Skip to content

Wire every vendored Poetry lock through utils::poetry_lock (#936) - #1185

Merged
Mikola Lysenko (mikolalysenko) merged 4 commits into
mainfrom
arch-refactor/936-poetry-one-splicer
Oct 8, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 4 commits into
mainfrom
arch-refactor/936-poetry-one-splicer

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

Fixes #936

Summary

Vendored Poetry chose its forward splicer by the lock's line endings. Legacy and CRLF locks went through the shared utils::poetry_lock engine, while LF 2.x locks went through a private toml_surgery line scanner. Now every lock goes through the engine, which writes Poetry's own one-file-per-line files array for 2.x locks. The scanner and its Poetry-only helpers are deleted.

Why

  • Issue #936, register row E66, living document Part 5 (doc/05-vendored.md, "Vendored Poetry has two forward splicers").
  • The two paths had drifted, and two runs of the audit's test confirmed it:
    • they wrote different files shapes for the same lock depending on core.autocrlf;
    • only the engine checked the wheel name and lowercased the digest;
    • only the scanner required a literal name = "…" line.
  • Leverage: B 0, U 1 (the E23 shared PyPI lock envelope and Tracking: revert every vendored backend through one record-revert engine instead of nine hand-written mechanisms #989 step 3 need one Poetry forward path), D 1 plus 129 net production lines deleted, S 0, R M. It was the best-ranked candidate whose files no open arch-refactor/* or agent/fix-* PR changes.
    • One exception: vendor/common.rs is also changed by my own #1160. Its hunks (the imports and the JSON BOM helpers, lines 9–220) don't overlap this PR's single deletion at line 626, so the two merge cleanly in either order.

What changed

  1. utils::poetry_lock writes a 2.x package's patched files with the multi-line renderer that the 1.0/1.1 [metadata.files] entries already use (multiline_files, split out of legacy_files_entry).
  2. wire_poetry calls rewrite_poetry_lock_with_edits for every lock generation and line ending.

Deleted

  • pypi_poetry::rewrite_target_package_unit
  • toml_surgery::package_unit_lines, toml_surgery::replace_files_array and their tests
  • common::unit_has_canon_name
  • Production: +37 / −166 (net −129). Tests: +144 / −140 across the unit tests and one CLI test. Two equivalence goldens are re-blessed.

Behavior

These changes are intended, and the issue's acceptance criteria ask for them:

  • Hosted rewrites of a 2.x poetry.lock (Poetry 1.3+) now write files = [\n {file = …, hash = …},\n] instead of files = [{ file = …, hash = … }]. Vendored CRLF 2.x locks get the same shape. Vendored LF output is unchanged: the fixture test wiring_matches_fixtures_byte_identically_both_lock_versions stays byte-identical. Legacy 0/1.0/1.1 output is unchanged.
  • A vendored LF 2.x lock spelled name="six", or one whose unit has no files array, now wires and reverts byte-exact, as a CRLF lock already did. Before, it was refused with pypi_poetry_lock_package_missing / pypi_poetry_lock_parse_failed.
  • Vendored LF 2.x now gets the engine's wheel-name and digest-case gates. Today's orchestrator always passes a matching wheel and a lowercase sha, so this changes nothing in practice.
  • Revert is unchanged, because both paths already reverted through revert_lock_fragment_splice_atomic. Ledgers written by the old LF path still revert: their fragments are spliced back verbatim.

Golden re-bless

  • poetry_rewrite.golden: only the 2.x generations (1.3.2 through 2.4.3, 8 cases each) move. The 0.12.17, 1.0.10, 1.1.15 and 1.2.2 cases keep their digests.
  • poetry_lock_reused_parse.golden: cases 0–231 (the 4 legacy generations × 58) keep their digests, and cases 232–869 (the 11 2.x generations) move.

Tests

  • New:
    • lf_and_crlf_locks_wire_to_the_same_fixture: each 2.x fixture wired as LF and as CRLF gives the same lock, and that lock is Poetry's own fixture. It fails on main, where CRLF wrote the inline shape.
    • wire_accepts_a_unit_spelled_without_spaces (LF and CRLF) and wire_adds_files_to_a_unit_without_one: these replace the two fail-closed tests that pinned the scanner's refusals. Both wire and then revert byte-exact.
    • lock_2x_files_keep_poetrys_multiline_shape: the hosted (url) and vendored (file) rewrite of 3 2.x fixtures, plus an idempotent re-run.
  • Commands:
    • cargo clippy --workspace --all-features -- -D warnings: clean.
    • cargo test -p socket-patch-core --lib: 5,799 passed. 4 failed, the known root-only tests (relax_loop_must_not_traverse_symlinked_root, an_unremovable_hidden_lock_keeps_every_store_entry, wire_write_failure_maps_error_and_leaves_lock_untouched, wire_failure_rolls_back_already_written_files).
    • cargo test -p socket-patch-core --test '*': all passed.
    • CLI suites, all passing: e2e_vex_lockfile (343), in_process_redirect_poetry (7), in_process_vendor (122) and hosted_memory_engine (34). covgap_commands_vendor passed 51; 3 failed, all root-only (*_state_write_failure_*, which chmod the vendor dir to 0555).
  • No changes are needed in the wrappers (npm/, pypi/, gem/).

