Skip to content

Route Gradle digests through utils::digest - #878

Open
Mikola Lysenko (mikolalysenko) wants to merge 1 commit into
mainfrom
agent/ci-gradle-digest-helpers
Open

Mikola Lysenko (mikolalysenko) wants to merge 1 commit into
mainfrom
agent/ci-gradle-digest-helpers

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

Summary

main has been failing socket-patch-core --lib since c644ab0. The cause is a semantic conflict between Gradle support (#646) and the digest helpers (#865), not either PR alone. #865 added a guard test, utils::digest::tests::production_digests_go_through_the_helpers, which asserts that production code hashes only through utils::digest. #646 landed three files that still hash inline:

  • crawlers/gradle_cache.rs: pristine and DerivedIndex::query (sha1)
  • patch/jvm_jar.rs: sha256_hex / sha1_hex
  • patch/sidecars/maven.rs: Algo::digest (sha1)

This breaks test (ubuntu/macos), test-release and coverage on every open PR (first seen on #827).

Fix

Each inline call goes through utils::digest::sha1_hex_of / sha256_hex_of. Those helpers compute the same lowercase hex, so behaviour is unchanged. I removed the Digest imports that became unused. The test-only inline SRI in jvm_jar.rs's test module is left alone, since the guard skips test modules. No other production code changes.

Evidence

  • On origin/main c644ab0: cargo test -p socket-patch-core --all-features --lib -- utils::digest::tests::production_digests fails, with left listing the three files above.
  • With this change, cargo test -p socket-patch-core --all-features --lib passes 5243 tests. The only 4 failures are the chmod-based write-failure tests (copy_tree, vlt_heal, pypi_poetry, pypi_requirements), which can't fail as root in the sandbox; they're unrelated, and CI runs as non-root.
  • cargo test -p socket-patch-core --all-features --lib -- utils::digest gradle_cache jvm_jar sidecars: 67/67 pass.
  • cargo clippy --workspace --all-features -- -D warnings is clean, and rustfmt --check is clean on the three touched files.

Related: #827 needs this fix to go green.

🤖 Generated with Claude Code


Generated by Claude Code


Note

Low Risk
Refactor-only: same hex digests via shared helpers; no logic or API changes beyond satisfying the digest guard test.

Overview
Gradle cache, JVM jar patching, and Maven sidecar code no longer compute SHA-1/SHA-256 with inline Digest + hex::encode calls. Production hashing now goes through utils::digest::sha1_hex_of and sha256_hex_of in gradle_cache (pristine, DerivedIndex::query), jvm_jar (sha1_hex / sha256_hex), and sidecars/maven (Algo::Sha1::digest).

This aligns Gradle/JVM paths with the production_digests_go_through_the_helpers guard from #865, which was failing after #646 landed inline digests. Unused sha1/sha2 Digest imports were removed; digest output format is unchanged.

Reviewed by Cursor Bugbot for commit 659ac2c. Configure here.


Generated by Claude Code

main has failed socket-patch-core's lib tests since Gradle support
(#646) and the digest helpers (#865) both landed. The guard test
production_digests_go_through_the_helpers flags three files #646 added
that still hash inline: crawlers/gradle_cache.rs, patch/jvm_jar.rs and
patch/sidecars/maven.rs. That breaks test, test-release and coverage on
every open PR.

Each inline sha1/sha256 call now goes through sha1_hex_of or
sha256_hex_of, which compute the same lowercase hex. Behaviour is
unchanged.

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 659ac2c. Configure here.

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[agent] Ported into #873 (cherry-picked as e5dfad6) so that PR can go green while main's coverage is red on production_digests_go_through_the_helpers. It becomes a no-op there once this lands.


Generated by Claude Code

Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 5, 2026
main is red: #646 added inline sha1/sha256 calls that #865's
production_digests_go_through_the_helpers guard rejects. This ports
the fix from #878 so this PR's coverage job can go green. It becomes a
no-op once #878 lands.

Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 5, 2026
main has been red since #865 added a check that production code
computes digests through utils::digest, while #646's Gradle code
still hashes inline. Port #878's change so this PR's coverage and
test-release go green; it no-ops once #878 lands on main.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uQyhodCtdJGrKaD7AAV1n
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 5, 2026
utils::digest's production_digests_go_through_the_helpers fails on
main: three Gradle/JVM files compute digests inline. That makes
`coverage`, `test` and `test-release` red on every PR. #878 routes
them through utils::digest. This is the same change, ported so this
PR's CI is green. It becomes a no-op once #878 lands.

