You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit f71cabe
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: doc/02-cli.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -103,7 +103,7 @@ A sliding-window copy-paste detector finds little *literal* duplication. **The d
103
103
-**Name collisions:**
104
104
-`--package` is a value list on `scan` but a boolean type-forcer (`-p`) on `get`.
105
105
-`--check` on `apply` audits *Go `replace` redirects only*; on `vendor` it audits artifacts and JVM wiring.
106
-
-**`SOCKET_FORCE` is bound to three unrelated `--force` flags** (`vendor.rs:80`, `apply.rs:339`, `update.rs:61`; verified on `045d7ec`). Exporting it to force a self-update also forces `apply` and `vendor`. Decided in #615: no per-command names. The env binding is removed in v5 because nothing sets it (no hook, wrapper, CI or depscan use), and`--force` stays as a flag. {{C05}}
106
+
-**`SOCKET_FORCE` is bound to three unrelated `--force` flags** (`vendor.rs:80`, `apply.rs:339`, `update.rs:61`; verified on `045d7ec`). Exporting it to force a self-update also forces `apply` and `vendor`. Decided in #615: no per-command names. #1021 removed the env binding on `main`because nothing set it (no hook, wrapper, CI or depscan use);`--force` stays as a flag. {{C05}}
107
107
-**VEX passthroughs:** 5 `--vex-*` flags × 3 host commands = 15 flag instances, with the env vars bound twice. Hosted `scan --vex` attests before install through `assume_applied`, which the standalone `vex` can't do, so dropping the embedded form needs a replacement. Still open: #966 left embedded `--vex` unchanged; E42 carries the shared-helper refactor. {{C05}}
108
108
-**Hosted-only opt-outs are globals:**`--no-trust-lockfile-config`, `--no-npm-allow-remote-config` and `--no-vlt-install-cleanup` appear on `apply`, `list`, `vex`, `repair` and the rest.
109
109
-**Two env mechanisms:** clap `env=` vs manual reads in `rollout_args.rs`/`socket_yml_args.rs`. `SOCKET_NO_SOCKET_YML` is missing from `LOCAL_ARG_ENV_VARS`, which is meant to be the single source of truth.
Copy file name to clipboardExpand all lines: doc/06-discovery-vex.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -167,7 +167,7 @@ cli: ProjectContext owns ONE Inventory; one EmbeddedVex helper
167
167
168
168
- {{E72}} October 7: VEX attested over yarn Plug'n'Play loaders, pnpm bundled copies and deno.lock npm copies. Standalone `vex` no longer does (#1033, fixing #519). The in-run `scan --mode hosted --vex` path still attests a deno project's `package-lock.json` pin (#406), and npm and vlt still emit their own bundled-copy diagnostics.
169
169
- {{E87}} Product detection has no Gradle or sbt probe, and `scan --vex` resolves the product only after writing.
170
-
- {{E89}} The pure-wheel rule is written four times: lock inventory and ledger recovery use `ends_with("-none-any.whl")` instead of the shared `wheel_platform_from_filename` (so the #1053 fix won't reach them), and recovery re-parses the uv.lock unit with a string scanner that paired a hashless pure wheel with the next wheel's hash (executed twice).
170
+
- {{E89}} The pure-wheel rule was written four times. Since #1121, ledger recovery reads the recorded uv/pdm unit through `utils::python_lock::package_artifacts` and picks wheels through `pypi_distribution::is_portable_wheel_url`, so its string scanner (which paired a hashless pure wheel with the next wheel's hash) is gone. Lock inventory still uses `ends_with("-none-any.whl")` twice (`lock_inventory/pypi.rs`) instead of the shared rule, so the #1053 fix won't reach it.
171
171
- {{E91}} PyPI tool-lock precedence is written twice since #1044: the lock inventory keys on "the lock yielded entries", the vendored router on presence. With a package-less `poetry.lock` or `pdm.lock` beside a pinned `requirements.txt`, scan offers a package that vendored then refuses with `pypi_poetry_lock_package_missing` (executed twice).
172
172
- {{E90}} Which gem homes Bundler loads has two answers since #1002: the stale guard uses `bundler_install_homes`, while `vex` (and agent `apply`) still use `get_gem_paths`, which keeps the `gem env` homes under an explicit Bundler `path`. An unused, unpatched system-home copy then blocks standalone `vex` from attesting (proven by execution).
Copy file name to clipboardExpand all lines: doc/08-tests-ci-docs.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -32,8 +32,8 @@ PR #277 has already started cleaning up: it deleted 237,608 lines, including 136
32
32
**Duplicated helpers.**
33
33
-`common/mod.rs` (792 lines) is `#[path]`-included and recompiled by ~60 binaries, and `vex_e2e_common` (876) by ~53. 34 helper files carry `#![allow(dead_code)]`.
