Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

Project-mode NuGet agent scan patches, and VEX attests, packages the project doesn't depend on (the crawler lists the whole ~/.nuget/packages)

未關閉
#427 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

維護者通常 1 天內回覆

還沒有人認領這個 Issue。

評估

難度
4/5
預估耗時
3-5 天
新手友好度
68/100
Issue 類型
缺陷
描述清晰度
描述清楚
活躍度
活躍
技術堆疊
csharp, rust
領域
cli, devtools

研究方向

Start in crates/socket-patch-core/src/crawlers/nuget_crawler.rs:74-78 and inspect how obj/project.assets.json libraries and packageFolders could determine project packages. Run the provided Linux reproduction and verify project-mode discovery no longer crawls unrelated global-cache packages, patches them, or includes them in VEX output.

由索引模型根據 Issue 內容生成。

描述

agent:triaged bug bughunt pm:nuget priority:p3

[agent] Found by the scheduled NuGet / dotnet bug-hunt routine (ledger #320).

Summary

Without -g, NuGet discovery for a .NET project lists every package in the user-wide global packages folder (~/.nuget/packages, %USERPROFILE%\.nuget\packages), not just the packages the project resolves. So, in a project that depends only on Newtonsoft.Json:

  • scan reports and looks up [email protected], netstandard.library, … left over from unrelated projects on the same machine.
  • scan --mode agent --yes applies a patch to [email protected] in the shared cache, which the project never uses, and records it in this project's .socket/manifest.json. Exit 0, 1 of 1 targeted patch applied.
  • vex --product pkg:nuget/[email protected] then emits not_affected / inline_mitigations_already_exist with pkg:nuget/[email protected] as a subcomponent of App. App doesn't contain serilog.

This is the NuGet twin of #265 (Maven: "the crawler lists all of ~/.m2").

Impact

  • A false VEX: the product's attestation names components it doesn't ship. That pollutes SBOM/VEX consumers and can mask the real dependency set.
  • Agent mode mutates bytes in a cache shared by every other project on the machine. The patch is recorded against this project, so another project's rollback / repair doesn't know about it.
  • Noise: scan output and the patch-API batch carry the whole machine cache (hundreds of packages on a dev box or warm CI image).

Repro (Linux, dotnet SDK 8.0.131, main 2463257)

SP=/path/to/target/release/socket-patch
export SOCKET_NO_CONFIG=1 SOCKET_TELEMETRY_DISABLED=1
# another project on this machine uses Serilog
mkdir other && cd other && cat > O.csproj <<'X'
<Project Sdk="Microsoft.NET.Sdk"><PropertyGroup><TargetFramework>net8.0</TargetFramework></PropertyGroup><ItemGroup><PackageReference Include="Serilog" Version="3.1.1" /></ItemGroup></Project>
X
dotnet restore && cd ..
# our project depends only on Newtonsoft.Json
mkdir app && cd app && cat > App.csproj <<'X'
<Project Sdk="Microsoft.NET.Sdk"><PropertyGroup><TargetFramework>netstandard2.0</TargetFramework></PropertyGroup><ItemGroup><PackageReference Include="Newtonsoft.Json" Version="13.0.3" /></ItemGroup></Project>
X
dotnet restore
grep -ci serilog obj/project.assets.json          # 0, not a dependency
# local stand-in for the public proxy (POST /patch/batch, GET /patch/by-package/<purl>,
# GET /patch/view/<uuid>) that serves one free patch for pkg:nuget/[email protected] (README.md + marker line)
$SP scan --mode agent --yes --proxy-url http://127.0.0.1:8766
#   Found 4 packages (4 nuget) ... Patched packages: pkg:nuget/[email protected] (via blob)
#   Summary: 1 of 1 targeted patch applied   (exit 0)
grep -c SOCKET_MARKER ~/.nuget/packages/serilog/3.1.1/README.md   # 1
$SP vex --offline --product pkg:nuget/[email protected]
#   products[0] = pkg:nuget/[email protected], subcomponents = [pkg:nuget/[email protected]], status not_affected

Reproduced twice (rollback in between restores the bytes exactly). scan --json without --mode (report-only / hosted) also lists the unrelated packages.

Expected vs actual

  • Expected: project-mode discovery covers the packages this project resolves. For PackageReference projects that's the libraries in obj/project.assets.json (or packages.lock.json); for packages.config, the packages/ folder. The VEX contract (README VEX section, CLI_CONTRACT.md) attests only what is patched in the product. The maintainers' global-mode note (ledger #320, 20261001T040000Z entry) also asks that a scan without -g never touch the global location beyond the project.
  • Actual: get_nuget_package_paths adds the whole global packages folder as a crawl root in local mode, and crawl_all emits every <id>/<ver>/ in it.

OS × SDK matrix

OS SDK unrelated cache package patched + attested
Linux (local) 8.0.131 yes (2/2 runs)

The crawler code path is OS-independent (the same nuget_home() root is used on macOS and Windows; the probe run https://github.com/SocketDev/socket-patch/actions/runs/36820498426 shows the same ~/.nuget/packages / C:\Users\runneradmin\.nuget\packages root being crawled on all 3 OSes). I haven't separately run this agent-mode scenario on macOS or Windows.

First bad version

Not a regression: v4.0.0 (scan --apply --yes) patches [email protected] the same way.

Suspect code

crates/socket-patch-core/src/crawlers/nuget_crawler.rs:74-78 (// 2. Fall back to the global cache. pushes nuget_home() as a crawl root in local mode). A fix would crawl only the <id>/<ver> dirs named in obj/project.assets.json libraries (resolved against its packageFolders) instead of the whole folder. That would also fix the wrong-folder half of #397.

主要語言
Rust
星號
8
分支
0
平均合併
1 天 31 分鐘
30 天內合併 PR
151

環境準備

  • 沒有 Dockerfile 或 Docker Compose 檔案
  • 沒有 Pull Request 範本
  • 閱讀貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

SocketDev/socket-patch 的其他 Issue

查看 SocketDev/socket-patch 的全部 Issue

相似的 Issue

更多 Rust Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。