Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 15 additions & 4 deletions crates/socket-patch-cli/src/commands/vex_consumed.rs
Original file line number Diff line number Diff line change
Expand Up @@ -715,8 +715,11 @@ mod tests {
None,
)
.await;
assert_eq!(installed_again, installed);
let (paths, calls) = tracked_npm_hosted(&common, &installed_again).await;
// Since #605 the name-keyed resolver probes bundled trees itself, so
// it already returns the aliases and the nested store's peers. Feed
// the earlier, alias-free set to keep exercising alias expansion;
// the resolver's own set is checked against the same result below.
let (paths, calls) = tracked_npm_hosted(&common, &installed).await;
assert_eq!(calls.len(), 1);
let mut inputs = calls[0].clone();
inputs.sort();
Expand All @@ -738,6 +741,9 @@ mod tests {
.len(),
paths.len()
);
let (mut resolved, _) = tracked_npm_hosted(&common, &installed_again).await;
resolved.sort();
assert_eq!(resolved, expected, "the resolver's own copy set");
}

#[cfg(unix)]
Expand Down Expand Up @@ -768,14 +774,19 @@ mod tests {
None,
)
.await;
assert!(installed.is_empty(), "{installed:?}");
let (mut paths, calls) = tracked_npm_hosted(&common, &installed).await;
// Since #605 the name-keyed resolver reaches the alias and its
// sibling peers on its own. An alias-only set (what an alias-blind
// resolver returns) must still expand to the same copies.
let (mut paths, calls) = tracked_npm_hosted(&common, &HashMap::new()).await;
assert_eq!(calls, vec![vec![alias.clone()]]);
let mut expected = peers;
expected.push(alias);
paths.sort();
expected.sort();
assert_eq!(paths, expected);
let (mut resolved, _) = tracked_npm_hosted(&common, &installed).await;
resolved.sort();
assert_eq!(resolved, expected, "the resolver's own copy set");
}

#[cfg(unix)]
Expand Down
19 changes: 9 additions & 10 deletions crates/socket-patch-cli/tests/cli/api_client_errors_e2e.rs
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,6 @@
//! failure into a fake success fails loudly.

use std::path::{Path, PathBuf};
use std::process::Command;

use wiremock::matchers::{method, path};
use wiremock::{Mock, MockServer, ResponseTemplate};
Expand Down Expand Up @@ -116,7 +115,7 @@ async fn get_uuid_with_401_falls_back_to_proxy() {
.await;

let tmp = tempfile::tempdir().unwrap();
let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args([
"get",
UUID,
Expand Down Expand Up @@ -199,7 +198,7 @@ async fn get_uuid_with_500_reports_error() {
.await;

let tmp = tempfile::tempdir().unwrap();
let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args([
"get",
UUID,
Expand Down Expand Up @@ -239,7 +238,7 @@ async fn get_uuid_with_malformed_json_reports_parse_error() {
.await;

let tmp = tempfile::tempdir().unwrap();
let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args([
"get",
UUID,
Expand Down Expand Up @@ -281,7 +280,7 @@ async fn scan_with_400_bad_request_reports_failure() {
write_root(tmp.path());
write_npm_package(tmp.path(), "foo");

let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args([
"scan",
"--json",
Expand Down Expand Up @@ -323,7 +322,7 @@ async fn scan_with_400_bad_request_reports_failure() {
async fn get_with_unreachable_api_url_reports_error() {
let tmp = tempfile::tempdir().unwrap();
// Port 1 is reserved and reliably refuses connections.
let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args([
"get",
UUID,
Expand Down Expand Up @@ -354,7 +353,7 @@ async fn scan_with_unreachable_api_url_reports_failure() {
write_root(tmp.path());
write_npm_package(tmp.path(), "bar");

let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args([
"scan",
"--json",
Expand Down Expand Up @@ -397,7 +396,7 @@ async fn get_by_cve_with_500_reports_error() {
.await;

