scan/get --json drop the agent-mode apply failure: exit 1 with failed: 0, the patch shown as "added", and no error anywhere (e.g. a read-only global ~/.m2)
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 78/100
Direzione di ricerca
Start in crates/socket-patch-cli/src/commands/get.rs at run_nested_apply around line 2469 and the envelope assembly around lines 2487-2495; the nested apply currently returns only a bool and drops its events. Read the matching apply_failed site around line 3453, the patches[] contract in CLI_CONTRACT.md, and the agent-mode shapes in tests/docker_e2e_maven.rs. Done means JSON reports the per-patch apply_failed metadata and counters match the failed outcome for scan and get.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
[agent] Found by the scheduled Maven bug-hunt routine (ledger #318).
Summary
When scan --mode agent / get download a patch and the nested apply step then fails, the --json envelope reports "status": "partial_failure" and exits 1. But it says "failed": 0, "applied": 0, lists the patch as "action": "added", and has no error code or message, on stdout or stderr. The human-mode run of the same command prints Error: Failed to patch pkg:maven/…: Permission denied (os error 13), so the cause is known; it just doesn't reach the JSON.
I found it with the global-mode (-g) checklist item "a global directory you can't write to must fail loudly with a clear error". The code path is not Maven-specific: get.rs keeps only a bool from the nested apply. I reproduced it with Maven only.
Impact
The exit code is right, but a CI job or automation that reads --json (the documented machine interface) can't tell what failed or why. The only per-patch record says added, and the counters show nothing failed. A consumer that keys on failed/patches[].action rather than the exit code reads this as "recorded, nothing failed".
Repro (Linux, Maven 3.9.11 local repository, run as a non-root user)
You need the agent-mode patch stub for pkg:maven/org.apache.commons/[email protected] (the shapes from tests/docker_e2e_maven.rs).
H=$(mktemp -d); REL=org/apache/commons/commons-text/1.10.0/commons-text-1.10.0.pom
mkdir -p $H/.m2/repository/$(dirname $REL); cp commons-text-1.10.0.pom $H/.m2/repository/$REL
chmod -R a+rX,go-w $H/.m2 # root-owned, read-only for the user
W=$(mktemp -d); chmod 777 $W; cd $W
A="--api-url http://127.0.0.1:18997 --api-token fake --org org --ecosystems maven"
setpriv --reuid=65534 --regid=65534 --clear-groups env HOME=$H socket-patch scan -g --mode agent --yes --json $A
# rc=1 {"status":"partial_failure", "apply":{"found":1,"downloaded":1,"failed":0,"applied":0,
# "patches":[{"purl":"pkg:maven/[email protected]","action":"added",...}]}} <- no error text
setpriv ... socket-patch get pkg:maven/org.apache.commons/[email protected] -g --yes --json $A
# rc=1 same: failed 0, applied 0, action "added", no error
setpriv ... socket-patch scan -g --mode agent --yes $A # human mode
# Error: Failed to patch pkg:maven/org.apache.commons/[email protected]: Permission denied (os error 13)
# Summary: 0 of 1 targeted patch applied, 0 already patched, 1 failed, 0 not found on disk
setpriv ... socket-patch apply -g --json --offline --ecosystems maven
# standalone apply is fine: events[0] = {"action":"failed","errorCode":"apply_failed","error":"Permission denied (os error 13)"}
Each command was run twice, in fresh workdirs, with the same result. No permission text appears in the JSON or on stderr in either JSON run.
Expected vs actual
- Expected: the JSON carries the per-patch apply outcome, the same
{action:"failed", errorCode:"apply_failed", error}the standaloneapply --jsonemits. The counters agree with the status (failed ≥ 1, or anapplyfailure count). CLI_CONTRACT.md'spatches[]entry shape forgetandscan --applysays records "carry the same metadata regardless of which command" produced them, and the human path for this same run reports1 failed. - Actual:
failed: 0,action: "added", no error. Only the exit code andstatusshow the failure.
Matrix
| OS | Maven local repository | scan -g --mode agent --json |
get -g --json |
human mode | apply -g --json |
|---|---|---|---|---|---|
| Linux | 3.9.11 layout, read-only | fail (no error, failed 0) | fail (no error, failed 0) | pass (error printed) | pass (apply_failed event) |
macOS and Windows are untested. The failure is in the JSON assembly, which doesn't depend on the OS. Other ecosystems are probably affected too (same code), but I only checked Maven.
Tested on: main 2463257 (v5 consolidation, #277). Not bisected.
Suspect code
crates/socket-patch-cli/src/commands/get.rs:2469:run_nested_apply(...)returns only abool. The nested apply's events (witherrorCode/error) are dropped, and the envelope atget.rs:2487-2495fillsfailedfrombatch.failed(download failures only) andappliedfromdownloadedor0.get.rs:3453(the secondapply_failedsite) has the same shape.
- Lingua principale
- Rust
- Stelle
- 8
- Fork
- 0
- Merge medio
- 1g 31m
- PR unite (30g)
- 151
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di SocketDev/socket-patch
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
Difficoltà 2/5 1-3 ore Idoneità per principianti 73/100
SocketDev/socket-patch#783 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
agent:triaged bug bughunt pm:pipenv priority:p1
Difficoltà 2/5 1-3 ore Idoneità per principianti 83/100
SocketDev/socket-patch#744 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
agent:triaged bug bughunt pm:cargo priority:p2
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
SocketDev/socket-patch#651 · 3 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
agent:triaged bug bughunt pm:composer priority:p2
Difficoltà 2/5 1-3 ore Idoneità per principianti 90/100
SocketDev/socket-patch#515 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
A report-only `scan -g` tells you to run `socket-patch scan --mode agent [PATHS]` without `-g`, so following the hint scans the cwd project instead of the global installForse già presa Una pull request collegata a questa issue è aperta o già unita. Apertaagent:triaged bug bughunt pm:npm priority:p1
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
SocketDev/socket-patch#464 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di SocketDev/socket-patch
Issue simili
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 74/100
-
review-drift
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
oxidecomputer/hansei#14 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
rubys/roundhouse#444 ·
I maintainer di solito rispondono entro 1 giorno
-
Published hardy-bpa-server image is built without the file-cla featureForse già presa @EmbryoSpace l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
ricktaylor/hardy#755 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
semaphoreci/docker-images#46 · 1 commento ·