Repository navigation
Decide: warn on and then remove scan --apply/--vendor, and whether --vex stays embedded #966
Description
Activity
- addedarch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)Filed by a scheduled architecture audit routine (see the architecture review discussion)refactorStructural change: duplicated code or logic, missing abstraction, layering, dead codeStructural change: duplicated code or logic, missing abstraction, layering, dead code
on Oct 6, 2026 - added a commit that references this issue
on Oct 6, 2026 mikolalysenko commented
on Oct 7, 2026 CollaboratorAuthorMore actionsLet's try to clean up the unused junk before v5 goes out.
- Retire --no-apply, download and gc
- Remove scan --apply/--vendor
mikolalysenko commented
on Oct 7, 2026 CollaboratorAuthorMore actions[agent] Recording the decision from the triage comment above.
Decision
The legacy spellings are removed in v5, with no warning release first.
Removed in v5 Use instead scan --applyscan --mode agentscan --vendorscan --mode vendoredget --no-applyget --save-only(SOCKET_SAVE_ONLYis unchanged)socket-patch download …socket-patch get …socket-patch gcsocket-patch repairAfter this change each removed spelling is a plain clap usage error (exit 2, no JSON envelope), like any other unknown flag or subcommand. The only argv shortcut is the bare-UUID rewrite to
get(lib.rsparse_argv_with_shortcuts), sodownloadandgcwill not be swallowed as identifiers.Staying as-is:
--syncis a documented shorthand for--mode agent --prune, not a deprecated spelling. It keeps its check that--mode hosted|vendored --syncis exit 2.--save-only,SOCKET_SAVE_ONLYand therepairsubcommand.
Q2 (embedded
--vex) is still open. The triage comment doesn't cover it, so--vexand the four--vex-*knobs onscan,applyandvendorstay unchanged for now. The shared-helper cleanup is tracked separately as E42. If you want embedded--vexremoved before v5 too, say so here. That needs avexflag that trusts the hosted pins the lockfile confirms. Without it, hostedscan --vexcan't attest before install (assume_applied,scan/hosted.rs).What changes (main @
db83f014)crates/socket-patch-cli/src/commands/scan/mod.rs- Delete the hidden
apply(L267-270) andvendor(L287-291) fields and theirconflicts_with_all. - Shrink
resolve_mode_flags(L184-246) to three things: the--syncvs different--modecheck,--sync→ agent, and the hosted default plus the global-scope check. - Drop the "deprecated spelling" comments on
ScanModeand--mode.
- Delete the hidden
crates/socket-patch-cli/src/commands/get.rsL420-427: dropalias = "no-apply".crates/socket-patch-cli/src/lib.rs: dropvisible_alias = "download"(L74) andvisible_alias = "gc"(L109).- Comments in
scan/{hosted,vendor_flow,discovery}.rsandapply.rsthat say--apply/--vendormove to--mode agent/--mode vendored. - Tests:
- Move every
"--vendor"(27 files) and"--apply"(8 files) invocation to--mode vendored/--mode agent. - Same for the
--no-applyuses ine2e_{npm,gem,pypi}.rs(move to--save-only). - Drop the
apply/vendorfields fromScanArgsstruct literals. The 3 that settruemove tomode: Some(…). - Retire the alias tests in
cli_parse_get.rs,cli_parse_main.rsandoutput_modes_e2e.rs, and the boolean conflict arms incovgap_commands_scan_mod.rsandscan_vendor_e2e.rs. - Add one test asserting that all five removed spellings exit 2.
- Move every
- Wrappers: none to change. The npm wrapper forwards argv untouched, and nothing in
npm/,scripts/,.github/ortests/uses these spellings. CLI_CONTRACT.md:- Clear the alias column for
get/repair(L23, L27). - Remove the boolean spellings from the scan flag rows and the mode-resolution text (L96-99, L127, L135, L160, L429).
