aboutsummaryrefslogtreecommitdiffhomepage
AgeCommit message (Collapse)Author
2026-07-05fix(git-bitbucket-driver): match PHP exception/fallibility semantics for ↵nsfisis
fallback paths VcsDriverInterface::get_source/get_dist were made fallible in the Rust port even though PHP's are infallible, forcing GitBitbucketDriver's fallback delegation to silently swallow errors via unwrap_or_default()/ok().flatten(). Make the trait infallible to match PHP, updating the mechanical Ok(...) wrapping in all implementors. Also narrow attempt_clone_fallback's cleanup to only trigger on RuntimeException, mirroring PHP's catch (\RuntimeException $e), using the same downcast pattern already used by has_composer_file for TransportException.
2026-07-05fix(problem): port PHP reason-string formatting for alias/security-advisory ↵nsfisis
paths Both code paths were left as phase-c placeholders (debug-formatted reason_data, and a security-advisory fallback that ignored getMatchingSecurityAdvisories entirely). The blockers noted in those TODOs were already resolved elsewhere (RuleSetGenerator now wires reason_data for alias rules, and BasePackageHandle/PackageInterfaceHandle are the same type), so port the PHP logic faithfully.
2026-07-05feat(reinstall-command): wire InstallationManager::execute and ↵nsfisis
AutoloadGenerator::dump The two phase-c TODOs blocking these calls were already resolved elsewhere (RepositoryInterfaceHandle::as_installed_repository_interface_mut was added after this file was ported), so reinstall now actually performs the uninstall/install operations and regenerates the autoloader instead of no-oping. Mirrors the pattern already used in installer.rs and dump_autoload_command.rs.
2026-07-05feat(remote-filesystem): support file:// URLs in get_remote_contentsnsfisis
get_remote_contents was a full stub always returning None, so any file:// download raised a TransportException. Read local files directly for the file scheme, mirroring PHP's file_get_contents transparently handling the file:// stream wrapper. Also fixes file_get_contents5 to strip the file:// prefix like the 0-arg variant already did.
2026-07-05perf(pcre): cache compiled regex patterns across preg_* callsnsfisis
Composer's classmap generator re-issues the same PHP-derived pattern string for every scanned file (and every token within it), relying on PCRE's built-in compiled-pattern cache to make that free. shirabe had no equivalent, so every Preg::* call recompiled the pattern from scratch via regex::Regex::new(), making `composer create-project` autoload generation ~130x slower than Composer on a fresh laravel/laravel install (130s vs ~1s). Memoizing compiled patterns by their raw string in compile_php_pattern closes that gap. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-05fix(platform): match PHP truthy semantics for CI env checksnsfisis
Platform::get_env("CI").is_some()/is_none() only checked whether the variable was set, unlike PHP's (bool) Platform::getEnv('CI') which treats "" and "0" as falsy. CI="0" (used by some CI providers to explicitly disable CI mode) would previously flip behavior compared to Composer.
2026-07-05feat(installation-manager): render install/download progress barnsfisis
Real Composer shows a ProgressBar during InstallationManager's waitOnPromises (`Package operations: N installs` ... `0/109 [>---] 0%` ... `100%`), but this port never wired one up: output_progress was set by callers and never consulted. This adds the same gating PHP uses (output_progress, ConsoleIO, not CI, not debug, more than one operation) for both the download phase and the install/extract phase. The port runs downloads/installs serially rather than as concurrently polled promises (see the existing TODO(phase-c-promise) notes), so there is no active-job count to poll for intermediate snapshots. Stepping the bar per completed operation was tried first, but it interleaves with the "- Installing ..." lines mid-terminal-line since both share the same overwrite/newline state; rendering a single 0% -> 100% jump after each phase avoids that garbling at the cost of the timing-driven intermediate snapshots real Composer shows.
2026-07-05fix(autoload-generator): read exclude-from-classmap/classmap as PhpMixed::Arraynsfisis
parse_autoloads_type stores exclude-from-classmap and classmap as PhpMixed::Array (string-keyed), but dump()/create_loader() read them with as_list(), which only matches PhpMixed::List and thus always returned None. exclude-from-classmap patterns declared by vendor packages (e.g. symfony/service-contracts' /Test/) were consequently never excluded from the generated classmap. Switched both call sites to as_array()/.values(), matching the already-correct usage earlier in the same function.
