pub struct CargoRegistry { /* private fields */ }Expand description
Router in front of crates.io and every resolved alternate/private registry a workspace’s
.cargo/config.toml hierarchy names.
The value behind CargoEcosystem::registry (formerly a bare
CratesIoRegistry). deps_core::Registry::get_versions/get_latest_matching/search
(the source-blind trait methods) always mean crates.io, matching pre-1a behavior exactly
(spec NFR-008); only the source-aware get_versions_from/get_latest_matching_from
entry points route to an alternate index, and only for a
DependencySource::AlternateRegistry source.
§Examples
use deps_cargo::CargoRegistry;
use deps_core::HttpCache;
use std::sync::Arc;
let cache = Arc::new(HttpCache::new());
let registry = CargoRegistry::new(cache);Implementations§
Source§impl CargoRegistry
impl CargoRegistry
Sourcepub fn new(cache: Arc<HttpCache>) -> Self
pub fn new(cache: Arc<HttpCache>) -> Self
Creates a new router with the given HTTP cache, backing both crates.io and every alternate registry client this router later registers.
Sourcepub fn register_alternate(&self, index: RegistryIndex, auth: Option<AuthToken>)
pub fn register_alternate(&self, index: RegistryIndex, auth: Option<AuthToken>)
Registers (or reuses an existing registration for) index, with auth attached to
every request against it.
A no-op when index is already registered — the first successful registration for
a given index URL sticks for the process lifetime; a later registration attempt
carrying a different auth for the same already-registered index is silently
ignored. This is a known, accepted limitation for a P4-priority feature (see
ECOSYSTEM_GUIDE.md): it can only matter if the same index URL is reachable through
two different resolution paths with different tokens across the process’s lifetime,
which no current call site does.
Also a no-op, with a tracing::warn!, once MAX_ALTERNATE_REGISTRIES is reached
and index is not already present (spec NFR-007) — the dependency stays
unregistered rather than evicting an existing, possibly still-in-use, client.
Issue #455, C3: a re-registration of an already-registered index URL now folds to
the stricter of the stored and incoming crate::config::IndexTrust tier, dropping
any stored credential when the fold actually tightens — closing the shape where a
Trusted+token registration of URL X (from $CARGO_HOME) makes a later
WorkspaceDeclared registration of the same X a no-op, leaving a workspace-controlled
alias fetch through the looser Trusted-tier client. A re-registration that does not
tighten the tier keeps the existing client (and its credential) untouched — this is a
stricter, not weaker, version of the pre-existing idempotency contract this method’s
summary line above documents.
Sourcepub fn alternate_client(&self, index: &str) -> Option<Arc<SparseIndexClient>>
pub fn alternate_client(&self, index: &str) -> Option<Arc<SparseIndexClient>>
The registered client for index, if any — read-only, performs no registration, no
validation. A plain map lookup: index only ever originates from an already-validated
RegistryIndex::as_str, on both sides — registration above, and a dependency’s own
resolved index string (crate::parser) — so normalization stays symmetric with no
need to reconstruct a RegistryIndex (and the IndexTrust/policy that would require)
just to look one up (plan-1b §1.2, critic S2).
Used by completion (crate::ecosystem::CargoEcosystem::generate_completions, FR-012)
to address one specific alternate index directly via deps_core::Registry’s
generic helpers, without going through this router’s source-based dispatch.
Trait Implementations§
Source§impl Registry for CargoRegistry
impl Registry for CargoRegistry
Source§fn search<'a>(
&'a self,
query: &'a str,
limit: usize,
) -> BoxFuture<'a, Result<Vec<Box<dyn Metadata>>>>
fn search<'a>( &'a self, query: &'a str, limit: usize, ) -> BoxFuture<'a, Result<Vec<Box<dyn Metadata>>>>
Always crates.io — the sparse index protocol has no search endpoint, so this is unreachable for an alternate source by construction (spec FR-001).
