Skip to content

fix(core): an SE-0292 registry pin is queried against SwiftURL with an identity that is not a URL #117

Description

@justin13888

Found during review of #97 (feat/85-swift-package-resolved). Disclosed there but not repaired, because the fix is a behaviour change to pin classification that belongs with registry support rather than inside a review repair.

What happens

crates/dependable-core/src/lockfiles/swift_package_resolved.rs, pin_item (~line 311).

A Package.resolved pin of "kind": "registry" — the SE-0292 package-registry kind — carries no location: a registry package is addressed by its scoped identity (mona.LinkedList), not by a repository URL.

pin_item treats only fileSystem and localSourceControl (or a location that looks like a local path) as local. A registry pin is therefore neither local nor location-bearing, so the name falls through to:

pin.location
    .as_deref()
    .map(swift_package_name)
    .filter(|name| !name.is_empty())
    .or_else(|| pin.identity.clone())?

which yields the bare registry identity, e.g. mona.linkedlist. It has a version, so it becomes PackageSource::Inherited — a checkable dependency.

That name is then queried against OSV's SwiftURL ecosystem, which is keyed by repository URL with no scheme and no .git (github.com/apple/swift-nio). A registry identity is not a repository URL and can never match that key.

Why it matters

The query cannot match, so the row reports clean, and nothing anywhere says the query was meaningless. This is the exact failure mode the Swift work exists to prevent: an answer that looks like "no advisories" when it is really "we asked a question that cannot be answered".

It is narrower than the general Swift caveat. Undetermined already says currency was never established, but the OSV verdict is the one verdict a Swift run does claim to give — and for a registry pin that claim is unfounded rather than merely absent.

Why it is Low today

Reachability, not correctness. No public SE-0292 registry has meaningful adoption, so "kind": "registry" is vanishingly rare in a real Package.resolved. That is a statement about likelihood, and it will stop being true if a registry lands.

Direction

Either:

  • skip a kind == "registry" pin outright, or
  • give it a non-checkable source, so it is visible in the listing but never queried against SwiftURL with an identifier that is not a URL.

Either way the row must not report clean off the back of a query that could not match.

Close this alongside whatever ships real registry support — at which point the pin gets a source that can actually be checked.

Reproduction

A Package.resolved containing:

{
  "pins" : [
    {
      "identity" : "mona.linkedlist",
      "kind" : "registry",
      "state" : { "version" : "0.1.2" }
    }
  ],
  "version" : 2
}

The pin is read as a checkable dependency named mona.linkedlist and scanned as if it were a repository path.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions