CLI_CONTRACT.md documents status paidRequired for get and scan, but get emits "paid_required" and scan never reports it
維護者通常 1 天內回覆
還沒有人認領這個 Issue。
評估
- 難度
- 2/5
- 預估耗時
- 1-3 小時
- 新手友好度
- 74/100
- Issue 類型
- 文件
- 描述清晰度
- 描述清楚
- 活躍度
- 活躍
- 技術堆疊
- rust
- 領域
- cli, documentation
研究方向
閱讀 CLI_CONTRACT.md 中第 1092 行和第 1163 行附近的内容,然後與 crates/socket-patch-cli/src/commands/get.rs 中兩處手寫的 paid JSON 程式碼區塊(L2894-L2905 和位於 L3179-L3215 的 report_paid_required_uuid)以及 scan/mod.rs 中的 select_accessible 進行比較。重寫合約中的 paid_required 列和 status 列舉,使其與實際輸出的內容一致,可選擇在 get.rs 中提取一個共用的 emitter,並使用 cargo test -p socket-patch-cli --test get paid 驗證(4 個測試必須保持通過)。完成標準是合約與輸出的 JSON 相符,並且一個以 contract_gradle_codes.rs 為範本的新合約解析測試斷言 status 的拼寫。
由索引模型根據 Issue 內容生成。
描述
[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: discussion #560 register.
Kind: bug (contract drift). Source: new finding; register C54.
Problem (main @ 9c43dfc)
CLI_CONTRACT.md documents a paid-plan refusal that no command emits, and doesn't document the one that get does emit.
-
What the contract says. The envelope's status enum lists
"paidRequired". The errorCode table rowpaid_requiredsays: actionfailed,status=paidRequired, emitted by "get/scan". -
What
getemits. Both paid paths hand-write a legacy object with a snake_case status and no events orerrorCode:- package/CVE search where nothing is accessible:
get.rs#L2894-L2905; get <uuid>on the public proxy (paid view or proxy 403):report_paid_required_uuid.
Both print
{"status":"paid_required","found":N,"downloaded":0,"applied":0,"patches":[…]}and exit 0. - package/CVE search where nothing is accessible:
-
What
scanemits. Nothing paid-specific. It drops inaccessible patches inselect_accessibleand reports them only as thepaidPatches/canAccessPaidPatchescounts.`` -
Status::PaidRequiredis never constructed. The variant is referenced only by tests below#[cfg(test)](L481). Its own doc comment already says "Nothing emits it yet (getreports this via its legacystatus: "paid_required"shape; scan never does)". So the code knows; the contract was never updated.
Proof by execution. On 9c43dfc, cargo test -p socket-patch-cli --test get paid ran twice: 4 passed both times. Those tests pin status == "paid_required" and exit 0 for both get paths: get_edge_cases_e2e.rs#L241-L287 and get_invariants.rs#L439-L490.`` A consumer that follows the contract and matches status == "paidRequired" or `errorCode == "paid_required"` never matches.
Symptoms
None filed. PR bots that implement the documented "upgrade your plan" branch silently never take it.
Impact
Small and user-visible: the documented machine contract for the paid tier is wrong in three ways (status spelling, action/errorCode, and the command list). It's another instance of C13/C33: the contract's code tables aren't checked against the code.
Proposed change
Make the contract describe what ships. No behavior change.
- Rewrite the
paid_requiredrow (L1163):getonly; legacy top-levelstatus: "paid_required"withfound/downloaded/applied/patches[], exit 0, noevents/errorCode. Keep the existingget <uuid>proxy sentence, which is accurate. - State that
scanreports paid patches only throughpaidPatchesandcanAccessPaidPatches. - In the status enum (L1092), mark
paidRequiredas reserved, or remove it. DeletingStatus::PaidRequiredand its two test references is optional and belongs with this change if it is removed. - Route the two hand-written
getJSON blocks through one helper so the shape is written once.
Moving get onto the unified envelope (where paidRequired would become real) is the owner decision in #704 and is out of scope here.
Size and scope
CLI_CONTRACT.md (two lines), get.rs (one shared ~20-line emitter replacing two blocks), and optionally json_envelope.rs (−6 lines). Under 60 changed lines.
Acceptance criteria
- The contract's
paid_requiredrow and status enum match the emitted JSON. -
get's two paid JSON blocks share one emitter. - The 4
--test get paidtests stay green. - Add a test that reads the contract's
paid_requiredrow and asserts thestatusspellinggetemits, in the style ofcontract_gradle_codes.rs.
Dependencies
- Independent of #704; if #704 later moves
getonto the envelope, that PR updates this row again. - Feeds #948 (checked contract reference) and #930 (typed error codes).
- 主要語言
- Rust
- 星號
- 8
- 分支
- 0
- 平均合併
- 1 天 1 小時
- 30 天內合併 PR
- 257
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 沒有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
SocketDev/socket-patch 的其他 Issue
-
agent:triaged bug bughunt pm:npm priority:p1
難度 2/5 1-3 小時 新手友好度 85/100
SocketDev/socket-patch#1127 · 1 則留言 ·
維護者通常 1 天內回覆
-
agent:triaged bug bughunt pm:bundler priority:p1
難度 2/5 1-3 小時 新手友好度 75/100
SocketDev/socket-patch#1125 · 1 則留言 ·
維護者通常 1 天內回覆
-
agent:triaged bug bughunt pm:pipenv priority:p1
難度 2/5 1 小時以內 新手友好度 85/100
SocketDev/socket-patch#1122 · 1 則留言 ·
維護者通常 1 天內回覆
-
agent:triaged bug bughunt pm:npm priority:p1
難度 2/5 1-3 小時 新手友好度 75/100
SocketDev/socket-patch#1072 · 1 則留言 ·
維護者通常 1 天內回覆
-
agent:triaged arch-audit bug priority:p3
難度 2/5 1-3 小時 新手友好度 85/100
SocketDev/socket-patch#1062 · 1 則留言 ·
維護者通常 1 天內回覆
查看 SocketDev/socket-patch 的全部 Issue
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 70/100
維護者通常 1 天內回覆
-
難度 1/5 1 小時以內 新手友好度 75/100
element-hq/lk-jwt-service#248 ·
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 78/100
pact-foundation/pact-cli#154 ·
維護者通常 3 天內回覆
-
難度 2/5 1-3 小時 新手友好度 72/100
antithesishq/bombadil#361 ·
維護者通常 1 天內回覆
-
test(executor_l0): assert execute() TaskOutcome, not only bus events / 断言 execute() 返回的 TaskOutcome未關閉type:debt
難度 2/5 1-3 小時 新手友好度 62/100
skaiy/wild_agentos#425 ·
維護者通常 1 天內回覆