Skip to main content

ralph/commands/
scan.rs

1//! Task scanning command that inspects repo state and updates the queue.
2//!
3//! Responsibilities:
4//! - Validate queue state before/after scanning and persist updated tasks.
5//! - Render scan prompts with repo context and dispatch runner execution.
6//! - Enforce clean-repo and queue-lock safety around scan operations.
7//!
8//! Not handled here:
9//! - CLI parsing or interactive UI wiring.
10//! - Runner process implementation details or output parsing.
11//! - Queue schema definitions or config persistence.
12//!
13//! Invariants/assumptions:
14//! - Queue/done files are the source of truth for task ordering and status.
15//! - Runner execution requires stream-json output for parsing.
16//! - Permission/approval defaults come from config unless overridden at CLI.
17
18use crate::cli::scan::ScanMode;
19use crate::commands::run::PhaseType;
20use crate::contracts::{
21    ClaudePermissionMode, GitRevertMode, Model, ProjectType, ReasoningEffort, Runner,
22    RunnerCliOptionsPatch,
23};
24use crate::{config, fsutil, git, prompts, queue, runner, runutil, timeutil};
25use std::sync::atomic::{AtomicBool, Ordering};
26
27/// Global flag indicating if debug mode is enabled.
28/// This is set by the CLI when `--debug` flag is used.
29static DEBUG_MODE: AtomicBool = AtomicBool::new(false);
30
31/// Set the global debug mode flag.
32pub fn set_debug_mode(enabled: bool) {
33    DEBUG_MODE.store(enabled, Ordering::SeqCst);
34}
35
36/// Check if debug mode is enabled.
37fn is_debug_mode() -> bool {
38    DEBUG_MODE.load(Ordering::SeqCst)
39}
40use anyhow::{Context, Result};
41
42pub struct ScanOptions {
43    pub focus: String,
44    pub mode: ScanMode,
45    pub runner_override: Option<Runner>,
46    pub model_override: Option<Model>,
47    pub reasoning_effort_override: Option<ReasoningEffort>,
48    pub runner_cli_overrides: RunnerCliOptionsPatch,
49    pub force: bool,
50    pub repoprompt_tool_injection: bool,
51    pub git_revert_mode: GitRevertMode,
52    /// How to handle queue locking (acquire vs already-held by caller).
53    pub lock_mode: ScanLockMode,
54    /// Optional output handler for streaming scan output.
55    pub output_handler: Option<runner::OutputHandler>,
56    /// Optional revert prompt handler for interactive UIs.
57    pub revert_prompt: Option<runutil::RevertPromptHandler>,
58}
59
60#[derive(Debug, Clone, Copy, PartialEq, Eq)]
61pub enum ScanLockMode {
62    Acquire,
63    Held,
64}
65
66#[derive(Debug, Clone)]
67struct ScanRunnerSettings {
68    runner: Runner,
69    model: Model,
70    reasoning_effort: Option<ReasoningEffort>,
71    runner_cli: runner::ResolvedRunnerCliOptions,
72    permission_mode: Option<ClaudePermissionMode>,
73}
74
75fn resolve_scan_runner_settings(
76    resolved: &config::Resolved,
77    opts: &ScanOptions,
78) -> Result<ScanRunnerSettings> {
79    let settings = runner::resolve_agent_settings(
80        opts.runner_override.clone(),
81        opts.model_override.clone(),
82        opts.reasoning_effort_override,
83        &opts.runner_cli_overrides,
84        None,
85        &resolved.config.agent,
86    )?;
87
88    Ok(ScanRunnerSettings {
89        runner: settings.runner,
90        model: settings.model,
91        reasoning_effort: settings.reasoning_effort,
92        runner_cli: settings.runner_cli,
93        permission_mode: resolved.config.agent.claude_permission_mode,
94    })
95}
96
97pub fn run_scan(resolved: &config::Resolved, opts: ScanOptions) -> Result<()> {
98    // Prevents catastrophic data loss if scan fails and reverts uncommitted changes.
