Skip to content

Share the npm-family wiring kinds and line-array codec between the vendored backends and lock_inventory::recover #835

Description

[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: discussion #560 register.

Kind: refactor. Source: review Part 4.4 (JS helper copies: "wiring lines ↔ JSON ×3", "KIND_* re-spelled as literals"); register E18.

Problem

The vendor ledger's WiringRecord.kind strings and the encoding of a line-shaped original are the contract between each vendored writer and the readers that recover a pre-vendor fragment. Today each side spells them on its own.

1. Kind constants are private, so the reader re-spells them. Each backend defines its kinds as private consts, for example KIND_LOCK_ENTRY = "npm_lock_entry" (npm_lock.rs#L64-L65), KIND_LOCK_BLOCK (yarn_classic_lock.rs#L51), the berry kinds ([`yarn_berry_lock.rs#L84-L85`](https://github.com/SocketDev/socket-patch/blob/045d7ec783d788bf3c5a1310724b51e09fb6505d/crates/socket-patch-core/src/vendor/yarn_berry_lock.rs#L84-L85)),`` the bun kind (bun_lock.rs#L86) and the vlt kinds (vlt_lock.rs#L55-L57).

lock_inventory::recover matches on 7 string literals instead: "npm_lock_entry", "npm_lock_legacy_entry", "pnpm_lock_package", "yarn_lock_block", "yarn_berry_lock_entry", "vlt_lock_node" and "bun_lock_package" (recover.rs#L308, [`#L323`](https://github.com/SocketDev/socket-patch/blob/045d7ec783d788bf3c5a1310724b51e09fb6505d/crates/socket-patch-core/src/vendor/lock_inventory/recover.rs#L323),`` #L335, [`#L364`](https://github.com/SocketDev/socket-patch/blob/045d7ec783d788bf3c5a1310724b51e09fb6505d/crates/socket-patch-core/src/vendor/lock_inventory/recover.rs#L364),`` #L404, [`#L421`](https://github.com/SocketDev/socket-patch/blob/045d7ec783d788bf3c5a1310724b51e09fb6505d/crates/socket-patch-core/src/vendor/lock_inventory/recover.rs#L421)).`` A rename on the writer side would compile and silently stop recovery.

2. The line-array codec is written five times, with two decoding rules.

Symptoms

None filed. Impact: low risk and small; it removes a silent-coupling hazard on the revert/recovery path.

Proposed change

  • One vendor::wiring module (next to WiringRecord in state.rs, or a small vendor/wiring_kinds.rs) holding pub(crate) consts for the 7 npm-family kinds recover reads. The backends import them instead of redefining their private copies (the other private kinds can move too, but needn't).
  • One codec in the same module: lines_to_value(&[String]) -> Value and value_to_lines(&Value) -> Option<Vec<String>>, with the strict rule (any non-string element → None, so revert and recovery refuse a damaged record rather than splicing a partial one).
  • Delete pnpm_lock::lines_value, pnpm_lock::value_lines, recover::lines_of and yarn_classic_lock::{lines_to_json, json_to_lines}, and replace the 7 literals in recover.rs.

Size and scope

vendor/{state.rs or wiring_kinds.rs, recover.rs, pnpm_lock.rs, pnpm_lock_legacy.rs, yarn_classic_lock.rs, yarn_berry_lock.rs, npm_lock.rs, bun_lock.rs, vlt_lock.rs}; about −40/+30 production lines. Out of scope: the other E18 items (name@spec split ×2, recursion bounds, per-loop regex compilation); the JSON-pointer escape is already in #663.

Acceptance criteria

  • grep -n '"npm_lock_entry"\|"yarn_lock_block"\|"pnpm_lock_package"' crates/socket-patch-core/src/vendor/lock_inventory/recover.rs finds nothing in production code.
  • One encoder and one decoder remain, and a unit test shows that a record with a non-string element decodes to None.
  • recover_tests.rs (whose fixture literals pin the persisted kind strings and must stay as literals) and the pnpm/yarn revert suites stay green.

Dependencies

None. It touches pnpm_lock.rs and yarn_* files that open PRs may also edit (#657); keep the diff to the helper sites.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:triagedarch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)priority:p3refactorStructural change: duplicated code or logic, missing abstraction, layering, dead code

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions