Repository navigation
Scan every vendored-write file for vendored references (#832, #958) - #1015
Merged
Mikola Lysenko (mikolalysenko) merged 6 commits intoOct 7, 2026
Merged
Mikola Lysenko (mikolalysenko) merged 6 commits into
Mikola Lysenko (mikolalysenko) merged 6 commits into
Conversation
Assisted-by: Claude Code:claude-opus-5-5
The vendored-reference scan behind repair, the orphan sweeps (vendor --revert, the vendored gc), the vendor stranded-reference gate and rollback's ledger-less gate read only the registry's VENDORED rows, while the files NuGet, Maven, Hatch and pnpm vendoring also write sat in a second list, VENDORED_WRITES_UNMARKED, that only the dry run's symlink check used. NuGet's feed and Maven's repository also name the uuid directory itself, which parse_vendor_path rejects. So with a missing ledger entry, a NuGet or Maven unit, or a wheel a hatch.toml environment installs, was deleted by the orphan sweep and never reported by repair while the project still pointed at it. The eight rows now carry the VENDORED role and the second list is gone, so the scan and wiring_paths read one notion of "a file a vendored run writes". parse_vendor_reference is parse_vendor_path's grammar plus the bare uuid dir, and the scan reads through it, with `<` ending a reference inside XML text. Fixes #832 and #958. Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 7, 2026
main is red on production_digests_go_through_the_helpers: #690 moved gradle_cache.rs, jvm_jar.rs and sidecars/maven.rs onto the utils::digest helpers, but PENDING_INLINE_DIGESTS still lists them, and the ratchet fails on a stale entry. Same three-line change as #889 and #980; it no-ops once main carries it. Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko)
marked this pull request as ready for review
October 7, 2026 13:19
Collaborator
Author
|
BugBot review Generated by Claude Code |
nuget.config and NuGet.Config are one file on a case-insensitive file system (Windows, default macOS), so the second fixture write replaced the first and the scan test could not see both uuids. The backslashed NuGet.Config case now runs in its own temp project. Assisted-by: Claude Code:claude-opus-5-5
Collaborator
Author
|
BugBot review Generated by Claude Code |
This was referenced Oct 7, 2026
Collaborator
Author
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit ecfc1e7. Configure here.
Tanmay Singla (Tanmay182003)
approved these changes
Oct 7, 2026
Mikola Lysenko (mikolalysenko)
deleted the
arch-refactor/832-vendored-reference-scan
branch
October 7, 2026 16:29
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 7, 2026
Collaborator
Author
|
[agent] Ready for review at ecfc1e7.
Generated by Claude Code |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by Claude Code:claude-opus-5-5
Fixes #832
Fixes #958
Summary
The vendored-reference scan (
scan_vendor_references) is what keeps a.socket/vendor/<eco>/<uuid>/unit with no ledger entry from being deleted while a project file still points at it. Every caller goes through it:repair(vendor_ledger_missing), the orphan sweeps (vendor --revert, the vendored gc), thevendorstranded-reference gate, and rollback's ledger-less gate. It missed NuGet, Maven and Hatch wiring for two reasons:registry::paths_with(VENDORED).nuget.config(all three spellings),packages.lock.json,pom.xml,.mvn/maven.config,hatch.tomlandpnpm-workspace.yamlsat in a second list,VENDORED_WRITES_UNMARKED, that only the vendored dry run's symlink check (wiring_paths) read.value=".socket/vendor/nuget/<uuid>") and Maven's repository (<url>file://${project.basedir}/.socket/vendor/maven/<uuid></url>) name the uuid directory itself, whileparse_vendor_pathrequires a leaf. The scanner also had no<terminator.Why (leverage)
B 2 (#832, #958: same root cause, per the fixer's "Shares root cause" comments), U 0, D ≈1 (two registry notions collapse to one role, and the second list is deleted), R M. Score ≈5, the best eligible candidate this run: every higher-ranked queue row is blocked by open PRs on
commands/vendor.rsor by claims. Register rows E61 and E67 (register); living documentdoc/05-vendored.md, new findings E61/E67.What changed