99    git::require_clean_repo_ignoring_paths(
100        &resolved.repo_root,
101        opts.force,
102        git::RALPH_RUN_CLEAN_ALLOWED_PATHS,
103    )?;
104
105    let _queue_lock = match opts.lock_mode {
106        ScanLockMode::Acquire => Some(queue::acquire_queue_lock(
107            &resolved.repo_root,
108            "scan",
109            opts.force,
110        )?),
111        ScanLockMode::Held => None,
112    };
113
114    let before = queue::load_queue(&resolved.queue_path)
115        .with_context(|| format!("read queue {}", resolved.queue_path.display()))?;
116    let done = queue::load_queue_or_default(&resolved.done_path)
117        .with_context(|| format!("read done {}", resolved.done_path.display()))?;
118    let done_ref = if done.tasks.is_empty() && !resolved.done_path.exists() {
119        None
120    } else {
121        Some(&done)
122    };
123    let max_depth = resolved.config.queue.max_dependency_depth.unwrap_or(10);
124    match queue::validate_queue_set(
125        &before,
126        done_ref,
127        &resolved.id_prefix,
128        resolved.id_width,
129        max_depth,
130    )
131    .context("validate queue set before scan")
132    {
133        Ok(warnings) => {
134            queue::log_warnings(&warnings);
135        }
136        Err(err) => {
137            let preface = format!("Scan validation failed before run.\n{err:#}");
138            let outcome = runutil::apply_git_revert_mode_with_context(
139                &resolved.repo_root,
140                opts.git_revert_mode,
141                runutil::RevertPromptContext::new("Scan validation failure (pre-run)", false)
142                    .with_preface(preface),
143                opts.revert_prompt.as_ref(),
144            )?;
145            return Err(err).context(runutil::format_revert_failure_message(
146                "Scan validation failed before run.",
147                outcome,
148            ));
149        }
150    }
151    let before_ids = queue::task_id_set(&before);
152
153    let scan_version = resolved
154        .config
155        .agent
156        .scan_prompt_version
157        .unwrap_or_default();
158    let template = prompts::load_scan_prompt(&resolved.repo_root, scan_version, opts.mode)?;
159    let project_type = resolved.config.project_type.unwrap_or(ProjectType::Code);
160    let mut prompt = prompts::render_scan_prompt(
161        &template,
162        &opts.focus,
163        opts.mode,
164        scan_version,
165        project_type,
166        &resolved.config,
167    )?;
168
169    prompt = prompts::wrap_with_repoprompt_requirement(&prompt, opts.repoprompt_tool_injection);
170    prompt = prompts::wrap_with_instruction_files(&resolved.repo_root, &prompt, &resolved.config)?;
171
172    let settings = resolve_scan_runner_settings(resolved, &opts)?;
173    let bins = runner::resolve_binaries(&resolved.config.agent);
174    // Two-pass mode disabled for scan (only generates findings, should not implement)
175
176    let retry_policy = runutil::RunnerRetryPolicy::from_config(&resolved.config.agent.runner_retry)
177        .unwrap_or_default();
178
179    let output = runutil::run_prompt_with_handling(
180        runutil::RunnerInvocation {
181            settings: runutil::RunnerSettings {
182                repo_root: &resolved.repo_root,
183                runner_kind: settings.runner,
184                bins,
185                model: settings.model,
186                reasoning_effort: settings.reasoning_effort,
187                runner_cli: settings.runner_cli,
188                timeout: None,
189                permission_mode: settings.permission_mode,
190                output_handler: opts.output_handler.clone(),
191                output_stream: if opts.output_handler.is_some() {
192                    runner::OutputStream::HandlerOnly
193                } else {
194                    runner::OutputStream::Terminal
195                },
196            },
197            execution: runutil::RunnerExecutionContext {
198                prompt: &prompt,
199                phase_type: PhaseType::SinglePhase,
200                session_id: None,
201            },
202            failure: runutil::RunnerFailureHandling {
203                revert_on_error: true,
204                git_revert_mode: opts.git_revert_mode,
205                revert_prompt: opts.revert_prompt.clone(),
206            },
207            retry: runutil::RunnerRetryState {
208                policy: retry_policy,
209            },
210        },
211        runutil::RunnerErrorMessages {
212            log_label: "scan runner",
213            interrupted_msg: "Scan runner interrupted: the agent run was canceled.",
214            timeout_msg: "Scan runner timed out: the agent run exceeded the time limit. Changes in the working tree were NOT reverted; review the repo state manually.",
215            terminated_msg: "Scan runner terminated: the agent was stopped by a signal. Rerunning the command is recommended.",
216            non_zero_msg: |code| {
217                format!(
218                    "Scan runner failed: the agent exited with a non-zero code ({code}). Rerunning the command is recommended after investigating the cause."