- Drop the
--no-applyandgcparagraphs (L190-192) and thegetrow's alias note (L105). - Rewrite the alias rows of the bump table (L1676-1677, L1684-1685) generically.
- Replace the remaining
scan --apply/scan --vendorreferences with the--modespelling.
- Clear the alias column for
docs/migrating-to-v5.md: add the five rows above to "Retired spellings".docs/usage.mdalready uses only--mode/--save-only. It gets re-checked, with no edit expected.
Coordination: #792 (
--download-modedefault) touchesargs.rs, the contract's globals and bump tables, and the same migration table, but notget's flags. Whichever PR lands second rebases the doc tables.Outside this repo, these consumers use the removed spellings and need updating when they bump to v5:
- depscan:
package.jsonscriptssocket-patch download, anddocs/patches.md(get --no-apply,gc). - socket-cli: integration tests
socket patch download --dry-run.
A PR implementing this will follow.
Generated by Claude Code
- added a commit that references this issue
on Oct 7, 2026 mikolalysenko commented
on Oct 7, 2026 CollaboratorAuthorMore actions- addedv5-blockerMust resolve before v5: public interface/migration or ordinary patch-install-undo failure.Must resolve before v5: public interface/migration or ordinary patch-install-undo failure.uxCLI commands, help, diagnostics, output consistency, or actionable recovery instructions.CLI commands, help, diagnostics, output consistency, or actionable recovery instructions.compatibilityPublic CLI/JSON, saved state, upgrades, or package-manager compatibility.Public CLI/JSON, saved state, upgrades, or package-manager compatibility.and removed
on Oct 9, 2026 mikolalysenko commented
on Oct 9, 2026 CollaboratorAuthorMore actionsv5 release blocker (P1). The flag/alias removals landed in #1031, but current depscan scripts still invoke socket-patch download. Finish downstream migration before their v5 upgrade; retain embedded --vex as currently supported.
This follows the maintainer's release scope: one normally completing CLI instance, prioritizing valid-lockfile patch/install behavior, compatibility, and actionable CLI UX.
Verified current downstream calls: depscan package.json, local/staging scripts still invoke
socket-patch download; socket-cli integration test still invokespatch download. Migrate the actual call sites and assert the expected command succeeds rather than accepting any nonnegative exit code. The v5 spelling removals are intentional; this does not propose restoring the old aliases.mikolalysenko commented
on Oct 9, 2026 CollaboratorAuthorMore actions[agent] Claiming the downstream migration for v5 blocker burn-down (shared root cause: depscan and socket-cli still invoke the removed
downloadalias). Branches: socket-patch-v5-migrate-download in SocketDev/depscan and SocketDev/socket-cli. Claim-ID: 2026-10-09T16:42:28Z-710d9dmikolalysenko commented
on Oct 9, 2026 CollaboratorAuthorMore actions[agent] Downstream migration PRs for the v5 spelling removals (embedded
--vexunchanged):- SocketDev/depscan#27676:
socket-patch-local/socket-patch-stagingscripts now runsocket-patch getinstead ofsocket-patch download;docs/patches.mdmoves offget --no-apply,--one-offand thegcalias; one test comment moves fromscan --vendortoscan --mode vendored. - test(patch): use get instead of the removed download alias socket-cli#1600:
test/integration/binary/js.test.mtsrunspatch get --dry-runand now requires exit 0 plus the forwardedget expressarguments, instead of accepting any exit code.
Both spellings also work on the socket-patch versions those repos use today, so the PRs can land before the v5 bump. Neither PR is merged. This issue can close once both land.
- SocketDev/depscan#27676:
[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: discussion #560 register.
