Fix Bundler global config being ignored (#577) - #621
Conversation
Assisted-by: Claude Code:claude-opus-5-5
`bundle config set --global` writes cache_path, gemfile and path to ~/.bundle/config (or $BUNDLE_USER_CONFIG, $BUNDLE_USER_HOME/config, $BUNDLE_CONFIG), and Bundler honours that file below the local config and the environment. socket-patch never read it, so with a global setting: - hosted scan gave no stale-install warning for the archive Bundler installs from, and its VEX attested the unpatched gem; - hosted scan rewired Gemfile while Bundler loaded another manifest, instead of refusing with redirect_gem_bundle_gemfile_unsupported; - agent apply patched a gem copy Bundler never loads. Resolve the global file the way Bundler does and consult it as the lowest config tier for all three settings, honouring BUNDLE_IGNORE_CONFIG and Bundler's rule that a local or env path setting shadows the global one. Fixes #577 Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
|
[agent] I don't think this PR caused it:
No fix exists to port. I'll re-run the failed job once the CI run finishes (GitHub refuses a re-run while the run is still going). If it fails again I'll treat it as a real failure and investigate. Generated by Claude Code |
Bundler's Settings#path stops at the first tier that sets path or path.system. An env BUNDLE_PATH__SYSTEM (any value, even "false" or empty) therefore shadows a global `bundle config set --global path`, but agent-mode store discovery still probed the global path and treated a store Bundler never loads as a primary apply target. An empty env BUNDLE_PATH likewise stops Bundler at the env tier. Drop the global file from the install-root probe whenever BUNDLE_PATH__SYSTEM is set, and count an empty BUNDLE_PATH as shadowing. Both behaviours checked against Bundler 4.0.17. Assisted-by: Claude Code:claude-opus-5-5 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UK1QVxjDnEWft8VPvRUwVg
|
bugbot run Generated by Claude Code |
|
Ready for review at head
Generated by Claude Code |
|
Review updated for
All 137 focused tests passed (73 Ruby unit, 10 manifest, 26 crawler integration, 28 hosted stale-install). Six reviewer probes reproduce regressions against the original PR and pass on main; two production integration tests fail before the correction and pass afterward. Independent review checked 40 native controls across Bundler 4.0.17, 2.6.9 and 1.17.2, including the documented legacy 1.x limitation. The committed files match the tested snapshot, targeted core clippy and diff checks pass, and the patch merges cleanly with current main. Existing baseline formatting and the unrelated macOS warning are documented in the PR. No remaining actionable finding from this review. The Ready label has been restored after all checks completed on the corrected commit. |
|
BugBot review Please review the corrected commit |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 906f775. Configure here.
Resolves conflicts with #621 (Bundler global config tier). Discovery now takes both the global config file and the BUNDLE_IGNORE_CONFIG flag; with the flag set, the app config's path neither adds a root nor shadows the global one. Assisted-by: Claude Code:claude-opus-5-5
Final-head CI is complete: 350 successful checks, 6 skipped; no failures or pending checks. Bugbot passed, there are no unresolved review threads, and the PR is mergeable.
Fixes #577. Bundler's global
cache_path,gemfileandpathsettings were ignored, allowing stale global-cache archives to escape the warning/VEX guard, a manifest Bundler does not load to be rewritten, or the wrong installed gem copy to be selected.The crawler now consults the global config below local configuration and the environment. Its lookup follows
BUNDLE_CONFIG,BUNDLE_USER_CONFIG,BUNDLE_USER_HOME/config, then~/.bundle/config; regular-file reads avoid blocking on FIFOs, andBUNDLE_IGNORE_CONFIGsuppresses file configuration. A global gemfile selecting an unsupported manifest is refused with a remedy identifying the global setting. Global install paths are trusted as user configuration, while the existing containment guard for project configuration is preserved.The review corrections preserve higher-tier setting presence:
path,path.system, ordisable_shared_gemssetting stops the global path fallback, including empty strings and false flags. This prevents scanning or patching a global store that native Bundler does not select.BUNDLE_GEMFILEstill takes effect when the local setting is empty; nonempty local settings retain the existing same-root/cross-root behavior.The path-tier behavior matches native Bundler 2.6.9 and 4.0.17. Bundler 1.x's legacy global-path shortcut is not modeled; this limit is explicit in
CLI_CONTRACT.md. The older emptycache_pathbehavior is unchanged by these corrections.Validation on
906f775c:unused_variableswarning. The committed files match the tested sources, independent review is clear, and the commit merges cleanly with current main045d7ec7.906f775c.Note
Medium Risk
Changes gem install-path discovery, cache probing, and hosted manifest selection; incorrect precedence could miss stale installs or refuse/redirect the wrong manifest, but behavior is heavily tested and aligned with Bundler settings.
Overview
Fixes #577 by teaching Ruby/Bundler integration to honor global Bundler config (
bundle config set --global …) at the correct priority: local app config → environment → global file ($BUNDLE_CONFIG/$BUNDLE_USER_CONFIG/$BUNDLE_USER_HOME/config/~/.bundle/config) → defaults.BUNDLE_IGNORE_CONFIGstill skips file tiers.Discovery & hosted gem behavior now use global
BUNDLE_PATH(install roots),BUNDLE_CACHE_PATH(stale-install probe), andBUNDLE_GEMFILE(manifest selection). Higher tiers shadow global settings when present—including emptypath/gemfilevalues and envBUNDLE_PATH__SYSTEM/BUNDLE_DISABLE_SHARED_GEMS—so behavior matches Bundler 2.6/4.x and does not scan or rewrite against stores/manifests Bundler would not use. Unsupported global gemfiles get the same fail-closed refusal as local ones (redirect_gem_bundle_gemfile_unsupported).Contract docs (
CLI_CONTRACT.md,ecosystems.md) and e2e/unit tests cover global cache stale warnings (and VEX exclusion), global gemfile refusal, and empty-setting shadowing.Reviewed by Cursor Bugbot for commit 906f775. Configure here.