aboutsummaryrefslogtreecommitdiffhomepage
AgeCommit message (Collapse)Author
2026-07-20fix(process-executor): un-ignore 11 tests by implementing execute_async mock ↵nsfisis
support ProcessExecutor::execute_async's mock branch was an unimplemented todo!(), blocking every test whose code path calls it (feature-branch git diffing, system-unzip/7z fallback extraction). Implement it by: - Adding Process::__mock (mirroring the existing ZipArchive::__mock pattern) so execute_async can resolve with a fabricated, already- terminated Process instead of spawning a real subprocess. - Extracting the sync mock's expectation-matching logic into a shared ProcessExecutor::mock_match, wrapping the mock state in a RefCell so it works from execute_async's &self/&mut self receivers. - Setting error_output/capture_output from the mock branch, matching PHP's ProcessExecutorMock::executeAsync sharing doExecute with the sync path; execute_async now takes &mut self for this (safe, since the borrow only needs to live through the synchronous setup, not across the .await). - Turning a strict-mode expectation mismatch from a panic!() into a shirabe_php_shim::RuntimeException Err, mirroring PHPUnit's AssertionFailedError extending \RuntimeException: PHP call sites that catch (\RuntimeException $e) around a mocked git/hg/svn call (e.g. Git::get_mirror_default_branch, GitDriver::supports) treat a mismatch as an ordinary recoverable failure, and now so does the port. The RefMut is dropped before firing an expectation's optional callback so a re-entrant callback doesn't panic on double-borrow. Also fixes two real bugs found while porting test_private_repository_ no_interaction: GitHub::authorize_oauth and GitLab::authorize_oauth checked their domains config via PhpMixed::as_array(), which only matches the Array (map) variant, but github-domains/gitlab-domains default to PhpMixed::List, so the check always returned false and OAuth token lookup was silently skipped. Use the in_array shim instead, matching PHP's in_array() semantics. Also fix Git::run_command's "capture credentials from git remote -v" call, which used the panic- swallowing execute_args wrapper instead of a fallible execute(), so a mock mismatch there couldn't reach get_mirror_default_branch's catch. Un-ignores: - zip_downloader_test::test_system_unzip_only_{good,failed} - zip_downloader_test::test_non_windows_fallback_{good,failed} - event_dispatcher_test::test_dispatcher_outputs_error_on_failed_command - root_package_loader_test::test_feature_branch_pretty_version - version_guesser_test::test_guess_version_reads_and_respects_non_feature_branches_configuration_for_arbitrary_naming{,_regex} - version_guesser_test::test_remote_branches_are_selected - github_driver_test::test_private_repository_no_interaction (also adds the missing #[serial], since it seeds the shared Git::VERSION static that vcs_repository_test::test_load_versions depends on for real) - init_command_test::test_get_git_config, made deterministic by pointing HOME at a throwaway dir with its own .gitconfig instead of depending on the host's global git config Deduplicates the GitVersionGuard/RestoreEnv test-drop-guard idioms into tests/common/test_case.rs instead of reimplementing them per file. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-19fix(root-package-loader): un-ignore 4 tests by fixing stability-flag isset() ↵nsfisis
port extract_stability_flags ported PHP's `isset($stabilityFlags[$name]) && $stabilityFlags[$name] > $stability` as `unwrap_or(i64::MAX) > stability`, so the check always short-circuited to "already more unstable" and no flag (e.g. from an explicit `*@dev` requirement) was ever recorded. Fixed using Option::is_some_and, a direct translation of PHP's isset() && ... check. Also fixes tests/common/test_case.rs's shared installation_manager() helper, which built a real InstallationManager::new instead of the __new_mock constructor (mirroring PHP's FactoryMock::createInstallationManager()), so it always had zero installers registered and wrote install-path: null into fixture installed.json files. Un-ignores test_reinstall_command, test_locally_modified_packages_from_source/ _from_dist, and test_package_still_present_error_when_no_install_flag_used — the first three were already passing (their #[ignore] reasons were stale), the last is fixed by the test_case.rs change above. Updates the #[ignore] reasons on installer_test.rs's three fixture-driven integration tests to reflect their current state: the install pipeline now runs end-to-end, but the ~189-fixture installer/ set still hits several independent, unrelated bugs/gaps that need case-by-case triage rather than a single fix. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-19fix(show-command): un-ignore 10 tests by fixing show-warnings typing and ↵nsfisis
