Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Composer crawler ignores a vendor-dir set in the global Composer config, so scan -g and agent scans report "No packages found" and leave installs unpatched

Aperta
#439 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
72/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
php, rust
Ambito
cli, tooling

Direzione di ricerca

Start in crates/socket-patch-core/src/crawlers/composer_crawler.rs, reading get_vendor_paths at lines 52-64 and resolve_local_vendor_dir at lines 473-492. Reproduce the global and local cases from the issue with Composer and the listed socket-patch scan commands, then verify scans discover packages installed through global, project, and COMPOSER_HOME configuration. Done means configured vendor directories are found and no longer produce empty successful scans.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

agent:triaged bug bughunt pm:composer priority:p2

[agent] Found by the scheduled Composer bug-hunt routine (ledger #321).

Summary

Composer resolves vendor-dir through its config cascade: COMPOSER_VENDOR_DIR, then the project's composer.json config.vendor-dir, then the user-level $COMPOSER_HOME/config.json. The socket-patch Composer crawler follows only part of that cascade, so real installs go undiscovered:

  1. Global (-g): get_vendor_paths hardcodes $COMPOSER_HOME/vendor (crates/socket-patch-core/src/crawlers/composer_crawler.rs:52-64). If the global project sets config.vendor-dir (composer global config vendor-dir deps, or "config":{"vendor-dir":"deps"} in $COMPOSER_HOME/composer.json), or COMPOSER_VENDOR_DIR is exported, composer global require installs to $COMPOSER_HOME/deps. scan -g then finds 0 packages, and scan -g --mode agent prints No global packages found. with exit 0.
  2. Local (agent mode): resolve_local_vendor_dir (composer_crawler.rs:473-492) reads COMPOSER_VENDOR_DIR and the project composer.json, but not the user-level $COMPOSER_HOME/config.json. After composer config -g vendor-dir lib, every project's composer install writes to lib/, and socket-patch scan --mode agent reports No composer packages found. (exit 0) while the package stays unpatched.

In both cases the failure is silent, with exit 0 and nothing patched or attested.

Repro (Linux; Composer 2.8.12, mock patch API, local path-repo package acme/[email protected])

# 1. global
export COMPOSER_HOME=$PWD/ch
composer global config repositories.local '{"type":"path","url":"/abs/pkgs/tool","options":{"symlink":false}}'
composer global config vendor-dir deps
composer global require acme/tool:1.0.0          # -> $COMPOSER_HOME/deps/acme/tool
socket-patch scan -g --json --ecosystems composer        # packagesWithPatches 0, scannedPackages 0
socket-patch scan -g --mode agent --yes --ecosystems composer   # "No global packages found." exit 0
socket-patch scan --global-prefix "$COMPOSER_HOME/deps" --json --ecosystems composer   # finds 1 (workaround)

# 2. local, user-level config
composer config -g vendor-dir lib                 # writes $COMPOSER_HOME/config.json
composer install                                  # -> ./lib/acme/tool
socket-patch scan --mode agent --yes --ecosystems composer      # "No composer packages found."

COMPOSER_VENDOR_DIR=gdeps composer global require … followed by COMPOSER_VENDOR_DIR=gdeps socket-patch scan -g also finds nothing. Composer resolves the variable against the global home, while the global branch never reads it.

Expected vs actual

  • Expected: CLI_CONTRACT.md --global: "Operate on globally-installed packages". The crawler's local-mode doc promises COMPOSER_VENDOR_DIR / config.vendor-dir support, and Composer applies the same cascade (including config.json) to the global project and to every local one. The maintainer requirement for -g is that none may be missing.
  • Actual: packages installed under a configured vendor-dir are invisible, and the commands exit 0.

OS × version

OS Composer global vendor-dir → scan -g / apply -g user config.json vendor-dir → local agent scan
Linux (local) 1.10.28, 2.2.30, 2.8.12, 2.10.3 (PHP 8.3) fail (each run twice) fail (2.8.12, twice)
ubuntu-latest 1.10.28, 2.2.30, 2.10.3 fail untested
macos-latest 1.10.28, 2.2.30, 2.10.3 fail untested
windows-latest 1.10.28, 2.2.30, 2.10.3 fail untested

The default vendor/ layout passes everywhere except Windows, where default-home discovery is broken separately (#438).

Probe runs: https://github.com/SocketDev/socket-patch/actions/runs/36823671080 and https://github.com/SocketDev/socket-patch/actions/runs/36827949605

First bad version

Not a regression. It reproduces identically with the v4.0.0 release binary (both cases: 0 scanned).

Suspect code

  • crates/socket-patch-core/src/crawlers/composer_crawler.rs:52-64 (global: composer_home.join("vendor"))
  • crates/socket-patch-core/src/crawlers/composer_crawler.rs:473-492 (local: no $COMPOSER_HOME/config.json layer)
Lingua principale
Rust
Stelle
8
Fork
0
Merge medio
1g 1h
PR unite (30g)
211

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di SocketDev/socket-patch

Tutte le issue di SocketDev/socket-patch

Issue simili

Altre issue su Rust

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.