deps: batch dependabot roll-up (v0.5.892) - #737
Merged
Conversation
proggeramlug
force-pushed
the
deps/batch-roll-up-2026-05-13
branch
from
May 13, 2026 05:15
ecafaa0 to
961e444
Compare
Bundles seven green dependabot bumps into a single commit instead of seven round-trips through the PR queue. Cargo crates: - scraper 0.19.1 → 0.27.0 (#731) — perry-ext-cheerio, perry-stdlib - gstreamer 0.23.7 → 0.25.2 (#730) — perry-ui-gtk4 - bcrypt 0.15 → 0.17 (#728) — perry-stdlib (aligns with perry-ext-bcrypt which already pinned 0.17, so the workspace now resolves a single bcrypt version) GitHub Actions: - actions/download-artifact v4 → v8 (#724) - actions/setup-node v4 → v6 (#725) - actions/cache v4 → v5 (#726) (test.yml line 110's comment referencing v4 is left as-is — it is documenting historical state, not configuring a step.) NPM test fixture: - drizzle-orm ^0.36.0 → ^0.45.2 (#723) in tests/release/packages/drizzle-sqlite/ PR #723 had a stale security-audit FAILURE from a transient advisory-db hit on May 12; main's subsequent run against the unchanged Cargo.lock passed on May 13. The PR only touches npm test fixtures so the audit result was unrelated to its diff. Skipped (real breakage, not safe): - toml 0.8.23 → 1.1.2+spec-1.1.0 (#727) — major version breaks well_known_bindings.toml parsing; 7 cargo tests + 31 compile-smoke failures. - deno_core 0.311.0 → 0.400.0 (#729) — 89-patch jump, parity + compile-smoke failures from API-breaking changes. Rebased onto main at e8c4a95 (HarmonyOS Chart + TreeView shipped as v0.5.893 after #734 shipped as v0.5.892); this commit moves the batch roll-up to v0.5.894 to avoid the patch-version collision.
proggeramlug
force-pushed
the
deps/batch-roll-up-2026-05-13
branch
from
May 13, 2026 05:21
961e444 to
25159ad
Compare
proggeramlug
added a commit
that referenced
this pull request
May 13, 2026
…g (v0.5.895) Two-site override (resolve.rs::resolve_import + collect_modules.rs) so a package listed in `perry.compilePackages` is compiled from its node_modules source instead of routed to the built-in Rust FFI binding. Unblocks users of packages whose native binding is incomplete (e.g. `rate-limiter-flexible`, where `perry-ext-ratelimit` only wires `consume` through codegen and the codegen-declared `js_ratelimit_create(I64)` doesn't match the real two-arg `js_ratelimit_new(points, duration_secs)` impl). Default behavior unchanged: stock projects without `compilePackages` go through the exact same path. Opt-in and package-scoped. Refs #665. Renumbered from v0.5.892 → v0.5.895 (parallel PRs #734/#736/#737 landed on main). See CHANGELOG.md for full root-cause notes.
4 tasks
proggeramlug
added a commit
that referenced
this pull request
May 13, 2026
…g (v0.5.895) Two-site override (resolve.rs::resolve_import + collect_modules.rs) so a package listed in `perry.compilePackages` is compiled from its node_modules source instead of routed to the built-in Rust FFI binding. Unblocks users of packages whose native binding is incomplete (e.g. `rate-limiter-flexible`, where `perry-ext-ratelimit` only wires `consume` through codegen and the codegen-declared `js_ratelimit_create(I64)` doesn't match the real two-arg `js_ratelimit_new(points, duration_secs)` impl). Default behavior unchanged: stock projects without `compilePackages` go through the exact same path. Opt-in and package-scoped. Refs #665. Renumbered from v0.5.892 → v0.5.895 (parallel PRs #734/#736/#737 landed on main). See CHANGELOG.md for full root-cause notes.
