[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: register comment.
Kind: tracking. Source: review Part 6.5 ("vex_consumed.rs is a third copy of package-manager layout knowledge"); register E40, plus new finding E62.
Problem
commands/vex_consumed.rs decides which installed copy a hosted build consumes. The review measured it at 596 lines; on 4646693 it is 1,173. It is the only place this layout knowledge lives, and it lives in the CLI, beside crawlers in core that know the same layouts:
Target design
HostedCopies already lives in core (vex/verify.rs#L98). Each crawler gains a consumed_copies(options, purl, wiring) that applies its ecosystem's rule and reuses that ecosystem's own grammar (the cargo source parser, formats::maven's suffix grammar, go_mod_edit). The CLI's hosted_consumed_copies becomes a dispatch over those, or moves whole into core::vex. Every grammar listed above is then defined once.
Children (in order, one PR each)
Size and scope
Five PRs of 100–300 production lines each, every one deleting the CLI copy it replaces. Out of scope: changing which copies count as evidence (that is decision E46).
Acceptance criteria
Dependencies
Child 1 should land after #851, which edits the same tests. Coordinate child 3 with #715, and child 4 with #781.
[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: register comment.
Kind: tracking. Source: review Part 6.5 ("
vex_consumed.rsis a third copy of package-manager layout knowledge"); register E40, plus new finding E62.Problem
commands/vex_consumed.rsdecides which installed copy a hosted build consumes. The review measured it at 596 lines; on4646693it is 1,173. It is the only place this layout knowledge lives, and it lives in the CLI, beside crawlers in core that know the same layouts:npm_alias_copies_reusing, L224-L289).Since #738 and #605 the core resolver finds alias copies too ([`NpmCrawler::alias_copies`](https://github.com/SocketDev/socket-patch/blob/4646693150cf5efca6222b87092e1620e58566f8/crates/socket-patch-core/src/crawlers/npm_crawler.rs#L1559-L1609)),`` and the two have already drifted (child 1).Cargo.locksource-host parser and cargo'sregistry/src/<host>-<16 hex>naming (registry_host…cached_crate, L514-L571).`CargoCrawler` owns `registry/src` enumeration ([`cargo_crawler.rs#L274`](https://github.com/SocketDev/socket-patch/blob/4646693150cf5efca6222b87092e1620e58566f8/crates/socket-patch-core/src/crawlers/cargo_crawler.rs#L274)),`` andvex/discover/cargo.rshas its ownsparse+/registry+source check (source_uuid).``format!("{version}-socket.{hex8}")fromuuid.get(..8)(L575-L612).The `<base>-socket.<hex8>` grammar is also written in [`jvm::Coords::suffixed_version`](https://github.com/SocketDev/socket-patch/blob/4646693150cf5efca6222b87092e1620e58566f8/crates/socket-patch-core/src/vendor/jvm/mod.rs#L95-L109) (lowercases and drops dashes; the CLI copy does neither), [`formats::maven::split_socket_version`](https://github.com/SocketDev/socket-patch/blob/4646693150cf5efca6222b87092e1620e58566f8/crates/socket-patch-core/src/formats/maven/mod.rs#L9-L22), [`maven_reactor::is_base_like`](https://github.com/SocketDev/socket-patch/blob/4646693150cf5efca6222b87092e1620e58566f8/crates/socket-patch-core/src/vendor/jvm/maven_reactor.rs#L1073-L1084``) andreferences_other_patch.`` That makes two builders and three parsers.golang_replacement, L399-L438) re-derives "is this our socket module" fromHOSTED_GO_MODULE_PREFIXbesidevendor::go_mod_edit.Target design
HostedCopiesalready lives in core (vex/verify.rs#L98). Each crawler gains aconsumed_copies(options, purl, wiring)that applies its ecosystem's rule and reuses that ecosystem's own grammar (the cargo source parser,formats::maven's suffix grammar,go_mod_edit). The CLI'shosted_consumed_copiesbecomes a dispatch over those, or moves whole intocore::vex. Every grammar listed above is then defined once.Children (in order, one PR each)
CargoCrawler, with oneCargo.lockregistry-source parser shared withvex/discover/cargo.rs.<base>-socket.<hex8>builder and parser informats::maven, used byjvm::Coords,maven_reactorand the maven consumed-copy rule, which then moves intoMavenCrawler.go_mod_edit(coordinate with Read the go.mod module directive through go_mod_edit and delete the crawler's unused parse_go_mod_module #781, which moves the go.modmodulereader).hosted_consumed_copiesintocore::vex.vex_consumed.rsis then deleted.Size and scope
Five PRs of 100–300 production lines each, every one deleting the CLI copy it replaces. Out of scope: changing which copies count as evidence (that is decision E46).
Acceptance criteria
vex_consumed.rsno longer exists, and the CLI holds no package-manager layout rules.commands::vex_consumedtest is ported to core and stays green, along withvexe2e and the hosted VEX goldens.Dependencies
Child 1 should land after #851, which edits the same tests. Coordinate child 3 with #715, and child 4 with #781.