You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: E15.
Kind: refactor. Source: review §1 recommendation 1 and Part 5.4 ("Cargo"); register E15.
Problem
Five places read a Cargo.toml[package] table, with three different parsers. Two of them are hand-rolled line scanners, although toml_edit is already a dependency of socket-patch-core.
toml_edit, ad hoc .get("package").get("rust-version")
the declared cargo floor
They have drifted. I ran one set of manifests through the crawler, VEX product detection and cargo_tag on 045d7ec, in a throwaway integration test that I ran twice and did not commit. toml_edit parses all of these inputs:
Cargo.toml
crawler
VEX product
cargo_tag
[package] name/version
("old", "0.1.0")
pkg:cargo/old@0.1.0
tags it
same, with a UTF-8 BOM
None
pkg:cargo/old@0.1.0 (strips the BOM)
tags it
legacy [project] table
None
None
tags it
dotted keys (package.name = …)
None
None
tags it
[package] junk (invalid TOML)
("old", "0.1.0")
None
refuses (Unparseable)
So a crate whose manifest cargo_tag reads can be invisible to the crawler, and the crawler accepts a manifest that cargo rejects. In a cargo vendor directory the crawler's fallback (the directory name) carries no version, so such a crate cannot be discovered at all. The VEX scanner and the crawler also disagree with each other on BOMs.
Normalized crates.io manifests always use a plain [package] table, so real registry crates hit none of these rows today. The point of this issue is the duplicate parsers and the rules that have already drifted, not a live wrong answer.
Impact: low risk, small size. Deleting the hand-rolled scanner removes a class of "valid TOML the scanner misreads" bugs (the crawler has already needed fixes for header comments and single quotes, according to its own comments).
Proposed change
Add one pure reader in formats/cargo/manifest.rs (or formats/cargo/mod.rs), built on toml_edit:
Deleteparse_cargo_toml_name_version, parse_table_header and extract_string_value from cargo_crawler.rs (about 100 lines plus their unit tests). The crawler parses with toml_edit (BOM handled by the parser) and keeps its directory-name fallback for Inherit::Workspace. tests/crawler_cargo_e2e.rs and cargo_crawler/oracle.rs switch to the shared reader.
vex/product.rsparse_cargo_toml uses package_fields (scan_toml_section stays for pyproject.toml, which is E38's).
cargo_tag::version_literal takes its item from the shared lookup and keeps only the span and quote logic.
path_crate_version uses the shared reader. Its [project] blind spot goes away.
plan_cargo_toml's regex dependency scanner in patch/redirect/mod.rs is the other half of E15. It is out of scope here and will be filed separately.
Size and scope
formats/cargo/ (new reader, about 60 lines), crawlers/cargo_crawler.rs (−100), vex/product.rs, vendor/cargo_tag.rs, vendor/cargo.rs.
Estimated diff: about 150 production lines added, 130 removed, plus tests.
One [package] reader in formats/cargo. No hand-rolled TOML scanner reads Cargo.toml in crawlers/ or vex/product.rs.
A table test over the rows above (plain, BOM, [project], dotted keys, inline package = { … }, version.workspace = true, invalid TOML): crawler, VEX product and cargo_tag agree on every row.
version.workspace = true still falls back to the directory name in the registry layout (existing crawler tests).
Green: cargo test -p socket-patch-core (crawler_cargo_e2e, the cargo_crawler oracle, vex::product, vendor::cargo_tag, vendor::cargo) and cargo clippy --workspace --all-targets.
[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: E15.
Kind: refactor. Source: review §1 recommendation 1 and Part 5.4 ("Cargo"); register E15.
