You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Delete lock_inventory::wired_vendor_integrity and PnpmLock::wired_integrity, which have no production caller #801
vendor/lock_inventory/wired.rs#L1-L221 is 221 production lines. Its one public function, wired_vendor_integrity,`` is documented as "the trust anchor for repair's no-ledger reconstruction". It reads the rewired package-lock, shrinkwrap, pnpm, yarn classic/berry, bun.lock, bun.lockb and Python locks.
Its only callers are in vendor/lock_inventory/tests.rs (lines 491–515, 1490–1508 and 2007). It is re-exported at lock_inventory/mod.rs#L79 but used nowhere in socket-patch-cli, socket-patch-node or socket-patch-bench.
commands/repair.rs no longer reconstructs from lockfile integrity. Its no-ledger path (repair.rs#L519-L535) only scopes the manifest by referenced uuids.
There are no user-visible bugs. Maintainers pay for it: 221 production lines plus about 80 test lines that model a repair path which no longer exists. The misleading doc ("trust anchor for repair") also suggests that a security property depends on it.
Proposed change
Delete:
vendor/lock_inventory/wired.rs, its mod, the re-export and the module-doc line at lock_inventory/mod.rs:15;
the wired_vendor_integrity tests in lock_inventory/tests.rs;
PnpmLock::wired_integrity and its test wired_integrity_reads_the_vendored_entry_pin_only;
the "wired_vendor_integrity(" needle in the forbidden-reader guard at vex/discover/mod.rs#L3563, plus the doc mentions in utils/python_lock.rs:36 and vex/discover/bun.rs:11.
Afterwards, delete any helper that wired.rs was the last production user of. Check with cargo clippy -D dead_code; for example, the pub(crate) lock-model accessors it imports from super::{bun,npm,yarn}.
Size and scope
Production: about −235 lines (wired.rs −221, plus the PnpmLock method and doc lines). Tests: about −90 lines.
[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: discussion #560 register.
Kind: refactor (dead code; no behavior change). Source: review 6.4, R11; register E41.
Problem (verified on
045d7ec)vendor/lock_inventory/wired.rs#L1-L221is 221 production lines. Its one public function,wired_vendor_integrity,`` is documented as "the trust anchor for repair's no-ledger reconstruction". It reads the rewired package-lock, shrinkwrap, pnpm, yarn classic/berry, bun.lock, bun.lockb and Python locks.vendor/lock_inventory/tests.rs(lines 491–515, 1490–1508 and 2007). It is re-exported atlock_inventory/mod.rs#L79but used nowhere insocket-patch-cli,socket-patch-nodeorsocket-patch-bench.commands/repair.rsno longer reconstructs from lockfile integrity. Its no-ledger path (repair.rs#L519-L535) only scopes the manifest by referenced uuids.formats::pnpm::PnpmLock::wired_integrityis called only fromwired.rs:141and its own unit test, so it is dead too.wired.rsimportscrate::vex::discover::{vendor_ref, vendor_ref_decorated}, avendor→vexedge against the intended layering.Symptoms / impact
There are no user-visible bugs. Maintainers pay for it: 221 production lines plus about 80 test lines that model a repair path which no longer exists. The misleading doc ("trust anchor for repair") also suggests that a security property depends on it.
Proposed change
Delete:
vendor/lock_inventory/wired.rs, itsmod, the re-export and the module-doc line atlock_inventory/mod.rs:15;wired_vendor_integritytests inlock_inventory/tests.rs;PnpmLock::wired_integrityand its testwired_integrity_reads_the_vendored_entry_pin_only;"wired_vendor_integrity("needle in the forbidden-reader guard atvex/discover/mod.rs#L3563, plus the doc mentions inutils/python_lock.rs:36andvex/discover/bun.rs:11.Afterwards, delete any helper that
wired.rswas the last production user of. Check withcargo clippy -D dead_code; for example, thepub(crate)lock-model accessors it imports fromsuper::{bun,npm,yarn}.Size and scope
wired.rs−221, plus thePnpmLockmethod and doc lines). Tests: about −90 lines.vendor/lock_inventory/{wired,mod,tests}.rs,formats/pnpm/mod.rs,vex/discover/{mod,bun}.rs,utils/python_lock.rs.vex/discover/deno.rs, which is a deliberate, documented empty extractor;list,rollbackretire_legacy_redirect_ledger);Acceptance criteria
grep -rn "wired_vendor_integrity\|fn wired_integrity" cratesreturns nothing.vendor/lock_inventory/no longer imports fromcrate::vex.cargo test -p socket-patch-core --lib,cargo test -p socket-patch-cliandcargo clippy --workspace --all-features -- -D warningsstay green.repaire2e tests stay green unchanged, which shows that no runtime path used it.Dependencies