Skip to content

Commit f71cabe

Browse files
committed
refactor: run 2026-10-08T17:20Z (#1151, merged #1121/#1124/#1021)
1 parent 578d772 commit f71cabe

7 files changed

Lines changed: 28 additions & 16 deletions

File tree

‎doc/02-cli.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -103,7 +103,7 @@ A sliding-window copy-paste detector finds little *literal* duplication. **The d
103103
- **Name collisions:**
104104
- `--package` is a value list on `scan` but a boolean type-forcer (`-p`) on `get`.
105105
- `--check` on `apply` audits *Go `replace` redirects only*; on `vendor` it audits artifacts and JVM wiring.
106-
- **`SOCKET_FORCE` is bound to three unrelated `--force` flags** (`vendor.rs:80`, `apply.rs:339`, `update.rs:61`; verified on `045d7ec`). Exporting it to force a self-update also forces `apply` and `vendor`. Decided in #615: no per-command names. The env binding is removed in v5 because nothing sets it (no hook, wrapper, CI or depscan use), and `--force` stays as a flag. {{C05}}
106+
- **`SOCKET_FORCE` is bound to three unrelated `--force` flags** (`vendor.rs:80`, `apply.rs:339`, `update.rs:61`; verified on `045d7ec`). Exporting it to force a self-update also forces `apply` and `vendor`. Decided in #615: no per-command names. #1021 removed the env binding on `main` because nothing set it (no hook, wrapper, CI or depscan use); `--force` stays as a flag. {{C05}}
107107
- **VEX passthroughs:** 5 `--vex-*` flags × 3 host commands = 15 flag instances, with the env vars bound twice. Hosted `scan --vex` attests before install through `assume_applied`, which the standalone `vex` can't do, so dropping the embedded form needs a replacement. Still open: #966 left embedded `--vex` unchanged; E42 carries the shared-helper refactor. {{C05}}
108108
- **Hosted-only opt-outs are globals:** `--no-trust-lockfile-config`, `--no-npm-allow-remote-config` and `--no-vlt-install-cleanup` appear on `apply`, `list`, `vex`, `repair` and the rest.
109109
- **Two env mechanisms:** clap `env=` vs manual reads in `rollout_args.rs`/`socket_yml_args.rs`. `SOCKET_NO_SOCKET_YML` is missing from `LOCAL_ARG_ENV_VARS`, which is meant to be the single source of truth.

‎doc/06-discovery-vex.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -167,7 +167,7 @@ cli: ProjectContext owns ONE Inventory; one EmbeddedVex helper
167167

168168
- {{E72}} October 7: VEX attested over yarn Plug'n'Play loaders, pnpm bundled copies and deno.lock npm copies. Standalone `vex` no longer does (#1033, fixing #519). The in-run `scan --mode hosted --vex` path still attests a deno project's `package-lock.json` pin (#406), and npm and vlt still emit their own bundled-copy diagnostics.
169169
- {{E87}} Product detection has no Gradle or sbt probe, and `scan --vex` resolves the product only after writing.
170-
- {{E89}} The pure-wheel rule is written four times: lock inventory and ledger recovery use `ends_with("-none-any.whl")` instead of the shared `wheel_platform_from_filename` (so the #1053 fix won't reach them), and recovery re-parses the uv.lock unit with a string scanner that paired a hashless pure wheel with the next wheel's hash (executed twice).
170+
- {{E89}} The pure-wheel rule was written four times. Since #1121, ledger recovery reads the recorded uv/pdm unit through `utils::python_lock::package_artifacts` and picks wheels through `pypi_distribution::is_portable_wheel_url`, so its string scanner (which paired a hashless pure wheel with the next wheel's hash) is gone. Lock inventory still uses `ends_with("-none-any.whl")` twice (`lock_inventory/pypi.rs`) instead of the shared rule, so the #1053 fix won't reach it.
171171
- {{E91}} PyPI tool-lock precedence is written twice since #1044: the lock inventory keys on "the lock yielded entries", the vendored router on presence. With a package-less `poetry.lock` or `pdm.lock` beside a pinned `requirements.txt`, scan offers a package that vendored then refuses with `pypi_poetry_lock_package_missing` (executed twice).
172172
- {{E90}} Which gem homes Bundler loads has two answers since #1002: the stale guard uses `bundler_install_homes`, while `vex` (and agent `apply`) still use `get_gem_paths`, which keeps the `gem env` homes under an explicit Bundler `path`. An unused, unpatched system-home copy then blocks standalone `vex` from attesting (proven by execution).
173173

