Skip to content
CAI
Software that uses CAICheck a score

puppetlabs/puppet

54.2

Adequate · 26 September 2026

138.8k

lines of production code

Ruby

primary language

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This release introduces a comprehensive CLI face-based interface, replacing the legacy application structure with a modular, extensible command system. It significantly expands the Puppet language with a large set of new built-in functions, a new Pcore-based AST model, and enhanced type inference capabilities. The update also delivers a major overhaul of the HTTP client and server architecture, alongside extensive improvements to the acceptance test framework and benchmarking tools.

Features

Add Debian init script and defaults configuration for the Puppet agent

Introduced new Debian packaging artifacts for the Puppet agent, including an init script (puppet.init) and a defaults configuration file (puppet.default). The init script provides standard service management capabilities (start, stop, restart, status, reload, and condrestart) for the Puppet agent, sourcing runtime options from /etc/default/puppet. This establishes the standard Debian service control interface for managing the Puppet agent process.

ext/debian · high confidence

Add DirectoryService, ObjectAdd, and PW providers for OS X and BSD-style systems

New providers are introduced to manage user and group accounts on OS X and BSD-style systems. The DirectoryService provider enables management of users and groups via macOS's DirectoryService (dscl), including support for password hashes and plist output. The ObjectAdd and PW providers provide a base for BSD-style user management using the 'pw' command. These changes allow Puppet to manage local accounts on these platforms using their native tools.

lib/puppet/provider/nameservice · high confidence

Add Hiera and None data binding terminus classes

New data binding terminus classes are introduced for Hiera and a dummy 'None' option. The Hiera class inherits from Puppet::Indirector::Hiera to retrieve data using Hiera, while the None class inherits from Puppet::Indirector::None and always throws a :no\_such\_key exception for data lookups, effectively disabling data binding.

_lib/puppet/indirector/data\binding · high confidence

Add JSON, MessagePack, REST, YAML, and Processor terminuses for report indirection

The report indirection layer now includes dedicated terminus classes for serializing and transmitting reports in multiple formats. A new JSON terminus saves the last run report to a local file using JSON serialization, while a MessagePack terminus provides a more compact binary format. The REST terminus has been updated to use the HTTP client for sending reports over the wire, and the YAML and Processor terminuses are also introduced to handle file-based and plugin-based report processing respectively. These changes provide users with flexible options for storing and transmitting Puppet reports.

lib/puppet/indirector/report · high confidence

Add LDAP utility classes for connection, generation, and management

The change introduces three new Ruby classes in the Puppet codebase: \Puppet::Util::Ldap::Connection\, \Puppet::Util::Ldap::Generator\, and \Puppet::Util::Ldap::Manager\. \Connection\ handles the underlying LDAP network connection, including SSL/TLS configuration and simple binding. \Generator\ provides a builder pattern for creating attribute value generators. \Manager\ serves as the primary interface for LDAP providers, handling connection pooling, search, create, delete, and modify operations, and mapping between LDAP attributes and Puppet provider attributes.

lib/puppet/util/ldap · high confidence

Add Red Hat client init script and sysconfig

A new init script (client.init) and sysconfig file (client.sysconfig) are added for the Puppet client on Red Hat-based systems. The init script manages the puppet agent daemon, handling start, stop, restart, status, and reload operations, while the sysconfig file provides a location for optional extra options.

ext/redhat · high confidence

Add SUSE init script for the Puppet client

A new SysV init script (client.init) is introduced for SUSE Linux Enterprise Server, enabling the Puppet client daemon to be managed via standard service commands (start, stop, restart, status, etc.). The script handles process management using a PID file and lockfile, supports hot-reloading via HUP signal, and integrates with SUSE's rc.status and rc.failed utilities for consistent service state reporting.

ext/suse · high confidence

Add Solaris SMF service manifest and startup script for Puppet

New files are added to ext/solaris/smf to enable the Puppet agent to run as a native Solaris Service Management Facility (SMF) service. The addition includes a shell script that handles start/stop logic and an XML manifest defining the service dependencies and execution methods, allowing users to manage the Puppet agent via standard Solaris service commands.

ext/solaris · high confidence

Add benchmark for serialization performance

A new benchmark suite has been added to measure the overhead of Ruby JSON and PSON serialization. The suite includes a benchmarker script that can generate or parse catalog data in either JSON or PSON format, allowing users to compare the performance of different serialization methods.

_benchmarks/hiera\_include\one, benchmarks/serialization · high confidence

Add benchmark for virtual collection catalog compilation

A new benchmark suite has been added to measure catalog compilation performance with heavy use of virtual resources. The suite includes a Ruby-based benchmarker that generates a Puppet environment with a specified number of virtual resources and their corresponding notifications, along with the necessary configuration and manifest templates to run the benchmark.

_benchmarks/virtual\collection · high confidence

Add environments API endpoint for v3

A new HTTP API endpoint has been added at \lib/puppet/network/http/api/server/v3/environments.rb\ to expose environment details. When accessed, it returns a JSON response containing the search paths and a list of environments, where each environment includes its settings (modulepath, manifest, environment\_timeout, and config\_version).

lib/puppet/network/http/api/server/v3 · high confidence

Add example Hiera modules for NTP configuration and user management

The examples/hiera directory now includes new modules for demonstrating Hiera integration with Puppet. The ntp module provides a configurable NTP server list via Hiera data (common.yaml) and an EPP template to generate /tmp/ntp.conf. The users module includes placeholder classes (common, dc1) that demonstrate how to structure example code for different node types. These changes illustrate how to use Hiera for externalizing configuration data in example scenarios.

examples/hiera/modules/ntp, examples/hiera/modules/users · high confidence

Add information services for classes, plans, and tasks

The Puppet agent now exposes structured metadata about classes, plans, and tasks via new information service classes. The ClassInformationService parses Puppet manifests to return class names, parameter types, and default values. The PlanInformationService retrieves metadata and file lists for Puppet plans within modules. The TaskInformationService lists available tasks and their metadata, gracefully handling malformed tasks. These services enable external tools to query the state of Puppet code without executing it.

_lib/puppet/info\service · high confidence

Add micro-benchmarking for evaluation performance

A new micro-benchmarking framework has been added to the \benchmarks/evaluations\ directory to measure the performance of individual use cases of evaluation. The \Benchmarker\ class and its associated Rake task support running specific benchmarks such as function calls (3x and 4x), variable lookups, and string interpolation. The setup generates a temporary Puppet environment with supporting logic, including 3x and 4x functions, to facilitate these performance measurements.

benchmarks/evaluations · high confidence

Add native group providers for AIX, FreeBSD/DragonFly BSD, LDAP, Windows ADSI, and Linux (groupadd/libuser)

Introduces new group management providers for specific platforms: AIX (using mkgroup/lsgroup/chgroup), FreeBSD and DragonFly BSD (using the pw command), LDAP (posixGroup mapping), Windows (using ADSI/SID resolution), and Linux (using groupadd/groupmod and libuser for local groups). These providers implement the \manages\_members\ and \manages\_local\_users\_and\_groups\ features, enabling Puppet to manage group membership and local group creation/modification on these systems.

lib/puppet/provider/group · high confidence

Add new functions to the Puppet language

This update adds a large number of new built-in functions to the Puppet language, including \abs\, \all\, \any\, \annotate\, \assert\_type\, \binary\_file\, \break\, \call\, \camelcase\, \capitalize\, \ceiling\, \chomp\, and many others. These functions provide capabilities such as type assertion, iteration control, string manipulation, and data lookup, with some functions supporting deferred value resolution and block parameters. The implementation includes both the new 4.x API functions and their corresponding 3.x stubs or documentation updates.

lib/puppet/functions · high confidence

Add node clean face to remove node data

A new \node clean\ face has been added, allowing administrators to remove signed certificates, cached facts, node objects, and reports for specified nodes. The implementation delegates certificate cleanup to the Puppet Server CA API when available, while also clearing local cached data and reports.

lib/puppet/face/node · high confidence

Add repository configuration files for Git and development workflow

Added .gitattributes to enforce line-ending consistency for specific test fixtures, .gitignore to exclude build artifacts and IDE files, .gitmodules to include a performance control submodule, and .mailmap to standardize contributor email addresses across the repository.

(repo-wide) · high confidence

Add resource indirector implementation and validation

The resource indirector now includes a new \ral.rb\ implementation that enables finding, searching, and saving resources via the Resource Abstraction Layer (RAL). A new \validator.rb\ module enforces that resource instances match their request keys, and \store\_configs.rb\ is added to support the storeconfigs backend for resources. These changes introduce internal mechanisms for resource management and validation within the indirector system.

lib/puppet/indirector/resource · high confidence

Add resource type generator application

The \puppet generate\ command now supports generating resource type definitions. This new capability allows users to convert custom type source files into Pcore format, with the generator finding inputs from module directories and producing \.pp\ output files. The implementation includes an \Input\ class to manage file paths and formats, and a \generate\ method that handles template rendering and file management.

lib/puppet/generate · high confidence

Add resource type model and Pcore template for code generation

The Puppet code generator now includes new model classes for resource types and properties, along with a Pcore ERB template. The \Property\ model extracts name, type, documentation, and namevar status, while the \Type\ model captures name, documentation, properties, parameters, title patterns, and capability flags. The \pcore.erb\ template renders these models into a Ruby file that defines \Puppet::Resource::ResourceType3\ instances, enabling the \puppet generate types\ command to produce Pcore-compatible resource type definitions.

lib/puppet/generate/models · high confidence

Add stub functions for new 4.x parser functions

Added stub implementations for several new 4.x parser functions, including \assert\_type\, \binary\_file\, \break\, \dig\, \epp\, \file\, \filter\, \find\_file\, \fqdn\_rand\, \generate\, and others. These stubs provide documentation and error handling for the legacy 3.x parser, ensuring that calls to these functions in older code paths trigger appropriate deprecation or compatibility errors. The changes also include updated documentation for existing functions like \create\_resources\ and \defined\, and introduce new functions such as \each\ and \epp\ with their respective stubs.

lib/puppet/parser/functions · high confidence

Add system startup benchmarking

A new benchmarking tool has been introduced to measure the overhead of loading Puppet, specifically targeting the CLI startup time. The \benchmarker.rb\ script provides a framework for running Puppet commands (such as \puppet help\) to serve as a proxy for full startup performance, allowing users to track and optimize system startup times.

