Generate checksums for vendored git archives - #289
Draft
snoopuppy582 wants to merge 1 commit into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
--gitcreates a.cratearchive locally, but the corresponding package has no checksum inCargo.lock. The generated index entry therefore uses an emptycksum, leaving Cargo without an archive checksum to verify.This change computes SHA-256 after each git archive is created and writes that value to the index entry. Registry packages continue to use their resolved lockfile checksums, so existing registry downloads do not receive an additional hashing pass.
This is the companion change for rust-lang/cargo#10939 and rust-lang/cargo#17228. It lets Cargo keep git entries checksumless in
Cargo.lockwhile verifying the replacement archive against the local-registry index.Tests
The existing
git_dependencytest now checks that the index checksum matches the generated.cratefile exactly.cargo test --all --lockedcargo clippy --bin cargo-local-registry -- -D warnings