Vendored and hosted NuGet ignore a per-project packages.<project>.lock.json, so the lock is never re-pinned and every later restore fails NU1403 while VEX attests the patch
維護者通常 1 天內回覆
還沒有人認領這個 Issue。
評估
研究方向
Start with crates/socket-patch-core/src/vendor/nuget_feed.rs and crates/socket-patch-core/src/patch/redirect/mod.rs, where the hard-coded lock filename is used, then review crates/socket-patch-core/src/vex/discover/nuget.rs. Use the repro based on crates/socket-patch-cli/tests/e2e_nuget_dotnet_build.rs and verify vendored and hosted scans recognize packages..lock.json, repin its contentHash, and leave locked and plain dotnet restore succeeding.
由索引模型根據 Issue 內容生成。
描述
[agent] Found by the scheduled NuGet / dotnet bug-hunt routine (ledger #320).
Summary
NuGet supports a per-project lock name: when packages.<ProjectName>.lock.json exists beside the project, NuGet reads and writes that file and does not use packages.lock.json (the convention for several projects in one directory, documented in the NuGet docs under "Locking dependencies"). socket-patch only looks for the hard-coded packages.lock.json:
- Vendored (
scan --mode vendored): it reportsvendor_nuget_no_lockfilewith the message "no packages.lock.json (RestorePackagesWithLockFile is off)". That is false, because the project does have a lock. It wires the folder feed and mapping but leavespackages.app.lock.jsonpinned to the upstreamcontentHash. Exit code is 0, and the in-run VEX attestsnot_affected (vendored). - Hosted (
scan --mode hosted): it adds the Socket source and the exact-id mapping, reportsredirected: 1with no warning, and leaves the named lock pinned to upstream. Exit code is 0, and the in-run VEX attestsnot_affected (redirected).
On the next restore, the patched nupkg doesn't match the lock. Every restore of the committed files then fails with NU1403: Package content hash validation failed for Newtonsoft.Json.13.0.3, both --locked-mode and plain dotnet restore.
Impact
Running vendored or hosted mode on such a project breaks its build in CI, and a fresh clone can't restore. The CLI reports success. The vendored warning tells the user the project has no lock, which points them the wrong way. VEX attests a patch the project can't install.
Repro (Linux, .NET SDK 8.0.131)
The repro is a scratch copy of crates/socket-patch-cli/tests/e2e_nuget_dotnet_build.rs, with the same wiremock Backend stand-in for the patch API and the hosted feed, and a real nuget.org fixture restore. The only change is that the fixture's lock is renamed:
# app.csproj: net8.0, RestorePackagesWithLockFile=true, PackageReference Newtonsoft.Json 13.0.3
dotnet restore # writes packages.lock.json
mv packages.lock.json packages.app.lock.json
rm -rf obj && dotnet restore --locked-mode # OK, and no packages.lock.json is created: NuGet uses the named lock
# sanity: corrupting a contentHash in packages.app.lock.json makes this restore fail NU1403,
# which proves NuGet really reads the named file
socket-patch scan --mode vendored --vendor-source service --json --yes --vex scan.vex.json ...
# rc 0; vendor result errorCode "vendor_nuget_no_lockfile":
# "no packages.lock.json (RestorePackagesWithLockFile is off); the vendored feed forces Newtonsoft.Json from the patched copy but its contentHash is not pinned"
# packages.app.lock.json unchanged; scan.vex.json: not_affected "Patched via Socket patch … (vendored)"
# fresh checkout (app.csproj, nuget.config, packages.app.lock.json, .socket/), cold NUGET_PACKAGES:
dotnet restore --locked-mode # rc 1: error NU1403: Package content hash validation failed for Newtonsoft.Json.13.0.3
dotnet restore # rc 1: same NU1403
The hosted run (scan --mode hosted --patch-server-url <stand-in>) behaves the same way: redirected: 1, warnings: [], the named lock is unchanged, the in-run VEX attests (redirected), and both restores fail NU1403.