formats/registry.rs: the eight rows get theVENDOREDrole, andVENDORED_WRITES_UNMARKEDis deleted.wiring_paths(eco)is now justecosystem && VENDORED, and its output is unchanged for every ecosystem.vendor/path.rs: newparse_vendor_reference, which isparse_vendor_path's grammar but also accepts an empty leaf (the bare uuid dir).parse_vendor_pathis nowparse_vendor_reference(..).filter(leaf non-empty), so there is one grammar and every existing caller is unchanged.vendored_backend/repair.rs: the scan reads throughparse_vendor_reference, and<ends a reference. A directory-wired unit reports the uuid dir as its path, with any trailing/trimmed.utils/digest.rs(separate commit): ports the base-red fix that Honor HTTP-date Retry-After on vendor-service retries through api::retry (#677) #889 and Fix uv dry run missing inline [tool.uv] refusal (#979) #980 carry.mainfailsproduction_digests_go_through_the_helpersbecause sbt, Mill and scala-cli support in agent, hosted and vendored modes #690 migratedgradle_cache.rs,jvm_jar.rsandsidecars/maven.rswhile the pending list still names them. It is the same three-line removal, and it no-ops oncemaincarries it.Deleted
git diff --stat origin/main, split at#[cfg(test)]:VENDORED_WRITES_UNMARKEDand its filter are gone; the grammar is shared)Behavior
These are the intended fixes:
nuget.config,pom.xml,hatch.toml,packages.lock.json,.mvn/maven.configorpnpm-workspace.yamlis now kept by the orphan sweeps (stillWired) instead of being deleted.repairnow reports such a unit asvendor_ledger_missing(exit 1) instead of finding no vendored traces.vendorstranded-reference gate and rollback's ledger-less refusal now see the same references.Nothing else changes:
wiring_pathsreturns the same files, andparse_vendor_pathcallers see the same results. Not done here: the deadeco == "maven2"arm of the stranded-reference gate incommands/vendor.rs, which is unreachable. That file is changed by #776 and #978, so the arm is left for a follow-up.Test evidence
repair_vendor_e2e::repair_reports_missing_ledger_for_nuget_maven_and_hatch_wiring(CLI, built binary): onmainit fails withleft: [](no events); on this branch it passes with 3vendor_ledger_missingevents (maven, nuget, pypi).vendored_backend::repair::tests::scan_recovers_unit_dir_and_hatch_toml_references: covers the NuGet dir with a trailing/, the backslashedNuGet.Config, Maven<url>…</url>andhatch.toml. It also checks that a baremaven/, the v5maven2tree and a non-uuid dir are still not references.vendor::path::tests::parse_vendor_reference_accepts_the_uuid_dir_itself:parse_vendor_pathstill rejects the bare dir.formats::registry::tests::the_reference_scan_and_the_symlink_check_read_the_same_files:paths_with(VENDORED)equals the union ofwiring_pathsover every ecosystem, and the NuGet and PyPI lists are pinned.cargo clippy --workspace --all-features -- -D warnings: clean.cargo test -p socket-patch-core --lib: 5,559 passed. The 4 failures are the known root-only ones (copy_tree::relax_loop…,vlt_heal::an_unremovable…,pypi_poetry::wire_write_failure…,pypi_requirements::wire_failure…). The digest ratchet passes after the port.cargo test -p socket-patch-cli --all-features --test <suite>:repair(125 + 1 new),in_process_vendor(120),in_process_remove_repair_lifecycle(23),remove(91),rollback(38),scan(118),vendor_crash_safety_e2e(6),vendor_jvm_cli(29),e2e_sbt_vendor(18),mode_migration_npm(19),mode_migration_cargo(9),apply(106),cli(92);repair's 2 known chmod tests, andcovgap_commands_vendor's 3*_state_write_failure_*tests, whichchmod 0o555the vendor dir and are ineffective as root (51 others pass).Risk
M. Where a project file references a unit, the orphan sweep now keeps it rather than deleting it, so the risk is that something is kept, not that something is lost. The new
<terminator and the bare-dir form only add matches, and a match still needs a known ecosystem dir and a canonical uuid.🤖 Generated with Claude Code
https://claude.ai/code/session_01RcjbNmuocdNawny89vudHV
Note
Medium Risk
Changes which vendor units are considered “still wired” across repair, revert/prune, vendor, and rollback—generally retaining more dirs rather than deleting them; matching logic is additive (more files scanned, dir-level paths,
<terminator) with uuid/ecosystem validation unchanged.Overview
Fixes #832 and #958 by making the shared vendored-reference scan see NuGet, Maven, and Hatch wiring that was previously ignored.
Registry: NuGet configs,
packages.lock.json,pom.xml,.mvn/maven.config,hatch.toml, andpnpm-workspace.yamlnow carry theVENDOREDrole; the separateVENDORED_WRITES_UNMARKEDlist is removed sopaths_with(VENDORED)andwiring_pathsuse one definition of “files a vendored run writes.”Path parsing: New
parse_vendor_referenceaccepts references to the uuid directory (no leaf), which NuGet feeds and Maven<url>use;parse_vendor_pathstill requires a leaf.scan_vendor_referencesuses the new parser, treats<as an XML terminator, and normalizes trailing slashes.Behavior: Orphan sweeps, repair’s
vendor_ledger_missingpath, vendor stranded-reference checks, and rollback’s ledger-less gate now detect these wires instead of treating projects as unwired or deleting still-referenced vendor dirs.Reviewed by Cursor Bugbot for commit ecfc1e7. Configure here.