v5: remove setup (WS7) + patch UI streamlining (WS8) - #279
Mikola Lysenko (mikolalysenko) wants to merge 7 commits into
Conversation
`socket-patch setup` (and --check/--remove/--exclude) is gone, with every install hook it wired: npm postinstall/dependencies scripts, the socket-patch[hook] .pth wheel, the in-tree Bundler plugin + Gemfile block, and Composer post-install/update scripts. `apply` stays; agent mode in CI is `scan --mode agent` once, then `socket-patch apply` after each install. Deleted: commands/setup.rs, core setup/** and the setup-only package_json helpers, the setup tests and setup-matrix suites, the setup-e2e feature, the setup-matrix CI job, tests/setup_matrix and scripts/setup-matrix.sh. vex's install-hook "Property 7" filter goes with it. The socket-patch-hook wheel and socket-patch-bundler gem are dropped from the build and publish workflows (sources kept, frozen, pending an owner decision). Also the plan's small follow-ups: drop the core crate's deprecated re-export aliases (and the CI grep that guarded them), the unused utils::process::tool_command, the vacuous e2e_cargo/e2e_golang CI rows, add the merged 01019627 and 9c2b4925 gem patches to the vendored production e2e, and retire the backtest-poetry "known crawler gap" label. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj
- `-h` lists about eight options per command (`cli_command()` marks the rest hide_short_help; `--help` is unchanged); `scan --apply/--vendor` are hidden (still accepted). - Human warnings drop the `(code)` tag (`Warning: …`, `GC: skipped: …`); JSON keeps every code. Error lines keep theirs. - Human text says "hosted", not "redirect" (JSON keys unchanged). - npm's allow-remote notice is one line; `--verbose`/JSON keep the full policy text. - One `ui::next_steps` renderer for hosted and vendored results. - Hosted and vendored `get` never prompt: top-ranked patch per package, like scan, in JSON too. Agent-mode `get` keeps its picker and confirm. - `list` with nothing to list says `No patches in this project. Run \`socket-patch scan\`.` (exit codes unchanged: 1 missing, 0 empty). - One cancel line (`ui::CANCELLED`) and one paid upsell (`ui::PAID_UPGRADE`). - `get`'s self-enforced flag conflicts and `rollback --one-off` exit 2, like every other usage error. Docs: CLI_CONTRACT (human output conventions, exit codes, get prompts), README, CHANGELOG [Unreleased], v5 plan status. Tests updated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj
`get <uuid>` defaults to hosted since v5, so the leg's in-place patched/pristine assertions need agent mode spelled out. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj
|
CI failure summary. Current commit: f200524. Also failing on the base branch (
Fixed in this PR:
Likely flaky, to be re-run once:
Generated by Claude Code |
These chmod-guarded tests skip under root, so the WS8 wording change
("hosted redirect ledger" -> "hosted ledger") only showed up in CI.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj
Mikola Lysenko (mikolalysenko)
left a comment
There was a problem hiding this comment.
v5 review at f200524f — removing install-hook setup is the largest concrete simplification in this stack. Keep that deletion and the explicit CI apply escape hatch.
A few interface changes would make this a simpler product, beyond hiding flags:
- Make an empty project a successful empty
list. I built this head and checked both forms: human output says “No patches in this project” but exits 1;--jsonexits 1 withmanifest_not_found. Absence of an agent manifest is normal for hosted v5. Return one consistent empty result in both renderers; reserve failure for unreadable/corrupt state. This is an intentional v5 contract improvement, not a claim that this PR introduced the old exit code. - Fix the primary help's command grouping. It calls
getandrollback“older agent-mode commands”, whilegetdefaults to hosted and rollback is needed to undo hosted wiring. Describe the lifecycle by user intent, with agent-specific commands in their own group. Short help currently keeps--prunebut hides--cwd,--ecosystems, and--offline; prioritize the hosted workflow's useful controls. - Consolidate results before rendering. The deferred scan/get JSON-envelope work is worth doing in this major release: one typed operation result, one exit-status rule, human and JSON renderers. The current split preserves a large amount of branching and lets their stories drift.
- Make the removal actionable for existing users. Include a short upgrade recipe for existing npm/Composer scripts and installed Python/Bundler hooks, alongside the frozen-package notices. Keep explicit
applyinstructions for users retaining agent mode.
Validation: built this head; exercised root/scan help and empty list in human/JSON modes. I have not run the full compatibility matrix.
Review follow-ups: - `list` on a project with no manifest and no ledger record is an empty list: exit 0, the empty-project line (human) or the success envelope with `events: []` (`--json`). Only an unreadable or invalid manifest fails. Hosted mode writes no manifest, so this is the normal case. - Root help groups the commands by task (patch, undo, ship, agent mode) instead of calling get/rollback/remove "older agent-mode commands"; the subcommand list follows the same order. `-h` keeps --cwd, --ecosystems and --offline, and moves `scan --prune` to --help. - README gains "Upgrading from `setup`": move to hosted or keep agent mode, and the exact hook to delete per ecosystem. The CHANGELOG and the frozen hook/plugin READMEs link it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj
|
Thanks for the review. c4f3625 makes three of the four changes. I've held back the fourth and propose a plan for it below.
Not done: one result type for scan/get, with human and JSON renderers. I agree it belongs in v5, but I think it needs its own PR. scan and get build their JSON ad hoc in about 120 places across roughly 24k lines. About 1,350 test assertions read those shapes (
If you'd rather have it in this PR anyway, say so and I'll start on step 1 here. Generated by Claude Code |
|
Restack request from the v5 coordinator (please act now). #280 (ledger-free hosted) is now merged into
|
|
Owner decision (via coordinator): land this PR without the shared scan/get result type. Do that as a follow-up PR against |
…setup-and-ui Conflicts resolved toward #280's model: no hosted ledger, rollback/remove/ vendor restore hosted pins via patch::redirect::upstream. This branch's changes stay on top: `setup` removed, human text says "hosted" and drops warning codes, one numbered Next steps block, empty `list` exits 0 (the contested-wiring error from #280 still exits 1), shared cancel line. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj
… and docs #280 added tests and contract lines with the pre-WS8 human strings ("Would redirect", "<purl> redirected, but its patch record ...", `Warning (<code>): ...`). Switch them to this branch's conventions. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj
Draft. Covers WS7, WS8, the "Remaining small follow-ups" in
docs/design/v5-plan.md, and the review follow-ups in c4f3625.WS7: remove
setupsetupsubcommand and everything only it used: coresetup/**, the setup-onlypackage_jsonhelpers,commands/setup.rs, its tests and the setup-matrix suites, thesetup-e2efeature, the setup-matrix CI job,tests/setup_matrix,scripts/setup-matrix.sh, and the setup-only gem Dockerfiles.setupblock still parses, but nothing reads it.socket-patch-hookwheel and thesocket-patch-bundlergem are no longer built or published (publish workflows,build-pypi-wheels.py,version-sync.sh), and thesocket-patch[hook]extra is dropped.pypi/socket-patch-hook/andgem/socket-patch-bundler/are kept, frozen, with a deprecation README. Deleting them and yanking the published packages is noted in the plan.setup" section gives each ecosystem's hook to delete, plus how to move to hosted mode or keep agent mode. The CHANGELOG and the frozen package READMEs link to it.tool_commande2e_cargo/e2e_golange2e rowsGEM_PATCHESWS8: patch UI streamlining
Help: the root help groups commands by task:
scan,get,listremove,rollbackvex,vendorapply,repairThe subcommand list and the README command reference follow the same order.
Short help:
-hlists about 8 options per command, including--json,--dry-run,--cwd,--ecosystemsand--offline.--helpis unchanged.scan --apply/--vendorare hidden but still accepted.Warning codes: human warnings drop the
(code)tag (Warning: …,GC: skipped: …); the JSON keeps every code. Error lines keepError (<code>)so--silentoutput stays grep-able.Wording: human text says "hosted" instead of "redirect", e.g.
Switched N packages to hosted patches; rewrote M files.. JSON keys and codes are unchanged.npm allow-remote: the notice is one line;
--verboseand--jsonkeep the full text.Next steps: hosted and vendored runs share one numbered block from
ui::next_steps.getprompts: hosted and vendoredgetnever prompt. Like scan, they take the top-ranked patch, in JSON too, so there is noselection_requiredoutside agent mode. Agent-modegetkeeps its picker and confirmation.Empty
list(BREAKING): a project with no manifest and no ledger record exits 0. It printsNo patches in this project. Run \socket-patch scan`., or under--jsonthe success envelope withevents: []`. Only an unreadable or invalid manifest exits 1.Shared strings: one cancel line (
Cancelled; no changes made.) and one paid-plan upsell line.Exit codes:
get's own flag-conflict errors androllback --one-offnow exit 2 (previously 1), like every other usage error.Not done: one result type and
json_envelopeoutput for scan/get. I've proposed a separate workstream for it; see the review reply.Docs: CLI_CONTRACT has a new "Human output conventions" section plus updated exit-code and prompt rows. README, CHANGELOG and the plan status are updated.
Testing
cargo clippy --workspace --all-targets --all-features -- -D warnings: clean.cargo test --workspace --all-features --no-fail-fast -j4: the only failures were ones this sandbox or the base branch explains:e2e_redirect_cargo_buildoffline-vex cases, which also fail on the base branch (see the CI comment).e2e_redirect_cargo_buildon every OS, andcovgap_commands_scan_modon Windows.🤖 Generated with Claude Code
https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj