Repository navigation
Fix gem crawler missing Bundler 4 standalone bundle (#796) - #797
Conversation
|
[agent] Two "PDM patch compatibility" legs failed on 41b7809: Generated by Claude Code |
|
BugBot review Generated by Claude Code |
Assisted-by: Claude Code:claude-opus-5-5
`bundle install --standalone` puts gems in ./bundle and the app loads them through bundle/bundler/setup.rb. Bundler 2 also recorded the path in .bundle/config, but Bundler 4 writes no config at all, so the gem crawler never looked in ./bundle. Agent apply then patched an ambient copy of the same gem (or said it was not installed), VEX attested not_affected while the app ran the unpatched copy, and the hosted stale-install warning stayed silent. Probe ./bundle as an install root when bundle/bundler/setup.rb is present, in the slot Bundler 2's recorded path used to take. Fixes #796. Assisted-by: Claude Code:claude-opus-5-5
List the Bundler 4 standalone ./bundle tree in the CLI contract's gem install-root order, so the documented roots match what the crawler probes. Assisted-by: Claude Code:claude-opus-5-5
41b7809 to
20898fd
Compare
|
BugBot review Generated by Claude Code |
|
Ready for review (burn-down agent).
Generated by Claude Code |
Conflicts: ruby_crawler.rs root list keeps both new roots (standalone ./bundle as root 3, main's global-config BUNDLE_PATH as root 4, vendor/bundle 5); crawler_ruby_e2e.rs keeps both tests; PR tests updated to main's 5-arg discovery signatures. Co-Authored-By: Claude <noreply@anthropic.com>
Clean follow-up merge of newer main (no conflicts). Co-Authored-By: Claude <noreply@anthropic.com>
|
bugbot run Generated by Claude Code |
main is red since #605: two commands::vex_consumed tests assumed the name-keyed resolver never returns npm-aliased copies, but #605 taught it to probe bundled store trees. This ports the tests-only fix from #851 so this PR's CI goes green; it no-ops once main carries #851. Assisted-by: Claude Code:claude-opus-5-5
|
[agent] Generated by Claude Code |
|
BugBot review Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 6bcaf51. Configure here.
|
Burn-down agent: labeled Ready for review.
Generated by Claude Code |
LLM Description written by Claude Code:claude-opus-5-5
Fixes #796
Summary
On Bundler 4,
bundle install --standaloneprojects were invisible to the gem crawler. Agentapplypatched an ambient copy of the same gem (or reportedpackage_not_installed), and VEX attestednot_affectedwhile the app loaded the unpatched./bundlecopy. The crawler now finds the standalone tree, so the copy the app loads is the one patched, judged by VEX, and checked by the hosted stale-install guard.Root cause
RubyCrawler::discover_bundle_stores_with_envbuilt its Bundler install roots from three sources only: the configpath,$BUNDLE_PATHand<cwd>/vendor/bundle.bundle install --standaloneinstalls into<cwd>/bundle/and writesbundle/bundler/setup.rb. Bundler 2.x also recordedBUNDLE_PATH: "bundle"in.bundle/config, which is why the issue's 2.x rows pass. Bundler 4 no longer remembers CLI flags and writes no config, so the root was never probed and the crawler fell back to thegem envhomes. The hosted stale-install guard (scan/hosted.rs) discovers installs through the same crawler, so it missed the root too. One fix at the discovery boundary covers apply, rollback, vex and the hosted guard.Fix (4 files)
crates/socket-patch-core/src/crawlers/ruby_crawler.rs: probe<cwd>/bundleas an install root whenbundle/bundler/setup.rbis a regular file. The root sits in the slot Bundler 2's recorded path occupied: after the config and env roots, beforevendor/bundle, behind the same Bundler-manifest gate. It is lexically normalized, so a Bundler 2 project whose config also namesbundlededups to one store. Like that recorded path, it is an explicit root: thegem envfallback stays on, because default gems only live there. Bundler 4 standalone projects therefore behave exactly like the Bundler 2 standalone projects the issue lists as correct.bundle/dir without the marker (a frontend build dir, scripts) is not treated as a gem store.CLI_CONTRACT.md: the gem install-root order now lists the standalone root.crawler_ruby_e2e.rsande2e_redirect_gem_stale_install.rs(below).Test evidence
Each new test was run red on main's code and green with the fix:
ruby_crawler::tests::standalone_bundle_root_discovered_without_configruby_crawler::tests::standalone_bundle_root_probes_between_env_and_defaultcrawler_ruby_e2e::get_gem_paths_finds_bundler4_standalone_tree_before_gem_homes(standalone copy found and ranked ahead of an ambient copy of the same version)e2e_redirect_gem_stale_install::gem_hosted_stale_bundler4_standalone_install_warns_and_is_not_attested(hosted guard warns with the project-local remedy; same-run--vexdoes not attest)bundle_dir_without_standalone_marker_is_not_a_store,standalone_bundle_root_ignored_without_manifest,standalone_bundle_root_dedups_with_bundler2_config_pathReal Bundler 4.0.17 repro (Ruby 3.3.6, the issue's steps:
gem install rack -v 3.2.7into the ambientGEM_HOME, thenbundle install --standalone, which writes no.bundle/config, then a staged marker patch forpkg:gem/rack@3.2.7):socket-patch apply --json --offline: the standalone copy is patched (grep -c PROBE bundle/ruby/3.3.0/gems/rack-3.2.7/lib/rack.rbreturns 1), andruby -e 'require_relative "bundle/bundler/setup"; require "rack"; p defined?(Rack::PROBE)'prints"constant". On main the standalone copy stayed at 0 and this printednil.socket-patch vex --offline:not_affectedwhile the loaded copy is patched. After reverting only the standalone copy (the issue's false-attestation state), vex omits the purl (not_applied) instead of attesting it.Local gates
.rsfiles are rustfmt-clean (rustfmt --check). A repo-widecargo fmt --all -- --checkis not clean onmainitself, and CI doesn't run it, so this PR leaves the other files alone.cargo clippy --workspace --all-features -- -D warnings: clean.cargo test --workspace --all-features --no-fail-fast: 9731 passed, 12 failed. All 12 are permission-based write-failure tests (chmod 555/ unremovable-file fixtures) that cannot fail as root, and this container runs as uid 0. Spot-checked tests from both affected crates, re-run as an unprivileged user (setpriv --reuid=65534), pass. None touches the gem path. The touched suites were re-run on the final head 20898fd:ruby_crawler69/69,crawler_ruby_e2e26/26,e2e_redirect_gem_stale_install26/26.CI on 20898fd: all 338 check runs pass (332 success, 6 skipped). Bugbot reviewed 20898fd and found no issues.
Per-issue checklist
bundle install --standalonetree (./bundle), so agentapplypatches the system copy and VEX attestsnot_affectedwhile the app loads the unpatched standalone copy #796, agent apply patches the standalone copy:crawler_ruby_e2e::get_gem_paths_finds_bundler4_standalone_tree_before_gem_homes+ real 4.0.17 reprobundle install --standalonetree (./bundle), so agentapplypatches the system copy and VEX attestsnot_affectedwhile the app loads the unpatched standalone copy #796, VEX never attests while the standalone copy is unpatched: real 4.0.17 repro +gem_hosted_stale_bundler4_standalone_install_warns_and_is_not_attestedbundle install --standalonetree (./bundle), so agentapplypatches the system copy and VEX attestsnot_affectedwhile the app loads the unpatched standalone copy #796,package_not_installedwith no ambient copy: covered by the same discovery (standalone_bundle_root_discovered_without_config)bundle install --standalonetree (./bundle), so agentapplypatches the system copy and VEX attestsnot_affectedwhile the app loads the unpatched standalone copy #796, hosted stale-install guard (flagged as unverified in the issue):gem_hosted_stale_bundler4_standalone_install_warns_and_is_not_attestedCI note
An earlier head picked up unrelated whitespace reformatting from a repo-wide
cargo fmt. The branch (agent-owned) was rebuilt frommainwith only the four files above. On that earlier head, three PDM-compatibility legs each failed one different PDM hosted case (appliedExactlyOne). That path is untouched here, and the rerun of the failed jobs passed.🤖 Generated with Claude Code
https://claude.ai/code/session_01WT6bsGwkaDRadX3XUgBxvt
Note
Medium Risk
Changes which on-disk gem trees are discovered and patched for Ruby projects; behavior is narrowed by the setup.rb marker and manifest gate, but mistaken discovery could still target the wrong directory in edge layouts.
Overview
Fixes #796: Bundler 4
bundle install --standalonelayouts were skipped because they install under./bundle/and no longer write.bundle/config, so the gem crawler only saw ambientgem envcopies.apply, hosted stale-install checks, and--vexcould miss or mis-judge the tree the app actually loads viabundle/bundler/setup.rb.The Ruby crawler now treats
<cwd>/bundleas an explicit Bundler root whenbundle/bundler/setup.rbis present—after config/env roots and beforevendor/bundle, gated on a Bundler manifest like other explicit roots, with dedup when Bundler 2 still recordsBUNDLE_PATH: "bundle". Abundle/directory without that marker is not crawled.CLI_CONTRACT.mddocuments the updated root order.Coverage adds unit tests in
ruby_crawler, an e2eget_gem_pathsranking test, a hosted stale-install +--vexe2e for standalone copies, and smallvex_consumednpm regression tweaks after #605 (resolver vs alias-expansion expectations).Reviewed by Cursor Bugbot for commit 6bcaf51. Configure here.
Generated by Claude Code