let tmp = tempfile::tempdir().unwrap();
let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args([
"get",
cve,
Expand Down Expand Up @@ -434,7 +433,7 @@ async fn get_by_ghsa_with_404_reports_not_found() {
.await;

let tmp = tempfile::tempdir().unwrap();
let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args([
"get",
ghsa,
Expand Down Expand Up @@ -510,7 +509,7 @@ async fn repair_with_blob_404_marks_failure_in_summary() {
)
.unwrap();

let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args([
"repair",
"--json",
Expand Down
41 changes: 10 additions & 31 deletions crates/socket-patch-cli/tests/cli/cli_dry_run_paths_e2e.rs
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,6 @@
//! dry-run flag-propagation branches each command's `run` has.

use std::path::{Path, PathBuf};
use std::process::Command;

use sha2::{Digest, Sha256};

Expand Down Expand Up @@ -95,11 +94,9 @@ fn make_applicable_npm_patch(root: &Path) {
fn apply_dry_run_empty_manifest_emits_dry_run_envelope() {
let tmp = tempfile::tempdir().expect("tempdir");
make_socket_with_empty_manifest(tmp.path());
let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args(["apply", "--json", "--dry-run"])
.current_dir(tmp.path())
.env_remove("SOCKET_API_TOKEN")
.env_remove("SOCKET_CLI_API_TOKEN")
.output()
.expect("run apply");
let stdout = String::from_utf8_lossy(&out.stdout);
Expand Down Expand Up @@ -165,11 +162,9 @@ fn apply_dry_run_with_real_patch_verifies_without_mutating() {
);

// ---- DRY RUN ----
let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args(["apply", "--json", "--dry-run", "--offline"])
.current_dir(tmp.path())
.env_remove("SOCKET_API_TOKEN")
.env_remove("SOCKET_CLI_API_TOKEN")
.output()
.expect("run apply --dry-run");
let stdout = String::from_utf8_lossy(&out.stdout);
Expand Down Expand Up @@ -249,11 +244,9 @@ fn apply_dry_run_with_real_patch_verifies_without_mutating() {
// This guarantees the dry-run assertions above are non-vacuous: the
// patch really is applicable, so "nothing changed" under --dry-run is a
// meaningful result rather than an artifact of an inapplicable fixture.
let out2 = Command::new(binary())
let out2 = crate::common::hermetic_command(&binary())
.args(["apply", "--json", "--offline"])
.current_dir(tmp.path())
.env_remove("SOCKET_API_TOKEN")
.env_remove("SOCKET_CLI_API_TOKEN")
.output()
.expect("run apply (real)");
let stdout2 = String::from_utf8_lossy(&out2.stdout);
Expand Down Expand Up @@ -335,11 +328,9 @@ fn apply_dry_run_human_count_excludes_vendored() {
// Prove the fixture is non-vacuous first: in JSON mode the vendored
// entry must classify as skipped/vendored (if the vendor ledger were
// unreadable it would fail open and this test would assert nothing).
let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args(["apply", "--json", "--dry-run", "--offline"])
.current_dir(tmp.path())
.env_remove("SOCKET_API_TOKEN")
.env_remove("SOCKET_CLI_API_TOKEN")
.output()
.expect("run apply --json --dry-run");
let stdout = String::from_utf8_lossy(&out.stdout);
Expand All @@ -366,11 +357,9 @@ fn apply_dry_run_human_count_excludes_vendored() {

// The human summary must agree with that classification: only the
// genuinely applicable package counts as patchable.
let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args(["apply", "--dry-run", "--offline"])
.current_dir(tmp.path())
.env_remove("SOCKET_API_TOKEN")
.env_remove("SOCKET_CLI_API_TOKEN")
.output()
.expect("run apply --dry-run");
assert_eq!(out.status.code(), Some(0));
Expand All @@ -387,11 +376,9 @@ fn apply_dry_run_human_count_excludes_vendored() {
fn repair_dry_run_offline_emits_dry_run_envelope() {
let tmp = tempfile::tempdir().expect("tempdir");
make_socket_with_empty_manifest(tmp.path());
let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args(["repair", "--json", "--dry-run", "--offline"])
.current_dir(tmp.path())
.env_remove("SOCKET_API_TOKEN")
.env_remove("SOCKET_CLI_API_TOKEN")
.output()
.expect("run repair");
let stdout = String::from_utf8_lossy(&out.stdout);
Expand All @@ -415,11 +402,9 @@ fn repair_dry_run_offline_emits_dry_run_envelope() {
fn rollback_with_empty_manifest_emits_envelope() {
let tmp = tempfile::tempdir().expect("tempdir");
make_socket_with_empty_manifest(tmp.path());
let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args(["rollback", "--json", "--offline"])
.current_dir(tmp.path())
.env_remove("SOCKET_API_TOKEN")
.env_remove("SOCKET_CLI_API_TOKEN")
.output()
.expect("run rollback");
let stdout = String::from_utf8_lossy(&out.stdout);
Expand Down Expand Up @@ -449,7 +434,7 @@ fn rollback_with_empty_manifest_emits_envelope() {
fn remove_with_no_socket_dir_emits_manifest_not_found() {
let tmp = tempfile::tempdir().expect("tempdir");
// NO .socket/ directory at all.
let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args([
"remove",
"11111111-1111-4111-8111-111111111111",
Expand All @@ -458,8 +443,6 @@ fn remove_with_no_socket_dir_emits_manifest_not_found() {
"--skip-rollback",
])
.current_dir(tmp.path())
.env_remove("SOCKET_API_TOKEN")
.env_remove("SOCKET_CLI_API_TOKEN")
.output()
.expect("run remove");
let stdout = String::from_utf8_lossy(&out.stdout);
Expand All @@ -483,11 +466,9 @@ fn remove_with_no_socket_dir_emits_manifest_not_found() {
fn list_with_empty_manifest_emits_empty_envelope() {
let tmp = tempfile::tempdir().expect("tempdir");
make_socket_with_empty_manifest(tmp.path());
let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args(["list", "--json"])
.current_dir(tmp.path())
.env_remove("SOCKET_API_TOKEN")
.env_remove("SOCKET_CLI_API_TOKEN")
.output()
.expect("run list");
let stdout = String::from_utf8_lossy(&out.stdout);
Expand All @@ -511,11 +492,9 @@ fn list_with_empty_manifest_emits_empty_envelope() {
#[test]
fn apply_silent_no_manifest_produces_no_output() {
let tmp = tempfile::tempdir().expect("tempdir");
let out = Command::new(binary())
let out = crate::common::hermetic_command(&binary())
.args(["apply", "--silent"])
.current_dir(tmp.path())
.env_remove("SOCKET_API_TOKEN")
.env_remove("SOCKET_CLI_API_TOKEN")
.output()
.expect("run apply");
assert_eq!(out.status.code(), Some(0));
Expand Down
5 changes: 4 additions & 1 deletion crates/socket-patch-cli/tests/cli_parse_remove.rs
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,9 @@ use socket_patch_cli::commands::remove::{run, RemoveArgs};
use socket_patch_cli::{Cli, Commands};
use std::path::PathBuf;

#[path = "common/hermetic.rs"]
mod hermetic;

fn parse_remove(extra: &[&str]) -> RemoveArgs {
let mut argv = vec!["socket-patch", "remove"];
argv.extend_from_slice(extra);
Expand Down Expand Up @@ -335,7 +338,7 @@ fn record_json(uuid: &str) -> String {
/// Run the compiled `socket-patch remove` binary against `cwd`, fully offline
/// and with telemetry disabled so the test never touches the network.
fn run_remove_binary(cwd: &std::path::Path, extra: &[&str]) -> std::process::Output {
std::process::Command::new(env!("CARGO_BIN_EXE_socket-patch"))
hermetic::binary_command()
.arg("remove")
.arg("--cwd")
.arg(cwd)
Expand Down
Loading
Loading