Skip to content

Commit 1e3ace6

Browse files
v5: remove dead code and v3 compatibility shims (#296)
* Share one hosted-URL check for pdm and poetry The pdm and poetry lockfile rewriters each carried an identical copy of the rule that decides whether an existing pin is an earlier hosted redirect of the same artifact. They now use one copy in python_lock, so the two rewriters cannot drift apart. No behavior change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018JsczaHn8e6YrCpxs1NznQ * Remove the never-implemented --one-off flag `get --one-off` and `rollback --one-off` (and SOCKET_ONE_OFF) never did anything: they only failed with a "not yet implemented" usage error. v5.0 drops them. Passing `--one-off` is now an ordinary unknown-flag error (still exit 2), and SOCKET_ONE_OFF is ignored. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Drop blanket dead-code allow on vlt lock parser The whole vlt lockfile text module was exempt from dead-code checks, which hid an unused edge-rendering method. The exemption is gone, the unused method is deleted, and the macOS-only global node_modules helper now opts out of the lint only on builds where it is truly unused. No behavior change for vlt users. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Stop reading never-written package archives Nothing has written `.socket/packages/<uuid>.tar.gz` for several releases, yet apply, vendor and repair still probed and overlaid that directory and the patch pipeline tried it before the diff archive. v5.0 drops the read path and the `appliedVia: "package"` JSON value. The GC sweeps (scan --prune, rollback, remove, repair) now remove any leftover `.socket/packages/` files whole, so old projects are cleaned up; the `removedPackageArchives` counter keeps reporting them. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Drop v3 env names and legacy scan spellings v5.0 removes compatibility surface kept since v3/v4: - The legacy env names SOCKET_PATCH_PROXY_URL, SOCKET_PATCH_DEBUG and SOCKET_PATCH_TELEMETRY_DISABLED are no longer read (use SOCKET_*). - The hidden `scan --redirect` flag (use `--mode hosted`) and the hidden no-op `scan --detached` flag are gone; both are now unknown flags (exit 2). - The hidden `--mode` values `host`, `redirect` and `vendor` (scan and get) are rejected; only hosted, vendored and agent remain. The hidden `scan --apply` and `scan --vendor` spellings stay. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Delete uncalled public helpers in core vendor code Several public functions in the core crate had no callers anywhere in the workspace: the bun workspace artifact snapshot, the vlt lock sniff wrapper, the in-memory project's binary/symlink/path helpers, and the disk snapshot's invalidate, sync text read and disk-root accessors. They are removed. The in-memory project's text/present/entries helpers that only tests use are now test-only. No user-visible behavior change. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Drop the never-read berry zip URL from hosted The hosted engine copied the yarn-berry cache-zip URL into every redirect entry, but no rewriter ever read it: berry pins only the zip's checksum, which is still taken from the patch reference. The field is gone from DepOverride; references that still send it parse as before. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Note the v5 dead-code removals in the changelog Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Share one service fallback policy across backends Every service-backed vendor backend (npm tarball and directory, pypi, cargo, composer, golang, gem, and the frozen maven/nuget path) decided on its own when a patch-service miss falls back to a local build, when `--vendor-source=service` refuses, and when tampered bytes are fatal. Seven hand-copied versions of that policy could drift apart. The policy now lives once in service_fetch.rs: ServicePolicy maps the Pending, Unavailable, Failed and IntegrityMismatch outcomes, and each backend keeps only its own handling of a ready artifact. Warnings, refusal codes, messages and check order are unchanged, including the npm tarball backend's wording for a failed request in service mode. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Align tests and docs with package-archive removal Three integration tests still expected a leftover package archive to be a patch source or to survive GC; they now pin the v5.0 rule (not a source, always swept). Also: a rollback --one-off rejection test, test names that no longer mention the removed --detached flag, a dead berryZipUrl branch in the hosted memory harness, and contract rows that still listed `--download-mode package`. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude <noreply@anthropic.com>
1 parent a7b0d00 commit 1e3ace6

153 files changed

Lines changed: 1510 additions & 3519 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎CHANGELOG.md‎

