| Age | Commit message (Collapse) | Author |
|
advisories
get_security_advisories cloned each package's full metadata blob
(hundreds of versions for popular packages) just to peek at its
"security-advisories" field. Same pattern already fixed in
load_async_packages by 2862d2da; move ownership through pattern
matches and IndexMap::shift_remove instead.
Measured with laravel/laravel create-project: response processing in
the security-advisories metadata branch drops ~80% (236ms -> 48ms),
and the whole run_security_advisory_filter phase drops from ~420-500ms
to ~250-270ms. End-to-end, shirabe now matches or edges out upstream
Composer (6.57s vs 6.85s in this run) instead of trailing by ~1.2s.
|
|
metadata
load_async_packages cloned each response's version metadata up to
three times (spec_list/response, response_arr, versions_mixed, then
every per-version field) before building the versions Vec. Move
ownership through pattern matches and IndexMap::shift_remove instead.
Measured with laravel/laravel create-project: per-batch response
processing time in load_async_packages drops ~39% (1.30s -> 0.80s
cumulative), narrowing the E2E gap vs upstream Composer from 1.37s to
1.14s on average.
|
|
Several call sites coerced PhpMixed to bool via `.as_bool()` (which
only matches a literal Bool variant) where the corresponding PHP code
does a plain `(bool)` cast or truthy check (isset()/array_key_exists()
+ implicit bool conversion). This silently dropped truthy non-bool
values (e.g. String("true"), String("1"), Int(1)) to their unwrap_or
default instead of PHP's actual truthy result. Switched these sites to
PhpMixed::to_bool(), which implements PHP's full truthy-cast rules.
|
|
PHP's `?:` chain in getComposerInformation short-circuits, so
getBranches() only runs when the tags search is falsy. The eager port
issued an extra git/refs/heads API request that PHP never makes.
Un-ignore test_public_repository_archived, which this fixes.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
|
abandoned propagation
The json format branch ignored search results entirely and always wrote
null. Encode results into the same name/description/abandoned/url shape
Composer's array-backed repositories produce. Also fix
ComposerRepository's RepositoryInterface::search adapter, which dropped
the abandoned field from raw API results even when present.
|
|
executeBatch now builds one future per operation — the PHP promise
chain prepare -> install/update/uninstall -> cleanup -> repo->write,
including the '<Op> of <pkg> failed' rejection handler covering the
chain up to cleanup — and drives the whole batch through
waitOnPromises()/Loop::wait, so archive extraction (the unzip
subprocesses gated by ProcessExecutor's semaphore) finally overlaps
across packages. Alias operations stay synchronous in the collection
loop like PHP.
The shared repository is threaded through the chains as
RefCell<&mut dyn InstalledRepositoryInterface>: execute() wraps the
incoming &mut once, and InstallerInterface::install/update/uninstall
take the cell so implementations borrow it only in their synchronous
head/tail, never across an await. InstallationManager's own
install/update/uninstall/download/get_installer/get_install_path/
mark_for_notification move to &self (cache and notifiable_packages
behind RefCell) so every chain can capture &self.
WritableRepositoryInterface::write and the InstallationManagerInterface
get_install_path it relies on lose their &mut manager requirement —
the per-op repo->write inside the chains only reads install paths.
Warm-cache create-project laravel/laravel: the package-operations
phase (109 installs) drops from ~3.0-3.8s serial to ~1.9s, on par
with real Composer (~2.1s) measured back-to-back; the resulting
vendor tree, installed.json included, stays byte-identical to
Composer's (diff -rq clean).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
|
regex::Regex::clone() does not share the underlying meta engine's
search-cache pool, so every fresh clone pays a ~10us warmup cost on
its first use. Two changes together eliminate this across nearly all
preg_* call sites:
- A php_regex! macro resolves PHP-style patterns to a per-call-site
&'static regex::Regex (via regex-macro's LazyLock), applied at the
majority of call sites throughout the codebase.
- Call sites still passing dynamic pattern strings go through
PATTERN_CACHE, which now stores Arc<(Regex, bool)> and hands out
Arc::clone()s instead of cloning the Regex itself.
PregPattern::resolve() returns a ResolvedPattern enum (Arc or
'static reference) rather than an owned Regex, so neither path ever
clones the Regex proper.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
|
security-advisories in a p2 provider response is a JSON array, which
decodes to PhpMixed::List rather than PhpMixed::Array. The check only
matched Array, so it always missed and silently fell through to the
api-url fallback instead of using the already-cached provider data.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
|
Replace sync_executor::block_on's reactor-less busy-spin poller with
tokio::task::block_in_place + Handle::current().block_on(), riding a
single tokio Runtime entered once in main.rs (falling back to a
disposable one when no ambient runtime exists, e.g. in tests). This
lets HttpDownloader::dispatch await CurlDownloader::download directly
instead of bouncing through the separate curl_runtime() bridge, which
is now deleted.
