Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Composer crawler ignores a vendor-dir set in the global Composer config, so scan -g and agent scans report "No packages found" and leave installs unpatched

オープン
#439 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
72/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
php, rust
領域
cli, tooling

調査の方向性

Start in crates/socket-patch-core/src/crawlers/composer_crawler.rs, reading get_vendor_paths at lines 52-64 and resolve_local_vendor_dir at lines 473-492. Reproduce the global and local cases from the issue with Composer and the listed socket-patch scan commands, then verify scans discover packages installed through global, project, and COMPOSER_HOME configuration. Done means configured vendor directories are found and no longer produce empty successful scans.

索引モデルが issue の本文から書いたものです。

説明

agent:triaged bug bughunt pm:composer priority:p2

[agent] Found by the scheduled Composer bug-hunt routine (ledger #321).

Summary

Composer resolves vendor-dir through its config cascade: COMPOSER_VENDOR_DIR, then the project's composer.json config.vendor-dir, then the user-level $COMPOSER_HOME/config.json. The socket-patch Composer crawler follows only part of that cascade, so real installs go undiscovered:

  1. Global (-g): get_vendor_paths hardcodes $COMPOSER_HOME/vendor (crates/socket-patch-core/src/crawlers/composer_crawler.rs:52-64). If the global project sets config.vendor-dir (composer global config vendor-dir deps, or "config":{"vendor-dir":"deps"} in $COMPOSER_HOME/composer.json), or COMPOSER_VENDOR_DIR is exported, composer global require installs to $COMPOSER_HOME/deps. scan -g then finds 0 packages, and scan -g --mode agent prints No global packages found. with exit 0.
  2. Local (agent mode): resolve_local_vendor_dir (composer_crawler.rs:473-492) reads COMPOSER_VENDOR_DIR and the project composer.json, but not the user-level $COMPOSER_HOME/config.json. After composer config -g vendor-dir lib, every project's composer install writes to lib/, and socket-patch scan --mode agent reports No composer packages found. (exit 0) while the package stays unpatched.

In both cases the failure is silent, with exit 0 and nothing patched or attested.

Repro (Linux; Composer 2.8.12, mock patch API, local path-repo package acme/[email protected])

# 1. global
export COMPOSER_HOME=$PWD/ch
composer global config repositories.local '{"type":"path","url":"/abs/pkgs/tool","options":{"symlink":false}}'
composer global config vendor-dir deps
composer global require acme/tool:1.0.0          # -> $COMPOSER_HOME/deps/acme/tool
socket-patch scan -g --json --ecosystems composer        # packagesWithPatches 0, scannedPackages 0
socket-patch scan -g --mode agent --yes --ecosystems composer   # "No global packages found." exit 0
socket-patch scan --global-prefix "$COMPOSER_HOME/deps" --json --ecosystems composer   # finds 1 (workaround)

# 2. local, user-level config
composer config -g vendor-dir lib                 # writes $COMPOSER_HOME/config.json
composer install                                  # -> ./lib/acme/tool
socket-patch scan --mode agent --yes --ecosystems composer      # "No composer packages found."

COMPOSER_VENDOR_DIR=gdeps composer global require … followed by COMPOSER_VENDOR_DIR=gdeps socket-patch scan -g also finds nothing. Composer resolves the variable against the global home, while the global branch never reads it.

Expected vs actual

  • Expected: CLI_CONTRACT.md --global: "Operate on globally-installed packages". The crawler's local-mode doc promises COMPOSER_VENDOR_DIR / config.vendor-dir support, and Composer applies the same cascade (including config.json) to the global project and to every local one. The maintainer requirement for -g is that none may be missing.
  • Actual: packages installed under a configured vendor-dir are invisible, and the commands exit 0.

OS × version

OS Composer global vendor-dir → scan -g / apply -g user config.json vendor-dir → local agent scan
Linux (local) 1.10.28, 2.2.30, 2.8.12, 2.10.3 (PHP 8.3) fail (each run twice) fail (2.8.12, twice)
ubuntu-latest 1.10.28, 2.2.30, 2.10.3 fail untested
macos-latest 1.10.28, 2.2.30, 2.10.3 fail untested
windows-latest 1.10.28, 2.2.30, 2.10.3 fail untested

The default vendor/ layout passes everywhere except Windows, where default-home discovery is broken separately (#438).

Probe runs: https://github.com/SocketDev/socket-patch/actions/runs/36823671080 and https://github.com/SocketDev/socket-patch/actions/runs/36827949605

First bad version

Not a regression. It reproduces identically with the v4.0.0 release binary (both cases: 0 scanned).

Suspect code

  • crates/socket-patch-core/src/crawlers/composer_crawler.rs:52-64 (global: composer_home.join("vendor"))
  • crates/socket-patch-core/src/crawlers/composer_crawler.rs:473-492 (local: no $COMPOSER_HOME/config.json layer)
主要言語
Rust
スター
8
フォーク
0
平均マージ
1日 1時間
マージ済み PR(30日)
211

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

SocketDev/socket-patch のほかの issue

SocketDev/socket-patch の issue をすべて見る

似ている issue

Rust の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。