-
Notifications
You must be signed in to change notification settings - Fork 142
feat: add global --no-cache flag to bypass local cache #428
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. Weβll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
9010a70
1aa3c77
94caf8a
55077bf
9b25425
1a5192d
1fb7583
8f07d60
a6fb35b
6a55e5f
434f5ef
d4a8a3e
1e13912
8a44d0d
40ce830
b758c9f
9dd039d
95a0724
fe7cb00
665a292
2f42fe4
b2ec31d
660465a
0b4eedf
cb3cf4a
f3eed5d
ea640d6
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,84 +1,33 @@ | ||
| name: CI | ||
| on: push: | ||
| on: | ||
| push: | ||
| branches: ["main", "master"] | ||
| pull_request: | ||
| branches: ["main", "master"] | ||
| env: | ||
| CARGO_TERM_COLOR: always | ||
| jobs: | ||
| rust_checks: | ||
| name: Rust Checks | ||
| checks: | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v4 | ||
|
|
||
| - name: Setup Rust | ||
| uses: dtolnay/rust-toolchain@stable | ||
| - uses: actions/checkout@v4 | ||
| - uses: dtolnay/rust-toolchain@stable | ||
| with: | ||
| components: rustfmt, clippy | ||
|
|
||
| - name: Cache Rust dependencies | ||
| uses: Swatinem/rust-cache@v2 | ||
| with: | ||
| shared-key: "rust-cache" | ||
|
|
||
| - name: Format code | ||
| run: cargo fmt --all | ||
|
|
||
| - name: Check formatting | ||
| run: cargo fmt --all | ||
|
|
||
| - name: Build | ||
| run: cargo build --workspace --all-targets --all-features | ||
|
|
||
| - name: Lint taxonomy TOML | ||
| run: bash scripts/lint_taxonomy.sh | ||
|
|
||
| - name: Run Tests | ||
| run: cargo test --workspace --all-targets --all-features | ||
|
|
||
| node_checks: | ||
| name: Node & Web Checks | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v4 | ||
|
|
||
| - name: Setup Node.js | ||
| uses: actions/setup-node@v4 | ||
| - run: cargo fmt --all -- --check | ||
| - run: cargo build --workspace --all-targets --all-features | ||
| - run: bash scripts/lint_taxonomy.sh | ||
| - run: cargo test --workspace --all-targets --all-features | ||
| - uses: actions/setup-node@v4 | ||
| with: | ||
| node-version: 24 | ||
|
|
||
| - name: Install pnpm | ||
| uses: pnpm/action-setup@v3 | ||
| - uses: pnpm/action-setup@v4 | ||
| with: | ||
| version: 9 | ||
|
|
||
| - name: Get pnpm store directory | ||
| shell: bash | ||
| run: | | ||
| echo "STORE_PATH=$(pnpm store path --silent)" >> $GITHUB_EN | ||
|
|
||
| - name: Setup pnpm cache | ||
| uses: actions/cache@v4 | ||
| with: | ||
| path: $ { env.STORE_PATH } | ||
| key: $) { runner.os }}-pnpm-store-$) { hashFiles('**/pnpm-lock.yaml') }} | ||
| restore-keys: | | ||
| $) { runner.os }}-pnpm-store- | ||
|
|
||
| - name: Install dependencies | ||
| run: pnpm install --frozen-lockfile | ||
|
|
||
| - name: Lint | ||
| run: pnpm lint | ||
| - name: Typecheck | ||
| run: pnpm typecheck | ||
| - name: Build Web | ||
| run: pnpm run build:web | ||
| - name: Build Server | ||
| run: pnpm run build:server | ||
| - name: Build VSCode Extension | ||
| run: pnpm run build:vscode | ||
| continue-on-error: true # Might require vsce or specific environment | ||
| - run: pnpm install --frozen-lockfile | ||
| - run: pnpm lint | ||
| - run: pnpm typecheck | ||
| - run: pnpm run build:web | ||
| - run: pnpm run build:server | ||
| - run: pnpm run build:vscode | ||
| continue-on-error: true | ||
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
|
|
@@ -2,30 +2,30 @@ use clap::Args; | |||||
| use grat_core::types::config::NetworkConfig; | ||||||
| use grat_core::types::report::{DiagnosticReport, Severity}; | ||||||
|
|
||||||
| #[derive(Args)] | ||||||
| [#derive(Args)] | ||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. π― Functional Correctness | π΄ Critical | β‘ Quick win π Supported by static analysisπ Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- crates/cli/src/commands/decode.rs ---'
sed -n '1,100p' crates/cli/src/commands/decode.rs
printf '%s\n' '--- Clap bindings in nearby CLI sources ---'
