Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/bun-compatibility.yml
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ on:
- 'crates/socket-patch-cli/src/commands/scan/**'
- 'crates/socket-patch-cli/src/commands/rollback.rs'
- 'crates/socket-patch-cli/src/commands/vendor.rs'
- 'crates/socket-patch-cli/src/commands/repair_vendor.rs'
- 'crates/socket-patch-cli/src/commands/vendored_backend/**'
- 'crates/socket-patch-cli/src/commands/remove.rs'
# Main runs are the only rust-cache writers (save-if below), so a
# path-filtered push trigger is what seeds the cache the PR builds restore
Expand Down Expand Up @@ -75,7 +75,7 @@ on:
- 'crates/socket-patch-cli/src/commands/scan/**'
- 'crates/socket-patch-cli/src/commands/rollback.rs'
- 'crates/socket-patch-cli/src/commands/vendor.rs'
- 'crates/socket-patch-cli/src/commands/repair_vendor.rs'
- 'crates/socket-patch-cli/src/commands/vendored_backend/**'
- 'crates/socket-patch-cli/src/commands/remove.rs'
workflow_dispatch:
inputs:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/vlt-compatibility.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ on:
- 'crates/socket-patch-cli/src/commands/remove.rs'
- 'crates/socket-patch-cli/src/commands/setup.rs'
- 'crates/socket-patch-cli/src/commands/vendor.rs'
- 'crates/socket-patch-cli/src/commands/repair_vendor.rs'
- 'crates/socket-patch-cli/src/commands/vendored_backend/**'
- 'crates/socket-patch-cli/src/commands/get.rs'
- 'crates/socket-patch-cli/src/commands/vlt_preflight.rs'
- 'crates/socket-patch-cli/src/commands/scan/**'
Expand Down Expand Up @@ -74,7 +74,7 @@ on:
- 'crates/socket-patch-cli/src/commands/remove.rs'
- 'crates/socket-patch-cli/src/commands/setup.rs'
- 'crates/socket-patch-cli/src/commands/vendor.rs'
- 'crates/socket-patch-cli/src/commands/repair_vendor.rs'
- 'crates/socket-patch-cli/src/commands/vendored_backend/**'
- 'crates/socket-patch-cli/src/commands/get.rs'
- 'crates/socket-patch-cli/src/commands/vlt_preflight.rs'
- 'crates/socket-patch-cli/src/commands/scan/**'
Expand Down
24 changes: 24 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -226,6 +226,30 @@ into the new version's section — see docs/releasing.md.
(`https://repo.packagist.org`) and `SOCKET_NUGET_URL`
(`https://api.nuget.org`).

- **`repair` no longer rebuilds the vendor ledger from lockfiles.** A
lockfile that references `.socket/vendor/<eco>/<uuid>/` with no entry in
`.socket/vendor/state.json` now fails with `vendor_ledger_missing` (an
artifact-level `failed` event with `uuid` and `details.{ecosystem,path}`;
exit 1) instead of re-synthesizing the entry (`details.ledgerRestored` is
gone). The rewired lockfile cannot supply the pre-vendor originals a
revert needs, so the remedy is restoring `state.json` from version
control (or `git checkout -- <lockfile>` and re-vendoring). The unverified
npm "rebuild from the wired integrity" rung and the gem Gemfile wiring
reconstruction went with it; `rollback`'s missing-ledger error now asks
for `state.json` to be restored instead of naming `repair`.
- **`repair` re-vendors broken artifacts the way `vendor` does.** Missing
or corrupt vendored artifacts go through the same vendored backend as
`vendor` / `scan --mode vendored` / `get --mode vendored`, so under the
default `--vendor-source auto` the patch service's prebuilt artifact is
downloaded again, with a local build as the fallback (and the only
source under `--offline` / `--vendor-source build`). The result is still
verified against the ledger fingerprint before it counts as `rebuilt`.
Failure details are now `vendor`'s own (for example "no installed
package found on disk"), and a drifted installed copy of a gem or pypi
release variant is no longer force-overwritten by repair — it fails the
same installed-variant check `vendor` applies. Internally, `vendor`, `scan`/`get --mode vendored`, `vendor --revert`,
`rollback`'s vendored leg, `remove` and `repair` now share one
`VendoredBackend { apply, revert, repair }`.
- **Vendored runs refuse lock-text failures before downloading them.**
`scan --mode vendored` and `get --mode vendored` evaluate the vendor
backends' pure lock-text gates — pnpm, yarn classic and yarn berry
Expand Down
12 changes: 8 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -476,7 +476,7 @@ need the network and refuse to run with `--offline`.
| [`remove`](#remove) | The single-patch form of `rollback`: restore, unwind, drop the record and GC for one PURL/UUID (a hosted patch is restored to upstream) |
| [`vendor --revert`](#vendor) | **Un-vendors wholesale**: restores the recorded original lockfile fragments byte-for-byte and removes the `.socket/vendor/` artifacts (a package vendored over a hosted pin returns to upstream, not to hosted) |
| [`scan --prune`](#scan) | Agent mode: **reconciles, doesn't reverse** — drops manifest entries for packages that have left the project and garbage-collects orphan blob/diff/archive files |
| [`repair`](#repair) (alias `gc`) | **Restores health, not originals**: re-downloads missing blobs, rebuilds missing/corrupt vendored artifacts, and cleans up unused ones |
| [`repair`](#repair) (alias `gc`) | **Restores health, not originals**: re-downloads missing blobs, re-vendors missing/corrupt vendored artifacts, and cleans up unused ones |

And `setup --remove` reverts the install hooks that `setup` added.

Expand All @@ -497,7 +497,7 @@ And `setup --remove` reverts the install hooks that `setup` added.
| [`setup`](#setup) | Wire install hooks (npm, Python, Bundler, Composer) that re-apply patches after install |
| [`rollback`](#rollback) | Undo patches in every mode: restore original files, unwind vendored lockfile wiring, and restore hosted lockfile entries to upstream |
| [`remove`](#remove) | Remove one patch by PURL or UUID (rolls back first) |
| [`repair`](#repair) | Download missing patch artifacts, rebuild vendored artifacts, clean up unused ones (alias: `gc`) |
| [`repair`](#repair) | Download missing patch artifacts, re-vendor broken vendored artifacts, clean up unused ones (alias: `gc`) |

`socket-patch --update` updates the CLI itself (see [Updating](#updating)).

Expand Down Expand Up @@ -1215,14 +1215,18 @@ socket-patch remove "pkg:npm/[email protected]" --json

### `repair`

Download missing blobs, rebuild missing or corrupt vendored artifacts, and clean up unused
Download missing blobs, re-vendor missing or corrupt vendored artifacts, and clean up unused
blobs.

Alias: `gc`

`repair` cleans up the `.socket/` directory without running a scan — useful when you've
manually adjusted the manifest, recovered from a partial-failure state, or just want to
free space. It also rebuilds missing or corrupt vendored artifacts. For the combined
free space. It also re-vendors missing or corrupt vendored artifacts the same way `vendor`
does (the patch service's prebuilt artifact first, a local build as the fallback), checked
against `.socket/vendor/state.json`. `repair` does not recreate a lost `state.json`: if a
lockfile points into `.socket/vendor/` and the ledger has no entry for it, `repair` fails with
`vendor_ledger_missing` — restore `state.json` from version control. For the combined
agent-mode workflow (discover + apply + GC in one pass), use `scan --sync` instead.

Like every other mutating command, `repair` takes the `.socket/apply.lock` advisory lock
Expand Down
Loading
Loading