Skip to content

Commit 2990e48

Browse files
committed
Merge remote-tracking branch 'origin/main' into fix/gc-report-json-1257
2 parents 3e6153c + a8e9397 commit 2990e48

313 files changed

Lines changed: 19136 additions & 3003 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.gitattributes‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,3 +47,11 @@ crates/socket-patch-core/tests/fixtures/sbt/** -text
4747
# (sbt-compatibility.yml); a CRLF checkout breaks them ($'\r').
4848
scripts/sbt-warm-seed.sh text eol=lf
4949
scripts/sbt-compat-matrix.sh text eol=lf
50+
51+
# Real `bun install --save-text-lockfile` output: the migrated-lock revert
52+
# tests compare restored bun.lock bytes against it exactly (#784).
53+
crates/socket-patch-core/tests/fixtures/bun-lockb/1.2.23-migrated/*.lock -text
54+
55+
# Real Bun locks with a version-less own-source copy (#497): the VEX tests
56+
# rewire the nested registry entry of the captured bytes in place.
57+
crates/socket-patch-core/tests/fixtures/bun-unversioned-copy/** -text

‎.github/workflows/bun-compatibility.yml‎

Lines changed: 17 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,11 @@ name: Bun patch compatibility
1616
on:
1717
pull_request:
1818
types: [opened, synchronize, reopened, ready_for_review]
19+
# Only this ecosystem's own files. A change to shared engine code
20+
# (vendor/, patch/, vex/, scan/, Cargo.lock, ...) runs the full matrix on
21+
# push to main, or on demand via workflow_dispatch on the PR branch;
22+
# ci.yml's per-ecosystem blocking slice still runs on every PR and in
23+
# the merge queue (#1198).
1924
paths:
2025
- '.github/actions/upload-artifact/**'
2126
- '.github/actions/pin-socket-hosts/**'
@@ -24,30 +29,13 @@ on:
2429
- 'scripts/backtest-bun*.py'
2530
- 'scripts/probe-bun-historical-linux.py'
2631
- 'scripts/bun-historical-shas.json'
32+
- 'docs/testing/bun-compatibility.md'
33+
- 'crates/*/src/**/bun_*'
34+
- 'crates/*/src/**/bun.rs'
35+
- 'crates/*/src/**/bun/**'
2736
- 'crates/socket-patch-cli/tests/e2e_bun_lockb.rs'
2837
- 'crates/socket-patch-core/tests/fixtures/bun-lockb/**'
29-
- 'docs/testing/bun-compatibility.md'
30-
- 'Cargo.lock'
31-
- 'crates/socket-patch-core/src/vendor/**'
32-
- 'crates/socket-patch-core/src/patch/redirect/**'
33-
- 'crates/socket-patch-core/src/vendor/bun_lock_text.rs'
34-
- 'crates/socket-patch-core/src/crawlers/npm_crawler.rs'
35-
- 'crates/socket-patch-core/src/crawlers/pkg_managers.rs'
36-
- 'crates/socket-patch-core/src/constants.rs'
37-
- 'crates/socket-patch-core/src/utils/process.rs'
3838
- 'crates/socket-patch-core/tests/fixtures/redirect/npm/bun/**'
39-
- 'crates/socket-patch-cli/src/commands/get.rs'
40-
- 'crates/socket-patch-core/src/vex/**'
41-
- 'crates/socket-patch-cli/src/commands/vex.rs'
42-
- 'crates/socket-patch-cli/src/commands/vex_consumed.rs'
43-
- 'crates/socket-patch-cli/src/commands/vex_sources.rs'
44-
- 'crates/socket-patch-cli/src/commands/apply.rs'
45-
- 'crates/socket-patch-cli/tests/vex_e2e_common/**'
46-
- 'crates/socket-patch-cli/src/commands/scan/**'
47-
- 'crates/socket-patch-cli/src/commands/rollback.rs'
48-
- 'crates/socket-patch-cli/src/commands/vendor.rs'
49-
- 'crates/socket-patch-cli/src/commands/vendored_backend/**'
50-
- 'crates/socket-patch-cli/src/commands/remove.rs'
5139
# Main runs are the only rust-cache writers (save-if below), so a
5240
# path-filtered push trigger is what seeds the cache the PR builds restore
5341
# (rust-cache keys on Cargo.lock, so Cargo.lock belongs here) and re-runs
@@ -82,6 +70,14 @@ on:
8270
- 'crates/socket-patch-cli/src/commands/vendor.rs'
8371
- 'crates/socket-patch-cli/src/commands/vendored_backend/**'
8472
- 'crates/socket-patch-cli/src/commands/remove.rs'
73+
- '.github/actions/upload-artifact/**'
74+
- 'docs/testing/bun-compatibility.md'
75+
- 'crates/socket-patch-core/src/vendor/bun_lock_text.rs'
76+
- 'crates/socket-patch-core/src/crawlers/npm_crawler.rs'
77+
- 'crates/socket-patch-core/src/crawlers/pkg_managers.rs'
78+
- 'crates/socket-patch-core/src/constants.rs'
79+
- 'crates/socket-patch-core/src/utils/process.rs'
80+
- 'crates/socket-patch-core/tests/fixtures/redirect/npm/bun/**'
8581
workflow_dispatch:
8682
inputs:
8783
versions:

‎.github/workflows/ci.yml‎

Lines changed: 22 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -710,24 +710,18 @@ jobs:
710710
tags: socket-patch-test-${{ matrix.ecosystem }}:latest
711711
load: true
712712

713-
- name: Build instrumented socket-patch binary
714-
# Source `cargo llvm-cov show-env` into the current shell so this
715-
# `cargo build` picks up RUSTC_WRAPPER=cargo-llvm-cov and the
716-
# same RUSTFLAGS that the subsequent `cargo llvm-cov` test step
717-
# will use. The bin we build ends up byte-compatible with the
718-
# test binaries — same source hashes → unified coverage map at
719-
# report time. Env stays scoped to this step (intentional;
720-
# cargo llvm-cov manages its own env in the test step).
721-
run: |
722-
eval "$(cargo llvm-cov show-env --export-prefix 2>/dev/null)"
723-
cargo build --bin socket-patch
724-
725713
- name: Configure docker-e2e coverage hooks
714+
# Mount the instrumented socket-patch that the test step's own
715+
# `cargo llvm-cov` builds for the integration tests (cargo builds
716+
# a package's bins before running its integration tests), and
717+
# write the in-container profraws next to the test processes'
718+
# ones. `cargo llvm-cov report` reads only
719+
# target/llvm-cov-target/*.profraw and objects built there, so a
720+
# separately built binary or profraws elsewhere in target/ never
721+
# reach the lcov.
726722
run: |
727-
echo "SOCKET_PATCH_COV_BIN=$PWD/target/debug/socket-patch" >> "$GITHUB_ENV"
728-
# Profraw files from the in-container binary land here.
729-
# cargo-llvm-cov scans target/ for *.profraw at report time.
730-
echo "SOCKET_PATCH_COV_PROFRAW_DIR=$PWD/target" >> "$GITHUB_ENV"
723+
echo "SOCKET_PATCH_COV_BIN=$PWD/target/llvm-cov-target/debug/socket-patch" >> "$GITHUB_ENV"
724+
echo "SOCKET_PATCH_COV_PROFRAW_DIR=$PWD/target/llvm-cov-target" >> "$GITHUB_ENV"
731725
732726
- name: Run ${{ matrix.ecosystem }} Docker e2e test with coverage
733727
run: |
@@ -1109,8 +1103,13 @@ jobs:
11091103
- {os: ubuntu-latest, suite: e2e_bun_lockb, bun: '1.0.36', test_filter: --include-ignored}
11101104
- {os: ubuntu-latest, suite: e2e_bun_lockb, bun: '1.1.45', test_filter: --include-ignored}
11111105
# Bun >= 1.4 migrating a hosted workspace bun.lockb to bun.lock
1112-
# (#803): the only binary-lock test whose reader must be 1.4+.
1113-
- {os: ubuntu-latest, suite: e2e_bun_lockb, bun: '1.4.2', test_filter: --include-ignored workspace_text_migration_heals_on_rerun}
1106+
# (#803; its reader must be 1.4+) and a vendored one, then
1107+
# reverting it (#784; skipped by the < 1.2 readers above). Both
1108+
# 1.4.2 and 1.3.14 also run the isolated-linker vendored re-run
1109+
# after a late dependent (#861); 1.3 re-hoists a frozen binary lock
1110+
# and refuses one whose trees changed.
1111+
- {os: ubuntu-latest, suite: e2e_bun_lockb, bun: '1.4.2', test_filter: --include-ignored text_migration workspace_late_dependent}
1112+
- {os: ubuntu-latest, suite: e2e_bun_lockb, bun: '1.3.14', test_filter: --include-ignored workspace_late_dependent}
11141113
# Real-vlt capstones (DESIGN §8.4): wiremock patch service and a local
11151114
# npm registry fed from npmjs, driven by the pinned vlt release
11161115
# (`node vlt.js`, installed below from a sha512-checked `npm pack`).
@@ -1355,14 +1354,15 @@ jobs:
13551354
env:
13561355
UV_TEST_VERSION: ${{ matrix.uv }}
13571356
run: |
1358-
python -m pip install --disable-pip-version-check --upgrade pip "uv==$UV_TEST_VERSION"
1357+
scripts/pip-install-retry.sh --upgrade pip "uv==$UV_TEST_VERSION"
13591358
uv --version
13601359
13611360
- name: Install uv (PDM / Hatch legs)
13621361
if: matrix.pdm != '' || matrix.hatch != ''
13631362
# The suites bootstrap the pinned PDM / Hatch into their own venv
13641363
# with uv; this uv is tooling, not the release under test.
1365-
run: python -m pip install uv==0.11.19
1364+
shell: bash
1365+
run: scripts/pip-install-retry.sh uv==0.11.19
13661366