‎doc/08-tests-ci-docs.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -32,8 +32,8 @@ PR #277 has already started cleaning up: it deleted 237,608 lines, including 136
3232
**Duplicated helpers.**
3333
- `common/mod.rs` (792 lines) is `#[path]`-included and recompiled by ~60 binaries, and `vex_e2e_common` (876) by ~53. 34 helper files carry `#![allow(dead_code)]`.
3434
- Helpers that `common` already exports are redefined locally:
35-
- `fn binary()` in **103 files** (7 variants);
36-
- `fn git_sha256` in **86 files** (10 variants), although `common::git_sha256` exists and core exports `compute_git_sha256_from_bytes`;
35+
- `fn binary()` in **51 files** (103 before #1124 moved 72 files onto `tests/common`; a one-sided ratchet stops new copies);
36+
- `fn git_sha256` in **54 files** (86 before #1124), although `common::git_sha256` exists and core exports `compute_git_sha256_from_bytes`;
3737
- `copy_dir_recursive` in 26 files;
3838
- `scrub_socket_env`: since #850, child processes are built by one `common/hermetic.rs` builder, and 7 per-file copies remain (the `PENDING_SCRUB_COPIES` list in `tests/spawn_env_hygiene.rs`); 2 files still spawn the binary with no scrub (see {{C47}}). {{C30}}
3939
- `vex_pdm_hatch_common` and `vex_pipenv_pip_common` share **977 identical non-blank lines** (78% similar).
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
[agent] 2026-10-08: architecture refactor run
2+
3+
- main: `30a45b3`.
4+
- Merged since the last entry: #1121 (#1079, E89 slice 1), #1124 (#824, C30 children 2–3) and the maintainer draft #1021 (#615, C05). Register: E89 `partly fixed (#1121)`, then `in PR #1151`; C30 `#824 children 2–3 fixed (#1124)`; C05 `partly fixed (#1021)`. Living document rewritten: `doc/06-discovery-vex.md` E89 bullet (recovery's string scanner is gone; only inventory's suffix checks remained), `doc/08-tests-ci-docs.md` helper counts (`binary()` 103 → 51 files, `git_sha256` 86 → 54), `doc/02-cli.md` `SOCKET_FORCE` (removed on `main` by #1021).
5+
- Ranking: the higher-scoring items (#989 finish blocks, #594/#717, C69, #1129) still have their sites in files that open `arch-refactor/*` / `agent/fix-*` PRs change. The best free item was the E89 remainder: lock inventory's two `-none-any.whl` suffix checks, which drifted from the shared #1048 classifier, plus the inventory/recovery wheel pick written twice. #1079 was closed by #1121, so I verified the remainder on `main` (a red table test) and filed it as #1150.
6+
- PR: [#1151](https://github.com/SocketDev/socket-patch/pull/1151), `state: ready`, Bugbot requested. Production +30 / −32, tests +101. Checks: clippy clean; core lib 5784 passed (only the 4 known root-only failures); `in_process_vendor_pypi_takeover`, `in_process_redirect_poetry` and `hosted_superseding_pypi` all passed; `mode_migration_pypi` passed 40/41 (the one failure needs network and fails on `main` too).
7+
- Claimed: #1150. Released: none.
8+
- Lessons: when a merged slice closes the tracked issue, file the remainder as a new issue. Put tests for a blocked `tests.rs` in a sibling `#[path]` module of the file you change.

