Skip to content

Fix report-only scan -g hint dropping -g (#464) - #777

Open
Mikola Lysenko (mikolalysenko) wants to merge 3 commits into
mainfrom
agent/fix-report-only-hint-global-scope
Open

Mikola Lysenko (mikolalysenko) wants to merge 3 commits into
mainfrom
agent/fix-report-only-hint-global-scope

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

Fixes #464

Summary

scan -g and scan --global-prefix <dir> with no --mode only report. They end with a hint showing how to apply what they found. The hint used to drop the global scope:

To apply these patches in place, run:
  socket-patch scan --mode agent [PATHS]
  socket-patch get <package-name-or-purl-or-CVE-ID>

If you ran it as printed, it scanned the cwd project instead of the global install, exited 0, and left the global copy unpatched. The hint now repeats the run's scope:

  socket-patch scan --mode agent -g
  socket-patch get -g <package-name-or-purl-or-CVE-ID>

With a prefix, it prints --global-prefix '<dir>' instead, shell-quoted only when the path needs it (POSIX single quotes; double quotes on Windows). A project --prune report-only scan keeps the old hint.

Root cause

render::report_only_hint() took no arguments, so it never saw the run's GlobalArgs. It now takes &GlobalArgs and builds both commands from global / global_prefix. SOCKET_GLOBAL / SOCKET_GLOBAL_PREFIX set the same fields, so they're covered too. CLI_CONTRACT.md documents the scoped hint.

The npm, PyPI and gem wrappers only dispatch to the binary, so they need no change.

Tests (red → green)

Issue Test Without the fix With the fix
#464 (-g, --global-prefix, quoting) scan::render::tests::report_only_hint_keeps_global_scope (unit) does not compile (the hint takes no scope) pass
#464 (real report-only scan) covgap_commands_scan_mod::scan_global_report_only_hint_keeps_the_global_scope fails: the hint printed socket-patch scan --mode agent [PATHS] pass
project hint unchanged report_only_hint_names_agent_mode, scan_prune_without_a_mode_is_report_only pass pass

Commands run locally on b311073:

  • cargo clippy --workspace --all-features -- -D warnings: clean.
  • cargo test -p socket-patch-cli --all-features --lib: 835 passed.
  • cargo test -p socket-patch-cli --all-features --test covgap_commands_scan_mod --test cli_parse_scan --test e2e_socket_yml_policy: 45 + 52 + 20 passed.
  • cargo fmt --check: my hunks are clean. main already has about 500 rustfmt diffs under the pinned 1.93.1 toolchain, and CI doesn't run fmt, so I didn't reformat unrelated code.
  • A full cargo test --workspace filled the sandbox disk while linking test binaries, so the full suite is left to CI.

🤖 Generated with Claude Code


Note

Low Risk
Human-output and documentation only; no patch/apply or lockfile logic changes.

Overview
Fixes #464: report-only scan (--prune or global with no --mode) now prints follow-up commands that preserve global scope, so copying the hint no longer accidentally applies patches to the cwd project instead of the global install.

render::report_only_hint takes &GlobalArgs and appends -g or --global-prefix <dir> to the suggested scan --mode agent and get lines; paths are shell-quoted via a new shell_word helper when needed (POSIX single quotes, double quotes on Windows). Project-scoped report-only hints are unchanged. CLI_CONTRACT.md documents the behavior. Unit and integration tests cover -g, --global-prefix, and quoting.

Reviewed by Cursor Bugbot for commit 6a31b6b. Configure here.


Generated by Claude Code

Assisted-by: Claude Code:claude-opus-5-5
A report-only `scan -g` (or `--global-prefix <dir>`) ends with a hint
for applying what it found. The hint dropped the global flag, so
running it as printed scanned the cwd project instead, exited 0, and
left the global install unpatched.

The hint now repeats the run's scope: `-g`, or `--global-prefix <dir>`
shell-quoted when the path needs it. A project `--prune` scan keeps
the old hint. Covered by unit tests on the hint and an integration
test of a real report-only global-prefix scan.

Fixes #464

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko
Mikola Lysenko (mikolalysenko) marked this pull request as ready for review October 4, 2026 12:48
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[agent] Ready for review at b311073.


Generated by Claude Code

@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 4, 2026
@mikolalysenko Mikola Lysenko (mikolalysenko) removed the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 5, 2026
Main reflowed the old one-line report_only_hint() test with rustfmt;
this branch replaced that test with ones for the scoped hint
(report_only_hint(&GlobalArgs)). Keep the branch's tests, which cover
the same header line plus the #464 global-scope cases.

Co-Authored-By: Claude <noreply@anthropic.com>
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

bugbot run


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is ON. A cloud agent has been kicked off to fix the reported issue.

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 6a31b6b. Configure here.

if !word.is_empty() && word.chars().all(plain) {
word.to_string()
} else if cfg!(windows) {
format!("\"{word}\"")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Windows hint quoting breaks trailing slash

Low Severity

On Windows, shell_word wraps the prefix in double quotes without escaping a trailing backslash. cmd treats that backslash as escaping the closing quote, so a --global-prefix path that has a space and ends with \ produces a hint that does not paste as one argument.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 6a31b6b. Configure here.

@mikolalysenko

Mikola Lysenko (mikolalysenko) commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator Author

[agent] coverage and test-release are both red on 6a31b6b (exit 101, a test failure in each), but this PR didn't cause either. Both checks are also red on the latest main (4646693), before this branch merged main in. I don't know of a fix for them yet, so there's nothing to port in here. The job's log download is blocked from this sandbox, so I couldn't name the failing tests. This PR is in-progress under another agent run (heartbeat 12:36 UTC), so I'm not pushing. Separately, Bugbot's finding on the Windows quoting of a path with a trailing backslash is real and still needs a fix.


Generated by Claude Code

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

3 participants