Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Python crawler ignores `.egg-info` installs, so packages pip ≤ 23.0 installed from sdists are never patched, never get a stale-install warning, and are invisible to `scan -g`

Đã đóng
#447 3 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
55/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
python, rust
Lĩnh vực
cli, devtools

Hướng nghiên cứu

Start at crates/socket-patch-core/src/crawlers/python_crawler.rs:1576-1584 and trace how discovery feeds find_each_by_purl and the hosted probe in crates/socket-patch-cli/src/commands/scan/hosted/python.rs:76. Read crates/socket-patch-cli/tests/in_process_python_envs.rs:455 as the regression target. Done means directory and bare-file egg-info installs are covered by agent, hosted stale-install, and -g behavior, with the regression coverage passing.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

agent:claimed agent:triaged bug bughunt pm:pip priority:p1

[agent] Found by the scheduled pip / requirements.txt bug-hunt routine (ledger #309).

Summary

The Python crawler only recognises *.dist-info directories. When pip before 23.1 installs a package from an sdist and the wheel package isn't installed, it uses the legacy setup.py install path. That path writes <name>-<version>-pyX.Y.egg-info instead of .dist-info. This is the default state of a fresh python -m venv on CPython ≤ 3.11, which ships setuptools but no wheel, so it affects every pip release from 20 through 23.0.x (Ubuntu 22.04's pip 22.0.2 and Debian 12's pip 23.0.1 included).

socket-patch never sees these packages, which are really installed and importable:

  • Agent mode (scan --mode agent, get) reports the package as [skip] … (not installed; run your package manager's install first …) with errorCode: package_not_installed, then exits 0 / success. The installed file stays unpatched.
  • Hosted mode (the default scan) rewrites requirements.txt to the hosted wheel. pip then keeps the same-version egg-info install (Requirement already satisfied), so the patched bytes never land. The redirect_pypi_stale_install guard doesn't fire, because it uses the same crawler lookup (find_each_by_purl). The user gets no signal that the venv is still vulnerable.
  • Global mode (scan -g, --global-prefix) omits these packages from the report. On Debian/Ubuntu that also includes every apt-installed Python package (python3-six etc. ship six-1.16.0.egg-info). In this sandbox, scan -g sent 102 purls and left out [email protected], [email protected], oauthlib, launchpadlib and other egg-info packages.

Impact

Silent false negatives. A vulnerable, patchable package is reported as "not installed" (agent) or quietly left stale (hosted), and the command still exits 0. The hosted case is the worst: the documented safety net is the stale-install warning, and it never fires.

Repro (Linux shown; the probe covers macOS and Windows)

python3.11 -m venv .venv
.venv/bin/pip install -q 'pip==23.0.1'           # also 20.3.4, 22.3.1
.venv/bin/pip uninstall -y wheel || true          # default venv state on py<=3.11 anyway
echo 'six==1.16.0' > requirements.txt
.venv/bin/pip install --no-binary six -r requirements.txt
ls .venv/lib/python3.11/site-packages | grep six  # six-1.16.0-py3.11.egg-info, six.py

socket-patch scan --mode agent --yes --json       # apply.patches[0] = skipped / package_not_installed, exit 0
socket-patch scan --yes --json                    # hosted: redirect.warnings == [] (no redirect_pypi_stale_install)
.venv/bin/pip install -r requirements.txt         # "Requirement already satisfied" -> still unpatched
socket-patch scan -g --global-prefix .venv/lib/python3.11/site-packages --json   # six not reported

The patch data came from a local mock of the authenticated patch API (the same batch / by-package / view / package shapes as tests/docker_e2e_pypi.rs) serving a marked six.py. pip, the venvs and the installs were all real.

Expected vs actual

  • CLI_CONTRACT.md "Python stale-install guard": "after a hosted redirect, scan / get use the Python crawler to inspect every matching installed package … A readable file that differs from the patch's afterHash emits redirect_pypi_stale_install". Actual: an installed egg-info copy isn't inspected, and no warning fires.
  • docs/ecosystems.md lists PyPI agent mode as "✅ in place". Actual: pip's own legacy install layout is reported as "not installed" and isn't patched.
  • The maintainer's -g checklist (ledger #309) says scan -g must find every globally installed package that has a patch. Actual: egg-info installs are missing.

OS × version matrix (probe run 36836217323, plus local Linux runs)

OS Python pip 20.3.4 pip 22.3.1 pip 23.0.1 pip 23.1 (control, writes dist-info)
ubuntu-latest 3.8.18 / 3.11.16 fail fail fail pass
macos-latest 3.8.10 / 3.11.9 fail fail fail pass
windows-latest 3.8.10 / 3.11.9 fail fail fail pass
Linux (local) 3.10, 3.11 fail fail (21.3.1 too) fail pass (24.0 too)

"fail" means all of: agent skipped/package_not_installed with the marker absent, hosted with no redirect_pypi_stale_install and the file still unpatched after pip install -r, and -g not reporting six. Each pip 23.1 cell gives agent added with the file patched, the stale warning present, and -g reporting six.

First bad version

Not a regression. Released v4.0.0 (PyPI socket-patch==4.0.0) behaves the same way: [skip] pkg:pypi/[email protected] (not installed …). crates/socket-patch-cli/tests/in_process_python_envs.rs:455 (pypi_egg_info_layout_handled) pins the gap as the "current contract" and asks for the assertion to be flipped once egg-info support lands. No user-facing doc mentions the limitation.

Suspect code

  • crates/socket-patch-core/src/crawlers/python_crawler.rs:1576-1584: list_dist_info_packages_sync keeps only entries ending in .dist-info. It feeds find_each_by_purl (:1529), which the hosted stale-install probe uses (crates/socket-patch-cli/src/commands/scan/hosted/python.rs:76), and the crawl / apply lookups.
  • Egg-info metadata lives in <dir>.egg-info/PKG-INFO, or in a bare .egg-info file (distutils / some distro packages, e.g. PyGObject-3.48.2.egg-info). It has the same Name: / Version: headers as METADATA. Filenames can carry a -pyX.Y suffix.

Probe

Ngôn ngữ chính
Rust
Star
8
Fork
0
Merge trung bình
1 ngày 7 phút
Pull request đã merge (30 ngày)
178

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của SocketDev/socket-patch

Tất cả issue của SocketDev/socket-patch

Issue tương tự

Thêm issue về Rust

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.