aboutsummaryrefslogtreecommitdiffhomepage
path: root/crates/shirabe/src
AgeCommit message (Collapse)Author
2026-08-02fix(io): propagate ask/select errors instead of panickingnsfisis
IOInterface::ask/select now return anyhow::Result<PhpMixed>, and ConsoleIO::ask_question forwards QuestionHelper errors (validator failures, MissingInputException) instead of collapsing them with .expect(). In PHP these exceptions propagate from QuestionHelper through ConsoleIO to the caller, so callers such as UpdateCommand's interactive package selection must be able to observe them; the MissingInputException is wrapped with its concrete type preserved so Application's ExceptionInterface downcast keeps working. All call sites now propagate with `?` (Perforce::query_p4_user becomes Result-returning: PHP declares it void but exceptions still escape), and the previously ignored test_interactive_mode_throws_if_no_package_entered passes. ask_confirmation/ask_and_hide_answer still collapse errors; extending propagation to them is left as TODO(phase-c) pending a decision. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-02fix(repository): run lazy initialization in count/has_packagensfisis
PHP's ArrayRepository::count()/hasPackage() call $this->initialize(), which late-binds to the concrete repository class and lazily loads its packages. The Rust pass-throughs skipped that: they ran ArrayRepository's stub initialize instead, returning 0/false and marking the repository initialized with an empty package list, which made ensure_initialized() skip the real initialization forever after. Take &mut self in RepositoryInterface::count/has_package so the lazy repositories (Filesystem, Platform, Composer) can guard with their real initialize, and return Result from has_package since that initialization can fail (PHP propagates the exception). InstallerInterface::is_installed and InstallationManager::is_package_installed/mark_alias_installed propagate the same way, which also resolves the TODO(phase-d) markers on Package/Path/Artifact/Vcs repositories about initialization errors being swallowed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-02fix(downloader): restore late binding in getLocalChanges/update pathsnsfisis
PHP's FileDownloader::getLocalChanges and ::update call $this->download() / $this->install() / $this->remove() / $this->getInstallOperationAppendix(), which late-bind to the concrete downloader class. The Rust port embeds the parent as `inner`, so delegating these methods to FileDownloader pinned the calls to FileDownloader's own implementations: `status` built the compare tree without extracting the archive (flagging every file of dist-installed packages as changed), and `update` re-installed the raw dist file instead of extracting it. Thread the concrete downloader in as `this: &dyn DownloaderInterface` via shared helpers (base_get_local_changes / base_update) and pass `self` from each delegating downloader. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-02refactor(console-io): make ensure_valid_utf8 a no-op, drop iconv shimnsfisis
Rust's &str is always valid UTF-8, so the mbstring/iconv sanitization chain can never trigger. Reduce it to a no-op with a TODO(phase-c) marker: once the codebase strictly separates Vec<u8> from String, this should take &[u8] and convert lossily. This removes the last caller of the php-shim iconv(), so delete it as well. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-02refactor(php-shim): drop pack/unpack in favor of direct byte handlingnsfisis
The only callers were trivial fixed-format uses: reading the first four hash bytes as a native int, splitting in_addr byte strings, and building a constant ZIP EOCD record. Each site now does the byte manipulation directly, so the general-purpose shims are no longer needed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-02refactor(auditor): build the summary line with format! instead of sprintfnsfisis
The two summary templates are compile-time constants, so the runtime sprintf shim is unnecessary; carry the tag and the "ignored " prefix through the passes list instead of pre-built template strings. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-02fix(diagnose-command): pass the self-audit when installed.json is absentnsfisis
A native binary never ships vendor/composer/installed.json, so Composer's "non-standard Composer installation" warning fired on every diagnose run and forced exit 1. The self-audit itself stays: a Composer source snapshot is planned to be embedded together with the plugin API implementation, which will make it functional; until then the missing file reports success, marked with TODO(phase-c). Also un-ignore diagnose_command_test::test_cmd_success: the other half of its ignore reason ("requires real network access") is no blocker — the PHP original runs its live packagist/github checks unguarded too. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-02fix(symfony-finder): make Glob::to_regex regex-crate compatiblensfisis