proggeramlug
added a commit
that referenced
this pull request
May 13, 2026
…er-flexible work end-to-end (#735) * feat(resolve): #665 — compilePackages overrides NATIVE_MODULES routing (v0.5.895) Two-site override (resolve.rs::resolve_import + collect_modules.rs) so a package listed in `perry.compilePackages` is compiled from its node_modules source instead of routed to the built-in Rust FFI binding. Unblocks users of packages whose native binding is incomplete (e.g. `rate-limiter-flexible`, where `perry-ext-ratelimit` only wires `consume` through codegen and the codegen-declared `js_ratelimit_create(I64)` doesn't match the real two-arg `js_ratelimit_new(points, duration_secs)` impl). Default behavior unchanged: stock projects without `compilePackages` go through the exact same path. Opt-in and package-scoped. Refs #665. Renumbered from v0.5.892 → v0.5.895 (parallel PRs #734/#736/#737 landed on main). See CHANGELOG.md for full root-cause notes. * fix(codegen): #665 — default-import collision no longer mints phantom cross-class method symbols (v0.5.896) When two different classes are both default-imported in the same file, the `class_ids` / `imported_class_prefix` / `imported_class_source_name` side maps in `compile_module` overwrote each other (last-writer-wins) while `class_table` kept the first stub (first-writer-wins). The mismatch produced method symbols mangled with FIRST stub's method list + LAST writer's class name + LAST writer's source prefix — names the linker can't resolve since Phase F only declares each ic's REAL methods. Flip the three side-map `.insert()` calls to `.entry().or_insert()` so all four maps agree on first-writer-wins. Fixes the `@perry_method_..._RateLimiterRes_js__RateLimiterRes__delete` / `__get` / `__set` / `__block` undefined-value errors that surfaced in rate-limiter-flexible's 5 leaf files once v0.5.895's routing opt-in let them reach codegen. Refs #665. See CHANGELOG.md for full root-cause walkthrough. * fix(codegen,runtime): #665 — setTimeout(fn, delay, ...args) forwards trailing args (v0.5.897) Existing `"setTimeout" if args.len() == 2` arm only handled the 2-arg shape; 3+ arg call sites (e.g. `setTimeout(resolve, delay, res)` inside Promise executors per ECMA-262 §27.5.4.1) fell through to the generic ExternFuncRef fallthrough and emitted `call @settimeout(...)` against a symbol nothing in stdlib defines. Discovering call site: `RateLimiterMemory.consume()`'s Promise executor in rate-limiter-flexible. Adds: - `CallbackTimer::args: Vec<f64>` (empty for 2-arg shape — back-compat). - `js_set_timeout_callback_args(callback, delay_ms, args_ptr, n_args)` runtime entry that copies the buffer in. - `js_callback_timer_tick` dispatch via `match args.len()` to `js_closure_call0..js_closure_call9`, clamping at 9 trailing args. - Codegen `"setTimeout" if args.len() >= 3` arm: alloca a stack buffer of doubles for the trailing args, GEP for the base, call the new runtime entry. Refs #665. See CHANGELOG.md for full root-cause + scope notes. * fix(hir): #665 — compilePackages-opted-in packages skip native-instance lowering (v0.5.898) HIR's `is_native_module` only consulted the NATIVE_MODULES manifest, so `rate-limiter-flexible` was lowered as a native import regardless of the user's `compilePackages` opt-in. That cascaded: register_native_module(local, "rate-limiter-flexible", ...) → new RateLimiterMemory(...) triggers register_native_instance(limiter, "rate-limiter-flexible", "RateLimiterMemory") → limiter.consume in expr_member::lower_member emits NativeMethodCall { module, object: Some(limiter), method: "consume", args: [] } → codegen routes to js_native_call_method → no FFI entry → 0.0 So `typeof limiter.consume === "number"`. For genuine native bindings (req.method on http.IncomingMessage) this zero-arg-getter lowering is correct; for compile-package-overridden classes it's wrong because `consume` is a real method, not a getter. Fix: add a thread-local `COMPILE_PACKAGES_OVERRIDE: HashSet<String>` in perry-hir, set by the compiler driver via `set_compile_packages_override(ctx.compile_packages.clone())` before each `lower_module_full` invocation and cleared after. `is_native_module` parses the package name (supports `node:` prefix + `@scope/pkg` scoped form) and returns false when the package is in the override even if it appears in NATIVE_MODULES. Validation: rate-limiter-flexible probe now reports `typeof limiter.consume: function` (was "number"). Workspace tests green. Refs #665. See CHANGELOG.md for full root-cause walkthrough.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Folds 7 green-CI dependabot PRs into a single commit so I don't burn 7× the CI minutes on the same lockfile bumps.
Cargo crates
scraper0.19.1 → 0.27.0 — closes deps(deps): bump scraper from 0.19.1 to 0.27.0 #731gstreamer0.23.7 → 0.25.2 — closes deps(deps): bump gstreamer from 0.23.7 to 0.25.2 #730bcrypt0.15 → 0.17 — closes deps(deps): bump bcrypt from 0.15.1 to 0.17.1 #728 (also aligns perry-stdlib'sbundled-bcryptfeature with perry-ext-bcrypt which was already at 0.17, so the workspace resolves one bcrypt instead of two)GitHub Actions
actions/download-artifactv4 → v8 — closes ci(deps): bump actions/download-artifact from 4 to 8 #724actions/setup-nodev4 → v6 — closes ci(deps): bump actions/setup-node from 4 to 6 #725actions/cachev4 → v5 — closes ci(deps): bump actions/cache from 4 to 5 #726actions/cache@v4reference in.github/workflows/test.yml:110is left untouched — it's a historical-context comment, not auses:directive)NPM test fixture
drizzle-orm^0.36.0 → ^0.45.2 intests/release/packages/drizzle-sqlite/— closes ci(deps): bump drizzle-orm from 0.36.4 to 0.45.2 in /tests/release/packages/drizzle-sqlite #723Not bumped (real breakage, deferred)
well_known_bindings.tomlparsing (TOML parse error at line 1, column 1); 7 cargo-test failures + 31 compile-smoke regressions. Needs a migration commit.Test plan
cargo build --release -p perry-runtime -p perry-stdlib -p perryclean (6m03s, warnings only)cargo test --release --workspace --exclude perry-ui-{ios,tvos,watchos,visionos,android,windows,gtk4}0 failures