Skip to content

Delete the vendored and hosted-vlt helpers left without a production caller by the v5 consolidation #782

Description

[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: discussion #560 register.

Kind: refactor. Source: new finding, register E58. The vlt part is the review's "delete the dead vlt ledger helpers" (Part 3.6 and Part 3 recommendation 7, register E34).

Problem

A sweep of every pub/pub(crate) item in formats/, patch/redirect/, hosted/, vendor/, crawlers/ and vex/ for references outside #[cfg(test)] code, across the whole workspace including socket-patch-node, found these on 045d7ec. Most lost their last caller when #277 (the v5 consolidation) deleted the redirect-ledger merge and the deferred-download path.

No reference anywhere, not even a test:

Used only by their own unit tests:

Test helpers compiled into production builds (their only callers are inside #[cfg(test)] modules):

Symptoms and impact

No user-visible bug. The cost is ~150–180 production lines that look live, are pub, and are kept compiling and tested. carried_pin_original and ledger_targets in particular read as if hosted vlt still merges and heals from the redirect ledger, which misleads anyone working on hosted rollback (E33/E45).

Proposed change

  1. Delete committed_artifact_intact, go_sum_edit::remove_lines, vlt::edit_dep_id, vlt::lock_node_ids, vlt::carried_pin_original, vlt_heal::ledger_targets, and the helpers that become unused (carried_pin_ids, carried_pin_lines, same_slots, and claims_key if nothing else is left calling it), together with their tests.
  2. Gate seed_rubygems_sha256, copy_manifest_tag and read_project_file with #[cfg(test)], or move them into the test modules that use them.
  3. Correct the doc comments that still describe the deleted paths (vlt_heal module doc, LedgerTarget::record).

Size and scope

About −170 production and −150 test lines in vendor/state.rs, vendor/go_sum_edit.rs, patch/redirect/vlt.rs, patch/redirect/vlt_heal.rs, patch/redirect/upstream/client.rs, vendor/cargo_tag.rs and vendor/jvm/apply.rs. It's mechanical, with no behavior change. Out of scope:

  • the legacy redirect-ledger readers (redirect_record_live, hosted_wiring_in_files; E41);
  • save_redirect_state and the ledger's group-commit entry (audit-core's legacy-ledger rows);
  • the #[cfg(test)] oracles in registry_fetch.rs and reuse.rs (E35).

Acceptance criteria

  • None of the deleted names appear under crates/.
  • cargo build -p socket-patch-cli --release has no new dead_code warnings. cargo test -p socket-patch-core, the vlt suites (e2e_redirect_vlt_build, e2e_vlt, mode_migration_vlt, in_process_rollback_hosted) and cargo clippy --all-targets stay green.
  • The vlt_heal tests that exercised ledger_targets are deleted or retargeted at lock_targets, with no loss of lock_targets coverage.

Dependencies

None; it can start now. It touches go_sum_edit.rs lightly, so whichever of this and #631 lands second drops remove_lines from its list.


Consolidated work — backlog review, 2026-10-08

The following standalone issues are now tracked here. Their closure consolidates scheduling; it does not mean their implementation is complete. Original reports and discussion remain linked below.

#746: Delete PatchSources::mem_blobs, the single-variant VendorSource predicates, the redirect-state group-commit capture and the group_commit switch-off oracle

Preserved scope and acceptance criteria from #746

Proposed change

Delete:

  • the mem_blobs field, its branch in apply.rs, its ~25 mem_blobs: None initializers and the fixture read;
  • VendorSource::{may_use_service, requires_service} and the always-true condition at vendor.rs:141. Keep VendorSource::parse and the --vendor-source flag, because accepting service/auto and rejecting build is contract (CLI_CONTRACT "Prebuilt vendor artifacts"). Removing the flag is out of scope (decision C35);
  • the redirect-state.json entry from group_commit::LEDGERS, along with its doc line and its test row (group_commit.rs:1071);
  • the switched_off("group_commit") guard, failpoint::switched_off if it is then unused, and the oracle test (or turn it into a golden check of the group-commit output).

Size and scope

  • Production: about −60 lines. Tests: about −350 lines.
  • Files: patch/apply.rs, vendor/{mod,npm_flavor}.rs, vendor/test_support/service_fixture.rs, utils/{group_commit,failpoint}.rs, commands/{vendor,repair,fetch_stage}.rs, commands/vendored_backend/mod.rs, tests/vendor_group_commit_e2e.rs.
  • Out of scope: --vendor-source removal, the update channels, the pre-v5 redirect ledger readers (migration).

Acceptance criteria

  • grep -rn mem_blobs crates returns nothing.
  • VendorSource has no always-true predicate, and --vendor-source service|auto still parses while build is still rejected (the args.rs tests stay green).
  • group_commit::LEDGERS lists only .socket/vendor/state.json; the group-commit crash and replay tests stay green.
  • No SOCKET_PATCH_SWITCH_OFF reference remains (or one documented user, if a maintainer wants to keep the mechanism).
  • cargo test -p socket-patch-core --lib and cargo test -p socket-patch-cli stay green; cargo clippy --workspace --all-features -- -D warnings stays clean.

#800: Replace the single-variant vendor PackageSource with &Path and delete the scaffolding it props up

Preserved scope and acceptance criteria from #800

Proposed change

Delete:

  • vendor/source.rs and the PackageSource re-export. Every impl Into<PackageSource<'a>> parameter becomes &'a Path; .into() / .path() calls go away.
  • vend_installed!. NuGet and Maven dispatch through vend!, and the tautological debug_assert! goes. StagedSource::as_source returns &Path.
  • the SERVICE_ECOSYSTEMS block, the vendor_service_unsupported_ecosystem code and service_mode_gate_admits_maven.
  • the _cfg parameter of ServicePolicy::new and the argument at its 10 call sites.

