diff options
| author | nsfisis <nsfisis@gmail.com> | 2026-08-02 20:11:51 +0900 |
|---|---|---|
| committer | nsfisis <nsfisis@gmail.com> | 2026-08-02 20:11:51 +0900 |
| commit | c2a2bd3a2573f585c902c39bd28b8c3cad10c317 (patch) | |
| tree | aa8138a0570966f26e3708b500041258074dcd24 /crates/shirabe/src/package | |
| parent | 7db937af313d857d0f66bebaf8ac72d518559bac (diff) | |
| download | php-shirabe-c2a2bd3a2573f585c902c39bd28b8c3cad10c317.tar.gz php-shirabe-c2a2bd3a2573f585c902c39bd28b8c3cad10c317.tar.zst php-shirabe-c2a2bd3a2573f585c902c39bd28b8c3cad10c317.zip | |
fix(repository): resolve remaining late-binding hazards from the audit
Three fixes for the ComposerRepository/FilesystemRepository/PlatformRepository
hazards where inner-composition delegation skipped PHP's late-bound virtual
dispatch:
- ComposerRepository::has_package now builds its packageMap through the
late-bound getPackages() equivalent, so lazy-providers repos surface the
LogicException and available-packages repos load their package list, as in
PHP, instead of silently answering false from the raw array.
- RepositoryInterface::get_repo_name returns anyhow::Result<String>: PHP's
getRepoName() counts through the late-bound initialize(), which is fallible
in file-reading subclasses. FilesystemRepository and PackageRepository now
run that initialization instead of freezing the inner array repository to an
empty state (which also made a later write() truncate installed.json).
Supporting changes keep the initialization chain callable from &self:
JsonFile::read takes &self (indent moved into a RefCell), FilesystemRepository
dev_mode became a Cell, and WritableArrayRepository dev_package_names a
RefCell.
- PlatformRepository::new routes constructor packages through its own
add_package so the override handling and full platform initialization run
as they do via PHP's parent constructor; the inner find_package/add_package
delegations inside add_package (and ComposerRepository::add_package) gained
the same is_initialized guard, since the constructor path would otherwise
freeze the repository.
Same defect class as 7db937af, 97b5211a and 3e367f78.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Diffstat (limited to 'crates/shirabe/src/package')
| -rw-r--r-- | crates/shirabe/src/package/archiver/archive_manager.rs | 2 | ||||
| -rw-r--r-- | crates/shirabe/src/package/loader/json_loader.rs | 2 |
2 files changed, 2 insertions, 2 deletions
diff --git a/crates/shirabe/src/package/archiver/archive_manager.rs b/crates/shirabe/src/package/archiver/archive_manager.rs index 92fe9d6c..afc89f32 100644 --- a/crates/shirabe/src/package/archiver/archive_manager.rs +++ b/crates/shirabe/src/package/archiver/archive_manager.rs @@ -182,7 +182,7 @@ impl ArchiveManager { let composer_json_path = format!("{}/composer.json", source_path); if file_exists(&composer_json_path) { - let mut json_file = JsonFile::new(composer_json_path, None, None)?; + let json_file = JsonFile::new(composer_json_path, None, None)?; let json_data = json_file.read()?; if let Some(archive) = json_data.get("archive") { if let Some(name) = archive.get("name").and_then(|v| v.as_string()) diff --git a/crates/shirabe/src/package/loader/json_loader.rs b/crates/shirabe/src/package/loader/json_loader.rs index 205028f7..c30fbe07 100644 --- a/crates/shirabe/src/package/loader/json_loader.rs +++ b/crates/shirabe/src/package/loader/json_loader.rs @@ -23,7 +23,7 @@ impl JsonLoader { pub fn load(&self, json: JsonLoaderInput) -> anyhow::Result<PackageInterfaceHandle> { let config = match json { - JsonLoaderInput::File(mut json_file) => json_file.read()?, + JsonLoaderInput::File(json_file) => json_file.read()?, JsonLoaderInput::String(ref s) if Path::new(s).exists() => { let contents = std::fs::read_to_string(s)?; JsonFile::parse_json(Some(&contents), Some(s))? |