_benchmarks/system\startup · high confidence

Add user management providers for AIX, HP-UX, OpenBSD, FreeBSD, and Solaris RBAC

New user providers are introduced for AIX, HP-UX, OpenBSD, FreeBSD, and Solaris RBAC, each implementing the \user\ type for their respective operating systems. The AIX provider uses \mkuser\/\chuser\ and supports password expiry, password age, and local user management. The HP-UX provider (\hpuxuseradd\) extends the \useradd\ base to handle trusted computing mode and password expiration. The OpenBSD provider supports login classes, expiry, and password management via \ruby-shadow\. The FreeBSD/DragonFly BSD provider (\pw\) manages shells, expiry, and passwords. The Solaris provider (\user\_role\_add\) extends \useradd\ to manage Solaris RBAC roles, authorizations, and profiles. These additions expand Puppet's ability to manage user resources across a wider range of Unix-like systems.

lib/puppet/provider/user · high confidence

Add v3 HTTP API server implementation

A new v3 HTTP API server implementation has been added at lib/puppet/network/http/api/server/v3.rb. This file defines the routing structure for the v3 API, including indirected routes and an environments endpoint, and provides a wrapper for authorization checks.

lib/puppet/network/http/api/server · high confidence

Add vendoring system to Puppet

A new vendoring system has been introduced to manage third-party Ruby libraries within the Puppet codebase. This includes the addition of a \require\_vendored.rb\ file in \lib/puppet/vendor\, which serves as the central point for loading vendored dependencies. This change supports the integration of external gems like \rgen\ and \deep\_merge\ directly into the project's library path, ensuring consistent versions and reducing external dependencies.

lib/puppet/vendor · high confidence

Add version range comparison operators

The \lib/puppet/util/package/version/range\ directory now includes new classes for version range comparisons, including equality (\Eq\), greater-than (\Gt\), greater-than-or-equal (\GtEq\), less-than (\Lt\), less-than-or-equal (\LtEq\), and a combined \MinMax\ range. These classes implement the \include?\ method to determine if a given version falls within the specified range, supporting operators like \\>\, \\>=\, \\<\, \\<=\, and \==\ for package versioning.

lib/puppet/util/package/version/range · high confidence

Added Hiera example demonstrating YAML backend with fact-driven overrides

A new example in the examples/hiera directory provides a working demo of Hiera with the YAML backend. It includes configuration files (hiera.yaml, data/common.yaml, data/dc1.yaml) and a site.pp manifest that illustrate how to use Hiera for fact-driven data lookups, specifically showing how to override NTP server settings and include classes based on location facts.

examples/hiera · high confidence

Added RDoc parser for Puppet modules and plugins

The RDoc documentation generation now supports parsing Puppet modules, functions, and facts. This change introduces a new parser that scans Puppet module directories to extract documentation from README files and Ruby-based plugins (functions and facts). Users will see improved documentation output for their Puppet modules, including module names, comments, and custom facts.

lib/puppet/util/rdoc/parser · high confidence

Added Windows batch scripts for interactive and shell environments

Three new Windows batch files have been added to the ext/windows directory: puppet\_interactive.bat, puppet\_shell.bat, and run\_puppet\_interactive.bat. The interactive script launches the Puppet agent in test mode, while the shell and interactive launcher scripts configure the environment path and invoke the respective tools, providing convenient entry points for Windows users.

ext/windows · high confidence

Added benchmark for hiera\_include performance

A new benchmark scenario has been added to measure the performance of the hiera\_include function using a large nested hierarchy dataset. This includes a Ruby script to generate the test environment and data, a description of the benchmark target, and a Puppet configuration template for the test environment.

_benchmarks/hiera\include · high confidence

Added benchmark for module dependency loading performance

A new benchmark suite has been added to measure the performance of the module loader when traversing module dependencies. The suite generates a chain of modules with inter-dependencies and measures the time taken to load and resolve them, allowing for comparison of different loading strategies.

_benchmarks/dependency\loading · high confidence

Added catalog\_memory benchmark for memory leak detection

A new 'catalog\_memory' benchmark has been added to the benchmarks suite. It runs an empty catalog and dumps the state of the memory after all runs, providing a diff between the first and last run to help identify memory leaks. The benchmark requires Ruby 2.1.0 or higher and uses the Future parser.

_benchmarks/catalog\memory · high confidence

Added concurrent module with thread-safe singleton and lock utilities

The lib/puppet/concurrent directory now contains new files: lock.rb, synchronized.rb, and thread\_local\_singleton.rb. These introduce a simple Lock class for JRuby, a Synchronized module that enables thread-safe synchronization on JRuby while being a no-op on MRI, and a ThreadLocalSingleton module that provides thread-local singleton access. These changes support concurrent execution patterns in Puppet, particularly for JRuby environments.

lib/puppet/concurrent · high confidence

Added default configuration file examples for Puppet

The repository now includes example configuration files for environment.conf, fileserver.conf, hiera.yaml, and puppet.conf in the conf/ directory. These files provide default settings and documentation links to help users understand and customize their Puppet configuration. Specifically, the fileserver.conf example notes that permission directives have been removed and access control should be handled via auth.conf, while the environment.conf example highlights environment\_timeout as a recommended setting to configure in puppet.conf.

conf · high confidence

Added development utilities for parallelizing and debugging RSpec tests

Added new utility scripts to the \util\ directory to improve the test execution workflow. \rspec\_grouper\ and \rspec\_runner\ provide a mechanism to split and run RSpec tests in parallel, while \binary\_search\_specs\ helps identify the specific test that causes a flaky or intermittent failure by performing a binary search over the test suite. A \README\_UTIL.md\ file was also added to document these tools.

util · high confidence

Added empty English locale file for Puppet

An empty English (en) translation file (puppet.po) has been added to the project. This establishes the base template for English strings, allowing future translations to be built upon this foundation.

locales/en · high confidence

Added empty catalog benchmark to measure catalog compilation overhead

A new benchmark scenario has been introduced to measure the overhead of catalog compilation and environment setup. The 'empty catalog' test compiles a minimal catalog containing only a single log message, allowing users to track the baseline cost of the Puppet environment and compiler initialization.

_benchmarks/empty\catalog · high confidence

Added external DOT graphing library

Added a new external library (lib/puppet/external/dot.rb) that provides a Ruby interface for generating DOT graph descriptions, including support for nodes, edges, and graph options.

lib/puppet/external · high confidence

Added external node classifier and Nagios monitoring script examples

Added new example files for implementing external node classification using regular expressions, including the \regexp\_nodes.rb\ script and its associated configuration files for classes, parameters, and environments. Also added a \check\_puppet.rb\ script for Nagios monitoring, which verifies that the Puppet process is running and the state file is up to date.

examples/enc · high confidence

Added full catalog benchmarking tooling

A new full catalog benchmarking suite has been introduced to the codebase. This includes a Ruby-based benchmarker that sets up a Puppet environment with specific node facts, manages submodules, and generates configuration files (puppet.conf, hiera.yaml, site.pp) to drive the benchmark. The suite also provides the necessary templates and configuration files (such as r10k.yaml and Gemfile) to support the benchmarking process.

_benchmarks/full\catalog · high confidence

Added function loading benchmark to measure performance

A new benchmark scenario has been introduced in the \benchmarks/function\_loading\ directory to measure the performance of function loading and call overhead. The \benchmarker.rb\ script generates a test environment containing multiple modules and environment functions, creating deep recursion and cross-module calls to stress-test the function loading mechanism.

_benchmarks/function\loading · high confidence

Added locale configuration and translation templates for internationalization

The \locales\ directory now contains a \config.yaml\ file that configures the \fast\_gettext\ library for the project, specifying the project name, default locale, and file patterns for extracting translatable strings. Additionally, a \puppet.pot\ template file has been added, containing the extracted English source strings from the codebase, enabling future translation efforts.

locales · high confidence

Added macOS launchd plist for the Puppet agent service

A new launchd property list (puppet.plist) has been added to the ext/osx directory. This configuration file defines how the Puppet agent runs as a macOS service, specifying the executable path (/opt/puppetlabs/bin/puppet), command-line arguments (agent, --verbose, --no-daemonize), environment variables (LANG), and logging destinations. This enables the Puppet agent to be managed by macOS's launchd system.

ext/osx · high confidence

Added many-modules benchmarking scenario

A new benchmarking scenario has been added to evaluate catalog compilation performance with many modules. The change introduces a Ruby-based benchmarker that dynamically generates a test environment containing multiple modules, each with internal classes and roles, along with the necessary configuration and manifest templates to support this specific test case.

_benchmarks/many\modules · high confidence

Added micro-benchmarking for defined types

A new micro-benchmarking suite for defined types has been added to the benchmarks/defined\_types directory. This includes a Ruby-based Benchmarker class that generates a test environment with multiple modules and manifests to measure catalog compilation performance. The suite is designed to run against specific Puppet versions (e.g., 3.4.2) and allows for warm-up and detailed output via command-line arguments.

_benchmarks/defined\types · high confidence

Added placeholder migration checker infrastructure

A new \MigrationChecker\ class has been introduced in the POPS migration module. This placeholder implementation provides a private API for reporting various migration issues (such as ambiguous integers, empty string truthiness, and type mismatches) that will be used to detect and report breaking changes between Puppet 3.8/4.0 and newer versions. Currently, all reporting methods raise a \DevError\, indicating that the actual migration checks are not yet fully implemented.

lib/puppet/pops/migration · high confidence

Added syntax checking for embedded strings in heredocs

Puppet now supports syntax checking for embedded strings in heredocs. This change introduces a new extension point, \Puppet::Plugins::SyntaxCheckers\, which allows for the registration of syntax checkers for different data formats. The \Configuration\ module in \lib/puppet/plugins/configuration.rb\ registers built-in syntax checkers for JSON, Base64, PP, and EPP. This enables users to specify syntax types in heredoc tags (e.g., \@(END:userdata+json)\) to validate the content of embedded strings against the corresponding syntax rules.

lib/puppet/plugins · high confidence

Added type inference benchmark suite

A new benchmarking tool has been introduced in the benchmarks/type\_inference directory to measure the overhead of the type inference process. This includes a Ruby-based benchmarker script, configuration templates, and a sample manifest that exercises complex type structures, allowing users to evaluate parser performance under the Future parser.