2026-07-05fix(composer-repository): use create_packages for lazy metadata-url packagesnsfisis
load_async_packages (the v2 metadata-url/packagist protocol path) called a separate create_packages_static helper instead of the instance method create_packages. PHP has a single createPackages method used everywhere, so this duplicate silently skipped the notification-url injection (and dist-mirror/transport-options setup) that create_packages performs. Every package resolved via the lazy provider path ended up missing notification-url in composer.lock/installed.json. Removed the now-dead duplicate.
2026-07-04fix(cache): gate "reading/writing ... cache" messages behind debug verbositynsfisis
Cache::read/write/copy_to called write_error (always visible) instead of write_error3(.., IOInterface::DEBUG) like the PHP source, so these messages leaked into default-verbosity output instead of only showing under -vvv, producing extra lines not present in real Composer's output.
2026-07-04fix(class-map-generator): avoid unsupported regex backreference/lookahead in ↵nsfisis
heredoc detection PhpFileCleaner's heredoc-start pattern used a `\1` backreference to match the closing quote, and skip_heredoc's delimiter boundary check used a `(?!...)` negative lookahead. The `regex` crate supports neither, so it panicked with "invalid regex" whenever a scanned PHP file contained a heredoc/nowdoc (e.g. vendor code pulled in via `composer create-project`). The backreference is expanded into three quote-state alternatives, and the lookahead becomes a direct check of the next byte.
2026-07-04fix(console-application): implement --profile via IOInterface::enable_debuggingnsfisis
The --profile flag parsed the option but never actually enabled the timing/memory output, because ConsoleIO::enableDebugging existed only as an inherent method, unreachable through the `dyn IOInterface` handle held by Application. Promote enable_debugging to an IOInterface trait method (default panics, since only ConsoleIO/BufferIO ever legitimately receive this call) so do_run can invoke it directly without downcasting.
2026-07-04feat(php-shim): stub memory_get_usage/memory_get_peak_usage to return 0nsfisis
2026-07-04feat(plugin-installer): implement PluginInstaller::get_plugin_managernsfisis
Wires PartialComposer.as_full() to fetch the PluginManager, replacing the todo!() stub. Mirrors PHP's assertion that $this->composer must be a fully-loaded Composer instance.
2026-07-04fix(php-rpc): panic on RPC failure instead of silently swallowing itnsfisis
Worker spawn failure, socket I/O errors, and unparseable responses used to fall back to plausible-looking defaults (empty string, false, None), making real failures indistinguishable from legitimate PHP-side results. Panicking is not the final design, but replaces silent data corruption with a loud failure until proper error propagation is implemented.
2026-07-04fix(search-command): use as_list() to read variadic tokens argumentnsfisis
ArgvInput stores variadic arguments as PhpMixed::List, not PhpMixed::Array, so as_array() always returned None and the search query was silently empty, causing packagist to reject every request with a 400 Bad Request.
2026-07-04fix(platform-repository): avoid infinite recursion in addOverriddenPackagensfisis
PHP's addOverriddenPackage calls parent::addPackage() (a non-virtual call straight to ArrayRepository), but the port called self.add_package, re-entering PlatformRepository::add_package. Since the newly created override package's name also starts with "php-", this recursed forever and blew the stack.
2026-07-04feat(config): use shirabe-branded default home/cache/data dirsnsfisis
Avoid colliding with an existing Composer installation on the same machine by defaulting COMPOSER_HOME/CACHE_DIR/DATA_DIR paths to shirabe/Shirabe instead of composer/Composer, while keeping the env var names, composer.json/lock, and vendor/composer/ unchanged for ecosystem compatibility.
2026-07-04fix(package): reset repository/id on package clonensfisis
AnyPackage::dup() (PHP's `clone $package`) copied the `repository` and `id` fields verbatim instead of resetting them like PHP's BasePackage::__clone() does. LibraryInstaller::install() relies on the duplicate being unbound so it can register the package with the local repository; without the reset, add_package() silently failed with "A package can only be added to one repository", leaving installed.json empty after every install/create-project run.
