Skip to content

Commit f4e6ce1

Browse files
Merge branch 'main' into agent/v5-go-windows-readonly-copy
2 parents 6830b65 + 9ab72d4 commit f4e6ce1

8 files changed

Lines changed: 47 additions & 14 deletions

File tree

‎crates/socket-patch-cli/tests/e2e_hosted_production.rs‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@
3333
//!
3434
//! | Ecosystem | PURL | Patch UUID | Advisory |
3535
//! |-----------|------|------------|----------|
36-
//! | npm | `pkg:npm/minimist@1.2.2` | `80630680-4da6-45f9-bba8-b888e0ffd58c` | GHSA-xvch-5gv4-984h (CVE-2021-44906) |
36+
//! | npm | `pkg:npm/minimist@1.2.2` | `642d7f02-ebc1-4ab0-99e2-07f5dd8463cb` | GHSA-xvch-5gv4-984h (CVE-2021-44906) |
3737
//! | PyPI | `pkg:pypi/urllib3@1.26.18` | *any of three* (see [`PYPI_UUIDS`]) | GHSA-gm62-xv2j-4w53 &co |
3838
//! | gem | `pkg:gem/activestorage@6.0.3` | *any of* [`GEM_UUIDS`] (six today; the sixth merges three advisories) | GHSA-m42x-37p3-fv5w (CVE-2020-8162), GHSA-w749-p3v6-hccq (CVE-2022-21831), GHSA-9xrj-h377-fr87 (CVE-2026-33195), GHSA-r4mg-4433-c7g3 (CVE-2025-24293), GHSA-xr9x-r78c-5hrm (CVE-2026-66066) |
3939
//!
@@ -123,7 +123,7 @@ const PATCH_HOST: &str = "patch.socket.dev";
123123
const NPM_PURL: &str = "pkg:npm/minimist@1.2.2";
124124
const NPM_NAME: &str = "minimist";
125125
const NPM_VERSION: &str = "1.2.2";
126-
const NPM_UUID: &str = "80630680-4da6-45f9-bba8-b888e0ffd58c";
126+
const NPM_UUID: &str = "642d7f02-ebc1-4ab0-99e2-07f5dd8463cb";
127127

128128
const PYPI_PURL: &str = "pkg:pypi/urllib3@1.26.18";
129129
const PYPI_NAME: &str = "urllib3";

‎crates/socket-patch-cli/tests/e2e_npm.rs‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
//! End-to-end tests for the npm patch lifecycle.
22
//!
33
//! These tests exercise the full CLI against the real Socket API, using the
4-
//! **minimist@1.2.2** patch (UUID `80630680-4da6-45f9-bba8-b888e0ffd58c`),
4+
//! **minimist@1.2.2** patch (UUID `642d7f02-ebc1-4ab0-99e2-07f5dd8463cb`),
55
//! which fixes CVE-2021-44906 (Prototype Pollution).
66
//!
77
//! # Prerequisites
@@ -26,14 +26,14 @@ use common::cache_env;
2626
// Constants
2727
// ---------------------------------------------------------------------------
2828

29-
const NPM_UUID: &str = "80630680-4da6-45f9-bba8-b888e0ffd58c";
29+
const NPM_UUID: &str = "642d7f02-ebc1-4ab0-99e2-07f5dd8463cb";
3030
const NPM_PURL: &str = "pkg:npm/minimist@1.2.2";
3131

3232
/// Git SHA-256 of the *unpatched* `index.js` shipped with minimist 1.2.2.
3333
const BEFORE_HASH: &str = "311f1e893e6eac502693fad8617dcf5353a043ccc0f7b4ba9fe385e838b67a10";
3434

3535
/// Git SHA-256 of the *patched* `index.js` after the security fix.
36-
const AFTER_HASH: &str = "043f04d19e884aa5f8371428718d2a3f27a0d231afe77a2620ac6312f80aaa28";
36+
const AFTER_HASH: &str = "ec956dcafb886f14315570bf3981d44aa12c561716abb46eed8b067aaa1f6bdf";
3737

3838
// ---------------------------------------------------------------------------
3939
// Helpers