‎register/10-audit-ecosystems.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -83,7 +83,7 @@ _Last updated 2026-10-08T13:00Z · main @ e2d9633_
8383
| E86 | 3 | Vendored JVM fetches upstream artifacts and checksums only from Central or `SOCKET_MAVEN_REGISTRY`, ignoring mirrors and the build's repositories. | audit B63 | #1069 | filed #1069 |
8484
| E87 | 2 | VEX product detection has no Gradle or sbt probe, and `scan --vex` resolves the product only after writing. | audit B64 | #1064 | filed #1064 |
8585
| E88 | 3 | Small duplicates: hosted patch origins, max-severity ordering, "ecosystem filter is empty", and the inventory matching vendored-router refusal-code strings (#975). | audit §3.A, §3.B | #975 | to verify; #975 fixed (#978), but the inventory still branches on router code strings (`npm_family.rs:73,90`) |
86-
| E89 | 3 | Pure-wheel rule written 4× (inventory and recovery skip `wheel_platform_from_filename`); recovery pairs a hashless pure wheel with another wheel's hash (executed twice). | new finding | #1079 | in PR #1121 (slice 1: recovery; the two `lock_inventory/pypi.rs` suffix checks remain) |
86+
| E89 | 3 | Pure-wheel rule written 4× (inventory and recovery skip `wheel_platform_from_filename`); recovery pairs a hashless pure wheel with another wheel's hash (executed twice). | new finding | #1079, #1150 | in PR #1151; slice 1 fixed (#1121), PR #1151 routes the two `lock_inventory/pypi.rs` suffix checks through the shared rule |
8787
| E90 | 2 | Which gem homes Bundler loads has two answers: `vex` and agent `apply` use `get_gem_paths` (keeps `gem env` homes under an explicit `path`), only the stale guard uses `bundler_install_homes` (executed twice). | new finding | #1098 | filed #1098 |
8888
| E91 | 3 | PyPI tool-lock precedence is written twice since #1044: the inventory keys on "yielded entries", the vendored router on presence. A package-less `poetry.lock`/`pdm.lock` beside `requirements.txt` makes scan offer a package vendored refuses (`pypi_poetry_lock_package_missing`; executed twice). | new finding | #1114 | filed #1114 |
8989
| E92 | 3 | pnpm `modulesDir` is honored by the crawler but not by `pkg_managers`: `node-linker=pnp` + `modulesDir` is classified yarn PnP, so apply refuses (`yarn_pnp_unsupported`), vendored gives the yarn remedy and VEX reads the wrong loader (real pnpm 10.28, executed twice). | new finding | #1129 | filed #1129 |

