v5: remove dead code and v3 compatibility shims - #296
Conversation
The pdm and poetry lockfile rewriters each carried an identical copy of the rule that decides whether an existing pin is an earlier hosted redirect of the same artifact. They now use one copy in python_lock, so the two rewriters cannot drift apart. No behavior change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018JsczaHn8e6YrCpxs1NznQ
`get --one-off` and `rollback --one-off` (and SOCKET_ONE_OFF) never did anything: they only failed with a "not yet implemented" usage error. v5.0 drops them. Passing `--one-off` is now an ordinary unknown-flag error (still exit 2), and SOCKET_ONE_OFF is ignored. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The whole vlt lockfile text module was exempt from dead-code checks, which hid an unused edge-rendering method. The exemption is gone, the unused method is deleted, and the macOS-only global node_modules helper now opts out of the lint only on builds where it is truly unused. No behavior change for vlt users. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Nothing has written `.socket/packages/<uuid>.tar.gz` for several releases, yet apply, vendor and repair still probed and overlaid that directory and the patch pipeline tried it before the diff archive. v5.0 drops the read path and the `appliedVia: "package"` JSON value. The GC sweeps (scan --prune, rollback, remove, repair) now remove any leftover `.socket/packages/` files whole, so old projects are cleaned up; the `removedPackageArchives` counter keeps reporting them. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
v5.0 removes compatibility surface kept since v3/v4: - The legacy env names SOCKET_PATCH_PROXY_URL, SOCKET_PATCH_DEBUG and SOCKET_PATCH_TELEMETRY_DISABLED are no longer read (use SOCKET_*). - The hidden `scan --redirect` flag (use `--mode hosted`) and the hidden no-op `scan --detached` flag are gone; both are now unknown flags (exit 2). - The hidden `--mode` values `host`, `redirect` and `vendor` (scan and get) are rejected; only hosted, vendored and agent remain. The hidden `scan --apply` and `scan --vendor` spellings stay. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Several public functions in the core crate had no callers anywhere in the workspace: the bun workspace artifact snapshot, the vlt lock sniff wrapper, the in-memory project's binary/symlink/path helpers, and the disk snapshot's invalidate, sync text read and disk-root accessors. They are removed. The in-memory project's text/present/entries helpers that only tests use are now test-only. No user-visible behavior change. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # crates/socket-patch-cli/CLI_CONTRACT.md
The hosted engine copied the yarn-berry cache-zip URL into every redirect entry, but no rewriter ever read it: berry pins only the zip's checksum, which is still taken from the patch reference. The field is gone from DepOverride; references that still send it parse as before. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Every service-backed vendor backend (npm tarball and directory, pypi, cargo, composer, golang, gem, and the frozen maven/nuget path) decided on its own when a patch-service miss falls back to a local build, when `--vendor-source=service` refuses, and when tampered bytes are fatal. Seven hand-copied versions of that policy could drift apart. The policy now lives once in service_fetch.rs: ServicePolicy maps the Pending, Unavailable, Failed and IntegrityMismatch outcomes, and each backend keeps only its own handling of a ready artifact. Warnings, refusal codes, messages and check order are unchanged, including the npm tarball backend's wording for a failed request in service mode. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Three integration tests still expected a leftover package archive to be a patch source or to survive GC; they now pin the v5.0 rule (not a source, always swept). Also: a rollback --one-off rejection test, test names that no longer mention the removed --detached flag, a dead berryZipUrl branch in the hosted memory harness, and contract rows that still listed `--download-mode package`. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
[agent] Generated by Claude Code |
|
[agent] Root cause, in the test itself: on Linux, Proposed fix (W2/tests territory, so I'm not adding it here): on Linux, read Generated by Claude Code |
|
[agent] Generated by Claude Code |
|
#291 landed on release/v5-prerelease as f9cb7e1; please merge origin/release/v5-prerelease again, resolve conflicts, get green, and keep it ready. Generated by Claude Code |
|
[agent] ready to land Head 3b5cdb2 (merges
Generated by Claude Code |
|
#292 landed on release/v5-prerelease as a7b0d00; please merge origin/release/v5-prerelease again, resolve conflicts, get green, and keep it ready. Generated by Claude Code |
#292 fixes created-file coverage for diff archives and has pypi refuse non-wheel references before downloading. Conflicts, resolved against this branch's removal of .socket/packages and the shared service policy: - fetch_stage: keep #292's per-file coverage check (a diff covers only files that exist before the patch), without the package-archive arm. - repair: take #292's download_pass helper and its created-file blob top-up; SourcePaths and PatchSources lose the packages path. - pypi: keep ServicePolicy; add #292's PYPI_NOT_A_WHEEL refusal (warns under auto, refuses under service) and its shared constant. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
[agent] On 156710f (the merge of #292), Generated by Claude Code |
|
Coordinator: not landing yet. The head 156710f (base merge of #292, pushed 05:27Z) is newer than the last Generated by Claude Code |
|
[agent] ready to land Head 156710f merges
Generated by Claude Code |
1e3ace6
into
release/v5-prerelease
Brings in #296, which removes dead code and the v3 compatibility shims. The only conflict is CLI_CONTRACT's exit-code rows: they take the base's text (no `--detached`, `--one-off` removed) plus the socket.yml and SOCKET_MIN_SEVERITY rows. Clippy and the policy, in-memory, parity, e2e policy, parser, help and scan suites pass. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BKsyzefGhAnPkYmXCwq3H3
#296 drops DepOverride's berry_zip_url, so the goldens' input digests (which serialize the deps) are re-blessed: 1848 lines in 12 files change only their input digest, and every case key and output digest is unchanged, so the rewrites behave exactly as before. The two env-gated fixture tests #296 edited stay deleted here. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01N9YdJqaGiT9Jf5LN1hDFhB
Brings in #296, which removes dead code and the v3 compatibility shims. #296 made MemoryProject::entries() test-only because nothing else called it. This branch's in-memory rollout does: it reads every text file in the project to find the patches it mentions. The method stays crate-visible outside tests. In CLI_CONTRACT.md the exit-code rows keep both sides' changes: #296 drops the --detached and --one-off entries, and this branch adds the socket.yml, scan PATH and SOCKET_MAX_NEW_PATCHES entries. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AvGSu5jGg1z3f3sePc2eHC
W3 of the v5 waste-review follow-ups (#286). It removes dead code and v3/v4 compatibility shims from the CLI and core, and shares the service-fallback policy across the vendor backends. v5 is a major release, so the removed flags and env vars are listed under "Removed (BREAKING)" in CHANGELOG.md.
Base is
release/v5-prerelease@ 14a9cb0, after #279, #281, #282 and #283 landed. I re-checked every finding against that head.Findings
SOCKET_PATCH_PROXY_URL,SOCKET_PATCH_DEBUGandSOCKET_PATCH_TELEMETRY_DISABLED, along withpromote_legacy_env_varsand its deprecation warning. Removed the hiddenscan --redirectflag, the hidden no-opscan --detachedflag, and the hidden--mode host/redirect/vendorvalues onscanandget. The hiddenscan --applyand--vendorflags stay, per the WS8 owner decision. CurrentSOCKET_PATCH_*names are untouched (SERVER_URL,VERSION, installer vars, test knobs). Deferred: depscanworkspaces/patches/src/test/integration/live/hosted-live.e2e.test.ts:571passes--redirectand needs--mode hosted. That change is out of scope for a socket-patch PR.get --one-off,rollback --one-offandSOCKET_ONE_OFF. They only ever returned a "not yet implemented" exit 2; the flag is now an unknown-argument error (still exit 2)..socket/packages/<uuid>.tar.gz. Dropped the read, probe and overlay paths (PatchSources::packages_path,resolve_from_archive,pkg_present) andappliedVia: "package". For one release the GC sweeps (scan --prune,rollback,remove,repair) remove any leftover.socket/packages/whole.rollbackandscan --prunestill reportremovedPackageArchives, so their JSON shape is unchanged.DepOverride::berry_zip_url; nothing read it. The berry 10c0 checksum merge stays.DepOverridehas nodeny_unknown_fields, so references that still carryberryZipUrlparse as before. The depscan-side storage and serving is out of scope.bun_lock::snapshot_binary_workspace_artifactsandBinaryWorkspaceArtifactSnapshot,bun_workspace::snapshot,vlt_lock_sniff_ok,MemoryProject::{insert_binary, insert_symlink, paths}, andDiskSnapshot::invalidate. AlsoProjectView::{disk_root, read_text_sync}, which were used only by their own test. Test-only helpers moved under#[cfg(test)].DirEntryInfostays because it is live viaProjectView::list_dir. Not added:#[warn(unreachable_pub)], which reports 22 lib warnings across 10 files that other workstreams touch; left for a follow-up.#[allow(dead_code)]onvlt_lock_textand deleted the deadEdgeEntry::entry_text.find_node_dirs_syncnow uses a targetedcfg_attr. vlt support is unchanged.ServicePolicyinvendor/service_fetch.rs(hard/miss/settle) covering the Pending, Unavailable, Failed and IntegrityMismatch outcomes. It is used by cargo, composer, golang, pypi, npm tarball, npm dir and gem (step 1). Maven/nuget use it throughservice_archive_copy, and their behavior is unchanged (frozen per the owner decision). Warning codes, refusal codes, message text and check order are unchanged. That includes npm's "patch service request failed: …" wording in service mode, which keeps its own guard arm.is_prior_hosted_urlwas identical inutils/pdm_lock.rsandutils/poetry_lock.rs; it now lives once inutils/python_lock.rs. Deferred: the fourcheck_target_guards(poetry, uv, pdm, pipenv) differ in substance and share only about 15 lines of opening. #281 did not take the Python family, so the generic guard belongs in a WS3 Python formats PR.parse_memois still load-bearing: 22 statics with 53 live call sites. The per-package re-parse it covers is not fixed.vendor_recordsstill calls one backend per package, and each backend re-reads and re-parses the lock. Removing it now would cost roughly N to 3N full lock parses instead of about 1 for N patched packages, and N × workspace-members manifest parses for cargo. It can go once vendoring parses throughProjectContextonce per run.formats/pnpmbut did not unify the vendor/revert skeleton across npm, pnpm, pnpm-legacy, bun, yarn classic, yarn berry and vlt. That is a new trait plus driver, about 1,200 lines under heavy e2e coverage, and too large to count as contained here.Size
git diff --shortstat 14a9cb0..HEAD: 153 files, +1502 / −3512, −2010 net.src/: 60 files, +798 / −1800 (−1002 net).tests/: 90 files, +647 / −1674 (−1027 net).Per commit:
Tests
cargo clippy --workspace --all-targets --all-features -- -D warnings: clean on the final head, F32 included.cargo test --workspace --all-features --no-fail-faston the head before F32 (0a2bd3a): 9394 passed, 17 failed, 239 ignored.apply_network::apply_online_…package_archive…,covgap_commands_repair::repair_removes_orphan_archives…,remove_duality_invariants::default_remove_sweeps_archives_too).vlt patch compatibility / install-proof (0.0.0-1)also fails on the base branch: the same 3hosted_*rollback tests fail on v5: fix partial-stage repair bug, cut redundant downloads #292's base-merged head. See the PR comment.Grep evidence for the removals, excluding
docs/design:SOCKET_PATCH_(PROXY_URL|DEBUG|TELEMETRY)appears only in the removal notes in CLI_CONTRACT.md and the historical CHANGELOG.--redirect,--detachedand--one-offappear only in the new rejection tests, a stderr negative assertion and the removal notes.packages_path,resolve_from_archive,AppliedVia::Packageandberry_zip_urlhave no matches.Review
Two adversarial reviews ran on the diff.
Correctness and regressions. It found the 3 stale tests and some doc drift above, all fixed. Checks that came back clean:
resolve_mode_flagsconflicts are intact.get --modeis covered.Coverage and owner decisions.
redirect-state.jsonread stays, maven/nuget are frozen, hidden--apply/--vendorstay.🤖 Generated with Claude Code
https://claude.ai/code/session_018JsczaHn8e6YrCpxs1NznQ
Note
Medium Risk
Major-release breaking CLI and JSON contract changes affect scripts still using legacy flags/env vars; apply/repair GC behavior changes how leftover package archives are handled but does not alter live patch application when blobs/diffs exist.
Overview
v5 breaking cleanup drops compatibility layers and artifact paths that nothing writes anymore, and tightens the public CLI contract docs to match.
CLI surface: Legacy env names (
SOCKET_PATCH_PROXY_URL,SOCKET_PATCH_DEBUG,SOCKET_PATCH_TELEMETRY_DISABLED) are no longer read. Hiddenscan --redirect,--detached, and--modealiaseshost/redirect/vendorare removed (unknown flag/value → exit 2).get/rollback --one-offandSOCKET_ONE_OFFare gone.--download-mode packageis rejected; patch staging and apply only use diff and blob sources. JSONappliedViano longer includes"package"..socket/packages/:apply,vendor, andrepairstop probing or overlaying package archives. GC onscan --prune,rollback,remove, andrepairdeletes the whole legacy directory;rollback/pruneJSON still reportsremovedPackageArchivesfor swept files.Core: Removed unused
DepOverride::berry_zip_urlfield usage and several uncalled public helpers (per CHANGELOG). Hosted scan docs/comments no longer reference--redirect.Reviewed by Cursor Bugbot for commit 3b5cdb2. Configure here.