[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: C11.
Kind: refactor. Source: review §2.2 and R5; register C11, child 1 of tracking #843.
Problem
The inventory phase of run_scan is about 210 inline lines, L1560–L1771: crawler options and the status line, the crawl (with or without the npm crawl kept for the vendored and VEX paths), the [lockfile supplement](https://github.com/SocketDev/socket-patch/blob/045d7ec783d788bf3c5a1310724b51e09fb6505d/crates/socket-patch-cli/src/commands/scan/mod.rs#L1593), layout-refusal warnings, the [vendored-ledger supplement](https://github.com/SocketDev/socket-patch/blob/045d7ec783d788bf3c5a1310724b51e09fb6505d/crates/socket-patch-cli/src/commands/scan/mod.rs#L1624-L1642),`` the scanned/vendored/vendor-owned purl sets, the hosted pins and update manifest, and the three successive filtered_crawled passes (package specs, path scope, the final filter), ending in all_purls and package_count at L1770–L1771.``
The block has no early return. It only builds about 20 locals that the rest of the function reads. Because they are locals of the 1,540-line body, nothing else (for example a test, or a future ModeBackend) can get "what this scan covers" without running the whole scan.
Impact
Low risk, and it unblocks the rest of the split: children 3–5 need the inventory as a value to hand to the selection and the mode consumers.
Proposed change
- Add
struct ScanInventory, holding the locals the later phases read (all_crawled, eco_counts, npm_crawl, lockfile_only, layout_refusals, scanned_purls, vendored_purls, vendor_owned_purls, unwired_vendored, hosted_pins, update_manifest, filtered_crawled, all_purls, …).
- Add
async fn collect_inventory(args, ctx, policy, path_scope, mode, prune, status) -> ScanInventory in a new scan/inventory.rs, and move the block there verbatim.
run_scan calls it once and destructures the result. Deleted: the ~210 inline lines.
- No behavior change: same crawl, same order of warnings, same status-line text.
Size and scope
scan/mod.rs (−~210) and a new scan/inventory.rs (+~240), with no changes to other files. Out of scope: the batch query, the selection and the mode dispatch (later children), and any change to what is crawled.
Acceptance criteria
Dependencies
None; it can start now. It blocks children 3–5 of #843.
[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: C11.
Kind: refactor. Source: review §2.2 and R5; register C11, child 1 of tracking #843.
Problem
The inventory phase of
run_scanis about 210 inline lines, L1560–L1771:crawler options and the status line, the crawl (with or without the npm crawl kept for the vendored and VEX paths), the [lockfile supplement](https://github.com/SocketDev/socket-patch/blob/045d7ec783d788bf3c5a1310724b51e09fb6505d/crates/socket-patch-cli/src/commands/scan/mod.rs#L1593), layout-refusal warnings, the [vendored-ledger supplement](https://github.com/SocketDev/socket-patch/blob/045d7ec783d788bf3c5a1310724b51e09fb6505d/crates/socket-patch-cli/src/commands/scan/mod.rs#L1624-L1642),`` the scanned/vendored/vendor-owned purl sets, the hosted pins and update manifest, and the three successivefiltered_crawledpasses (package specs, path scope, the final filter), ending inall_purlsandpackage_countat L1770–L1771.``The block has no early return. It only builds about 20 locals that the rest of the function reads. Because they are locals of the 1,540-line body, nothing else (for example a test, or a future
ModeBackend) can get "what this scan covers" without running the whole scan.Impact
Low risk, and it unblocks the rest of the split: children 3–5 need the inventory as a value to hand to the selection and the mode consumers.
Proposed change
struct ScanInventory, holding the locals the later phases read (all_crawled,eco_counts,npm_crawl,lockfile_only,layout_refusals,scanned_purls,vendored_purls,vendor_owned_purls,unwired_vendored,hosted_pins,update_manifest,filtered_crawled,all_purls, …).async fn collect_inventory(args, ctx, policy, path_scope, mode, prune, status) -> ScanInventoryin a newscan/inventory.rs, and move the block there verbatim.run_scancalls it once and destructures the result. Deleted: the ~210 inline lines.Size and scope
scan/mod.rs(−~210) and a newscan/inventory.rs(+~240), with no changes to other files. Out of scope: the batch query, the selection and the mode dispatch (later children), and any change to what is crawled.Acceptance criteria
run_scanno longer contains the crawl or the filters. It reads them from oneScanInventory.scanintegration targets, the--jsonsnapshots and the benchmark gate (Add ascanbenchmark suite and a CI performance gate #485) stay green.collect_inventoryon a small fixture and checksall_purlsagainst the path-scope and package-spec filters.Dependencies
None; it can start now. It blocks children 3–5 of #843.