Control: the same test with the default packages.lock.json passes. The lock is re-pinned, both restores exit 0, and the patched bytes are installed.
Each case reproduced 2/2 on main 61cfb9b.
Expected vs actual
- Expected: docs/ecosystems.md (NuGet row and "NuGet locked mode") says vendored and hosted mode pin the patched
.nupkgthrough the lock'scontentHash, so a locked restore installs the patched package. When there's no lock, vendored says so withvendor_nuget_no_lockfile. A lock that NuGet actually uses should be re-pinned. If socket-patch can't handle it, it should refuse loudly rather than report success. - Actual: the named lock is ignored. Vendored claims there's no lock, hosted says nothing, both exit 0, the build then fails NU1403, and VEX attests.
OS × version
| OS | SDK | vendored | hosted |
|---|---|---|---|
| Linux | 8.0.131 | reproduces | reproduces |
| Linux | 8.0.131, default packages.lock.json (control) |
pass | pass |
| macOS / Windows, SDK 6/9/10 | untested (NuGet has supported the named-lock convention since 4.9, so it should be the same) |
Not bisected. The lock name is a constant in both writers.
Suspect code
crates/socket-patch-core/src/vendor/nuget_feed.rs:33(const PACKAGES_LOCK: &str = "packages.lock.json"), used at:244to locate the lock and at:586for the misleadingvendor_nuget_no_lockfilemessage.crates/socket-patch-core/src/patch/redirect/mod.rs:4413(rewrite_nugetreads onlyfiles.get("packages.lock.json")).crates/socket-patch-core/src/vex/discover/nuget.rsonly documents customNuGetLockFilePathnames as a VEX non-goal. Thepackages.<project>.lock.jsonconvention needs no property, and NuGet picks it up automatically.
- 主要語言
- Rust
- 星號
- 8
- 分支
- 0
- 平均合併
- 1 天 7 分鐘
- 30 天內合併 PR
- 178
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 沒有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
SocketDev/socket-patch 的其他 Issue
-
Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap)可能已有人在做 @mikolalysenko 今天認領。 未關閉agent:claimed agent:triaged bug bughunt pm:yarn-classic priority:p1
難度 2/5 1-3 小時 新手友好度 85/100
SocketDev/socket-patch#907 · 2 則留言 ·
維護者通常 1 天內回覆
-
agent:triaged bug bughunt pm:npm priority:p1
難度 2/5 1-3 小時 新手友好度 75/100
SocketDev/socket-patch#900 ·
維護者通常 1 天內回覆
-
agent:triaged bug bughunt pm:bundler priority:p1
難度 2/5 1-3 小時 新手友好度 85/100
SocketDev/socket-patch#896 · 1 則留言 ·
維護者通常 1 天內回覆
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
難度 2/5 1-3 小時 新手友好度 73/100
SocketDev/socket-patch#783 · 1 則留言 ·
維護者通常 1 天內回覆
-
agent:triaged bug bughunt pm:pipenv priority:p1
難度 2/5 1-3 小時 新手友好度 83/100
SocketDev/socket-patch#744 · 1 則留言 ·
維護者通常 1 天內回覆
查看 SocketDev/socket-patch 的全部 Issue
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 74/100
維護者通常 5 天內回覆
-
難度 2/5 1-3 小時 新手友好度 85/100
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 76/100
tauri-apps/tauri#16219 ·
維護者通常 2 天內回覆
-
state:triage-needed
難度 2/5 1-3 小時 新手友好度 82/100
維護者通常 1 天內回覆
-
ktuner keeps a stale ledger path and can never restore that entry可能已有人在做 @Frun1na 今天認領。 未關閉component:ktuner
難度 2/5 1-3 小時 新手友好度 75/100
agentic-os-org/ANOLISA#6483 · 1 則留言 ·
維護者通常 1 天內回覆