repo bugs Replace the PhpMixed-based `$showWarnings` hack in VersionSelector:: findBestCandidate with a typed ShowWarnings enum (Always / Predicate), letting ShowCommand::findLatestPackage pass its real closure instead of hardcoding `true`. Fix the --no-dev branch in ShowCommand::execute, which built `repos` from an empty package list instead of sharing the same InstalledRepository as `installed_repo`. Pass repository handles instead of pre-borrowed `&dyn RepositoryInterface` refs into get_package/ generate_package_tree/add_tree to stop a RefCell double-borrow panic on --all/--locked. Add the missing CompletePackage/RootPackage set_release_date setter so the outdated sorting-by-age test can set fixture dates. Resolve OutputFormatterStyleStack::pop's empty-style todo!() via clone_box(), and fix FileDownloader's cache-GC log call to pass the VERY_VERBOSE verbosity PHP uses. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-19fix(search-command): un-ignore test_search by fixing JSON output and ↵nsfisis
abandoned propagation The json format branch ignored search results entirely and always wrote null. Encode results into the same name/description/abandoned/url shape Composer's array-backed repositories produce. Also fix ComposerRepository's RepositoryInterface::search adapter, which dropped the abandoned field from raw API results even when present.
2026-07-19fix(alias-package): stop delegating own-state accessors to aliasOfnsfisis
AliasPackage wrongly delegated several methods (id, names, unique name, pretty string, full pretty version, repository, __toString) to aliasOf, but PHP's AliasPackage inherits these from BasePackage unmodified, so they must use the alias's own state instead. This collapsed alias and aliasOf into the same SAT literal id, breaking the solver's alias-resolution rules; un-ignore the two solver tests that exposed it.
2026-07-19test(gitlab-driver): un-ignore test_get_paginated_refsnsfisis
The Preg delimiter bug the ignore reason described was already fixed.
2026-07-19feat(spdx-licenses): implement is_valid_license_string SPDX expression parsernsfisis
PHP matches the SPDX license-expression grammar with a single recursive PCRE pattern ((?(DEFINE) subpatterns plus (?&name) recursion), which the regex crate cannot express, so port it as a hand-written recursive-descent parser instead. licenseid/licenseexceptionid dictionary lookups use longest-match-first, guarded against accepting a short entry that is only a coincidental prefix of a longer identifier run (e.g. "DOC" prefixing "DocumentRef-..."), which a length-sorted greedy match alone would misparse. Un-ignores the two validating_array_loader tests that were blocked on this todo!().
2026-07-19fix(update-command): un-ignore test_update by fixing 3 real bugsnsfisis
test_update was skipped for a stale reason; running it uncovered three distinct bugs it was actually catching: - ApplicationTester::run never restored SHELL_VERBOSITY after Application::configureIO mutates it, so one dataset's -vv verbosity leaked into later runs sharing the process (Symfony's tester restores it in a finally block; the port dropped that). - Installer::do_install built its RepositorySet with a hardcoded empty temporary_constraints map instead of self.temporary_constraints, so --with never actually constrained the resolver. - BumpCommand was missing a <warning> tag pair around one of its output lines.
2026-07-19fix(test-harness): set COMPOSER_TESTS_ARE_RUNNING so interactive tests ↵nsfisis
actually run Without this, Application::do_run force-disabled interactivity whenever stdin wasn't a tty (as under cargo test), so ApplicationTester runs with set_inputs silently produced non-interactive default output instead of consuming the answers, masking real behavior as several stale #[ignore]s blaming already-implemented ProcessExecutor/Process todo!()s. Port composer/tests/bootstrap.php's env setup into a bootstrap() helper called from get_application_tester(), un-ignore the now-passing init/update command tests, and update init_command_test's expected schema-validation wording to match the jsonschema crate (already the accepted wording per 541a8b4f, not an unported gap).