Glob::toRegex emits PCRE-only constructs — the (?=[^\.]) look-ahead for the strict-leading-dot rule, the possessive [^/]++ in /**/ segments, and, via BaseExcludeFilter, the (?=$|/) dir-boundary look-ahead — which the regex crate cannot compile, so `archive` and every ArchivableFilesFinder path panicked. Rewrite the port to tokenize the glob (mirroring the PHP loop's dispatch) and resolve every no-dot constraint by recursive union expansion. The dir boundary must take part in that expansion (a trailing `*` matching zero characters drops the constraint onto the boundary itself), so BaseExcludeFilter now uses the new Glob::to_regex_dir_boundary instead of string surgery. Equivalence was verified against PHP 8.5.8 (vendored Glob.php + preg_match) over 66,176 glob x flag x subject combinations with zero divergence. Un-ignores the five archiver tests blocked on this and updates GitExcludeFilterTest's expected pattern text, an explicitly authorized exception to the no-test-modification rule. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-02refactor(git-exclude-filter): pass the line parser as a method referencensfisis
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-01feat(symfony-console): implement interactive question/style helpersnsfisis
Resolve the remaining todo!()s in SymfonyStyle, OutputStyle, QuestionHelper and SymfonyQuestionHelper: * Wire up the virtual dispatch PHP performs for the protected writePrompt()/writeError() overrides, following the codebase's established inheritance idiom (Command, ArchiveDownloader): the base class becomes a trait (QuestionHelperInterface, named after the QuestionInterface precedent) whose provided methods ask/do_ask/ validate_attempts carry the template logic and late-bind the write_prompt/write_error hooks through Self, with inner()/inner_mut() reaching the base-class state. SymfonyQuestionHelper overrides the hooks as plain trait-impl methods, mirroring PHP's protected-method overriding, so SymfonyStyle-driven questions now render the Symfony Style Guide prompt. * Type definition_list input as an enum (string|array|TableSeparator) because PhpMixed intentionally cannot carry objects; the InvalidArgumentException branch (a LogicException) becomes unrepresentable. horizontal_table now takes typed Cells/Rows. * Propagate the MissingInputException thrown inside autocomplete() through a Result instead of aborting. * Implement as_console_output_interface via Ref::filter_map on ConsoleOutput, the interface's only implementor. * Port progressIterate eagerly, following ProgressBar::iterate. * Map __FILE__ to current_exe(): a native binary never runs from a phar, so the hiddeninput.exe relocation branch correctly never fires. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-01feat(php-shim): implement Phar/PharData and the zlib/bzip2 functionsnsfisis
Adopt the tar, flate2, and bzip2 crates to fill in the phar.rs and compress.rs todos: PharData tar/zip reading, building, and whole-archive compression, plus a native .phar reader that follows the php.net file-format manual and verifies hash-based signatures. Callers now propagate the constructor/extract errors PHP throws, and fwrite accepts byte strings so gzread no longer needs lossy UTF-8. The native .phar writing API stays todo!() (no call sites; Composer's Compiler is not ported) and OPENSSL phar signatures are accepted unverified (TODO(phase-c)). This unblocks Tar::getComposerJson and the tar/phar/gzip downloaders; tar_test (7), artifact_repository_test (2), and phar_archiver_test zip (1) are un-ignored. The archive command itself still panics because ArchiveManager::archive always generates glob excludes whose look-ahead regexes the regex crate cannot compile; converting those patterns to regex-compatible ones is a separate, still-undecided work item. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-26feat(diagnose-command): report the real curl versionnsfisis
The line was a "TODO: curl_version()" placeholder. Extend the diagnose payload with curl_version() and the CURL_* constants getCurlVersion() consults, so the libz/brotli/zstd/ssl/HTTP details come from the PHP runtime instead of being guessed. curl_version() is only reachable while the extension is loaded, mirroring the ioncube_loader_* entries. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-26fix(diagnose-command): give the audit BufferIO normal verbositynsfisis
PHP's BufferIO defaults to StreamOutput::VERBOSITY_NORMAL; passing 0 sits below VERBOSITY_QUIET, so every write was dropped and "Audit found some issues:" was followed by an empty advisory table. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-26feat(diagnose-command): query the real PHP runtime in one RPC callnsfisis