_benchmarks/type\inference · high confidence

Added version parsing and comparison for Debian, Gem, Pip, RPM, and version ranges

Puppet now supports parsing and comparing package versions for Debian, RubyGems, Python (pip), and RPM, as well as version ranges. This enables more accurate version matching and dependency resolution for these package types.

lib/puppet/util/package/version · high confidence

Configure Git-based acceptance testing with Puppet and Puppetserver settings

A new configuration file for Git-based acceptance testing has been added, specifying that the Puppet agent and server should be installed from a Git repository. The configuration also sets up Puppetserver-related options, including service management and configuration paths, enabling the test suite to run against a Git-based Puppet installation.

acceptance/config/git · high confidence

Extensive updates to package management providers

The package management subsystem received a massive overhaul, adding support for new package managers including tdnf, opkg, xbps, and pkgin, while also adding Yaourt support to the pacman provider. Existing providers were significantly enhanced with new features such as install\_options, uninstall\_options, and version range support across apt, pip, rpm, and others. Numerous bug fixes were applied to improve reliability, including fixes for yum, dpkg, and portage providers, alongside general code quality improvements and test coverage.

lib/puppet/provider/package · high confidence

Implemented modular translation loading and domain management for Puppet

Puppet now loads translations from module paths and the $vardir, allowing each module to provide its own localized strings. The new GettextConfig module manages text domains, enabling environment-specific translations and ensuring that module translations are loaded before catalog compilation. If the gettext library is unavailable, the system gracefully falls back to English with no errors. This change introduces a structured way to handle translations for both the core Puppet code and individual modules.

lib/puppet/gettext · high confidence

Introduce Bundler-based dependency management with new Gemfiles

The project now uses Bundler to manage Ruby dependencies, introducing a root Gemfile that defines runtime, feature, test, and development groups, along with a separate Gemfile for acceptance tests. This change standardizes how gems like Facter, semantic\_puppet, and RSpec are resolved, making it easier for contributors to set up the development environment and for CI systems to install consistent dependencies.

(dependencies) · high confidence

Introduce EPP (Embedded Puppet) template parsing and code merging

The parser now supports EPP templates, allowing Puppet manifests to include embedded Puppet code within template files. This change adds a new \EppParser\ and \EppSupport\ module to scan and parse EPP syntax, integrating it into the main \EvaluatingParser\ for evaluation. Additionally, a \CodeMerger\ utility is introduced to combine multiple parse results into a single AST block, facilitating the processing of manifest directories where files are merged before evaluation.

lib/puppet/pops/parser · high confidence

Introduce Error data type implementation

A new Error data type implementation has been added to the datatypes directory, defining the structure and behavior for error handling. This includes attributes for message, kind, details, and issue code, along with methods for initialization, equality comparison, and hash generation, enabling consistent error representation within the system.

lib/puppet/datatypes/impl · high confidence

Introduce Hiera scope wrapper and base function class

Added lib/hiera/scope.rb and lib/hiera/puppet\_function.rb to provide a Hiera-specific scope wrapper and a base class for Hiera Puppet functions. The scope wrapper exposes calling\_class, calling\_class\_path, and calling\_module, allowing Hiera lookups to correctly identify the calling class and module context. The base class standardizes dispatch for Hiera functions, supporting splat arguments, default values, and default blocks, while issuing deprecation warnings for the legacy hiera\_xxx functions in favor of the new lookup framework.

lib/hiera · high confidence

Introduce Pcore-based AST model for the Puppet parser

The Puppet parser's internal model has been replaced with a new Pcore-based AST model (lib/puppet/pops/model/ast.pp and ast.rb) that defines a structured hierarchy of expression and statement types (e.g., BinaryExpression, LambdaExpression, CaseExpression). This change introduces a new model layer that the parser builds, along with transformers (AstTransformer, PnTransformer) to convert between the new model, the legacy 3.x AST, and the PN (Reverse Polish Notation) representation. This enables better type safety, improved error reporting, and a more consistent internal representation for the compiler and evaluator.

lib/puppet/pops/model · high confidence

Introduce Plan and Task classes for module content

Added new \Puppet::Module::Plan\ and \Puppet::Module::Task\ classes to handle the discovery, validation, and metadata loading for Puppet plans and tasks. The \Plan\ class validates plan names and file extensions (\.pp\, \.yaml\), while the \Task\ class validates task names, file extensions, and metadata structure, including support for multi-implementation tasks and associated file mounts.

lib/puppet/module · high confidence

Introduce Puppet as a Library (PAL) API for programmatic Puppet language evaluation

The lib/puppet/pal directory now contains a new set of classes that expose the Puppet language evaluation engine as a library. This includes Puppet::Pal::Compiler for evaluating Puppet code strings and files, Puppet::Pal::CatalogCompiler for building and inspecting compiled catalogs, and signature classes (FunctionSignature, PlanSignature, TaskSignature) for introspecting callable signatures. Users can now programmatically evaluate Puppet code, retrieve compiled catalogs as JSON or hashes, and check if functions, plans, or tasks can be called with specific arguments, all without invoking the full Puppet CLI or agent.

lib/puppet/pal · high confidence

Introduce Puppet::Node::Environment and Puppet::Node::Facts classes

Added new classes for managing environment configuration and node facts. Puppet::Node::Environment now serves as a container for environment-specific configuration, including module paths, manifest paths, and config versions, with support for remote environments and command-line overrides. Puppet::Node::Facts manages node facts with timestamping, serialization, and automatic expiration of cached nodes upon save. Additionally, Puppet::Node::ServerFacts loads server-specific facts like PE version and network information.

lib/puppet/node · high confidence

Introduce Timespan and Timestamp types for time handling

The \lib/puppet/pops/time\ directory now contains new \Timespan\ and \Timestamp\ classes, providing structured representations for time intervals and absolute points in time. These classes support parsing from strings with various formats, arithmetic operations (addition, subtraction, multiplication), and serialization to and from hashes. This adds new capabilities for handling time-based data in Puppet's Pops layer.

lib/puppet/pops/time · high confidence

Introduce TrustedInformation class to manage certificate and trusted facts

A new \Puppet::Context::TrustedInformation\ class has been added to encapsulate trusted context data, including authentication status, certificate name, extensions, hostname, domain, and external facts. This class provides a structured way to handle trusted information derived from certificates and external sources, with support for lazy evaluation of external facts and deep freezing of data structures to ensure immutability.

lib/puppet/context · high confidence

Introduce Windows package providers for MSI and EXE installers

The Windows package provider is refactored into a base class and two new subclasses: MsiPackage and ExePackage. This change enables Puppet to manage Windows packages installed via MSI or EXE installers by reading their registry entries, supporting installation from local files or HTTP/HTTPS URLs for EXE packages, and handling uninstall commands appropriately for each type.

lib/puppet/provider/package/windows · high confidence

Introduce bin/puppet executable entry point

Added a new bin/puppet script that serves as the primary entry point for the Puppet CLI. The script requires the Puppet::Util::CommandLine module and executes the command-line interface, with a rescue block to handle LoadError exceptions by printing the error message to stderr and exiting with a non-zero status code.

bin · high confidence

Introduce dedicated HTTP service classes for CA, compiler, file server, report, and puppetserver endpoints

Puppet now uses specific HTTP service classes (Ca, Compiler, FileServer, Report, and Puppetserver) to handle distinct server interactions, replacing the previous generic service pattern. This change introduces dedicated endpoints for certificate management, catalog compilation, file serving, report submission, and server status checks, each with their own URL prefixes, headers, and request methods. Users benefit from clearer separation of concerns and more robust handling of server-specific requirements like SSL contexts, content types, and response parsing.

lib/puppet/http/service · high confidence

Introduce in-memory file system implementation for testing

Added a new in-memory file system implementation (Puppet::FileSystem::MemoryImpl and Puppet::FileSystem::MemoryFile) that allows tests to interact with a virtual file system in memory rather than the real disk. This enables faster, isolated tests that do not depend on the actual file system state. The implementation supports common file operations like reading, writing, and checking existence, providing a mockable alternative to the standard file system abstractions.

_lib/puppet/file\system · high confidence

Introduce new AST node classes for the parser

The parser now uses a set of new AST node classes to represent language constructs. This includes \BlockExpression\ for evaluating contained expressions, \Branch\ as a parent for nodes containing other AST objects, \Leaf\ for simple values, and specific nodes for \Hostclass\, \Node\, and \Resource\ definitions. A \PopsBridge\ is added to connect the new Pops-based model with the 3.x AST, allowing the system to reuse \Puppet::Resource::Type\ and support features like typed parameters and plan definitions.

lib/puppet/parser/ast · high confidence

Introduce new CLI faces for catalog, config, epp, facts, generate, help, module, node, and parser

Puppet introduces a new command-line interface (CLI) structure based on 'faces' and 'actions', replacing the older application-based command structure. This change adds new subcommands including \puppet catalog\ (for compiling, downloading, and applying catalogs), \puppet config\ (for inspecting and modifying settings), \puppet epp\ (for validating and dumping EPP templates), \puppet facts\ (for retrieving and uploading facts), \puppet generate\ (for generating Puppet code from Ruby definitions), \puppet help\ (for displaying help about subcommands), \puppet module\ (for managing modules), \puppet node\ (for managing node definitions), and \puppet parser\ (for validating and dumping Puppet manifests). These faces provide a more consistent and extensible way to interact with Puppet's core functionalities, with many legacy commands and options being deprecated or removed in favor of the new face-based interface.

lib/puppet/face · high confidence

Introduce new HTTP API routing for indirections

Added new HTTP API routing classes in lib/puppet/network/http/api, including IndirectedRoutes, IndirectionType, Master, and Server. These files implement the mapping of HTTP methods and URIs to indirection methods, define URL prefixes for master and CA endpoints, and provide the foundational structure for handling indirection-based HTTP requests.

lib/puppet/network/http/api · high confidence

Introduce new HTTP client and service architecture

The HTTP client has been refactored into a new, modular architecture in lib/puppet/http, introducing a dedicated HTTP client, session, and service abstraction. This change adds support for persistent HTTP connections, DNS SRV record resolution, and service routing to endpoints like :puppet, :ca, :fileserver, and :report. The new client supports streaming response bodies, automatic redirect following, and basic authentication, while maintaining compatibility with external HTTP clients via an adapter.

lib/puppet/http · high confidence

Introduce new HTTP resolvers for server list, settings, and DNS SRV

Added three new HTTP resolver classes to lib/puppet/http/resolver: ServerList, Settings, and SRV. The ServerList resolver iterates through a configured list of servers to find a functional connection, logging warnings for unavailable servers. The Settings resolver uses default server and port settings to establish a connection. The SRV resolver queries DNS SRV records to locate available services. These changes provide a structured way to resolve HTTP services through different configuration methods.

lib/puppet/http/resolver · high confidence

Introduce new HTTP routing and error handling structures

The HTTP handler now uses a dedicated routing and error handling structure. A new \Puppet::Network::HTTP::API\ class defines server and master routes, including a fallback for invalid URLs and a 404 for unmatched routes. The \Puppet::Network::HTTP::Handler\ module is refactored to use this new routing system, allowing for more explicit route registration and processing. Additionally, a new \Puppet::Network::HTTP::Error\ module provides specific HTTP error classes (e.g., \HTTPNotFoundError\, \HTTPBadRequestError\) that are used to standardize error responses from the HTTP handler.

lib/puppet/network/http · high confidence

Introduce new Resource model classes for catalog, status, and type management

The Puppet resource model has been refactored into new classes: \Puppet::Resource::Catalog\ manages the collection of resources and their relationships; \Puppet::Resource::Status\ tracks evaluation results, timing, and events for each resource; and \Puppet::Resource::Type\ represents node, class, and defined type definitions with parameter handling. These changes provide a more structured and maintainable way to handle resource compilation, status reporting, and type collection, improving error handling, serialization, and performance.

lib/puppet/resource · high confidence

Introduce new SSL classes for managing keys, certificates, and requests

Puppet now uses a new set of classes in the \lib/puppet/ssl\ directory to manage SSL keys, certificates, and certificate signing requests (CSRs). This includes a new \Puppet::SSL::Base\ class that wraps OpenSSL objects, and specific classes like \Puppet::SSL::Certificate\, \Puppet::SSL::CertificateRequest\, and \Puppet::SSL::SSLProvider\ to handle SSL context creation, certificate loading, and CSR generation. These changes provide a more structured and testable approach to SSL operations, replacing the previous indirector-based system with direct class-based interactions for certificate and key management.

lib/puppet/ssl · high confidence

Introduce new Windows utility classes for security descriptors, COM, and services

Added new classes to manage Windows security descriptors and access control lists, including \Puppet::Util::Windows::AccessControlEntry\ and \Puppet::Util::Windows::AccessControlList\ for parsing and manipulating DACLs and ACEs. Introduced \Puppet::Util::Windows::ADSI\ and \Puppet::Util::Windows::COM\ modules to handle Active Directory Service Interfaces and COM object instantiation via FFI. Additionally, added \Puppet::Util::Windows::Daemon\ to manage Windows service lifecycle and status reporting, alongside new error handling in \Puppet::Util::Windows::Error\ and event logging in \Puppet::Util::Windows::EventLog\.

lib/puppet/util/windows · high confidence

Introduce new catalog indirection terminuses for JSON, MessagePack, and REST

Puppet adds new indirection terminuses for catalog storage and transport: a JSON serializer (with PSON fallback), a MessagePack serializer, and a REST client for fetching catalogs over HTTP. The existing YAML and StoreConfigs terminuses are also present. These changes enable more efficient catalog serialization and network transport, supporting richer data formats and configurable checksum types in catalog requests.

lib/puppet/indirector/catalog · high confidence

Introduce new evaluator components for the future evaluator

Added new classes in the \lib/puppet/pops/evaluator\ directory to support the future evaluator architecture. This includes \AccessOperator\ to handle the \\[\]\ operator for various types (strings, arrays, hashes, and type instances), \CallableSignature\ as an abstract base for callable signatures, \Closure\ to represent and execute lambdas and closures with proper scope and parameter binding, and \CollectorTransformer\ to transform collect expressions into collector instances. These components provide the foundation for evaluating Puppet code using the new evaluator.

lib/puppet/pops/evaluator · high confidence

Introduce new facter and JSON fact terminuses

The facts indirection now includes dedicated terminuses for retrieving facts from Facter and storing them as JSON. The new Facter terminus provides an abstract interface to Facter, handling external search paths, core Puppet facts, and legacy fact inclusion based on configuration. The new JSON terminus enables storing and retrieving client facts as flat files serialized in JSON format, supporting node name searches. These additions expand the available storage and retrieval mechanisms for node facts within the Puppet indirection system.

lib/puppet/indirector/facts · high confidence

Introduce new file serving architecture with dedicated model classes

The file serving subsystem has been refactored into a new structure with dedicated model classes: Base, Content, Metadata, and Fileset. This introduces a cleaner separation between retrieving file content and metadata, and supports features like HTTP-based file serving, recursive file sets, and improved handling of symlinks and file attributes. The configuration system now explicitly manages mounts for modules, plugins, locales, and scripts, with a new TerminusHelper and TerminusSelector to route requests appropriately.

_lib/puppet/file\serving · high confidence

Introduce new file-watching components

Added three new classes to the watcher utility: ChangeWatcher, PeriodicWatcher, and Timer. ChangeWatcher tracks value changes over time, PeriodicWatcher monitors a ChangeWatcher on a periodic interval, and Timer handles timeout and expiration logic for the periodic checks.

lib/puppet/util/watcher · high confidence

Introduce new lookup framework and reroute calls to it

The lookup and data provider APIs have been refactored into a new framework located in lib/puppet/pops/lookup. This introduces a new \Puppet::LookupContext\ Pcore type and a suite of new data provider classes (such as \ConfiguredDataProvider\, \EnvironmentDataProvider\, and \GlobalDataProvider\) that handle data resolution. The change also adds an \Explainer\ to provide detailed explanations of lookup results and enables the lookup system to support rich data types and dotted key navigation. This internal restructuring supports features like lookup explainability and improved error reporting for users.

lib/puppet/pops/lookup · high confidence

Introduce new network format and authorization infrastructure

The network layer now uses a structured \Puppet::Network::Format\ class and a \FormatHandler\ registry to manage serialization formats (JSON, YAML, MsgPack, etc.) with explicit MIME types, weights, and method requirements. Additionally, a new \Authorization\ module and \AuthConfig\ class are introduced to handle REST request authorization, including support for external authorization providers and improved error handling for unauthenticated or forbidden requests.

lib/puppet/network · high confidence

Introduce new provider base classes and utilities

Added new base classes for specific provider types: AIXObject for AIX user/group management, Ldap for LDAP-backed resources, NameService for system user/group types, NetworkDevice for network device management, and ParsedFile for file-based resources like cron and hosts. Also introduced a generic Command class to encapsulate executable paths and execution options, and a Confine class to handle provider constraints.

lib/puppet/provider · high confidence

Introduce new serialization framework for rich data

The serialization subsystem in lib/puppet/pops/serialization has been replaced with a new architecture. This introduces new classes including AbstractReader, AbstractWriter, Serializer, and Deserializer to handle the conversion of Puppet objects to and from data formats like JSON. The new system supports rich data types such as Binary, Sensitive, and Timespan, and provides a more robust mechanism for serializing complex object graphs with tabulation and local references.

lib/puppet/pops/serialization · high confidence

Introduce new validation framework for Puppet 4.0

The validation logic for the Puppet 4.0 language has been refactored into a new \Checker4\_0\ class, which enforces stricter rules on top-level constructs, assignments, and expressions. A specialized \TasksChecker\ is now used when the 'tasks' feature is enabled, restricting catalog-related operations and disallowing certain resource expressions in that context. The \ValidatorFactory\_4\_0\ configures these checkers and maps specific validation issues to severity levels (e.g., making duplicate keys and name hyphens errors, while others become deprecations or warnings based on the \strict\ setting).

lib/puppet/pops/validation · high confidence

Introduce pcore-based resource type implementations

Added new pcore type definitions and Ruby implementations for resource types, including \Puppet::Pops::Resource::Param\ and \Puppet::Pops::Resource::ResourceTypeImpl\, which adapt the 3.x compiler and catalog expectations on a resource instance backed by a pcore representation. This introduces a new type set (\resource\_type\_set.pcore\) and registers these types via \register\_ptype\ methods, enabling the use of pcore resource types in the Puppet language.

lib/puppet/pops/resource · high confidence

Introduce platform-specific AtFork handlers for Solaris contracts

Added new implementation files for the AtFork utility: a Noop handler for platforms that do not require special fork handling, and a Solaris-specific handler that manages process contracts via the Fiddle library. This change enables Puppet to execute agent runs in a separate contract on Solaris, ensuring that child processes survive service restarts without being killed.

_lib/puppet/util/at\fork · high confidence

Introduce remote network device transport system

Added a new remote network device transport system that allows Puppet to manage network devices via a configurable device.conf file. This introduces a new configuration format supporting device names, URLs, and debug options, with a transport abstraction that handles connection parameters like host, port, and credentials. The system parses device configurations, validates URLs, and provides a base transport class for executing commands and expecting prompts, enabling remote device management.

_lib/puppet/util/network\device · medium confidence

Introduce structured logging and new log destinations

The logging system has been refactored to support structured log output. Users can now write logs in JSON or JSON Lines format by appending \.json\ or \.jsonl\ to the log file path, enabling easier parsing by external tools. Additionally, a new \logstash\_event\ destination was added to format log messages for Logstash, and the console output was updated to include colored, structured messages. These changes allow for more flexible and machine-readable logging configurations.

lib/puppet/util/log · high confidence

Introduce systemd unit file for the Puppet agent service

A new systemd unit file (puppet.service) is added to manage the Puppet agent as a background service. This replaces previous init scripts or manual service management, providing structured control over the agent's lifecycle, including dependencies on network targets, environment file loading, and hot-reload capability via SIGHUP.

ext/systemd · high confidence

Introduce the \`puppet agent\` CLI application

The \puppet agent\ command-line interface is now implemented as a dedicated \Puppet::Application::Agent\ class in \lib/puppet/application/agent.rb\. This change encapsulates the agent's specific configuration defaults (such as REST for catalogs and nodes, JSON for cache, and Facter for facts), command-line options (like \--disable\, \--enable\, \--fingerprint\, \--waitforcert\), and help text, separating the agent's behavior from the generic application base class.

lib/puppet/application · high confidence

Introduce the new Puppet Module Tool (PMT) codebase

The lib/puppet/module\_tool directory now contains the complete implementation of the new Module Tool, including applications (installer, upgrader, uninstaller), dependency resolution, metadata handling, and tarball unpacking. This restructures how module management commands are executed and how dependencies are resolved, replacing the previous module tool implementation.

_lib/puppet/module\tool · high confidence

Introduced new FileBucket implementation classes

Added new classes for the file bucket system: \Puppet::FileBucket::Dipper\ and \Puppet::FileBucket::File\. The \Dipper\ class provides a transitional implementation that uses REST to access remote filebucket files, supporting operations like backup, diff, getfile, restore, and list. The \File\ class handles the abstract notion of a file in a filebucket, supporting both string and pathname contents, and provides methods for checksums, binary serialization, and streaming.