2026-07-19fix(check-platform-reqs): restore raw Link column in text tablensfisis
PHP's printTable builds a 5-column row for text output, with the raw Link object (cast via __toString) as its own column separate from the formatted description string. The port had collapsed both into one column, dropping an empty column for successful checks and throwing off the rendered column widths/spacing versus real Composer output.
2026-07-18chore: rustfmtnsfisis
2026-07-18perf(installation-manager): run executeBatch operation chains concurrentlynsfisis
executeBatch now builds one future per operation — the PHP promise chain prepare -> install/update/uninstall -> cleanup -> repo->write, including the '<Op> of <pkg> failed' rejection handler covering the chain up to cleanup — and drives the whole batch through waitOnPromises()/Loop::wait, so archive extraction (the unzip subprocesses gated by ProcessExecutor's semaphore) finally overlaps across packages. Alias operations stay synchronous in the collection loop like PHP. The shared repository is threaded through the chains as RefCell<&mut dyn InstalledRepositoryInterface>: execute() wraps the incoming &mut once, and InstallerInterface::install/update/uninstall take the cell so implementations borrow it only in their synchronous head/tail, never across an await. InstallationManager's own install/update/uninstall/download/get_installer/get_install_path/ mark_for_notification move to &self (cache and notifiable_packages behind RefCell) so every chain can capture &self. WritableRepositoryInterface::write and the InstallationManagerInterface get_install_path it relies on lose their &mut manager requirement — the per-op repo->write inside the chains only reads install paths. Warm-cache create-project laravel/laravel: the package-operations phase (109 installs) drops from ~3.0-3.8s serial to ~1.9s, on par with real Composer (~2.1s) measured back-to-back; the resulting vendor tree, installed.json included, stays byte-identical to Composer's (diff -rq clean). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18perf(installation-manager): fan out package downloads via Loop::waitnsfisis
InstallationManager::downloadAndExecuteBatch now matches PHP: every update/install operation's installer->download() promise is collected and driven concurrently through waitOnPromises()/Loop::wait instead of being awaited one package at a time. Concurrency caps stay where PHP puts them (HttpDownloader 12, ProcessExecutor 10 via their semaphores). Error semantics follow PHP too: all downloads settle before the first rejection is rethrown, rather than aborting on the first failure. To let the collected futures and the cleanup closures own their installer beyond the loop iteration that created them, the installer registry becomes Vec<Rc<dyn InstallerInterface>> and get_installer hands out clones (PHP closures capture $installer the same way), with InstallerInterface methods taking &self across the six implementors — the only genuinely mutable state was LibraryInstaller.vendor_dir (canonicalized in place), now behind a RefCell. as_plugin_installer_mut/as_binary_presence_interface lose their &mut. The cleanup_promises entries are now the real thing: the PHP closure including the getInstallationSource() guard and the installer->cleanup($opType, $package, $initialPackage) call, replacing the no-op futures (drops one TODO(phase-b) and two TODO(phase-c)). Verified against the real network: create-project laravel/laravel produces a vendor tree byte-identical to real Composer's (diff -rq clean across all 109 packages including vendor/composer). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18refactor(downloader): take &self across the downloader hierarchynsfisis
Concurrent package operations call into the same downloader instances through Rc<RefCell<dyn DownloaderInterface>>; with &mut self methods every call holds a RefMut across its awaits, which panics with 'already mutably borrowed' the moment two operations overlap. This is groundwork for fanning out InstallationManager's download/install loops (same rework HttpDownloader/CurlDownloader already got). - DownloaderInterface/ChangeReportInterface/ArchiveDownloader/ VcsDownloader methods now take &self; as_change_report_interface returns &dyn instead of &mut dyn. - Implementors move their genuinely mutable state behind cells: FileDownloader.additional_cleanup_paths, the archive downloaders' cleanup_executed, ZipDownloader.zip_archive_object, VcsDownloaderBase.has_cleaned_changes, GitDownloader's