Repository navigation
Fix lockless Gemfile pinning shared-home gems (#1125) - #1304
Merged
Merged
Conversation
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A Gemfile with no Gemfile.lock (a fresh library clone before `bundle install`) skipped the #1060 version-not-locked guard, so a hosted scan pinned whatever version the shared gem home held: `gem "x", "~> 2.0"` was rewritten down to another project's 1.0.0, and a gem the project never declared was appended as a new dependency. Both exited 0, and rollback cannot undo a Gemfile-only pin. Hosted mode now skips every gem in a lockless project with `redirect_gem_no_lockfile`, writing nothing; the detail asks for `bundle lock` (or `bundle install`) and a re-run. Rewriter unit tests that used lockless Gemfiles now carry a CHECKSUMS-less lock. Fixes #1125 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko)
marked this pull request as ready for review
October 9, 2026 17:54
Collaborator
Author
|
BugBot review |
Mikola Lysenko (mikolalysenko)
enabled auto-merge
October 9, 2026 17:54
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 25aabce. Configure here.
Tanmay Singla (Tanmay182003)
approved these changes
Oct 9, 2026
Mikola Lysenko (mikolalysenko)
disabled auto-merge
October 9, 2026 19:55
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by Claude Code:claude-opus-5-5
Fixes #1125
Summary
In a project with a
Gemfile/gems.rband noGemfile.lock/gems.locked(a library repo beforebundle install), a hosted scan pinned whatever version the machine's shared gem home held:gem "x", "~> 2.0"was rewritten tosource "<patch registry>" do gem "x", "1.0.0" end, a downgrade below the user's constraint.Both runs exited 0 with
action: pinned.rollback/removecan't undo a Gemfile-only pin, because CLI_CONTRACT "Lockless pins" says it isn't a reference.Root cause
The #1060 guard (
redirect_gem_version_not_locked) inrewrite_gemsits insideif let Some(specs) = &locked. With no lock,lockedisNone, so a crawled shared-home version fell through to the exact-pin rewrite and the append-a-block branch.Fix
Hosted mode re-points the version a lock resolves and never picks one itself. So with no lock, every gem is now skipped with the new additive warning
redirect_gem_no_lockfile, and nothing is written. The warning detail names the gem and asks forbundle lock(orbundle install), a commit, and a re-run. This follows the maintainer's triage: "Require a resolve/lock step with a clear remedy." CLI_CONTRACT.md documents the code in the additive-codes list and the warnings table.Several existing rewriter unit tests used lockless Gemfiles to exercise Gemfile spelling logic: paren calls, CRLF, rotated grants, and gems.rb twins. They now carry a minimal CHECKSUMS-less lock through a new
gem_lock_resolvinghelper. That lock shape leaves the lock untouched, so those tests still check exactly what they checked before.Tests (per issue)
gem "x", "~> 2.0"becomes the older patched"1.0.0", and a gem the project never declared is appended as a new dependency #1125 unit:patch::redirect::tests::gem_without_a_lock_is_never_pinnedcovers a~> 2.0range, an undeclared gem, an exact pin, and thegems.rbspelling. No files, no edits, oneredirect_gem_no_lockfile.gem "x", "~> 2.0"becomes the older patched"1.0.0", and a gem the project never declared is appended as a new dependency #1125 e2e (real binary + mock API):e2e_redirect_gem_stale_install::gem_hosted_scan_without_a_lock_pins_nothinguses a shared-home copy at 1.0.0 with a lockless~> 2.0Gemfile and with an undeclared gem. Exit 0,redirected: 0, and the Gemfile is byte-identical.Red→green: with the guard disabled, the e2e fails at the
redirected: 0assertion, and the unit test failed before the fix.Commands run
cargo test -p socket-patch-core --tests: all pass. The lib run is 6110 tests.cargo test -p socket-patch-cli --all-features --test hosted_memory_engine --test e2e_vex_redirect --test e2e_vex_lockfile --test e2e_redirect_gem_stale_install --test in_process_vendor: all passcargo test -p socket-patch-cli --test e2e_redirect_gem_build -- --ignored(Bundler 4.0.15): 28 passedcargo clippy --workspace --all-features -- -D warnings: cleancargo fmt --all -- --check: clean for the changed files. Theupstream/mod.rsdiff already exists on main.🤖 Generated with Claude Code