Repository navigation
Fix pnpm vendored refusal missing quoted scoped aliases (#957) - #986
Mikola Lysenko (mikolalysenko) wants to merge 3 commits into
Conversation
Assisted-by: Claude Code:claude-opus-5-5
|
[agent] Generated by Claude Code |
pnpm 9+ quotes a lock value that starts with `@`, so a scoped npm alias (`sl: npm:@scope/pkg@1.1.0`) is written as `'@scope/pkg@1.1.0'` in the importer or a dependent's snapshot. The vendored "aliased reference" refusal compared that raw value with the unquoted `name@version`, never matched, and vendoring reported success over a lock that every frozen install rejects (ERR_PNPM_LOCKFILE_MISSING_DEPENDENCY) while VEX attested the package. Unquote importer versions and snapshot dependency values once, both in the scan and where the lock index keys them, so scoped aliases (and their peer-suffixed spellings) are refused like unscoped ones. The index-vs-scan oracle now generates the quoted spelling too. Fixes #957 Assisted-by: Claude Code:claude-opus-5-5
main has failed socket-patch-core's lib tests since Gradle support (#646) and the digest helpers (#865) both landed. The guard test production_digests_go_through_the_helpers flags three files #646 added that still hash inline: crawlers/gradle_cache.rs, patch/jvm_jar.rs and patch/sidecars/maven.rs. That breaks test, test-release and coverage on every open PR. Each inline sha1/sha256 call now goes through sha1_hex_of or sha256_hex_of, which compute the same lowercase hex. Behaviour is unchanged. Assisted-by: Claude Code:claude-opus-5-5 (cherry picked from commit 659ac2c)
fa2202a to
a406a10
Compare
|
BugBot review Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit a406a10. Configure here.
|
Ready for review — head
Generated by Claude Code |
LLM Description written by Claude Code:claude-opus-5-5
Fixes #957
Summary
Vendored pnpm 9+ now refuses a package that a scoped
npm:alias references (sl: npm:@scope/pkg@x), in a root importer or in a dependent's snapshot, exactly as it already refused an unscoped alias. Before this change,vendor/scan --mode vendoredreported success, left a dangling quoted reference, broke everypnpm install --frozen-lockfile(ERR_PNPM_LOCKFILE_MISSING_DEPENDENCY) and let VEX attestnot_affected.Root cause
check_rewritable_refsincrates/socket-patch-core/src/vendor/pnpm_lock.rsrefuses a package that annpm:alias references, because the pair surgery can't rewrite that reference. To do that it compares raw YAML values (importerversion:and snapshot body dependency values) against the unquoted registry keyname@version. pnpm 9+ quotes any value that starts with@, so a scoped alias ('@isaacs/string-locale-compare@1.1.0') never matches. This affects the indexed path (LockIndex::buildstores raw values infirst_snapshot_rest*/first_importer_ver*) and the non-indexed fallback loops alike.Fix
LockIndex::buildkeysfirst_snapshot_rest*,first_snapshot_dep_rest_paren,first_importer_ver*andfirst_importer_catalog. The scan and the index therefore still agree. A scoped alias, including a peer-suffixed one, is now refused like an unscoped alias. The refusal text shows the unquoted reference.indexed_lock_probes_match_the_scans) now generates the quoted spelling pnpm writes for@-leading values, so any future drift between the two paths on that shape fails the test.production_digests_go_through_the_helpersguard test that is red onmain(coverage/test). It becomes a no-op once Route Gradle digests through utils::digest #878 lands.Test evidence
vendor::pnpm_lock::tests::quoted_scoped_alias_references_refusee2e_vendor_pnpm_build::pnpm_vendor_refuses_quoted_scoped_alias_references(importerleg)status: success,applied: 1vendor_lock_entry_unsupported, lock/package.json byte-identical, no artifact, untouched lock frozen-installsfile:tarball dep, real pnpm 10snapshotleg)status: success,applied: 1Commands run locally on
a406a10:cargo clippy --workspace --all-features -- -D warnings: clean.rustfmt --checkon every touched file: clean. CI runs no fmt check, andmainitself is notcargo fmt-clean, so a whole-workspacecargo fmtis not part of this PR.cargo test --workspace --all-features --no-fail-fast: 10,820 passed, 340 ignored, 12 failed. All 12 failures are failure-injection tests that make paths read-only or unremovable, and the sandbox runs as root, which bypasses those permissions. Re-run as an unprivileged user (setpriv --reuid=65534), all 12 pass.cargo test -p socket-patch-core --lib vendor::pnpm: 211 passed, including the 600-seed index oracle.🤖 Generated with Claude Code
https://claude.ai/code/session_018PuTamr8nmfojGXJ7zn9Xc
Generated by Claude Code