Repository navigation
Bench: cover Gradle and Hatch hosted modes - #925
Conversation
#646 gave Gradle builds a hosted mode: scan crawls Gradle's modules-2/files-2.1 cache, pins suffixed versions in gradle.lockfile and wires the build through an owned settings script and index under .socket/gradle/. None of that was benchmarked; the maven scenarios only reach the pom.xml + ~/.m2 path. The gradle fixture is a single-project Groovy build with dependency locking (1000 locked artifacts, 25 patched direct deps), its cache under the fixture's GRADLE_USER_HOME with jar and pom in separate sha1 dirs. The Maven-coordinate generator, pom writer and maven2 grant builder are shared with the maven fixture, whose bytes are unchanged. The grant's indexUrl is https because the Gradle planner refuses anything else; scan never fetches it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
bugbot run Generated by Claude Code |
main has failed socket-patch-core's lib tests since Gradle support (#646) and the digest helpers (#865) both landed. The guard test production_digests_go_through_the_helpers flags three files #646 added that still hash inline: crawlers/gradle_cache.rs, patch/jvm_jar.rs and patch/sidecars/maven.rs. That breaks test, test-release and coverage on every open PR. Each inline sha1/sha256 call now goes through sha1_hex_of or sha256_hex_of, which compute the same lowercase hex. Behaviour is unchanged. Assisted-by: Claude Code:claude-opus-5-5 (cherry picked from commit 659ac2c)
|
[agent] Bench:
The fix is open as #878. I cherry-picked its single commit here ( Generated by Claude Code |
|
bugbot run Generated by Claude Code |
|
Burn-down agent: labeled Ready for review.
Generated by Claude Code |
Hatch hosted mode (#680, #743) rewrites pyproject.toml and hatch.toml in place, with no lockfile, through utils::hatch::plan. No scenario exercised that rewriter: hatch.toml is a HOSTED pypi input, and a hatch project with no lock fell through every existing pypi fixture. The fixture is a lockless hatchling app. Direct deps go in [project], and a hatch.toml default env (in-project .venv) pins every patched transitive, since hosted Hatch only redirects deps a Hatch table declares. A scan rewrites both files and adds [tool.hatch.metadata] allow-direct-references. It is sized at 1000 packages / 25 patched so a scan takes about 75-85 ms. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
bugbot run Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 5b9ae8e. Configure here.
|
[agent] Ready for review at
Generated by Claude Code |
What main changed. Two hosted rewriters landed without bench coverage.
Gradle: #646 (
0685ba8c) added full Gradle support, including hosted mode.scannow crawls Gradle'smodules-2/files-2.1cache underGRADLE_USER_HOMEand pins the suffixed versions ingradle.lockfile. It wires the build through an owned settings script and index under.socket/gradle/. The suite had no Gradle scenario:maven/*only covers thepom.xml+~/.m2path.Hatch: #680/#743 (
0475695f) added hosted Hatch. With a Hatch project (hatch.toml,[tool.hatch]or ahatchling.buildbackend) and no lockfile,scanrewrites each declared dep in place throughutils::hatch::plan: it turnspyproject.toml[project]deps andhatch.toml[envs.*]deps intoname @ <url>#sha256=…and enablesallow-direct-references.hatch.tomlis a HOSTED pypi input informats/registry.rs, but no fixture reached this path.Suite changes
hatch/hostedandhatch/rescan(commit5b9ae8ea, 2026-10-07). The project is a lockless hatchling app with 1000 dists and 25 patched. Direct deps go in[project]. Ahatch.tomldefault env (in-project.venv) pins every patched dist, plus every 10th other one, so the planner has to skip non-matching specs. Hosted Hatch only redirects deps a Hatch table declares (a transitive-only dep getsredirect_hatch_unsupported), so these pins are what a real project patching its transitives writes. The scenarios expecthatch.tomlandpyproject.tomlto be rewritten, and the only allowed warning is the