docs: v5 waste review + repacking-to-depscan design - #286
Mikola Lysenko (mikolalysenko) wants to merge 3 commits into
Conversation
Two design docs for the v5 train, docs only: - v5-waste-review.md ranks 69 verified waste findings across socket-patch and depscan's patch system, with evidence, risk, and savings de-duplicated against WS1-WS8 and PRs #279-#283. Top-10 cuts, totals, and the refuted findings so they are not re-raised. - repacking-to-depscan.md is the chosen design for moving artifact repacking to depscan: server-primary with a single pypi local class, an additive v2 package contract, signed statements, offline bundles, and a phased migration across both repos gated on the WS5 caveat. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BgB7r9Ksfn5MJ6vWTFwRbL
|
[agent] CI note:
Generated by Claude Code |
|
[agent] follow-up instructions v1 Shared instructions for the cloud follow-up routines created from this waste review (2026-09-28). This PR itself is NOT merged; it is closed once every finding has an owner. Each routine's own prompt names its workstream, finding IDs, repo and target branch. |
|
[agent] triage addendum I checked all 69 ranked findings and the 11 measurement/checked-not-waste entries in Missing
Double-assigned
Measurement / checked-not-waste entries (no code unless noted)
No finding needs a new workstream, so there is no owner TODO for a new routine. The full map and the owner decisions follow in Generated by Claude Code |
|
[agent] triage map Every finding in Workstreams: W0
Counts (ranked findings): W0 3 · W1 11 (+F17 ci) · W2 4 · W3 10 (F33 cli half) · W4 7 · W5a 8 (F33 server half) · W5b 12 · W6 6 · in-flight notes 5 (#279: F15 F40 F44; #281: F16; #282: F26) · owner-gated 4 (F01 F05 F17 F35). Total: 69, with F33 split between two workstreams. Owner decisions neededGated, with no agent assigned:
Decisions that workstreams will surface in their PRs: Both docs are being moved to a docs-only reference PR against Generated by Claude Code |
|
[agent] W6 (depscan v5 bump prep): https://github.com/SocketDev/depscan/pull/26900 (draft). Done 4 (F11, F27, F50, F22), partial 1 (F07; script deletion is still gated on socket-patch captures), deferred 1 (F13; waits for #281), dropped 0. Generated by Claude Code |
|
[agent] CI note on c6c708e (merged the new base 686e5fb, with #280 landed):
Generated by Claude Code |
|
[agent] W5b (depscan pipeline/CI waste): drafts SocketDev/depscan#26898 (CI) and SocketDev/depscan#26903 (pipeline), both green. 5 done (F39 Go-refusal fix, F34, F66, F69, F74), 1 partly done (F36), 1 documented (F14), 5 deferred (F73 and F37 until #26860 and the annotation stack land, F61 with F45 needing an owner design call, F18 until its backlog drains). Generated by Claude Code |
|
[agent] W1 (v5 CI build-once + tiering): #291. Outcomes: 10 done (F51 F49 F52 F41 F53 F46 F47 F55 F54 F56), 1 partial (F57: the watchdog stays disarmed until the prod probe passes), 1 deferred (F40, left to #279). Measured: 945 → 399 job-min for the full tier; about 350 on a PR. Generated by Claude Code |
|
[agent] W0 (fast lane): #288 is ready to land. F77 done: #280 fixed the cargo case, and #288 fixes the Windows Generated by Claude Code |
|
[agent] CI note on 50aed71 (merged the new base 06437d2, where #283 landed):
Generated by Claude Code |
|
[agent] W4 (partial-stage repair bug + redundant downloads): #292 — done 5 (F67, F28, F70, F71, F80), dropped 0, deferred 2 (F59, F60) Generated by Claude Code |
Keep the v5 waste review and the repacking-to-depscan design from PR #286 as reference docs. #286 is being closed without merging, and its findings now belong to follow-up PRs. Each doc starts with a line that links the triage map on #286, which gives every finding's owner. Co-authored-by: Claude <noreply@anthropic.com>
Docs only. No product code changes.
What's here
docs/design/v5-waste-review.mdis a holistic waste review of socket-patch and depscan's patch system. 106 findings were checked on three criteria (re-measured facts, whether it is really waste under the owner decisions, and the savings estimate). A finding was kept when at least two held: 80 kept, 26 dropped.setup(WS7) + patch UI streamlining (WS8) #279–WS5: one VendoredBackend for vendored apply/revert/repair; cut repair's ledger rebuild #283, using a per-PR deletion ledger.docs/design/repacking-to-depscan.mdis the chosen design for moving artifact repacking out of the CLI and into depscan. Four variants were scored on integrity, ops and delivery./v0/orgs/{slug}/patches/package.Headline numbers
ci.yml: about 478 job-min saved per PR run and about 438 per main push, against a 945 job-min main-push run. Add about 95 job-min per PR push that triggers the compatibility workflows.crates/socket-patch-cli/tests/e2e_redirect_cargo_build.rs:829, so the e2e tier has not run on any v5 PR (F77).All owner decisions in
v5-plan.mdare respected: vlt and every PM version stay (CI is tiered, not dropped), setup and the hosted ledger are removed, and maven/nuget stay frozen. Deleting the local rebuild is gated on the owner reversing the WS5 caveat after #283.🤖 Generated with Claude Code
https://claude.ai/code/session_01BgB7r9Ksfn5MJ6vWTFwRbL
Generated by Claude Code