diagnose used to read hardcoded shim stubs, so it described a fictional runtime: OPENSSL_VERSION_NUMBER was always 0 and tripped the TLSv1.1/1.2 check, PHP_BINARY and OPENSSL_VERSION_TEXT were empty, and the extension, function and ini probes answered from a fixed table. The PHP worker gained a `diagnose` entry that returns every fact the command needs as one PHP array, cached in a OnceLock so the several call sites share a single round trip. Reading it back needed array support in the serialize() parser, which in turn lets get_loaded_extensions and get_all_ini_files return real lists instead of comma-joined strings. Also fixes the openssl_version message, which dropped strstr()'s before_needle argument during the port, and check_connectivity's allow_url_fopen test, which did not follow PHP string truthiness. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-25fix(package-discovery): honor ignored platform reqs in shadowed-repo lookupnsfisis
The ALLOW_SHADOWED_REPOSITORIES probe that decides whether to raise the repository-priority error hardcoded ignoreNothing(), while PHP reuses $platformRequirementFilter. With --ignore-platform-req the probe could fail to find the lower-priority package and suppress the error PHP would raise. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-25fix(require-command): end input borrow before asking for confirmationnsfisis
The `fixed` option was read as a temporary inside the argument list of update_requirements_after_resolution(), so the Ref lived until the end of the enclosing let statement — i.e. across the whole call. When the resolved version looks like a feature branch, that call asks for confirmation, and ConsoleIO takes the same input RefCell mutably, panicking with "RefCell already borrowed". Hoisting the read into its own statement ends the borrow before the call. The expected output of the un-ignored test transcribed PHP's string concatenation operator (`[y,n]? '.'`, used to keep the trailing space visible) as a literal `.`; it now matches RequireCommandTest.php. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-25fix(package-discovery): pass IO so platform requirement warnings surfacensfisis
findBestVersionForPackage is the only findBestCandidate() caller that PHP hands $this->getIO() to; the port passed None, so VersionSelector silently skipped every "Cannot use <pkg> as it requires <ext> which is missing from your platform" warning. require/update/create-project therefore dropped a candidate without telling the user why. Un-ignores require_command_test::test_require, whose first data-provider case asserts exactly that warning. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-25feat(console): register plugin commands via Application::addnsfisis
get_plugin_commands now yields shared command handles so the discovered commands can go through the same add() path as built-in ones, dropping the placeholder that discarded them. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-25refactor(json): embed Composer schemas instead of copying them to targetnsfisis
build.rs guessed target/<profile> from OUT_DIR to place res/*.json next to the executable (twice, since test binaries live in deps/), and JsonFile resolved them through current_exe(). That made the binary undistributable on its own. The schemas are now include_str!'d and referenced through a shirabe:///res/ URI that SchemaRetriever resolves, keeping the $ref indirection PHP uses for the phar case. The res/ path segment is required so composer-lock-schema.json's relative "./composer-schema.json" reference still resolves.
2026-07-25perf(advisory): share AnySecurityAdvisory via Rcnsfisis
PHP's SecurityAdvisoryPoolFilter stores advisory *object references* in $securityRemovedVersions, and PoolOptimizer::applyRemovalsToPool hands that array to the new Pool by copy-on-write. Porting AnySecurityAdvisory as a value type turned both of those into deep copies. Measured on `require laravel/framework` (offline, warm cache): 113 distinct advisories were duplicated into 314,309 copies of ~1.08 KiB, retaining 331.9 MiB in the filter loop and another 331.9 MiB when apply_removals_to_pool cloned the whole map. 3.54s -> 2.62s (-26%), peak RSS 975 MB -> 343 MB, which matches the upper bound measured by ablation. Composer runs the same workload in 1.49s. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-25refactor: replace redundant clones with movesnsfisis
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-25feat(tracing): init tracing subscriber from $SHIRABE_TRACINGnsfisis
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-25refactor(operation): replace OperationInterface with AnyOperation enumnsfisis