‎crates/socket-patch-cli/tests/e2e_safety_pnpm.rs‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@
1111
//! view and the store entry byte-identical.
1212
//!
1313
//! Fixture: minimist@1.2.2 + its Socket patch (UUID
14-
//! `80630680-4da6-45f9-bba8-b888e0ffd58c`, CVE-2021-44906) — same
14+
//! `642d7f02-ebc1-4ab0-99e2-07f5dd8463cb`, CVE-2021-44906) — same
1515
//! pair `e2e_npm.rs` uses, so the BEFORE/AFTER hashes are known.
1616
//!
1717
//! Network: yes (pnpm install + socket-patch get). Toolchain: pnpm.
@@ -24,12 +24,12 @@ mod common;
2424

2525
use common::{assert_run_ok, git_sha256_file, has_command, pnpm_run, write_package_json};
2626

27-
const NPM_UUID: &str = "80630680-4da6-45f9-bba8-b888e0ffd58c";
27+
const NPM_UUID: &str = "642d7f02-ebc1-4ab0-99e2-07f5dd8463cb";
2828

2929
/// Git-SHA-256 of the *unpatched* `index.js` shipped with minimist 1.2.2.
3030
const BEFORE_HASH: &str = "311f1e893e6eac502693fad8617dcf5353a043ccc0f7b4ba9fe385e838b67a10";
3131
/// Git-SHA-256 of the *patched* `index.js` after the security fix.
32-
const AFTER_HASH: &str = "043f04d19e884aa5f8371428718d2a3f27a0d231afe77a2620ac6312f80aaa28";
32+
const AFTER_HASH: &str = "ec956dcafb886f14315570bf3981d44aa12c561716abb46eed8b067aaa1f6bdf";
3333

3434
// ── Setup helpers ─────────────────────────────────────────────────────
3535

‎crates/socket-patch-cli/tests/e2e_vendored_production.rs‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@
4949
//!
5050
//! | Ecosystem | PURL | Patch UUID | Marker in the patched bytes |
5151
//! |-----------|------|------------|-----------------------------|
52-
//! | npm | `pkg:npm/minimist@1.2.2` | `80630680-4da6-45f9-bba8-b888e0ffd58c` | `Socket Community Patch` header |
52+
//! | npm | `pkg:npm/minimist@1.2.2` | `642d7f02-ebc1-4ab0-99e2-07f5dd8463cb` | `Socket Community Patch` header |
5353
//! | PyPI | `pkg:pypi/urllib3@1.26.18` | *any of three* (see [`PYPI_UUIDS`]) | `Socket Community Patch` header |
5454
//! | gem | `pkg:gem/activestorage@6.0.3` | *any of* [`GEM_PATCHES`] | `Socket Community Patch` header |
5555
//!
@@ -137,7 +137,7 @@ const PROXY: &str = "https://patches-api.socket.dev";
137137
const NPM_PURL: &str = "pkg:npm/minimist@1.2.2";
138138
const NPM_NAME: &str = "minimist";
139139
const NPM_VERSION: &str = "1.2.2";
140-
const NPM_UUID: &str = "80630680-4da6-45f9-bba8-b888e0ffd58c";
140+
const NPM_UUID: &str = "642d7f02-ebc1-4ab0-99e2-07f5dd8463cb";
141141

142142
const PYPI_PURL: &str = "pkg:pypi/urllib3@1.26.18";
143143
const PYPI_NAME: &str = "urllib3";

‎docs/testing/bun-compatibility.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ projects using text `bun.lock` or native binary `bun.lockb`. Real-Bun evidence b
55

66
- **The native matrix** — `scripts/backtest-bun.py` runs real Bun releases
77
against the public free Socket patch for `minimist@1.2.2`
8-
(`80630680-4da6-45f9-bba8-b888e0ffd58c`) with the production CLI and patch
8+
(`642d7f02-ebc1-4ab0-99e2-07f5dd8463cb`) with the production CLI and patch
99
service, without a token or substitute service, and checks the INSTALLED
1010
bytes, lock stability, digest rejection and rollback on Linux, macOS and
1111
Windows ([workflow](../../.github/workflows/bun-compatibility.yml)).