Kind: decision. Source: review R9 and R10 (§1 #13, Part 2); register C35. The
SOCKET_FORCEhalf of R9 is already #615 and is out of scope here.Questions
Q1. What happens to the legacy spellings?
scan --apply(=--mode agent) andscan --vendor(=--mode vendored) are hidden and called "deprecated" in the code and inCLI_CONTRACT.md. But nothing ever tells a user they are deprecated: they are accepted silently, with no warning, and the contract has no removal date.get --no-apply,get'sdownloadalias andrepair'sgcalias are not called deprecated: the contract makes each one a MAJOR to remove.Options:
--apply/--vendor). In this release,scan --apply/--vendorprint a stderrWarning: --apply is deprecated; use --mode agentand add adeprecated_flagentry to the--jsonwarnings[](additive, MINOR). The next MAJOR removes both, which deletes the boolean fold inresolve_mode_flagsand its conflict rules. Keep--no-apply,downloadandgcas permanent aliases, as the contract already promises, and stop calling anything "deprecated" that isn't scheduled for removal.--apply/--vendorin the next MAJOR with no warning release. This is less work, but scripts get no notice before they break with exit 2.--no-apply,downloadandgc(warn, then remove). This is the full R9 cleanup. The contract notes that--no-apply"is widely used in existing scripts".Q2. Should
--vexstay embedded inscan,applyandvendor? R10 proposes replacing it with<command> && vex -O <path>. Verifying on main found one capability the standalone command can't reproduce. In hosted mode,scan --vexattests before install: this run's confirmed rewrites go inassume_applied, so their bytes aren't verified on disk. A standalonevexrun before install would verify those packages against the unpatched tree and omit them. So option 1 below needs a replacement for that.Options:
--vexin the next MAJOR, and givevexa--assume-hosted(or similar) to trust lockfile-confirmed hosted pins. This deletes 5--vex-*flags × 3 commands and the per-command glue that E42 counts.--vex, but route it through one sharedEmbeddedVexhelper (recommended). That is register E42, owned by the ecosystems auditor. It's no contract change: it only removes the duplicate glue.Problem (main @
9c43dfc)applyandvendor. They are folded into--modebyresolve_mode_flags. That function carries a cross-flag conflict table that exists only because of the booleans, plus its own error wording, which a contract test matches.grep -rn deprecat crates/socket-patch-cli/srcfinds only comments. No code path emits a deprecation notice. Run twice on a debug build:scan --apply --dry-run --yesandscan --vendor --dry-run --yesin an npm project (API pointed at a closed port) exit 0, and neither stdout nor stderr contains "deprecat".CLI_CONTRACT.mdcalls--applya "deprecated spelling" (L97), and saysscan --apply/--vendorare "hidden (still accepted)" (L424).--no-apply"part of the contract" and keepsgc(L188-L190), and it classes removing any alias as MAJOR (L1603-L1612).``get'sdownload,repair'sgcand--save-only'sno-apply."--vendor"appears in 27 CLI test files and"--apply"in 8, against 4 for"--no-apply".VexEmbedArgshas 5 flags, each with its own env var, and is flattened intoscan,applyandvendor.scan --vexfillsassume_appliedfrom this run's confirmed rewrites (scan/hosted.rs).`` The standalonevexalways passes an empty list, as the `VexBuildParams` doc says.Symptoms and impact
Proposed change (after the decision; option 1 for Q1 and option 2 for Q2)
warn_deprecated(flag, replacement)call inresolve_mode_flags, which emits a stderr line and adds adeprecated_flagentry towarnings[];applyandvendorfields;resolve_mode_flags, so only the global-scope check is left;--mode.--syncstays: it is a documented shorthand for--mode agent --prune, not a deprecated spelling.Size and scope
SOCKET_FORCE(Decide: give SOCKET_FORCE per-command names so forcing a self-update doesn't also force apply and vendor #615), the command model (C34) and the JSON envelope (Decide: one shape for the--jsontop-levelerror(scan and get emit both a string and a {code, message} object) #704).Acceptance criteria
scan --applyandscan --vendorwarn on stderr and in--jsonwarnings[], with a test for each, andCLI_CONTRACT.mdnames the removal release.cargo test -p socket-patch-clistays green, including thescan_vendor_e2econflict tests.Dependencies
SOCKET_FORCE), E42 (the embedded-VEX helper).