Skip to content

Commit 96327a9

Browse files
committed
bughunt go probe: windows apply
1 parent f6b7fb9 commit 96327a9

1 file changed

Lines changed: 83 additions & 0 deletions

File tree

‎.github/workflows/bughunt-go.yml‎

Lines changed: 83 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,83 @@
1+
name: bughunt go probe
2+
on:
3+
push:
4+
branches: ['bughunt/go/**']
5+
permissions:
6+
contents: read
7+
jobs:
8+
probe:
9+
strategy:
10+
fail-fast: false
11+
matrix:
12+
os: [windows-latest, windows-2022, ubuntu-latest]
13+
go: ['1.21.13', '1.26.3']
14+
runs-on: ${{ matrix.os }}
15+
timeout-minutes: 45
16+
defaults:
17+
run:
18+
shell: bash
19+
steps:
20+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
21+
with:
22+
persist-credentials: false
23+
- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
24+
with:
25+
go-version: ${{ matrix.go }}
26+
cache: false
27+
- run: cargo build --release -p socket-patch-cli
28+
- name: probe
29+
run: |
30+
cat > "$RUNNER_TEMP/probe.sh" <<'PROBE'
31+
# Portable (Linux/macOS/Windows git-bash) repro for two Go findings.
32+
set -u
33+
SP="$1"; ROOT="$2"; rm -rf "$ROOT"; mkdir -p "$ROOT"
34+
PY=$(command -v python3 || command -v python)
35+
mp() { if command -v cygpath >/dev/null 2>&1; then cygpath -m "$1"; else echo "$1"; fi; }
36+
furl() { local p; p=$(mp "$1"); case "$p" in /*) echo "file://$p";; *) echo "file:///$p";; esac; }
37+
export GOTOOLCHAIN=local GOSUMDB=off GOENV=off GOFLAGS= SOCKET_NO_CONFIG=1 SOCKET_NO_UPDATE_CHECK=1
38+
stage() {
39+
T="$1"; M=example.com/upstream; V=v1.0.0
40+
mkdir -p "$T/stage/$M@$V" "$T/modcache" "$T/gocache" "$T/proxy/$M/@v" "$T/c/.socket/blobs"
41+
printf 'module %s\n\ngo 1.16\n' $M > "$T/stage/$M@$V/go.mod"
42+
printf 'package upstream\n\nfunc Greeting() string { return "PRISTINE" }\n' > "$T/stage/$M@$V/lib.go"
43+
printf 'package upstream\n\nfunc Greeting() string { return "PATCHED" }\n' > "$T/patched.go"
44+
echo "{\"Version\":\"$V\"}" > "$T/proxy/$M/@v/$V.info"; cp "$T/stage/$M@$V/go.mod" "$T/proxy/$M/@v/$V.mod"
45+
"$PY" - "$T" "$M@$V" <<'P'
46+
import sys,zipfile,os
47+
t,pre=sys.argv[1],sys.argv[2]
48+
src=os.path.join(t,'stage',pre); z=zipfile.ZipFile(os.path.join(t,'proxy','example.com','upstream','@v','v1.0.0.zip'),'w')
49+
for f in ('go.mod','lib.go'): z.write(os.path.join(src,f),pre+'/'+f)
50+
z.close()
51+
import hashlib
52+
def g(p):
53+
d=open(p,'rb').read(); return hashlib.sha256(b'blob %d\0'%len(d)+d).hexdigest()
54+
b=g(os.path.join(src,'lib.go')); a=g(os.path.join(t,'patched.go'))
55+
import shutil; shutil.copy(os.path.join(t,'patched.go'),os.path.join(t,'c','.socket','blobs',a))
56+
open(os.path.join(t,'c','.socket','manifest.json'),'w').write('{"patches":{"pkg:golang/example.com/upstream@v1.0.0":{"uuid":"4d5e6f70-8192-4a1b-8c2d-0123456789ab","exportedAt":"t","files":{"lib.go":{"beforeHash":"%s","afterHash":"%s"}},"vulnerabilities":{"GHSA-gogo-patc-hes1":{"cves":["CVE-2026-5151"],"summary":"s","severity":"high","description":"d"}},"description":"","license":"","tier":""}},"setup":{"manual":["golang"]}}'%(b,a))
57+
P
58+
export GOMODCACHE=$(mp "$T/modcache") GOCACHE=$(mp "$T/gocache") GOPROXY=$(furl "$T/proxy")
59+
printf 'module example.com/consumer\n\ngo 1.16\n\nrequire %s %s\n' $M $V > "$T/c/go.mod"
60+
printf 'package main\n\nimport (\n\t"fmt"\n\t"%s"\n)\n\nfunc main() { fmt.Println("OUT:", upstream.Greeting()) }\n' $M > "$T/c/main.go"
61+
(cd "$T/c" && go mod download $M@$V && go mod tidy) || echo "STAGE FAILED"
62+
}
63+
res() { echo "RESULT $1: $2"; }
64+
65+
66+
echo "################ W. plain apply / vendor (no vendor/ dir)"
67+
for mode in ro rw; do
68+
for cmd in apply vendor; do
69+
T="$ROOT/w-$cmd-$mode"; if [ $mode = rw ]; then export GOFLAGS=-modcacherw; else export GOFLAGS=; fi
70+
stage "$T"; cd "$T/c"; export GOFLAGS=
71+
ls -l "$(mp "$T/modcache")/example.com/upstream@v1.0.0/" 2>&1 | head -4
72+
if command -v attrib >/dev/null 2>&1; then attrib "$(cygpath -w "$T/modcache/example.com/upstream@v1.0.0/lib.go")"; fi
73+
RUST_BACKTRACE=1 "$SP" $cmd --offline --ecosystems golang --json > out.json 2>err.txt; ec=$?
74+
echo "--- $cmd/$mode json:"; head -c 1500 out.json; echo; head -20 err.txt
75+
out=$(go run . 2>&1 | tail -1)
76+
res "W-$cmd-$mode" "exit=$ec run=[$out] $(grep -o '"error":"[^"]*' out.json | head -1)"
77+
ls -la .socket/go-patches/example.com 2>/dev/null | head -3
78+
done; done
79+
PROBE
80+
go version
81+
SP="$PWD/target/release/socket-patch"; [ -f "$SP.exe" ] && SP="$SP.exe"
82+
bash "$RUNNER_TEMP/probe.sh" "$SP" "$RUNNER_TEMP/bh" 2>&1 | tee "$RUNNER_TEMP/log.txt"
83+
echo "=========== SUMMARY"; grep RESULT "$RUNNER_TEMP/log.txt"

0 commit comments

Comments
 (0)