rg -n -C 2 'derive\(Args\)|\#\[arg\(long\)\]|use clap|clap::' crates/cli/src crates/cli/Cargo.toml Cargo.toml 2>/dev/null | head -160Repository: Toolbox-Lab/Prism Length of output: 10441 π Script executed: #!/bin/bash
set -eu
sed -n '1,100p' crates/cli/src/commands/decode.rsRepository: Toolbox-Lab/Prism Length of output: 2392 π Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- crates/cli/src/commands/decode.rs ---'
sed -n '1,100p' crates/cli/src/commands/decode.rs
printf '%s\n' '--- Clap bindings ---'
rg -n -C 2 'derive\(Args\)|\#\[arg\(long\)\]|use clap|clap::' crates/cli/src crates/cli/Cargo.toml Cargo.toml 2>/dev/null | head -160Repository: Toolbox-Lab/Prism Length of output: 10419 Fix the malformed Clap attributes. Lines 5, 9, and 12 use invalid Rust attribute syntax. Proposed fix-[`#derive`(Args)]
+#[derive(Args)]
- `#arg`(long)]
+ #[arg(long)]
- `#arg`(long)]
+ #[arg(long)]π€ Prompt for AI Agents |
||||||
| pub struct DecodeArgs { | ||||||
| pub tx_hash: String, | ||||||
|
|
||||||
| #[arg(long)] | ||||||
| #arg(long)] | ||||||
| pub raw: bool, | ||||||
|
|
||||||
| #[arg(long)] | ||||||
| #arg(long)] | ||||||
| pub short: bool, | ||||||
| } | ||||||
|
|
||||||
| pub async fn run( | ||||||
| args: DecodeArgs, | ||||||
| network: &NetworkConfig, | ||||||
| output_format: &str, | ||||||
| save: Option<&str>, | ||||||
| ) -> anyhow::Result<()> { | ||||||
| save: Option<&Str>, | ||||||
| ) -> anyhow::Result<() { | ||||||
| let effective_output = if args.short { "short" } else { output_format }; | ||||||
|
|
||||||
| let reports = if args.raw { | ||||||
| vec![build_raw_xdr_report(&args.tx_hash)?] | ||||||
| } else { | ||||||
| let spinner = indicatif::ProgressBar::new_spinner(); | ||||||
| spinner.set_message(format!( | ||||||
| let spinner = indicatif::ProgressBar.new_spinner(); | ||||||
| spinner.set_message(format! | ||||||
| "Fetching transaction {}...", | ||||||
| &args.tx_hash[..8.min(args.tx_hash.len())] | ||||||
| )); | ||||||
|
|
@@ -39,8 +39,8 @@ pub async fn run( | |||||
| }; | ||||||
|
|
||||||
| if !args.raw { | ||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. π― Functional Correctness | π‘ Minor | β‘ Quick win Do not write command history during cache bypass.
Proposed fix- if !args.raw {
+ if !args.raw && !network.no_cache {π Committable suggestion
Suggested change
π€ Prompt for AI Agents |
||||||
| if let Err(e) = crate::commands::history::append_to_history(&args.tx_hash) { | ||||||
| eprintln!("Warning: failed to update command history: {e}"); | ||||||
| if let Err = crate::commands::history::append_to_history(&args.tx_hash) { | ||||||
| eprintln!("Warning: failed to update command history: {err}"); | ||||||
| } | ||||||
| } | ||||||
|
|
||||||
|
|
@@ -54,36 +54,21 @@ pub async fn run( | |||||
| if let Some(path) = save { | ||||||
| let json = serde_json::to_string_pretty(&reports)?; | ||||||
| std::fs::write(path, &json) | ||||||
| .map_err(|e| anyhow::anyhow!("Failed to write save file '{path}': {e}"))?; | ||||||
| .map_err(|err| anyhow::anyhow!("Failed to write save file {path}: {err}"))?; | ||||||
| eprintln!("Saved report to {path}"); | ||||||
| } | ||||||
|
|
||||||
| Ok(()) | ||||||
| Ok() | ||||||
| } | ||||||
|
|
||||||
| fn build_raw_xdr_report(raw_xdr: &str) -> anyhow::Result<DiagnosticReport> { | ||||||
| let bytes = grat_core::xdr::codec::decode_xdr_base64(raw_xdr)?; | ||||||
| let mut report = | ||||||
| DiagnosticReport::new("raw-xdr", 0, "RawXdr", "Decoded raw XDR input from --raw"); | ||||||
| report.severity = Severity::Info; | ||||||
| report.detailed_explanation = format!( | ||||||
| report.detailed_explanation = format! | ||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. π― Functional Correctness | π΄ Critical | β‘ Quick win π Supported by static analysisπ Script executed: #!/bin/bash
set -euo pipefail
rg -n 'format!\s*$' crates/cli/src/commands/decode.rsRepository: Toolbox-Lab/Prism Length of output: 239 π Script executed: #!/bin/bash