Problem
Five places read a
Cargo.toml[package]table, with three different parsers. Two of them are hand-rolled line scanners, althoughtoml_editis already a dependency ofsocket-patch-core.crawlers/cargo_crawler.rs#L12-L113:``parse_cargo_toml_name_version+ `parse_table_header` + `extract_string_value`crawl_all(#L399-L407) andfind_by_purls(#L285-L302)vex/product.rs#L167-L170parse_cargo_toml→scan_toml_sectionpyproject.toml)vendor/cargo_tag.rs#L132-L155version_literaltoml_edit,[package]or legacy[project]vendor/cargo.rs#L1665-L1680path_crate_versiontoml_edit,[package]only[patch]path points atvendor/cargo.rs#L82-L101declared_cargo_minortoml_edit, ad hoc.get("package").get("rust-version")They have drifted. I ran one set of manifests through the crawler, VEX product detection and
cargo_tagon045d7ec, in a throwaway integration test that I ran twice and did not commit.toml_editparses all of these inputs:Cargo.tomlcargo_tag[package]name/version("old", "0.1.0")pkg:cargo/old@0.1.0Nonepkg:cargo/old@0.1.0(strips the BOM)[project]tableNoneNonepackage.name = …)NoneNone[package] junk(invalid TOML)("old", "0.1.0")NoneUnparseable)So a crate whose manifest
cargo_tagreads can be invisible to the crawler, and the crawler accepts a manifest that cargo rejects. In acargo vendordirectory the crawler's fallback (the directory name) carries no version, so such a crate cannot be discovered at all. The VEX scanner and the crawler also disagree with each other on BOMs.Normalized crates.io manifests always use a plain
[package]table, so real registry crates hit none of these rows today. The point of this issue is the duplicate parsers and the rules that have already drifted, not a live wrong answer.Symptoms
declared_cargo_minorreads[package].rust-versionwith an ad hoctoml_editlookup and missesrust-version.workspace = true. A shared reader that models workspace inheritance ({ workspace = true }→[workspace.package]) fixes this once forversionandrust-versionalike.Impact: low risk, small size. Deleting the hand-rolled scanner removes a class of "valid TOML the scanner misreads" bugs (the crawler has already needed fixes for header comments and single quotes, according to its own comments).
Proposed change
Add one pure reader in
formats/cargo/manifest.rs(orformats/cargo/mod.rs), built ontoml_edit:Then:
parse_cargo_toml_name_version,parse_table_headerandextract_string_valuefromcargo_crawler.rs(about 100 lines plus their unit tests). The crawler parses withtoml_edit(BOM handled by the parser) and keeps its directory-name fallback forInherit::Workspace.tests/crawler_cargo_e2e.rsandcargo_crawler/oracle.rsswitch to the shared reader.vex/product.rsparse_cargo_tomlusespackage_fields(scan_toml_sectionstays forpyproject.toml, which is E38's).cargo_tag::version_literaltakes its item from the shared lookup and keeps only the span and quote logic.path_crate_versionuses the shared reader. Its[project]blind spot goes away.plan_cargo_toml's regex dependency scanner inpatch/redirect/mod.rsis the other half of E15. It is out of scope here and will be filed separately.Size and scope
formats/cargo/(new reader, about 60 lines),crawlers/cargo_crawler.rs(−100),vex/product.rs,vendor/cargo_tag.rs,vendor/cargo.rs.plan_cargo_tomlscanner, pyproject parsing, Cargo.lock (already shared throughformats::cargo), and the Vendored cargo warns cargo_multi_version_old_cargo ("declares no rust-version") when the root package inherits rust-version from [workspace.package] #651 warning text. Vendored cargo warns cargo_multi_version_old_cargo ("declares no rust-version") when the root package inherits rust-version from [workspace.package] #651 can land here if the reader modelsrust-versioninheritance; otherwise it stays separate.Acceptance criteria
[package]reader informats/cargo. No hand-rolled TOML scanner readsCargo.tomlincrawlers/orvex/product.rs.[project], dotted keys, inlinepackage = { … },version.workspace = true, invalid TOML): crawler, VEX product andcargo_tagagree on every row.version.workspace = truestill falls back to the directory name in the registry layout (existing crawler tests).cargo test -p socket-patch-core(crawler_cargo_e2e, thecargo_crawleroracle,vex::product,vendor::cargo_tag,vendor::cargo) andcargo clippy --workspace --all-targets.Dependencies
cargo_crawler.rs). It touches the same read call sites but not the parser.