Source§fn get_versions<'a>(
&'a self,
name: &'a PackageName,
) -> BoxFuture<'a, Result<Vec<Box<dyn Version>>>>
fn get_versions<'a>( &'a self, name: &'a PackageName, ) -> BoxFuture<'a, Result<Vec<Box<dyn Version>>>>
Source§fn get_versions_with<'a>(
&'a self,
name: &'a PackageName,
freshness: FreshnessSettings,
) -> BoxFuture<'a, Result<Vec<Box<dyn Version>>>>
fn get_versions_with<'a>( &'a self, name: &'a PackageName, freshness: FreshnessSettings, ) -> BoxFuture<'a, Result<Vec<Box<dyn Version>>>>
get_versions, but lets a registry that can obtain
Version::published_at only through an extra request gate that request behind
freshness.enabled instead of always paying for it. Read moreSource§fn get_versions_from<'a>(
&'a self,
name: &'a PackageName,
source: &'a DependencySource,
freshness: FreshnessSettings,
) -> BoxFuture<'a, Result<Vec<Box<dyn Version>>>>
fn get_versions_from<'a>( &'a self, name: &'a PackageName, source: &'a DependencySource, freshness: FreshnessSettings, ) -> BoxFuture<'a, Result<Vec<Box<dyn Version>>>>
get_versions_with, but additionally carries the
dependency’s resolved DependencySource, for a registry that routes a single
fetch across more than one underlying index (e.g. deps-cargo’s CargoRegistry,
which dispatches a DependencySource::AlternateRegistry to a private sparse index
instead of crates.io). Read moreSource§fn get_latest_matching<'a>(
&'a self,
name: &'a PackageName,
req: &'a VersionReq,
) -> BoxFuture<'a, Result<Option<Box<dyn Version>>>>
fn get_latest_matching<'a>( &'a self, name: &'a PackageName, req: &'a VersionReq, ) -> BoxFuture<'a, Result<Option<Box<dyn Version>>>>
Source§fn get_latest_matching_with_context<'a>(
&'a self,
name: &'a PackageName,
req: &'a VersionReq,
minimum_stability: Option<&'a str>,
) -> BoxFuture<'a, Result<Option<Box<dyn Version>>>>
fn get_latest_matching_with_context<'a>( &'a self, name: &'a PackageName, req: &'a VersionReq, minimum_stability: Option<&'a str>, ) -> BoxFuture<'a, Result<Option<Box<dyn Version>>>>
get_latest_matching, but lets a registry whose
“latest matching” selection can be refined by ecosystem-specific manifest state (e.g.
Composer’s minimum-stability field, #424) read it, alongside req. Read moreSource§fn get_latest_matching_from<'a>(
&'a self,
name: &'a PackageName,
source: &'a DependencySource,
req: &'a VersionReq,
_minimum_stability: Option<&'a str>,
) -> BoxFuture<'a, Result<Option<Box<dyn Version>>>>
fn get_latest_matching_from<'a>( &'a self, name: &'a PackageName, source: &'a DependencySource, req: &'a VersionReq, _minimum_stability: Option<&'a str>, ) -> BoxFuture<'a, Result<Option<Box<dyn Version>>>>
get_latest_matching_with_context,
but additionally carries the dependency’s resolved DependencySource — the
get_latest_matching-shaped counterpart to
get_versions_from, covering the fallback path a caller
takes when the list-based pick fails on a non-empty get_versions_from
result (see deps_core::lsp_helpers::hover’s list_fallback_latest and
deps-lsp’s background-fetch fallback for the two call sites this exists for). Read moreSource§fn select_latest_matching(
&self,
versions: &[Box<dyn Version>],
req: &VersionReq,
) -> Option<usize>
fn select_latest_matching( &self, versions: &[Box<dyn Version>], req: &VersionReq, ) -> Option<usize>
Source§fn as_any(&self) -> &dyn Any
fn as_any(&self) -> &dyn Any
Source§fn select_latest_matching_with_context(
&self,
versions: &[Box<dyn Version>],
req: &VersionReq,
minimum_stability: Option<&str>,
) -> Option<usize>
fn select_latest_matching_with_context( &self, versions: &[Box<dyn Version>], req: &VersionReq, minimum_stability: Option<&str>, ) -> Option<usize>
select_latest_matching, but lets a registry
whose selection can be refined by ecosystem-specific manifest state (e.g. Composer’s
minimum-stability field, #424) read it, alongside versions and req. See
get_latest_matching_with_context for why
minimum_stability is an opaque per-ecosystem string rather than a shared type. Read moreSource§fn reports_yanked(&self) -> bool
fn reports_yanked(&self) -> bool
get_versions results carry meaningful
per-version yank/deprecation data via Version::removal_status. Read more