Skip to content

Move scan's crawl, supplements and filters out of run_scan into collect_inventory #844

Description

[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: C11.

Kind: refactor. Source: review §2.2 and R5; register C11, child 1 of tracking #843.

Problem

The inventory phase of run_scan is about 210 inline lines, L1560–L1771: crawler options and the status line, the crawl (with or without the npm crawl kept for the vendored and VEX paths), the [lockfile supplement](https://github.com/SocketDev/socket-patch/blob/045d7ec783d788bf3c5a1310724b51e09fb6505d/crates/socket-patch-cli/src/commands/scan/mod.rs#L1593), layout-refusal warnings, the [vendored-ledger supplement](https://github.com/SocketDev/socket-patch/blob/045d7ec783d788bf3c5a1310724b51e09fb6505d/crates/socket-patch-cli/src/commands/scan/mod.rs#L1624-L1642),`` the scanned/vendored/vendor-owned purl sets, the hosted pins and update manifest, and the three successive filtered_crawled passes (package specs, path scope, the final filter), ending in all_purls and package_count at L1770–L1771.``

The block has no early return. It only builds about 20 locals that the rest of the function reads. Because they are locals of the 1,540-line body, nothing else (for example a test, or a future ModeBackend) can get "what this scan covers" without running the whole scan.

Impact

Low risk, and it unblocks the rest of the split: children 3–5 need the inventory as a value to hand to the selection and the mode consumers.

Proposed change

  • Add struct ScanInventory, holding the locals the later phases read (all_crawled, eco_counts, npm_crawl, lockfile_only, layout_refusals, scanned_purls, vendored_purls, vendor_owned_purls, unwired_vendored, hosted_pins, update_manifest, filtered_crawled, all_purls, …).
  • Add async fn collect_inventory(args, ctx, policy, path_scope, mode, prune, status) -> ScanInventory in a new scan/inventory.rs, and move the block there verbatim.
  • run_scan calls it once and destructures the result. Deleted: the ~210 inline lines.
  • No behavior change: same crawl, same order of warnings, same status-line text.

Size and scope

scan/mod.rs (−~210) and a new scan/inventory.rs (+~240), with no changes to other files. Out of scope: the batch query, the selection and the mode dispatch (later children), and any change to what is crawled.

Acceptance criteria

  • run_scan no longer contains the crawl or the filters. It reads them from one ScanInventory.
  • No output change: the scan integration targets, the --json snapshots and the benchmark gate (Add a scan benchmark suite and a CI performance gate #485) stay green.
  • A unit test calls collect_inventory on a small fixture and checks all_purls against the path-scope and package-spec filters.
  • The debug-build stack budget still holds (the Windows CI leg stays green).

Dependencies

None; it can start now. It blocks children 3–5 of #843.


Backlog review — 2026-10-08

Consolidated into #843. The retained tracker(s) preserve this issue’s implementation scope and acceptance criteria. Closing this separate scheduling item as not planned, not as completed.

Explicit inventory-extraction child of the scan-phase split; one tracker can hold this step.

Activity

  1. added
    arch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)
    refactorStructural change: duplicated code or logic, missing abstraction, layering, dead code
    on Oct 5, 2026
  2. added a commit that references this issue on Oct 5, 2026
  3. mikolalysenko commented on Oct 5, 2026

    @mikolalysenko
    CollaboratorAuthor

    [agent] Triaged as priority:p3 (cross-cutting refactor, a sub-task of tracking issue #843). No duplicate or fix PR found.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:triagedarch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)priority:p3refactorStructural change: duplicated code or logic, missing abstraction, layering, dead code

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions