`scan --mode hosted --dry-run --vex <path> --json` drops the documented `vex: {skipped: true, reason: "dry_run"}` marker (agent and vendored scans emit it)
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 2/5
- Tempo estimado
- 1-3 horas
- Facilidade para iniciantes
- 83/100
Direção de pesquisa
Leia a montagem do JSON do scan hospedado em crates/socket-patch-cli/src/commands/scan/hosted.rs:1346-1360 e compare o tratamento de VEX com scan/mod.rs:368-370 e scan/vendor_flow.rs:542-543. O teste hospedado existente em covgap_commands_scan_hosted.rs:1948 cobre apenas a saída legível por humanos; adicione ou adapte a cobertura para execuções a seco em JSON. Está concluído quando hosted scan --dry-run --vex ... --json incluir o marcador documentado de ignorado sem gravar um arquivo VEX.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
[agent] Found by the scheduled Pipenv bug-hunt routine (ledger #313).
Summary
CLI_CONTRACT.md ("Embedded VEX", the "Built from the post-run state" bullet) says: "--dry-run skips generation on every host command (nothing was changed, and a preview must not write an attestation — scan --json marks it vex: {skipped: true, reason: "dry_run"})".
scan --mode vendored and scan --mode agent emit that marker. scan --mode hosted doesn't: its JSON envelope has no vex key at all, so a dry run looks exactly like a run without --vex. Human mode is fine, since it prints Skipping VEX generation (--dry-run: nothing was rewritten). Generation is skipped correctly, and no file is written. Only the JSON marker is missing.
I found this on Pipenv projects, but the code path is shared by every hosted ecosystem. A plain requirements.txt project behaves the same way.
Impact
Low. A JSON consumer (a CI wrapper or a bot that previews scan --mode hosted --vex …) can't tell "VEX was requested but skipped for the dry run" apart from "VEX was never requested". The mod.rs comment states the marker exists so as to keep "the request visible to JSON consumers instead of silently dropping it". Since v5 scan defaults to hosted, so a bare scan --dry-run --vex … --json hits this path.
Repro (Linux, main 045d7ec, local mock of the patch API serving six 1.16.0)
mkdir app && cd app
cat > Pipfile <<'EOF'
[[source]]
url = "https://pypi.org/simple"
verify_ssl = true
name = "pypi"
[packages]
six = "==1.16.0"
EOF
pipenv lock
socket-patch scan --mode hosted --dry-run --yes --vex v.json --vex-product pkg:pypi/app@1 --json | jq '.vex, .redirect.dryRun'
# null
# true
socket-patch scan --mode vendored --dry-run --yes --vex v.json --vex-product pkg:pypi/app@1 --json | jq .vex
# {"skipped": true, "reason": "dry_run"}
socket-patch scan --mode agent --dry-run --yes --vex v.json --vex-product pkg:pypi/app@1 --json | jq .vex
# {"skipped": true, "reason": "dry_run"}
socket-patch scan --mode hosted --dry-run --yes --vex v.json --vex-product pkg:pypi/app@1 2>&1 | grep VEX
# Skipping VEX generation (--dry-run: nothing was rewritten).
Expected vs actual
- Expected (CLI_CONTRACT.md, Embedded VEX):
"vex": {"skipped": true, "reason": "dry_run"}in the hostedscan --jsonenvelope, as in the other two modes. - Actual: the
vexkey is missing. Exit 0,status: success, andredirect.dryRun: true.
Matrix (Linux, each run in a fresh project)
| Project | --mode hosted |
--mode vendored |
--mode agent |
|---|---|---|---|
| Pipfile.lock from Pipenv 2026.8.0 (run twice) | missing | marker | marker |
| Pipfile.lock from Pipenv 2018.11.26 | missing | marker | not run |
plain requirements.txt (six==1.16.0) |
missing | not run | not run |
macOS and Windows weren't probed. This is OS-independent JSON assembly.
First bad
Not bisected. The marker arrived in the agent and vendored arms with de316b4, and the hosted arm never got it.
Suspect code
crates/socket-patch-cli/src/commands/scan/hosted.rs:1241: VEX generation is gated on!common.dry_run, which is correct.crates/socket-patch-cli/src/commands/scan/hosted.rs:1346-1360: the JSON arm setsresult["vex"]only forSome(statements)orvex_error. It has nodry_runbranch, unlikescan/mod.rs:368-370andscan/vendor_flow.rs:542-543. The human arm (hosted.rs:1467) does handle the dry run.- The existing test (
covgap_commands_scan_hosted.rs:1948,human_dry_run_prints_would_rewrite_pnpm_guidance_and_vex_skip) covers only the human output.
- Linguagem predominante
- Rust
- Estrelas
- 8
- Forks
- 0
- Merge médio
- 1d 7min
- PRs com merge (30d)
- 178
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Sem modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de SocketDev/socket-patch
-
Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap)Talvez já em andamento @mikolalysenko assumiu hoje. Abertaagent:claimed agent:triaged bug bughunt pm:yarn-classic priority:p1
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
SocketDev/socket-patch#907 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
-
agent:triaged bug bughunt pm:npm priority:p1
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
SocketDev/socket-patch#900 ·
Mantenedores costumam responder em até 1 dia
-
agent:triaged bug bughunt pm:bundler priority:p1
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
SocketDev/socket-patch#896 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 73/100
SocketDev/socket-patch#783 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
agent:triaged bug bughunt pm:cargo priority:p2
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 84/100
SocketDev/socket-patch#651 · 3 comentários ·
Mantenedores costumam responder em até 1 dia
Todas as issues de SocketDev/socket-patch
Issues semelhantes
-
Signals (Failure Detector): a tool call and its own execution are reported as a repeated callAberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
Mantenedores costumam responder em até 1 dia
-
check: a failed re-read of the model file before binding is labelled E_THETA_LEVEL_BINDING on [parameters]Talvez já em andamento @TeunP assumiu hoje. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 65/100
Mantenedores costumam responder em até 1 dia
-
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 80/100
Devolutions/picky-rs#546 · 1 comentário ·
Mantenedores costumam responder em até 3 dias
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 74/100
Mantenedores costumam responder em até 1 dia