2026-07-04fix(event-dispatcher): avoid reentrant RefCell panicsnsfisis
Two related "already borrowed" panics reachable from AutoloadGenerator::dump() (which holds the local-repository, installation-manager, and config RefCells for the duration of its own statement, per the temporary-lifetime-extension pattern fixed separately in create_project_command.rs): - ensure_bin_dir_is_in_path called config.borrow_mut() to read "bin-dir", but Config::get only needs &self; use borrow() so it can coexist with an outer borrow instead of conflicting with it. - make_autoloader's real body needed composer_handle.borrow_mut() plus the same local-repository/installation-manager RefCells the caller already holds mutably, which cannot be made reentrant-safe without a larger restructuring. Since all 3 call sites already discard its return value, and its only effect (registering a Composer-generated ClassLoader for autoloading during event-listener PHP execution) is unobservable in this port — there's no embedded PHP interpreter to register it into, and class_exists for user-defined classes is a hardcoded-false shim so the caller's very next check always treats the class as unavailable regardless — make it a genuine no-op. This unblocks the post-autoload-dump event for any script listener naming a PHP class (e.g. Illuminate\Foundation\ComposerScripts), which every create-project/install run reaches once real packages get installed. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-04fix(installer): preserve fixedRootPackage identity for solver poolnsfisis
PHP's createRepositorySet does `$this->fixedRootPackage = clone $this->package;` once and then passes that same object both to `new RootPackageRepository($this->fixedRootPackage)` and, later, to createRequest($this->fixedRootPackage) — object identity matters because the solver assigns a pool id by mutating the package object itself. The port instead called RootPackageInterfaceHandle::dup() a second time when registering the RootPackageRepository, producing a second object that never went through the pool and so never got an id. create_request's `request.fix_package(root_package_handle)` then referenced a package with id -1, which add_rules_for_request treats as a real bug: "Fixed package ... was not added to solver pool." This surfaced whenever a create-project run reached the second-stage install (i.e. every dist-installed project with real dependencies). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-04fix(create-project-command): split chained config.borrow_mut() callsnsfisis
install_project's fluent builder chain called config.borrow_mut() four times inline as method arguments. Rust extends every argument temporary's lifetime to the end of the enclosing statement, so the first borrow_mut() was still alive when the second one ran, panicking with "already borrowed". Compute each value into a local before the chain instead, matching the pattern already used in install/update/require/remove_command.rs. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-04fix(xdebug-handler): implement get_skipped_versionnsfisis
The restart-to-disable-xdebug mechanism isn't ported (is_xdebug_active is hardcoded false), so a restart never happens and PHP's self::$skipped stays at its default empty string. Return that directly instead of todo!(), since PlatformRepository::initialize() calls this unconditionally. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-04fix(php-rpc): wire Runtime::invoke/get_extension_info/extensionsnsfisis
Route the platform-repository seams that need real PHP introspection through php-rpc instead of todo!()/hardcoded shims: - Runtime::invoke now handles the two dynamic callables PlatformRepository actually reaches (inet_pton, curl_version) via new php-rpc calls; other callables remain unsupported. - Runtime::get_extension_info uses a new `extension_info` php-rpc call (ReflectionExtension::info() + output buffering) instead of todo!(). - Runtime::get_extensions/get_extension_version now query the real PHP process (get_loaded_extensions, phpversion) instead of the shirabe-php-shim's hardcoded "standard CLI environment" model, so platform requirement checks see the extensions actually installed. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-04fix(pcre): restore missing regex delimiters in ported patternsnsfisis
Several Preg::*() call sites lost their PHP delimiter (and in one case the `i` modifier) during porting, since preg_*() expects the delimiter to be preserved in the caller's pattern literal and stripped internally. This made compile_php_pattern panic or silently misparse the pattern. Un-ignore the Version tests that were blocked by this bug.