Operations are only ever constructed by the dependency resolver, so a plugin has no way to inject an implementation of its own and the set is closed. Modelling it as an enum, like AnyPackage, removes the OperationInterface trait together with its two parallel downcast mechanisms (as_any() + downcast_ref, and as_*_operation()) and the get_package() default method that panicked on UpdateOperation. The PHP idiom `$op instanceof UpdateOperation ? getTargetPackage() : getPackage()`, written out at six call sites, becomes AnyOperation::get_target_package(). InstallationManager's three blocks that matched on the type string and then recovered the type with expect() collapse into exhaustive matches. SolverOperation keeps only its TYPE constant; the shared getOperationType()/__toString() implementations move to AnyOperation, which also drops the five Self::TYPE.to_string() allocations. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-25chore: remove unused importsnsfisis
2026-07-24fix(event-dispatcher): invoke Closure listeners instead of always failing ↵nsfisis
is_callable RequireCommand registers an inline listener on InstallerEvents::PRE_OPERATIONS_EXEC to track dependency_resolution_completed, mirroring PHP's `function () use (&$dependencyResolutionCompleted) { ... }`. This is Composer's own code, not a Plugin subscriber, but it went through the shared non-string-callable path, which checked is_callable() against a hardcoded PhpMixed::Null and always failed, breaking every `require` that reaches the install step. Callable::Closure now carries the actual Rc<dyn Fn> instead of being a data-less placeholder, and is invoked directly (Closures are always callable in PHP). The ArrayCallable path used by future Plugin subscribers is untouched. Un-ignoring the two require_command_test cases that cited this bug reveals two separate, pre-existing issues (a missing ext-requirement warning message, and a RefCell re-entrancy panic in ConsoleIO::ask_question); their #[ignore] reasons are updated to describe the real current blocker instead of the now-fixed one.
2026-07-24fix(solver-problems): compare RULE_LEARNED sort keys like PHP's <=>nsfisis
Problem::getPrettyString sorts same-priority reasons by getSortableString(), whose RULE_LEARNED key is a '-'-joined literal id string (e.g. "-95"). PHP's <=> compares two numeric strings numerically, but the port used plain String::cmp (byte-wise), which reverses relative order for same-length negative-number keys. Added shirabe_php_shim::loosely_compare to approximate PHP's <=> for this pattern (numeric compare when both sides parse as numbers, else byte compare) and switched the sort comparator to use it. The diagnosis this replaces (from the commit being amended) blamed Pool package-id assignment order diverging from PHP under COMPOSER_POOL_OPTIMIZER=0. That was disproven this session: direct instrumentation of both PHP and the Rust port confirmed identical relative package-id order, including on the ~335-package github-issues-7665 fixture (ids matched up to a constant +2 offset from a platform-mock package count difference). The sort comparator was the actual bug, not package loading order. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-24fix(solver-problems): preserve first-occurrence order in extension hintnsfisis
create_extension_hint's --ignore-platform-req suggestion list sorted missing extensions alphabetically before deduping. PHP's array_unique removes duplicates while preserving first-occurrence order instead, which for this call site matches the order problems were reported in (root-require-not-found problems before SAT-conflict problems). Replaced the sort+dedup with the existing order-preserving shirabe_php_shim::array_unique, which was already ported for exactly this PHP semantic but wasn't used here.
2026-07-24fix(array-dumper): dump source/dist mirrors as a JSON arraynsfisis
ArrayDumper::dump built the mirrors field as PhpMixed::Array keyed by stringified index ("0", "1", ...), which this codebase's PhpMixed JSON serialization renders as an object. PHP just assigns the plain, sequentially-keyed mirrors array directly, which json_encode renders as a JSON array. Use PhpMixed::List instead, matching the actual shape written to composer.lock.
2026-07-24fix(package): rewrite dist-reference SHA regex without look-aroundnsfisis
Package::set_source_dist_references and LockTransaction's dist-url mirroring both used {(?<=/|sha=)[a-f0-9]{40}(?=/|$)}i, but the regex crate has no look-around support at all and panics compiling it. Per docs/dev/regex-porting.md, rewrote the boundary assertions into capturing groups and switched to Preg::replace_callback, which re-emits the captured delimiters around the replaced reference.