219                )
220            },
221            other_msg: |err| {
222                format!(
223                    "Scan runner failed: the agent could not be started or encountered an error. Error: {:#}",
224                    err
225                )
226            },
227        },
228    )?;
229
230    let mut after = match queue::load_queue(&resolved.queue_path)
231        .with_context(|| format!("read queue {}", resolved.queue_path.display()))
232    {
233        Ok(queue) => queue,
234        Err(err) => {
235            let mut safeguard_msg = String::new();
236            match fsutil::safeguard_text_dump_redacted("scan_error", &output.stdout) {
237                Ok(path) => {
238                    let dump_type = if is_debug_mode() { "raw" } else { "redacted" };
239                    safeguard_msg = format!("\n({dump_type} stdout saved to {})", path.display());
240                }
241                Err(e) => {
242                    log::warn!("failed to save safeguard dump: {}", e);
243                }
244            }
245            let context = format!(
246                "{}{}",
247                "Scan failed to reload queue after runner output.", safeguard_msg
248            );
249            let preface = format!("{context}\n{err:#}");
250            let outcome = runutil::apply_git_revert_mode_with_context(
251                &resolved.repo_root,
252                opts.git_revert_mode,
253                runutil::RevertPromptContext::new("Scan queue read failure", false)
254                    .with_preface(preface),
255                opts.revert_prompt.as_ref(),
256            )?;
257            return Err(err).context(runutil::format_revert_failure_message(&context, outcome));
258        }
259    };
260
261    let done_after = queue::load_queue_or_default(&resolved.done_path)
262        .with_context(|| format!("read done {}", resolved.done_path.display()))?;
263    let done_after_ref = if done_after.tasks.is_empty() && !resolved.done_path.exists() {
264        None
265    } else {
266        Some(&done_after)
267    };
268    match queue::validate_queue_set(
269        &after,
270        done_after_ref,
271        &resolved.id_prefix,
272        resolved.id_width,
273        max_depth,
274    )
275    .context("validate queue set after scan")
276    {
277        Ok(warnings) => {
278            queue::log_warnings(&warnings);
279        }
280        Err(err) => {
281            let mut safeguard_msg = String::new();
282            match fsutil::safeguard_text_dump_redacted("scan_validation_error", &output.stdout) {
283                Ok(path) => {
284                    let dump_type = if is_debug_mode() { "raw" } else { "redacted" };
285                    safeguard_msg = format!("\n({dump_type} stdout saved to {})", path.display());
286                }
287                Err(e) => {
288                    log::warn!("failed to save safeguard dump: {}", e);
289                }
290            }
291            let context = format!("{}{}", "Scan validation failed after run.", safeguard_msg);
292            let preface = format!("{context}\n{err:#}");
293            let outcome = runutil::apply_git_revert_mode_with_context(
294                &resolved.repo_root,
295                opts.git_revert_mode,
296                runutil::RevertPromptContext::new("Scan validation failure (post-run)", false)
297                    .with_preface(preface),
298                opts.revert_prompt.as_ref(),
299            )?;
300            return Err(err).context(runutil::format_revert_failure_message(&context, outcome));
301        }
302    }
303
304    let added = queue::added_tasks(&before_ids, &after);
305    if !added.is_empty() {
306        let added_ids: Vec<String> = added.iter().map(|(id, _)| id.clone()).collect();
307        let now = timeutil::now_utc_rfc3339_or_fallback();
308        let default_request = format!("scan: {}", opts.focus);
309        queue::backfill_missing_fields(&mut after, &added_ids, &default_request, &now);
310        queue::save_queue(&resolved.queue_path, &after)
311            .context("save queue with backfilled fields")?;
312    }
313    if added.is_empty() {
314        log::info!("Scan completed. No new tasks detected.");
315    } else {
316        log::info!("Scan added {} task(s):", added.len());
317        for (id, title) in added.iter().take(15) {
318            log::info!("- {}: {}", id, title);
319        }
320        if added.len() > 15 {
321            log::info!("...and {} more.", added.len() - 15);
322        }
323    }
324    Ok(())
325}
326
327#[cfg(test)]
328mod tests;