Lines changed: 33 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -79,6 +79,33 @@ into the new version's section — see docs/releasing.md.
7979
`gem_setup` / `composer_setup` / `pth_hook` aliases are removed from
8080
`socket-patch-core`, along with the setup-only `npm_family` table column
8181
(`FileRow::detects_pnpm`) and `VLT_SETUP_MARKERS`.
82+
- **v3/v4 compatibility spellings are gone.**
83+
- The v3.0 legacy env names `SOCKET_PATCH_PROXY_URL`, `SOCKET_PATCH_DEBUG`
84+
and `SOCKET_PATCH_TELEMETRY_DISABLED` are no longer read and no longer
85+
print a deprecation warning. Use `SOCKET_PROXY_URL`, `SOCKET_DEBUG` and
86+
`SOCKET_TELEMETRY_DISABLED`.
87+
- The hidden `scan --redirect` flag (use `--mode hosted`) and the hidden
88+
no-op `scan --detached` flag (vendored mode is always manifest-free) are
89+
removed. Both are now unknown-flag usage errors (exit 2).
90+
- The hidden `--mode` values `host`, `redirect` and `vendor` on `scan` and
91+
`get` are rejected; only `hosted`, `vendored` and `agent` are accepted.
92+
The hidden `scan --apply` and `scan --vendor` spellings stay.
93+
- **`get --one-off` and `rollback --one-off`** (and `SOCKET_ONE_OFF`) are
94+
removed. They were never implemented and only failed with a usage error;
95+
`--one-off` is now an unknown-flag error (still exit 2) and
96+
`SOCKET_ONE_OFF` is ignored.
97+
- **`.socket/packages/` package archives are no longer read.** Nothing has
98+
written them for several releases. `apply`, `vendor` and `repair` stop
99+
probing and staging the directory, and `apply`'s JSON `appliedVia` loses
100+
its `"package"` value (`"diff"` or `"blob"` remain). The GC sweeps
101+
(`scan --prune`, `rollback`, `remove`, `repair`) delete any leftover
102+
`.socket/packages/` files whole (`rollback` and `scan --prune` still
103+
report them as `removedPackageArchives`).
104+
- **Core crate:** removed uncalled public helpers
105+
(`bun_lock::snapshot_binary_workspace_artifacts`, `vlt_lock_sniff_ok`,
106+
and several `lock_inventory::view` accessors) and the never-read
107+
`DepOverride::berry_zip_url` field (a `berryZipUrl` key in a patch
108+
reference still parses).
82109

83110
### Changed (BREAKING): patch UI streamlining
84111

@@ -96,10 +123,10 @@ into the new version's section — see docs/releasing.md.
96123
confirmation, in `--json` too (no `selection_required` outside agent
97124
mode). Agent-mode `get` keeps its picker and `Download and apply N
98125
patches?` prompt.
99-
- **`get` and `rollback` usage errors exit 2** (were 1): `get`'s
100-
`--id`/`--cve`/`--ghsa`/`--package` multi-select, `--one-off --save-only`,
101-
`--mode hosted|vendored --save-only`, `--one-off`, a malformed forced
102-
identifier, and `rollback --one-off`. Every usage error now exits 2.
126+
- **`get` usage errors exit 2** (were 1): `get`'s
127+
`--id`/`--cve`/`--ghsa`/`--package` multi-select,
128+
`--mode hosted|vendored --save-only` and a malformed forced identifier.
129+
Every usage error now exits 2.
103130
- **Human output:** warning lines no longer carry the `(code)` tag
104131
(`Warning: …`, `GC: skipped: …`); the codes stay in the JSON envelope.
105132
Error lines keep theirs (`Error (<code>): …`). Hosted mode is called "hosted", not "redirect", in human
@@ -502,9 +529,8 @@ into the new version's section — see docs/releasing.md.
502529
selected patch records are fetched into memory and every vendor-ledger entry
503530
carries `detached: true` plus the embedded `record` as its verification
504531
source, so a vendored project's footprint is `.socket/vendor/**` only. The
505-
former `--detached` opt-in is now the only vendored posture — the flag is
506-
hidden, accepted as a no-op for compatibility, and still a usage error
507-
without vendored mode. JSON uses the detached download vocabulary for both
532+
former `--detached` opt-in is now the only vendored posture, and the flag
533+
itself is removed (see "Removed"). JSON uses the detached download vocabulary for both
508534
commands (`downloaded: N`, `detached: true`, `patches[].action` =
509535
`downloaded` | `skipped` | `failed`). The vendor step vendors exactly what
510536
discovery selected — the "whole manifest is vendored" re-vendor from a