Manual create-project verification against the real network caught a
concurrency bug this exposed: async_fetch_file held http_downloader's
RefMut across the await on add(), which only panics once downloads
genuinely overlap. add() only needs &self, so borrow() fixes it.
With everything now sharing one real reactor, the FuturesOrdered
fan-out added for ComposerRepository::get_security_advisories/
load_async_packages finally overlaps for real: fetching 8 packages'
metadata dropped from ~7-40s to a consistent ~3-4s in a before/after
comparison, with identical resulting lock files.
sync_executor::block_on's call sites are still synchronous rather
than async fn propagated up to Command::execute, which remains the
end goal (see the TODO(phase-e) in sync_executor.rs) - nested block_on
calls elsewhere don't get this same overlap, only prevented panics.
|
|
get_security_advisories/load_async_packages serialized every
start_cached_async_download call through sync_executor::block_on
per name, matching PHP's structure but not its promise-based
concurrency. Wrap the mutable state those downloads touch (cache,
fresh_metadata_urls, packages_not_found_cache, degraded_mode) in
RefCell/Cell so start_cached_async_download and its async_fetch_file
helpers can drop to &self, then fan out all downloads for a batch via
FuturesOrdered before processing responses sequentially in original
order, mirroring PHP's build-all-promises-then-wait shape.
Real I/O overlap still awaits item 7 (HttpDownloader::add currently
resolves through the curl_runtime()/sync_executor::block_on bridge
either way), so this is architectural groundwork, not a perf win yet.
|
|
|
|
Convert errors/warnings/config to RefCell so load() can satisfy the
trait's &self signature, matching upstream's `instanceof
ValidatingArrayLoader` check in VcsRepository. This makes the
InvalidPackageException downcast path in VcsRepository reachable for
the first time instead of being permanently dead code.
|
|
fallback paths
VcsDriverInterface::get_source/get_dist were made fallible in the Rust
port even though PHP's are infallible, forcing GitBitbucketDriver's
fallback delegation to silently swallow errors via
unwrap_or_default()/ok().flatten(). Make the trait infallible to match
PHP, updating the mechanical Ok(...) wrapping in all implementors.
Also narrow attempt_clone_fallback's cleanup to only trigger on
RuntimeException, mirroring PHP's catch (\RuntimeException $e), using
the same downcast pattern already used by has_composer_file for
TransportException.
|
|
load_async_packages (the v2 metadata-url/packagist protocol path)
called a separate create_packages_static helper instead of the
instance method create_packages. PHP has a single createPackages
method used everywhere, so this duplicate silently skipped the
notification-url injection (and dist-mirror/transport-options setup)
that create_packages performs. Every package resolved via the
lazy provider path ended up missing notification-url in
composer.lock/installed.json. Removed the now-dead duplicate.
|
|
PHP's addOverriddenPackage calls parent::addPackage() (a non-virtual
call straight to ArrayRepository), but the port called self.add_package,
re-entering PlatformRepository::add_package. Since the newly created
override package's name also starts with "php-", this recursed
forever and blew the stack.
|
|
Several Preg::*() call sites lost their PHP delimiter (and in one case
the `i` modifier) during porting, since preg_*() expects the delimiter
to be preserved in the caller's pattern literal and stripped internally.
This made compile_php_pattern panic or silently misparse the pattern.
Un-ignore the Version tests that were blocked by this bug.
|
|
Extends no_banned_use to cover std::any::Any, std::io::Read/Write, and
std::process::Command, and teaches the linter to allow `as _` imports
so trait methods can still be brought into scope without binding the
banned name. Fully qualifies all existing usages across the codebase.
|
|
PlatformRepository::initialize() (php-version/extension detection) was
never invoked: the RepositoryInterface impl delegated straight to the
inner ArrayRepository without the ensure_initialized lazy-init guard
that sibling repositories (FilesystemRepository, PathRepository) use.
As a result pool.what_provides("php") was always empty, and any
package requiring php failed platform resolution. Also fixes the
trait search() bypassing PlatformRepository's own SEARCH_VENDOR
override.
