Resolve vlt registry bases through one shared function (#562) - #574
Mikola Lysenko (mikolalysenko) wants to merge 8 commits into
Conversation
Assisted-by: Claude Code:claude-opus-5-5
vlt lock inventory (vendored fetch, VEX) and hosted rollback/remove each turned a DepID registry segment into a registry URL with their own precedence, so one lock could resolve to two registries. Both now call vlt_lock_text::registry_base, which follows vlt's DepID hydration: a mapped alias is its registries URL, the default registry is options.registry, then the default alias's URL, then npmjs. The private copies, the inline tarball URL, restore's NPM_REGISTRY and its default_alias helper are deleted. Fixes #562 Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
|
[agent] Generated by Claude Code |
|
bugbot run Generated by Claude Code |
|
[burn-down agent] Labeled Ready for review at
Generated by Claude Code |
|
Reviewed final head The scoped-registry and modern The full forward rewrite/restore regression failed before this correction and now recovers the original bytes with and without an empty-segment sibling. Direct hosted pins and sibling layout are covered too. 17 distinct focused tests pass (20 executions across restore, resolver, and inventory filters); formatting and diff checks pass. The final commit merges cleanly with checked main Ready to merge as-is from this review. Final-head CI is complete: 485 successful checks, 6 skipped; no failures or pending checks. Bugbot passed, there are no unresolved review threads, and the PR is mergeable. Legacy empty segments retain the prior compatibility policy; no full local workspace or timing run was repeated. |
|
[agent] I confirmed the scoped-registries finding against How I checked:
What this shows:
Proposed fix:
I'm marking the PR Generated by Claude Code |
Assisted-by: Claude Code:claude-opus-5-5
clippy -D warnings rejected the registry_base doc comment (doc_lazy_continuation), failing CI on cb35d5a. Separate the scoped-registry paragraph from the list, and rustfmt the three touched files that were rustfmt-clean on main. No behavior change. Assisted-by: Claude Code:claude-opus-5-5
|
[agent] One item from my earlier comment is still open on this head. With Generated by Claude Code |
|
BugBot review Generated by Claude Code |
Assisted-by: Claude Code:claude-opus-5-5
|
Follow-up to the empty-segment finding: the scoped correction is pushed as An agent in this review is now implementing and testing the |
Assisted-by: Claude Code:claude-opus-5-5
|
[agent] Generated by Claude Code |
|
BugBot review Please review final commit |
Assisted-by: Claude Code:claude-opus-5-5
…h-pr-574-empty-20261002
(cherry picked from commit 329b146)
Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Please review final head |
Assisted-by: Claude Code:claude-opus-5-5
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit ae7a035. Configure here.
Assisted-by: Claude Code:claude-opus-5-5
Fixes #562.
vlt lock inventory and hosted rollback/remove now use one registry-base resolver. A lock resolves to the same registry in both paths, including scoped packages and modern empty-tilde DepIDs. Hosted rewrite and restore retain compatible admission and tuple-layout rules.
Behavior and implementation
vlt_lock_text::registry_base(era, segment, name, options)replaces both private resolvers. Inventory also uses the shared npm tarball URL builder; duplicate default-alias and registry constants are removed.~~resolves through the literalnpmalias, matching fresh-process checks against published vlt 1.3.5. A mapped alias takes precedence overoptions.registry; a recognized default falls back to the configured registry and then the npm default. Unknown unmapped aliases are refused.scoped-registriesentry supplies the package's base. Explicit URL and named-alias segments keep their existing treatment.··empty segments retain the previous compatibility policy. Historical Node and browser vlt releases differ here; this is not a claim that every old runtime hydrated them identically.203e092band the isolated Berry benchmark correction from Stream ZIP member hashes during vendored verification #587. The fixture strictly requires bothpackage.jsonandyarn.lock, matching Berry's descriptor and lockfile rewrites.Validation
d03ae6b6and passes withae7a0353. Both the no-sibling and same-empty-sibling cases recover the original lockfile bytes, including registry B's tarball URL when the configured default is registry A.b1f9818a. The benchmark correction is identical to the already validated fixture from Stream ZIP member hashes during vendored verification #587. No full local workspace or timing run was repeated.Risk and scope
Registry precedence changes affect locks with non-default registry configuration. Unknown bases still fail closed. JSON layout, forward admission, error codes, and exit codes are unchanged. #521 remains outside this change.
Note
Medium Risk
Changes registry precedence for vlt locks with custom
registry, aliases, and scoped registries; unknown aliases still fail closed, but mis-resolved bases could affect inventory and restore slot [3] URLs.Overview
Unifies vlt DepID → registry URL resolution so lock inventory and hosted upstream restore agree, including scoped packages and modern empty-tilde (
~~) segments.The duplicate local resolvers in
vlt_lock_textare replaced by sharedregistry_base(era, segment, name, options), withdefault_registry_alias, tilde empty-segment normalization,scoped-registriesoverrides, and legacy-era empty-segment policy kept distinct from vlt 1.3.5 behavior. Lock inventory now derives inferred tarball URLs via that helper andnpm_tarball_url. Upstream restore uses the same base for slot [3], refuses when a segment maps to no registry, and keeps admission/sibling slot-3 rules on the raw DepID segment (matching forward rewrite). Mock registry paths now URL-encode scoped package names.The Yarn Berry bench fixture expects rewrites on
package.jsonandyarn.lock, not lockfile alone. Coverage addsREGISTRY_BASE_CASES, scoped-registry cases, and a forward-rewrite → restore round-trip for custom default aliases.Reviewed by Cursor Bugbot for commit ae7a035. Configure here.