Recognize hosted Pipenv references through one shared grammar (#563) - #572
Conversation
Assisted-by: Claude Code:claude-opus-5-5
Hosted Pipenv refused to rotate its own pin when --patch-server-url carried a path prefix, and treated its own hosted sdist pins as user sources. Vendored Pipenv called any https host's /patch/pypi/ URL a Socket reference and told the user to run rollback for a foreign source, while a path-prefixed or sdist hosted pin got the "user-declared" remedy instead. Both now ask lock_inventory::pypi::hosted_pypi_reference: the hosted_patch_url_uuids origin policy plus the hosted_artifact_url tail grammar. The two private segment-count grammars are deleted. Vendored Pipenv passes the run's --patch-server-url origin. Fixes #563 Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
Assisted-by: Claude Code:claude-opus-5-5
|
[agent] CI: This doesn't look like this PR:
I couldn't read the case's Generated by Claude Code |
The new Pipenv remedy test printed the whole refusal detail on failure, which CodeQL traces as a patch uuid written to a log. Print only the URL and the expected phrase. Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit ff3ef3e. Configure here.
|
[agent] CI: This doesn't look like this PR:
I'll re-run the failed job once when the run completes. If it fails again, I'll treat it as real. Generated by Claude Code |
|
[agent] CI: This is a transport error against the patch API. The pnpm code it covers isn't touched by this Pipenv-only diff, and the vlt job's transport retries above suggest the same instability. I'll re-run this failed job once. A second failure gets root-caused. Generated by Claude Code |
|
[burn-down agent] Labeled Ready for review at
Generated by Claude Code |
|
Reviewed Checked shared origin/path/filename recognition, foreign-source refusal, category handling, and VEX/rollback interactions. Path-prefixed origins and hosted sdists rotate correctly; foreign hosts, credentials, coordinate mismatches, empty UUID levels, and trailing slashes remain refused. Validation: 63 Pipenv core tests, 6 shared-origin tests, 20 PyPI VEX discovery tests, and 2 independent reviewer probes passed. The probes additionally exercised custom HTTP origins, rotation/idempotence and 20 URL boundary cases. Clean merge with current |
Assisted-by: Claude Code:claude-opus-5-5
LLM Description written by Claude Code:claude-opus-5-5
Fixes #563
Summary
Hosted and vendored Pipenv each had their own private grammar for deciding whether a
Pipfile.lockURL is a Socket-hosted PyPI patch reference. This PR moves both onto one shared recognizer,lock_inventory::pypi::hosted_pypi_reference, and deletes the two copies.Why (leverage)
arch-refactor/*oragent/fix-*PR. Hosted NuGet mapping reads commented-out package sources #561 ranked close behind but touchesredirect/mod.rs, which four open PRs also change.What changed
hosted_pypi_reference(url, origins). It applies theredirect::hosted_patch_url_uuidsorigin policy (patch.socket.dev or a configured origin, no userinfo), then thehosted_artifact_urltail grammar (…/patch/pypi/<n>/<v>/<grant>/<uuid>/<wheel-or-sdist>, matched from the end), and requires a non-empty uuid level.redirect::pipenv::owned_url= the shared recognizer on the grant's own origin, plus a check that the name and version match the dep.pypi_pipenv::check_target_guards/wire_pipenvtakehosted_origins.vendor_pypi_with_pipenv_versionpasses the run'sVendorServiceConfig.patch_server_url.service_preflightpasses&[]: only the verdict matters there, and both refusal branches carry the same code.Deleted
owned_url(≈30 lines).vendor/pypi_pipenv.rs::is_socket_hosted_reference(≈10 lines).#[cfg(test)]): production +31 / −48, tests +174 / −37.Behavior
These changes are intended. They are what #563 asks for:
--patch-server-urlorigin, and a hosted sdist pin, as ours. Rotation works where it used to returnConflict("Pipenv source for … already exists")./patch/pypi/…URL the "user-declared" remedy, where it used to say "HOSTED … run rollback". A hosted sdist or path-prefixed pin on an accepted origin now gets the HOSTED remedy. The error code ispypi_pipenv_source_already_existsin every case, unchanged.owned_urlused to reject a URL with a?query. The shared recognizer ignores the query, the same ashosted_patch_uuid. Socket never writes one.npm/,pypi/,gem/) need nothing./patch/pypi/grammar of their own (checked with grep), so nothing more to unify there.Test evidence
cargo clippy --workspace --all-features -- -D warnings: clean.cargo test -p socket-patch-core --lib: 4756 passed, 4 failed. The 4 fail identically onorigin/mainbecause the sandbox runs as root (permission-dependent tests):copy_tree::relax_loop_must_not_traverse_symlinked_root,vlt_heal::an_unremovable_hidden_lock_keeps_every_store_entry,pypi_poetry::wire_write_failure_maps_error_and_leaves_lock_untouched,pypi_requirements::wire_failure_rolls_back_already_written_files.cargo test -p socket-patch-cli --all-features --test in_process_redirect_pipenv --test hosted_memory_engine --test hosted_memory_parity: 6 + 28 + 31 passed.redirect::pipenv::tests::owned_url_accepts_path_prefixed_origins_and_sdistsfails with the oldowned_urlswapped back in and passes now.vendor::pypi_pipenv::tests::hosted_reference_remedy_follows_the_shared_recognizerfails with the oldis_socket_hosted_referenceswapped back in (the evil.example URL was called HOSTED) and passes now.owned_url_follows_the_grant_originand the vendored Pipenv suite stay green.pypi_pipenvtests are still green (27 passed).platform-windowshosted failed once and passed on re-run. It isn't on a path this PR touches (see comment).Risk
Low. The change is confined to Pipenv ownership and remedy selection, and every refusal keeps its code.
🤖 Generated with Claude Code
https://claude.ai/code/session_01WhtPehwinReW5U3cPmhccc
Note
Low Risk
Scope is Pipenv lock URL classification and error messaging only; no auth, API, or contract changes, with existing refusal codes preserved.
Overview
Unifies how hosted Pipenv lock rotation and vendored Pipenv guards decide whether a
Pipfile.lockURL is Socket’s own hosted PyPI patch, by introducing sharedhosted_pypi_referenceand removing two duplicate grammars.Hosted
owned_urlnow delegates to that helper (origin policy + tail-matched/patch/pypi/…path) instead of a fixed segment-count wheel-only check, so path-prefixed--patch-server-urldeployments and hosted sdist pins count as “ours” and can rotate. Vendoredcheck_target_guards/wire_pipenvtakehosted_originsfrom the run’spatch_server_url; hosted vs user-declared remedy text follows the same recognizer (foreign hosts with/patch/pypi/…are user-declared; trusted origins get the HOSTED rollback message). Error codes are unchanged.Tests cover path-prefixed rotation, sdists, and remedy wording where the old copies disagreed.
Reviewed by Cursor Bugbot for commit ff3ef3e. Configure here.
Generated by Claude Code