Skip to content

Composer vendored → hosted takeover rewrites the vendored lock entry in place, keeping the patch-uuid dist.reference and transport-options: Composer 1 install crashes and rollback refuses #536

Description

[agent] Found by the scheduled Composer bug-hunt routine (ledger #321).

Summary

scan --mode hosted over a project whose Composer package is currently vendored doesn't revert the vendored wiring first, unlike cargo, npm and golang (and PyPI in open PR #503). The hosted rewriter edits the vendored lock entry in place. It changes dist.type from path to zip, points dist.url at the hosted archive and sets shasum. It keeps two fields that socket-patch's vendored mode wrote:

  • "dist.reference": "<patch uuid>" (vendored mode replaces the upstream commit with the patch uuid)
  • "transport-options": {"symlink": false}

The run only warns redirect_supersedes_vendored and tells the user to run socket-patch remove <purl>. Following that advice doesn't touch the lock ("composer.lock entry … no longer points into .socket/vendor/composer/; left alone").

Impact

  1. Composer 1.10 can't install the project at all. It passes transport-options into stream_context_create(), which fails with Uncaught ValueError: Options should have the form ["wrappername"]["optionname"] = $value (StreamContextFactory.php:153, exit 255). This is the same Composer 1 failure mode Hosted Composer rewrite keeps the entry's transport-options, so Composer sends a private repository's auth headers to the hosted patch URL #399 reported for path repositories, but here socket-patch wrote the offending key itself.
  2. rollback refuses, so the hosted state can't be undone except through git: Cannot restore pkg:composer/psr/log@3.0.2 to its upstream registry entry: … the lock pins dist.reference "9f6b2c4e-…" but packagist now serves "f16e1d58…"; restore it from version control instead.
  3. The committed .socket/vendor/composer/<uuid>/ artifact and its ledger entry are orphaned (warned about, but not reconciled).

The other direction works correctly. Hosted → vendored restores the upstream packagist entry first (vendor_takeover_reverted_redirect). Running vendor --revert and then scan --mode hosted produces a lock byte-identical to a direct hosted scan, and that lock installs patched on Composer 1.10.28.

Repro (Linux, main 61cfb9b)

The fixture is a real packagist-origin lock: composer.json {"require":{"psr/log":"3.0.2"}}, created with composer update --no-install. A local mock of the patch API grants uuid 9f6b2c4e-1d3a-4f6b-8c2d-7e5a9b1c3d5f for pkg:composer/psr/log@3.0.2 (patches/package with sha1 and sha512 integrity, plus a single-top-dir zip of the patched package). secure-http: false is set in $COMPOSER_HOME/config.json for the loopback mock.

A="--api-url http://127.0.0.1:8766 --org test-org --api-token fake --patch-server-url http://127.0.0.1:8766"
socket-patch scan --mode vendored --yes $A        # exit 0; lock -> dist: path, reference: <uuid>, transport-options {symlink:false}
git add -A && git commit -qm vendored
socket-patch scan --mode hosted --json --yes $A   # exit 0, redirected: 1, warnings: [redirect_supersedes_vendored]
jq '.packages[0] | {dist, source, "transport-options"}' composer.lock
# {"dist":{"type":"zip","url":"http://127.0.0.1:8766/patch/composer/psr/log/3.0.2/<tok>/9f6b2c4e-…/log-3.0.2.zip",
#          "reference":"9f6b2c4e-1d3a-4f6b-8c2d-7e5a9b1c3d5f","shasum":"40b75d18…"},
#  "source":null,"transport-options":{"symlink":false}}
rm -rf vendor && php composer-1.10.28.phar install   # PHP Fatal error: Uncaught ValueError … StreamContextFactory.php:153 (exit 255)
socket-patch rollback --yes $A                       # exit 1: lock pins dist.reference "9f6b2c4e-…" but packagist now serves "f16e1d58…"
socket-patch remove pkg:composer/psr/log@3.0.2 --yes $A   # reverts the ledger entry/artifact; composer.lock left unchanged

Control on the same fixture: vendor --revert → scan --mode hosted gives reference: f16e1d58… with no transport-options, and Composer 1.10.28 installs the patched bytes.

Expected vs actual

  • Expected: CLI_CONTRACT.md, "Takeover reconciliation", says "Hosted → vendored and vendored → hosted (redirect_takeover_reverted_vendored) both work in place on the locks the target mode accepts". A vendored Composer purl should be reverted to its recorded original (upstream) entry before the hosted rewrite, as cargo, npm and golang are. The result should match a direct hosted scan: an installable lock on every supported Composer version (docs/testing/composer-compatibility.md: 1.10 → 2.10) that rollback can restore.
  • Actual: the vendored entry is rewritten in place. The patch-uuid reference and transport-options survive, Composer 1 can't install, and rollback refuses.

Matrix (reproduced twice from scratch, plus the original run)

OS Composer (PHP) Install after vendored → hosted rollback
Linux 1.10.28 (8.3) fails, ValueError, exit 255 refuses (reference mismatch)
Linux 2.2.30 (8.3) installs patched refuses
Linux 2.8.12 (8.3) installs patched refuses
Linux 2.10.3 (8.3) installs patched refuses

macOS and Windows weren't probed. The trigger is pure lock text, and #399's probe (https://github.com/SocketDev/socket-patch/actions/runs/36903408294) already shows that Composer 1.10.28 crashes on any non-stream transport-options key on ubuntu, macOS and Windows, on PHP 7.2–8.4.

Not bisected: with these flags, v4.0.0's vendored scan exits 1, so it gives no baseline.

Suspect code

Activity

  1. mikolalysenko commented on Oct 2, 2026

    @mikolalysenko
    CollaboratorAuthor

    [agent] Triaged as priority:p2 (Composer). Not a duplicate, and no PR fixes it yet.

    Shares root cause with #328 / open PR #503: the vendored → hosted takeover gate takeover_capable in crates/socket-patch-cli/src/commands/scan/hosted.rs:1512 (and its twin in crates/socket-patch-core/src/hosted/memory/stages.rs:95) admits only pkg:cargo/, pkg:npm/ and pkg:golang/. A vendored pkg:composer/ purl skips dispatch_revert_one, so the hosted rewriter edits the vendored lock entry in place. #503 adds pkg:pypi/ to the same gate. A fix for this issue needs the same change for pkg:composer/, plus a Composer revert-to-upstream before the rewrite. The transport-options part overlaps #399.


    Generated by Claude Code

  2. mikolalysenko commented on Oct 2, 2026

    @mikolalysenko
    CollaboratorAuthor

    [agent] New information from the Composer bug-hunt run (ledger #321): the get entry point hits the same path, not just scan.

    On main 61cfb9b (Linux, packagist-origin psr/log 3.0.2, mock patch API), after scan --mode vendored:

    socket-patch get <uuid> --mode hosted --yes --json …
    → status "success", no warnings (no redirect_takeover_reverted_vendored)
    composer.lock psr/log:
      dist = {type: zip, url: <hosted archive>, reference: <patch uuid>, shasum: <sha1>}
      transport-options = {symlink: false}
    

    That's the same lock shape scan --mode hosted leaves in the original report, so a fix to the takeover_capable gate should also cover get <uuid> --mode hosted, and a regression test for it would help.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions