Project-mode NuGet agent scan patches, and VEX attests, packages the project doesn't depend on (the crawler lists the whole ~/.nuget/packages)
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 68/100
調査の方向性
Start in crates/socket-patch-core/src/crawlers/nuget_crawler.rs:74-78 and inspect how obj/project.assets.json libraries and packageFolders could determine project packages. Run the provided Linux reproduction and verify project-mode discovery no longer crawls unrelated global-cache packages, patches them, or includes them in VEX output.
索引モデルが issue の本文から書いたものです。
説明
[agent] Found by the scheduled NuGet / dotnet bug-hunt routine (ledger #320).
Summary
Without -g, NuGet discovery for a .NET project lists every package in the user-wide global packages folder (~/.nuget/packages, %USERPROFILE%\.nuget\packages), not just the packages the project resolves. So, in a project that depends only on Newtonsoft.Json:
scanreports and looks up[email protected],netstandard.library, … left over from unrelated projects on the same machine.scan --mode agent --yesapplies a patch to[email protected]in the shared cache, which the project never uses, and records it in this project's.socket/manifest.json. Exit 0,1 of 1 targeted patch applied.vex --product pkg:nuget/[email protected]then emitsnot_affected/inline_mitigations_already_existwithpkg:nuget/[email protected]as a subcomponent ofApp. App doesn't contain serilog.
This is the NuGet twin of #265 (Maven: "the crawler lists all of ~/.m2").
Impact
- A false VEX: the product's attestation names components it doesn't ship. That pollutes SBOM/VEX consumers and can mask the real dependency set.
- Agent mode mutates bytes in a cache shared by every other project on the machine. The patch is recorded against this project, so another project's
rollback/repairdoesn't know about it. - Noise:
scanoutput and the patch-API batch carry the whole machine cache (hundreds of packages on a dev box or warm CI image).
Repro (Linux, dotnet SDK 8.0.131, main 2463257)
SP=/path/to/target/release/socket-patch
export SOCKET_NO_CONFIG=1 SOCKET_TELEMETRY_DISABLED=1
# another project on this machine uses Serilog
mkdir other && cd other && cat > O.csproj <<'X'
<Project Sdk="Microsoft.NET.Sdk"><PropertyGroup><TargetFramework>net8.0</TargetFramework></PropertyGroup><ItemGroup><PackageReference Include="Serilog" Version="3.1.1" /></ItemGroup></Project>
X
dotnet restore && cd ..
# our project depends only on Newtonsoft.Json
mkdir app && cd app && cat > App.csproj <<'X'
<Project Sdk="Microsoft.NET.Sdk"><PropertyGroup><TargetFramework>netstandard2.0</TargetFramework></PropertyGroup><ItemGroup><PackageReference Include="Newtonsoft.Json" Version="13.0.3" /></ItemGroup></Project>
X
dotnet restore
grep -ci serilog obj/project.assets.json # 0, not a dependency
# local stand-in for the public proxy (POST /patch/batch, GET /patch/by-package/<purl>,
# GET /patch/view/<uuid>) that serves one free patch for pkg:nuget/[email protected] (README.md + marker line)
$SP scan --mode agent --yes --proxy-url http://127.0.0.1:8766
# Found 4 packages (4 nuget) ... Patched packages: pkg:nuget/[email protected] (via blob)
# Summary: 1 of 1 targeted patch applied (exit 0)
grep -c SOCKET_MARKER ~/.nuget/packages/serilog/3.1.1/README.md # 1
$SP vex --offline --product pkg:nuget/[email protected]
# products[0] = pkg:nuget/[email protected], subcomponents = [pkg:nuget/[email protected]], status not_affected
Reproduced twice (rollback in between restores the bytes exactly). scan --json without --mode (report-only / hosted) also lists the unrelated packages.
Expected vs actual
- Expected: project-mode discovery covers the packages this project resolves. For PackageReference projects that's the
librariesinobj/project.assets.json(orpackages.lock.json); for packages.config, thepackages/folder. The VEX contract (README VEX section, CLI_CONTRACT.md) attests only what is patched in the product. The maintainers' global-mode note (ledger #320, 20261001T040000Z entry) also asks that a scan without-gnever touch the global location beyond the project. - Actual:
get_nuget_package_pathsadds the whole global packages folder as a crawl root in local mode, andcrawl_allemits every<id>/<ver>/in it.
OS × SDK matrix
| OS | SDK | unrelated cache package patched + attested |
|---|---|---|
| Linux (local) | 8.0.131 | yes (2/2 runs) |
The crawler code path is OS-independent (the same nuget_home() root is used on macOS and Windows; the probe run https://github.com/SocketDev/socket-patch/actions/runs/36820498426 shows the same ~/.nuget/packages / C:\Users\runneradmin\.nuget\packages root being crawled on all 3 OSes). I haven't separately run this agent-mode scenario on macOS or Windows.
First bad version
Not a regression: v4.0.0 (scan --apply --yes) patches [email protected] the same way.
Suspect code
crates/socket-patch-core/src/crawlers/nuget_crawler.rs:74-78 (// 2. Fall back to the global cache. pushes nuget_home() as a crawl root in local mode). A fix would crawl only the <id>/<ver> dirs named in obj/project.assets.json libraries (resolved against its packageFolders) instead of the whole folder. That would also fix the wrong-folder half of #397.
- 主要言語
- Rust
- スター
- 8
- フォーク
- 0
- 平均マージ
- 1日 7分
- マージ済み PR(30日)
- 178
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
SocketDev/socket-patch のほかの issue
-
Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap)対応中かも @mikolalysenko が今日担当しました。 オープンagent:claimed agent:triaged bug bughunt pm:yarn-classic priority:p1
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
SocketDev/socket-patch#907 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
agent:triaged bug bughunt pm:npm priority:p1
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
SocketDev/socket-patch#900 ·
メンテナーはふだん 1 日以内に返信
-
agent:triaged bug bughunt pm:bundler priority:p1
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
SocketDev/socket-patch#896 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
難易度 2/5 1〜3時間 初心者へのやさしさ 73/100
SocketDev/socket-patch#783 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
agent:triaged bug bughunt pm:pipenv priority:p1
難易度 2/5 1〜3時間 初心者へのやさしさ 83/100
SocketDev/socket-patch#744 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
SocketDev/socket-patch の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
メンテナーはふだん 1 日以内に返信
-
check: a failed re-read of the model file before binding is labelled E_THETA_LEVEL_BINDING on [parameters]対応中かも @TeunP が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 80/100
Devolutions/picky-rs#546 · コメント 1 件 ·
メンテナーはふだん 3 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
メンテナーはふだん 1 日以内に返信