stash/discard/ cache maps and GitUtil, SvnDownloader.cache_credentials, PerforceDownloader.perforce. FileDownloader.io gains a RefCell layer so get_local_changes can keep PHP's NullIO swap under &self. - ProcessExecutor::execute_async now returns a future that captures everything up front instead of borrowing the executor, and call sites build the future before awaiting, so no borrow on the shared executor is held while a subprocess runs. - Filesystem::remove_directory_async becomes remove_directory_async_via taking the Rc handle: the Filesystem is only borrowed for the sync head/tail, never across the rm subprocess await (sync borrow_mut users like rename/ensure_directory_exists would otherwise collide). - DownloadManager async call sites hold shared borrows only. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18perf(process-executor): make execute_async genuinely concurrentnsfisis
execute_async was a serial pump: it queued a job, then drove it to completion itself via wait_id()'s blocking usleep loop before returning, so concurrent callers never overlapped even when polled together through FuturesUnordered. Rewrite it as a single &self async fn mirroring the CurlDownloader/ HttpDownloader rework: a tokio Semaphore sized by max_jobs (COMPOSER_MAX_PARALLEL_PROCESSES, PHP parity) gates admission, the child is started non-blocking, and an async 1ms sleep loop pumps is_running()/check_timeout() while yielding to the reactor so sibling jobs genuinely run in parallel. The Job table, STATUS_* lifecycle, start_job/mark_job_done/count_active_jobs/wait/wait_id all had no remaining callers and are removed. &self also lets callers hold only a shared borrow across their awaits (zip_downloader, version_guesser, filesystem via the new get_process_handle), which would otherwise panic with 'already mutably borrowed' once two async jobs overlap on the same Rc<RefCell<ProcessExecutor>>. The async mock branch no longer consumes the expectation before hitting its todo!(): the panic made that bookkeeping unobservable. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18chore(bench): pass --no-audit to create-project benchmarknsfisis
The earlier measurements documented in the perf notes were taken with --no-audit to keep the security-advisories request out of the timings, but the flag never landed in the committed script. Add it so future runs are comparable. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18perf(regex): eliminate per-call clone overhead in preg_* dispatchnsfisis
regex::Regex::clone() does not share the underlying meta engine's search-cache pool, so every fresh clone pays a ~10us warmup cost on its first use. Two changes together eliminate this across nearly all preg_* call sites: - A php_regex! macro resolves PHP-style patterns to a per-call-site &'static regex::Regex (via regex-macro's LazyLock), applied at the majority of call sites throughout the codebase. - Call sites still passing dynamic pattern strings go through PATTERN_CACHE, which now stores Arc<(Regex, bool)> and hands out Arc::clone()s instead of cloning the Regex itself. PregPattern::resolve() returns a ResolvedPattern enum (Arc or 'static reference) rather than an owned Regex, so neither path ever clones the Regex proper. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-18perf(json-file): buffer schema file reads in FileRetrievernsfisis
serde_json::from_reader issues one read() syscall per byte against an unbuffered Reader. FileRetriever passed a raw File straight through, so resolving the composer-schema.json $ref read its ~71KB contents one byte at a time (twice per require, since schema validation runs both before and during the update). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-18fix(composer-repository): match List for security-advisories fieldnsfisis
security-advisories in a p2 provider response is a JSON array, which decodes to PhpMixed::List rather than PhpMixed::Array. The check only matched Array, so it always missed and silently fell through to the api-url fallback instead of using the already-cached provider data. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-18perf: add require --no-install benchmark scriptnsfisis
Lighter-weight companion to scripts/bench/create-project.sh: compares shirabe vs composer on dependency resolution alone (require --no-install --no-audit), skipping the download/install step that dominates create-project's runtime.
