CLI_CONTRACT.md documents status paidRequired for get and scan, but get emits "paid_required" and scan never reports it
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 2/5
- Geschätzter Aufwand
- 1-3 Stunden
- Anfängerfreundlichkeit
- 74/100
- Issue-Typ
- Dokumentation
- Klarheit
- Klar beschrieben
- Aktivitätsstatus
- Aktiv
- Tech-Stack
- rust
- Bereich
- cli, documentation
Rechercherichtung
Lies CLI_CONTRACT.md um die Zeilen 1092 und 1163 und vergleiche sie dann mit den zwei handgeschriebenen paid-JSON-Blöcken in crates/socket-patch-cli/src/commands/get.rs (L2894-L2905 und report_paid_required_uuid bei L3179-L3215) sowie mit select_accessible in scan/mod.rs. Schreibe die paid_required-Zeile und das Status-Enum des Contracts so um, dass sie zum ausgelieferten Verhalten passen, extrahiere optional einen gemeinsamen Emitter in get.rs und verifiziere mit cargo test -p socket-patch-cli --test get paid (4 Tests müssen grün bleiben). Fertig, wenn der Contract dem ausgesendeten JSON entspricht und ein neuer contract-parsing-Test, angelehnt an contract_gradle_codes.rs, die Schreibweise des Statuss behauptet.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: discussion #560 register.
Kind: bug (contract drift). Source: new finding; register C54.
Problem (main @ 9c43dfc)
CLI_CONTRACT.md documents a paid-plan refusal that no command emits, and doesn't document the one that get does emit.
-
What the contract says. The envelope's status enum lists
"paidRequired". The errorCode table rowpaid_requiredsays: actionfailed,status=paidRequired, emitted by "get/scan". -
What
getemits. Both paid paths hand-write a legacy object with a snake_case status and no events orerrorCode:- package/CVE search where nothing is accessible:
get.rs#L2894-L2905; get <uuid>on the public proxy (paid view or proxy 403):report_paid_required_uuid.
Both print
{"status":"paid_required","found":N,"downloaded":0,"applied":0,"patches":[…]}and exit 0. - package/CVE search where nothing is accessible:
-
What
scanemits. Nothing paid-specific. It drops inaccessible patches inselect_accessibleand reports them only as thepaidPatches/canAccessPaidPatchescounts.`` -
Status::PaidRequiredis never constructed. The variant is referenced only by tests below#[cfg(test)](L481). Its own doc comment already says "Nothing emits it yet (getreports this via its legacystatus: "paid_required"shape; scan never does)". So the code knows; the contract was never updated.
Proof by execution. On 9c43dfc, cargo test -p socket-patch-cli --test get paid ran twice: 4 passed both times. Those tests pin status == "paid_required" and exit 0 for both get paths: get_edge_cases_e2e.rs#L241-L287 and get_invariants.rs#L439-L490.`` A consumer that follows the contract and matches status == "paidRequired" or `errorCode == "paid_required"` never matches.
Symptoms
None filed. PR bots that implement the documented "upgrade your plan" branch silently never take it.
Impact
Small and user-visible: the documented machine contract for the paid tier is wrong in three ways (status spelling, action/errorCode, and the command list). It's another instance of C13/C33: the contract's code tables aren't checked against the code.
Proposed change
Make the contract describe what ships. No behavior change.
- Rewrite the
paid_requiredrow (L1163):getonly; legacy top-levelstatus: "paid_required"withfound/downloaded/applied/patches[], exit 0, noevents/errorCode. Keep the existingget <uuid>proxy sentence, which is accurate. - State that
scanreports paid patches only throughpaidPatchesandcanAccessPaidPatches. - In the status enum (L1092), mark
paidRequiredas reserved, or remove it. DeletingStatus::PaidRequiredand its two test references is optional and belongs with this change if it is removed. - Route the two hand-written
getJSON blocks through one helper so the shape is written once.
Moving get onto the unified envelope (where paidRequired would become real) is the owner decision in #704 and is out of scope here.
Size and scope
CLI_CONTRACT.md (two lines), get.rs (one shared ~20-line emitter replacing two blocks), and optionally json_envelope.rs (−6 lines). Under 60 changed lines.
Acceptance criteria
- The contract's
paid_requiredrow and status enum match the emitted JSON. -
get's two paid JSON blocks share one emitter. - The 4
--test get paidtests stay green. - Add a test that reads the contract's
paid_requiredrow and asserts thestatusspellinggetemits, in the style ofcontract_gradle_codes.rs.
Dependencies
- Independent of #704; if #704 later moves
getonto the envelope, that PR updates this row again. - Feeds #948 (checked contract reference) and #930 (typed error codes).
- Vorherrschende Sprache
- Rust
- Sterne
- 8
- Forks
- 0
- Ø Merge
- 1 T. 1 Std.
- Gemergte PRs (30 T.)
- 257
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus SocketDev/socket-patch
-
agent:triaged bug bughunt pm:npm priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 85/100
SocketDev/socket-patch#1127 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:bundler priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
SocketDev/socket-patch#1125 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:pipenv priority:p1
Schwierigkeit 2/5 Unter einer Stunde Anfängerfreundlichkeit 85/100
SocketDev/socket-patch#1122 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:npm priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
SocketDev/socket-patch#1072 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged arch-audit bug priority:p3
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 85/100
SocketDev/socket-patch#1062 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in SocketDev/socket-patch
Ähnliche Issues
-
test(executor_l0): assert execute() TaskOutcome, not only bus events / 断言 execute() 返回的 TaskOutcomeOffentype:debt
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 62/100
skaiy/wild_agentos#425 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Default-import note suggests `import * as process` for velt:process, which does not name the builtinOffen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
Maintainer antworten meist innerhalb von 1 Tag
-
bug ticket
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
cratestack/cratestack#1154 ·
Maintainer antworten meist innerhalb von 1 Tag
-
status:needs-triage
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
agentic-os-org/ANOLISA#6742 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag