CLI_CONTRACT.md documents status paidRequired for get and scan, but get emits "paid_required" and scan never reports it
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 74/100
- Loại issue
- Tài liệu
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- rust
- Lĩnh vực
- cli, documentation
Hướng nghiên cứu
Đọc CLI_CONTRACT.md quanh các dòng 1092 và 1163, rồi so sánh với hai khối JSON paid viết tay trong crates/socket-patch-cli/src/commands/get.rs (L2894-L2905 và report_paid_required_uuid tại L3179-L3215) cộng với select_accessible trong scan/mod.rs. Viết lại hàng paid_required và enum status của contract để khớp với những gì được xuất ra, tùy chọn trích xuất một emitter dùng chung trong get.rs và kiểm chứng bằng cargo test -p socket-patch-cli --test get paid (4 test phải giữ màu xanh). Xong khi contract khớp với JSON được xuất ra và một test phân tích contract mới, mô phỏng theo contract_gradle_codes.rs, khẳng định cách viết của status.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: discussion #560 register.
Kind: bug (contract drift). Source: new finding; register C54.
Problem (main @ 9c43dfc)
CLI_CONTRACT.md documents a paid-plan refusal that no command emits, and doesn't document the one that get does emit.
-
What the contract says. The envelope's status enum lists
"paidRequired". The errorCode table rowpaid_requiredsays: actionfailed,status=paidRequired, emitted by "get/scan". -
What
getemits. Both paid paths hand-write a legacy object with a snake_case status and no events orerrorCode:- package/CVE search where nothing is accessible:
get.rs#L2894-L2905; get <uuid>on the public proxy (paid view or proxy 403):report_paid_required_uuid.
Both print
{"status":"paid_required","found":N,"downloaded":0,"applied":0,"patches":[…]}and exit 0. - package/CVE search where nothing is accessible:
-
What
scanemits. Nothing paid-specific. It drops inaccessible patches inselect_accessibleand reports them only as thepaidPatches/canAccessPaidPatchescounts.`` -
Status::PaidRequiredis never constructed. The variant is referenced only by tests below#[cfg(test)](L481). Its own doc comment already says "Nothing emits it yet (getreports this via its legacystatus: "paid_required"shape; scan never does)". So the code knows; the contract was never updated.
Proof by execution. On 9c43dfc, cargo test -p socket-patch-cli --test get paid ran twice: 4 passed both times. Those tests pin status == "paid_required" and exit 0 for both get paths: get_edge_cases_e2e.rs#L241-L287 and get_invariants.rs#L439-L490.`` A consumer that follows the contract and matches status == "paidRequired" or `errorCode == "paid_required"` never matches.
Symptoms
None filed. PR bots that implement the documented "upgrade your plan" branch silently never take it.
Impact
Small and user-visible: the documented machine contract for the paid tier is wrong in three ways (status spelling, action/errorCode, and the command list). It's another instance of C13/C33: the contract's code tables aren't checked against the code.
Proposed change
Make the contract describe what ships. No behavior change.
- Rewrite the
paid_requiredrow (L1163):getonly; legacy top-levelstatus: "paid_required"withfound/downloaded/applied/patches[], exit 0, noevents/errorCode. Keep the existingget <uuid>proxy sentence, which is accurate. - State that
scanreports paid patches only throughpaidPatchesandcanAccessPaidPatches. - In the status enum (L1092), mark
paidRequiredas reserved, or remove it. DeletingStatus::PaidRequiredand its two test references is optional and belongs with this change if it is removed. - Route the two hand-written
getJSON blocks through one helper so the shape is written once.
Moving get onto the unified envelope (where paidRequired would become real) is the owner decision in #704 and is out of scope here.
Size and scope
CLI_CONTRACT.md (two lines), get.rs (one shared ~20-line emitter replacing two blocks), and optionally json_envelope.rs (−6 lines). Under 60 changed lines.
Acceptance criteria
- The contract's
paid_requiredrow and status enum match the emitted JSON. -
get's two paid JSON blocks share one emitter. - The 4
--test get paidtests stay green. - Add a test that reads the contract's
paid_requiredrow and asserts thestatusspellinggetemits, in the style ofcontract_gradle_codes.rs.
Dependencies
- Independent of #704; if #704 later moves
getonto the envelope, that PR updates this row again. - Feeds #948 (checked contract reference) and #930 (typed error codes).
- Ngôn ngữ chính
- Rust
- Star
- 8
- Fork
- 0
- Merge trung bình
- 1 ngày 1 giờ
- Pull request đã merge (30 ngày)
- 211
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của SocketDev/socket-patch
-
arch-audit refactor
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
SocketDev/socket-patch#1011 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap)Có thể đã có người làm @mikolalysenko đã nhận 1 ngày trước. Đang mởagent:claimed agent:triaged bug bughunt pm:yarn-classic priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
SocketDev/socket-patch#907 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged bug bughunt pm:bundler priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
SocketDev/socket-patch#896 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 73/100
SocketDev/socket-patch#783 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged bug bughunt pm:pipenv priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 83/100
SocketDev/socket-patch#744 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của SocketDev/socket-patch
Issue tương tự
-
app enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 80/100
elodin-sys/elodin#890 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
guidance-ai/llguidance#391 ·
-
documentation
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
Verifiedz/Shimmer#144 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
点击设置提示`操作未能完成,详情请查看应用日志`Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
Y-ASLant/ElegantClipboard#166 ·