2026-07-04test: ignore broken testsnsfisis
2026-07-02feat(php-rpc): implement Runtime::has_constant/get_constant via php-rpcnsfisis
Runtime::hasConstant/getConstant need a real PHP interpreter's defined()/ constant() to answer platform requirement checks (e.g. PHP_ZTS, PHP_INT_SIZE), which the shim can't provide since Rust constants aren't queryable by string. Extend shirabe-php-rpc's protocol to carry one string argument and return the full PHP scalar range, add defined/constant dispatch entries to the worker, and wire Runtime and get_php_version/get_php_binary onto them.
2026-07-02chore(lint): ban std::io::Read/Write, Any, Command use importsnsfisis
Extends no_banned_use to cover std::any::Any, std::io::Read/Write, and std::process::Command, and teaches the linter to allow `as _` imports so trait methods can still be brought into scope without binding the banned name. Fully qualifies all existing usages across the codebase.
2026-07-02fix(platform-repository): wire ensure_initialized into RepositoryInterfacensfisis
PlatformRepository::initialize() (php-version/extension detection) was never invoked: the RepositoryInterface impl delegated straight to the inner ArrayRepository without the ensure_initialized lazy-init guard that sibling repositories (FilesystemRepository, PathRepository) use. As a result pool.what_provides("php") was always empty, and any package requiring php failed platform resolution. Also fixes the trait search() bypassing PlatformRepository's own SEARCH_VENDOR override.
2026-07-01test(repository-manager): port testFilterRepoWrappingnsfisis
PathRepository already implements RepositoryInterface and create_repository already handles the "path" class, so the prior ignore reason no longer applies; verify the FilterRepository/PathRepository wrapping via RepositoryInterfaceHandle::is/downcast_rc.
2026-07-01test(application): port two doRun script-command testsnsfisis
Port testNoPluginsDisablesPluginsWhenScriptCommandsExist and testScriptCommandTakesPriorityOverAbbreviatedBuiltinCommand. Both stay #[ignore]d because do_run panics at the script-registration todo!() (application.rs:2461) when composer.json has scripts. Add a test-only ApplicationHandle::__get_composer accessor so the first test's getPluginManager assertions can be expressed. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01test(archive-manager): port testArchiveTar and testArchiveCustomFileNamensfisis
Wire a git downloader into the test's DownloadManager (mirroring Factory::createDownloadManager) so the archive path clones the package source as PHP does. Both remain #[ignore]'d on PharData tar archiving (new_with_format/build_from_iterator are todo!() in the php-shim). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01test(downloader): port ZipDownloader testErrorMessagesnsfisis
The faithful port drives a real HttpDownloader + Loop over a file:// dist URL, but RemoteFilesystem::get_remote_contents is a phase-c stub returning None, so the download fails with a "could not be downloaded" TransportException before reaching the ZipArchive "is not a zip archive" path. Kept #[ignore] with the corrected reason (the previous curl_multi_init note was wrong, file:// never uses curl). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01test(remote-filesystem): port get_contents, copy, bitbucket downloadnsfisis
These three tests exercise getContents/copy against a file:// URL (and a real network download for BitBucket). They remain #[ignore] because get_remote_contents has no stream/file layer yet (TODO(phase-c)) and returns None, so the calls raise a TransportException. The ignore reasons are updated to reflect the actual failure point. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01test(autoload): port 5 AutoloadGenerator testsnsfisis
Port testVendorDirExcludedFromWorkingDir, testUpLevelRelativePaths, testGeneratesPlatformCheck (all 12 data-provider rows), and both testAbsoluteSymlinkWith* tests from the Composer suite. testVendorDirExcludedFromWorkingDir passes. The other four expose behavioral gaps in shirabe (exclude-from-classmap with up-level/symlink paths, psr-4 symlink warnings, get_platform_check provider matching), so they keep their fully-ported bodies but are marked #[ignore] with the specific incompatibility rather than weakening expectations. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01test(php-rpc): cover serialize parser, framing, and PHP querynsfisis
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01feat(php-rpc): query real PHP version and binary for --versionnsfisis
Add a minimal shirabe-php-rpc crate that spawns the system PHP as a child process and asks it for runtime information over a Unix domain socket, then use it to fill the `--version` PHP line with the real \PHP_VERSION and \PHP_BINARY instead of fixed placeholder values. See docs/dev/php-rpc.md for the design and scope. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-30refactor(git): replace is_callable with RunCommandOutput traitnsfisis
Model Git::runCommand's mixed $commandOutput parameter with the RunCommandOutput trait (one impl per PHP mode: discard, by-ref capture, callable handler), mirroring ProcessExecutor's IntoExecOutput. This moves the is_callable($commandOutput) value-inspection into the type system and drops the dependency on the shim's incomplete is_callable. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29feat(php-shim): implement DirectoryIterator in fs shimnsfisis
Give DirectoryIteratorEntry a backing path (mirroring RecursiveIteratorFileInfo) and make directory_iterator enumerate entries, returning Result to match PHP DirectoryIterator's UnexpectedValueException on an unopenable directory. Wire the new Result through DumpCompletionCommand's get_supported_shells. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29feat(repository): instantiate vcs, artifact, path repositories by classnsfisis
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29feat(vcs): clone io handle in ForgejoDriver git/OAuth setupnsfisis
Resolve the two todo!() placeholders by passing self.inner.io.clone() to VcsDriverBase::new and Forgejo::new, matching the PHP source's $this->io arguments and the GitHub/GitLab driver idiom. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29feat(console): implement StringInput stringification in global proxynsfisis
StringInput inherits __toString from ArgvInput in PHP; mirror that with a Display impl delegating to its inner ArgvInput, and use it in GlobalCommand::input_to_string. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29feat(require): update locker hash with stability flags rewriternsfisis
Resolve the remaining todo! in update_requirements_after_resolution by passing the stability-flags rewriter closure to Locker::update_hash, porting the static closure from RequireCommand.php. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29feat(audit): implement get_packages non-locked branchnsfisis
Port AuditCommand::getPackages's non-locked path: build an InstalledRepository from the local repository and return its packages, filtered by RootPackage requires when --no-dev is set. The prior TODO(phase-c) assumption (InstalledRepository::new vs get_local_repository type mismatch) no longer holds since both sides use RepositoryInterfaceHandle. Enables the two previously ignored audit command tests. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29feat(package): implement RootAliasPackage root getters via owned returnsnsfisis
It is faithful to PHP's by-value array/string semantics. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29fix(json): use php_truthy for JsonManipulator content validity guardsnsfisis
The `!@json_decode($children)` guards in addSubNode/removeSubNode were translated as `is_null() || as_bool() == Some(false)`, which drops PHP's other falsy cases (empty array/string, "0", 0). At the removeSubNode site (assoc=true) this diverged from Composer: an empty object node decodes to an empty array, which PHP treats as falsy and aborts on, but the Rust guard kept going. Replace both with php_truthy, the faithful rendering of PHP `!`, preserving the deliberate empty-`{}` behavior difference between the assoc=false (addSubNode) and assoc=true (removeSubNode) sites. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-29feat(console): implement output instanceof downcasts in process/progress helpersnsfisis
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29fix(advisory): pass IO as shared handle to Auditor::auditnsfisis
Auditor::audit took io as &mut dyn IOInterface, forcing the audit and installer post-audit call sites to hold a borrow_mut() on the shared IO RefCell for the whole call. During advisory fetching the repositories write to their own clones of the same handle, so the borrow_mut() collided with their borrow() and panicked with 'RefCell already mutably borrowed' on 'audit --locked'. Take the Rc<RefCell<dyn IOInterface>> handle instead so writes borrow briefly and never overlap. Un-ignore the locked-audit regression test that this unblocks. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29refactor(json): replace seld/jsonlint with serde_jsonnsfisis
Validate JSON syntax with serde_json's parse errors in JsonFile, and detect duplicate keys in ConfigValidator with a hand-written serde visitor, dropping the now-unused JsonParser/Lexer/DuplicateKeyException ports. ParsingException is kept as the thrown error type and downcast signal. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29chore(lint): ban bare `use anyhow::Result` and fully qualify itnsfisis
Add a no_banned_use linter that forbids importing anyhow::Result, and update all call sites to reference it via its fully-qualified path so it is never confused with std::result::Result. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>