CLI_CONTRACT.md documents status paidRequired for get and scan, but get emits "paid_required" and scan never reports it
Les mainteneurs répondent en général sous 1 jour
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 2/5
- Temps estimé
- 1-3 heures
- Accessibilité débutants
- 74/100
- Type d'issue
- Documentation
- Clarté
- Clairement spécifiée
- Activité
- Active
- Stack technique
- rust
- Domaine
- cli, documentation
Piste de recherche
Lis CLI_CONTRACT.md autour des lignes 1092 et 1163, puis compare avec les deux blocs JSON paid écrits à la main dans crates/socket-patch-cli/src/commands/get.rs (L2894-L2905 et report_paid_required_uuid à L3179-L3215) ainsi que select_accessible dans scan/mod.rs. Réécris la ligne paid_required et l'enum de statut du contrat pour qu'ils correspondent à ce qui est livré, extrais éventuellement un émetteur partagé dans get.rs et vérifie avec cargo test -p socket-patch-cli --test get paid (4 tests doivent rester verts). Terminé lorsque le contrat correspond au JSON émis et qu'un nouveau test d'analyse du contrat, inspiré de contract_gradle_codes.rs, vérifie l'orthographe du statut.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: discussion #560 register.
Kind: bug (contract drift). Source: new finding; register C54.
Problem (main @ 9c43dfc)
CLI_CONTRACT.md documents a paid-plan refusal that no command emits, and doesn't document the one that get does emit.
-
What the contract says. The envelope's status enum lists
"paidRequired". The errorCode table rowpaid_requiredsays: actionfailed,status=paidRequired, emitted by "get/scan". -
What
getemits. Both paid paths hand-write a legacy object with a snake_case status and no events orerrorCode:- package/CVE search where nothing is accessible:
get.rs#L2894-L2905; get <uuid>on the public proxy (paid view or proxy 403):report_paid_required_uuid.
Both print
{"status":"paid_required","found":N,"downloaded":0,"applied":0,"patches":[…]}and exit 0. - package/CVE search where nothing is accessible:
-
What
scanemits. Nothing paid-specific. It drops inaccessible patches inselect_accessibleand reports them only as thepaidPatches/canAccessPaidPatchescounts.`` -
Status::PaidRequiredis never constructed. The variant is referenced only by tests below#[cfg(test)](L481). Its own doc comment already says "Nothing emits it yet (getreports this via its legacystatus: "paid_required"shape; scan never does)". So the code knows; the contract was never updated.
Proof by execution. On 9c43dfc, cargo test -p socket-patch-cli --test get paid ran twice: 4 passed both times. Those tests pin status == "paid_required" and exit 0 for both get paths: get_edge_cases_e2e.rs#L241-L287 and get_invariants.rs#L439-L490.`` A consumer that follows the contract and matches status == "paidRequired" or `errorCode == "paid_required"` never matches.
Symptoms
None filed. PR bots that implement the documented "upgrade your plan" branch silently never take it.
Impact
Small and user-visible: the documented machine contract for the paid tier is wrong in three ways (status spelling, action/errorCode, and the command list). It's another instance of C13/C33: the contract's code tables aren't checked against the code.
Proposed change
Make the contract describe what ships. No behavior change.
- Rewrite the
paid_requiredrow (L1163):getonly; legacy top-levelstatus: "paid_required"withfound/downloaded/applied/patches[], exit 0, noevents/errorCode. Keep the existingget <uuid>proxy sentence, which is accurate. - State that
scanreports paid patches only throughpaidPatchesandcanAccessPaidPatches. - In the status enum (L1092), mark
paidRequiredas reserved, or remove it. DeletingStatus::PaidRequiredand its two test references is optional and belongs with this change if it is removed. - Route the two hand-written
getJSON blocks through one helper so the shape is written once.
Moving get onto the unified envelope (where paidRequired would become real) is the owner decision in #704 and is out of scope here.
Size and scope
CLI_CONTRACT.md (two lines), get.rs (one shared ~20-line emitter replacing two blocks), and optionally json_envelope.rs (−6 lines). Under 60 changed lines.
Acceptance criteria
- The contract's
paid_requiredrow and status enum match the emitted JSON. -
get's two paid JSON blocks share one emitter. - The 4
--test get paidtests stay green. - Add a test that reads the contract's
paid_requiredrow and asserts thestatusspellinggetemits, in the style ofcontract_gradle_codes.rs.
Dependencies
- Independent of #704; if #704 later moves
getonto the envelope, that PR updates this row again. - Feeds #948 (checked contract reference) and #930 (typed error codes).
- Langage dominant
- Rust
- Étoiles
- 8
- Forks
- 0
- Merge moyen
- 1 j 1 h
- PR mergées (30 j)
- 211
Préparer son environnement
- Aucun Dockerfile ni fichier Docker Compose
- Aucun modèle de pull request
- Lire le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de SocketDev/socket-patch
-
arch-audit refactor
Difficulté 2/5 1-3 heures Accessibilité débutants 82/100
SocketDev/socket-patch#1011 ·
Les mainteneurs répondent en général sous 1 jour
-
Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap)Peut-être pris @mikolalysenko l’a pris il y a 2 jours. Ouverteagent:claimed agent:triaged bug bughunt pm:yarn-classic priority:p1
Difficulté 2/5 1-3 heures Accessibilité débutants 85/100
SocketDev/socket-patch#907 · 2 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
agent:triaged bug bughunt pm:bundler priority:p1
Difficulté 2/5 1-3 heures Accessibilité débutants 85/100
SocketDev/socket-patch#896 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
Difficulté 2/5 1-3 heures Accessibilité débutants 73/100
SocketDev/socket-patch#783 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
-
agent:triaged bug bughunt pm:pipenv priority:p1
Difficulté 2/5 1-3 heures Accessibilité débutants 83/100
SocketDev/socket-patch#744 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
Toutes les issues de SocketDev/socket-patch
Issues similaires
-
documentation enhancement
Difficulté 2/5 1-3 heures Accessibilité débutants 62/100
adorsys/status-list-server#619 ·
Les mainteneurs répondent en général sous 2 jours
-
batch-backport only backports the first 30 matching PRsPeut-être pris @DvirDukhan l’a pris aujourd’hui. Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
Les mainteneurs répondent en général sous 5 jours
-
bug
Difficulté 2/5 1-3 heures Accessibilité débutants 77/100
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 2/5 1-3 heures Accessibilité débutants 65/100
equinor/septic-config-generator#481 ·
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 2/5 1-3 heures Accessibilité débutants 76/100
Les mainteneurs répondent en général sous 1 jour