‎scripts/backtest-bun.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -117,7 +117,7 @@
117117
# former `vendored-detached` leg collapsed into `vendored`: same footprint.
118118
MODES = ['hosted', 'vendored']
119119
PURL = 'pkg:npm/minimist@1.2.2'
120-
UUID = '80630680-4da6-45f9-bba8-b888e0ffd58c'
120+
UUID = '642d7f02-ebc1-4ab0-99e2-07f5dd8463cb'
121121
# The registry slot bun writes for a non-default registry: the full tarball URL.
122122
REGISTRY_SLOT = 'https://registry.npmjs.org/minimist/-/minimist-1.2.2.tgz'
123123
LOCAL_TUPLE_SPEC = f'minimist@.socket/vendor/npm/{UUID}/minimist-1.2.2.tgz'

‎scripts/backtest-vlt.py‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -88,7 +88,7 @@
8888
VERSIONS = ['0.0.0-16', '0.0.0-32', '1.0.0-rc.14', '1.0.0-rc.32', '1.0.4', '1.0.10', '1.2.0']
8989
MODES = ['hosted', 'vendored', 'agent']
9090
PURL = 'pkg:npm/minimist@1.2.2'
91-
UUID = '80630680-4da6-45f9-bba8-b888e0ffd58c'
91+
UUID = '642d7f02-ebc1-4ab0-99e2-07f5dd8463cb'
9292
NAME = 'minimist'
9393
VERSION = '1.2.2'
9494
TARGET = f'{NAME}@{VERSION}'
@@ -1069,7 +1069,7 @@ def holds(self, root, lock_text, side):
10691069
ok = True
10701070
for copy_dir in self.copies(root, lock_text):
10711071
for key, hashes in self.record['files'].items():
1072-
path = copy_dir / key.split('/', 1)[1]
1072+
path = copy_dir / key.removeprefix('package/')
10731073
digest = git_hash(path.read_bytes()) if path.is_file() else None
10741074
details[str(path.relative_to(root))] = digest
10751075
ok = ok and digest == hashes.get(f'{side}Hash')

‎scripts/tests/test_backtest_harnesses.py‎

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -814,6 +814,39 @@ def test_shapes_are_depscan_capture_shapes(self):
814814
self.assertLessEqual(set(vlt.SHAPES), capture_names)
815815

816816

817+
class VltInstalledBytesTests(unittest.TestCase):
818+
def test_holds_checks_root_and_nested_files_with_optional_package_prefix(self):
819+
contents = {
820+
'index.js': {'before': b'original entrypoint', 'after': b'patched entrypoint'},
821+
'test/proto.js': {'before': b'original test', 'after': b'patched test'},
822+
}
823+
for prefix in ('', 'package/'):
824+
for side in ('before', 'after'):
825+
with self.subTest(prefix=prefix, side=side), tempfile.TemporaryDirectory() as temp:
826+
root = Path(temp)
827+
package = root / 'node_modules' / 'minimist'
828+
record = {'files': {
829+
prefix + name: {s + 'Hash': vlt.git_hash(data) for s, data in sides.items()}
830+
for name, sides in contents.items()
831+
}}
832+
cell = vlt.Cell({'out': root, 'record': record}, '1.2.0', 'vendored', 'direct')
833+
expected = {}
834+
for name, sides in contents.items():
835+
path = package / name
836+
path.parent.mkdir(parents=True, exist_ok=True)
837+
path.write_bytes(sides[side])
838+
expected[str(path.relative_to(root))] = vlt.git_hash(sides[side])
839+
self.assertEqual(cell.holds(root, '{}', side), (True, expected))
840+
other_side = 'after' if side == 'before' else 'before'
841+
self.assertFalse(cell.holds(root, '{}', other_side)[0])
842+
843+
nested = package / 'test' / 'proto.js'
844+
nested.write_bytes(b'corrupted')
845+
self.assertFalse(cell.holds(root, '{}', side)[0])
846+
nested.unlink()
847+
self.assertFalse(cell.holds(root, '{}', side)[0])
848+
849+
817850
class VltConfigTests(unittest.TestCase):
818851
"""write_vlt_json follows the DESIGN §8.3 per-era registry table."""
819852

0 commit comments

Comments
 (0)