‎README.md‎

Lines changed: 2 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -644,16 +644,15 @@ socket-patch scan [PATHS]... [options]
644644
|------|---------|-------------|
645645
| `--mode <hosted\|vendored\|agent>` | — | Selects one of the three [patch modes](#three-patch-modes) (default: `hosted`). Combining `--mode` with a legacy boolean flag of a *different* mode is an error (exit 2); the same mode spelled both ways is accepted. |
646646
| `--package <name\|purl>` | `SOCKET_SCAN_PACKAGES` | Only scan these packages: a name (`lodash`, `@scope/pkg`, `requests`; case-insensitive) or a purl with or without its version (`pkg:npm/lodash`, `pkg:pypi/requests@2.31.0`). Repeat the flag or separate with commas. |
647-
| `--prune` | — | Agent-mode garbage collection after the scan: remove manifest entries for packages no longer present in the crawl (installed trees + lockfiles — a wiped `node_modules` alone doesn't prune lockfile-listed entries) and delete orphan blob/diff/package-archive files. [Vendored](#vendor) packages are exempt from the crawl-based prune, but a vendored entry whose dependency has left the lockfile is reverted. Ignored, with a `redirect_prune_ignored` warning, in hosted mode; without a mode the scan is report-only. |
647+
| `--prune` | — | Agent-mode garbage collection after the scan: remove manifest entries for packages no longer present in the crawl (installed trees + lockfiles — a wiped `node_modules` alone doesn't prune lockfile-listed entries) and delete orphan blob/diff-archive files (plus any legacy package archives). [Vendored](#vendor) packages are exempt from the crawl-based prune, but a vendored entry whose dependency has left the lockfile is reverted. Ignored, with a `redirect_prune_ignored` warning, in hosted mode; without a mode the scan is report-only. |
648648
| `--sync` | — | Shorthand for `--mode agent --prune`: the one-flag agent-mode auto-update run. |
649649
| `--batch-size <n>` | `SOCKET_BATCH_SIZE` | Packages per API request (default: `500` on the authenticated API, `100` on the public proxy). A request whose body would exceed 256 KiB is split into smaller ones. |
650650
| `--all-releases` | `SOCKET_ALL_RELEASES` | Store patches for every release/distribution variant, not just the installed one — PyPI wheel/sdist, RubyGems platform, Maven classifier. Makes the manifest portable across environments (e.g. cross-platform CI caches). |
651651
| `--vex <path>` | `SOCKET_VEX` | On a successful scan, also write an OpenVEX 0.2.0 document to this path. See [Inline VEX](#inline-vex-on-apply--scan--vendor). |
652652
| `--vex-product`, `--vex-no-verify`, `--vex-doc-id`, `--vex-compact` | `SOCKET_VEX_*` | Passthrough to the embedded VEX builder; mirror the standalone [`vex`](#vex) knobs. Inert unless `--vex` is set. |
653653
654654
> Deprecated, hidden spellings (still accepted): `--apply` (== `--mode agent`) and
655-
> `--vendor` (== `--mode vendored`). `--detached` is a hidden no-op kept for compatibility (vendored mode is
656-
> always manifest-free); it is still an error without vendored mode.
655+
> `--vendor` (== `--mode vendored`).
657656
658657
**Examples:**
659658
```bash
@@ -901,7 +900,6 @@ socket-patch get <identifier> [options]
901900
| `--ghsa` | — | Force identifier to be treated as a GHSA ID. |
902901
| `-p, --package` | — | Force identifier to be treated as a package name. |
903902
| `--save-only` | `SOCKET_SAVE_ONLY` | Download the patch without applying it (alias: `--no-apply`). |
904-
| `--one-off` | `SOCKET_ONE_OFF` | Reserved (hidden from `--help`): apply the patch immediately without saving to the `.socket` folder. **Not yet implemented** — the command currently errors up front. |
905903
| `--all-releases` | `SOCKET_ALL_RELEASES` | Download patches for every release/distribution variant of a matched package (PyPI wheel/sdist, RubyGems platform, Maven classifier), not just the installed one. |
906904
| `--mode <hosted\|vendored\|agent>` | — | How to consume the patch; the same modes as `scan --mode` (default: `agent`). |
907905
@@ -1020,7 +1018,6 @@ socket-patch rollback [targets]... [options]
10201018
| Flag | Env var | Description |
10211019
|------|---------|-------------|
10221020
| `--preserve-state` | `SOCKET_PRESERVE_STATE` | Unpatch the system but keep the local patch state — manifest entries, vendored artifacts + ledger entries — for a later re-apply, and skip GC. Hosted patches have no preservable state (the lockfile is their only record) and are restored to upstream either way. |
1023-
| `--one-off` | `SOCKET_ONE_OFF` | Reserved: rollback by fetching original (`beforeHash`) files from the API, no manifest required. **Not yet implemented** — the command currently errors up front. |
10241021
10251022
**Examples:**
10261023
```bash

0 commit comments

Comments
 (0)