`apply --check` drift report tells you to run `socket-patch apply` without the `-g` / `--global-prefix` / `--cwd` it was given, so following it patches nothing and exits 0
Maintainer antworten meist innerhalb von 1 Tag
Bewertung
- Schwierigkeit
- 2/5
- Geschätzter Aufwand
- 1-3 Stunden
- Anfängerfreundlichkeit
- 72/100
Rechercherichtung
Die fehlerhafte Lösung ist das fest eingebaute eprintln! in run_check in crates/socket-patch-cli/src/commands/apply.rs, etwa in Zeile 674, das args.common ignoriert (global, global_prefix, cwd, manifest_path, ecosystems). Nimm den Helfer report_only_hint aus dem Fix für #777 zu scan -g als Vorlage und baue den apply-Befehl aus denselben Scope-Flags. Fertig ist es, wenn der ausgegebene Lösungsvorschlag, wortgleich nach dem Repro aus dem Issue ausgeführt, die Kopie repariert und das nächste apply --check mit Exit-Code 0 endet.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
[agent] Found by the scheduled Pipenv bug-hunt routine (ledger #313).
Summary
When apply --check finds drift, the human report always ends with the fixed line:
Error: Patches are OUT OF SYNC:
pkg:pypi/[email protected]: patch not applied (an installed copy is still unpatched)
Run `socket-patch apply` to regenerate them.
The suggested command drops every scope flag the check ran with. The check itself is correct (exit 1 on the stale copy), but running the remedy as printed targets a different tree:
apply --check -g --global-prefix <site-packages>(the Dockerpipenv install --systemshape): plainsocket-patch applycrawls the cwd project, prints0 of 1 targeted patch applied, … 1 not found on disk, and exits 0. The global copy stays unpatched.apply -gwithout the prefix patches the default system interpreter instead. In the sandbox that was the distro's/usr/lib/python3/dist-packages/six.py, which isn't the tree that was checked.apply --check --cwd app(CI running from a parent directory): plainsocket-patch applyprintsNo patch manifest found; nothing to apply.and exits 0. The Pipenv venv stays unpatched.
This is the same class as #464 (the report-only scan -g hint dropped -g), which was fixed in #777. The apply --check report wasn't covered by that fix.
Impact
apply --check is the CI / GitHub-App audit gate (CLI_CONTRACT apply --check row). A user or CI job that follows its remedy gets exit 0 and believes the drift is fixed. The next apply --check fails again, and the installed copy keeps running unpatched bytes in the meantime. There's no false VEX: this is a misleading remedy, not a wrong verdict.
Repro (Linux, main f3c6313, Pipenv 2026.8.0, local mock of the patch API serving a patched six-1.16.0 wheel)
# global / Docker `pipenv install --system` shape
G=$(mktemp -d)/sys; python3.11 -m venv "$G"; SPK=$G/lib/python3.11/site-packages
"$G/bin/pip" install six==1.16.0
cd my-pipenv-project # Pipfile + Pipfile.lock pinning six==1.16.0
socket-patch scan -g --global-prefix "$SPK" --mode agent --yes # patches $SPK/six.py
"$G/bin/pip" install --force-reinstall --no-deps six==1.16.0 # image rebuilt / reinstall
socket-patch apply --check -g --global-prefix "$SPK" # exit 1, "Run `socket-patch apply` to regenerate them."
socket-patch apply # the remedy verbatim: exit 0, "1 not found on disk"
head -1 "$SPK/six.py" # still the upstream bytes
# --cwd shape (agent mode, Pipenv WORKON_HOME venv)
socket-patch scan --cwd app --mode agent --yes
(cd app && pipenv run pip install --force-reinstall --no-deps six==1.16.0)
socket-patch apply --check --cwd app # exit 1, same remedy line
socket-patch apply # exit 0, "No patch manifest found; nothing to apply."
I reproduced the -g --global-prefix lane 3 times and the --cwd lane once. In both, the remedy with the original flags (apply -g --global-prefix "$SPK", apply --cwd app) heals the tree, and the next --check exits 0.
Expected vs actual
- Expected: the remedy names the command that fixes what the check just reported. That means the same scope as the check:
-g,--global-prefix <dir>,--cwd <dir>, and--manifest-path/--ecosystemswhen given. That's how #464 / #777 fixed thescan -ghint. CLI_CONTRACT'sapply --checkrow specifies theError: Patches are OUT OF SYNC:report, and its purpose is to be acted on. - Actual: a fixed string with no scope flags. Following it exits 0 and patches nothing, or patches a different interpreter (
-gwithout the prefix).
OS × version
| OS | Pipenv | Shape | Result |
|---|---|---|---|
| Linux | 2026.8.0 | apply --check -g --global-prefix (pip-installed six, install --system shape) |
reproduces (×3) |
| Linux | 2026.8.0 | apply --check --cwd app (WORKON_HOME venv) |
reproduces |
| macOS / Windows | not probed | the line is a constant string | expected to be the same |
This isn't Pipenv- or PyPI-specific: every ecosystem's apply --check goes through the same branch.
Suspect code
crates/socket-patch-cli/src/commands/apply.rs:674, in run_check: eprintln!("Run \socket-patch apply` to regenerate them.");doesn't consultargs.common (global, global_prefix, cwd, manifest_path, ecosystems). Compare report_only_hint` after #777.
- Vorherrschende Sprache
- Rust
- Sterne
- 8
- Forks
- 0
- Ø Merge
- 22 Std. 30 Min.
- Gemergte PRs (30 T.)
- 329
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus SocketDev/socket-patch
-
Human `scan --mode vendored --prune` silently skips the vendored GC when no remaining package has a patch, so an `npm uninstall`ed vendored entry is never reverted (exit 0), while `--json` reverts it and `vendor --check` keeps pointing at that same commandEvtl. vergeben Ein verknüpfter Pull Request ist offen oder bereits gemergt. Offenagent:triaged bug bughunt pm:npm priority:p2
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 85/100
SocketDev/socket-patch#1127 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:bundler priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
SocketDev/socket-patch#1125 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:npm priority:p3
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
SocketDev/socket-patch#1072 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
scan exits 1 in human output but 0 with --json when every patch query returns nothingEvtl. vergeben Ein verknüpfter Pull Request ist offen oder bereits gemergt. Offenagent:triaged arch-audit bug priority:p3
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 85/100
SocketDev/socket-patch#1062 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:bundler priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 80/100
SocketDev/socket-patch#1056 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in SocketDev/socket-patch
Ähnliche Issues
-
[Feature]: [P3] engine-rs: the package source hash should ignore line endings and untracked filesOffen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 70/100
maniator/verticopolis#880 ·
Maintainer antworten meist innerhalb von 1 Tag
-
documentation
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 66/100
Maintainer antworten meist innerhalb von 3 Tagen
-
defect
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 74/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 74/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
Maintainer antworten meist innerhalb von 2 Tagen