Fix report-only scan -g hint dropping -g (#464) - #777
Mikola Lysenko (mikolalysenko) wants to merge 3 commits into
Conversation
Assisted-by: Claude Code:claude-opus-5-5
A report-only `scan -g` (or `--global-prefix <dir>`) ends with a hint for applying what it found. The hint dropped the global flag, so running it as printed scanned the cwd project instead, exited 0, and left the global install unpatched. The hint now repeats the run's scope: `-g`, or `--global-prefix <dir>` shell-quoted when the path needs it. A project `--prune` scan keeps the old hint. Covered by unit tests on the hint and an integration test of a real report-only global-prefix scan. Fixes #464 Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
|
[agent] Ready for review at
Generated by Claude Code |
Main reflowed the old one-line report_only_hint() test with rustfmt; this branch replaced that test with ones for the scoped hint (report_only_hint(&GlobalArgs)). Keep the branch's tests, which cover the same header line plus the #464 global-scope cases. Co-Authored-By: Claude <noreply@anthropic.com>
|
bugbot run Generated by Claude Code |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
Bugbot Autofix is ON. A cloud agent has been kicked off to fix the reported issue.
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 6a31b6b. Configure here.
| if !word.is_empty() && word.chars().all(plain) { | ||
| word.to_string() | ||
| } else if cfg!(windows) { | ||
| format!("\"{word}\"") |
There was a problem hiding this comment.
Windows hint quoting breaks trailing slash
Low Severity
On Windows, shell_word wraps the prefix in double quotes without escaping a trailing backslash. cmd treats that backslash as escaping the closing quote, so a --global-prefix path that has a space and ends with \ produces a hint that does not paste as one argument.
Reviewed by Cursor Bugbot for commit 6a31b6b. Configure here.
|
[agent] Generated by Claude Code |


LLM Description written by Claude Code:claude-opus-5-5
Fixes #464
Summary
scan -gandscan --global-prefix <dir>with no--modeonly report. They end with a hint showing how to apply what they found. The hint used to drop the global scope:If you ran it as printed, it scanned the cwd project instead of the global install, exited 0, and left the global copy unpatched. The hint now repeats the run's scope:
With a prefix, it prints
--global-prefix '<dir>'instead, shell-quoted only when the path needs it (POSIX single quotes; double quotes on Windows). A project--prunereport-only scan keeps the old hint.Root cause
render::report_only_hint()took no arguments, so it never saw the run'sGlobalArgs. It now takes&GlobalArgsand builds both commands fromglobal/global_prefix.SOCKET_GLOBAL/SOCKET_GLOBAL_PREFIXset the same fields, so they're covered too. CLI_CONTRACT.md documents the scoped hint.The npm, PyPI and gem wrappers only dispatch to the binary, so they need no change.
Tests (red → green)
-g,--global-prefix, quoting)scan::render::tests::report_only_hint_keeps_global_scope(unit)covgap_commands_scan_mod::scan_global_report_only_hint_keeps_the_global_scopesocket-patch scan --mode agent [PATHS]report_only_hint_names_agent_mode,scan_prune_without_a_mode_is_report_onlyCommands run locally on
b311073:cargo clippy --workspace --all-features -- -D warnings: clean.cargo test -p socket-patch-cli --all-features --lib: 835 passed.cargo test -p socket-patch-cli --all-features --test covgap_commands_scan_mod --test cli_parse_scan --test e2e_socket_yml_policy: 45 + 52 + 20 passed.cargo fmt --check: my hunks are clean.mainalready has about 500 rustfmt diffs under the pinned 1.93.1 toolchain, and CI doesn't run fmt, so I didn't reformat unrelated code.cargo test --workspacefilled the sandbox disk while linking test binaries, so the full suite is left to CI.🤖 Generated with Claude Code
Note
Low Risk
Human-output and documentation only; no patch/apply or lockfile logic changes.
Overview
Fixes #464: report-only
scan(--pruneor global with no--mode) now prints follow-up commands that preserve global scope, so copying the hint no longer accidentally applies patches to the cwd project instead of the global install.render::report_only_hinttakes&GlobalArgsand appends-gor--global-prefix <dir>to the suggestedscan --mode agentandgetlines; paths are shell-quoted via a newshell_wordhelper when needed (POSIX single quotes, double quotes on Windows). Project-scoped report-only hints are unchanged. CLI_CONTRACT.md documents the behavior. Unit and integration tests cover-g,--global-prefix, and quoting.Reviewed by Cursor Bugbot for commit 6a31b6b. Configure here.
Generated by Claude Code