Skip to content

Commit c951323

Browse files
committed
refactor: #858 merged; C21 fixed, doc 07 atomic writes
1 parent 5d93afb commit c951323

3 files changed

Lines changed: 3 additions & 3 deletions

File tree

‎doc/07-infra-agent.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -73,7 +73,7 @@ The vendor policy also has three separate hand-written retry loops, plus a first
7373
- `1|true|yes|on|y|t` in `socket_cli_config::env_truthy`, which `update_notifier` imports, and the same set in the CLI's clap `parse_bool_flag`.
7474

7575
The narrow core match stays correct only because `apply_env_toggles` rewrites every truthy flag back into the env as `"1"`; all ten command entry points call it on `045d7ec`. "Empty means unset" is one private helper (`socket_cli_config::env_non_empty`) plus about 29 inline copies in 16 files. In this area there are at least six home-directory resolvers, and they disagree: `policy::home_dir` reads only `USERPROFILE` on Windows, while `utils::fs::home_dir` prefers `HOME`. The crawlers keep further variants.
76-
- **Atomic writes:** `utils/fs.rs` has six writers, which are four boolean policies (capture, fsync, keep mode, durability record) spelled as separate functions. `atomic_write_sync` re-implements `stage_and_rename` + `create_stage` + `commit_stage` in blocking form, with no drift yet. `blob_fetcher::write_cache_entry_atomic` is a third, deliberately non-fsyncing stage+rename. The self-update stage (`update/download.rs`, `update/swap.rs`) is legitimately separate. Correction: the artifact writers inside `utils::fs` don't capture into a group commit either, so bypassing `utils::fs` isn't itself a group-commit escape. {{C21}} `get` writes `.socket/blobs/<hash>` with neither: it uses an in-place `fs::write` and doesn't check the content's hash ({{C42}}).
76+
- **Atomic writes:** `utils/fs.rs` has six public writers. Each is a named `WriteOpts` policy: capture, durable (barrier + fsync + dir fsync), keep mode, and durability record. They all run one blocking core, `stage_and_rename_blocking`; the async writers run it through `run_blocking`, and `atomic_write_sync` is the core itself (#858). One `stage_path` builds every stage name: `.socket-stage-` for these writers and `.socket-dl-` for the blob cache, whose streaming writer verifies the hash between stage and rename and keeps its own body. The self-update stage (`update/download.rs`, `update/swap.rs`) is legitimately separate. The artifact writers don't capture into a group commit, so bypassing `utils::fs` isn't itself a group-commit escape. {{C21}} `get` writes `.socket/blobs/<hash>` with neither: it uses an in-place `fs::write` and doesn't check the content's hash ({{C42}}).
7777
- **Process spawning** is centralized in `process.rs::resolve_tool`/`command_for`; on `0d302dc` no production `Command::new("<tool>")` remains. Vendored Hatch now resolves `hatch` through `resolve_tool_with` instead of a bare spawn in the project root (#617). {{C04}} Spawn *deadlines* are not centralized: the shared probe runners (`gem env`, `python --version`, `npm root -g`, …) have none, while four sites hand-roll `timeout` + `kill_on_drop` with 10/10/10/30–60 s budgets; on `045d7ec` a hung `gem` shim hung a local `scan` indefinitely. {{C48}}
7878

7979
### 7.4 Agent mode

‎register/20-audit-core.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ _Last updated 2026-10-05T15:52Z · main @ 0d302dc_
2323
| C18 | 2 | There are four UUID grammars. `client.rs` has one, CLI `lib.rs` a byte-identical copy, `path_safety.rs` accepts lowercase only, and `apply.rs` accepts any alphanumeric plus `-`/`_`. | 7.3 | #705 | filed #705; a fifth grammar (`Uuid::parse_str` in `python_script.rs`) |
2424
| C19 | 2 | Env truthiness has three vocabularies (core's `"1"`/`"true"` match kept correct only by `apply_env_toggles`), and there are ~29 inline "empty means unset" reads and six or more home-directory resolvers that disagree on Windows. | 7.3 | #727 | filed #727 |
2525
| C20 | 2 | Tracking: purls have two builder families in `utils/purl.rs` (canonicalization already drifted), plus 42 production hand-built `pkg:` strings and 24 `starts_with("pkg:<type>/")` checks beside `Ecosystem::from_purl`. | 6.4; 7.3 | #748, #747 | filed #748, #747; children 2–4 touch the ecosystem area |
26-
| C21 | 3 | `utils/fs.rs` has six atomic writers (four boolean policies) and a blocking copy of the stage code; `blob_fetcher` has a third stage+rename. (The group-commit escape claim was wrong; `update/` is legitimately separate.) | 5.7; 7.3 | #728 | in PR #858 |
26+
| C21 | 3 | `utils/fs.rs` has six atomic writers (four boolean policies) and a blocking copy of the stage code; `blob_fetcher` has a third stage+rename. (The group-commit escape claim was wrong; `update/` is legitimately separate.) | 5.7; 7.3 | #728 | fixed (#858) |
2727
| C22 | 2 | Telemetry has 19 near-identical public wrappers (17 `track_*`, 2 `spawn_*`), builds a new HTTP client for every event, and the CLI threads token/org through ~45 call sites (review said 125), resolved two ways. Target: one `Telemetry` handle with `track(Event)` and a shared client. | 7.5; R15 | #770 | filed #770 |
2828
| C23 | 2 | Dead code: `PatchSources::mem_blobs` is never `Some`; `VendorSource` predicates are always true; group commit captures `redirect-state.json`, which nothing in its scope writes; the `switched_off("group_commit")` oracle path. | 7.4; 7.6 #3; 5.6 | #746 | filed #746; `Pypi`/`LauncherCache` channels are live (not dead) |
2929
| C24 | 2 | Apply and rollback are mirror images: the verify types are identical, and `fold_copy_result`, the pnpm peer fan-out and the sidecar boundary are each written twice; the folds have drifted and both drop per-file records (#756). Target: one engine. | 7.4; 7.6 #4 | #771, #772 | in PR #774; #772 is in PR #774, tracking #771 open |