Risk

Medium. The user-visible change is the hosted 2.x files layout, which now matches what Poetry writes. Hosted restore already rebuilds files through multiline_toml_array, and VEX discovery reads files through the parsed TOML, so neither depends on the layout.

🤖 Generated with Claude Code

https://claude.ai/code/session_019qW3rRLpBivgBuWXHMZ36z


Note

Medium Risk
Changes committed poetry.lock shape for hosted/vendored 2.x rewrites and consolidates lock mutation logic; well-covered by fixtures and goldens but affects installer hash/layout expectations.

Overview
Unifies vendored Poetry lock wiring so every lock generation and line ending goes through the shared utils::poetry_lock engine (same path hosted mode uses). The separate LF 2.x text-surgery path (rewrite_target_package_unit, toml_surgery::replace_files_array, unit_has_canon_name) is removed.

Poetry 2.x files layout: hosted and vendored rewrites now emit Poetry’s one-file-per-line files array via new multiline_files, instead of inline files = [{ file = … }]. Legacy 0/1.0/1.1 behavior is unchanged.

Behavior shifts (previously scanner-only): vendored wiring accepts name="pkg" spelling and inserts a files block when the unit had none, with byte-exact revert. LF and CRLF 2.x locks produce the same shape after normalization.

Tests and equivalence goldens are updated for the new 2.x output; e2e pin tests recognize the multiline files spelling.

Reviewed by Cursor Bugbot for commit 0c4ddab. Configure here.


Generated by Claude Code

Assisted-by: Claude Code:claude-opus-5-5
The shared poetry.lock engine rendered a 2.x package's patched
files array inline ([{ file = ..., hash = ... }]), while Poetry
itself, and the vendored LF splicer, write one file per line. Hosted
rewrites and vendored CRLF locks now get Poetry's own shape, so the
same lock gets the same diff in every mode and line ending.

Reuses the multi-line renderer the 1.0/1.1 [metadata.files] entries
already use. The poetry_rewrite and reused-parse goldens are
re-blessed: only the 2.x generations (Poetry 1.3.2+) move; every
legacy 0/1.0/1.1 case keeps its digest.

Assisted-by: Claude Code:claude-opus-5-5
Vendored Poetry picked its forward splicer by line ending: CRLF and
legacy locks went through utils::poetry_lock, LF 2.x locks through a
private line scanner that skipped the engine's wheel-name and
digest-case gates and matched only a literal 'name = "..."' line.
Every lock now goes through the engine hosted mode uses.

A 2.x lock spelled name="six", or a unit with no files array, now
wires (as a CRLF lock already did) and reverts byte-exact instead of
being refused.

Deletes rewrite_target_package_unit, toml_surgery's
package_unit_lines and replace_files_array, and
common::unit_has_canon_name (Poetry-only helpers).

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko Mikola Lysenko (mikolalysenko) added arch-refactor PR opened by the scheduled architecture refactor routine refactor Structural change: duplicated code or logic, missing abstraction, layering, dead code labels Oct 8, 2026
The VEX pin-spelling test now also strips the one-file-per-line
package files array a 2.x hosted lock carries, and the fragment
boundary test drops that array (not only an inline line) when it
simulates a relock.

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko
Mikola Lysenko (mikolalysenko) marked this pull request as ready for review October 8, 2026 22:16
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 0c4ddab. Configure here.

@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 8, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[burn-down agent] Ready for review at 0c4ddabfba

  • CI: all checks on the current head green (ci-ok success; 0 failing of 480 check runs, the rest success/skipped).
  • Mergeable against main, no conflicts; no CHANGELOG.md change.
  • Cursor Bugbot reviewed 0c4ddabfba; no unresolved review threads.

Ready for a human approval.


Generated by Claude Code

@mikolalysenko
Mikola Lysenko (mikolalysenko) added this pull request to the merge queue Oct 8, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[final reviewer] Enqueued (auto-merge on, squash) at head 0c4ddabf: approved at this head by Tanmay Singla (@Tanmay182003), ci-ok and clippy green, mergeable with current main, no open review threads. Entered the merge queue at 23:26 UTC.


Generated by Claude Code

Merged via the queue into main with commit 3a54db9 Oct 8, 2026
481 checks passed
@mikolalysenko
Mikola Lysenko (mikolalysenko) deleted the arch-refactor/936-poetry-one-splicer branch October 8, 2026 23:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

arch-refactor PR opened by the scheduled architecture refactor routine Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review refactor Structural change: duplicated code or logic, missing abstraction, layering, dead code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Vendored Poetry wires a 2.x lock through two different splicers depending on its line endings

3 participants