|
| 1 | +name: bughunt-cargo probe |
| 2 | +on: |
| 3 | + push: |
| 4 | + branches: ['bughunt/cargo/**'] |
| 5 | +permissions: |
| 6 | + contents: read |
| 7 | +jobs: |
| 8 | + probe: |
| 9 | + strategy: |
| 10 | + fail-fast: false |
| 11 | + matrix: |
| 12 | + os: [ubuntu-latest, macos-latest, windows-latest] |
| 13 | + runs-on: ${{ matrix.os }} |
| 14 | + timeout-minutes: 45 |
| 15 | + defaults: |
| 16 | + run: |
| 17 | + shell: bash |
| 18 | + steps: |
| 19 | + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 |
| 20 | + - uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1 |
| 21 | + - name: Build socket-patch |
| 22 | + run: cargo build --release -p socket-patch-cli |
| 23 | + - name: Install probe toolchains |
| 24 | + run: rustup toolchain install 1.56.1 --profile minimal && rustup toolchain install stable --profile minimal |
| 25 | + - name: Probe custom cargo-vendor directory |
| 26 | + run: | |
| 27 | + SP="$GITHUB_WORKSPACE/target/release/socket-patch" |
| 28 | + cat > "$RUNNER_TEMP/stage.py" <<'PY' |
| 29 | + import sys, json, hashlib, os |
| 30 | + proj, purl, src, rel = sys.argv[1:5] |
| 31 | + def g(b): return hashlib.sha256(b"blob %d\0" % len(b) + b).hexdigest() |
| 32 | + before = open(os.path.join(src, rel), "rb").read() |
| 33 | + after = before + b"\n/// socket marker\npub fn socket_patched() -> u32 { 1 }\n" |
| 34 | + s = os.path.join(proj, ".socket"); os.makedirs(os.path.join(s, "blobs"), exist_ok=True) |
| 35 | + m = {"setup": {"manual": ["cargo"]}, "patches": {purl: {"uuid": "11111111-2222-4333-8444-555555555555", |
| 36 | + "exportedAt": "2026-01-01T00:00:00Z", "files": {rel: {"beforeHash": g(before), "afterHash": g(after)}}, |
| 37 | + "vulnerabilities": {"GHSA-xxxx-xxxx-xxxx": {"cves": ["CVE-2024-1"], "summary": "s", "severity": "high", "description": "d"}}, |
| 38 | + "description": "m", "license": "MIT", "tier": "free"}}} |
| 39 | + json.dump(m, open(os.path.join(s, "manifest.json"), "w"), indent=2) |
| 40 | + for b in (before, after): open(os.path.join(s, "blobs", g(b)), "wb").write(b) |
| 41 | + PY |
| 42 | + for TC in 1.56.1 stable; do |
| 43 | + for D in vendor third_party; do |
| 44 | + W="$RUNNER_TEMP/w-$TC-$D"; rm -rf "$W"; mkdir -p "$W/src" "$W/.cargo"; cd "$W" |
| 45 | + export CARGO_HOME="$W/cargo-home" |
| 46 | + printf '[package]\nname = "app"\nversion = "0.1.0"\nedition = "2018"\n\n[dependencies]\ncfg-if = "=1.0.0"\n' > Cargo.toml |
| 47 | + echo 'fn main(){ println!("{}", cfg_if::socket_patched()); }' > src/main.rs |
| 48 | + cargo +$TC generate-lockfile -q |
| 49 | + cargo +$TC vendor -q "$D" > /dev/null |
| 50 | + printf '[source.crates-io]\nreplace-with = "vendored-sources"\n\n[source.vendored-sources]\ndirectory = "%s"\n' "$D" > .cargo/config.toml |
| 51 | + python "$RUNNER_TEMP/stage.py" . pkg:cargo/cfg-if@1.0.0 "$D/cfg-if" src/lib.rs |
| 52 | + ST=$("$SP" apply --json --offline 2>/dev/null | grep -m1 '"status"' | tr -d ' ,') |
| 53 | + INV=$(grep -c socket_patched "$D/cfg-if/src/lib.rs") |
| 54 | + INC=$(cat "$CARGO_HOME"/registry/src/*/cfg-if-1.0.0/src/lib.rs 2>/dev/null | grep -c socket_patched) |
| 55 | + if cargo +$TC build -q --frozen --offline >/dev/null 2>&1; then B=ok; else B=FAIL; fi |
| 56 | + "$SP" vex --offline -O vex.json >/dev/null 2>&1; VX=$(grep -o '"status": "[a-z_]*"' vex.json 2>/dev/null | tr -d ' "') |
| 57 | + echo "RESULT os=${{ matrix.os }} cargo=$TC dir=$D apply=$ST patched_in_dir=$INV patched_in_cache=$INC build=$B vex=$VX" |
| 58 | + cd "$RUNNER_TEMP" |
| 59 | + done |
| 60 | + done |
0 commit comments