Skip to content

Classify purls through Ecosystem::from_purl in free files (#747) - #1126

Merged
Mikola Lysenko (mikolalysenko) merged 6 commits into
mainfrom
arch-refactor/747-purl-ecosystem-checks
Oct 11, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 6 commits into
mainfrom
arch-refactor/747-purl-ecosystem-checks

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

Slice 1 of #747 (closes nothing yet; the issue stays open for the remaining files).

Summary

Eight production checks decided a purl's ecosystem with an inline starts_with("pkg:<type>/"): seven when this PR opened, plus one that main added since. They now ask Ecosystem::from_purl, the one map from purl type to ecosystem. A one-sided guard stops new inline checks.

Why

What changed

File Check Now
cli/commands/bun_preflight.rs (×3) pkg:npm/ from_purl(p) == Some(Npm)
cli/commands/vlt_preflight.rs pkg:npm/ from_purl(p) == Some(Npm)
core/crawlers/fuzzy_match.rs pkg:pypi/ from_purl(p) == Some(Pypi)
core/patch/sidecars/coursier.rs pkg:maven/ from_purl(p) != Some(Maven)
cli/commands/scan/hosted/nuget.rs pkg:nuget/ from_purl(p) == Some(Nuget) (added on main after this PR opened)
core/vex/verify.rs (×2) pkg:maven/, pkg:golang/ from_purl

crawlers/types.rs gains a purl_type_tests module:

  • from_purl_matches_each_former_inline_prefix: for 23 inputs (near misses like pkg:npm, pkg:NPM/, pkg:npmx/, pkg:maven:, leading space, empty) and all 9 prefixes, from_purl(p) == Some(eco) holds exactly when p.starts_with(prefix). Every migrated caller therefore keeps its answer.
  • production_code_classifies_purls_through_from_purl: a source scan over both crates' production code (before the first in-file test module, CRLF-normalized). It's one-sided: it fails only on a file outside PENDING_INLINE_PREFIXES. That list holds the files still to migrate: 16 when the PR opened, 22 after merging main, which had added six. Because of that, a PR that migrates one of those files can't turn main red.

Deleted

  • Production: +20 / −11 (8 inline prefix literals replaced; the rest are imports and rustfmt wrapping).
  • Tests: +161 / −0.

Behavior

None. The prefixes from_purl tests are mutually exclusive, so from_purl(p) == Some(X) is equivalent to p.starts_with(X's prefix) (proved by the table test).

Test evidence

  • cargo clippy --workspace --all-features -- -D warnings: clean, including after each merge of main.
  • cargo test -p socket-patch-core --lib after the first merge of main: 6,221 passed. 4 failed, the known root-sandbox failures that fail on main too (copy_tree::relax_loop_must_not_traverse_symlinked_root, vlt_heal::an_unremovable_hidden_lock_keeps_every_store_entry, pypi_poetry::wire_write_failure_maps_error_and_leaves_lock_untouched, pypi_requirements::wire_failure_rolls_back_already_written_files).
  • cargo test -p socket-patch-cli --all-features --lib after the second merge of main: 911 passed. Earlier, on the PR as opened: in_process_vendor 122, in_process_vendor_bun_takeover 30, in_process_rollback_vendored 16, covgap_commands_scan_mod 53 and spawn_env_hygiene 12, all passed. covgap_commands_vendor had 51 passing and 3 root-only failures (*_state_write_failure_*, chmod-based) that fail on main too.
  • Guard red→green: reintroducing pkg.purl.starts_with("pkg:pypi/") in fuzzy_match.rs fails the guard, naming core/src/crawlers/fuzzy_match.rs.
  • Guard after merging main:
    • First merge (review thread): the guard failed on the six files main had added (agent_download.rs, hosted_unwind.rs, scan/hosted/takeover.rs, scan/policy.rs, hosted/takeover.rs, utils/target.rs). It passed once they were listed as pending (f5fb195).
    • Second merge: the guard failed on scan/hosted/nuget.rs. No other open PR changes that file, so I converted its check instead of listing it (8782ee9).
  • CI on 47dd195: 505 check runs, 429 success, 76 skipped, 0 failed. On f5fb195: 54 check runs (reduced PR scope), 36 success, 18 skipped, 0 failed.

Risk

Low: one-line predicate swaps backed by an equivalence test.

🤖 Generated with Claude Code


Note

Low Risk
Predicate swaps only, backed by equivalence and a ratchet test; runtime behavior should be unchanged.

Overview
First slice of centralizing PURL ecosystem checks (#747): seven production starts_with("pkg:<type>/") predicates now use Ecosystem::from_purl in Bun/vlt vendor prefights (npm), fuzzy package search (PyPI), Coursier sidecar retry (Maven), and VEX verification (Maven copy handling and Go vendored drift exemption).

crawlers/types.rs adds tests that from_purl matches the old prefix behavior on near-miss inputs, plus a one-sided CI guard that fails if new inline starts_with("pkg:…/") checks appear outside an allowlist of files still pending migration.

No intended behavior change; equivalence is locked by the table test.

