Vendored Hatch runs a `hatch` executable planted in the scanned project
メンテナーはふだん 1 日以内に返信
評価
調査の方向性
crates/socket-patch-core/src/vendor/pypi_hatch.rs の require_environment_context_support から始め、utils/process.rs、vendor/npm_dir.rs、patch/redirect/npmrc.rs にある安全な spawn パターンと比較してください。配置された Hatch 実行可能ファイルと絶対 PATH の実行可能ファイルに対するリグレッションカバレッジを追加し、その後 cargo test -p socket-patch-core vendor::pypi_hatch と vendored Hatch のエンドツーエンドテストを実行してください。配置された実行可能ファイルが実行されず、バージョンゲートが引き続き機能すれば完了です。
索引モデルが issue の本文から書いたものです。
説明
[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: discussion #560 register.
Kind: bug. Source: §1 #4; Part 7.3. Register row C04.
Problem
require_environment_context_support spawns the bare name hatch from inside the scanned project:
vendor/pypi_hatch.rs#L114-L135
tokio::process::Command::new("hatch")
.arg("--version")
.current_dir(root)
It runs whenever a vendored Hatch project has an environment dependency on the patched package (#L103-L105).``
utils/process.rs#L23-L42 documents this exact pattern as unsafe. A relative PATH entry (. or an empty component) resolves against the child's cwd, so a bare spawn runs a hatch file committed to the repository being scanned. Every other spawn uses resolve_tool and spawns the resolved path, for example git in vendor/npm_dir.rs#L453 and node in redirect/npmrc.rs#L315. This is the only production bare-name spawn left. #442 closed the global package-manager probes but didn't touch this one.
Reproduced twice on 045d7ec with a temporary unit test in pypi_hatch.rs (not committed):
root/hatchis an executable script that touchesroot/PWNEDand printsHatch, version 1.13.0;PATHis set to.:$PATH, and no realhatchis installed;- the test calls
require_environment_context_support(root).
Output: result=Ok(()) pwned=true resolve_tool=None. The planted script ran, and its fake version also passed the >=1.2 gate. resolve_tool("hatch") returns None on the same PATH, so the shared helper would have refused it.
Symptoms
None filed. This is the same class as #421, #434 and #438 (bare spawns), which were fixed by #442 for the PM probes.
Impact
Arbitrary code execution from a scanned checkout when the user's PATH contains a relative entry, which is common in some CI images and dev shells. On macOS, posix_spawnp can run both the planted file and the real binary (see the process.rs doc). The fix is small.
Proposed change
- Resolve with
crate::utils::process::resolve_tool("hatch"). When it returnsNone, take the existing "Hatch >=1.2 on PATH" refusal. - Spawn the resolved path through
process::command_for(lifted withtokio::process::Command::from), keepingcurrent_dir(root), the null stdin,kill_on_dropand the 10 s timeout. - Nothing else changes; the bare spawn is deleted.
Size and scope
crates/socket-patch-core/src/vendor/pypi_hatch.rs only, about 10 production lines plus tests. Out of scope: the Hatch {root:uri} issues #505 and #547.
Acceptance criteria
- No
Command::new("hatch")remains in production code. - A Unix regression test: a planted executable
hatchinrootwithPATH=.:<dirs without hatch>is not executed (its marker file is absent), and the result ispypi_hatch_unsupported. - A test where a real-looking
hatchon an absolutePATHdir is used and passes the version gate. - Optional: an architecture test banning
Command::new("<literal>")in core/CLI production code outsideutils/process.rs, so the next bare spawn fails CI. -
cargo test -p socket-patch-core vendor::pypi_hatchand the vendored Hatch e2e stay green.
Dependencies
None. No open PR touches pypi_hatch.rs.
- 主要言語
- Rust
- スター
- 8
- フォーク
- 0
- 平均マージ
- 1日 1時間
- マージ済み PR(30日)
- 211
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
SocketDev/socket-patch のほかの issue
-
arch-audit refactor
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
SocketDev/socket-patch#1011 ·
メンテナーはふだん 1 日以内に返信
-
agent:triaged arch-audit bug priority:p3
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
SocketDev/socket-patch#982 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap)対応中かも @mikolalysenko が 1 日前に担当しました。 オープンagent:claimed agent:triaged bug bughunt pm:yarn-classic priority:p1
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
SocketDev/socket-patch#907 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
agent:triaged bug bughunt pm:bundler priority:p1
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
SocketDev/socket-patch#896 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
難易度 2/5 1〜3時間 初心者へのやさしさ 73/100
SocketDev/socket-patch#783 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
SocketDev/socket-patch の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
bmander/geomsolver#118 ·
メンテナーはふだん 1 日以内に返信
-
Three Windows builds are keyed on a later release than their layout対応中かも @ero-qt が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 2 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 95/100
メンテナーはふだん 1 日以内に返信
-
Markdown Preview Fonts Don't Show Selected Option対応中かも @RadhiRasho が今日担当しました。 オープンstate:needs triage
難易度 2/5 1〜3時間 初心者へのやさしさ 61/100
zed-industries/zed#65300 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 73/100
メンテナーはふだん 1 日以内に返信