Add the NuGet vendoring design (docs only) - #285
Conversation
`cargo clippy --all-targets -- -D warnings` failed on the dead before_hash/after_hash fields of PatchedFixture. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01R11RZRvYFL3fzmEnkFAU4A
Setting SOCKET_PATCH_NUGET_LAYOUT=fallback vendors a patched NuGet package under a Socket-only version V' (the upstream version plus a 4th part derived from the patch uuid). The package is committed already extracted, as a NuGet fallback package folder under .socket/vendor/nuget/<uuid>/. It is wired through a generated socket-patch.targets file (imported via CustomAfterDirectoryBuildTargets from a Directory.Build.props block) and byte-exact packages.lock.json splices. Because nothing else can produce V', the patched bytes never enter or collide with the shared global packages folder, and nuget.config and source mapping are left alone. Restore-time and build-time guards fail closed on a tampered, incomplete or missing seed, or an unpatched resolution (SOCKETPATCH001/002/005/007). Supported shapes: SDK-style solutions with per-project lock files under --locked-mode, and Central Package Management with or without transitive pinning. Other shapes are refused with explicit codes. The default layout is unchanged. A repo is opted in only by the env var or an existing nuget-fallback ledger entry. Tests: - unit tests; - lock goldens captured from real dotnet; - an ignored real-SDK e2e (sln_locked, cpm_locked, cpm_pinning, sln_patch_update). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01R11RZRvYFL3fzmEnkFAU4A
docs/design/nuget-vendoring.md covers: - the verified NuGet facts behind the design; - the four candidate designs and the judge scores; - the decision (unique-version fallback seed); - the mechanism, supported shapes, failure modes, signing policy and migration; - the server/CLI split, the test plan and the adversarial review dispositions; - where the prototype overrides the design. The raw research and review notes are committed alongside in nuget-vendoring-research/. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01R11RZRvYFL3fzmEnkFAU4A
get now defaults to hosted mode (5e5f5ed), so the real-vlt get_and_remove leg ran a hosted get and found the installed copy unpatched. It now passes --mode agent, like the other agent-mode fixtures that commit updated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01R11RZRvYFL3fzmEnkFAU4A
|
[agent] The Cause: 5e5f5ed made I ported the fix into this PR as cc5f1b6: the test now passes Generated by Claude Code |
d9a3f53 removed PatchedFixture's before_hash/after_hash as dead code, but a macOS-only test reads them, which broke the macOS build. Restore the fields under #[cfg(target_os = "macos")], so they exist where they are read and clippy stays clean elsewhere. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01R11RZRvYFL3fzmEnkFAU4A
|
[agent] CI status for e8755a3:
Generated by Claude Code |
Vendored NuGet is future work for v5, so the opt-in fallback layout prototype (9 new modules, routing hooks and a real-dotnet e2e) moves to v5/nuget-vendoring-prototype, unmerged. This branch keeps the design doc, its research notes and the two test fixes. The doc now points at the prototype branch. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01R11RZRvYFL3fzmEnkFAU4A
…uget-vendoring # Conflicts: # crates/socket-patch-cli/tests/covgap_commands_rollback.rs
|
[agent] ready to land (docs/opt-in only) This PR is now the design doc and research notes plus a one-line Generated by Claude Code |
|
[agent]
Generated by Claude Code |
|
[agent] Generated by Claude Code |
get defaults to hosted mode since 5e5f5ed, so the real-vlt get_and_remove leg ran a hosted get and found the installed copy unpatched (Absent, expected Patched). Pass --mode agent, as the other agent-mode fixtures already do. Same change as cc5f1b6 on #285; it blocked the e2e tier's e2e_vlt jobs now that they run. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AfGnDQMy2FvpExneXmR1qp
|
#283 landed on release/v5-prerelease as 06437d2; please merge origin/release/v5-prerelease again, resolve conflicts, get green, and keep it ready. Generated by Claude Code |
|
[agent] Merged Generated by Claude Code |
|
[agent] CI on a1f7082 has two red checks. Neither comes from this PR: its diff is only
No fix exists for either failure, so there is nothing to port. I'm re-running the failed jobs once. If Generated by Claude Code |
* Cancel only superseded PR runs in CI A CI or compatibility run is now cancelled only when a newer push to the same pull request replaces it. Push, dispatch and scheduled runs always finish, so a manually dispatched run on the v5 base branch (its only CI verdict, since push CI runs on main alone) is no longer killed by a later dispatch or by the non-main cancel rule, and main keeps finishing its rust-cache saves. CI now groups PR runs by PR number, like the compatibility workflows already do. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AfGnDQMy2FvpExneXmR1qp * Expect native path separators in scan headers scan_hosted_paths_run_once_per_project_directory compared the per-directory `== apps/a ==` header against a literal forward-slash path, but scan prints the directory glob matched, which Windows spells `apps\a`. The Windows test leg failed on this since 62f07c7, and because every e2e job waits on `test`, the whole e2e tier was skipped on v5 PRs. Build the expected header from path components. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AfGnDQMy2FvpExneXmR1qp * Run the vlt agent get test in agent mode get defaults to hosted mode since 5e5f5ed, so the real-vlt get_and_remove leg ran a hosted get and found the installed copy unpatched (Absent, expected Patched). Pass --mode agent, as the other agent-mode fixtures already do. Same change as cc5f1b6 on #285; it blocked the e2e tier's e2e_vlt jobs now that they run. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AfGnDQMy2FvpExneXmR1qp * Run the pnpm safety e2e gets in agent mode get defaults to hosted mode since 5e5f5ed, so the three pnpm safety tests ran a hosted redirect and found proj_a's installed copy unpatched and no pnpm-layout note. They test the in-place apply path, so pass --mode agent. These e2e-tier tests had not run since that change because a red base test skipped the tier. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AfGnDQMy2FvpExneXmR1qp * Let the NuGet hosted e2e run without .socket/ v5 hosted mode writes no `.socket/` directory (the lock pins are the whole hosted state), so the hosted leg's fresh_checkout panicked with NotFound copying a tree that no longer exists. Copy it only when the run left one; the vendored leg still carries its ledger through. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AfGnDQMy2FvpExneXmR1qp --------- Co-authored-by: Claude <noreply@anthropic.com>
c02ccf8
into
release/v5-prerelease
…etup-and-ui Take the base's configuration.md deferred-defaults paragraph, which already accounts for `setup` being removed in v5. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj
…ed-engine Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KHZ8uzdXfkG2zH8ZYDG8ju
Summary
This PR adds the design for robust vendored (offline, committed) NuGet:
docs/design/nuget-vendoring.md. The raw research and adversarial-review notes are indocs/design/nuget-vendoring-research/. It is docs only; no code changes. The v5 plan keeps vendored NuGet as future work, so the prototype was moved out of this PR.Why the current layout can't be made safe. Today the patched package is vendored under the same id and version as upstream, in a local feed. Experiments with the real SDK showed:
--locked-moderestore still leaves the wrong copy in that cache.Chosen design. It scored 76.3/100 with the judge panel; the other three candidates scored 59.6–70.5.
socket-patch.targets, imported fromDirectory.Build.props, redirectsPackageReferenceand CPMPackageVersionto V′.packages.lock.jsongets byte-exact splices.nuget.configis not edited.The doc also covers:
§0 records where the prototype changed the design.
Prototype (not in this PR)
The opt-in prototype lives on
v5/nuget-vendoring-prototypeand is not merged.SOCKET_PATCH_NUGET_LAYOUT=fallback.--locked-mode, and CPM with or without transitive pinning.Testing
release/v5-prerelease(v5 WS1+WS2: ledger-free hosted mode, upstream-restore rollback, vendor ejects hosted projects #280, WS5: one VendoredBackend for vendored apply/revert/repair; cut repair's ledger rebuild #283).cargo clippy --workspace --all-targets --all-features -- -D warnings: clean.e2e_vlt--mode agentfix is now on the base, so this PR's diff is docs only.🤖 Generated with Claude Code
https://claude.ai/code/session_01R11RZRvYFL3fzmEnkFAU4A