Skip to content

Route purl ecosystem checks through Ecosystem::from_purl instead of 24 inline starts_with("pkg:<type>/") tests #747

Description

[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: discussion #560 register.

Kind: refactor (mechanical, no behavior change). Source: review 6.4, 7.3; register C20, child 1 of the purl tracking issue.

Problem (verified on 045d7ec)

Ecosystem::from_purl is the one map from purl type to ecosystem. Production code outside it still spells the type prefixes inline: 24 starts_with("pkg:<type>/") checks.

  • core:
    • hosted/engine.rs (6, L1382-L1446);
    • hosted/memory/stages.rs (2);
    • patch/apply.rs:745 and patch/rollback.rs:355, the npm sidecar gates;
    • api/client.rs:1338;
    • vex/verify.rs:210.
  • CLI:
    • commands/vendor.rs (3, L1907-L1943);
    • commands/bun_preflight.rs (3);
    • vlt_preflight.rs:50, rollback.rs:2446, get.rs:1536, apply.rs:2315, scan/discovery.rs:108 and scan/hosted/python.rs:28.

All 24 agree with from_purl today (all are case-sensitive prefix tests), so there is no drift yet. But the type vocabulary has 25 copies. A purl-type change, such as accepting pkg:PyPI/, or jsr mapping to Deno, would have to find all of them. And matching on Ecosystem makes the npm-only gates exhaustive and greppable.

Proposed change

  • Replace each check with Ecosystem::from_purl(p) == Some(Ecosystem::X), or a matches! on it. Where a site checks several types, add a small Ecosystem::is_one_of-style helper only if it reads better.
  • Delete the inline literals.
  • Leave from_purl itself and the parsers in utils/purl.rs unchanged.

Size and scope

  • About 24 one-line production edits across 14 files; no test changes expected.
  • Out of scope: the purl builders (later children of the tracking issue), and the starts_with("pkg:") "is this a purl" tests (utils::purl::is_purl).

Acceptance criteria

  • No starts_with("pkg:<type>/") remains in non-test code outside crawlers/types.rs and utils/purl.rs. Add a source-scan architecture test like crawlers::architecture_tests, normalizing CRLF.
  • cargo test -p socket-patch-core --lib and cargo test -p socket-patch-cli stay green; clippy stays clean.

Dependencies

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:triagedarch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)priority:p3refactorStructural change: duplicated code or logic, missing abstraction, layering, dead code

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions