CLI_CONTRACT.md documents status paidRequired for get and scan, but get emits "paid_required" and scan never reports it
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 74/100
- Tipo di issue
- Documentazione
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- rust
- Ambito
- cli, documentation
Direzione di ricerca
Leggi CLI_CONTRACT.md intorno alle righe 1092 e 1163, poi confrontalo con i due blocchi JSON paid scritti a mano in crates/socket-patch-cli/src/commands/get.rs (L2894-L2905 e report_paid_required_uuid a L3179-L3215) oltre a select_accessible in scan/mod.rs. Riscrivi la riga paid_required e l'enum di status del contratto in modo che corrispondano a ciò che viene rilasciato, estrai eventualmente un emitter condiviso in get.rs e verifica con cargo test -p socket-patch-cli --test get paid (i 4 test devono restare verdi). Concluso quando il contratto corrisponde al JSON emesso e un nuovo test di parsing del contratto, modellato su contract_gradle_codes.rs, asserisce l'ortografia dello status.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: discussion #560 register.
Kind: bug (contract drift). Source: new finding; register C54.
Problem (main @ 9c43dfc)
CLI_CONTRACT.md documents a paid-plan refusal that no command emits, and doesn't document the one that get does emit.
-
What the contract says. The envelope's status enum lists
"paidRequired". The errorCode table rowpaid_requiredsays: actionfailed,status=paidRequired, emitted by "get/scan". -
What
getemits. Both paid paths hand-write a legacy object with a snake_case status and no events orerrorCode:- package/CVE search where nothing is accessible:
get.rs#L2894-L2905; get <uuid>on the public proxy (paid view or proxy 403):report_paid_required_uuid.
Both print
{"status":"paid_required","found":N,"downloaded":0,"applied":0,"patches":[…]}and exit 0. - package/CVE search where nothing is accessible:
-
What
scanemits. Nothing paid-specific. It drops inaccessible patches inselect_accessibleand reports them only as thepaidPatches/canAccessPaidPatchescounts.`` -
Status::PaidRequiredis never constructed. The variant is referenced only by tests below#[cfg(test)](L481). Its own doc comment already says "Nothing emits it yet (getreports this via its legacystatus: "paid_required"shape; scan never does)". So the code knows; the contract was never updated.
Proof by execution. On 9c43dfc, cargo test -p socket-patch-cli --test get paid ran twice: 4 passed both times. Those tests pin status == "paid_required" and exit 0 for both get paths: get_edge_cases_e2e.rs#L241-L287 and get_invariants.rs#L439-L490.`` A consumer that follows the contract and matches status == "paidRequired" or `errorCode == "paid_required"` never matches.
Symptoms
None filed. PR bots that implement the documented "upgrade your plan" branch silently never take it.
Impact
Small and user-visible: the documented machine contract for the paid tier is wrong in three ways (status spelling, action/errorCode, and the command list). It's another instance of C13/C33: the contract's code tables aren't checked against the code.
Proposed change
Make the contract describe what ships. No behavior change.
- Rewrite the
paid_requiredrow (L1163):getonly; legacy top-levelstatus: "paid_required"withfound/downloaded/applied/patches[], exit 0, noevents/errorCode. Keep the existingget <uuid>proxy sentence, which is accurate. - State that
scanreports paid patches only throughpaidPatchesandcanAccessPaidPatches. - In the status enum (L1092), mark
paidRequiredas reserved, or remove it. DeletingStatus::PaidRequiredand its two test references is optional and belongs with this change if it is removed. - Route the two hand-written
getJSON blocks through one helper so the shape is written once.
Moving get onto the unified envelope (where paidRequired would become real) is the owner decision in #704 and is out of scope here.
Size and scope
CLI_CONTRACT.md (two lines), get.rs (one shared ~20-line emitter replacing two blocks), and optionally json_envelope.rs (−6 lines). Under 60 changed lines.
Acceptance criteria
- The contract's
paid_requiredrow and status enum match the emitted JSON. -
get's two paid JSON blocks share one emitter. - The 4
--test get paidtests stay green. - Add a test that reads the contract's
paid_requiredrow and asserts thestatusspellinggetemits, in the style ofcontract_gradle_codes.rs.
Dependencies
- Independent of #704; if #704 later moves
getonto the envelope, that PR updates this row again. - Feeds #948 (checked contract reference) and #930 (typed error codes).
- Lingua principale
- Rust
- Stelle
- 8
- Fork
- 0
- Merge medio
- 1g 1h
- PR unite (30g)
- 211
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di SocketDev/socket-patch
-
arch-audit refactor
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
SocketDev/socket-patch#1011 ·
I maintainer di solito rispondono entro 1 giorno
-
Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap)Forse già presa @mikolalysenko l’ha presa 1 giorno fa. Apertaagent:claimed agent:triaged bug bughunt pm:yarn-classic priority:p1
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
SocketDev/socket-patch#907 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
agent:triaged bug bughunt pm:bundler priority:p1
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
SocketDev/socket-patch#896 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
Difficoltà 2/5 1-3 ore Idoneità per principianti 73/100
SocketDev/socket-patch#783 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
agent:triaged bug bughunt pm:pipenv priority:p1
Difficoltà 2/5 1-3 ore Idoneità per principianti 83/100
SocketDev/socket-patch#744 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di SocketDev/socket-patch
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
bmander/geomsolver#118 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
I maintainer di solito rispondono entro 1 giorno
-
Three Windows builds are keyed on a later release than their layoutForse già presa @ero-qt l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 2 giorni
-
priority:P3 type:docs
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
sebastian-software/ferroni#253 ·
I maintainer di solito rispondono entro 1 giorno