Reviewed by Cursor Bugbot for commit 47dd195. Configure here.

Assisted-by: Claude Code:claude-opus-5-5
Seven production checks spelled a purl type prefix inline
(`starts_with("pkg:npm/")` and friends) in the Bun and vlt vendor
preflights, the PyPI fuzzy matcher, the Coursier sidecar retry and VEX
verification. They now ask `Ecosystem::from_purl`, the one map from purl
type to ecosystem, so a change to the type vocabulary has one place to
land.

No behavior change: a table test shows `from_purl(p) == Some(eco)`
holds exactly when `p` starts with that ecosystem's prefix, near misses
included. A one-sided source-scan guard fails on any new file that
spells a prefix inline; the 16 files open PRs change are listed as
pending for the next slice of #747.

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko Mikola Lysenko (mikolalysenko) added refactor Structural change: duplicated code or logic, missing abstraction, layering, dead code arch-refactor PR opened by the scheduled architecture refactor routine labels Oct 8, 2026
@mikolalysenko
Mikola Lysenko (mikolalysenko) marked this pull request as ready for review October 8, 2026 11:17
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 8, 2026
Assisted-by: Claude Code:claude-opus-5-5

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 8, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Ready for review (burn-down agent).

  • Head: 47dd195e5885efe9be68de6d19a89c6ac084d996
  • CI: 505/505 check runs green (success/skipped/neutral) on this head, mergeable, no conflicts.
  • Bugbot: reviewed this head (Cursor Bugbot check: success), no unresolved review threads.
  • Changelog: untouched.

Nothing specific flagged for the reviewer beyond the PR description.


Generated by Claude Code

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Final review brief

What it does. Swaps seven inline starts_with("pkg:<type>/") checks for Ecosystem::from_purl(p) == Some(X). The checks are in the Bun and vlt vendor preflights, the PyPI fuzzy matcher, the Coursier sidecar retry and VEX verify. It also adds a table test showing from_purl agrees with each old prefix test, plus a source-scan guard that fails on any new inline purl prefix check. The 16 files not yet migrated are allowlisted, so this is slice 1 of #747 and doesn't close it.

Risk: low. These are pure predicate swaps. from_purl is a case-sensitive chain of prefix checks ending in / that can't overlap, and no ecosystem is cfg-gated, so every replaced check returns the same answer as before. All other new code is test-only.

Look here

Verified

  • Read the full diff against Route purl ecosystem checks through Ecosystem::from_purl instead of 24 inline starts_with("pkg:<type>/") tests #747.
  • cargo clippy -p socket-patch-core -p socket-patch-cli --all-features -- -D warnings: clean. rustfmt is clean on the touched files.
  • cargo test -p socket-patch-core --lib: 5749 passed. The 4 failures are the root-sandbox ones the PR already names, none in touched code.
  • cargo test -p socket-patch-cli --all-features --lib: 879 passed.
  • Guard checked red→green: I re-added an inline check in fuzzy_match.rs, the guard failed and named that file, then I reverted it.
  • CI: ci-ok and clippy green, no failed checks. Bugbot found no issues, and there are no review threads.
  • CHANGELOG.md is untouched.

Changes I made: none.

Open questions (non-blocking)

Auto-merge is armed: approving sends this straight to the merge queue.


Generated by Claude Code

Comment thread crates/socket-patch-core/src/crawlers/types.rs
main gained inline purl-type prefix checks in six production files
after this branch was cut. The one-sided guard would have failed on
them once merged. List them as pending for #747's next slices so the
guard passes on main as it stands; migrating them stays out of this
slice.

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

@Tanmay182003

Copy link
Copy Markdown

[agent] f5fb195 covers the six files, but main has since gained one more: cli/src/commands/scan/hosted/nuget.rs:33 (purl.starts_with("pkg:nuget/"), from #1344), so production_code_classifies_purls_through_from_purl still fails once merged (checked with the test's filter + regex over origin/main). Fix: rebase and convert it to Ecosystem::from_purl (or add it to PENDING_INLINE_PREFIXES).

main added an inline pkg:nuget/ prefix check in the hosted NuGet
stale-install remedy after this branch last merged main, which the
guard rejects. Route it through Ecosystem::from_purl like the other
migrated checks; the answer is unchanged (see the table test).

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[agent] Confirmed: after merging main again, the guard failed only on cli/src/commands/scan/hosted/nuget.rs. Fixed in 8782ee9 (pushing now). This time I converted the check (Ecosystem::from_purl(purl) == Some(Ecosystem::Nuget)) rather than listing it as pending, because no other open PR changes that file. The guard passes. Clippy is clean, and the CLI --lib tests pass (911).


Generated by Claude Code

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 8782ee9. Configure here.

Merged via the queue into main with commit 578b63e Oct 11, 2026
53 checks passed
@mikolalysenko
Mikola Lysenko (mikolalysenko) deleted the arch-refactor/747-purl-ecosystem-checks branch October 11, 2026 01:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

arch-refactor PR opened by the scheduled architecture refactor routine Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review refactor Structural change: duplicated code or logic, missing abstraction, layering, dead code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants