Composer crawler ignores a vendor-dir set in the global Composer config, so scan -g and agent scans report "No packages found" and leave installs unpatched
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 72/100
調査の方向性
Start in crates/socket-patch-core/src/crawlers/composer_crawler.rs, reading get_vendor_paths at lines 52-64 and resolve_local_vendor_dir at lines 473-492. Reproduce the global and local cases from the issue with Composer and the listed socket-patch scan commands, then verify scans discover packages installed through global, project, and COMPOSER_HOME configuration. Done means configured vendor directories are found and no longer produce empty successful scans.
索引モデルが issue の本文から書いたものです。
説明
[agent] Found by the scheduled Composer bug-hunt routine (ledger #321).
Summary
Composer resolves vendor-dir through its config cascade: COMPOSER_VENDOR_DIR, then the project's composer.json config.vendor-dir, then the user-level $COMPOSER_HOME/config.json. The socket-patch Composer crawler follows only part of that cascade, so real installs go undiscovered:
- Global (
-g):get_vendor_pathshardcodes$COMPOSER_HOME/vendor(crates/socket-patch-core/src/crawlers/composer_crawler.rs:52-64). If the global project setsconfig.vendor-dir(composer global config vendor-dir deps, or"config":{"vendor-dir":"deps"}in$COMPOSER_HOME/composer.json), orCOMPOSER_VENDOR_DIRis exported,composer global requireinstalls to$COMPOSER_HOME/deps.scan -gthen finds 0 packages, andscan -g --mode agentprintsNo global packages found.with exit 0. - Local (agent mode):
resolve_local_vendor_dir(composer_crawler.rs:473-492) readsCOMPOSER_VENDOR_DIRand the projectcomposer.json, but not the user-level$COMPOSER_HOME/config.json. Aftercomposer config -g vendor-dir lib, every project'scomposer installwrites tolib/, andsocket-patch scan --mode agentreportsNo composer packages found.(exit 0) while the package stays unpatched.
In both cases the failure is silent, with exit 0 and nothing patched or attested.
Repro (Linux; Composer 2.8.12, mock patch API, local path-repo package acme/[email protected])
# 1. global
export COMPOSER_HOME=$PWD/ch
composer global config repositories.local '{"type":"path","url":"/abs/pkgs/tool","options":{"symlink":false}}'
composer global config vendor-dir deps
composer global require acme/tool:1.0.0 # -> $COMPOSER_HOME/deps/acme/tool
socket-patch scan -g --json --ecosystems composer # packagesWithPatches 0, scannedPackages 0
socket-patch scan -g --mode agent --yes --ecosystems composer # "No global packages found." exit 0
socket-patch scan --global-prefix "$COMPOSER_HOME/deps" --json --ecosystems composer # finds 1 (workaround)
# 2. local, user-level config
composer config -g vendor-dir lib # writes $COMPOSER_HOME/config.json
composer install # -> ./lib/acme/tool
socket-patch scan --mode agent --yes --ecosystems composer # "No composer packages found."
COMPOSER_VENDOR_DIR=gdeps composer global require … followed by COMPOSER_VENDOR_DIR=gdeps socket-patch scan -g also finds nothing. Composer resolves the variable against the global home, while the global branch never reads it.
Expected vs actual
- Expected: CLI_CONTRACT.md
--global: "Operate on globally-installed packages". The crawler's local-mode doc promisesCOMPOSER_VENDOR_DIR/config.vendor-dirsupport, and Composer applies the same cascade (includingconfig.json) to the global project and to every local one. The maintainer requirement for-gis that none may be missing. - Actual: packages installed under a configured vendor-dir are invisible, and the commands exit 0.
OS × version
| OS | Composer | global vendor-dir → scan -g / apply -g |
user config.json vendor-dir → local agent scan |
|---|---|---|---|
| Linux (local) | 1.10.28, 2.2.30, 2.8.12, 2.10.3 (PHP 8.3) | fail (each run twice) | fail (2.8.12, twice) |
| ubuntu-latest | 1.10.28, 2.2.30, 2.10.3 | fail | untested |
| macos-latest | 1.10.28, 2.2.30, 2.10.3 | fail | untested |
| windows-latest | 1.10.28, 2.2.30, 2.10.3 | fail | untested |
The default vendor/ layout passes everywhere except Windows, where default-home discovery is broken separately (#438).
Probe runs: https://github.com/SocketDev/socket-patch/actions/runs/36823671080 and https://github.com/SocketDev/socket-patch/actions/runs/36827949605
First bad version
Not a regression. It reproduces identically with the v4.0.0 release binary (both cases: 0 scanned).
Suspect code
crates/socket-patch-core/src/crawlers/composer_crawler.rs:52-64(global:composer_home.join("vendor"))crates/socket-patch-core/src/crawlers/composer_crawler.rs:473-492(local: no$COMPOSER_HOME/config.jsonlayer)
- 主要言語
- Rust
- スター
- 8
- フォーク
- 0
- 平均マージ
- 1日 1時間
- マージ済み PR(30日)
- 211
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
SocketDev/socket-patch のほかの issue
-
arch-audit refactor
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
SocketDev/socket-patch#1011 ·
メンテナーはふだん 1 日以内に返信
-
agent:triaged arch-audit bug priority:p3
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
SocketDev/socket-patch#982 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap)対応中かも @mikolalysenko が 1 日前に担当しました。 オープンagent:claimed agent:triaged bug bughunt pm:yarn-classic priority:p1
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
SocketDev/socket-patch#907 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
agent:triaged bug bughunt pm:bundler priority:p1
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
SocketDev/socket-patch#896 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
難易度 2/5 1〜3時間 初心者へのやさしさ 73/100
SocketDev/socket-patch#783 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
SocketDev/socket-patch の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
bmander/geomsolver#118 ·
メンテナーはふだん 1 日以内に返信
-
Three Windows builds are keyed on a later release than their layout対応中かも @ero-qt が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 2 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 95/100
メンテナーはふだん 1 日以内に返信
-
Markdown Preview Fonts Don't Show Selected Option対応中かも @RadhiRasho が今日担当しました。 オープンstate:needs triage
難易度 2/5 1〜3時間 初心者へのやさしさ 61/100
zed-industries/zed#65300 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 73/100
メンテナーはふだん 1 日以内に返信