2026-07-24fix(composer-repository): initialize wrapper before delegating loadPackagesnsfisis
For a simple, non-lazy composer repository (no providers-url/ metadata-url/providers-lazy-url), load_packages() delegates to self.inner.load_packages() (PHP: parent::loadPackages()). PHP's ArrayRepository::loadPackages() calls $this->getPackages(), which virtual-dispatches through ComposerRepository::getPackages() down to ComposerRepository::initialize() (the real HTTP/file fetch). Composition doesn't get that dispatch for free: self.inner is a bare ArrayRepository, so self.inner.load_packages() ends up calling ArrayRepository::initialize() — a no-op stub that just sets an empty package list — instead of ComposerRepository::initialize(). The repository's packages.json fetched and parsed successfully, but the result was silently discarded, so the repo always looked empty. get_packages() already carries the identical guard with the same diagnosis in its own comment; load_packages() was just missing it. Documented the same latent gap in find_package/find_packages/count/ has_package, which call into ArrayRepository the same unguarded way but aren't known to be exercised by any test yet.
2026-07-24fix(pool-builder): use plain getPackages() on locked repositorynsfisis
PoolBuilder::build_pool() and warn_about_non_matching_update_allow_list() called get_canonical_packages() on the locked repository during a partial update, but PHP's PoolBuilder uses the plain getPackages(). get_canonical_packages() unwraps AliasPackage down to its base package, discarding the alias's own version identity. Locker::get_locked_repository() wraps a lock entry with extra.branch-alias in a single CompleteAliasPackage rather than adding a separate base object, so canonicalizing it silently dropped the locked branch-alias version (e.g. 2.2.x-dev), leaving only the raw dev-master version behind. For a package excluded from the partial update's allow-list, that meant its locked branch-alias version could no longer satisfy the root's constraint, producing a spurious solver conflict instead of keeping the package pinned exactly as locked. Fixed the same bug in AuditCommand's --locked package listing, which had the identical get_canonical_packages()/getPackages() mismatch against AuditCommand.php.
2026-07-24fix(dependency-resolver): query real PHP for ext-* version/loaded checksnsfisis
Two shim gaps made the extension-related branches of solver-problem messages wrong: - phpversion($ext) with a non-empty extension can't be known statically (it's shirabe-php-shim's todo!()); Problem::get_missing_package_reason now calls shirabe_php_rpc::phpversion, the same RPC bridge platform::runtime::Runtime::get_extension_version already uses. - extension_loaded's hardcoded allowlist was missing "pcre", a mandatory always-compiled-in PHP extension, so ext-pcre was misreported as "missing from your system" instead of "disabled by your platform config" whenever a platform override disabled it. Also fix XdebugHandler::getAllIniFiles() always returning `[""]` (a php-runtime stub): create_extension_hint()'s early-return guard (`paths[0] empty && len==1`) fired unconditionally, silently dropping the entire "To enable extensions..." hint from every solver-problem message that mentions missing extensions. shirabe-external-packages can't depend on shirabe-php-rpc (shirabe-php-rpc already depends on shirabe-external-packages), so IniHelper::get_all() queries a new get_all_ini_files RPC command directly instead of going through the stub. This exposed that XdebugHandler is never constructed with a name because bin/composer's restart-without-Xdebug bootstrap was never ported to main.rs, making COMPOSER_ORIGINAL_INIS-driven behavior unreachable; documented with a TODO(phase-c) and updated ini_helper_test.rs's ignore reasons (and ignored test_with_no_ini, which only passed before by coincidence with the old stub's constant output) to match.
2026-07-24fix(locker): return stability-flags as int, not stringnsfisis
Locker::get_stability_flags returned IndexMap<String, String>, converting each value via PhpMixed::as_string(), which only matches the String variant. composer.lock's "stability-flags" values are always JSON integers (BasePackage::STABILITIES), so every flag silently decoded to "" and installer.rs's downstream .parse::<i64>() defaulted it to 0 (stable). This made any locked package pinned via a non-stable stability-flags entry look "unacceptable" during `composer install`, silently dropping it from the solver's pool instead of fixing/requiring it — turning a real dependency conflict into a spurious "lock file needs changes" result. Return i64 directly, matching RootPackageInterface::get_stability_flags and set_lock_data's existing convention for this same PHP array shape.
