`apply --check` drift report tells you to run `socket-patch apply` without the `-g` / `--global-prefix` / `--cwd` it was given, so following it patches nothing and exits 0
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 72/100
Hướng nghiên cứu
Cách khắc phục sai là eprintln! được ghi cứng trong run_check tại crates/socket-patch-cli/src/commands/apply.rs, khoảng dòng 674, và bỏ qua args.common (global, global_prefix, cwd, manifest_path, ecosystems). Hãy lấy helper report_only_hint từ bản sửa #777 cho scan -g làm mẫu và dựng lệnh apply từ cùng các cờ phạm vi. Công việc hoàn thành khi lời khuyên khắc phục được in ra, chạy nguyên văn sau bước tái hiện trong issue, sửa được bản sao, và apply --check tiếp theo kết thúc với mã thoát 0.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
[agent] Found by the scheduled Pipenv bug-hunt routine (ledger #313).
Summary
When apply --check finds drift, the human report always ends with the fixed line:
Error: Patches are OUT OF SYNC:
pkg:pypi/[email protected]: patch not applied (an installed copy is still unpatched)
Run `socket-patch apply` to regenerate them.
The suggested command drops every scope flag the check ran with. The check itself is correct (exit 1 on the stale copy), but running the remedy as printed targets a different tree:
apply --check -g --global-prefix <site-packages>(the Dockerpipenv install --systemshape): plainsocket-patch applycrawls the cwd project, prints0 of 1 targeted patch applied, … 1 not found on disk, and exits 0. The global copy stays unpatched.apply -gwithout the prefix patches the default system interpreter instead. In the sandbox that was the distro's/usr/lib/python3/dist-packages/six.py, which isn't the tree that was checked.apply --check --cwd app(CI running from a parent directory): plainsocket-patch applyprintsNo patch manifest found; nothing to apply.and exits 0. The Pipenv venv stays unpatched.
This is the same class as #464 (the report-only scan -g hint dropped -g), which was fixed in #777. The apply --check report wasn't covered by that fix.
Impact
apply --check is the CI / GitHub-App audit gate (CLI_CONTRACT apply --check row). A user or CI job that follows its remedy gets exit 0 and believes the drift is fixed. The next apply --check fails again, and the installed copy keeps running unpatched bytes in the meantime. There's no false VEX: this is a misleading remedy, not a wrong verdict.
Repro (Linux, main f3c6313, Pipenv 2026.8.0, local mock of the patch API serving a patched six-1.16.0 wheel)
# global / Docker `pipenv install --system` shape
G=$(mktemp -d)/sys; python3.11 -m venv "$G"; SPK=$G/lib/python3.11/site-packages
"$G/bin/pip" install six==1.16.0
cd my-pipenv-project # Pipfile + Pipfile.lock pinning six==1.16.0
socket-patch scan -g --global-prefix "$SPK" --mode agent --yes # patches $SPK/six.py
"$G/bin/pip" install --force-reinstall --no-deps six==1.16.0 # image rebuilt / reinstall
socket-patch apply --check -g --global-prefix "$SPK" # exit 1, "Run `socket-patch apply` to regenerate them."
socket-patch apply # the remedy verbatim: exit 0, "1 not found on disk"
head -1 "$SPK/six.py" # still the upstream bytes
# --cwd shape (agent mode, Pipenv WORKON_HOME venv)
socket-patch scan --cwd app --mode agent --yes
(cd app && pipenv run pip install --force-reinstall --no-deps six==1.16.0)
socket-patch apply --check --cwd app # exit 1, same remedy line
socket-patch apply # exit 0, "No patch manifest found; nothing to apply."
I reproduced the -g --global-prefix lane 3 times and the --cwd lane once. In both, the remedy with the original flags (apply -g --global-prefix "$SPK", apply --cwd app) heals the tree, and the next --check exits 0.
Expected vs actual
- Expected: the remedy names the command that fixes what the check just reported. That means the same scope as the check:
-g,--global-prefix <dir>,--cwd <dir>, and--manifest-path/--ecosystemswhen given. That's how #464 / #777 fixed thescan -ghint. CLI_CONTRACT'sapply --checkrow specifies theError: Patches are OUT OF SYNC:report, and its purpose is to be acted on. - Actual: a fixed string with no scope flags. Following it exits 0 and patches nothing, or patches a different interpreter (
-gwithout the prefix).
OS × version
| OS | Pipenv | Shape | Result |
|---|---|---|---|
| Linux | 2026.8.0 | apply --check -g --global-prefix (pip-installed six, install --system shape) |
reproduces (×3) |
| Linux | 2026.8.0 | apply --check --cwd app (WORKON_HOME venv) |
reproduces |
| macOS / Windows | not probed | the line is a constant string | expected to be the same |
This isn't Pipenv- or PyPI-specific: every ecosystem's apply --check goes through the same branch.
Suspect code
crates/socket-patch-cli/src/commands/apply.rs:674, in run_check: eprintln!("Run \socket-patch apply` to regenerate them.");doesn't consultargs.common (global, global_prefix, cwd, manifest_path, ecosystems). Compare report_only_hint` after #777.
- Ngôn ngữ chính
- Rust
- Star
- 8
- Fork
- 0
- Merge trung bình
- 22 giờ 30 phút
- Pull request đã merge (30 ngày)
- 329
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của SocketDev/socket-patch
-
agent:triaged bug bughunt pm:npm priority:p2
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
SocketDev/socket-patch#1127 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged bug bughunt pm:bundler priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
SocketDev/socket-patch#1125 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged bug bughunt pm:npm priority:p3
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
SocketDev/socket-patch#1072 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged arch-audit bug priority:p3
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
SocketDev/socket-patch#1062 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged bug bughunt pm:bundler priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 80/100
SocketDev/socket-patch#1056 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của SocketDev/socket-patch
Issue tương tự
-
enhancement user-priority/P3
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 75/100
element-hq/lk-jwt-service#248 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
pact-foundation/pact-cli#154 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
antithesishq/bombadil#361 ·
Maintainer thường phản hồi trong vòng 1 ngày