Repository navigation
Align ignored npm/vendored e2e tests with v5 behavior - #1354
Merged
Merged
Conversation
Three on-demand live-production tests encoded v4 behavior and failed on main. Each is drift from documented v5 semantics, not a product bug: - test_npm_global_lifecycle: v5 rollback is full-state and drops the manifest records, so the following `apply -g` had nothing to apply. The lifecycle now rolls back with --preserve-state and asserts the record is kept. - test_npm_uuid_shortcut: `socket-patch <uuid>` is `get <uuid>`, which runs hosted mode in a lockfile project. The test now asserts the hosted pin in package-lock.json, and that `<uuid> --mode agent` patches in place and records the manifest. - yarn_berry_vendored_install_proof: v5 vendored mode is manifest-free, so the manifest-less VEX leg asserts no manifest instead of deleting one. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Collaborator
Author
|
BugBot review |
Mikola Lysenko (mikolalysenko)
enabled auto-merge
October 9, 2026 17:35
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 9fb0100. Configure here.
Tanmay Singla (Tanmay182003)
approved these changes
Oct 9, 2026
Collaborator
Author
|
Ready for review at
Labeled Generated by Claude Code |
Mikola Lysenko (mikolalysenko)
removed this pull request from the merge queue due to a manual request
Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by Claude Code:claude-opus-5-5
Three on-demand live-production tests (
#[ignore], not run in CI) fail on main. In each case the test still encodes v4 behavior, and the CLI does what CLI_CONTRACT.md documents for v5. These are test fixes only, so no issue was filed.e2e_npm::test_npm_global_lifecyclerollback -g --global-prefix X,apply -g --global-prefix Xleavesindex.jsunpatchedrollbackis full-state: it restores files and removes the rolled-back manifest entries (contract:rollbackrow, and "Global scope never touches the project's state").applythen has nothing left to apply.--preserve-state, which restores the file and keeps the record, and assert that the record survives.remove -gstill checks that the manifest is dropped.e2e_npm::test_npm_uuid_shortcutsocket-patch <uuid>leaves the installed file unpatchedget <uuid>, andgetdefaults to hosted mode in a lockfile project (contract:getrow, "Bare-UUID fallback")package-lock.jsonpins minimist tohttps://patch.socket.dev/…<uuid>…, the installed tree is untouched and no manifest exists. Then check that<uuid> --mode agentgoes through the shortcut and patches in place with a manifest record.e2e_vendored_production::yarn_berry_vendored_install_proofremove_file(.socket/manifest.json)panicsscan --mode vendoredis manifest-free, and the ledger embeds each entry's recordCoordination
This PR does not touch the UUID/hash constants. #1301 repins those to the republished minimist patch
642d7f02-…. Its body already lists these three failures as unrelated to the repin. The two PRs touch separate hunks of the same files and merge cleanly in either order.Verification (macOS, live production, with #1301's repin applied locally on top)
cargo test -p socket-patch-cli --test e2e_npm -- --ignored: 7/7 pass, includingtest_npm_global_lifecycleandtest_npm_uuid_shortcutcargo test -p socket-patch-cli --test e2e_vendored_production -- --include-ignored yarn_berry_vendored_install_proof: pass (yarn@4.6.0,VEX-MATRIX|…|PASS)🤖 Generated with Claude Code
Note
Low Risk
Test-only updates to ignored live e2e suites; no runtime or CLI logic changes.
Overview
Updates three
#[ignore]live e2e tests that still asserted v4 CLI semantics so they match v5 (CLI_CONTRACT.md). No production code changes.e2e_npm::test_npm_global_lifecycle— Global rollback now uses--preserve-stateso the manifest entry remains for the followingapply -g; v5 defaultrollbackis full-state and would leave nothing to re-apply. Adds an assertion that the patch record survives rollback.e2e_npm::test_npm_uuid_shortcut— Baresocket-patch <UUID>is exercised as hostedget: lockfileresolvedpoints athttps://patch.socket.dev/…, installed tree and hash stay pristine, no.socket/manifest.json. A second fixture checks<UUID> --mode agentfor in-place patch + manifest, matching the prior single-scenario expectation.e2e_vendored_production(yarn berry manifest-less VEX) — Replacesremove_file(.socket/manifest.json)(which panicked) with an assertion that vendoredscannever creates a manifest; the vendor ledger already embeds records in v5.Reviewed by Cursor Bugbot for commit 9fb0100. Configure here.
Generated by Claude Code