From b4ab3df2ec85fbe477d7721344a8cd3630b437a1 Mon Sep 17 00:00:00 2001 From: nsfisis Date: Sun, 16 Aug 2026 13:59:28 +0900 Subject: feat(plugin): guard Rust-owned classes the worker has no proxy for The worker's autoloader fell through to the real Composer source for every Rust-owned FQCN without a proxy stub, so plugin code doing `new Filesystem()` or subclassing `LibraryInstaller` silently ran on a second instance the Rust side never sees. An unimplemented part of the plugin API has to fail with an explicit error naming it, not quietly work on a disconnected copy. The stub generator now emits a guard class for each of those FQCNs: the real declaration, hierarchy and constants, with every constructor and method raising an explicit error. References satisfied by the declaration alone (`instanceof`, `X::class`, `Link::TYPE_REQUIRE`) keep working. Two FQCNs stay resolvable to the real class, each listed with the worker-side mechanism that makes a natively constructed instance correct. The error had nowhere to go: `Installer::run` dropped the `Result` of both `dispatch_script` calls, so an exception from a listener ended in exit 0. Both propagate now, the way the exception does upstream. Three real-plugin E2E comparisons stop at a guard and are ignored, each naming the class it needs. Co-Authored-By: Claude Opus 5 (1M context) --- scripts/plugin-stub-generator/guard-exemptions.list | 14 ++++++++++++++ 1 file changed, 14 insertions(+) create mode 100644 scripts/plugin-stub-generator/guard-exemptions.list (limited to 'scripts/plugin-stub-generator/guard-exemptions.list') diff --git a/scripts/plugin-stub-generator/guard-exemptions.list b/scripts/plugin-stub-generator/guard-exemptions.list new file mode 100644 index 00000000..90adcb20 --- /dev/null +++ b/scripts/plugin-stub-generator/guard-exemptions.list @@ -0,0 +1,14 @@ +# Classes the Rust side owns that the worker still resolves to the real Composer implementation, +# so no guard is emitted for them. An entry belongs here only when the worker has a mechanism that +# makes a natively constructed instance correct; without one the class must be guarded, or code +# running here would silently work on an instance the Rust side never sees. One FQCN per line, +# each with the mechanism that justifies it. + +# The wire codec revives values of this class from the object record serialize() writes for them +# (php/runtime/Shirabe/MaterializedValue.php), so the real declaration has to stay loadable. +Composer\Package\Link + +# Real Composer\Command code running in this worker constructs one (BaseCommand::initialize), and +# the dual-mode Composer\EventDispatcher\Event (php/runtime/) carries a natively constructed event +# to the Rust side as a P-table entity. +Composer\Plugin\PreCommandRunEvent -- cgit v1.3.1-4-g156e