sharedredirect_pypi_stale_install.gradle/hostedandgradle/rescan. The project is a single-project Groovy-DSL build withdependencyLocking: 1000 locked artifacts, 25 of them patched direct deps. Its cache lives under the fixture'sGRADLE_USER_HOME, with jar and pom in separate sha1 hash dirs. The scenarios expect these rewrites:.socket/gradle/{.gitattributes,hosted-index.tsv,socket-patch.hosted.settings.gradle},gradle.lockfileandsettings.gradle. The only allowed warning isredirect_gradle_detached_configs_unguarded, which the planner always emits.indexUrlishttps://patch.socket.dev/..., not the mock. The Gradle planner refuses non-https repositories (redirect_gradle_override_invalid), and a scan never fetches the index. The artifact URL still points at the mock.mavenandgradlenow share the Maven-coordinate generator, the pom writer and the maven2 grant builder. Themavenfixture bytes are unchanged: I builtmaven/hostedwith the old and new bench binaries anddiff -rshowed them identical.gradleandGRADLE_USER_HOME.Validation, Gradle (all runs against the main CLI
9c43dfc9, on a 4 vCPU Xeon @ 2.10GHz)cargo fmt -p socket-patch-bench,cargo clippy -p socket-patch-bench --all-features --all-targets -- -D warningsandcargo test -p socket-patch-bench(29 passed) are all clean.run -f '^gradle/' --runs 3: gradle/hosted 170.5 ms (0.17 ms/pkg), gradle/rescan 259.2 ms. Both validate with 53 requests each.compare -f '^gradle/' -f '^maven/'(head binary vs a copy of itself): no regressions. gradle/hosted -1.1%, gradle/rescan +4.5%, maven/hosted -1.6%, maven/rescan +1.7%.strace -f -e trace=execveon theserve gradle/hostedcommand: the CLI spawns nothing; the only execves are the shell,envandsocket-patchitself. The rewrittengradle.lockfilecarries<v>-socket.<uuid8>pins, andsettings.gradlegains theapply from:line.Validation, Hatch (main CLI
9c43dfc9, 4 vCPU Xeon @ 2.80GHz, 2026-10-07)cargo fmt -p socket-patch-bench,cargo clippy -p socket-patch-bench --all-features --all-targets -- -D warningsandcargo test -p socket-patch-bench(29 passed) are all clean.run -f '^hatch/' --runs 5: hatch/hosted 86.1 ms (0.086 ms/pkg), hatch/rescan 77.0 ms. Both validate with 53 requests and 25 redirected. At 400/12 a scan took about 50 ms, under the suite's ~70 ms floor, so the size was raised to 1000/25.compare -f '^hatch/': no regressions. hatch/hosted -2.1%, hatch/rescan +2.5%.strace -f -e trace=execveon theserve hatch/hostedcommand: the only execve issocket-patchitself. The rewrittenhatch.tomlholdsname @ http://…/…whl#sha256=…pins, andpyproject.tomlgains[tool.hatch.metadata] allow-direct-references = true.Time budget:
comparegrows by about 2 × 0.4 s per pair. A fullcomparetook about 13 min on this runner both before and after, so the change is within noise. Hatch adds about 2 × 0.16 s per pair, roughly 6 s per fullcompare. Nothing was removed.🤖 Generated with Claude Code
https://claude.ai/code/session_019rfKYrfN4H9XDnDS8MYaYJ
Note
Low Risk
Changes are benchmark fixtures, docs, and digest helper consolidation with no intended production behavior change.
Overview
Adds socket-patch-bench coverage for hosted Hatch and Gradle scan paths, which previously had no benchmark scenarios.
Hatch gets a lockless hatchling fixture (
hatch.tomlenv pins +pyproject.toml) withhosted/rescanexpectations on rewriting both files. Gradle gets a lockedgradle.lockfilebuild with a syntheticGRADLE_USER_HOMEcache, expecting.socket/gradle/hosted wiring plussettings.gradleand lockfile updates; patch grants use anhttps://registry index URL because Gradle rejects non-HTTPS repos.Maven fixture generation is refactored to share JVM coordinate universe, POM, and maven2 patch builders with Gradle; Maven fixture bytes are intended to stay identical. The bench README documents
hatch,gradle, andGRADLE_USER_HOMEisolation.In socket-patch-core, Gradle cache, JVM jar patching, and Maven sidecar checksum logic now call shared
utils::digesthelpers instead of inliningsha1/sha2hashing (refactor only).Reviewed by Cursor Bugbot for commit 5b9ae8e. Configure here.
Generated by Claude Code