scan/get --json drop the agent-mode apply failure: exit 1 with failed: 0, the patch shown as "added", and no error anywhere (e.g. a read-only global ~/.m2)
Les mainteneurs répondent en général sous 1 jour
Évaluation
- Difficulté
- 3/5
- Temps estimé
- 1-2 jours
- Accessibilité débutants
- 78/100
Piste de recherche
Start in crates/socket-patch-cli/src/commands/get.rs at run_nested_apply around line 2469 and the envelope assembly around lines 2487-2495; the nested apply currently returns only a bool and drops its events. Read the matching apply_failed site around line 3453, the patches[] contract in CLI_CONTRACT.md, and the agent-mode shapes in tests/docker_e2e_maven.rs. Done means JSON reports the per-patch apply_failed metadata and counters match the failed outcome for scan and get.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
[agent] Found by the scheduled Maven bug-hunt routine (ledger #318).
Summary
When scan --mode agent / get download a patch and the nested apply step then fails, the --json envelope reports "status": "partial_failure" and exits 1. But it says "failed": 0, "applied": 0, lists the patch as "action": "added", and has no error code or message, on stdout or stderr. The human-mode run of the same command prints Error: Failed to patch pkg:maven/…: Permission denied (os error 13), so the cause is known; it just doesn't reach the JSON.
I found it with the global-mode (-g) checklist item "a global directory you can't write to must fail loudly with a clear error". The code path is not Maven-specific: get.rs keeps only a bool from the nested apply. I reproduced it with Maven only.
Impact
The exit code is right, but a CI job or automation that reads --json (the documented machine interface) can't tell what failed or why. The only per-patch record says added, and the counters show nothing failed. A consumer that keys on failed/patches[].action rather than the exit code reads this as "recorded, nothing failed".
Repro (Linux, Maven 3.9.11 local repository, run as a non-root user)
You need the agent-mode patch stub for pkg:maven/org.apache.commons/[email protected] (the shapes from tests/docker_e2e_maven.rs).
H=$(mktemp -d); REL=org/apache/commons/commons-text/1.10.0/commons-text-1.10.0.pom
mkdir -p $H/.m2/repository/$(dirname $REL); cp commons-text-1.10.0.pom $H/.m2/repository/$REL
chmod -R a+rX,go-w $H/.m2 # root-owned, read-only for the user
W=$(mktemp -d); chmod 777 $W; cd $W
A="--api-url http://127.0.0.1:18997 --api-token fake --org org --ecosystems maven"
setpriv --reuid=65534 --regid=65534 --clear-groups env HOME=$H socket-patch scan -g --mode agent --yes --json $A
# rc=1 {"status":"partial_failure", "apply":{"found":1,"downloaded":1,"failed":0,"applied":0,
# "patches":[{"purl":"pkg:maven/[email protected]","action":"added",...}]}} <- no error text
setpriv ... socket-patch get pkg:maven/org.apache.commons/[email protected] -g --yes --json $A
# rc=1 same: failed 0, applied 0, action "added", no error
setpriv ... socket-patch scan -g --mode agent --yes $A # human mode
# Error: Failed to patch pkg:maven/org.apache.commons/[email protected]: Permission denied (os error 13)
# Summary: 0 of 1 targeted patch applied, 0 already patched, 1 failed, 0 not found on disk
setpriv ... socket-patch apply -g --json --offline --ecosystems maven
# standalone apply is fine: events[0] = {"action":"failed","errorCode":"apply_failed","error":"Permission denied (os error 13)"}
Each command was run twice, in fresh workdirs, with the same result. No permission text appears in the JSON or on stderr in either JSON run.
Expected vs actual
- Expected: the JSON carries the per-patch apply outcome, the same
{action:"failed", errorCode:"apply_failed", error}the standaloneapply --jsonemits. The counters agree with the status (failed ≥ 1, or anapplyfailure count). CLI_CONTRACT.md'spatches[]entry shape forgetandscan --applysays records "carry the same metadata regardless of which command" produced them, and the human path for this same run reports1 failed. - Actual:
failed: 0,action: "added", no error. Only the exit code andstatusshow the failure.
Matrix
| OS | Maven local repository | scan -g --mode agent --json |
get -g --json |
human mode | apply -g --json |
|---|---|---|---|---|---|
| Linux | 3.9.11 layout, read-only | fail (no error, failed 0) | fail (no error, failed 0) | pass (error printed) | pass (apply_failed event) |
macOS and Windows are untested. The failure is in the JSON assembly, which doesn't depend on the OS. Other ecosystems are probably affected too (same code), but I only checked Maven.
Tested on: main 2463257 (v5 consolidation, #277). Not bisected.
Suspect code
crates/socket-patch-cli/src/commands/get.rs:2469:run_nested_apply(...)returns only abool. The nested apply's events (witherrorCode/error) are dropped, and the envelope atget.rs:2487-2495fillsfailedfrombatch.failed(download failures only) andappliedfromdownloadedor0.get.rs:3453(the secondapply_failedsite) has the same shape.
- Langage dominant
- Rust
- Étoiles
- 8
- Forks
- 0
- Merge moyen
- 1 j 1 h
- PR mergées (30 j)
- 211
Préparer son environnement
- Aucun Dockerfile ni fichier Docker Compose
- Aucun modèle de pull request
- Lire le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de SocketDev/socket-patch
-
arch-audit refactor
Difficulté 2/5 1-3 heures Accessibilité débutants 82/100
SocketDev/socket-patch#1011 ·
Les mainteneurs répondent en général sous 1 jour
-
agent:triaged arch-audit bug priority:p3
Difficulté 2/5 1-3 heures Accessibilité débutants 74/100
SocketDev/socket-patch#982 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
-
Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap)Peut-être pris @mikolalysenko l’a pris il y a 1 jour. Ouverteagent:claimed agent:triaged bug bughunt pm:yarn-classic priority:p1
Difficulté 2/5 1-3 heures Accessibilité débutants 85/100
SocketDev/socket-patch#907 · 2 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
agent:triaged bug bughunt pm:bundler priority:p1
Difficulté 2/5 1-3 heures Accessibilité débutants 85/100
SocketDev/socket-patch#896 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
Difficulté 2/5 1-3 heures Accessibilité débutants 73/100
SocketDev/socket-patch#783 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
Toutes les issues de SocketDev/socket-patch
Issues similaires
-
documentation
Difficulté 1/5 Moins d'une heure Accessibilité débutants 90/100
fastrevmd-lab/rustmistmcp#161 ·
-
bug user-priority/P2
Difficulté 1/5 Moins d'une heure Accessibilité débutants 92/100
Les mainteneurs répondent en général sous 1 jour
-
opencode: an unanswered --version probe launches opencode 2 without per-session service isolationOuverte
Difficulté 2/5 1-3 heures Accessibilité débutants 84/100
Les mainteneurs répondent en général sous 1 jour
-
security-advisory
Difficulté 2/5 1-3 heures Accessibilité débutants 85/100
MinBZK/regelrecht#1686 ·
Les mainteneurs répondent en général sous 1 jour
-
L: github:actions L: php:composer
Difficulté 2/5 1-3 heures Accessibilité débutants 88/100
dependabot/dependabot-core#16493 ·
Les mainteneurs répondent en général sous 1 jour