aboutsummaryrefslogtreecommitdiffhomepage
path: root/crates/shirabe/src/factory.rs
diff options
context:
space:
mode:
authornsfisis <nsfisis@gmail.com>2026-08-02 20:11:51 +0900
committernsfisis <nsfisis@gmail.com>2026-08-02 20:11:51 +0900
commitc2a2bd3a2573f585c902c39bd28b8c3cad10c317 (patch)
treeaa8138a0570966f26e3708b500041258074dcd24 /crates/shirabe/src/factory.rs
parent7db937af313d857d0f66bebaf8ac72d518559bac (diff)
downloadphp-shirabe-c2a2bd3a2573f585c902c39bd28b8c3cad10c317.tar.gz
php-shirabe-c2a2bd3a2573f585c902c39bd28b8c3cad10c317.tar.zst
php-shirabe-c2a2bd3a2573f585c902c39bd28b8c3cad10c317.zip
fix(repository): resolve remaining late-binding hazards from the audit
Three fixes for the ComposerRepository/FilesystemRepository/PlatformRepository hazards where inner-composition delegation skipped PHP's late-bound virtual dispatch: - ComposerRepository::has_package now builds its packageMap through the late-bound getPackages() equivalent, so lazy-providers repos surface the LogicException and available-packages repos load their package list, as in PHP, instead of silently answering false from the raw array. - RepositoryInterface::get_repo_name returns anyhow::Result<String>: PHP's getRepoName() counts through the late-bound initialize(), which is fallible in file-reading subclasses. FilesystemRepository and PackageRepository now run that initialization instead of freezing the inner array repository to an empty state (which also made a later write() truncate installed.json). Supporting changes keep the initialization chain callable from &self: JsonFile::read takes &self (indent moved into a RefCell), FilesystemRepository dev_mode became a Cell, and WritableArrayRepository dev_package_names a RefCell. - PlatformRepository::new routes constructor packages through its own add_package so the override handling and full platform initialization run as they do via PHP's parent constructor; the inner find_package/add_package delegations inside add_package (and ComposerRepository::add_package) gained the same is_initialized guard, since the constructor path would otherwise freeze the repository. Same defect class as 7db937af, 97b5211a and 3e367f78. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Diffstat (limited to 'crates/shirabe/src/factory.rs')
-rw-r--r--crates/shirabe/src/factory.rs8
1 files changed, 4 insertions, 4 deletions
diff --git a/crates/shirabe/src/factory.rs b/crates/shirabe/src/factory.rs
index b5f96cc3..29dc3e05 100644
--- a/crates/shirabe/src/factory.rs
+++ b/crates/shirabe/src/factory.rs
@@ -261,7 +261,7 @@ impl Factory {
// load global config
let global_config_path = format!("{}/config.json", config.get_str("home")?);
- let mut file = JsonFile::new(global_config_path, None, io.clone())?;
+ let file = JsonFile::new(global_config_path, None, io.clone())?;
if file.exists() {
if let Some(io_ref) = &io {
io_ref.write_error3(
@@ -316,7 +316,7 @@ impl Factory {
// load global auth file
let auth_file_path = format!("{}/auth.json", config.get_str("home")?);
- let mut auth_file = JsonFile::new(auth_file_path, None, io.clone())?;
+ let auth_file = JsonFile::new(auth_file_path, None, io.clone())?;
if auth_file.exists() {
if let Some(io_ref) = &io {
io_ref.write_error3(
@@ -460,7 +460,7 @@ impl Factory {
if let Some(LocalConfigInput::Path(path)) = &local_config {
composer_file = Some(path.clone());
- let mut file = JsonFile::new(path.clone(), None, Some(io.clone()))?;
+ let file = JsonFile::new(path.clone(), None, Some(io.clone()))?;
if !file.exists() {
let message = if path == "./composer.json" || path == "composer.json" {
@@ -535,7 +535,7 @@ impl Factory {
false,
)));
- let mut local_auth_file = JsonFile::new(
+ let local_auth_file = JsonFile::new(
format!(
"{}/auth.json",
dirname(&realpath(composer_file_path).unwrap_or_default())