‎register/20-audit-core.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ _Last updated 2026-10-08T15:50Z · main @ 823810a_
77
| C02 | 1 | The patch API clients set no HTTP timeout. | §1 #2 | #570 | fixed (#581) |
88
| C03 | 1 | `vendored_takeover` ignored `kept_artifact` on a drift-keep. | §1 #3; 2.4 | #568 | fixed (#708) |
99
| C04 | 1 | Vendored Hatch ran a planted `hatch`. | §1 #4; 7.3 | #613 | fixed (#617) |
10-
| C05 | 1 | `SOCKET_FORCE` is bound to `vendor --force`, `apply --force` and `self-update --force`, so forcing a self-update also forces past hash checks. Merged C35: drop the deprecated spellings and decide embedded `--vex`. `vendor --force` promises a tolerance nothing implements (#923). | §1 #6; R9; R10 | #615, #966, #923 | in PR #1021, #1031; decided 2026-10-07: `SOCKET_FORCE` binding removed (#615), v5 removes legacy spellings (#966); embedded `--vex` undecided |
10+
| C05 | 1 | `SOCKET_FORCE` is bound to `vendor --force`, `apply --force` and `self-update --force`, so forcing a self-update also forces past hash checks. Merged C35: drop the deprecated spellings and decide embedded `--vex`. `vendor --force` promises a tolerance nothing implements (#923). | §1 #6; R9; R10 | #615, #966, #923 | partly fixed (#1021); in PR #1031; decided 2026-10-07: `SOCKET_FORCE` binding removed (#615), v5 removes legacy spellings (#966); embedded `--vex` undecided |
1111
| C06 | 1 | `get` round-trips its arguments through `DownloadParams` and `..GlobalArgs::default()`, which silently resets `offline`, `patch_server_url` and more. `get` also builds a fake `ApplyArgs`, and `get` and `scan` call each other. | 2.1; 2.3; R7 | | rejected; resets inert on 045d7ec, cycle folded into C12 |
1212
| C07 | 1 | The URL builders disagree. When org auto-resolve fails, `patches_path` sends JSON calls to `/v0/orgs/default/…`, while `binary_url` and `vendor_package_url` send the same client to the public proxy. Telemetry has a fourth copy of this logic. | 7.2 | #648 | in PR #1041; decided 2026-10-07: org resolved once per run, failed auto-resolve → whole run on the proxy |
1313
| C08 | 2 | Repo hygiene: a stray `.github/actions/actions/cache/<sha>/.vscode/launch.json`, a README that documents v5 but whose installer installs v4, and 39 references to a "DESIGN §" document that doesn't exist. (The dead CI path filters go to the CI janitor.) | §1 #8; 8.5 J | #649 | rejected; #649 closed not planned 2026-10-08 |
@@ -32,7 +32,7 @@ _Last updated 2026-10-08T15:50Z · main @ 823810a_
3232
| C27 | 3 | Agent mode wrote no Maven sidecars. | 7.4 | #551 | already fixed (#646) |
3333
| C28 | 3 | socket.yml builds a hand-made YAML tree on serde-saphyr's event parser to read 8 keys. Target: serde with `deny_unknown_fields`. | 7.5 | | rejected; the tree implements the contract's scoped YAML refusals |
3434
| C29 | 3 | The `client.rs` split (2.8K lines) into client, vendor_service and credentials; the debug-ordering machinery (`HeldBack`) has 45 call sites. | 7.2; 7.6 #8 | #913 | filed #913; #871 deferred (closed not planned) |
35-
| C30 | 2 | No shared test-support: `binary()` is defined in 103 files and `git_sha256` in 86, there are 15 `scrub_socket_env` (14 bodies), xorshift is implemented four times, and the VEX helpers are forked. | 6.4; 8.5 D | #824, #823 | filed #824, #823; #850 deleted 8 of 15 `scrub_socket_env`; #824 children 2–3 in PR #1124 |
35+
| C30 | 2 | No shared test-support: `binary()` is defined in 103 files and `git_sha256` in 86, there are 15 `scrub_socket_env` (14 bodies), xorshift is implemented four times, and the VEX helpers are forked. | 6.4; 8.5 D | #824, #823 | filed #824, #823; #850 deleted 8 of 15 `scrub_socket_env`; #824 children 2–3 fixed (#1124) |
3636
| C31 | 3 | There are 235 test executables on `b762f41` (review: 207; no `[[test]]` entries; 12 directory binaries exist); the target is ~25. This needs C10 first. | 8.5 A | | to verify; count confirmed, not filed: blocked on #794 (env-mutating `#[serial]`) |
3737
| C32 | 3 | Tracking: ~478 one-line 4+-word `.contains` sentence assertions (245 in the 27 covgap files, 26,086 lines, 391 tests on `05ecc6e`) become `--json`/`errorCode` checks plus render suites; `_json`/`_human` twins collapse. | 2.5; 8.5 G/H | #1089 | filed #1089; tracking #1089 (#1090 folded in) |
3838
| C33 | 3 | Tracking: `CLI_CONTRACT.md` (417 KB on `431b818`; 332 KB at review) should be a checked reference (flags, env vars, codes, exit codes) plus ≤300 lines of prose, with freshness tests. | 8.3; 8.5 F/I | #948 | filed #948; tracking #948 (#949, #678 folded in) |

0 commit comments

Comments
 (0)