Size and scope

Acceptance criteria

  • grep -rn "PackageSource\b" crates --include=*.rs returns only NuGet-XML text (packageSource…), not the type.
  • grep -rn "vend_installed\|SERVICE_ECOSYSTEMS\|vendor_service_unsupported_ecosystem" crates returns nothing.
  • ServicePolicy::new takes only the terminal.
  • patch/redirect/golang_local.rs no longer imports from crate::vendor for this type.
  • cargo test -p socket-patch-core --lib, cargo test -p socket-patch-cli and cargo clippy --workspace --all-features -- -D warnings stay green. No golden or e2e output changes.

#801: Delete lock_inventory::wired_vendor_integrity and PnpmLock::wired_integrity, which have no production caller

Preserved scope and acceptance criteria from #801

Proposed change

Delete:

  • vendor/lock_inventory/wired.rs, its mod, the re-export and the module-doc line at lock_inventory/mod.rs:15;
  • the wired_vendor_integrity tests in lock_inventory/tests.rs;
  • PnpmLock::wired_integrity and its test wired_integrity_reads_the_vendored_entry_pin_only;
  • the "wired_vendor_integrity(" needle in the forbidden-reader guard at vex/discover/mod.rs#L3563, plus the doc mentions in utils/python_lock.rs:36 and vex/discover/bun.rs:11.

Afterwards, delete any helper that wired.rs was the last production user of. Check with cargo clippy -D dead_code; for example, the pub(crate) lock-model accessors it imports from super::{bun,npm,yarn}.

Size and scope

  • Production: about −235 lines (wired.rs −221, plus the PnpmLock method and doc lines). Tests: about −90 lines.
  • Files: vendor/lock_inventory/{wired,mod,tests}.rs, formats/pnpm/mod.rs, vex/discover/{mod,bun}.rs, utils/python_lock.rs.
  • Out of scope:

Acceptance criteria

  • grep -rn "wired_vendor_integrity\|fn wired_integrity" crates returns nothing.
  • vendor/lock_inventory/ no longer imports from crate::vex.
  • cargo test -p socket-patch-core --lib, cargo test -p socket-patch-cli and cargo clippy --workspace --all-features -- -D warnings stay green.
  • repair e2e tests stay green unchanged, which shows that no runtime path used it.

Activity

  1. added
    arch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)
    refactorStructural change: duplicated code or logic, missing abstraction, layering, dead code
    on Oct 4, 2026
  2. added a commit that references this issue on Oct 4, 2026
  3. mikolalysenko commented on Oct 4, 2026

    @mikolalysenko
    CollaboratorAuthor

    [agent] Triaged as priority:p3 (cross-cutting dead-code cleanup). No duplicate or open PR found.


    Generated by Claude Code

  4. mikolalysenko commented on Oct 8, 2026

    @mikolalysenko
    CollaboratorAuthor

    [agent] Claiming this issue for the architecture refactor routine (highest leverage: the only backlog item whose files no open fix/refactor PR changes now that #1039 merged; it deletes the dead hosted-vlt redirect-ledger helpers that mislead hosted-rollback work). Branch: arch-refactor/782-dead-vlt-ledger-helpers. Claim-ID: 2026-10-08T14:56:29Z-92661b

    Slice 1 covers the free files only: patch/redirect/vlt.rs (edit_dep_id, lock_node_ids, carried_pin_original, carried_pin_ids, carried_pin_lines, same_slots, claims_key), patch/redirect/vlt_heal.rs (ledger_targets) and vendor/jvm/apply.rs (read_project_file gated to tests). committed_artifact_intact (vendor/state.rs), go_sum_edit::remove_lines (#1103), seed_rubygems_sha256, copy_manifest_tag and the folded #746/#800/#801 items stay for later slices, because open PRs change their files.


    Generated by Claude Code

  5. mikolalysenko commented on Oct 8, 2026

    @mikolalysenko
    CollaboratorAuthor

    [agent] Draft PR: #1141.


    Generated by Claude Code

  6. mikolalysenko commented on Oct 9, 2026

    @mikolalysenko
    CollaboratorAuthor

    [agent] Claiming this issue for the architecture refactor routine (highest leverage: the top free candidate now that #1274 freed lock_inventory/tests.rs; it deletes lock_inventory/wired.rs, a ~220-line sixth reader of every npm-family and Python lock that no production code calls). Branch: arch-refactor/782-dead-wired-integrity. Claim-ID: 2026-10-09T19:56:02Z-4b7e1a

    Slice: the #801 scope inside the free files: vendor/lock_inventory/{wired,mod,tests}.rs and the vex/discover/bun.rs doc line. PnpmLock::wired_integrity (formats/pnpm/mod.rs, open #1320), the utils/python_lock.rs doc line (#1332) and the vex/discover/mod.rs guard needle (#1321, #1349) remain for later, along with the #746 and #800 items.


    Generated by Claude Code

  7. mikolalysenko commented on Oct 9, 2026

    @mikolalysenko
    CollaboratorAuthor

    [agent] PR for the #801 slice: #1370. It deletes lock_inventory/wired.rs and its tests. Still open: PnpmLock::wired_integrity, the utils/python_lock.rs doc line and the vex/discover/mod.rs guard needle (their files are in open PRs), plus the #746 and #800 items.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:claimedagent:triagedarch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)priority:p3refactorStructural change: duplicated code or logic, missing abstraction, layering, dead code

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions