Skip to content

Tracking: scope project-mode cache crawls to what the project resolves #595

Description

[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: E05.

Kind: tracking. Source: review §3 #3 and Part 6.6; register E05 (a step toward E36, one Inventory).

Problem

In local (project) mode, five crawlers return the whole machine cache as soon as the project has a marker file. Nothing narrows it to what the project resolves:

Crawler Marker gate Root returned
CargoCrawler::get_crate_source_paths Cargo.toml / Cargo.lock vendor/, else every $CARGO_HOME/registry/src/*
GoCrawler::get_module_cache_paths go.mod / go.sum GOMODCACHE
MavenCrawler::get_maven_repo_paths pom.xml, build.gradle*, settings.gradle* ~/.m2/repository
NuGetCrawler::get_nuget_package_paths any .csproj/.fsproj/.vbproj/.sln/.slnx, packages.config, nuget.config packages/, ~/.nuget/packages, every packageFolders key
DenoCrawler::get_jsr_cache_paths deno.json(c) / deno.lock $DENO_DIR/npm/jsr.io

scan feeds this crawl (crawl_every_ecosystem) to the patch API and to agent-mode apply and VEX. For Maven and NuGet the crawl is the only discovery.

Symptoms

Impact

These are wrong answers from a security tool: agent mode patches, and VEX attests, packages the project never uses, and scan sends every cached coordinate on the machine to the API. Scan cost grows with the machine cache, not with the project.

Target design

In project mode, crawlers become locators. The candidate set comes from the project's own resolution data, and the cache is consulted only to find the bytes for a coordinate:

  • fn project_coordinates(cwd) -> Option<Vec<Coordinate>> per ecosystem, built on the existing readers: Cargo.lock (formats::cargo), go.sum/go.mod (go_mod_edit/go_sum_edit), packages.lock.json / obj/project.assets.json libraries, the deno.lock jsr section, and Maven/Gradle lockfiles or the reactor's resolved POM set (vendor::jvm).
  • crawl_all in project mode becomes find_by_purls(cache, project_coordinates). Enumerating the whole cache stays, for --global / --global-prefix only.
  • When project_coordinates returns None (no lock or resolution file), keep today's enumeration but emit an explicit warning code (for example crawl_unscoped_cache), so lockless projects keep working and the result is labelled. Existing warning codes don't change.

Checklist (one PR each, in order)

Each child deletes its whole-cache path from project mode and adds a test with an unrelated package in the fake cache that must not appear in crawl_all.

Acceptance criteria

  • In project mode with a lock or resolution file, no crawler returns a package the project doesn't resolve.
  • --global output is unchanged.
  • The crawler oracle and equivalence suites, which encode today's whole-cache output, are updated deliberately rather than silenced.

Dependencies

Part of E36 (one Inventory). The NuGet child benefits from the shared packages.lock.json walker in #593 but doesn't need it. The FIFO fix #592 touches the same crawlers and should land first.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:triagedarch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)priority:p3refactorStructural change: duplicated code or logic, missing abstraction, layering, dead code

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions