You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
feat(cargo): project-local [patch]-redirect backend + single fail-closed guard (#102)
* feat(cargo): project-local [patch]-redirect backend with fail-closed guard
Local cargo patching no longer mutates the shared $CARGO_HOME registry. `apply`
now materialises a project-local patched copy under
`.socket/cargo-patches/<name>-<version>/`, points cargo at it with a managed
`[patch.crates-io]` entry in `.cargo/config.toml`, and reuses the hardened
`apply_package_patch` pipeline against the copy. Patches are project-scoped,
the `.cargo-checksum.json` rewrite disappears (a path-dep isn't checksum
verified), and removal is clean. Vendored crates and `--global` keep the
in-place sidecar path unchanged.
New `socket-patch-guard` crate (build-time) keeps committed patches honest. Its
build.rs runs `apply --check` and is FAIL-CLOSED: on drift it fails the build
rather than silently compiling stale/unpatched sources, so a one-shot CI build
can't ship an unpatched binary. The check inspects the static committed state,
so it's independent of cargo's build-script ordering. `SOCKET_PATCH_GUARD=warn`
heals-and-continues (one-build lag); `=off` disables it loudly.
`apply --check` is a read-only, lock-free, offline auditor (CI / GitHub-App
gate) that verifies copies vs manifest AND cross-checks Cargo.lock to catch a
patched dependency that resolved to an unpatched version. `setup` wires the
guard dep per workspace member + `[env] SOCKET_PATCH_ROOT` (never touching the
user's build.rs); that setup state is owned by setup/`setup --remove` and is
preserved by `rollback` (which removes only patch state).
Adds cargo_config + cargo_redirect (core), cargo_setup, the guard crate, and
unit + e2e coverage (e2e_cargo_coexist, setup_cargo_roundtrip,
guard_build_integration) incl. real-cargo fail-closed proofs.
Pre-GA: socket-patch-guard must be published to crates.io (in-repo path dep for
now).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(cargo): single fail-closed guard, ship cargo by default, harden redirect audit
Finalizes the project-local cargo `[patch]`-redirect backend for review.
Guard — collapse to a single **fail-closed** mode: remove `warn`/`off` and the
`SOCKET_PATCH_GUARD` env entirely (warn could ship unpatched on a resolved-version
mismatch). The build script runs `apply --check`; in sync → proceed; on drift it
heals (`apply`) then fails the build (the current build already compiled the stale
copy — the re-run is clean); a missing/unrecoverable CLI fails closed.
Ship cargo by default — `default = ["cargo"]` in both crates (npm + PyPI stay
unconditional), so released binaries and `cargo install socket-patch-cli` patch
Rust deps and run the guard out of the box; golang/maven/composer/nuget/deno stay
opt-in. A `--no-default-features` binary's `apply --check` now fails closed instead
of reporting "in sync", so a cargo-less CLI can never make the guard pass vacuously.
Hardening from an adversarial pre-push review (17 confirmed findings):
- verify_cargo_redirect_state now checks the `[patch]` entry path matches the
desired version (new `Drift::WrongEntryPath`, + regression test) — a stale-version
entry no longer audits as in-sync while cargo links the unpatched crate.
- a corrupt/unreadable manifest in `apply --check` now fails closed (was exit 0).
- wire `guard_build_integration` + `e2e_cargo_coexist` into the CI e2e matrix; the
real fail-closed proofs were `#[ignore]` and never ran in CI.
- tighten test assertions that passed spuriously on cargo's `failed to run custom
build command for \`socket-patch-guard\`` boilerplate (recoverable-drift, missing
CLI, unrecoverable-drift) + assert the sentinel.
- document the duplicate-version and malformed-`Cargo.lock` cross-check limitations;
fix doc/comment drift (CHANGELOG "build-dependency", README "no warn"
contradiction, R&D no_std caveat, `.socket`→`.`, "runtime hook"→"build-time guard").
R&D — same-tick auto-heal (tests/same_tick_heal_experiment.rs + SAME_TICK_HEAL_RND.md):
a patched copy depending on the guard heals in the SAME `cargo build` (verified on
cargo 1.93.1), at zero steady-state cost. Not shipped — publish-gated; documented as
a productionization path.
Tests green in both feature configs + guard; the `#[ignore]` real-cargo proofs pass;
clippy clean on all changed files.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
0 commit comments