|
|
Model Git::runCommand's mixed $commandOutput parameter with the
RunCommandOutput trait (one impl per PHP mode: discard, by-ref capture,
callable handler), mirroring ProcessExecutor's IntoExecOutput. This moves
the is_callable($commandOutput) value-inspection into the type system and
drops the dependency on the shim's incomplete is_callable.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Resolve the two todo!() placeholders by passing self.inner.io.clone()
to VcsDriverBase::new and Forgejo::new, matching the PHP source's
$this->io arguments and the GitHub/GitLab driver idiom.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Add a no_banned_use linter that forbids importing anyhow::Result, and
update all call sites to reference it via its fully-qualified path so
it is never confused with std::result::Result.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
flattenRepositories must recurse into InstalledRepository (which extends
CompositeRepository in PHP) and ShowCommand must unwrap FilterRepository
when categorizing repos. Without this, installed/locked/platform packages
all fell through to the "available" bucket, dropping the version column
and per-section grouping. Un-ignores 10 show_command tests.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Port composer/tests/Composer/Test/InstallerTest.php. testInstaller (the
provideInstaller cases) is fully ported and passes; the three integration
tests port doTestIntegration in full (the .test fixture loader, FactoryMock,
the in-process console Application with install/update commands, and the
PHPUnit assertStringMatchesFormat matcher) and remain #[ignore]'d since the
install pipeline is not yet executable end-to-end.
Add test-only `__`-seams to the concrete types the test depends on, since
their consumers (e.g. Locker takes the concrete InstallationManager) and the
subclass-style mocks have no trait to mock: InstallationManager (recording
mock + as_any), Factory (__create_mock), VersionGuesser, and
InstalledFilesystemRepository. The production path (mock: false) is unchanged.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
The CurlDownloader owned a tokio runtime and block_on'd reqwest from its
sync tick(), while the repository/installer/downloader sync bridges each
created another Runtime and block_on'd async fns that reach that leaf.
Driving one Runtime::block_on from within another panics with "Cannot
start a runtime from within a runtime", hit by `require` when fetching
p2 metadata.
Switch CurlDownloader to a blocking reqwest client (its own internal
thread, never nested) and replace the per-call Runtime::new().block_on
bridges with a no-reactor sync_executor::block_on helper. No awaited
future parks on a reactor once the only async I/O is blocking, so the
helper can be nested freely.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
|
|
The structural methods are inherited from ArrayRepository in PHP, where
the lazy package load is driven by the overridden initialize(). Without
virtual dispatch, each repository now ensures that load via a &self
ensure_initialized() before delegating to the inner ArrayRepository.
This required moving the repositories' lazily-populated state behind
interior mutability (RefCell/Cell) and adding &self find_package_internal
/find_packages_internal helpers on ArrayRepository.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Port 11 categories of previously-ignored Composer tests now reachable with
the mockall crate: DownloadManager, VCS/Perforce/File downloaders,
VersionSelector, PlatformRepository, Auditor, installer/FilesystemRepository,
RootPackageLoader, util auth/http, commands, and Cache.
Extract test seams additively on concrete structs as *Interface traits
(Runtime, HhvmDetector, VersionGuesser, RepositorySet, Perforce,
BinaryInstaller) plus mock-field seams (Cache, Filesystem); consumers take
trait objects. Mocks are defined locally in the test crates via
mockall::mock!, since automock-generated mocks are cfg(test)-gated and
invisible across the integration-test boundary.
dataProviders are ported in full; tests blocked by unported shims stay
#[ignore] with documented reasons rather than reduced or weakened.
Fix product bugs surfaced by the ports:
- util/github: use the exception code, not the HTTP status, for 401/403
- advisory: serialize empty audit maps as [] to match PHP json_encode
- repository/filesystem and downloader/file: fix RefCell double-borrow panics
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Composer/PartialComposer exposed its RepositoryManager, InstallationManager,
EventDispatcher, Locker, DownloadManager, AutoloadGenerator and ArchiveManager
as concrete types, but Composer's public setters (setDownloadManager() etc.)
let plugins swap in subclasses. Introduce a *Interface trait per manager and
store each as Rc<RefCell<dyn ...Interface>> so a replacement is honored.
Only Composer's slots and the sinks fed from its accessors become trait
objects; managers injected concretely at construction keep their concrete
references, matching PHP semantics. Fluent setters on the affected classes now
return () and Locker::update_hash is de-generified to a boxed FnOnce so the
traits stay object-safe.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
file_put_contents_if_modified held a filesystem borrow_mut() receiver
while its argument re-borrowed the same RefCell via dump_to_php_code(),
panicking with "RefCell already borrowed". Build the file contents
before taking the borrow.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
|
|
Add create_installed_json/create_composer_lock test helpers. Port command (8),
repository path/forgejo/perforce/vcs (11), and fossil/hg/download_manager (13)
tests. Fix production porting bugs: root_package_loader/forgejo_url/version_bumper
regex delimiters, repository_manager create_repository_by_class, array_loader
isset, licenses_command RefCell borrow; implement disk_free_space and
touch2/touch3 via libc.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Port command (9), util gitlab/forgejo/tls (6), package (6), repository (3)
tests. Implement TlsHelper. Fix porting bugs: config_command extra merge,
RootAliasPackage setters, ValidatingArrayLoader isset, repository_factory name
generation, forgejo exception code, version_parser error chaining.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Replace the libcurl-shim CurlDownloader with a reqwest+tokio implementation per
the .ken sketch, resolving the construction panic that blocked command tests
(mock path via __new_mock is untouched). Port remote_filesystem (7), hg/svn
driver (4), zip_archiver/git_exclude_filter (4) tests. Fix hg/svn/git_exclude
regex-delimiter and svn result-propagation porting bugs.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Port autoload_generator (24), bitbucket (14), suggested_packages (11),
git_driver (6), archive_manager (3), and a bump command test. Fix the
ApplicationTester output-capture root cause (php://memory streams must be
readable regardless of fopen mode). Implement posix_getuid/geteuid, the PCRE
'A' anchored modifier, php_strip_whitespace, stream_get_wrappers, is_callable
scalars; fix preg_quote angle-bracket escaping and class-map parser regexes.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Port perforce (36), locker (10), composer_repository (7), installation_manager
(6), file_downloader (5), and event_dispatcher (6) tests via the mock infra.
