Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

Vendored Hatch runs a `hatch` executable planted in the scanned project

Ouverte Adaptée aux débutants
#613 3 commentaires 0 réactions 0 personnes assignées Voir sur GitHub

Les mainteneurs répondent en général sous 1 jour

Personne n'a encore pris cette issue.

Évaluation

Difficulté
2/5
Temps estimé
Une demi-journée
Accessibilité débutants
88/100
Type d'issue
Bug
Clarté
Clairement spécifiée
Activité
Active
Stack technique
rust
Domaine
cli, security

Piste de recherche

Commencez dans crates/socket-patch-core/src/vendor/pypi_hatch.rs, au niveau de require_environment_context_support, et comparez les schémas de spawn sûrs dans utils/process.rs, vendor/npm_dir.rs et patch/redirect/npmrc.rs. Ajoutez une couverture de régression pour un exécutable Hatch placé et un exécutable avec un PATH absolu, puis exécutez cargo test -p socket-patch-core vendor::pypi_hatch et les tests end-to-end de Hatch vendored ; le travail est terminé lorsque l’exécutable placé n’est pas exécuté et que la vérification de version fonctionne toujours.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

agent:claimed agent:triaged arch-audit bug pm:hatch priority:p1

[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: discussion #560 register.

Kind: bug. Source: §1 #4; Part 7.3. Register row C04.

Problem

require_environment_context_support spawns the bare name hatch from inside the scanned project:
vendor/pypi_hatch.rs#L114-L135

tokio::process::Command::new("hatch")
    .arg("--version")
    .current_dir(root)

It runs whenever a vendored Hatch project has an environment dependency on the patched package (#L103-L105).``

utils/process.rs#L23-L42 documents this exact pattern as unsafe. A relative PATH entry (. or an empty component) resolves against the child's cwd, so a bare spawn runs a hatch file committed to the repository being scanned. Every other spawn uses resolve_tool and spawns the resolved path, for example git in vendor/npm_dir.rs#L453 and node in redirect/npmrc.rs#L315. This is the only production bare-name spawn left. #442 closed the global package-manager probes but didn't touch this one.

Reproduced twice on 045d7ec with a temporary unit test in pypi_hatch.rs (not committed):

  • root/hatch is an executable script that touches root/PWNED and prints Hatch, version 1.13.0;
  • PATH is set to .:$PATH, and no real hatch is installed;
  • the test calls require_environment_context_support(root).

Output: result=Ok(()) pwned=true resolve_tool=None. The planted script ran, and its fake version also passed the >=1.2 gate. resolve_tool("hatch") returns None on the same PATH, so the shared helper would have refused it.

Symptoms

None filed. This is the same class as #421, #434 and #438 (bare spawns), which were fixed by #442 for the PM probes.

Impact

Arbitrary code execution from a scanned checkout when the user's PATH contains a relative entry, which is common in some CI images and dev shells. On macOS, posix_spawnp can run both the planted file and the real binary (see the process.rs doc). The fix is small.

Proposed change

  • Resolve with crate::utils::process::resolve_tool("hatch"). When it returns None, take the existing "Hatch >=1.2 on PATH" refusal.
  • Spawn the resolved path through process::command_for (lifted with tokio::process::Command::from), keeping current_dir(root), the null stdin, kill_on_drop and the 10 s timeout.
  • Nothing else changes; the bare spawn is deleted.

Size and scope

crates/socket-patch-core/src/vendor/pypi_hatch.rs only, about 10 production lines plus tests. Out of scope: the Hatch {root:uri} issues #505 and #547.

Acceptance criteria

  • No Command::new("hatch") remains in production code.
  • A Unix regression test: a planted executable hatch in root with PATH=.:<dirs without hatch> is not executed (its marker file is absent), and the result is pypi_hatch_unsupported.
  • A test where a real-looking hatch on an absolute PATH dir is used and passes the version gate.
  • Optional: an architecture test banning Command::new("<literal>") in core/CLI production code outside utils/process.rs, so the next bare spawn fails CI.
  • cargo test -p socket-patch-core vendor::pypi_hatch and the vendored Hatch e2e stay green.

Dependencies

None. No open PR touches pypi_hatch.rs.

Langage dominant
Rust
Étoiles
8
Forks
0
Merge moyen
15 h 39 min
PR mergées (30 j)
104

Préparer son environnement

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de SocketDev/socket-patch

Toutes les issues de SocketDev/socket-patch

Issues similaires

Plus d'issues Rust

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.