You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 46ed1b0
Browse filesBrowse the repository at this point in the historyBrowse files
| E23 | 2 | The `pypi_{poetry,pdm,pipenv}.rs` backends repeat one skeleton: `load_*_project`, `classify_dependency`, `check_target_guards`, `wire_*`, `revert_*`. | 5.4 |#937| filed #937; shared wire/revert envelope + one `LockTarget` (no drift proven) |
29
29
| E24 | 2 | There are nine revert mechanisms (~3.5K lines). Target: one splice-record revert engine, with legacy ledger kinds adapted at load. | 2.1; 5.3; 5.8 |#989, #990| filed #989, #990; tracking #989, child 1 #990 (finish step ×12, four keep policies) |
30
30
| E25 | 3 | Per-backend copies: `cleanup_failed_stage`, `<eco>_service_copy` (cargo, composer, gem, golang), and the `service_preflight_names_exactly_*` test copied seven times. | 5.4; 5.8 |#906| filed #906; service-copy pipeline + cleanup (preflight test copies now share `plan_matches_grants`, out of scope) |
31
-
| E26 | 3 | JVM has two Maven backends. Target: merge `maven_repo.rs` into `jvm/` as `Shape::Single`. Its three artifact roots don't follow `<eco>/<uuid>`. | 5.7 |#971, #972, #973| filed #971, #972, #973; decided #973 (2026-10-07): one Maven backend, single poms planned as a reactor of one, legacy forward path deleted, legacy roots refused until `vendor --revert`; impl PR pending, lands before #972|
31
+
| E26 | 3 | JVM has two Maven backends. Target: merge `maven_repo.rs` into `jvm/` as `Shape::Single`. Its three artifact roots don't follow `<eco>/<uuid>`. | 5.7 |#971, #972, #973|in PR #1036; filed #971, #972, #973; decided #973 (2026-10-07): one Maven backend, single poms planned as a reactor of one, legacy forward path deleted, legacy roots refused until `vendor --revert`; lands before #972|
32
32
| E27 | 3 | The per-package call model needs ~3K lines of compensating machinery (`group_commit`, `durability`, `prestage`, `vendor_prefetch`, 22 `ParseMemo` statics, `ledger_snapshots`). Target: batched pure planners, after E21 and E24. | 2.4; 5.7 || to verify |
33
33
| E28 | 2 | Dead vendored scaffolding: `VendorSource` / `PackageSource` have one variant each, the `SERVICE_ECOSYSTEMS` refusal can never fire, `ServicePolicy::new` ignores its config, `vend_installed!` has no target, and several docs are stale. | 5.6; R11 |#800, #746| filed #800, #746; `VendorSource` predicates and `mem_blobs` are #746 (C23) |
34
34
| E29 | 3 |`registry_fetch.rs` (1.5K lines) is really archive extraction, integrity checks and the hosted-restore HTTP client, so it is misnamed and in the wrong place. | 5.6 |#1012| filed #1012; archive + Go module zip move; integrity (after #834) and registry bases (after #876) remain |
| C22 | 2 | Telemetry has 19 near-identical public wrappers (17 `track_*`, 2 `spawn_*`), builds a new HTTP client for every event, and the CLI threads token/org through ~45 call sites (review said 125), resolved two ways. Target: one `Telemetry` handle with `track(Event)` and a shared client. | 7.5; R15 |#770| filed #770|
28
28
| C23 | 2 | Dead code: `PatchSources::mem_blobs` is never `Some`; `VendorSource` predicates are always true; group commit captures `redirect-state.json`, which nothing in its scope writes; the `switched_off("group_commit")` oracle path. | 7.4; 7.6 #3; 5.6 |#746| filed #746; `Pypi`/`LauncherCache` channels are live (not dead) |
29
29
| C24 | 2 | Apply and rollback are mirror images: the verify types are identical, and `fold_copy_result`, the pnpm peer fan-out and the sidecar boundary are each written twice; the folds have drifted and both drop per-file records (#756). Target: one engine. | 7.4; 7.6 #4|#771, #772| filed #771; #772 fixed (#774), shared `store_copies::fan_out`; verify types + sidecar boundary remain |
30
-
| C25 | 2 |`--download-mode diff`, the default, re-downloads every blob on a cold cache, runs sequentially with no retry, and is the only user of `qbsdiff`. Making `file` the default is a decision; removing the duplicate fetch work is a refactor. | 7.4; R10 |#792|filed #792; decided 2026-10-07 (option A, v5): delete the diff path, `--download-mode` and `SOCKET_DOWNLOAD_MODE` outright; `patch/package.rs` stays; PR pending|
30
+
| C25 | 2 |`--download-mode diff`, the default, re-downloads every blob on a cold cache, runs sequentially with no retry, and is the only user of `qbsdiff`. Making `file` the default is a decision; removing the duplicate fetch work is a refactor. | 7.4; R10 |#792|in PR #1049; decided 2026-10-07 (option A, v5): delete the diff path, `--download-mode` and `SOCKET_DOWNLOAD_MODE` outright; `patch/package.rs` stays |
31
31
| C26 | 3 |`apply.lock` spends ~554 lines deleting the lock file on exit, and taking the lock replays the vendored group-commit journal, coupling vendored crash recovery to every command. | 7.4 |#808| in PR #1030; decided 2026-10-07 (option C): the lock stays transient; layering moves to #809/#793|
32
32
| C27 | 3 | Agent-mode sidecars don't handle Maven files at all. Verify whether in-place Maven patches leave stale checksum files behind. | 7.4 || rejected; Maven 3.9.11 ignores stale local `.jar.sha1` (built twice on 045d7ec); Gradle gap is #551|
33
33
| C28 | 3 | socket.yml builds a hand-made YAML tree on serde-saphyr's event parser to read 8 keys. Target: serde with `deny_unknown_fields`. | 7.5 || rejected; the tree implements the contract's scoped YAML refusals |
-[#1015](https://github.com/SocketDev/socket-patch/pull/1015): the vendored-reference scan (repair, orphan sweeps, `vendor` stranded gate, rollback) reads every `VENDORED` row; the eight `VENDORED_WRITES_UNMARKED` files get the role and the list is deleted; `vendor::path::parse_vendor_reference` accepts the bare uuid dir (NuGet feed, Maven repo). Issues #832, #958 (E61, E67). `ready`. Left: dead `eco == "maven2"` arm in `commands/vendor.rs` (busy file).
-[#876](https://github.com/SocketDev/socket-patch/pull/876): registry clients built through one `registry_client_builder` under `ApiTimeouts` (10 s connect, 60 s idle) instead of a 60 s total deadline; `registry_fetch::download` onto `read_capped`. Issue #872 (C49). Merged 2026-10-07 as `e2300cc` (+154 / −33 total).
0 commit comments