|
| 1 | +[agent] 2026-10-06: architecture audit (ecosystems and formats) |
| 2 | + |
| 3 | +**main @ `9c43dfc`**, unchanged since the last run. There were no new maintainer replies in the discussion and no handovers for this routine. |
| 4 | + |
| 5 | +**Reconciled.** |
| 6 | +- No status changed: E09/E51 are still in #657 and E64 is still in #909. No open PR references my other issues, except #927, which only cites #883. |
| 7 | +- With `main` unchanged, re-checking open issues would only repeat last run's permalinks, so I skipped it. |
| 8 | + |
| 9 | +**Verified and filed: E23 → [#937](https://github.com/SocketDev/socket-patch/issues/937)** (refactor). |
| 10 | +- `pypi_poetry.rs`, `pypi_pdm.rs` and `pypi_pipenv.rs` each wrap their format edit in the same envelope: |
| 11 | + - symlink refusal; |
| 12 | + - guards; |
| 13 | + - a defensive `InSync` refusal (the message is spelled three times); |
| 14 | + - `ensure_unchanged`; |
| 15 | + - memo invalidation; |
| 16 | + - a mode-preserving write mapped to `pypi_<flavor>_write_failed`. |
| 17 | +- Each revert opens with the same `kept_artifact: true` symlink prelude, and each backend has its own `{Fresh, InSync}` enum. |
| 18 | +- No drift is proven in the envelope. The issue proposes one shared module with flavor-derived codes (byte-identical strings), about −150 / +80 production lines. |
| 19 | + |
| 20 | +**New finding: E66, [#936](https://github.com/SocketDev/socket-patch/issues/936)** (refactor, `pm:poetry`). `wire_poetry` picks its forward splicer by line ending: |
| 21 | +- legacy and CRLF locks go through the shared `utils::poetry_lock` engine, which hosted mode uses too; |
| 22 | +- LF 2.x locks go through the private `toml_surgery` line scanner, `rewrite_target_package_unit`. |
| 23 | + |
| 24 | +**Proof:** a throwaway test, run twice on `9c43dfc`, wired each of the three 2.x fixtures as LF and as CRLF. |
| 25 | +- The outputs differ every time. LF writes Poetry's multi-line `files = [\n {file = …},\n]`; CRLF writes the inline `files = [{ file = … }]`. |
| 26 | +- Wheel `evil-9.9-py3-none-any.whl` wires on LF but is refused on CRLF. |
| 27 | +- An uppercase digest is written uppercase on LF and lowercase on CRLF. The engine's comment says an uppercase digest would fail every install. |
| 28 | +- The last two gates are latent with today's orchestrator inputs. |
| 29 | + |
| 30 | +The target is for the engine to emit Poetry's multi-line shape, which also aligns hosted output. The LF branch, `replace_files_array`, `package_unit_lines` and `unit_has_canon_name` would be deleted. |
| 31 | + |
| 32 | +**Searched without filing:** |
| 33 | +- PDM reverts non-atomically, while Poetry uses `revert_lock_fragment_splice_atomic`. This is documented, because PDM records a single fragment per unit, so it is not drift. |
| 34 | +- Only PDM has the partial-relock patched-hash guard (`target_carries_patched_wheel_hash`). I couldn't show that Poetry can reach the same state, so I didn't claim it. |
| 35 | +- requirements, pylock and Hatch don't call `ensure_unchanged`. requirements re-reads its files at wire time, and pylock and Hatch have their own compare-before-write (`pypi_lock_changed`, "Hatch configuration changed"). So none of them lacks the race guard. |
| 36 | +- Duplicate check for #936: #694 and #703 covered the utils engines only. Open PR #877 touches `utils/poetry_lock.rs` for parse reuse and not the vendored line scanner. |
| 37 | + |
| 38 | +**False positives ruled out:** |
| 39 | +- The wheel-name and uppercase-digest gate gap is not a live bug today. The orchestrator always passes a wheel it built for that package and a lowercase sha. It is recorded as drift, not filed as a bug. |
| 40 | + |
| 41 | +**Living document:** |
| 42 | +- Part 5 §5.4 Python: the skeleton bullet now describes the shared envelope with {{E23}}, and a new two-splicers bullet has {{E66}}. |
| 43 | +- Part 5: a new-findings bullet for {{E66}}; the check line is updated. |
| 44 | +- The register files E23 and adds E66. |
| 45 | + |
| 46 | +**Next backlog rows:** E08 (yarn grammars; after #657), E21 (`VendorBackend` tracking; count `Ecosystem` match sites), E14 (Pipfile.lock, still unproven), E24 (the nine revert mechanisms), E42 (embedded `--vex` glue; consider handing it to `audit-core`). |
| 47 | + |
| 48 | +--- |
| 49 | +_Generated by [Claude Code](https://claude.ai/code)_ |
0 commit comments