_lib/puppet/file\bucket · high confidence

Introduces AIO configuration for Puppet Server

Adds a new acceptance test configuration for All-In-One (AIO) setups that explicitly targets Puppet Server. This configuration enables service-based management of the Puppet Server, pointing to specific configuration directories and files, and includes a post-suite step to archive logs.

acceptance/config/aio · high confidence

Introduces Pcore-based type system with annotations and class loading

The Puppet type system has been refactored to use a new Pcore-based model, introducing support for annotating types and a new ClassLoader for resolving classes. This change adds the \Annotatable\ module and \Annotation\ class to allow attaching metadata to types, and implements a \ClassLoader\ that loads classes via the Puppet Autoloader, enabling dynamic class resolution from gems or modules. The diff shows the addition of files for \Annotatable\, \Annotation\, and \ClassLoader\, marking a significant shift in how types and classes are managed within the Puppet type system.

lib/puppet/pops/types · high confidence

Introduces a new issue reporting and adapter infrastructure in the parser

The parser now uses a new \IssueReporter\ and \Issues\ module to handle validation errors and warnings, replacing the previous error handling mechanism. This change introduces a structured \Adaptable\ pattern via \lib/puppet/pops/adaptable.rb\ and \lib/puppet/pops/adapters.rb\, which allows objects to carry additional context (like loaders or documentation) without modifying their core classes. The \IssueReporter\ centralizes how validation issues are formatted, logged, and raised as exceptions, ensuring consistent error messages and stack traces for all parser and semantic errors.

lib/puppet/pops · high confidence

Introduces a new, extensible loader architecture for Puppet entities

The loader system has been refactored to use a new base class hierarchy that supports a plugin-like architecture for loading functions, plans, tasks, and data types. This introduces new classes such as BaseLoader, DependencyLoader, and various instantiators (e.g., PuppetFunctionInstantiator, GenericPlanInstantiator) that handle the creation of these entities. The change also adds support for loading from multiple paths and environments, allowing for more flexible and modular entity discovery and loading.

lib/puppet/pops/loader · high confidence

Introduces new library entry points and configuration for Hiera and PAL

Adds new files to the lib directory to support the Puppet as a Library (PAL) API and Hiera integration. The \lib/puppet.rb\ file now enforces a minimum Ruby version (3.1.0) and initializes the load path with vendored modules. A new \lib/hiera\_puppet.rb\ file provides a wrapper for Hiera lookups, while \lib/puppet\_pal.rb\ serves as the entry point for the PAL API. Additionally, \lib/puppet\_x.rb\ is introduced to standardize the namespace for Puppet extensions.

lib · high confidence

New HTTP, Log, and Store report processors

Added new report processors for sending reports via HTTP/HTTPS, logging to local destinations, and storing reports to disk. The HTTP processor supports basic authentication and metric tracking, the log processor forwards logs to syslog or other local destinations, and the store processor writes YAML reports to a configurable directory with secure permissions. These processors provide users with flexible options for managing Puppet run reports.

lib/puppet/reports · high confidence

New Puppet RDoc HTML generator for documentation

A new \PuppetGenerator\ class has been added to \lib/puppet/util/rdoc/generators/puppet\_generator.rb\. This generator is responsible for producing HTML documentation for Puppet manifests, handling the creation of directory hierarchies, index files, and the mapping of Puppet entities (modules, classes, definitions, resources, nodes, plugins, and facts) to RDoc objects for the documentation engine.

lib/puppet/util/rdoc/generators · high confidence

New RDoc code objects and parser for Puppet documentation generation

Added new files \lib/puppet/util/rdoc/code\_objects.rb\ and \lib/puppet/util/rdoc/parser.rb\ to support the RDoc-based documentation generator. The \code\_objects.rb\ file introduces custom RDoc classes (\PuppetTopLevel\, \PuppetModule\, \PuppetClass\, \PuppetNode\) to represent and document Puppet language structures like modules, classes, nodes, and plugins. The \parser.rb\ file provides the parser that traverses the Puppet AST to instruct RDoc about these structures, enabling the generation of HTML documentation for Puppet manifests and Ruby plugins.

lib/puppet/util/rdoc · high confidence

New Rake tasks for generating documentation, benchmarks, and test fixtures

The project has moved Rake tasks into the rakelib directory and introduced several new automation tasks. Developers can now generate documentation references (configuration, metaparameters, reports, functions, and resource types) via the new \rake references:\*\ tasks. Additionally, new tasks have been added to generate man pages (\rake gen\_manpages\), create certificate test fixtures (\rake gen\_cert\_fixtures\), generate an AST model (\rake gen\_pcore\ast\), and run memory or CPU benchmarks (\rake benchmark:\\).

rakelib · high confidence

New X.509 certificate and CRL management components

The X.509 module now includes a \CertProvider\ class and a \PemStore\ module to handle loading, saving, and managing PEM-encoded certificates, private keys, and CRLs. The \CertProvider\ introduces methods to save and load CA certificates and CRLs, manage CRL and CA bundle update timestamps, and save private keys with optional encryption. The \PemStore\ module provides utilities for reading and writing PEM files, including atomic file replacement and permission management. These changes support more robust handling of SSL/TLS assets within Puppet.

lib/puppet/x509 · high confidence

New acceptance test utility libraries for Puppet

Added a suite of new utility modules in the acceptance test framework to support various testing scenarios. These include \AgentFqdnUtils\ for resolving fully qualified domain names, \AixUtil\ for managing AIX object attributes, \ClassifierUtils\ for interacting with the Puppet Classifier API, \EnvironmentUtils\ for managing test environments, \I18nUtils\ and \I18nDemoUtils\ for internationalization testing, \ModuleUtils\ for module path and installation checks, and \PuppetTypeTestTools\ for generating and asserting on Puppet resource manifests. Each utility includes corresponding spec tests to verify their behavior.

acceptance/lib/puppet/acceptance · high confidence

New catalog select action to filter resources by type

A new 'select' action has been added to the Puppet catalog face, allowing users to retrieve a catalog and filter it for resources of a given type. This feature enables filtering by specific resource types (e.g., 'file') or all types ('\*'), with output rendered in console or JSON formats.

lib/puppet/face/catalog · high confidence

New confine types for boolean, any, and variable checks

Puppet now supports new confine types: 'any' matches if any condition is true, 'true' and 'false' check boolean values (including lazy evaluation via lambdas), 'exists' checks file existence, 'feature' checks for available features, and 'variable' checks Facter or Puppet settings. These changes allow more flexible and precise conditionals in manifests and configuration files.

lib/puppet/confine · high confidence

New file server configuration parser

A new parser class has been introduced to handle the parsing of the file server configuration file. This component is responsible for reading the configuration, identifying mount points (such as modules, plugins, scripts, tasks, and locales), and validating the resulting mount objects. It also handles error reporting for invalid or unsupported configuration entries.

_lib/puppet/file\serving/configuration · high confidence

New file serving mount types for modules, plugins, scripts, tasks, and locales

The file serving system now supports dedicated mount types for modules, plugins, plugin facts, scripts, tasks, and locales. This allows the Puppet server to serve these specific file types from their respective directories within modules, enabling features like pluginsync and task execution directly from the file server.

_lib/puppet/file\serving/mount · high confidence

New module management commands: install, upgrade, uninstall, changes, and list

The \puppet module\ face now includes new actions for managing modules: \install\ to install modules from the Puppet Forge or release archives; \upgrade\ to update installed modules to newer versions; \uninstall\ to remove modules; \changes\ to show modified files in an installed module; and \list\ to display installed modules with dependency information. These commands provide a unified interface for module lifecycle management, supporting options for target directories, version constraints, and dependency handling.

lib/puppet/face/module · high confidence

New reference documentation for configuration, indirection, metaparameters, providers, reports, types, and functions

The \lib/puppet/reference\ directory now contains new Ruby files that generate structured reference documentation for key Puppet concepts. Specifically, it adds documentation for configuration settings (including updated default paths for directories like \vardir\, \confdir\, and \rundir\), the indirection system (listing all indirection types and their termini), all available metaparameters, available functions, available report processors, all resource types with their parameters and features, and a provider suitability report that indicates which providers are valid for the current host. These files replace the previous approach of generating these references via \puppetdoc\ or external classes, centralizing the generation logic within the \Puppet::Util::Reference\ framework.

lib/puppet/reference · high confidence

New syntax checkers for Base64, EPP, JSON, and PP

Added new syntax checkers for Base64, EPP, JSON, and PP. These checkers validate the syntax of these content types within Puppet manifests and templates, providing specific error messages for invalid Base64, EPP, JSON, and PP content. This allows users to catch syntax errors in these specific content types during development and validation.

_lib/puppet/syntax\checkers · high confidence

POSIX FFI interface for user group lookups

The codebase now includes a new FFI binding for the POSIX \getgrouplist\ function, allowing Puppet to query a user's supplementary groups directly via the C library. This is supported by a new \Constants\ module that defines \MAXIMUM\_NUMBER\_OF\_groups\ as 65, providing a reasonable upper bound for group lookups. These additions enable more efficient user group resolution on POSIX systems.

lib/puppet/ffi/posix · high confidence

Structured error handling for the Puppet Module Tool

The \lib/puppet/module\_tool/errors\ directory now contains a comprehensive set of structured error classes for the Puppet Module Tool. This includes a base \ModuleToolError\ and specific error types for installation conflicts, missing dependencies, invalid module names, and upgrade/downgrade restrictions. Users will now see detailed, multi-line error messages that explain the cause of failures (such as dependency cycles or version mismatches) and provide specific command-line workarounds (like \--force\ or \--ignore-dependencies\) to resolve them.

_lib/puppet/module\tool/errors · high confidence

Architecture

Error datatype moved to dedicated directory

The Error datatype implementation has been moved to a new lib/puppet/datatypes/ directory structure. This change reorganizes the codebase by relocating the Error datatype file and adding a frozen\_string\_literal magic comment, improving code organization and maintainability.

lib/puppet/datatypes · high confidence

Extracted POSIX and Windows file providers for ownership and permissions management

The file provider logic for managing file ownership (owner, group) and permissions (mode) has been extracted into dedicated platform-specific providers: \lib/puppet/provider/file/posix.rb\ and \lib/puppet/provider/file/windows.rb\. This refactoring separates the implementation details for POSIX systems (using \chown\/\chmod\) and Windows systems (using Win32 APIs and ACLs) from the generic provider, allowing each platform to handle its own security and permission management logic independently.

lib/puppet/provider/file · high confidence

Extracted property implementations into dedicated classes

The implementation for the 'ensure', 'boolean', 'keyvalue', 'list', and 'ordered\_list' properties has been moved from the base Puppet::Property class into their own respective files (lib/puppet/property/ensure.rb, boolean.rb, keyvalue.rb, list.rb, ordered\_list.rb). This refactoring isolates the logic for each property type, making the codebase more modular and easier to maintain.

lib/puppet/property · high confidence

File type refactored into separate property and parameter files

The \Puppet::Type::File\ type has been refactored by splitting its implementation into individual files for each property and parameter (e.g., \checksum.rb\, \content.rb\, \mode.rb\, \owner.rb\, \group.rb\, \selcontext.rb\, \data\_sync.rb\). This structural change organizes the codebase by separating concerns, making the file type's attributes easier to maintain and extend without modifying a single monolithic type definition file.

lib/puppet/type/file · high confidence

Refactor configurer into modular handlers

The monolithic configurer logic has been split into dedicated handler classes: Downloader, FactHandler, and PluginHandler. This refactoring isolates the responsibilities for downloading plugins and facts, making the code easier to test and maintain.

lib/puppet/configurer · high confidence

Refactor of the Puppet type system and resource management

The \lib/puppet/type\ directory underwent a massive refactoring of the core type system, transitioning from the legacy \TransObject\ and \TransBucket\ classes to the modern \Puppet::Resource\ and \Puppet::Resource::Type\ architecture. This change introduces a centralized resource graph for managing dependencies and execution order, replacing the previous \@children\ array approach. Additionally, the \Type\ class now supports implicit 'identity' transformations, and the resource graph correctly propagates dependencies up and down through components. These changes improve how Puppet handles resource relationships, graph generation, and internal object management.

lib/puppet/type · high confidence

Refactored Puppet type management into a dedicated Manager module

The logic for managing Puppet resource types (loading, caching, and creating types) has been extracted from the main Puppet::Type class into a new Puppet::MetaType::Manager module. This change improves code organization and clarity by separating type management responsibilities, while maintaining the same public API for defining and accessing types.

lib/puppet/metatype · high confidence

Refactored the Faces and Actions system into a new modular interface

The internal implementation of the Puppet Faces and Actions system has been refactored into a new set of classes in lib/puppet/interface, including Action, ActionBuilder, ActionManager, Option, OptionBuilder, and OptionManager. This change introduces a more structured and modular approach to defining and managing CLI faces and their actions, improving code organization and maintainability while preserving the existing public API for face and action definitions.

lib/puppet/interface · high confidence

Restructure indirection terminus classes into dedicated files

The indirection system has been refactored to organize terminus classes into their own dedicated files under the \lib/puppet/indirector\ directory. New files such as \code.rb\, \exec.rb\, \face.rb\, \hiera.rb\, and \json.rb\ have been introduced to handle specific indirection types, replacing the previous structure where terminus classes were often nested or grouped differently. This change improves code organization and makes it easier to maintain and extend the indirection subsystem by clearly separating each terminus implementation.

lib/puppet/indirector · high confidence

Behavioural changes

Add Debian repository fixture for version range support

A new Release file has been added to the Debian repository fixture, defining the archive, component, origin, label, and architecture. This provides the necessary metadata for the new version range support in the apt module.

acceptance/fixtures/debian-repo · high confidence

Add benchmark for qualified variable lookup performance

A new benchmark scenario has been added to measure catalog compilation performance with many qualified variable lookups. The change introduces a benchmarking script and associated template files that generate a test module with 500 file resources, allowing users to evaluate the impact of qualified variable resolution on compilation speed.

_benchmarks/fq\_var\lookup · medium confidence

Add default gem configuration for acceptance tests

A new configuration file at acceptance/config/gem/options.rb has been added to the project. This file defines the default gem source as 'git', ensuring that the acceptance test suite uses a sane Ruby environment for gem dependencies.

acceptance/config/gem · high confidence

Add environments API endpoint for the server

A new file \lib/puppet/network/http/api/master/v3/environments.rb\ has been added to the codebase. This file acts as a bridge, requiring the existing server-side environments API implementation (\puppet/network/http/api/server/v3/environments\) from the master's perspective, effectively exposing the server's environments endpoint through the master's v3 API namespace.

lib/puppet/network/http/api/master/v3 · high confidence

Added Hiera 5 environment and global lookup benchmarks

New benchmarking scripts and configuration files have been added for \benchmarks/hiera\_env\_lookup\ and \benchmarks/hiera\_global\_lookup\. These introduce performance tests for Hiera 5 lookups within an environment and global lookups, each generating 100 iterations of 100 lookups against nested hash structures containing 100 elements.

_benchmarks/hiera\_env\_lookup, benchmarks/hiera\_global\lookup · medium confidence

Added benchmark for Hiera configuration interpolation performance

A new benchmark scenario has been introduced to measure the performance of Hiera lookups when dealing with a large number of interpolations in the Hiera configuration. This addition allows users to evaluate how the system handles heavy usage of interpolations in Hiera config files.

_benchmarks/hiera\_conf\interpol · high confidence

Added comprehensive documentation for puppet.conf settings

The man page for puppet.conf has been regenerated and expanded to include detailed descriptions, default values, and usage notes for all configuration settings, including agent\_catalog\_run\_lockfile, allow\_duplicate\_certs, and autosign. This update ensures the documentation accurately reflects the current state of the configuration file, providing users with complete reference material for managing Puppet's behavior.

man/man5 · high confidence

Automated archiving of system and application logs after acceptance tests

A new post-suite step automatically archives logs and application data from all test hosts during the teardown phase. The script captures platform-specific logs (Windows, Linux, Solaris, AIX, macOS, Fedora, Debian/Ubuntu) and relevant system logs (syslog, messages, journalctl) into a single archive file named with the job name, build ID, and date. This ensures that diagnostic information is preserved for every test run, regardless of the test outcome.

acceptance/teardown · high confidence

Centralize and refactor Forge interaction with dedicated error handling and caching

The Forge interaction code in lib/puppet/forge has been restructured into dedicated classes for better maintainability and error handling. A new lib/puppet/forge/cache.rb provides a centralized mechanism for caching remote files locally. A new lib/puppet/forge/errors.rb introduces specific exception classes (ForgeError, SSLVerifyError, CommunicationError, ResponseError) to provide detailed, user-friendly error messages for various failure modes. The lib/puppet/forge/repository.rb refactors the repository logic to use these new components, including improved SSL context handling and a cleaner HTTP request flow that leverages the new cache and error classes.

lib/puppet/forge · high confidence

Centralized feature detection for system capabilities

Puppet has reorganized its feature detection logic by moving individual feature checks (such as syslog, posix, microsoft\_windows, ldap, openssl, sqlite, hiera, minitar, manages\_symlinks, puppetserver\_ca, bolt, cfpropertylist, eventlog, hiera\_eyaml, hocon, libuser, msgpack, pe\_license, pson, selinux, ssh, telnet, and zlib) into separate files within the \lib/puppet/feature/\ directory. This change consolidates how Puppet determines which system capabilities and libraries are available, making it easier to add or modify feature checks in the future.

lib/puppet/feature · high confidence

Custom RDoc template for improved Puppet documentation styling

The RDoc HTML template for Puppet documentation has been replaced with a custom template (puppet.rb) that applies specific CSS styles. This change alters the visual appearance of the generated documentation, introducing a cleaner layout with distinct header colors, improved font sizes, and better formatting for code blocks and navigation elements.

lib/puppet/util/rdoc/generators/template · high confidence

Enhanced method and class documentation with visibility, abstract, deprecated, and DSL markers

The YARD documentation templates have been updated to display additional metadata about methods and classes. Method signatures now explicitly show visibility (public/private/protected), abstract status, deprecation status, and DSL classification. The item summary for classes and modules also includes these markers, along with read/write-only attributes and inheritance information. This provides users with more detailed information about the API surface directly in the generated documentation.

yardoc · high confidence

Exec resource now uses distinct providers for POSIX and Windows

The exec resource type is now backed by separate providers: \posix\ and \shell\ for Unix-like systems, and \windows\ for Windows. The \posix\ provider executes commands directly without a shell, while the \shell\ provider passes commands through \/bin/sh\ to enable shell features like globbing. On Windows, the \windows\ provider executes binaries directly, requiring explicit invocation of \cmd.exe\ or \powershell\ for shell-based commands. This separation allows for safer, more predictable execution on each platform.

lib/puppet/provider/exec · high confidence

Expanded help output for all faces and actions

The help system now provides detailed, structured documentation for every face and action, including usage, options, descriptions, examples, and author information. This change completes the help text for all faces and actions, ensuring that users can access comprehensive documentation via the CLI and man pages.

lib/puppet/face/help · high confidence

Extracted Windows FFI bindings into a dedicated module

Puppet has extracted Windows-specific FFI (Foreign Function Interface) bindings from the general utility modules into a new, dedicated \Puppet::FFI::Windows\ namespace. This refactoring separates Windows API types, constants, functions, and structs into their own files (\api\_types.rb\, \constants.rb\, \functions.rb\, \structs.rb\), improving code organization and maintainability for Windows platform support.

lib/puppet/ffi/windows · high confidence

Fixes for resource metaparameter handling and scope lookups

The parser now correctly handles multiple metaparameters being added to resources, ensuring that metaparameters are only added to resources that do not explicitly set them. Additionally, the parser fixes issues with scope lookups, including ensuring that variables are looked up in the correct inherited scope and that qualified variable names are handled properly. The parser also corrects the behavior of the 'defined' function to handle qualified variable names and ensures that undefined variables return an empty string instead of raising an exception.

lib/puppet/parser · medium confidence

Improved error handling and logging for provider prefetch failures

Puppet now logs prefetch exceptions and limits the rescue list to prevent silent failures. This change ensures that when a provider fails to prefetch, the error is properly captured and reported, making it easier to diagnose issues with resource management.

lib/puppet · high confidence

Improved error reporting for exec resources

Exec resources now capture and report stderr output, allowing users to see the full output of failed commands rather than just a generic failure message. This change ensures that diagnostic information from the executed command is available in the Puppet logs, making it easier to troubleshoot issues with external commands.

lib/puppet/util · high confidence

Introduce dedicated terminus classes for file metadata retrieval

The file metadata indirection layer has been refactored to use specific terminus classes for each retrieval method. A new \Selector\ terminus routes requests to the appropriate handler: \File\ for local filesystem access, \FileServer\ for the internal file server, \Http\ for direct HTTP/HTTPS sources, and \Rest\ for the Puppet Server REST API. This change separates concerns by creating distinct classes for each source, replacing the previous monolithic or less structured approach, and ensures that metadata requests are handled by the correct implementation based on the source type.

_lib/puppet/indirector/file\metadata · high confidence

Introduce modular profiler architecture with new measurement types

The profiling utility has been refactored into a modular architecture, replacing the previous monolithic implementation with specialized profilers for different metrics. This includes a new \Aggregate\ profiler for hierarchical metric aggregation, an \AroundProfiler\ to manage the execution context for wrapped code blocks, a \Logging\ base class for structured output, a \WallClock\ for wall-time measurement, and an \ObjectCounts\ profiler to track memory object allocations. These components work together to provide more granular and structured profiling data for debugging and performance analysis.

lib/puppet/util/profiler · high confidence

Introduce new Module Tool application classes

The Puppet Module Tool (PMT) is refactored into a new set of application classes (Application, Checksummer, Installer, Uninstaller, Unpacker, and Upgrader) within lib/puppet/module\_tool/applications/. This change introduces a structured, object-oriented approach to module management, replacing the previous monolithic or ad-hoc implementations. Users will see improved error handling, better dependency resolution via SemanticPuppet, and more robust handling of module installation, upgrade, and uninstallation processes.

