Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion crates/socket-patch-cli/CLI_CONTRACT.md

Large diffs are not rendered by default.

11 changes: 11 additions & 0 deletions crates/socket-patch-cli/src/commands/scan/hosted.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1280,6 +1280,17 @@ pub(crate) async fn run_redirect_selected(
// v5 keeps no hosted ledger: this run's fetched records are the
// hosted record source of the in-run attestation.
params.hosted_records = records.clone();
// The gem intake gate withholds every gem file. VEX independently
// rediscovers older pins too, so a candidate-only set would miss some
// refused hosted gems. Keep their actual installed-byte verification,
// but do not infer applied status from the intercepted source.
params.hosted_gem_mirror_refused = rewrite
.warnings
.iter()
.any(|warning| warning.code == "redirect_gem_mirror_overrides_source");
Comment thread
cursor[bot] marked this conversation as resolved.
// The warning above exists only when this run had gem candidates;
// also check every hosted gem pin the VEX plan rediscovers.
params.hosted_gem_mirror_check = true;
// Stale-flagged purls are EXCLUDED from assume_applied: the same-run
// envelope carries a redirect_gem_stale_install warning proving the
// installed materialization unpatched, so attesting that purl from
Expand Down
32 changes: 24 additions & 8 deletions crates/socket-patch-cli/src/commands/scan/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -352,6 +352,7 @@ async fn embed_vex_into_json(
manifest_path: &Path,
base_code: i32,
result: &mut serde_json::Value,
hosted: bool,
) -> i32 {
if vex_args.vex.is_none() || base_code != 0 {
return base_code;
Expand All @@ -365,7 +366,10 @@ async fn embed_vex_into_json(
result["vex"] = serde_json::json!({ "skipped": true, "reason": "dry_run" });
return base_code;
}
let params = vex_args.to_build_params();
let mut params = vex_args.to_build_params();
// A hosted scan that redirected nothing (empty catalog / no grants)
// still attests older hosted gem pins: check them against the mirror.
params.hosted_gem_mirror_check = hosted;
match generate_vex_from_manifest_path(common, &params, manifest_path).await {
Ok(summary) => {
result["vex"] = serde_json::json!({
Expand Down Expand Up @@ -424,6 +428,7 @@ async fn embed_vex_human(
vex_args: &VexEmbedArgs,
manifest_path: &Path,
base_code: i32,
hosted: bool,
) -> i32 {
if vex_args.vex.is_none() || base_code != 0 {
return base_code;
Expand All @@ -438,7 +443,10 @@ async fn embed_vex_human(
}
return base_code;
}
let params = vex_args.to_build_params();
let mut params = vex_args.to_build_params();
// A hosted scan that redirected nothing (empty catalog / no grants)
// still attests older hosted gem pins: check them against the mirror.
params.hosted_gem_mirror_check = hosted;
match generate_vex_from_manifest_path(common, &params, manifest_path).await {
Ok(summary) => {
if !common.silent {
Expand Down Expand Up @@ -1878,8 +1886,15 @@ async fn run_scan(
result["redirectState"] = state;
}
}
let code =
embed_vex_into_json(&args.common, &args.vex, &manifest_path, 0, &mut result).await;
let code = embed_vex_into_json(
&args.common,
&args.vex,
&manifest_path,
0,
&mut result,
hosted,
)
.await;
print_json(&result);
return code;
} else if !args.common.silent {
Expand All @@ -1896,7 +1911,7 @@ async fn run_scan(
}
policy.print_human(args.common.silent, args.common.verbose);
}
return embed_vex_human(&args.common, &args.vex, &manifest_path, 0).await;
return embed_vex_human(&args.common, &args.vex, &manifest_path, 0, hosted).await;
}

// Build ecosystem summary
Expand Down Expand Up @@ -2429,6 +2444,7 @@ async fn run_scan(
&manifest_path,
apply_code,
&mut result,
hosted,
)
.await;
print_json(&result);
Expand Down Expand Up @@ -2460,7 +2476,7 @@ async fn run_scan(
)
.await;
}
embed_vex_human(&args_ref.common, &args_ref.vex, manifest_ref, code).await
embed_vex_human(&args_ref.common, &args_ref.vex, manifest_ref, code, hosted).await
};

// Every mode stops on an empty discovery, vendored included (restoring
Expand Down Expand Up @@ -2877,7 +2893,7 @@ async fn run_scan(
)
.await;
}
return embed_vex_human(&args.common, &args.vex, &manifest_path, 0).await;
return embed_vex_human(&args.common, &args.vex, &manifest_path, 0, hosted).await;
}

// Vendor mode: pre-verify baselines so a content mismatch is reported
Expand Down Expand Up @@ -2980,7 +2996,7 @@ async fn run_scan(
.await;
}

embed_vex_human(&args.common, &args.vex, &manifest_path, code).await
embed_vex_human(&args.common, &args.vex, &manifest_path, code, hosted).await
}

#[cfg(test)]
Expand Down
11 changes: 9 additions & 2 deletions crates/socket-patch-cli/src/commands/scan/vendor_flow.rs
Original file line number Diff line number Diff line change
Expand Up @@ -643,8 +643,15 @@ async fn run_vendor_json_path(
.await;
}

let final_code =
embed_vex_into_json(&args.common, &args.vex, manifest_path, vendor_code, result).await;
let final_code = embed_vex_into_json(
&args.common,
&args.vex,
manifest_path,
vendor_code,
result,
false,
)
.await;
print_json(result);
final_code
}
Expand Down
Loading
Loading