Skip to content

Commit e01f3fe

Browse files
committed
bughunt: cargo vendor-dir probe
1 parent f6b7fb9 commit e01f3fe

1 file changed

Lines changed: 60 additions & 0 deletions

File tree

Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
name: bughunt-cargo probe
2+
on:
3+
push:
4+
branches: ['bughunt/cargo/**']
5+
permissions:
6+
contents: read
7+
jobs:
8+
probe:
9+
strategy:
10+
fail-fast: false
11+
matrix:
12+
os: [ubuntu-latest, macos-latest, windows-latest]
13+
runs-on: ${{ matrix.os }}
14+
timeout-minutes: 45
15+
defaults:
16+
run:
17+
shell: bash
18+
steps:
19+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
20+
- uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1
21+
- name: Build socket-patch
22+
run: cargo build --release -p socket-patch-cli
23+
- name: Install probe toolchains
24+
run: rustup toolchain install 1.56.1 --profile minimal && rustup toolchain install stable --profile minimal
25+
- name: Probe custom cargo-vendor directory
26+
run: |
27+
SP="$GITHUB_WORKSPACE/target/release/socket-patch"
28+
cat > "$RUNNER_TEMP/stage.py" <<'PY'
29+
import sys, json, hashlib, os
30+
proj, purl, src, rel = sys.argv[1:5]
31+
def g(b): return hashlib.sha256(b"blob %d\0" % len(b) + b).hexdigest()
32+
before = open(os.path.join(src, rel), "rb").read()
33+
after = before + b"\n/// socket marker\npub fn socket_patched() -> u32 { 1 }\n"
34+
s = os.path.join(proj, ".socket"); os.makedirs(os.path.join(s, "blobs"), exist_ok=True)
35+
m = {"setup": {"manual": ["cargo"]}, "patches": {purl: {"uuid": "11111111-2222-4333-8444-555555555555",
36+
"exportedAt": "2026-01-01T00:00:00Z", "files": {rel: {"beforeHash": g(before), "afterHash": g(after)}},
37+
"vulnerabilities": {"GHSA-xxxx-xxxx-xxxx": {"cves": ["CVE-2024-1"], "summary": "s", "severity": "high", "description": "d"}},
38+
"description": "m", "license": "MIT", "tier": "free"}}}
39+
json.dump(m, open(os.path.join(s, "manifest.json"), "w"), indent=2)
40+
for b in (before, after): open(os.path.join(s, "blobs", g(b)), "wb").write(b)
41+
PY
42+
for TC in 1.56.1 stable; do
43+
for D in vendor third_party; do
44+
W="$RUNNER_TEMP/w-$TC-$D"; rm -rf "$W"; mkdir -p "$W/src" "$W/.cargo"; cd "$W"
45+
export CARGO_HOME="$W/cargo-home"
46+
printf '[package]\nname = "app"\nversion = "0.1.0"\nedition = "2018"\n\n[dependencies]\ncfg-if = "=1.0.0"\n' > Cargo.toml
47+
echo 'fn main(){ println!("{}", cfg_if::socket_patched()); }' > src/main.rs
48+
cargo +$TC generate-lockfile -q
49+
cargo +$TC vendor -q "$D" > /dev/null
50+
printf '[source.crates-io]\nreplace-with = "vendored-sources"\n\n[source.vendored-sources]\ndirectory = "%s"\n' "$D" > .cargo/config.toml
51+
python "$RUNNER_TEMP/stage.py" . pkg:cargo/cfg-if@1.0.0 "$D/cfg-if" src/lib.rs
52+
ST=$("$SP" apply --json --offline 2>/dev/null | grep -m1 '"status"' | tr -d ' ,')
53+
INV=$(grep -c socket_patched "$D/cfg-if/src/lib.rs")
54+
INC=$(cat "$CARGO_HOME"/registry/src/*/cfg-if-1.0.0/src/lib.rs 2>/dev/null | grep -c socket_patched)
55+
if cargo +$TC build -q --frozen --offline >/dev/null 2>&1; then B=ok; else B=FAIL; fi
56+
"$SP" vex --offline -O vex.json >/dev/null 2>&1; VX=$(grep -o '"status": "[a-z_]*"' vex.json 2>/dev/null | tr -d ' "')
57+
echo "RESULT os=${{ matrix.os }} cargo=$TC dir=$D apply=$ST patched_in_dir=$INV patched_in_cache=$INC build=$B vex=$VX"
58+
cd "$RUNNER_TEMP"
59+
done
60+
done

0 commit comments

Comments
 (0)