_lib/puppet/module\tool/applications · high confidence

Introduce new internal function dispatching architecture

The internal function invocation mechanism has been refactored to use a new \Dispatch\ and \Dispatcher\ system. This change introduces a structured way to match function signatures and weave arguments, allowing functions to receive injected dependencies like the calling scope or compiler. For users, this improves the robustness of function calls and enables better error reporting when function arguments do not match expected types.

lib/puppet/pops/functions · medium confidence

Introduce new node indirector terminus classes

The node indirector now includes dedicated terminus classes for each storage and transport mechanism, including exec, json, memory, msgpack, plain, rest, store\_configs, and yaml. This refactors the node lookup logic into separate, focused classes, allowing each to handle its specific serialization or protocol (e.g., REST, YAML, MessagePack) independently.

lib/puppet/indirector/node · high confidence

Introduce v3 API wrapper for the server namespace

A new file lib/puppet/network/http/api/master/v3.rb was added to serve as a compatibility wrapper that requires the corresponding server-side v3 API implementation. This change aligns the master-side routing with the broader HTTP API rename from 'master' to 'server', ensuring that requests to the v3 endpoint are correctly delegated to the server's v3 API logic.

lib/puppet/network/http/api/master · high confidence

Introduction of dedicated Param class for resource parameters

The parser now uses a dedicated \Puppet::Parser::Resource::Param\ class to represent resource parameters, replacing the previous implementation. This change introduces a structured class with explicit attributes (name, value, source, add, file, line) and a constructor that enforces the presence of a name, ensuring that parameter handling is more robust and consistent within the parser.

lib/puppet/parser/resource · high confidence

New acceptance test helper libraries

Added new Ruby library files for acceptance testing: acceptance/lib/acceptance\_spec\_helper.rb configures RSpec with Mocha, and acceptance/lib/helper.rb requires the beaker-puppet gem, supporting the migration to Beaker 4 and improved test infrastructure.

acceptance/lib · medium confidence

New modular scheduler with splay support

The scheduler has been refactored into a new modular structure, introducing dedicated classes for jobs, the scheduler loop, and timing. This change introduces support for splay (randomized delays) on scheduled jobs, allowing administrators to configure a splay limit to distribute agent runs more evenly. The scheduler now uses a timer abstraction for waiting and time retrieval, and the daemon loop has been updated to work with this new job-based scheduling system.

lib/puppet/scheduler · high confidence

Refactor filebucket file storage to use a local file-based terminus

The filebucket file storage mechanism has been refactored to use a dedicated local file-based terminus (lib/puppet/indirector/file\_bucket\_file/file.rb) for storing and retrieving backed-up files on the local filesystem, replacing the previous implementation. This change introduces a new \File\ class that handles \find\, \head\, \save\, and \list\ operations directly against the file system, while a \Rest\ terminus handles remote requests. The \Selector\ routes HTTPS requests to the REST terminus and other requests to the local file terminus. This improves reliability by ensuring files are stored locally on the master, with specific handling for corrupted backups and duplicate files.

_lib/puppet/indirector/file\_bucket\file · high confidence

Refactor graph implementation with new prioritization and tree map classes

The graph implementation in lib/puppet/graph has been refactored to use a new RbTreeMap for sorted key-value storage and a new Key class for ordering. A new Prioritizer base class and SequentialPrioritizer implementation manage resource priorities, which are used by the RelationshipGraph to determine execution order. The SimpleGraph class has been updated to use these new components, improving how dependencies and priorities are handled during graph traversal.

lib/puppet/graph · high confidence

Refactor parameter handling into dedicated classes

The \lib/puppet/parameter\ directory now contains new, dedicated classes for handling specific parameter types: \Boolean\, \PackageOptions\, \Path\, \Value\, and \ValueCollection\. This refactoring separates concerns, with \Value\ and \ValueCollection\ managing valid values and aliases, while specialized parameter classes handle type-specific munging and validation logic (e.g., path validation, boolean coercion).

lib/puppet/parameter · high confidence

Refactor resource collection logic into dedicated collector classes

The resource collection logic has been refactored from the evaluator into a new set of classes in lib/puppet/pops/evaluator/collectors. This introduces AbstractCollector, CatalogCollector, ExportedCollector, and FixedSetCollector, each handling specific collection scenarios (catalog, exported, and fixed-set resources). This change improves code organization and separates concerns within the POPS evaluator, making the collection process more modular and maintainable.

lib/puppet/pops/evaluator/collectors · high confidence

Refactored file content indirection to support multiple backends

The file content indirection now uses a selector terminus to route requests to specific backends: a local file system, the Puppet file server, or a REST HTTP interface. This change enables file serving to work across modules, the local file system, and the traditional file server, while also ensuring file content is returned as a binary string via the REST API.

_lib/puppet/indirector/file\content · high confidence

Refactored service provider architecture with a new base provider

The service type's provider hierarchy was restructured by introducing a new \base\ provider that handles core process management logic, such as detecting running processes via \ps\ and executing start/stop/status commands. Existing providers like \init\, \debian\, and \bsd\ were updated to inherit from this new base, centralizing common functionality and improving how service states are determined and managed across different operating systems.

lib/puppet/provider/service · high confidence

Refactored settings system with new setting types and config parsing

The settings system has been refactored to support a variety of new setting types, including :alias, :array, :boolean, :certificate\_revocation, :directory, :duration, :enum, :file\_or\_directory, :http\_extra\_headers, :integer, :port, :priority, :server\_list, :string, :symbolic\_enum, :terminus, and :ttl. This enables more precise validation and handling of configuration values, such as time intervals, port numbers, and environment-specific settings. Additionally, the config file parser has been restructured into separate classes (ConfigFile, IniFile) to better handle sections and metadata, and environment configuration is now managed through a dedicated EnvironmentConf class.

lib/puppet/settings · high confidence

Refactored tar extraction to use separate GNU and Minitar backends

The tarball handling in the module tool has been refactored into two distinct backends: a new GNU implementation that uses the system 'tar' command and a Minitar-based implementation that uses the 'minitar' Ruby library. The Minitar backend now explicitly validates tar entries to ignore non-standard PAX headers and ensures that file permissions are correctly sanitized (directories set to 0755, files to 0644 or 0755 depending on executability) and ownership is standardized. This change improves cross-platform compatibility and security by preventing path traversal and ensuring consistent file modes during extraction.

_lib/puppet/module\tool/tar · high confidence

Refactored transaction event handling and resource generation

The transaction logic has been refactored to use a callback-based event system. A new \Puppet::Transaction::EventManager\ class now manages event queuing and processing, allowing resources to subscribe to and respond to events. Additionally, a new \Puppet::Transaction::AdditionalResourceGenerator\ class handles the generation of dependent resources, and \Puppet::Transaction::Persistence\ manages storing system values for corrective change detection. These changes improve the modularity and testability of the transaction process.

lib/puppet/transaction · high confidence

Replace stdlib OptionParser with bundled Trollop for command-line parsing

The command-line option parser in lib/puppet/util/command\_line has been replaced with a bundled version of the Trollop library (v1.16.2). This change removes the dependency on Ruby's standard library OptionParser, allowing for more flexible argument parsing and consistent error handling within the Puppet codebase.

_lib/puppet/util/command\line · high confidence

Restructured acceptance test node configurations

The acceptance test node configuration files have been reorganized and cleaned up. The previous structure, which likely mixed different OS types or had inconsistent naming, has been replaced with a standardized set of YAML files for each supported operating system (CentOS, Debian, Oracle, Red Hat, Scientific Linux, SLES, Ubuntu, and Solaris). Each file defines the host roles (master, dashboard, database, agent) and platform details (e.g., el-5-i386, debian-6-amd64) for various test scenarios, ensuring consistent and clear configuration for the acceptance test suite.

acceptance/config/nodes/pe · high confidence

Separate lockfiles for agent disable and catalog run states

The agent's disable and catalog-run locking mechanisms have been refactored into dedicated modules (Disabler and Locker) backed by separate lockfiles. The disable state now uses a JSON lockfile (Puppet::Util::JsonLockfile) that can store a custom message, while the catalog-run lock uses a PID-based lockfile (Puppet::Util::Pidlock). This change isolates the two distinct locking concerns, allowing each to manage its own file path and state independently.

lib/puppet/agent · high confidence

Split FFI implementation into platform-specific modules

The generic FFI module has been split into separate, platform-specific modules for POSIX and Windows. This change organizes the Foreign Function Interface (FFI) code by separating POSIX and Windows implementations into their own directories, each requiring their respective API types, constants, and functions. This improves code organization and maintainability by isolating platform-specific logic.

lib/puppet/ffi · medium confidence

Updated EL repo acceptance fixture metadata

The acceptance test fixture for the EL repo has been regenerated, updating the repomd.xml metadata file. This ensures the test environment reflects the current state of the repository metadata, which is used by the rpm multiversion acceptance test.

acceptance/fixtures/el-repo · medium confidence

Updated SLES repository fixture with new metadata

The SLES repository fixture has been updated with a new repomd.xml file, which includes metadata for filelists, other, and primary package data. This change ensures the acceptance test fixture contains the necessary repository metadata for testing SLES package management.

acceptance/fixtures/sles-repo · medium confidence

Updated man pages for all Puppet subcommands

The manual pages for all Puppet CLI subcommands (including puppet agent, apply, catalog, config, describe, device, doc, epp, facts, etc.) have been regenerated and updated. This ensures the command-line help text and documentation reflect the current state of the software, including any recent changes to available options, arguments, and descriptions.

man/man8 · high confidence

Validation of resource relationships is extracted into a dedicated validator

The logic for validating resource relationships has been moved from the main compiler into a new \CatalogValidator\ system. This introduces a \RelationshipValidator\ that checks if referenced resources exist, providing specific file and line information when a reference is missing or invalid. This change also adds a \CatalogValidationError\ to handle these validation failures.

lib/puppet/parser/compiler · high confidence

Windows service now logs to the Windows Event Log

The Windows service daemon has been updated to write its logs to the Windows Event Log, providing better integration with Windows system monitoring tools. The daemon script and Ruby implementation now utilize the Windows Event Log API for logging, ensuring that service events are recorded in the system's event viewer rather than just local files.