2026-07-18fix(require-command): avoid unsupported regex lookahead in dev-branch checknsfisis
The `regex` crate does not support negative lookahead, so the ported `^dev-(?!main$|master$|trunk$|latest$)` pattern panicked at runtime on any `require` invocation that reached version-selection. Replace it with equivalent hand-written string logic per docs/dev/regex-porting.md.
2026-07-18refactor(curl-downloader): drop unnecessary Rc wrapping around handlesnsfisis
CurlDownloader::auth_helper was never cloned out to another owner, so Rc<RefCell<AuthHelper>> only needed the RefCell for interior mutability (all methods take &self). Likewise HttpDownloader::dispatch cloned self.rfs into a local binding it only ever used synchronously (copy/get_contents don't await), so the clone bought nothing. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-18fix(curl-downloader): unlink partial file on redirect-without-location failurensfisis
PHP's handleRedirect() throws a bare TransportException when the Location header is missing, and the caller's single catch block always unlinks the `~` partial file via rejectJob(). The Rust decide() loop splits each failure path into its own branch and had unlinked on every other one, but missed this branch, leaking the partial file. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-17perf(sync-executor): drive HTTP fetches through one real top-level runtimensfisis
Replace sync_executor::block_on's reactor-less busy-spin poller with tokio::task::block_in_place + Handle::current().block_on(), riding a single tokio Runtime entered once in main.rs (falling back to a disposable one when no ambient runtime exists, e.g. in tests). This lets HttpDownloader::dispatch await CurlDownloader::download directly instead of bouncing through the separate curl_runtime() bridge, which is now deleted. Manual create-project verification against the real network caught a concurrency bug this exposed: async_fetch_file held http_downloader's RefMut across the await on add(), which only panics once downloads genuinely overlap. add() only needs &self, so borrow() fixes it. With everything now sharing one real reactor, the FuturesOrdered fan-out added for ComposerRepository::get_security_advisories/ load_async_packages finally overlaps for real: fetching 8 packages' metadata dropped from ~7-40s to a consistent ~3-4s in a before/after comparison, with identical resulting lock files. sync_executor::block_on's call sites are still synchronous rather than async fn propagated up to Command::execute, which remains the end goal (see the TODO(phase-e) in sync_executor.rs) - nested block_on calls elsewhere don't get this same overlap, only prevented panics.
2026-07-17perf: add benchmark scriptnsfisis
2026-07-17refactor(composer-repository): fan out async metadata downloads concurrentlynsfisis
get_security_advisories/load_async_packages serialized every start_cached_async_download call through sync_executor::block_on per name, matching PHP's structure but not its promise-based concurrency. Wrap the mutable state those downloads touch (cache, fresh_metadata_urls, packages_not_found_cache, degraded_mode) in RefCell/Cell so start_cached_async_download and its async_fetch_file helpers can drop to &self, then fan out all downloads for a batch via FuturesOrdered before processing responses sequentially in original order, mirroring PHP's build-all-promises-then-wait shape. Real I/O overlap still awaits item 7 (HttpDownloader::add currently resolves through the curl_runtime()/sync_executor::block_on bridge either way), so this is architectural groundwork, not a perf win yet.
2026-07-17refactor(tests-async): unify duplicated tokio runtime bridgesnsfisis
11 downloader/installer integration-test files each redefined an identical current_thread `run()` helper to block on async code. Extract one shared multi_thread Runtime into tests/common/async_runtime.rs so concurrent #[test] threads can all block_on it, matching the direction item 7 (top-level Runtime) will take in production code.
2026-07-17refactor(loop): drive wait() promises concurrently via FuturesUnorderednsfisis
Loop::wait already had the target signature and a TODO(phase-c-promise) marker noting it drove promises serially; swap the for-loop for FuturesUnordered so all promises are polled together instead of one at a time, keeping the "remember only the first error" semantics. This adds the first real use of the futures dependency (already present in Cargo.toml/Cargo.lock from earlier prep work, now finally consumed), so those lockfile/manifest changes land in this commit. Real overlap still doesn't happen yet: each promise (HttpDownloader::add/ add_copy etc.) resolves through a blocking bridge (curl_runtime()/ sync_executor::block_on) that fully occupies the thread until it settles, so this is groundwork for once a single top-level Runtime replaces those bridges. Updated the TODO(phase-c-promise) comment to reflect that.
