Repository navigation
Fail closed on unreadable scala-cli Bloop evidence, as sbt does (#1270) - #1358
Mikola Lysenko (mikolalysenko) merged 3 commits into
Conversation
Assisted-by: Claude Code:claude-opus-5-5
A truncated, oversized or non-Bloop project file under .scala-build/.bloop was skipped, so the vendored scala-cli gate judged the remaining projects alone. When the skipped file was the newest project's -test twin, a test.dep at another version went unseen and vendoring went ahead while the test classpath kept the old version. Such a file now means no evidence at all, the policy the sbt evidence reader already follows, so the gate skips with vendor_scala_cli_resolution_missing and asks for a fresh compile. Symlinks, FIFOs and other workspaces' projects are still ignored. Fixes #1270 Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
Assisted-by: Claude Code:claude-opus-5-5
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit d762714. Configure here.
|
Ready for review at
Labeled Generated by Claude Code |
|
[agent] Generated by Claude Code |
LLM Description written by Claude Code:claude-opus-5-5
Fixes #1270
Summary
crawlers::scala_evidence::discovernow fails closed when a Bloop project file can't be read whole. That covers a file overMAX_FILE_BYTES, a read error, and a truncated or non-Bloop record. It now uses the policy thatformats::sbt::evidence::resolutionandcrawlers::sbt_evidencealready use. The skip-and-continue branches are deleted.Why
register/10-audit-ecosystems.md), living document Part 5 (vendored JVM gates).-testtwin,coursier_gate::gatejudged the main project alone, so a//> using test.depat another version passed asok.What changed
discover: an oversized, unreadable or non-Bloop.jsonreturnsNone. Non-regular entries (symlinks, FIFOs), non-.jsonnames and other workspaces' projects are still ignored.MAX_FILE_BYTESdocs now state the fail-closed rule.Lines
Production +23/−6 (one file, about half of it doc comments). Tests +87/−1.
Behavior
.scala-build/.bloopnow makes the scala-cli gate skip withvendor_scala_cli_resolution_missing, where it used to pass or judge partial evidence. Already-vendored GAVs still re-plan, because the gate'svendoredpath doesn't need evidence.Test evidence
crawlers::scala_evidence::tests::an_unreadable_project_file_hides_no_conflictcovers the issue's table. With both files intact the gate reportsvendor_scala_cli_version_conflict. A truncated, foreign or oversized-testtwin, or a truncated newest main project, makesdiscoverreturnNoneand the gate reportvendor_scala_cli_resolution_missing.discover:Some(ScalaEvidence { files: ["…/sc_p.json"] … })instead ofNone.caps_and_special_filesnow also asserts that an oversized file next to a readable project givesNone, and that removing it brings the evidence back.cargo clippy --workspace --all-features -- -D warnings: clean.cargo test -p socket-patch-core --lib: 6092 passed. The 4 failures are the known root-sandbox ones that also fail on main (relax_loop_must_not_traverse_symlinked_root,an_unremovable_hidden_lock_keeps_every_store_entry,wire_write_failure_maps_error_and_leaves_lock_untouched,wire_failure_rolls_back_already_written_files).cargo test -p socket-patch-cli --all-features --test e2e_scala_cli_vendor: 31 passed, 1 ignored.--test spawn_env_hygiene: 12 passed.Risk
Low. The change is one function, and it only adds refusals in a case where the result used to be partial evidence.
🤖 Generated with Claude Code
https://claude.ai/code/session_01YTFbfEEtE5pUm5pdEaFyMz
Note
Low Risk
Single-function policy tightening in evidence discovery only increases refusals when Bloop metadata is incomplete; no auth, wire format, or gate code contract changes.
Overview
Fixes #1270 by changing scala-cli Bloop evidence discovery to fail closed when any
.scala-build/.bloopproject JSON cannot be read whole—overMAX_FILE_BYTES, I/O failure, truncated content, or non-Bloop JSON—instead of skipping that file and returning partial resolution evidence.That matches the sbt evidence reader: an unreadable record might be the one that names a conflicting GAV (e.g. a
-testtwin withtest.depat another version), so the vendor gate must not judge main-only evidence. Unreadable cases now yield no evidence (discover→None, gate →vendor_scala_cli_resolution_missing) rather than incorrectly passing when the bad file hid a version conflict.Docs for the cap behavior are updated; tests cover oversized files beside valid projects and gate behavior for truncated/foreign/oversized
-testtwins and corrupt newest main projects.Reviewed by Cursor Bugbot for commit d762714. Configure here.
Generated by Claude Code