34
34
- Helpers that `common` already exports are redefined locally:
35
-
-`fn binary()` in **103 files** (7 variants);
36
-
-`fn git_sha256` in **86 files** (10 variants), although `common::git_sha256` exists and core exports `compute_git_sha256_from_bytes`;
35
+
-`fn binary()` in **51 files** (103 before #1124 moved 72 files onto `tests/common`; a one-sided ratchet stops new copies);
36
+
-`fn git_sha256` in **54 files** (86 before #1124), although `common::git_sha256` exists and core exports `compute_git_sha256_from_bytes`;
37
37
-`copy_dir_recursive` in 26 files;
38
38
-`scrub_socket_env`: since #850, child processes are built by one `common/hermetic.rs` builder, and 7 per-file copies remain (the `PENDING_SCRUB_COPIES` list in `tests/spawn_env_hygiene.rs`); 2 files still spawn the binary with no scrub (see {{C47}}). {{C30}}
39
39
-`vex_pdm_hatch_common` and `vex_pipenv_pip_common` share **977 identical non-blank lines** (78% similar).
- Merged since the last entry: #1121 (#1079, E89 slice 1), #1124 (#824, C30 children 2–3) and the maintainer draft #1021 (#615, C05). Register: E89 `partly fixed (#1121)`, then `in PR #1151`; C30 `#824 children 2–3 fixed (#1124)`; C05 `partly fixed (#1021)`. Living document rewritten: `doc/06-discovery-vex.md` E89 bullet (recovery's string scanner is gone; only inventory's suffix checks remained), `doc/08-tests-ci-docs.md` helper counts (`binary()` 103 → 51 files, `git_sha256` 86 → 54), `doc/02-cli.md``SOCKET_FORCE` (removed on `main` by #1021).
5
+
- Ranking: the higher-scoring items (#989 finish blocks, #594/#717, C69, #1129) still have their sites in files that open `arch-refactor/*` / `agent/fix-*` PRs change. The best free item was the E89 remainder: lock inventory's two `-none-any.whl` suffix checks, which drifted from the shared #1048 classifier, plus the inventory/recovery wheel pick written twice. #1079 was closed by #1121, so I verified the remainder on `main` (a red table test) and filed it as #1150.
6
+
- PR: [#1151](https://github.com/SocketDev/socket-patch/pull/1151), `state: ready`, Bugbot requested. Production +30 / −32, tests +101. Checks: clippy clean; core lib 5784 passed (only the 4 known root-only failures); `in_process_vendor_pypi_takeover`, `in_process_redirect_poetry` and `hosted_superseding_pypi` all passed; `mode_migration_pypi` passed 40/41 (the one failure needs network and fails on `main` too).
7
+
- Claimed: #1150. Released: none.
8
+
- Lessons: when a merged slice closes the tracked issue, file the remainder as a new issue. Put tests for a blocked `tests.rs` in a sibling `#[path]` module of the file you change.
| E86 | 3 | Vendored JVM fetches upstream artifacts and checksums only from Central or `SOCKET_MAVEN_REGISTRY`, ignoring mirrors and the build's repositories. | audit B63 |#1069| filed #1069|
84
84
| E87 | 2 | VEX product detection has no Gradle or sbt probe, and `scan --vex` resolves the product only after writing. | audit B64 |#1064| filed #1064|
85
85
| E88 | 3 | Small duplicates: hosted patch origins, max-severity ordering, "ecosystem filter is empty", and the inventory matching vendored-router refusal-code strings (#975). | audit §3.A, §3.B |#975| to verify; #975 fixed (#978), but the inventory still branches on router code strings (`npm_family.rs:73,90`) |
86
-
| E89 | 3 | Pure-wheel rule written 4× (inventory and recovery skip `wheel_platform_from_filename`); recovery pairs a hashless pure wheel with another wheel's hash (executed twice). | new finding |#1079| in PR #1121 (slice 1: recovery; the two `lock_inventory/pypi.rs` suffix checks remain)|
86
+
| E89 | 3 | Pure-wheel rule written 4× (inventory and recovery skip `wheel_platform_from_filename`); recovery pairs a hashless pure wheel with another wheel's hash (executed twice). | new finding |#1079, #1150| in PR #1151; slice 1 fixed (#1121), PR #1151 routes the two `lock_inventory/pypi.rs` suffix checks through the shared rule|
87
87
| E90 | 2 | Which gem homes Bundler loads has two answers: `vex` and agent `apply` use `get_gem_paths` (keeps `gem env` homes under an explicit `path`), only the stale guard uses `bundler_install_homes` (executed twice). | new finding |#1098| filed #1098|
88
88
| E91 | 3 | PyPI tool-lock precedence is written twice since #1044: the inventory keys on "yielded entries", the vendored router on presence. A package-less `poetry.lock`/`pdm.lock` beside `requirements.txt` makes scan offer a package vendored refuses (`pypi_poetry_lock_package_missing`; executed twice). | new finding |#1114| filed #1114|
89
89
| E92 | 3 | pnpm `modulesDir` is honored by the crawler but not by `pkg_managers`: `node-linker=pnp` + `modulesDir` is classified yarn PnP, so apply refuses (`yarn_pnp_unsupported`), vendored gives the yarn remedy and VEX reads the wrong loader (real pnpm 10.28, executed twice). | new finding |#1129| filed #1129|
| C02 | 1 | The patch API clients set no HTTP timeout. | §1 #2|#570| fixed (#581) |
8
8
| C03 | 1 |`vendored_takeover` ignored `kept_artifact` on a drift-keep. | §1 #3; 2.4 |#568| fixed (#708) |
9
9
| C04 | 1 | Vendored Hatch ran a planted `hatch`. | §1 #4; 7.3 |#613| fixed (#617) |
10
-
| C05 | 1 |`SOCKET_FORCE` is bound to `vendor --force`, `apply --force` and `self-update --force`, so forcing a self-update also forces past hash checks. Merged C35: drop the deprecated spellings and decide embedded `--vex`. `vendor --force` promises a tolerance nothing implements (#923). | §1 #6; R9; R10 |#615, #966, #923|in PR #1021,#1031; decided 2026-10-07: `SOCKET_FORCE` binding removed (#615), v5 removes legacy spellings (#966); embedded `--vex` undecided |
10
+
| C05 | 1 |`SOCKET_FORCE` is bound to `vendor --force`, `apply --force` and `self-update --force`, so forcing a self-update also forces past hash checks. Merged C35: drop the deprecated spellings and decide embedded `--vex`. `vendor --force` promises a tolerance nothing implements (#923). | §1 #6; R9; R10 |#615, #966, #923|partly fixed (#1021); in PR#1031; decided 2026-10-07: `SOCKET_FORCE` binding removed (#615), v5 removes legacy spellings (#966); embedded `--vex` undecided |
11
11
| C06 | 1 |`get` round-trips its arguments through `DownloadParams` and `..GlobalArgs::default()`, which silently resets `offline`, `patch_server_url` and more. `get` also builds a fake `ApplyArgs`, and `get` and `scan` call each other. | 2.1; 2.3; R7 || rejected; resets inert on 045d7ec, cycle folded into C12 |
12
12
| C07 | 1 | The URL builders disagree. When org auto-resolve fails, `patches_path` sends JSON calls to `/v0/orgs/default/…`, while `binary_url` and `vendor_package_url` send the same client to the public proxy. Telemetry has a fourth copy of this logic. | 7.2 |#648| in PR #1041; decided 2026-10-07: org resolved once per run, failed auto-resolve → whole run on the proxy |
13
13
| C08 | 2 | Repo hygiene: a stray `.github/actions/actions/cache/<sha>/.vscode/launch.json`, a README that documents v5 but whose installer installs v4, and 39 references to a "DESIGN §" document that doesn't exist. (The dead CI path filters go to the CI janitor.) | §1 #8; 8.5 J |#649| rejected; #649 closed not planned 2026-10-08 |
| C27 | 3 | Agent mode wrote no Maven sidecars. | 7.4 |#551| already fixed (#646) |
33
33
| C28 | 3 | socket.yml builds a hand-made YAML tree on serde-saphyr's event parser to read 8 keys. Target: serde with `deny_unknown_fields`. | 7.5 || rejected; the tree implements the contract's scoped YAML refusals |
34
34
| C29 | 3 | The `client.rs` split (2.8K lines) into client, vendor_service and credentials; the debug-ordering machinery (`HeldBack`) has 45 call sites. | 7.2; 7.6 #8|#913| filed #913; #871 deferred (closed not planned) |
35
-
| C30 | 2 | No shared test-support: `binary()` is defined in 103 files and `git_sha256` in 86, there are 15 `scrub_socket_env` (14 bodies), xorshift is implemented four times, and the VEX helpers are forked. | 6.4; 8.5 D |#824, #823| filed #824, #823; #850 deleted 8 of 15 `scrub_socket_env`; #824 children 2–3 in PR #1124|
35
+
| C30 | 2 | No shared test-support: `binary()` is defined in 103 files and `git_sha256` in 86, there are 15 `scrub_socket_env` (14 bodies), xorshift is implemented four times, and the VEX helpers are forked. | 6.4; 8.5 D |#824, #823| filed #824, #823; #850 deleted 8 of 15 `scrub_socket_env`; #824 children 2–3 fixed (#1124)|
36
36
| C31 | 3 | There are 235 test executables on `b762f41` (review: 207; no `[[test]]` entries; 12 directory binaries exist); the target is ~25. This needs C10 first. | 8.5 A || to verify; count confirmed, not filed: blocked on #794 (env-mutating `#[serial]`) |
37
37
| C32 | 3 | Tracking: ~478 one-line 4+-word `.contains` sentence assertions (245 in the 27 covgap files, 26,086 lines, 391 tests on `05ecc6e`) become `--json`/`errorCode` checks plus render suites; `_json`/`_human` twins collapse. | 2.5; 8.5 G/H |#1089| filed #1089; tracking #1089 (#1090 folded in) |
38
38
| C33 | 3 | Tracking: `CLI_CONTRACT.md` (417 KB on `431b818`; 332 KB at review) should be a checked reference (flags, env vars, codes, exit codes) plus ≤300 lines of prose, with freshness tests. | 8.3; 8.5 F/I |#948| filed #948; tracking #948 (#949, #678 folded in) |
0 commit comments