Claude-Session: https://claude.ai/code/session_01LS9AJhpVngXZxng8TRA2Kd
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 5, 2026
main is red on production_digests_go_through_the_helpers since the
Gradle squash-merge left inline digests in gradle_cache, jvm_jar and
the Maven sidecar. Port #878's change so this PR's CI can go green;
it no-ops once #878 lands on main.

Co-Authored-By: Claude <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 5, 2026
main's #865 added a test that fails when production code computes
digests inline; the Gradle cache, JVM jar and Maven sidecar code
landed with inline sha1/sha256 calls, so main's coverage and
test-release jobs fail production_digests_go_through_the_helpers.
Same change as #878, ported so this PR's CI runs green against the
current base; it no-ops once #878 lands.

Refs #831

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FMZyKmgYNAridSR5eqv999
@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 5, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Burn-down agent: labeled Ready for review at 659ac2c (659ac2c24e5c5904e743b4bc98ea4645da2ed6a1).

  • CI: 406/406 green on the head commit (6 skipped by matrix rule).
  • Bugbot: reviewed 659ac2c with no findings; no open review threads.
  • Mergeable against main (clean); approved by Tanmay Singla (@Tanmay182003) on this SHA.
  • Reviewer note: this fixes main's red production_digests_go_through_the_helpers; several open PRs carry a port of it, so landing it first unblocks them.

Generated by Claude Code

Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 5, 2026
`main` fails `utils::digest::tests::production_digests_go_through_the_
helpers` because #646 left inline sha1/sha256 calls in
`gradle_cache.rs`, `jvm_jar.rs` and `sidecars/maven.rs`, which turns
`test`, `test-release` and `coverage` red on every PR. This is #878's
change verbatim; it no-ops once #878 merges.

Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 5, 2026
main went red when Gradle code landed with inline sha1/sha256 calls that
utils::digest::tests::production_digests_go_through_the_helpers rejects.
Same change as #878; it no-ops once main carries it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NEpjVvY7X41jPuVuoiCLVz
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 5, 2026
Main is red since 1714299 (#865): its
production_digests_go_through_the_helpers guard flags the inline
digests that #646 added in gradle_cache.rs, jvm_jar.rs and
sidecars/maven.rs. This is the same change as #878 and becomes a
no-op once that lands.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VSXCFoPbraq7rNKJpXEP2n
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 5, 2026
main's production_digests_go_through_the_helpers guard is red because
the Gradle files hash inline. This carries #878's change so this PR's
CI can go green; it becomes a no-op once #878 lands.

Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 5, 2026
main fails socket-patch-core's lib guard test
production_digests_go_through_the_helpers because three Gradle files
still hash inline, which turns coverage, test and test-release red on
this PR. This is the same change as #878 and becomes a no-op once that
lands on main.

Co-Authored-By: Claude <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 5, 2026
utils::digest's production_digests_go_through_the_helpers fails on
main: three Gradle/JVM files compute digests inline. That makes
`coverage`, `test` and `test-release` red on every PR. #878 routes
them through utils::digest. This is the same change, ported so this
PR's CI is green. It becomes a no-op once #878 lands.

Claude-Session: https://claude.ai/code/session_01LS9AJhpVngXZxng8TRA2Kd
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 4d8cad2)
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 5, 2026
Ports #878 so the core lib tests pass here too: main is red on
utils::digest::tests::production_digests_go_through_the_helpers
because the Gradle files hash inline. This change is a no-op once #878
lands on main.

(cherry picked from commit 659ac2c)

Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 6, 2026
Main is red: the utils::digest guard test lists the Gradle files
that hash inline. This ports #878's change so this PR's CI can go
green; it becomes a no-op once #878 lands.

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[agent] Ported into #911 (commit 34051e4) so that PR's CI can go green while main's digest guard is red. It becomes a no-op once this lands.


Generated by Claude Code

Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 6, 2026
main's test suite is red: the Gradle cache, jar and Maven sidecar code
from #646 hashes inline, which the digest guard test from #865 forbids,
so coverage and the macOS/Windows test jobs fail on every PR. This is
the same change as #878, ported so this PR can go green; it no-ops
once #878 lands.

Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 6, 2026
main's production_digests_go_through_the_helpers guard is red
because the Gradle files hash inline. This carries #878's change so
this PR's CI can go green; it is a no-op once #878 lands.

Assisted-by: Claude Code:claude-opus-5-5

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants