Repository navigation
Only warn berry migration risk when the classic lock holds a pin - #1077
Merged
Mikola Lysenko (mikolalysenko) merged 3 commits intoOct 8, 2026
Merged
Conversation
An offline-mirror refusal leaves the matched classic entries untouched, but the matched entry still set any_pinned, so a first hosted run that wrote nothing reported redirect_yarn_classic_berry_migration_risk next to redirect_yarn_classic_offline_mirror. Count a refused entry as pinned only when an earlier run already wrote its hosted URL into the block. Reported by Cursor Bugbot on #917. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Collaborator
Author
|
bugbot run |
Under an offline-mirror refusal the prior-pin check matched only this run's exact artifact URL, so a lock still holding a hosted pin from an earlier grant token or patch uuid on the same patch server stayed silent about the berry migration risk. Reuse berry_hosted_pin_is_ours on the entry's resolved URL (fragment stripped) so any same-origin hosted pin naming the package version counts, while a user's own mirror does not. Reported by Cursor Bugbot on #1077. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Collaborator
Author
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit f0062e5. Configure here.
Tanmay Singla (Tanmay182003)
approved these changes
Oct 7, 2026
Collaborator
Author
|
[agent] Ready for review at f0062e5.
Generated by Claude Code |
Mikola Lysenko (mikolalysenko)
deleted the
agent/followup-917-berry-risk-mirror
branch
October 8, 2026 01:18
Mikola Lysenko (mikolalysenko)
added a commit
that referenced
this pull request
Oct 8, 2026
Resolve the redirect import and berry_reposition_blocks conflicts in favor of this branch's formats/yarn grammar, and read the classic resolved URL through classic_field in main's #1077 refused-pin check. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko)
added a commit
that referenced
this pull request
Oct 8, 2026
Resolve conflicts with main's #946 (PyPI takeover pre-gate), #1042 (containment helper) and #1077 (classic berry-migration warning): - hosted.rs: keep this PR's staged takeover; main's new `preflight_pypi_takeover` pre-gate inside the deleted `vendored_takeover` is dropped. The staged takeover's `explain` now calls `preflight_pypi_takeover` (instead of only the requirements check), so a retracted uv pin-down (#723) or Poetry 0.x (#945) takeover is still skipped with `redirect_uv_takeover_version_unreachable` / `redirect_poetry_lock_unsupported`, as main's tests expect. - socket_dir.rs: use main's `containment::ensure_unlinked` guard, then this PR's deferred removal. - redirect/mod.rs: take main's `pinned_any` (a mirror-refused entry counts only when it already carries our hosted pin), which subsumes this PR's mirror fix. - CLI_CONTRACT.md: describe the uv/Poetry cases as retractions. - mode_migration_pypi.rs: keep both sides' tests. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #917 (merged), fixing a Cursor Bugbot finding that landed after the merge.
Bugbot finding (Low severity, on #917)
Fix
rewrite_yarn_classic(crates/socket-patch-core/src/patch/redirect/mod.rs) now tracks a separatepinned_anyper dependency:any_pinned(which gatesredirect_yarn_classic_berry_migration_risk) is now fed frompinned_anyinstead ofmatched_any.Tests
New unit test
yarn_classic_berry_risk_follows_pins_under_offline_mirror_refusal:redirect_yarn_classic_offline_mirroris emitted (no berry-risk warning);Locally:
cargo test -p socket-patch-core --lib redirect656 passed. Branch has currentmainmerged in.🤖 Generated with Claude Code
Note
Low Risk
Narrows when a redirect advisory is emitted in yarn.lock rewriting; behavior change is limited to warning accuracy under offline-mirror refusal.
Overview
Fixes
redirect_yarn_classic_berry_migration_riskfiring when Yarn classic entries match but no hosted pin is actually present—e.g. first run under offline-mirror refusal, which skips rewritingresolvedURLs.rewrite_yarn_classicnow trackspinned_anyseparately frommatched_any: a dependency counts toward berry-migration risk only when a pin is written this run, or when a refused block already contains a patch-server hosted URL from an earlier run (berry_hosted_pin_is_ours).any_pinnedis updated frompinned_anyinstead ofmatched_any.Adds
yarn_classic_berry_risk_follows_pins_under_offline_mirror_refusalto assert mirror-only warnings on first refusal, berry-risk when re-running on an already-pinned lock, and correct behavior for old grant URLs vs unrelated mirrors.Reviewed by Cursor Bugbot for commit f0062e5. Configure here.