_purl's Composer test used a fake edit kind that main's new unknown-kind guard refuses, so it now uses a real kind.🤖 Generated with Claude Code
Note
Medium Risk
Changes core PURL matching, scan pruning, hosted lock rewrites, and VEX wiring across many CLI paths; risk is mitigated by extensive oracles and a multi-OS Composer CI matrix, but regressions could still mis-apply or drop patches for non-Composer ecosystems if identity helpers were misused.
Overview
Treats Composer patch PURLs and lock/crawler spellings (
@3.0.2,@v3.0.2, padded@3.0.2.0) as the same release via a newcomposer_versionnormalizer, wired through crawler lookup,purl_eq, scan discovery/prune/GC, apply/rollback vendored checks, hosted redirect ledger, and VEX source resolution—so padded API purls no longer miss apply, get pruned, or fail redirects.Hosted and vendored Composer behavior is tightened: redirects drop git
sourceanddist.mirrors(not only adjacent source), vendored copies neutralize mirror-skipping ignore rules, lock edits preserve CRLF/structure, and CLI reinstall hints explain Composer 1 / dist-only reinstall quirks. A dedicatedcomposer-compatibility.ymlmatrix runs checksum-pinnedcomposer.pharon Linux/macOS/Windows (plus Docker legs); e2e harness addsSOCKET_PATCH_COMPOSER_PHAR, Git CRLF isolation, and broad integration tests.Reviewed by Cursor Bugbot for commit 185f91a. Configure here.