‎register/90-refactor.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,12 @@
22
_Last updated 2026-10-05T17:00Z · main @ 0d302dc_
33

44
**In flight:**
5-
- [#858](https://github.com/SocketDev/socket-patch/pull/858): one blocking `stage_and_rename_blocking` core with a private `WriteOpts` policy behind the six `utils::fs` writers; `atomic_write_sync`'s copy and `create_stage`/`commit_stage` deleted; one `stage_path` builds `.socket-stage-` and `.socket-dl-` names. Issue #728 (C21). Production +171 / −168, tests ≈ +85 / −12. State: ready, with the PR burn-down.
65
- [#865](https://github.com/SocketDev/socket-patch/pull/865): `utils::digest` gains `sha256_hex_of`, `sha1_hex_of`, `sha512_base64_of`, `sha512_sri_of`; production digest sites in the 14 files no open PR changes move onto them; `ledger_snapshots::sha256_hex`, `vlt_preflight::sha512_sri`, `nuget_feed::content_hash`, `client::is_valid_sha256_hex` and the npm_pack/bun_lock SRI blocks deleted; a ratchet lists the 6 files left for slice 2. Issue #706 slice 1 (C17).
76

87
- [#870](https://github.com/SocketDev/socket-patch/pull/870): `go_mod_edit::module_path` on the shared directive walker reads the go.mod `module` directive for VEX `--product` (fixes the block-form `module ( … )` misread); `go_crawler::parse_go_mod_module` (dead) and `product.rs`'s line scanner deleted. Issue #781 (E19 Go half). Production ≈ +22 / −64, tests ≈ +65 / −117. State: ready, CI green after one re-run, Bugbot clean; with the PR burn-down.
98

109
**Merged:**
10+
- [#858](https://github.com/SocketDev/socket-patch/pull/858): one blocking `stage_and_rename_blocking` core with a private `WriteOpts` policy behind the six `utils::fs` writers; `atomic_write_sync`'s copy and `create_stage`/`commit_stage` deleted; one `stage_path` builds `.socket-stage-` and `.socket-dl-` names. Issue #728 (C21). Production +171 / −168, tests ≈ +85 / −12. Merged 2026-10-05 as `ee8ebf4`.
1111
- [#850](https://github.com/SocketDev/socket-patch/pull/850): one hermetic `common/hermetic.rs` builder for CLI test children; 8 `scrub_socket_env` copies deleted, 7 unscrubbed spawners made hermetic, `spawn_env_hygiene` ratchet. Issue #823 slice 1 (C30, C47). Merged 2026-10-05 as `99f61d2`. Test-only: +745 / −322.
1212
- [#607](https://github.com/SocketDev/socket-patch/pull/607): blob and diff downloads stream to disk through `BinaryBody`; one `download_entries` loop replaces the blob and diff copies. Issue #571 (C37). Merged 2026-10-05 as `366b155`. Production ≈ +190 / −80 (`blob_fetcher.rs`, `client.rs`), tests ≈ +230.
1313
- [#602](https://github.com/SocketDev/socket-patch/pull/602): crawler project-tree reads go through `utils::fs::read_regular_*`, plus a `crawlers::architecture_tests` guard against bare reads. Issue #592 (E06). Merged 2026-10-05 as `2eae9a0`. Production +4 / −4, tests +241.

0 commit comments

Comments
 (0)