|
| 1 | +[agent] 2026-10-04: architecture audit (CLI and core) |
| 2 | + |
| 3 | +**main @ `045d7ec`**, unchanged since the previous run. There were no new maintainer comments in the discussion, and no handovers addressed to `audit-core`. |
| 4 | + |
| 5 | +**Reconciled:** C24's first child #772 is now in [PR #774](https://github.com/SocketDev/socket-patch/pull/774), and tracking issue #771 stays open. All other rows hold their statuses: C03 #568, C04 in PR #617, C05 #615, C07 #648, C08 #649, C09/C39 #647, C14 #704, C15 #676/#677, C16 #675, C17 #706, C18 #705, C19 #727, C20 #748/#747, C21 #728, C22 #770, C23 #746, C37 in PR #607, C38 #614, C40 #678, C41 #707, C42 #726, C43 #745 and C44 #773. `main` hasn't moved, so I didn't re-check open issues against it. |
| 6 | + |
| 7 | +**Backlog verified and decomposed:** |
| 8 | +- **C25 → decision [#792](https://github.com/SocketDev/socket-patch/issues/792)**: make `--download-mode file` the default and retire the diff path. Re-verified on `045d7ec`: on a cold cache, the top-up at `fetch_stage.rs:377-398` sets `blob_scope = manifest` whenever any archive was missing, so diff mode fetches every archive *and* every blob. The diff-only code is `patch/diff.rs` (99 production lines), `patch/package.rs` (332), the diff branches of `blob_fetcher`/`fetch_stage`/`repair`, `AppliedVia::Diff` and `qbsdiff`. Changing the default is a contract MAJOR, so it is a decision. The options are A (make `file` the default, then delete), B (keep diff, but scope the blob top-up) and C (no change). |
| 9 | +- **C10 → tracking [#793](https://github.com/SocketDev/socket-patch/issues/793), first child [#794](https://github.com/SocketDev/socket-patch/issues/794)** (linked as a sub-issue). Verified: |
| 10 | + - `apply_env_toggles` is still called separately in 10 command entry points; `vendor --check` and `hosted-bundle` skip it, and the update notifier is spawned before it; |
| 11 | + - the lock timeout is converted by hand 12 times; |
| 12 | + - 13 production sites build the API client; |
| 13 | + - `#[serial]` now appears 993 times in `tests/` plus 185 in `src` (the review counted 553 + 182). |
| 14 | + |
| 15 | + #794 mirrors the flags once in `main` and adds `GlobalArgs::lock_timeout()`. Children 2–5 are listed in #793: a typed core `RunConfig`, a shared client, project paths (#745), and dropping `#[serial]`. |
| 16 | +- **C26 (`apply.lock`) checked, not filed:** 553 production lines (the review said 554). The deletion-on-exit machinery and the journal replay inside `acquire` are confirmed. Leaving the lock file on disk is a user-visible change, and this run's one decision went to C25, so C26's decision is due next run. |
| 17 | + |
| 18 | +**New finding: C45 → [#791](https://github.com/SocketDev/socket-patch/issues/791)** (bug). `--download-mode` is an unvalidated `String`, parsed at runtime in two places. |
| 19 | +- **Proof (debug CLI, run twice, empty manifest, `--offline --json`):** |
| 20 | + - `--download-mode bogus`, `--download-mode package` and `SOCKET_DOWNLOAD_MODE=Bogus` fail `apply` and `repair` with exit 1 and `apply_failed`/`repair_failed`; |
| 21 | + - `apply --check`, `rollback`, `list`, `vendor` and `vendor --check` exit 0; |
| 22 | + - the `--vendor-source bogus` control is a clap usage error (exit 2). |
| 23 | +- **Honest scope:** the review already noted the unvalidated `String` (Part 2.7) inside the MAJOR R8 bundle. This finding adds the execution proof and the exit-code and error-code split, and carves out the non-breaking fix, a typed clap parser. A comment on #791 corrects its Source line to say so. |
| 24 | + |
| 25 | +**Searched without filing:** |
| 26 | +- **Unlocked readers of the vendored state:** `list`, `vex` and `vendor --check` take no `apply.lock`, so they never replay an interrupted group-commit journal and can read a torn state (lockfiles new, ledger old). `vex` cross-checks the lock wiring (`vex_sources`), which limits the risk. I didn't prove a wrong output by execution, so it isn't filed; it is a candidate for the C26 decision. |
| 27 | +- **Production `ApiClient::new` bypasses:** only `hosted-bundle`, which is internal; the `scan/hosted/vlt.rs` and `discovery.rs` hits are test-only. |
| 28 | +- **Client rebuilds inside one command:** `rollback` reuses its telemetry client for blob downloads, and `repair` caches its client. No duplicate org auto-resolve was found. |
| 29 | +- **Lock-timeout handling:** uniform across sites (a C10 duplication, not a bug). |
| 30 | + |
| 31 | +**False positives ruled out:** `vendor --check` skipping `apply_env_toggles` has no proven effect, because the path does no network, telemetry or debug-gated work. It is folded into #794 as a structural fix. |
| 32 | + |
| 33 | +**Living document:** |
| 34 | +- Part 2: 2.5 has the corrected `#[serial]` counts and a {{C10}} token; 2.7 has the `--download-mode` proof and {{C45}}; {{C45}} is under new findings. |
| 35 | +- Part 7: the diff-download passage is re-verified with {{C25}}, the `apply.lock` count is corrected, and the check line now covers diff download and `apply.lock`. |
| 36 | +- Part 8: the `#[serial]` count is corrected and the check line refreshed. |
| 37 | +- Summary: the Configuration row's `#[serial]` count is corrected, with {{C10}}. |
| 38 | + |
| 39 | +**Next backlog rows:** C26 (decision: keep `.socket/apply.lock` on disk; move journal replay?), C13 (typed error codes; after #704), C27 (Maven sidecars), C28 (socket.yml serde), C30 (test-support crate). |
| 40 | + |
| 41 | +--- |
| 42 | +_Generated by [Claude Code](https://claude.ai/code)_ |
0 commit comments