2026-07-17refactor(http-downloader): drop the job table for a &self Semaphore corensfisis
Replaces Job/Request/JobHandle/id_gen/running_jobs/max_jobs with a tokio::sync::Semaphore permit held for the duration of each request. get/add/copy/add_copy are now &self (add/add_copy are also genuinely async); a shared execute()/dispatch() core replaces add_job/run_rfs_job/start_job/settle_job, returning the Response directly instead of deferring to wait()/count_active_jobs()/ get_response() (all removed — confirmed zero callers, same for the now-unused STATUS_* constants). get()/copy() stay synchronous rather than becoming async wrappers around add()/add_copy(), bridging via the existing sync_executor instead of the curl_runtime() introduced for CurlDownloader: their callers (~35 files reaching HttpDownloader) are mostly plain sync fns with no async boundary anywhere in the call chain, and forcing that propagation now would pull forward the dedicated async-propagation task. curl-eligible requests still route through curl_runtime() inside dispatch(), same as before — nesting sync_executor::block_on (no real reactor) around curl_runtime().block_on() (a real, separate Runtime) is safe; it's only nesting curl_runtime() inside itself that would panic. CurlDownloader no longer needs Rc<RefCell<>> wrapping despite the original design sketch: since item 2 made all of its methods &self, a plain Option<CurlDownloader> field works fine under HttpDownloader's own &self methods. get/add/copy/add_copy becoming &self (rather than &mut self) requires no changes at any of their ~35 calling files: RefMut/Ref both deref to a type that can call &self methods just fine. Verified manually against real network I/O (sandbox disabled): `shirabe show -a` (get()'s sync_executor-bridged path) and `shirabe create-project` (add_copy()'s genuinely async path via file_downloader.rs) both complete correctly with no hang.
2026-07-17docs(curl-downloader): mark unported abortRequest note as TODO(phase-c)nsfisis
Freeform notes about intentionally-unported production behavior are easy to miss on a read-through and impossible to grep for later.
2026-07-17refactor(curl-downloader): rewrite as a single async fn, drop Job/ticknsfisis
Replaces the Job-table + tick()-driven polling loop with one async download() that sends, decides (retry/redirect/fail/succeed via a new decide() extracted from the former run_job), and loops until it resolves — no more resolve/reject callbacks. The client switches from reqwest::blocking::Client to the non-blocking reqwest::Client, with body streaming now via tokio::fs. Because real async I/O needs a live tokio reactor and none runs yet at the process level (sync_executor::block_on is a no-reactor busy-spin executor that only works when awaited futures resolve synchronously), HttpDownloader::start_job drives CurlDownloader::download() through a dedicated temporary current_thread Runtime (curl_runtime(), marked TODO(phase-e)) instead. This keeps concurrency characteristics unchanged for now — start_job still resolves one job at a time — real parallel I/O lands once HttpDownloader/Loop are rearchitected on top of FuturesUnordered. count_active_jobs' curl.tick() polling and the Job.settled/curl_id plumbing are removed as dead weight now that start_job settles curl jobs synchronously, same as the rfs path already did. abort_request is dropped: it had no caller (the PHP Promise-cancellation flow it backs was never ported), and the job table it operated on no longer exists. Verified manually against real network I/O (sandbox disabled): `shirabe show -a` (JSON metadata, in-memory body) and `shirabe create-project` (actual dist zip download + extraction) both complete correctly with no hang. Two unrelated pre-existing bugs surfaced during manual testing (an event-dispatcher subscriber wiring gap during `require`, and a RefCell reentrancy panic in `diagnose`) reproduce identically on the pre-change code and are out of scope here.