Fix production porting bugs surfaced en route: BufferIO::get_output look-behind
regex, ComposerRepository list-form package iteration and initialize dispatch,
gethostname and spl_autoload_functions shims; add EventDispatcher get_listeners
test seam.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Port git, version_guesser, gitlab_driver, github_driver, and git_downloader
tests using the ProcessExecutor/HttpDownloader mocks and IO/Config stubs.
Fix production regex-porting bugs surfaced by the now-reachable paths:
Url::sanitize and Response::find_header_value had non-delimited PCRE patterns;
implement array_search_mixed non-strict branch and a datetime format mapping.
Add HttpDownloader::__new_mock so mocked downloaders skip curl construction.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Replace the Option<&mut PhpMixed> output plumbing with the IntoExecOutput
trait modelling each PHP `$output` case (forward, capture-to-buffer,
discard, callback). This lets do_execute pass a real output handler to
Process::run, captures output back via get_output, and lets Svn pass its
streaming filter handler through execute instead of skipping it.
|
|
Replace the generic cwd parameter backed by the IntoExecCwd trait with a
concrete Option<&str> across execute/execute_args/execute_tty/execute_async.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
|
|
composer::semver stubs
Flatten shirabe-semver's modules into glob re-exports at the crate
root and route all consumers through the short paths. Remove the
duplicate composer::semver stubs from shirabe-external-packages in
favor of the shirabe-semver types.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Move MetadataMinifier and SpdxLicenses out of shirabe-external-packages
into dedicated shirabe-metadata-minifier and shirabe-spdx-licenses
crates, updating all import sites accordingly.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Re-evaluate the reason'd #[ignore] tests under the Phase D criterion:
a test is unportable ONLY if the APIs/types needed to WRITE it do not
exist. A test that compiles but panics at runtime (todo!() body, a
regex the regex crate cannot compile) or fails at runtime (incomplete
or incorrect impl behavior) is portable -- it is written in full and
marked with a reason-less #[ignore].
About 120 test functions move from reason'd #[ignore] to reason-less
#[ignore] (the ported-but-not-yet-passing signal). Impl crates gain
only additive __ test hatches (init_command, pool, file_downloader,
package handle link setters, artifact/path repository, repository
manager, svn); no existing logic changes. Tests whose required APIs
genuinely do not exist (mock/reflection harness, ApplicationTester,
solve() discarding SolverProblemsException, a script::Event that
cannot be passed as an originating event) keep their reason'd
#[ignore].
cargo check -p shirabe --tests passes.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
JsonFile's schema paths previously relied on php_dir() (__DIR__), which has
no runtime equivalent. Add a build.rs that copies composer-schema.json and
composer-lock-schema.json next to the built executable, and resolve them with
std::env::current_exe(). FilesystemRepository now embeds InstalledVersions.php
directly via include_str! instead of reading it through php_dir().
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Faithfully port every method, field and constant of Symfony's
Process.php into process.rs, replacing the reduced stub. Add the
supporting pipes module (PipesInterface/AbstractPipes/UnixPipes/
WindowsPipes), ProcessUtils and the missing process exceptions
(LogicException/InvalidArgumentException) with constructors.
Methods now return anyhow::Result where PHP throws, take the env
argument and a bool-returning callback, and borrow &mut for
status-updating accessors; all callers are updated accordingly.
Extend the php-shim with proc_open/proc_close (PHP-compatible
signatures), proc_get_status, proc_terminate, posix_kill, uniqid,
ftruncate, ftell_stream, fseek3, stream_get_contents3 and env
helpers.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
|
The List and Array variants of PhpMixed boxed their elements
unnecessarily. Store PhpMixed values directly and update all callers
accordingly.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|