[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: register comment.
Kind: refactor (docs + guard test). Source: new finding; register row C40. It is related to review 8.5 F (generated contract) but narrower.
Problem
Two operator-facing environment variables that core reads appear in no documentation at all: not in CLI_CONTRACT.md, the README or docs/.
Its sibling knob SOCKET_API_MAX_RETRIES is documented (CLI_CONTRACT.md#L141). The difference is a guard: GLOBAL_ARG_ENV_VARS and LOCAL_ARG_ENV_VARS (args.rs#L580-L631) and their invariant tests cover only clap-bound variables. Variables that core reads directly through std::env::var have no check, so each one is documented, or not, by hand.
Evidence by execution on 045d7ec, run twice: every "SOCKET_*" literal under crates/socket-patch-{core,cli}/src was checked against CLI_CONTRACT.md. 84 names, 16 missing:
- the two above, which are operator-facing;
- 14 test-only hooks (
SOCKET_PATCH_FAILPOINT, SOCKET_PATCH_SWITCH_OFF, SOCKET_TEST_PEER_*, *_GOLDEN, *_FSIZE_CHILD, and SOCKET_PATCH_GIT_SHA/SOCKET_PATCH_TARGET, which are build-time env!).
The reverse check finds no phantoms: the four contract-only names are the documented v5.0 removals.
The knobs also disagree on 0: SOCKET_API_MAX_RETRIES=0 disables retries, SOCKET_API_CONCURRENCY=0 is ignored with a --debug note, and SOCKET_WALK_THREADS=0 silently keeps the default. That vocabulary is C19's to unify; this issue only documents current behavior.
Symptoms
#614 (the knob is unreachable for anyone who hasn't read the source). Impact: low risk, small size. Operators behind rate-limiting proxies can't discover the supported throttle.
Proposed change
- Add both variables to
CLI_CONTRACT.md. SOCKET_API_CONCURRENCY goes in the "Config-layer toggles (env-only)" table, with range, default and the 0 behavior. SOCKET_WALK_THREADS goes in "Internal env vars", unless the maintainers want it public.
- Add one guard test in
socket-patch-cli/tests/. It collects every "SOCKET_[A-Z0-9_]+" literal from crates/socket-patch-{core,cli}/src, skipping #[cfg(test)] modules or using an explicit allowlist of test hooks, and asserts that each appears in CLI_CONTRACT.md. It should also assert the reverse for names outside the "Removed env vars" section.
This deletes nothing. It is the env-var slice of 8.5 F and needs no generator.
Size and scope
CLI_CONTRACT.md (+2 rows) and one new test of about 60 lines. Out of scope: renaming or re-parsing any variable (C19, #615).
Acceptance criteria
Dependencies
None. Related: C19 (env vocabulary), C33 (generated contract) and #614.
[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: register comment.
Kind: refactor (docs + guard test). Source: new finding; register row C40. It is related to review 8.5 F (generated contract) but narrower.
Problem
Two operator-facing environment variables that core reads appear in no documentation at all: not in
CLI_CONTRACT.md, the README ordocs/.SOCKET_API_CONCURRENCY(utils/concurrent.rs#L55-L63, read at#L156-L178). It caps in-flight patch-API requests for everyscan,get,vexand vendored window, between 1 and 32. Its own doc comment calls it the escape hatch for "a self-hosted--api-url, a corporate reverse proxy, a WAF or CDN", which is exactly what users need to find. The public-proxy per-package fallback runs 10 requests in flight, ignoring SOCKET_API_CONCURRENCY and the proxy cap of 4 #614 is about a path that ignores it.SOCKET_WALK_THREADS(crawlers/walk_pool.rs#L88-L94, read at#L235). It sizes the crawl and POM-parse pool. It came in with Keep Composer redirects and rollback consistent #358.Its sibling knob
SOCKET_API_MAX_RETRIESis documented (CLI_CONTRACT.md#L141). The difference is a guard:GLOBAL_ARG_ENV_VARSandLOCAL_ARG_ENV_VARS(args.rs#L580-L631) and their invariant tests cover only clap-bound variables. Variables that core reads directly throughstd::env::varhave no check, so each one is documented, or not, by hand.Evidence by execution on
045d7ec, run twice: every"SOCKET_*"literal undercrates/socket-patch-{core,cli}/srcwas checked againstCLI_CONTRACT.md. 84 names, 16 missing:SOCKET_PATCH_FAILPOINT,SOCKET_PATCH_SWITCH_OFF,SOCKET_TEST_PEER_*,*_GOLDEN,*_FSIZE_CHILD, andSOCKET_PATCH_GIT_SHA/SOCKET_PATCH_TARGET, which are build-timeenv!).The reverse check finds no phantoms: the four contract-only names are the documented v5.0 removals.
The knobs also disagree on
0:SOCKET_API_MAX_RETRIES=0disables retries,SOCKET_API_CONCURRENCY=0is ignored with a--debugnote, andSOCKET_WALK_THREADS=0silently keeps the default. That vocabulary is C19's to unify; this issue only documents current behavior.Symptoms
#614 (the knob is unreachable for anyone who hasn't read the source). Impact: low risk, small size. Operators behind rate-limiting proxies can't discover the supported throttle.
Proposed change
CLI_CONTRACT.md.SOCKET_API_CONCURRENCYgoes in the "Config-layer toggles (env-only)" table, with range, default and the0behavior.SOCKET_WALK_THREADSgoes in "Internal env vars", unless the maintainers want it public.socket-patch-cli/tests/. It collects every"SOCKET_[A-Z0-9_]+"literal fromcrates/socket-patch-{core,cli}/src, skipping#[cfg(test)]modules or using an explicit allowlist of test hooks, and asserts that each appears inCLI_CONTRACT.md. It should also assert the reverse for names outside the "Removed env vars" section.This deletes nothing. It is the env-var slice of 8.5 F and needs no generator.
Size and scope
CLI_CONTRACT.md(+2 rows) and one new test of about 60 lines. Out of scope: renaming or re-parsing any variable (C19, #615).Acceptance criteria
grep -c SOCKET_API_CONCURRENCY crates/socket-patch-cli/CLI_CONTRACT.md≥ 1, and the same forSOCKET_WALK_THREADS.std::env::var("SOCKET_NEW_KNOB")is added to core without a contract row. Check this locally once.GLOBAL_ARG_ENV_VARS/LOCAL_ARG_ENV_VARSinvariant tests stay green.Dependencies
None. Related: C19 (env vocabulary), C33 (generated contract) and #614.