2026-07-16refactor(http-downloader): wrap HttpDownloaderMockState in Rc<RefCell<>>nsfisis
In prep for the upcoming &self conversion of add()/get()/copy(), the mock hook needs interior mutability too. The struct's Clone derive is dropped since nothing clones the whole state anymore, only the shared Rc handle.
2026-07-16refactor(remote-filesystem): return headers from copy/get_contentsnsfisis
Wrap RemoteFilesystem in Rc<RefCell<>> inside HttpDownloader, in prep for the upcoming &self conversion of add()/get(). copy()/get_contents() now bundle the response headers into their return value instead of requiring a follow-up get_last_headers() call, since two separate calls through a shared RefCell could otherwise race: nothing would guarantee the reader observes the headers from its own request rather than one clobbered by a concurrently borrowed call. get_last_headers() itself is left in place, mirroring RemoteFilesystem::getLastHeaders() in PHP.
2026-07-16refactor(curl-downloader): wrap AuthHelper in Rc<RefCell<>>nsfisis
CurlDownloader's download() is about to become an &self async method as part of the HttpDownloader async rearchitecture; its auth_helper field needs interior mutability ahead of that change. RemoteFilesystem keeps its own AuthHelper as a plain field since it stays &mut self.
2026-07-16fix(proxy-manager): correct singleton lifecycle and simplify to a plain Mutexnsfisis
reset() eagerly rebuilt the ProxyManager singleton immediately, capturing env vars before a caller could set them for the next request. PHP's reset() just nulls the static instance; getInstance() lazily constructs on next use. Match that so proxy env vars set after reset() are observed. get_instance() also ensured the singleton was constructed under its own lock, dropped that lock, and returned the bare Mutex; every caller then took a second, independent lock. A reset() landing in that gap would leave the caller observing None and panicking on .as_ref().unwrap(), a state the old eager-reconstructing reset() could not produce. Return the already-locked MutexGuard from get_instance() instead, so construction and use happen under one lock, and update all call sites accordingly. Holding that guard across a loop body then deadlocked in diagnose_command, since check_http_proxy transitively re-enters get_instance() via HttpDownloader -> CurlDownloader, and std::sync::Mutex is not reentrant. Re-acquire the lock fresh each iteration with a short-lived guard instead. Finally, Mutex::new is a const fn, so the OnceLock wrapper around it was unnecessary indirection; a bare static Mutex<Option<ProxyManager>> initializes to the same state without the get_or_init/get dance. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-16refactor(locker-test): reuse test_case's installation_manager helpernsfisis
locker_test.rs defined its own installation_manager, identical to test_case.rs's (both build a bare InstallationManager over a mock HttpDownloader). Expose the shared one via pub(crate) and drop the duplicate. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-16test(plugin): port capability-query tests, record remaining TODO(phase-d) ↵nsfisis
reasons Implement test_incapable_plugin_is_correctly_detected and test_querying_non_provided_capability_returns_null_safely against a real PluginManager, using hand-written PluginInterface/Capable stubs in place of PHPUnit's ad-hoc mocks. Wire the shared config_stub test helper into the plugin test binary, and derive Debug on the SetUp struct per this project's convention. The remaining plugin_installer_test.rs cases stay #[ignore]d: install/update/uninstall wiring in PluginInstaller and class instantiation in PluginManager::register_package are still TODO(plugin) stubs, so no plugin ever actually gets registered. Each now records its blocking TODO(plugin) site via // TODO(phase-d). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-16test: update TODO reason for unported test casesnsfisis
No test logic changes.
