[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: discussion #560 register.
Kind: bug. Source: §1 #3; Part 2.10 R1; register C03.
Problem
RevertOutcome.kept_artifact documents that when a backend drift-skips a wiring record it keeps the artifact dir, and that "callers must ALSO keep the state.json entry instead of pruning it, and report the package as skipped rather than removed" (vendor/mod.rs#L666-L675).
vendored_takeover in scan --mode hosted never reads the flag. It only checks success, then removes the entry from the ledger, saves it, and reports the "committed artifact" as reverted (scan/hosted.rs#L1733-L1792).`` It also discards every revert warning except REINSTALL_REQUIRED, so the user never sees `vendor_lock_entry_drifted` or `vendor_artifact_kept`.
Every other revert caller honors the flag:
Reproduced twice on main @ 1169ae6 with a probe based on tests/mode_migration_npm.rs (real yarn classic install of left-pad@1.3.0, mock patch API). The probe was not committed.
vendor --offline vendors the package.
- One extra wiring record is added to the entry in
.socket/vendor/state.json whose lock block no longer exists (key ghost-dep@^9.9.9). This is the standard drift-keep trigger the backend unit tests use.
- Control:
vendor --revert --yes --offline exits 0, emits vendor_artifact_kept, and keeps both the ledger entry and .socket/vendor/npm/<uuid>.
- Takeover:
scan --mode hosted --json --yes exits 0 with redirected: 1 and only redirect_takeover_reverted_vendored ("reverted its vendored wiring, ledger entry, and committed artifact"). Afterwards, state.json no longer has the purl, while .socket/vendor/npm/<uuid> still exists.
So the run says it removed an artifact it kept, and drops the only ledger record of the drifted wiring's originals. The artifact dir is now unreferenced, so a later orphan sweep is free to delete it, and that is the loss the drift-keep exists to prevent.
Symptoms
None filed yet. The neighbouring takeover bugs (#468, #369, #536, #553) have other causes.
Impact
The ledger loses the record of the drifted wiring's originals, and the user gets a false "fully hosted" report. This applies to all three takeover-capable families (npm flavors, cargo, golang). The fix is small.
Proposed change
- In
vendored_takeover, treat outcome.kept_artifact the way VendorRevertStep::Kept is treated: keep the ledger entry, do not push the purl to migrated, move it to refused/skipped, and forward the revert's vendor_lock_entry_drifted and vendor_artifact_kept warnings into pre_warnings.
- Preferably, route the wet takeover revert through
vendored_backend's revert step instead of calling dispatch_revert_one and editing state.entries by hand. That deletes the hand-rolled retain + save_state block, so a future change to the drift-keep contract only has to be made in one place.
Size and scope
crates/socket-patch-cli/src/commands/scan/hosted.rs, plus one regression test. That is ~40–80 production lines. Out of scope: the per-backend drift rules, and the dry-run preview path (it already only reports).
Acceptance criteria
Dependencies
None. Related: C24/E24 (one revert engine) would make this class of mismatch impossible.
[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: discussion #560 register.
Kind: bug. Source: §1 #3; Part 2.10 R1; register C03.
Problem
RevertOutcome.kept_artifactdocuments that when a backend drift-skips a wiring record it keeps the artifact dir, and that "callers must ALSO keep the state.json entry instead of pruning it, and report the package as skipped rather than removed" (vendor/mod.rs#L666-L675).vendored_takeoverinscan --mode hostednever reads the flag. It only checkssuccess, then removes the entry from the ledger, saves it, and reports the "committed artifact" as reverted (scan/hosted.rs#L1733-L1792).`` It also discards every revert warning exceptREINSTALL_REQUIRED, so the user never sees `vendor_lock_entry_drifted` or `vendor_artifact_kept`.Every other revert caller honors the flag:
vendorGC loops (a) and (b):vendor.rs#L3451-L3463andvendor.rs#L3486-L3500;vendored_backend's revert step (VendorRevertStep::Kept):vendored_backend/mod.rs#L182-L195.``Reproduced twice on main @
1169ae6with a probe based ontests/mode_migration_npm.rs(real yarn classic install ofleft-pad@1.3.0, mock patch API). The probe was not committed.vendor --offlinevendors the package..socket/vendor/state.jsonwhose lock block no longer exists (keyghost-dep@^9.9.9). This is the standard drift-keep trigger the backend unit tests use.vendor --revert --yes --offlineexits 0, emitsvendor_artifact_kept, and keeps both the ledger entry and.socket/vendor/npm/<uuid>.scan --mode hosted --json --yesexits 0 withredirected: 1and onlyredirect_takeover_reverted_vendored("reverted its vendored wiring, ledger entry, and committed artifact"). Afterwards,state.jsonno longer has the purl, while.socket/vendor/npm/<uuid>still exists.So the run says it removed an artifact it kept, and drops the only ledger record of the drifted wiring's originals. The artifact dir is now unreferenced, so a later orphan sweep is free to delete it, and that is the loss the drift-keep exists to prevent.
Symptoms
None filed yet. The neighbouring takeover bugs (#468, #369, #536, #553) have other causes.
Impact
The ledger loses the record of the drifted wiring's originals, and the user gets a false "fully hosted" report. This applies to all three takeover-capable families (npm flavors, cargo, golang). The fix is small.
Proposed change
vendored_takeover, treatoutcome.kept_artifactthe wayVendorRevertStep::Keptis treated: keep the ledger entry, do not push the purl tomigrated, move it torefused/skipped, and forward the revert'svendor_lock_entry_driftedandvendor_artifact_keptwarnings intopre_warnings.vendored_backend's revert step instead of callingdispatch_revert_oneand editingstate.entriesby hand. That deletes the hand-rolledretain+save_stateblock, so a future change to the drift-keep contract only has to be made in one place.Size and scope
crates/socket-patch-cli/src/commands/scan/hosted.rs, plus one regression test. That is ~40–80 production lines. Out of scope: the per-backend drift rules, and the dry-run preview path (it already only reports).Acceptance criteria
kept_artifact, the ledger entry survives, the purl is reported as skipped/refused (notredirect_takeover_reverted_vendored), and the drift and kept warnings appear in the envelope.mode_migration_npm,mode_migration_cargo,mode_migration_vlt,mode_migration_bunandin_process_vendor*stay green.Dependencies
None. Related: C24/E24 (one revert engine) would make this class of mismatch impossible.