[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: register comment.
Kind: refactor. Source: Part 5.6 ("registry_fetch.rs is misnamed and misplaced"). Register E29.
Problem
vendor/registry_fetch.rs is 3,048 lines at db83f01: 1,560 production lines and 38 tests from L1561. The review counted 1,535. Its own module doc (L1) describes it as "Bounded archive readers, integrity verification and registry metadata transport". Nothing in it is vendored-mode logic. It holds four unrelated families:
| Family |
Lines |
Non-vendor importers |
Archive extraction: the caps, extract_on_blocking_pool, Sink, DestShape, extract_zip*, plan_zip/inflate_*, extract_tgz*, extract_gem_data*, walk_tar_gz |
L20–L29, L95–L785, L1322–L1560 |
patch/jvm_jar.rs (agent mode, MAX_DOWNLOAD_BYTES), patch/redirect/upstream/client.rs (hosted restore) |
Go module zip: go_h1_of_zip, walk_module_zip, module_entry_refusal, verify_go_h1, extract_zip_with_prefix* |
L884–L1175 |
upstream/client.rs, api/vendor_prefetch.rs |
Integrity: artifact_matches_integrity, verify_integrity, verify_sri |
L1214–L1321 |
hosted/npm_manifest.rs, upstream/client.rs, api/vendor_prefetch.rs |
Registry bases and transport: npm_registry_base, npm_tarball_url, pypi_json_api_base, goproxy_base + Go glob, download, build_registry_client |
L18, L45–L100, L787–L883, L1176–L1213 |
upstream/{client,npm,vlt}.rs |
So agent mode (patch/), hosted restore (patch/redirect/upstream/), hosted/ and api/ all import crate::vendor::registry_fetch. That is a patch/hosted/api → vendor dependency for code that has nothing to do with vendoring.
The comment at L24–L26 justifies pub(crate) caps by a common::read_zip_members twin, which no longer exists. The caps have no importer outside the file except MAX_DOWNLOAD_BYTES.
Impact
Proposed change (this issue: the first two families only)
- Create
crates/socket-patch-core/src/utils/archive.rs (or utils/archive/{mod,go_module}.rs). Move the archive extraction and Go module zip families into it verbatim, with the tests that cover them.
- Keep the
vendor::registry_fetch paths for these items through a pub(crate) use crate::utils::archive::* for one release of the code, or update the ~16 import sites directly. Either is fine; update the imports if the diff stays reviewable.
- Delete the stale
read_zip_members comment.
Out of scope, as follow-ups recorded on register row E29:
Size and scope
- Files:
vendor/registry_fetch.rs, the new utils/archive.rs, utils/mod.rs, and the importers (vendor/{cargo,composer_lock,gem,golang,maven_repo,npm_dir,nuget_feed,redownload,service_fetch}.rs, patch/jvm_jar.rs, patch/redirect/upstream/client.rs, api/vendor_prefetch.rs).
- About 1,000 moved production lines plus their tests. The import edits are about 20 lines. There is no behavior change.
Acceptance criteria
Dependencies
Backlog review — 2026-10-08
Consolidated into #959, #833. The retained tracker(s) preserve this issue’s implementation scope and acceptance criteria. Closing this separate scheduling item as not planned, not as completed.
The archive-extractor file move is supporting layering work. Link this proposal from the backend/formats trackers and close the separate scheduling item.
[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: register comment.
Kind: refactor. Source: Part 5.6 ("
registry_fetch.rsis misnamed and misplaced"). Register E29.Problem
vendor/registry_fetch.rsis 3,048 lines atdb83f01: 1,560 production lines and 38 tests from L1561. The review counted 1,535. Its own module doc (L1) describes it as "Bounded archive readers, integrity verification and registry metadata transport". Nothing in it is vendored-mode logic. It holds four unrelated families:vendorimportersextract_on_blocking_pool,Sink,DestShape,extract_zip*,plan_zip/inflate_*,extract_tgz*,extract_gem_data*,walk_tar_gzpatch/jvm_jar.rs(agent mode,MAX_DOWNLOAD_BYTES),patch/redirect/upstream/client.rs(hosted restore)go_h1_of_zip,walk_module_zip,module_entry_refusal,verify_go_h1,extract_zip_with_prefix*upstream/client.rs,api/vendor_prefetch.rsartifact_matches_integrity,verify_integrity,verify_srihosted/npm_manifest.rs,upstream/client.rs,api/vendor_prefetch.rsnpm_registry_base,npm_tarball_url,pypi_json_api_base,goproxy_base+ Go glob,download,build_registry_clientupstream/{client,npm,vlt}.rsSo agent mode (
patch/), hosted restore (patch/redirect/upstream/),hosted/andapi/all importcrate::vendor::registry_fetch. That is apatch/hosted/api→vendordependency for code that has nothing to do with vendoring.The comment at L24–L26 justifies
pub(crate)caps by acommon::read_zip_memberstwin, which no longer exists. The caps have no importer outside the file exceptMAX_DOWNLOAD_BYTES.Impact
vendor/behind a backend trait (E21, Tracking: dispatch vendored backends through one per-ecosystem table instead of string matches in core and the CLI #959).patch/package.rsandvendor/common.rskeep their own caps (by design; different inputs), andregistry_fetchis not where a reader looks for them.Proposed change (this issue: the first two families only)
crates/socket-patch-core/src/utils/archive.rs(orutils/archive/{mod,go_module}.rs). Move the archive extraction and Go module zip families into it verbatim, with the tests that cover them.vendor::registry_fetchpaths for these items through apub(crate) use crate::utils::archive::*for one release of the code, or update the ~16 import sites directly. Either is fine; update the imports if the diff stays reviewable.read_zip_memberscomment.Out of scope, as follow-ups recorded on register row E29:
LockIntegrityto move intoformats(Move LockfileEntry, LockIntegrity, SourceKind and http_url from vendor::lock_inventory into formats::entry #834);download/build_registry_clientare being changed by PR Bound registry downloads by ApiTimeouts instead of a 60 s total deadline (#872) #876 for Registry downloads give up after 60 s even while the body is still arriving #872.Size and scope
vendor/registry_fetch.rs, the newutils/archive.rs,utils/mod.rs, and the importers (vendor/{cargo,composer_lock,gem,golang,maven_repo,npm_dir,nuget_feed,redownload,service_fetch}.rs,patch/jvm_jar.rs,patch/redirect/upstream/client.rs,api/vendor_prefetch.rs).Acceptance criteria
git diff --color-movedshows the two families as moved blocks only.vendor/imports archive or Go-module-zip items fromcrate::vendor::registry_fetch.Sink::ValidatevsSink::Writeparity tests) pass unchanged.cargo test -p socket-patch-coreandcargo test -p socket-patch-clipass;cargo clippy --all-targetsis clean.Dependencies
download/build_registry_client, so it doesn't conflict with Bound registry downloads by ApiTimeouts instead of a 60 s total deadline (#872) #876.fetch.rsmove) and E21/Tracking: dispatch vendored backends through one per-ecosystem table instead of string matches in core and the CLI #959 by removing non-vendor importers ofvendor/.Backlog review — 2026-10-08
Consolidated into #959, #833. The retained tracker(s) preserve this issue’s implementation scope and acceptance criteria. Closing this separate scheduling item as not planned, not as completed.
The archive-extractor file move is supporting layering work. Link this proposal from the backend/formats trackers and close the separate scheduling item.