2026-07-16test(downloader): record TODO(phase-d) reasons and port two git-downloader testsnsfisis
zip/git/file downloader tests that were already #[ignore]d for a documented reason lacked the required in-body // TODO(phase-d) comment; record it for each. Two git_downloader_test.rs cases, test_download_uses_various_protocols_and_sets_push_url_for_github and test_update_doesnt_throws_runtime_exception_if_git_command_fails_at_first_but_is_able_to_recover, had been left as todo!() with a TODO(phase-d) claiming ComposerMirror::process_git_url's github regex lacks PCRE delimiters and panics. That regex already has delimiters and does not panic (verified directly), and other tests in this same file already use Package::set_source_mirrors to give a real package a mirror-prefixed getSourceUrls() list, so the stated blocker no longer applies. Port both tests using that existing technique instead of recording a TODO(phase-d) for them. No other test logic changes. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-16test(util): port remaining todo!() tests in util test suitensfisis
Implement previously-todo!() tests in auth_helper_test.rs, process_executor_test.rs, remote_filesystem_test.rs, and stream_context_factory_test.rs by porting the corresponding PHPUnit test methods. Extend IOStub with writeRaw/setAuthentication call tracking and askAndValidate/getAuthentication overrides to model the PHPUnit mocks these tests rely on, deduping the resulting call-recording fields into a small generic CallRecorder<T> helper instead of repeating the same RefCell<Vec<T>> push/borrow().clone() boilerplate five times. testStoreAuthWithPromptInvalidAnswer and testPromptAuthIfNeededMultipleBitbucketDownloads had initially lost the ported PHPUnit mock's argument/call-count assertions (askAndValidate's exact prompt string, and hasAuthentication/getAuthentication's exactly(2) call counts), silently narrowing what the tests verify; IOStub now records these calls and the tests assert on them, matching upstream. Tests left unportable (PHP set_error_handler machinery, closures in data providers, network/subclass-mock dependencies, etc.) keep #[ignore] with a single // TODO(phase-d) reason recorded in the function body. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-11fix(console-application): render exceptions to ConsoleOutput's error outputnsfisis
Resolve the base_run render_exception TODO by downcasting the OutputInterface handle to the concrete ConsoleOutput type, mirroring `$output instanceof ConsoleOutputInterface` from Symfony's Application::run.
2026-07-11chore: remove stale commentnsfisis
2026-07-11fix(command-loader): return Rc<RefCell<dyn Command>> from get()nsfisis
CommandLoaderInterface::get() returned Box<dyn Command>, which didn't match the Rc<RefCell<dyn SymfonyCommand>> Application::add() expects, leaving both call sites as todo!() panics.
2026-07-11chore: use fully-qualified name for Rc/RefCellnsfisis
2026-07-11feat(completion): thread Rc<InputOption> through suggest_optionsnsfisis
InputDefinition stores options as Rc<InputOption> for sharing, so CompletionSuggestions::suggest_option[s] now accepts Rc<InputOption> instead of owned values, resolving the ownership mismatch left as a todo!() in Application::complete and CompleteCommand.
2026-07-11refactor(application): inline plugin command warning writesnsfisis
Buffering warnings into a Vec was a stale Phase B workaround for a borrow conflict that no longer exists now that io is a separately cloned Rc<RefCell<dyn IOInterface>> handle; write them directly in the loop like the original PHP does.
2026-07-07chore: fix stale commentnsfisis
2026-07-06fix(base-config-command): run BaseCommand::initialize before config setupnsfisis
BaseConfigCommand::initialize skipped the parent BaseCommand::initialize chain (plugin enable/disable resolution, PRE_COMMAND_RUN event dispatch, COMPOSER_NO_* env option overrides), unlike PHP's parent::initialize() call. The trait-disambiguation blocker cited in the old TODO was already solved elsewhere via the base_command_initialize free function; wire it in here too so ConfigCommand and RepositoryCommand match PHP behavior. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-05feat(run-script-command): resolve script command descriptions via find()nsfisis
Application::find is now available, so getScripts can look up each script's associated command and read its description, ignoring CommandNotFoundException/NamespaceNotFoundException the same way the PHP code does for scripts with no associated command.
2026-07-05feat(exec-command): restore working directory via getInitialWorkingDirectorynsfisis
Downcasts the generic Application handle to the concrete shirabe Application to read getInitialWorkingDirectory(), so exec once again switches back to the directory it started in (e.g. after `composer global exec`), matching PHP's behavior.