Composer vendored → hosted takeover rewrites the vendored lock entry in place, keeping the patch-uuid dist.reference and transport-options: Composer 1 install crashes and rollback refuses
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 68/100
Hướng nghiên cứu
Start in crates/socket-patch-cli/src/commands/scan/hosted.rs:1512 to trace Composer takeover dispatch, then inspect crates/socket-patch-core/src/formats/composer/hosted.rs:154 and the takeover reconciliation guidance in CLI_CONTRACT.md. Reproduce the vendored-to-hosted flow from the issue and check docs/testing/composer-compatibility.md. Done means the result matches a direct hosted scan, installs on supported Composer versions, and rollback can restore it.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
[agent] Found by the scheduled Composer bug-hunt routine (ledger #321).
Summary
scan --mode hosted over a project whose Composer package is currently vendored doesn't revert the vendored wiring first, unlike cargo, npm and golang (and PyPI in open PR #503). The hosted rewriter edits the vendored lock entry in place. It changes dist.type from path to zip, points dist.url at the hosted archive and sets shasum. It keeps two fields that socket-patch's vendored mode wrote:
"dist.reference": "<patch uuid>"(vendored mode replaces the upstream commit with the patch uuid)"transport-options": {"symlink": false}
The run only warns redirect_supersedes_vendored and tells the user to run socket-patch remove <purl>. Following that advice doesn't touch the lock ("composer.lock entry … no longer points into .socket/vendor/composer/; left alone").
Impact
- Composer 1.10 can't install the project at all. It passes
transport-optionsintostream_context_create(), which fails withUncaught ValueError: Options should have the form ["wrappername"]["optionname"] = $value(StreamContextFactory.php:153, exit 255). This is the same Composer 1 failure mode #399 reported for path repositories, but here socket-patch wrote the offending key itself. rollbackrefuses, so the hosted state can't be undone except through git:Cannot restore pkg:composer/psr/[email protected] to its upstream registry entry: … the lock pins dist.reference "9f6b2c4e-…" but packagist now serves "f16e1d58…"; restore it from version control instead.- The committed
.socket/vendor/composer/<uuid>/artifact and its ledger entry are orphaned (warned about, but not reconciled).
The other direction works correctly. Hosted → vendored restores the upstream packagist entry first (vendor_takeover_reverted_redirect). Running vendor --revert and then scan --mode hosted produces a lock byte-identical to a direct hosted scan, and that lock installs patched on Composer 1.10.28.
Repro (Linux, main 61cfb9b)
The fixture is a real packagist-origin lock: composer.json {"require":{"psr/log":"3.0.2"}}, created with composer update --no-install. A local mock of the patch API grants uuid 9f6b2c4e-1d3a-4f6b-8c2d-7e5a9b1c3d5f for pkg:composer/psr/[email protected] (patches/package with sha1 and sha512 integrity, plus a single-top-dir zip of the patched package). secure-http: false is set in $COMPOSER_HOME/config.json for the loopback mock.
A="--api-url http://127.0.0.1:8766 --org test-org --api-token fake --patch-server-url http://127.0.0.1:8766"
socket-patch scan --mode vendored --yes $A # exit 0; lock -> dist: path, reference: <uuid>, transport-options {symlink:false}
git add -A && git commit -qm vendored
socket-patch scan --mode hosted --json --yes $A # exit 0, redirected: 1, warnings: [redirect_supersedes_vendored]
jq '.packages[0] | {dist, source, "transport-options"}' composer.lock
# {"dist":{"type":"zip","url":"http://127.0.0.1:8766/patch/composer/psr/log/3.0.2/<tok>/9f6b2c4e-…/log-3.0.2.zip",
# "reference":"9f6b2c4e-1d3a-4f6b-8c2d-7e5a9b1c3d5f","shasum":"40b75d18…"},
# "source":null,"transport-options":{"symlink":false}}
rm -rf vendor && php composer-1.10.28.phar install # PHP Fatal error: Uncaught ValueError … StreamContextFactory.php:153 (exit 255)
socket-patch rollback --yes $A # exit 1: lock pins dist.reference "9f6b2c4e-…" but packagist now serves "f16e1d58…"
socket-patch remove pkg:composer/psr/[email protected] --yes $A # reverts the ledger entry/artifact; composer.lock left unchanged
Control on the same fixture: vendor --revert → scan --mode hosted gives reference: f16e1d58… with no transport-options, and Composer 1.10.28 installs the patched bytes.
Expected vs actual
- Expected: CLI_CONTRACT.md, "Takeover reconciliation", says "Hosted → vendored and vendored → hosted (
redirect_takeover_reverted_vendored) both work in place on the locks the target mode accepts". A vendored Composer purl should be reverted to its recorded original (upstream) entry before the hosted rewrite, as cargo, npm and golang are. The result should match a direct hosted scan: an installable lock on every supported Composer version (docs/testing/composer-compatibility.md: 1.10 → 2.10) thatrollbackcan restore. - Actual: the vendored entry is rewritten in place. The patch-uuid
referenceandtransport-optionssurvive, Composer 1 can't install, androllbackrefuses.
Matrix (reproduced twice from scratch, plus the original run)
| OS | Composer (PHP) | Install after vendored → hosted | rollback |
|---|---|---|---|
| Linux | 1.10.28 (8.3) | fails, ValueError, exit 255 | refuses (reference mismatch) |
| Linux | 2.2.30 (8.3) | installs patched | refuses |
| Linux | 2.8.12 (8.3) | installs patched | refuses |
| Linux | 2.10.3 (8.3) | installs patched | refuses |
macOS and Windows weren't probed. The trigger is pure lock text, and #399's probe (https://github.com/SocketDev/socket-patch/actions/runs/36903408294) already shows that Composer 1.10.28 crashes on any non-stream transport-options key on ubuntu, macOS and Windows, on PHP 7.2–8.4.
Not bisected: with these flags, v4.0.0's vendored scan exits 1, so it gives no baseline.
Suspect code
crates/socket-patch-cli/src/commands/scan/hosted.rs:1512:takeover_capableonly admitspkg:cargo/,pkg:npm/andpkg:golang/(PR #503 addspkg:pypi/), so a vendoredpkg:composer/purl skipsdispatch_revert_oneand goes straight to the rewriter.crates/socket-patch-core/src/formats/composer/hosted.rs:154(rewrite_composer_lock) keeps the entry'stransport-optionsanddist.reference. Thetransport-optionspart is the same root cause as #399; this issue is about the missing takeover revert.
- Ngôn ngữ chính
- Rust
- Star
- 8
- Fork
- 0
- Merge trung bình
- 1 ngày 7 phút
- Pull request đã merge (30 ngày)
- 178
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của SocketDev/socket-patch
-
Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap)Có thể đã có người làm @mikolalysenko đã nhận 1 ngày trước. Đang mởagent:claimed agent:triaged bug bughunt pm:yarn-classic priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
SocketDev/socket-patch#907 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
vendor --check fails a vendored package whose lock is contested by a sibling package-lock.json with "no lockfile or config references .socket/vendor/… any more", which is false, and its remedy ("re-run socket-patch vendor") is a no-op, so the check stays red foreverCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mởagent:triaged bug bughunt pm:npm priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
SocketDev/socket-patch#900 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged bug bughunt pm:bundler priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
SocketDev/socket-patch#896 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 73/100
SocketDev/socket-patch#783 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged bug bughunt pm:pipenv priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 83/100
SocketDev/socket-patch#744 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của SocketDev/socket-patch
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
joshstevens19/rindexer#483 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
VX_PRINT_DROPS prints each drop point twice on the default code generator, the second time at line 0Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 66/100
CommunityToolkit/Aspire#2231 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100