2026-07-24refactor(filesystem-repository): drop eval() shim, defer installed.php ↵nsfisis
reload to PHP runtime Rust has no PHP interpreter, so eval() can never be ported faithfully. safely_load_installed_versions()'s job of priming Composer\InstalledVersions before plugins run only matters within a single shared PHP process, which the RPC-based plugin architecture does not have; the PHP runtime process can call InstalledVersions::reload() itself instead. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23feat(process-executor): stub plugin-facing execute_async_php pathnsfisis
A plugin can reach ProcessExecutor::executeAsync() through the rust-proxy stub, which resolves with a real Symfony Process instance that can't be reconstructed on the Rust side (its state is tied to whichever process calls proc_open(), and it refuses serialization). Add execute_async_php() as a todo!() stub, documented as a dual- instantiation split in plugin-class-classification.md: Rust-internal callers keep using execute_async(), while the plugin path must forward spawning to the PHP child once the RPC channel exists.
2026-07-20perf(composer-repository): avoid redundant clones when checking security ↵nsfisis
advisories get_security_advisories cloned each package's full metadata blob (hundreds of versions for popular packages) just to peek at its "security-advisories" field. Same pattern already fixed in load_async_packages by 2862d2da; move ownership through pattern matches and IndexMap::shift_remove instead. Measured with laravel/laravel create-project: response processing in the security-advisories metadata branch drops ~80% (236ms -> 48ms), and the whole run_security_advisory_filter phase drops from ~420-500ms to ~250-270ms. End-to-end, shirabe now matches or edges out upstream Composer (6.57s vs 6.85s in this run) instead of trailing by ~1.2s.
2026-07-20perf(composer-repository): avoid redundant clones when loading async package ↵nsfisis
metadata load_async_packages cloned each response's version metadata up to three times (spec_list/response, response_arr, versions_mixed, then every per-version field) before building the versions Vec. Move ownership through pattern matches and IndexMap::shift_remove instead. Measured with laravel/laravel create-project: per-batch response processing time in load_async_packages drops ~39% (1.30s -> 0.80s cumulative), narrowing the E2E gap vs upstream Composer from 1.37s to 1.14s on average.
2026-07-20fix(json-file): forward detected indent into write's encode optionsnsfisis
JsonFile::write_with_options() used the caller-supplied JsonEncodeOptions verbatim, ignoring self.indent (set by read()'s detect_indenting), unlike PHP's write() which always passes $this->indent to encode() regardless of the $options argument. Un-ignore test_preserve_indentation_after_read.
2026-07-20fix(search-command): avoid usize overflow panic when truncating descriptionnsfisis
The negated remaining-width subtraction was cast straight to usize, overflowing whenever it went negative (e.g. an abandoned-package warning ate the available width) and panicking on slice indexing. Route through the shim's substr(), which mirrors PHP's negative-length semantics and clamps instead of overflowing.
2026-07-20fix(pool-builder): fix three build_pool bugs found by un-ignoring ↵nsfisis
test_pool_builder build_pool never populated skipped_load for locked packages skipped due to the update allow list (nor their replace targets), so load_package's skipped_load-driven transitive-unlock branch never fired. load_packages_marked_for_loading never recorded loaded packages into loaded_per_repo, so repositories had no way to dedupe already-loaded versions when a constraint got re-expanded, producing duplicate pool entries. unlock_package looked up a locked package's removal index via the position in a Vec snapshot of self.packages.values() instead of its actual IndexMap key, so after earlier removals the wrong entry (or none) got removed, leaving stale locked packages in the pool. Fixing all three lets test_pool_builder run un-ignored.
2026-07-20fix(no-proxy-pattern): stop chr() corrupting IP bytes as lossy UTF-8nsfisis
shirabe_php_shim::chr() returned a Rust String, which lossily re-encodes bytes >= 0x80 as UTF-8 replacement characters. ip_get_mask, ip_get_network, and ip_map_to_6 relied on chr() to build raw in_addr and netmask byte arrays, corrupting IPv4-in-IPv6 mappings and CIDR netmasks. Build the Vec<u8> byte arrays directly instead of round-tripping through String, and un-ignore test_ip_address and test_ip_range now that the underlying bug is fixed. chr()'s only other caller (http_downloader.rs, an ASCII ESC byte in a regex pattern) didn't need the indirection either, so remove the shim function entirely. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-20fix(php-shim): use PhpMixed::to_bool() for PHP truthy castsnsfisis
Several call sites coerced PhpMixed to bool via `.as_bool()` (which only matches a literal Bool variant) where the corresponding PHP code does a plain `(bool)` cast or truthy check (isset()/array_key_exists() + implicit bool conversion). This silently dropped truthy non-bool values (e.g. String("true"), String("1"), Int(1)) to their unwrap_or default instead of PHP's actual truthy result. Switched these sites to PhpMixed::to_bool(), which implements PHP's full truthy-cast rules.
2026-07-20fix(advisory): treat int-keyed ignore entries as plain IDsnsfisis
parseIgnoreWithApply distinguishes ['CVE-123' => 'reason'] from [0 => 'CVE-123'] by checking is_int($key) in PHP. AuditConfig only matched on the value's type, so a canonical-int-keyed string value was mistaken for an id => reason pair. Expose canonical_int_key from the php-shim to replicate PHP's key-canonicalization rule and unignore test_mixed_formats.
2026-07-20fix(diagnose-command): stop holding a Config borrow across http callsnsfisis
execute() held &config.borrow() across check_http/check_composer_repo/ check_composer_audit, which reach HttpDownloader -> CurlDownloader:: download; that method does self.config.borrow_mut() on the same Config RefCell, panicking with "RefCell already borrowed" once the phpinfo panic that previously masked this was fixed. Switch those three helpers to take the Rc<RefCell<Config>> handle (matching check_version's existing pattern) and borrow only where a field is actually read, so no borrow spans the downstream network call. Un-ignore the now-passing run_diagnose smoke test and test_cmd_fail; test_cmd_success stays ignored, now for two separate reasons: it needs real network access (as the PHP original does), and shirabe_php_shim::OPENSSL_VERSION_NUMBER is a hardcoded stub (0) that always trips check_platform's TLSv1.1/1.2 support check regardless of the real linked OpenSSL, forcing a non-zero exit code.
2026-07-20feat(php-rpc): implement phpinfo() capture over RPCnsfisis
DiagnoseCommand::check_platform needed phpinfo() output but shirabe-php-shim's ob_start()/phpinfo()/ob_get_clean() are unmodeled todo!()s. Add a phpinfo dispatch entry to the PHP worker (capturing output the same way extension_info already does) and a get_phpinfo() wrapper, then switch check_platform to call it directly. This unblocks the phpinfo-related panic in diagnose; the ignored tests now hit a separate RefCell double-borrow bug in check_http, so their ignore reasons are updated to point at that instead.
2026-07-20test(cli-tests): detail run_diagnose ignore reasonnsfisis
Measured the actual panic site: DiagnoseCommand::check_platform reaches the todo!() ob_start()/ob_get_clean() shims while capturing phpinfo(), the same root cause already recorded in tests/command/diagnose_command_test.rs. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20fix(require-command): drop input borrows before determine_requirementsnsfisis
The Ref temporaries created by input.borrow() inside the argument expressions of the determine_requirements call lived until the end of the whole call statement, so ConsoleIO::ask_question's borrow_mut() on the same shared input RefCell panicked with "RefCell already borrowed" when the command prompted for packages. Hoist the argument computations into locals so no borrow is held across the call, and un-ignore the run_require CLI test. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20fix(github-driver): defer get_branches until tags search missesnsfisis
PHP's `?:` chain in getComposerInformation short-circuits, so getBranches() only runs when the tags search is falsy. The eager port issued an extra git/refs/heads API request that PHP never makes. Un-ignore test_public_repository_archived, which this fixes. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20fix(config): drop insecure git protocol under secure-httpnsfisis
Config::get("github-protocols") ported PHP's array_search over the protocol list via a string-keyed map, but array_search_mixed returns the matched index as PhpMixed::Int, which the as_string() read never matched, so the git protocol was never removed (Config.php:447-449 removes it whenever secure-http is on). Search the list directly and read the index as an Int. Un-ignore test_update_throws_runtime_exception_if_git_command_fails which this had blocked. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20fix(config): restore PHP (int) cast for ttl and timeout valuesnsfisis
PHP's Config::get() applies an (int) cast to cache-files-ttl, cache-ttl, and the process-timeout env override (Config.php:326,367,398), so string values like '99999999' become integers. The strict PhpMixed::as_int returned None for strings, collapsing them to 0. Use the intval shim, which implements the PHP cast, and un-ignore test_cache_garbage_collection_is_called which this had blocked. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>