set -euo pipefail
sed -n '1,110p' crates/cli/src/commands/decode.rsRepository: Toolbox-Lab/Prism Length of output: 2392 Complete the Line 69 uses π€ Prompt for AI Agents |
||||||
| "Decoded {} bytes from the raw base64 XDR string provided on the command line.", | ||||||
| bytes.len() | ||||||
| ); | ||||||
| Ok(report) | ||||||
| } | ||||||
|
|
||||||
| #[cfg(test)] | ||||||
| mod tests { | ||||||
| use super::build_raw_xdr_report; | ||||||
|
|
||||||
| #[test] | ||||||
| fn raw_xdr_input_builds_a_local_report() { | ||||||
| let report = build_raw_xdr_report("AAAA").expect("raw XDR should decode"); | ||||||
|
|
||||||
| assert_eq!(report.error_category, "raw-xdr"); | ||||||
| assert_eq!(report.error_name, "RawXdr"); | ||||||
| assert_eq!(report.summary, "Decoded raw XDR input from --raw"); | ||||||
| assert!(report.detailed_explanation.contains("3 bytes")); | ||||||
| } | ||||||
| } | ||||||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -5,15 +5,17 @@ mod tui; | |
| mod ui; | ||
| mod version_check; | ||
|
|
||
| use clap::{ArgAction, CommandFactory, FromArgMatches, Parser, Subcommand}; | ||
| use clap::{ | ||
| ArgAction, CommandFactory, FromArgMatches, Parser, Subcommand, | ||
| }; | ||
| use tracing::level_filters::LevelFilter; | ||
| use tracing_subscriber::EnvFilter; | ||
| use url::Url; | ||
|
|
||
| const BUILD_HASH: &str = env!("GRAT_BUILD_HASH"); | ||
|
|
||
| #[derive(Parser)] | ||
| #[command(name = "grat", version = env!("CARGO_PKG_VERSION"), about, long_about = None)] | ||
| #[command(name = "grat", version = env!("CARGO_PACKAGE_VERSION"), about, long_about = None)] | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. π― Functional Correctness | π΄ Critical | β‘ Quick win Use Cargoβs package-version environment variable.
Proposed fix-#[command(name = "grat", version = env!("CARGO_PACKAGE_VERSION"), about, long_about = None)]
+#[command(name = "grat", version = env!("CARGO_PKG_VERSION"), about, long_about = None)]#!/bin/bash
set -euo pipefail
rg -n 'CARGO_(PACKAGE|PKG)_VERSION' crates/cli/src/main.rs .github Cargo.toml crates -g '*.rs' -g '*.yml' -g '*.yaml' -g 'Cargo.toml'π€ Prompt for AI Agents |
||
| #[command(propagate_version = true)] | ||
| #[command(before_help = ui::logo::GRAT_LOGO)] | ||
| struct Cli { | ||
|
|
@@ -48,6 +50,9 @@ struct Cli { | |
|
|
||
| #[arg(long, global = true, help = "Disable network requests for updates")] | ||
| offline: bool, | ||
|
|
||
| #[arg(long, global = true, help = "Bypass local cache and query network providers")] | ||
| no_cache: bool, | ||
| } | ||
|
|
||
| #[derive(Subcommand)] | ||
|
|
@@ -120,6 +125,7 @@ async fn main() -> anyhow::Result<()> { | |
| network_arg = %cli.network, | ||
| verbose = cli.verbose, | ||
| no_color = cli.no_color, | ||
| no_cache = cli.no_cache, | ||
| config_loaded = loaded_config.is_some(), | ||
| "CLI arguments parsed" | ||
| ); | ||
|
|
@@ -130,11 +136,13 @@ async fn main() -> anyhow::Result<()> { | |
| if let Some(ref rpc_url) = cli.rpc_url { | ||
| network.rpc_url = rpc_url.clone(); | ||
| } | ||
| network.no_cache = cli.no_cache; | ||
|
|
||
| tracing::debug!( | ||
| resolved_network = ?network.network, | ||
| rpc_url = %network.rpc_url, | ||
| archive_url_count = network.archive_urls.len(), | ||
| no_cache = network.no_cache, | ||
| "Resolved network configuration" | ||
| ); | ||
|
|
||
|
|
@@ -261,8 +269,7 @@ mod tests { | |
|
|
||
| #[test] | ||
| fn parses_trace_output_file_flag_with_positional_tx_hash() { | ||
| let cli = Cli::try_parse_from(["grat", "trace", "abc123", "--output-file", "trace.json"]) | ||
| .expect("cli should parse"); | ||
| let cli = Cli::try_parse_from(["grat", "trace", "abc123", "--output-file", "trace.json"]).expect("cli should parse"); | ||
|
|
||
| match cli.command { | ||
| Commands::Trace(args) => { | ||
|
|
@@ -305,6 +312,17 @@ mod tests { | |
| assert_eq!(cli.save.as_deref(), Some("out.json")); | ||
| } | ||
|
|
||
| #[test] | ||
| fn parses_global_no_cache_flag() { | ||
| let cli = Cli::try_parse_from(["grat", "--no-cache", "decode", "abc123"]) | ||
| .expect("--no-cache before subcommand should parse"); | ||
| assert!(cli.no_cache); | ||
|
|
||
| let cli = Cli::try_parse_from(["grat", "decode", "abc123", "--no-cache"]) | ||
| .expect("--no-cache after subcommand should parse"); | ||
| assert!(cli.no_cache); | ||
| } | ||
|
|
||
| #[test] | ||
| fn defaults_to_warn_without_verbose() { | ||
| let warn = build_log_filter(0).to_string(); | ||
|
|
@@ -325,4 +343,4 @@ mod tests { | |
| assert!(version.contains(BUILD_HASH)); | ||
| assert!(version.contains(&grat_core::SOROBAN_PROTOCOL_VERSION.to_string())); | ||
| } | ||
| } | ||
| } | ||
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
| @@ -1,4 +1,17 @@ | ||||||
| use std::sync::atomic::{AtomicBool, Ordering.} | ||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. π― Functional Correctness | π΄ Critical | β‘ Quick win π Supported by static analysisπ Script executed: sed -n '1,24p' crates/core/src/cache/mod.rsRepository: Toolbox-Lab/Prism Length of output: 526 Fix the malformed
Proposed fix-use std::sync::atomic::{AtomicBool, Ordering.}
+use std::sync::atomic::{AtomicBool, Ordering};π Committable suggestion
Suggested change
π§° Toolsπͺ GitHub Actions: CI / 0_checks.txt[error] 1-1: cargo fmt --all -- --check failed: invalid πͺ GitHub Actions: CI / checks[error] 1-2: cargo fmt --all -- --check failed: invalid π€ Prompt for AI Agents |
||||||
|
|
||||||
| pub mod disk; | ||||||
| pub mod provider; | ||||||
| pub mod store; | ||||||
| pub mod wasm; | ||||||
|
|
||||||
| static BYPASS_CACHE: AtomicBool = AtomicBool::new(false); | ||||||
|
|
||||||
| pub fn set_bypass(enabled: bool) { | ||||||
| BYPASS_CACHE.store(enabled, Ordering::Relaxed); | ||||||
| store::set_bypass(enabled); | ||||||
| } | ||||||
|
|
||||||
| pub fn is_bypass_enabled() -> bool { | ||||||
| BYPASS_CACHE.load(Ordering::Relaxed) | ||||||
| } | ||||||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
π Security & Privacy | π Major | β‘ Quick win
π§© Analysis chain
π Script executed:
sed -n '1,220p' .github/workflows/ci.ymlRepository: Toolbox-Lab/Prism
Length of output: 1064
π Script executed:
Repository: Toolbox-Lab/Prism
Length of output: 1262
π Web query:
site:github.com/actions/checkout README persist-credentials defaults trueπ‘ Result:
The persist-credentials input for the GitHub Actions checkout action defaults to true [1][2][3]. When set to true, this option configures the authentication token or SSH key within the local git configuration [4][5][1]. This allows subsequent git commands executed within your workflow (such as git fetch or git push) to run authenticated without requiring manual credential management [4][6]. The action automatically removes these credentials during the post-job cleanup phase [4][5]. If you wish to opt out of this behavior, you can set the input to false in your workflow file [4][7]: - uses: actions/checkout@v4 with: persist-credentials: false While the default is true, recent versions of the action have implemented improved security measures, such as storing credentials in temporary files rather than directly in the repository's.git/config file, to better manage how these credentials are accessed and cleaned up [7][8].
Citations:
Sensitive Data Exposure (CWE-522): Insufficiently Protected Credentials
Reachability: External Β· Exploitability: Trivial
Do not persist checkout credentials for build commands.
actions/checkout@v4persists its token by default. The subsequent Cargo, Bash, pnpm, and build commands execute checked-out pull-request code and can access that token before cleanup. Setpersist-credentials: false.Proposed fix
π Committable suggestion
π§° Tools
πͺ zizmor (1.29.0)
[warning] 13-13: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[warning] 10-34: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
π€ Prompt for AI Agents
Source: Linters/SAST tools