From b4ab3df2ec85fbe477d7721344a8cd3630b437a1 Mon Sep 17 00:00:00 2001 From: nsfisis Date: Sun, 16 Aug 2026 13:59:28 +0900 Subject: feat(plugin): guard Rust-owned classes the worker has no proxy for The worker's autoloader fell through to the real Composer source for every Rust-owned FQCN without a proxy stub, so plugin code doing `new Filesystem()` or subclassing `LibraryInstaller` silently ran on a second instance the Rust side never sees. An unimplemented part of the plugin API has to fail with an explicit error naming it, not quietly work on a disconnected copy. The stub generator now emits a guard class for each of those FQCNs: the real declaration, hierarchy and constants, with every constructor and method raising an explicit error. References satisfied by the declaration alone (`instanceof`, `X::class`, `Link::TYPE_REQUIRE`) keep working. Two FQCNs stay resolvable to the real class, each listed with the worker-side mechanism that makes a natively constructed instance correct. The error had nowhere to go: `Installer::run` dropped the `Result` of both `dispatch_script` calls, so an exception from a listener ended in exit 0. Both propagate now, the way the exception does upstream. Three real-plugin E2E comparisons stop at a guard and are ignored, each naming the class it needs. Co-Authored-By: Claude Opus 5 (1M context) --- crates/shirabe/tests/plugin/e2e_installers_test.rs | 7 +++++++ 1 file changed, 7 insertions(+) (limited to 'crates/shirabe/tests/plugin/e2e_installers_test.rs') diff --git a/crates/shirabe/tests/plugin/e2e_installers_test.rs b/crates/shirabe/tests/plugin/e2e_installers_test.rs index 67c51b5c..9d8693fb 100644 --- a/crates/shirabe/tests/plugin/e2e_installers_test.rs +++ b/crates/shirabe/tests/plugin/e2e_installers_test.rs @@ -99,6 +99,11 @@ fn edit(path: &Path, from: &str, to: &str) { std::fs::write(path, text.replace(from, to)).unwrap(); } +// TODO(plugin): the plugin's Installer extends Composer\Installer\LibraryInstaller, whose +// constructor the guard class the worker loads rejects with an explicit error: the Rust side owns +// LibraryInstaller and has no proxy a plugin can subclass. The same applies to the two tests +// below. +#[ignore = "LibraryInstaller is Rust-owned and has no proxy a plugin can subclass; see the TODO(plugin) above"] #[test] fn test_composer_installers_matches_upstream_composer() { if !php_runtime_available() || !plugin_fetched() { @@ -139,6 +144,7 @@ fn test_composer_installers_matches_upstream_composer() { /// The rest of the installer contract: `update` reinstalls a package in place, a second `install` /// runs over an already-installed tree, and `remove` reaches the plugin's own `uninstall()` /// override — the one that chains onto the promise `LibraryInstaller::uninstall` returns. +#[ignore = "LibraryInstaller is Rust-owned and has no proxy a plugin can subclass; see the TODO(plugin) above"] #[test] fn test_composer_installers_update_and_remove_match_upstream_composer() { if !php_runtime_available() || !plugin_fetched() { @@ -203,6 +209,7 @@ fn test_composer_installers_update_and_remove_match_upstream_composer() { /// The plugin's configuration surface: `installer-paths` in the root package's extra (both the /// `type:` and the package-name matcher, with `{$name}` templating) and `installer-name` in the /// installed package's own extra. Both are read back through the package proxy. +#[ignore = "LibraryInstaller is Rust-owned and has no proxy a plugin can subclass; see the TODO(plugin) above"] #[test] fn test_composer_installers_custom_paths_match_upstream_composer() { if !php_runtime_available() || !plugin_fetched() { -- cgit v1.3.1-4-g156e