ext/windows/service · high confidence

Test coverage

Add OpenRC service provider test fixtures; Add acceptance test for resource ordering on the master; Add acceptance tests for package resource behavior; Add integration test for compiler localization; Add integration tests for RDoc parser; Add integration tests for catalog compilation and filtering; Add integration tests for the file metadata indirection; Add unit tests for HTTP and Store report processors; Add unit tests for indirection terminus classes; Add unit tests for the POSIX, Shell, and Windows exec providers; Add unit tests for the file type's checksum, content, and property behaviors; Add unit tests for the module face actions; Added Apache module management fixtures for Debian-based systems; Added Gentoo rc\_update\_show fixture for service runlevel mapping; Added Hiera data provider test fixtures for environments; Added OpenBSD rcctl\_getall test fixture; Added SMF service fixture data for unit tests; Added Windows-specific acceptance test fixtures; Added a fixture for testing syntax errors in face definitions; Added acceptance test for Hiera lookup data parser function; Added acceptance test for pluginsync of feature and function definitions; Added acceptance tests for AIX package providers; Added acceptance tests for Puppet language features; Added acceptance tests for SSL certificate and trust features; Added acceptance tests for Solaris IPS package management; Added acceptance tests for agent lockfile, JSON catalog parsing, and last\_run\_summary.yaml permissions; Added acceptance tests for class parameterization and resource inclusion; Added acceptance tests for environment resolution and directory environments; Added acceptance tests for environment variable handling and deprecation warnings; Added acceptance tests for i18n disable and translation fallback; Added acceptance tests for module i18n translations; Added acceptance tests for multiple CVEs; Added acceptance tests for pluginsync scenarios; Added acceptance tests for report submission and catalog caching; Added acceptance tests for the Puppet face subsystem; Added acceptance tests for the autoloader; Added acceptance tests for the user resource; Added acceptance tests for tidy resource behavior; Added benchmark for environment lookup performance; Added benchmark for missing type caching; Added benchmarks for Hiera lookups; Added empty site.pp fixture for Puppet spec tests; Added fixture for local gem list in Puppetserver gem provider tests; Added integration test fixtures for a custom Puppet resource type; Added integration tests for Autoload, Execution, and Settings utilities; Added integration tests for DirectFileServer; Added integration tests for Puppet::Node::Environment and Puppet::Node::Facts; Added integration tests for Puppet::Transaction::Report; Added integration tests for Windows Process utilities; Added integration tests for Windows utility classes; Added integration tests for agent logging behavior; Added integration tests for all Puppet CLI applications; Added integration tests for core Puppet components; Added integration tests for environment settings and default manifests; Added integration tests for exec, file, notify, package, and tidy types; Added integration tests for indirected HTTP routes; Added integration tests for network formats and HTTP connection pooling; Added integration tests for resource catalog and type collection loading; Added integration tests for the Facter fact indirection; Added integration tests for the HTTP client; Added integration tests for the Puppet parser; Added integration tests for the Windows file provider; Added integration tests for the file content indirection; Added l10n module fixture for integration testing; Added lexer test fixtures for parser unit tests; Added new RSpec matchers for testing catalog, JSON, and tokenization; Added nginx module fixture for integration tests; Added shared examples for RHEL package provider tests; Added shared test behaviors for Puppet components; Added shared test contexts for checksums, digests, HTTPS, i18n, providers, and types; Added spec helper modules for testing infrastructure; Added systemd test fixtures for unit file parsing; Added test coverage for TestHelper environment cleanup; Added test fixture for Microsoft root certificate; Added test fixture for basic RDoc documentation scenarios; Added test fixture for environment data provider; Added test fixture for mixed-encoding ps output; Added test fixture for module abc with data provider function; Added test fixture for the obsolete huzzah face; Added test fixtures and helpers for certificate and indirection testing; Added test fixtures for 4x functions calling 3x functions; Added test fixtures for AIX crontab parsing; Added test fixtures for AIX object parsing; Added test fixtures for AIX user provider; Added test fixtures for Hiera lookup functions; Added test fixtures for OpenBSD package provider; Added test fixtures for POPS resource type loading; Added test fixtures for Puppet Faces; Added test fixtures for SSH key purging; Added test fixtures for Sun package metadata; Added test fixtures for deferred catalog caching; Added test fixtures for environment function provider; Added test fixtures for inter-module function calls; Added test fixtures for legacy function loading edge cases; Added test fixtures for manifest directory parsing; Added test fixtures for mixed 4x/3x function loading; Added test fixtures for module 'two' to support data provider isolation; Added test fixtures for module data provider; Added test fixtures for moduleb to support inter-module call testing; Added test fixtures for old-style certificate extensions and requests; Added test fixtures for production environment; Added test fixtures for recursive manifest parsing; Added test fixtures for tagmail report generation; Added test fixtures for the Hiera data provider; Added test fixtures for the jamtur01-apache module; Added test fixtures for the lookup function; Added test fixtures for the lookup function; Added test helpers for JSON, Memory, and MessagePack indirectors; Added test helpers for the module tool; Added tests for PSON encoding and parsing; Added tests for X.509 certificate and CRL loading, saving, and deletion; Added unit test fixture for non-module loader; Added unit tests for AIX, AppDmg, APT, APTitude, and APT-RPM package providers; Added unit tests for DirectoryService provider; Added unit tests for FileBucket components; Added unit tests for Forge error handling and repository interactions; Added unit tests for HTTP API routing and environment endpoints; Added unit tests for HTTP service implementations; Added unit tests for Hiera and None data binding terminuses; Added unit tests for Hiera::Scope behavior; Added unit tests for POSIX and Windows file providers; Added unit tests for PathPattern and Uniquefile; Added unit tests for Pops serialization and data conversion; Added unit tests for Puppet::Parser::Resource::Param; Added unit tests for SELinux file context attributes; Added unit tests for Timespan and Timestamp types; Added unit tests for Windows package providers; Added unit tests for agent locking mechanisms; Added unit tests for application commands; Added unit tests for catalog indirector terminuses; Added unit tests for concurrent locking and thread-local singleton patterns; Added unit tests for create\_resources syntax error handling; Added unit tests for facts indirection terminuses; Added unit tests for file serving mount classes; Added unit tests for file\_content indirectors; Added unit tests for function and Hiera data providers; Added unit tests for gettext configuration and module translation loading; Added unit tests for log destinations; Added unit tests for multiple CLI faces; Added unit tests for network device configuration parsing; Added unit tests for new and modified functions; Added unit tests for new profiler implementations; Added unit tests for new settings types and refactored config parsing; Added unit tests for package version parsing and range validation; Added unit tests for package\_settings validation and behavior; Added unit tests for parameter types; Added unit tests for parser AST nodes; Added unit tests for parser functions; Added unit tests for resource catalog, status, and type classes; Added unit tests for resource types; Added unit tests for the AtFork utility module; Added unit tests for the Network Device Transport base class; Added unit tests for the POPS loader system; Added unit tests for the POPS model and PN transformer; Added unit tests for the POPS parser lexer; Added unit tests for the POPS resource type implementation; Added unit tests for the Puppet type system; Added unit tests for the PuppetOptionParser utility; Added unit tests for the RAL and StoreConfigs resource indirections; Added unit tests for the TrustedInformation context; Added unit tests for the file server configuration parser; Added unit tests for the file serving subsystem; Added unit tests for the graph module components; Added unit tests for the module tool's tar handling; Added unit tests for the new HTTP client, DNS resolver, and service routing; Added unit tests for the new HTTP routing and connection components; Added unit tests for the new Lookup framework; Added unit tests for the new interface system components; Added unit tests for the scheduler, Job, and SplayJob components; Added unit tests for transaction components; Added unit tests for user providers on AIX, HP-UX, OpenBSD, and Solaris; Expanded acceptance test coverage for core Puppet behaviors; Expanded acceptance test coverage for the file resource; Expanded acceptance tests for Hiera lookup and configuration; Expanded acceptance tests for service resource management across platforms; Expanded test coverage for the unit test suite; Introduce Puppet::Test::TestHelper for consistent test isolation; Introduce spec\_helper.rb to centralize test configuration and helpers; New Windows acceptance tests for exit codes, file permissions, and service state; New acceptance test utilities for Windows package and service management; New acceptance tests for UTF-8 character handling; New acceptance tests for static catalogs, UTF-8 support, and catalog UUID correlation; Updated SSL test fixtures with new keys and certificates.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 34 → 54 (+20.3)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 91 → 56 (-34.7)
  • Architecture 94 → 98 (+3.7)
  • Maturity 59 → 53 (-6.1)
  • Readiness 27 → 48 (+20.5)
  • Security 15 → 70 (+55.0)
  • Accessibility 74 (new)

Resolved (52)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • Duplicated block (10 lines × 3) (lib/puppet/indirector/catalog/compiler.rb)
  • Duplicated block (11 lines × 2) (lib/puppet/util/windows/com.rb)
  • Duplicated block (12 lines × 2) (lib/puppet/util/windows/security.rb)
  • Duplicated block (13 lines × 2) (lib/puppet/util/rdoc/generators/puppet_generator.rb)
  • Duplicated block (16 lines × 2) (lib/puppet/pops/types/type_parser.rb)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 32 more

New (633)

  • AbstractPathBasedModuleLoader.discover (cognitive 18) (lib/puppet/pops/loader/module_loaders.rb)
  • AbstractPathBasedModuleLoader.find (cognitive 65) (lib/puppet/pops/loader/module_loaders.rb)
  • AbstractPathBasedModuleLoader.find (cyclomatic 30) (lib/puppet/pops/loader/module_loaders.rb)
  • AbstractPathBasedModuleLoader.find_existing_path (cognitive 16) (lib/puppet/pops/loader/module_loaders.rb)
  • AccessOperator.access_PClassType (cognitive 23) (lib/puppet/pops/evaluator/access_operator.rb)
  • AccessOperator.access_PResourceType (cognitive 27) (lib/puppet/pops/evaluator/access_operator.rb)
  • AccessOperator.access_PResourceType (cyclomatic 22) (lib/puppet/pops/evaluator/access_operator.rb)
  • AccessOperator.access_String (cognitive 25) (lib/puppet/pops/evaluator/access_operator.rb)
  • Agent.run (cognitive 17) (lib/puppet/agent.rb)
  • Ambiguous naming for context/state management operations. lookup and restore suggest retrieving or reverting state, while mark_context and rollback_context suggest versioning or checkpointing. [] and []= are generic accessors that conflict in intent with lookup if they operate on the same global state, or are confusingly distinct if they operate on different scopes. Specifically, Puppet.lookup vs Puppet.[] is a strong candidate for redundancy if both access the global settings/context.
  • ChainedValues.convert (cognitive 16) (lib/puppet/settings.rb)
  • Change coupling: compiler.rb ↔ report.rb (lib/puppet/http/service/compiler.rb)
  • Change coupling: groupadd.rb ↔ useradd.rb (lib/puppet/provider/group/groupadd.rb)
  • Checker4_0.check_TypeMapping (cognitive 23) (lib/puppet/pops/validation/checker4_0.rb)
  • Client.connect (cognitive 23) (lib/puppet/http/client.rb)
  • Client.execute_streaming (cognitive 22) (lib/puppet/http/client.rb)
  • Closure.combine_values_with_parameters (cognitive 23) (lib/puppet/pops/evaluator/closure.rb)
  • Compiler.compile (cognitive 22) (lib/puppet/indirector/catalog/compiler.rb)
  • Compiler.compile (cyclomatic 16) (lib/puppet/indirector/catalog/compiler.rb)
  • Compiler.inline_metadata (cognitive 39) (lib/puppet/indirector/catalog/compiler.rb)
  • …and 613 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

puppetlabs/puppet was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e227c27540975c25aa22d533a52424a9d2fc886a — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.