13671367
- name: Install pinned Poetry
13681368
if: matrix.poetry != ''
@@ -1374,7 +1374,7 @@ jobs:
13741374
env:
13751375
POETRY_TEST_VERSION: ${{ matrix.poetry }}
13761376
run: |
1377-
python -m pip install uv==0.11.19
1377+
scripts/pip-install-retry.sh uv==0.11.19
13781378
case "$POETRY_TEST_VERSION" in 1.0.*|1.1.*) py=3.8.20 ;; *) py=3.12 ;; esac
13791379
uv venv "$RUNNER_TEMP/poetry" --python "$py"
13801380
extra=""; [ "$POETRY_TEST_VERSION" = "1.2.2" ] && extra="cleo==1.0.0a5"
@@ -2460,7 +2460,7 @@ jobs:
24602460

24612461
- name: Install uv
24622462
if: steps.gate.outputs.run == 'true'
2463-
run: python -m pip install --disable-pip-version-check uv && uv --version
2463+
run: scripts/pip-install-retry.sh uv && uv --version
24642464

24652465
- name: Setup Ruby
24662466
if: steps.gate.outputs.run == 'true'

‎.github/workflows/composer-compatibility.yml‎

Lines changed: 31 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,9 +22,32 @@ name: Composer patch compatibility
2222
on:
2323
pull_request:
2424
types: [opened, synchronize, reopened, ready_for_review]
25+
# Only this ecosystem's own files. A change to shared engine code
26+
# (vendor/, patch/, vex/, scan/, Cargo.lock, ...) runs the full matrix on
27+
# push to main (when it is in the push filter below) or nightly, or on
28+
# demand via workflow_dispatch on the PR branch;
29+
# ci.yml's per-ecosystem blocking slice still runs on every PR and in
30+
# the merge queue (#1198).
2531
paths:
2632
- '.github/workflows/composer-compatibility.yml'
2733
- 'tests/docker/Dockerfile.composer'
34+
- 'crates/*/src/**/*composer*'
35+
- 'crates/*/src/**/*composer*/**'
36+
- 'crates/socket-patch-core/tests/fixtures/redirect/composer/**'
37+
- 'crates/socket-patch-core/tests/fixtures/composer-version-vectors.json'
38+
- 'crates/socket-patch-cli/tests/e2e_*composer*.rs'
39+
- 'crates/socket-patch-cli/tests/docker_e2e_vendor_composer.rs'
40+
- 'crates/socket-patch-cli/tests/composer_e2e_common/**'
41+
- 'crates/socket-patch-cli/tests/e2e_vex_lockfile/composer.rs'
42+
push:
43+
branches: [main]
44+
# The ecosystem's pre-#1198 relevance set (the shared engine code its
45+
# cells run through), its PR paths and the toolchain files. A main
46+
# push outside this set waits for the nightly run below.
47+
paths:
48+
- '.github/workflows/composer-compatibility.yml'
49+
- 'tests/docker/Dockerfile.composer'
50+
- 'tests/docker/Dockerfile.base'
2851
- 'Cargo.lock'
2952
- 'Cargo.toml'
3053
- 'crates/*/Cargo.toml'
@@ -62,8 +85,14 @@ on:
6285
- 'crates/socket-patch-cli/tests/docker_vendor_common/**'
6386
- 'crates/socket-patch-cli/tests/e2e_vex_lockfile/composer.rs'
6487
- 'crates/socket-patch-cli/tests/vex_e2e_common/**'
65-
push:
66-
branches: [main]
88+
- 'crates/*/src/**/*composer*'
89+
- 'crates/*/src/**/*composer*/**'
90+
- 'rust-toolchain.toml'
91+
- '.cargo/**'
92+
schedule:
93+
# Nightly full matrix, so a main change outside the push filter
94+
# still gets a run within a day.
95+
- cron: '17 4 * * *'
6796
workflow_dispatch:
6897

6998
permissions:

‎.github/workflows/go-compatibility.yml‎

Lines changed: 34 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,28 @@ name: Go patch compatibility
88
on:
99
pull_request:
1010
types: [opened, synchronize, reopened, ready_for_review]
11+
# Only this ecosystem's own files. A change to shared engine code
12+
# (vendor/, patch/, vex/, scan/, Cargo.lock, ...) runs the full matrix on
13+
# push to main (when it is in the push filter below) or nightly, or on
14+
# demand via workflow_dispatch on the PR branch;
15+
# ci.yml's per-ecosystem blocking slice still runs on every PR and in
16+
# the merge queue (#1198).
17+
paths:
18+
- '.github/workflows/go-compatibility.yml'
19+
- 'crates/*/src/**/*golang*'
20+
- 'crates/*/src/**/*golang*/**'
21+
- 'crates/socket-patch-core/src/vendor/go*.rs'
22+
- 'crates/socket-patch-core/src/crawlers/go_crawler.rs'
23+
- 'crates/socket-patch-core/src/crawlers/go_crawler/**'
24+
- 'crates/socket-patch-cli/tests/e2e_golang_*build.rs'
25+
- 'crates/socket-patch-cli/tests/e2e_vendor_golang_build.rs'
26+
- 'crates/socket-patch-cli/tests/golang_e2e_matrix/**'
27+
- 'crates/socket-patch-cli/tests/e2e_vex_lockfile/golang.rs'
28+
push:
29+
branches: [main]
30+
# The ecosystem's pre-#1198 relevance set (the shared engine code its
31+
# cells run through), its PR paths and the toolchain files. A main
32+
# push outside this set waits for the nightly run below.
1133
paths:
1234
- '.github/workflows/go-compatibility.yml'
1335
- 'crates/socket-patch-core/src/vendor/go*.rs'
@@ -22,8 +44,18 @@ on:
2244
- 'crates/socket-patch-cli/tests/golang_e2e_matrix/**'
2345
- 'crates/socket-patch-cli/tests/e2e_vex_lockfile/golang.rs'
2446
- 'crates/socket-patch-cli/tests/vex_e2e_common/**'
25-
push:
26-
branches: [main]
47+
- 'crates/*/src/**/*golang*'
48+
- 'crates/*/src/**/*golang*/**'
49+
- 'crates/socket-patch-core/src/crawlers/go_crawler/**'
50+
- 'Cargo.lock'
51+
- 'Cargo.toml'
52+
- 'crates/*/Cargo.toml'
53+
- 'rust-toolchain.toml'
54+
- '.cargo/**'
55+
schedule:
56+
# Nightly full matrix, so a main change outside the push filter
57+
# still gets a run within a day.
58+
- cron: '17 4 * * *'
2759
workflow_dispatch:
2860

2961
permissions:

‎.github/workflows/gradle-compatibility.yml‎

Lines changed: 53 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,12 @@ name: Gradle patch compatibility
3737
# download them. Every cell uploads its JSON probe reports
3838
# (gradle_build_common::probe_report: Gradle / JDK version, resolved jar path
3939
# and sha256, hash-dir naming, refresh / RO-cache / transform canaries).
40+
#
41+
# On pull_request the ubuntu `cells` are skipped: ci.yml's `e2e` PR tier runs
42+
# the same suites, filters, Gradle lines and JDKs on ubuntu on every PR and
43+
# in the merge queue. The ubuntu `extras` run on a PR only when it touches
44+
# Gradle code (`changes` below); every other PR gets them from the nightly
45+
# (#1177). Windows cells run on every PR that matches `paths:`.
4046

4147
on:
4248
pull_request:
@@ -100,16 +106,58 @@ env:
100106
SOCKET_TELEMETRY_DISABLED: '1'
101107

102108
jobs:
109+
changes:
110+
# Whether this run needs the ubuntu `extras`: always off pull_request, and
111+
# on a PR only when it touches Gradle code.
112+
if: github.event.pull_request.draft != true
113+
runs-on: ubuntu-latest
114+
timeout-minutes: 5
115+
outputs:
116+
gradle_core: ${{ steps.diff.outputs.gradle_core }}
117+
steps:
118+
- name: Checkout
119+
if: github.event_name == 'pull_request'
120+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
121+
with:
122+
persist-credentials: false
123+
# The PR merge commit and its first parent, the base it merges into.
124+
fetch-depth: 2
125+
126+
- name: Diff against the base
127+
id: diff
128+
shell: bash
129+
env:
130+
EVENT_NAME: ${{ github.event_name }}
131+
run: |
132+
set -euo pipefail
133+
if [ "$EVENT_NAME" != pull_request ]; then
134+
echo "gradle_core=true" >> "$GITHUB_OUTPUT"
135+
exit 0
136+
fi
137+
core='^(\.github/workflows/gradle-compatibility\.yml$|scripts/install-gradle\.sh$'
138+
core+='|crates/socket-patch-core/src/gradle/|crates/socket-patch-core/src/vendor/jvm/'
139+
core+='|crates/socket-patch-core/src/crawlers/gradle_cache\.rs$'
140+
core+='|crates/socket-patch-core/src/patch/redirect/([^/]*\.gradle|gradle\.rs|upstream/gradle\.rs)$'
141+
core+='|crates/socket-patch-cli/tests/(gradle_|e2e_[^/]*gradle|e2e_vendor_jvm_build))'
142+
if git diff --name-only HEAD^1 HEAD | grep -E "$core"; then
143+
echo "gradle_core=true" >> "$GITHUB_OUTPUT"
144+
else
145+
echo "No Gradle code changed; the ubuntu extras run nightly."
146+
echo "gradle_core=false" >> "$GITHUB_OUTPUT"
147+
fi
148+
103149
build:
104150
name: build ${{ matrix.os }}
105-
if: github.event.pull_request.draft != true
151+
needs: [changes]
106152
strategy:
107153
fail-fast: false
108154
matrix:
109155
os: [ubuntu-latest, macos-latest, windows-latest]
110156
exclude:
111157
# macOS legs run on push to main (and nightly where scheduled), not per PR push.
112158
- os: ${{ github.event_name == 'pull_request' && 'macos-latest' || '' }}
159+
# On a PR only the ubuntu `extras` use the ubuntu build.
160+
- os: ${{ github.event_name == 'pull_request' && needs.changes.outputs.gradle_core != 'true' && 'ubuntu-latest' || '' }}
113161
runs-on: ${{ matrix.os }}
114162
timeout-minutes: 60
115163
env:
@@ -185,6 +233,8 @@ jobs:
185233
exclude:
186234
# macOS legs run on push to main (and nightly where scheduled), not per PR push.
187235
- os: ${{ github.event_name == 'pull_request' && 'macos-latest' || '' }}
236+
# ci.yml's `e2e` runs these ubuntu cells on every PR (#1177).
237+
- os: ${{ github.event_name == 'pull_request' && 'ubuntu-latest' || '' }}
188238
runs-on: ${{ matrix.os }}
189239
timeout-minutes: 60
190240
steps: &cell-steps
@@ -348,7 +398,8 @@ jobs:
348398

349399
extras:
350400
name: gradle ${{ matrix.gradle }} / jdk ${{ matrix.java }} / ${{ matrix.mode }} / ${{ matrix.label }}
351-
needs: [build]
401+
needs: [changes, build]
402+
if: needs.changes.outputs.gradle_core == 'true'
352403
strategy:
353404
fail-fast: false
354405
matrix:

0 commit comments

Comments
 (0)