aboutsummaryrefslogtreecommitdiffhomepage
path: root/crates/shirabe/src/command/diagnose_command.rs
diff options
context:
space:
mode:
authornsfisis <nsfisis@gmail.com>2026-08-15 08:45:08 +0900
committernsfisis <nsfisis@gmail.com>2026-08-15 08:45:08 +0900
commit2e40eaf6bf5c4bd8eedad597e4c3b19b5457421b (patch)
treef4a3843e0c903d4eaca3ac7882836c77a255c999 /crates/shirabe/src/command/diagnose_command.rs
parent55f385450407a3d8c6c7c90ec4dc8995f5277a94 (diff)
downloadphp-shirabe-2e40eaf6bf5c4bd8eedad597e4c3b19b5457421b.tar.gz
php-shirabe-2e40eaf6bf5c4bd8eedad597e4c3b19b5457421b.tar.zst
php-shirabe-2e40eaf6bf5c4bd8eedad597e4c3b19b5457421b.zip
feat(diagnose): audit the Composer runtime the executable carries
checkComposerAudit reported success instead of auditing anything, because the binary ships no vendor/composer/installed.json on disk. It reads the one in the embedded Composer PHP runtime now, and Composer's warning for a missing installed.json is back. Only that file leaves the bundle, into a temporary directory that goes away with the handle; the runtime is unpacked whole only for a worker that cannot read the bundle in place. Phar::extractTo's $files argument selects it, which the shim ignored so far. SHIRABE_COMPOSER_PHP_DIR moves into composer_runtime, so the worker and a reader on the Rust side resolve the runtime through the same branch. DiagnoseCommandTest::testCmdSuccess is ignored: packagist has advisories against composer/composer 2.9.7, the version Composer::VERSION reports, so diagnose exits 1 where the test expects 0. Upstream Composer 2.9.7 reports the same advisories. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Diffstat (limited to 'crates/shirabe/src/command/diagnose_command.rs')
-rw-r--r--crates/shirabe/src/command/diagnose_command.rs32
1 files changed, 17 insertions, 15 deletions
diff --git a/crates/shirabe/src/command/diagnose_command.rs b/crates/shirabe/src/command/diagnose_command.rs
index 6b339c69..da043a4f 100644
--- a/crates/shirabe/src/command/diagnose_command.rs
+++ b/crates/shirabe/src/command/diagnose_command.rs
@@ -37,9 +37,9 @@ use shirabe_pcre::{CaptureKey, Preg};
use shirabe_php_shim::Catch as _;
use shirabe_php_shim::{
AnyThrowable, CmpOp, InvalidArgumentException, PHP_EOL, PhpClass as _, PhpMixed,
- disk_free_space, file_exists, filter_var_boolean, hash, impl_php_class, implode, is_array,
- is_string, php_regex, rtrim, str_replace, strpos, strstr, strstr3, strtolower, trim,
- version_compare,
+ RuntimeException, disk_free_space, file_exists, filter_var_boolean, hash, impl_php_class,
+ implode, is_array, is_string, php_regex, rtrim, str_replace, strpos, strstr, strstr3,
+ strtolower, trim, version_compare,
};
use shirabe_symfony_console::command::Command;
use shirabe_symfony_console::input::InputInterface;
@@ -592,19 +592,21 @@ impl DiagnoseCommand {
IndexMap::new(),
IndexMap::new(),
);
- // PHP: __DIR__ . '/../../../vendor/composer/installed.json'
- let installed_json = JsonFile::new(
- "composer/src/Composer/Command/../../../vendor/composer/installed.json".to_string(),
- None,
- None,
- )?;
+ // PHP reads the installed.json of the Composer that runs; here that is the one in the
+ // Composer PHP runtime. The handle holds the file in place while the repository reads it.
+ let installed =
+ shirabe_php_rpc::composer_runtime::local_file("vendor/composer/installed.json")?;
+ // TODO(bytes): JsonFile holds its path as a string, since it takes http URLs too, so the
+ // path has to be representable as UTF-8.
+ let path = installed.path();
+ let path = path.to_str().ok_or_else(|| {
+ RuntimeException::new(format!("Path contains invalid UTF-8: {}", path.display()))
+ })?;
+ let installed_json = JsonFile::new(path.to_string(), None, None)?;
if !installed_json.exists() {
- // TODO(distribution): the native binary never ships vendor/composer/installed.json, so
- // Composer's "non-standard Composer installation" warning would fire on every run.
- // A Composer source snapshot is planned to be embedded together with the plugin API
- // implementation, which will make this self-audit functional; until then report
- // success instead of the warning.
- return Ok(PhpMixed::Bool(true));
+ return Ok(PhpMixed::String(
+ "<warning>Could not find Composer's installed.json, this must be a non-standard Composer installation.</>".to_string(),
+ ));
}
let local_repo = FilesystemRepository::new(installed_json, false, None, None)?;