You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[agent] 2026-10-02T17:13Z: architecture refactor run
2
+
3
+
-**main:**`bf0e0d1`.
4
+
-**Ranking:**#561 (6) and #568 (4, new p1) were skipped because they change files that open PRs also change: #561 changes `redirect/mod.rs` (#552, #470, #465), and #568 changes `scan/hosted.rs` (#503, #470). #570 (C02, P1) and E37 tied at 4, and #570 won on register P. Maintainer steering on #569 and #571 (no size caps on trusted data, stream instead) re-scoped both as streaming changes with M risk. Both dropped in the ranking.
5
+
-**PR:**[#581](https://github.com/SocketDev/socket-patch/pull/581), "Bound patch API connects and stalled reads (#570)". It adds one `ApiTimeouts` policy (10 s connect, 60 s idle read) to both `ApiClient` clients. The stall tests were red with the bound disabled and are green on the branch. Ready for review, `@bugbot review` requested, handed to the burn-down.
6
+
-**Claimed:**#570. **Released:** none.
7
+
-**Merged:** none (#572 and #574 are still open). **Living document:**`{{C02}}` was already in Part 1 §2 and Part 7, and register row C02 is now `in PR #581`.
8
+
-**Lessons:** reqwest 0.12's `read_timeout` is an idle bound that also covers waiting for headers, so it bounds stalls without capping long downloads.
| C01 | 1 | Unbounded zip inflate on tamperable input. `zip_bytes_match_after_hashes` pre-allocates from the archive's declared size and reads with no cap, and it runs on committed `.nupkg`/`.jar` files and service archives. There are three archive caps (512/256/128 MiB). |#569| filed #569|
7
-
| C02 | 1 |`ApiClient::new` and `plain_client()` set no HTTP timeout, and blob and diff fetches have no retry, so `scan`, `get` and `apply` can hang in CI. |#570|filed #570|
7
+
| C02 | 1 |`ApiClient::new` and `plain_client()` set no HTTP timeout, and blob and diff fetches have no retry, so `scan`, `get` and `apply` can hang in CI. |#570|in PR #581|
8
8
| C03 | 1 |`vendored_takeover` ignores `RevertOutcome.kept_artifact`. It deletes the ledger entry and reports the artifact as reverted on a drift-keep, while every other revert caller honors the flag. |#568| filed #568|
9
9
| C04 | 1 | Planted-binary spawn: `vendor/pypi_hatch.rs` runs `Command::new("hatch").current_dir(root)` instead of `process::resolve_tool`. Check open PR #442 first. | §1 #4; 7.3 || to verify |
10
10
| C05 | 1 |`SOCKET_FORCE` is bound to `vendor --force`, `apply --force` and `--update --force`, so forcing a self-update also forces past hash checks. | §1 #6|| to verify |
-[#572](https://github.com/SocketDev/socket-patch/pull/572): one hosted-PyPI-URL recognizer for hosted and vendored Pipenv. Issues #563 (E04, E49). State: ready, handed to the PR burn-down.
6
6
-[#574](https://github.com/SocketDev/socket-patch/pull/574): one vlt `registry_base` following vlt's DepID hydration. Issues #562 (E02, E03). State: ready, handed to the PR burn-down.
7
+
-[#581](https://github.com/SocketDev/socket-patch/pull/581): one `ApiTimeouts` policy (10 s connect, 60 s idle read) on both `ApiClient` reqwest clients. Issue #570 (C02). State: ready, handed to the PR burn-down.
7
8
8
9
**Merged:** none yet.
9
10
10
11
**Queue** (B bugs closed, U unblocks, D duplication removed, R risk; score = 3B + 2U + D − risk):
11
12
12
13
| # | Candidate | B | U | D | R | Score | Note |
13
14
|---|---|:-:|:-:|:-:|:-:|:-:|---|
14
-
| 1 |#561 (E01): hosted NuGet sources via `formats::nuget`| 1 | 1 | 1 | L | 6 | skipped: `redirect/mod.rs` is changed by open PRs #552, #491, #470, #465|
15
-
| 2 |#571 (C37): `fetch_binary` through the shared `read_capped`| 1 | 0 | 1 | L | 4 |next|
16
-
| 3 |#569 (C01): capped zip inflate, one archive-cap set|1| 0 |1| L | 4 ||
17
-
| 4 |E37: byte-identical `is_safe_{cargo,gem,nuget}_coordinate` + `normalize_version` copy| 0 | 0 |4|L|4 | to verify, no issue yet|
| 5 |#569 (C01): stream zip entry comparison| 1 | 0 | 0 |M|1|maintainer: data is trusted, stream for performance instead of capping|
19
20
20
21
**Notes:**
21
22
- The sandbox runs as root, so 4 core lib tests fail on main and on branches alike: `copy_tree::relax_loop_must_not_traverse_symlinked_root`, `vlt_heal::an_unremovable_hidden_lock_keeps_every_store_entry`, `pypi_poetry::wire_write_failure_maps_error_and_leaves_lock_untouched`, `pypi_requirements::wire_failure_rolls_back_already_written_files`.
-`CLI_CONTRACT.md` lives at `crates/socket-patch-cli/CLI_CONTRACT.md`.
26
27
- vlt registry semantics: cite `@vltpkg/dep-id``hydrateTuple` and `@vltpkg/spec` (`registry ?? registries[default-registry-alias]`); the packages download from npm.
27
28
- Runs overlap: two runs started within minutes of each other on 2026-10-02. Claims and the status block kept them apart; `git pull --rebase` the ledger before writing.
29
+
- Maintainer steering (2026-10-02, on #569 and #571): don't add size caps on trusted upstream data; stream instead of buffering.
30
+
- reqwest 0.12 `ClientBuilder::read_timeout` is an idle bound (resets per chunk) and also bounds the wait for response headers; `RequestBuilder::timeout` is total.
0 commit comments