You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 33fbed7
Browse filesBrowse the repository at this point in the historyBrowse files
-**Merged since the last entry:** none. #858 is still with the PR burn-down (`in-progress`, heartbeat fresh), and #865 is `ready`.
5
+
-**Ranking:**#781 (E19 Go half, ≈2) won as the top candidate free of open-PR overlap. 30 fix PRs are open, and every higher raw score sits in files they change: #856 (`vex_consumed.rs`), #773 (`commands/vendor.rs`), #816 (`commands/vex.rs`), #705 and #677 (`api/client.rs`, #865), #693, #801, #782 and #845.
6
+
-**Opened:**[#870](https://github.com/SocketDev/socket-patch/pull/870), `arch-refactor/781-go-mod-module`. It is ready for review and handed to the PR burn-down (`@bugbot review` posted; CI pending).
7
+
- Adds `go_mod_edit::module_path` on `normalize_for_read` + `for_each_directive_body`.
8
+
-`vex/product.rs``parse_go_mod` now calls it.
9
+
- Deletes `go_crawler::parse_go_mod_module` and its 13 tests.
10
+
- Red→green: `detect_go_mod_block_form_module` gets `pkg:golang/(` with `main`'s reader.
-**Register:** E19 now reads "filed #780; … go.mod `module` reader (#781) in PR #870". `doc/05-vendored.md` (Go paragraph) and `doc/06-discovery-vex.md` (go.mod row) already carry `{{E19}}`. Rewrite both after the merge.
13
+
-**Lessons:**
14
+
- In the go.mod lexer, `//` starts a comment even inside a token (`module a//b` is `a`).
15
+
-`normalize_for_read` leaves an empty literal (`""`) quoted, so readers must reject still-quoted tokens themselves.
| E16 | 2 | CRLF has five policies in the npm family and three for `toml_edit` output, and `common::detect_eol` contradicts `LineEndings::Mixed`. Target: one line-ending policy. |#814, #815| filed #814, #815; tracking #814, child 1 #815|
22
22
| E17 | 2 | "Is a bun lock present" is asked at seven sites with three semantics (lstat, `exists`, `is_file`). With a dangling `bun.lock` symlink, Bun and the writers use `bun.lockb`, but the inventory returns nothing. | 4.4 |#735| filed #735|
| E19 | 3 | Gem has three section models and three DEPENDENCIES-name parsers (vendored sees only the first `GEM` section, so #779). Go: `go_crawler::parse_go_mod_module` has no production caller; `vex/product.rs` has its own `module` reader that misreads the block form; `go_mod_edit.rs` lives in `vendor/`. | 5.4 |#780, #781| filed #780, #781; gem models (#780), go.mod `module` reader (#781) |
24
+
| E19 | 3 | Gem has three section models and three DEPENDENCIES-name parsers (vendored sees only the first `GEM` section, so #779). Go: `go_crawler::parse_go_mod_module` has no production caller; `vex/product.rs` has its own `module` reader that misreads the block form; `go_mod_edit.rs` lives in `vendor/`. | 5.4 |#780, #781| filed #780; gem models (#780) open, go.mod `module` reader (#781) in PR #870|
25
25
| E20 | 3 | Pure codecs (`bun_lockb.rs`, `bun_lock_text.rs`, `vlt_lock_text.rs`) and the neutral types (`Edit`, `Warning`, `LockfileEntry`) live outside `formats/`, which creates `formats`↔`vendor`/`redirect`/`vex` cycles. | 2.1; 4.5 #2; 4.7 J |#833, #834| filed #833, #834; tracking #833, child 1 #834 (entry types) |
26
26
| E21 | 2 | Tracking: `VendorBackend` trait + registry. The ecosystem list is enumerated at 16 production sites, and the `vend!` / `vend_installed!` macros stand in for the trait. | 2.1; 5.2; 5.8 || to verify |
27
27
| E22 | 2 | The JS vendor driver skeleton is copied eight times (`guard_coordinates` → … → a literal `VendorEntry`). Target: one generic driver + `NpmLockBackend`. | 4.4; 4.7 C || to verify |
-[#858](https://github.com/SocketDev/socket-patch/pull/858): one blocking `stage_and_rename_blocking` core with a private `WriteOpts` policy behind the six `utils::fs` writers; `atomic_write_sync`'s copy and `create_stage`/`commit_stage` deleted; one `stage_path` builds `.socket-stage-` and `.socket-dl-` names. Issue #728 (C21). Production +171 / −168, tests ≈ +85 / −12. State: ready, with the PR burn-down.
6
6
-[#865](https://github.com/SocketDev/socket-patch/pull/865): `utils::digest` gains `sha256_hex_of`, `sha1_hex_of`, `sha512_base64_of`, `sha512_sri_of`; production digest sites in the 14 files no open PR changes move onto them; `ledger_snapshots::sha256_hex`, `vlt_preflight::sha512_sri`, `nuget_feed::content_hash`, `client::is_valid_sha256_hex` and the npm_pack/bun_lock SRI blocks deleted; a ratchet lists the 6 files left for slice 2. Issue #706 slice 1 (C17).
7
7
8
+
-[#870](https://github.com/SocketDev/socket-patch/pull/870): `go_mod_edit::module_path` on the shared directive walker reads the go.mod `module` directive for VEX `--product` (fixes the block-form `module ( … )` misread); `go_crawler::parse_go_mod_module` (dead) and `product.rs`'s line scanner deleted. Issue #781 (E19 Go half). Production ≈ +22 / −64, tests ≈ +65 / −117. State: ready, with the PR burn-down.
9
+
8
10
**Merged:**
9
11
-[#850](https://github.com/SocketDev/socket-patch/pull/850): one hermetic `common/hermetic.rs` builder for CLI test children; 8 `scrub_socket_env` copies deleted, 7 unscrubbed spawners made hermetic, `spawn_env_hygiene` ratchet. Issue #823 slice 1 (C30, C47). Merged 2026-10-05 as `99f61d2`. Test-only: +745 / −322.
10
12
-[#607](https://github.com/SocketDev/socket-patch/pull/607): blob and diff downloads stream to disk through `BinaryBody`; one `download_entries` loop replaces the blob and diff copies. Issue #571 (C37). Merged 2026-10-05 as `366b155`. Production ≈ +190 / −80 (`blob_fetcher.rs`, `client.rs`), tests ≈ +230.
| 3 |#815 (E16 child 1 of #814): one `line_endings::terminator`| 0 | 1 |≈12| L | ≈14 raw | skipped: 9 of 12 copies in files changed by open PRs|
23
-
| 4 |#717 (E10 slice of #715): `formats::maven` element queries for hosted rewrite + restore | 3| 1 |4|M|13 raw |skipped: `redirect/mod.rs` changed by 7 open PRs|
24
-
| 5 |#781 (E19 Go half): go.mod `module` through `go_mod_edit`, delete `parse_go_mod_module`| 0 | 0 | ≈2| L | ≈2| free of open-PR overlap; fixes the block-form misread in VEX `--product`|
22
+
| 1 |#781 (E19 Go half): go.mod `module` through `go_mod_edit`, delete `parse_go_mod_module`| 0 |0| ≈2.2| L | ≈2| taken: PR #870 (only top candidate free of open-PR overlap)|
23
+
| 2 |#856 (E62, child 1 of #855): VEX npm aliases through the core resolver|1| 1 | ≈1.8|M| ≈5| skipped: `vex_consumed.rs` changed by 15 open fix PRs, `npm_crawler.rs` by #829|
24
+
| 3 |#773 (C44): one `Ecosystem::from_cli_name` for flag, env, socket.yml, vendor | 1 |0 | ≈2| L | ≈5 | skipped: `commands/vendor.rs`changed by #730, #776, #802, #825|
| 5 |#631 slice 1 (E52): delete `go_sum_edit`'s oracle-only free functions (no move) | 0 | 0 | ≈1.5| L | ≈1.5| free of overlap if limited to `go_sum_edit.rs`; the move touches `redirect/mod.rs` (7 open PRs)|
25
27
26
-
Re-ranked 2026-10-05T13:56Z: #850 merged; 1 open (#858). #706 slice 1 is the top candidate free of overlap (14 of its 20 production files untouched by open PRs). Also free: #631 (go_sum_edit oracle, ≈3), #801 (`wired.rs` 221 dead lines, overlaps #813/#750/#724 in `lock_inventory`). #726 waits on #858 (`utils/fs.rs`). Others unchanged from the 20261005T115639Z entry. Decisions (not candidates): #648, #704, #792, #808, #615; C07 needs an owner decision.
28
+
Re-ranked 2026-10-05T15:00Z: 3 open (#858, #865, #870). With 30 open fix PRs, most candidates overlap: #823 slice 2, #815, #717, #856 (`vex_consumed.rs`), #773 (`vendor.rs`), #816 (`commands/vex.rs`), #705 and #677 (`api/client.rs`, #865), #693 (`vendor/cargo.rs`, #598), #801 and #782 (`lock_inventory`, `vendor/state.rs`, `redirect/vlt*.rs`), #845 (`npm_crawler.rs`, #829). #726 waits on #858. Decisions (not candidates): #648, #704, #792, #808, #615; C07 needs an owner decision.
27
29
28
30
**Notes:**
29
31
- The sandbox runs as root, so 4 core lib tests fail on main and on branches alike: `copy_tree::relax_loop_must_not_traverse_symlinked_root`, `vlt_heal::an_unremovable_hidden_lock_keeps_every_store_entry`, `pypi_poetry::wire_write_failure_maps_error_and_leaves_lock_untouched`, `pypi_requirements::wire_failure_rolls_back_already_written_files`.
@@ -47,4 +49,5 @@ Re-ranked 2026-10-05T13:56Z: #850 merged; 1 open (#858). #706 slice 1 is the top
47
49
-`cargo test --test repair` under `SOCKET_DRY_RUN=true` is a quick hermeticity probe: on `main` 20 fail, after #850 only the 2 root-only tests.
48
50
-`main` @ `4646693` (#605) broke 2 `socket-patch-cli --lib``vex_consumed` alias tests, so `coverage` fails on every PR until #851 lands; #850 carries the port.
49
51
-`#[cfg(test)] mod tests` blocks often lean on the parent's `use sha2::…` through `use super::*`: removing a production import breaks the test build (`cargo test --lib --no-run`), not `cargo build`. Add the import to the test module.
52
+
- go.mod's lexer treats `//` as a comment anywhere, so `module a//b` declares `a`: don't expect `//` inside a token to be rejected.
50
53
-`vendor/berry_zip.rs`'s `berry_cache_checksum_10c0` has only test callers, so a helper used only there is dead code in the lib build.
0 commit comments