[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: E06.
Kind: bug. Source: review Part 6.6 ("FIFO safety"); register E06.
Problem
The crawlers' FIFO-safe read discipline (utils::fs::read_regular_to_string / read_regular_to_string_sync, a non-blocking open that rejects FIFOs, devices and directories) is missing from three reads of project-tree files. A FIFO planted at one of these paths blocks the open forever, so scan, get and apply hang:
- NuGet
parse_project_assets_package_folders reads obj/project.assets.json and <sub>/obj/project.assets.json with tokio::fs::read_to_string. It runs from get_nuget_package_paths and so from every NuGet crawl.
- Cargo
read_crate_cargo_toml (crawl_all) reads vendor/<crate>/Cargo.toml with std::fs::read_to_string.
- Cargo
verify_crate_at_path (find_by_purls) does the same with tokio::fs::read_to_string.
The sibling crawlers already guard the same kind of read: python parse_metadata_headers,`` composer, npm and ruby.
Repro (unit tests, each run twice on main 203e092):
- NuGet: a temp project with
App.csproj and mkfifo obj/project.assets.json. NuGetCrawler::get_nuget_package_paths was still pending after 3 s (timed_out=true).
- Cargo: a temp project with
Cargo.toml and mkfifo vendor/left-1.0.0/Cargo.toml. CargoCrawler::crawl_all and find_by_purls(vendor, ["pkg:cargo/left@1.0.0"]) were both pending after 3 s.
The probes weren't committed.
Symptoms
None filed. The review's other example, python_crawler.rs .venv at L1214-L1215,`` is guarded by is_file() and only has a TOCTOU window, so it isn't part of this issue.
Impact
A checked-out repository (or a PR in CI) can wedge every socket-patch scan on it with one FIFO. The other crawlers were fixed for this bug class in #111. Size: three call sites.
Proposed change
Replace the three reads with read_regular_to_string (async) and read_regular_to_string_sync (in the blocking-pool scan_crate_source). Keep today's "unreadable means skip" behavior. Nothing else is deleted; the shared readers already exist.
Size and scope
crawlers/nuget_crawler.rs, crawlers/cargo_crawler.rs: about 10 production lines plus tests. Out of scope: the Maven POM reads at maven_crawler.rs L498 and L813, which read the machine repository, not the project tree. Follow-up: an architecture test that bans bare read_to_string in crawlers/ outside #[cfg(test)].
Acceptance criteria
Dependencies
None. Independent of the E05 cache-scoping work.
[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: E06.
Kind: bug. Source: review Part 6.6 ("FIFO safety"); register E06.
Problem
The crawlers' FIFO-safe read discipline (
utils::fs::read_regular_to_string/read_regular_to_string_sync, a non-blocking open that rejects FIFOs, devices and directories) is missing from three reads of project-tree files. A FIFO planted at one of these paths blocks the open forever, soscan,getandapplyhang:parse_project_assets_package_foldersreadsobj/project.assets.jsonand<sub>/obj/project.assets.jsonwithtokio::fs::read_to_string. It runs fromget_nuget_package_pathsand so from every NuGet crawl.read_crate_cargo_toml(crawl_all) readsvendor/<crate>/Cargo.tomlwithstd::fs::read_to_string.verify_crate_at_path(find_by_purls) does the same withtokio::fs::read_to_string.The sibling crawlers already guard the same kind of read: python
parse_metadata_headers,`` composer, npm and ruby.Repro (unit tests, each run twice on main
203e092):App.csprojandmkfifo obj/project.assets.json.NuGetCrawler::get_nuget_package_pathswas still pending after 3 s (timed_out=true).Cargo.tomlandmkfifo vendor/left-1.0.0/Cargo.toml.CargoCrawler::crawl_allandfind_by_purls(vendor, ["pkg:cargo/left@1.0.0"])were both pending after 3 s.The probes weren't committed.
Symptoms
None filed. The review's other example,
python_crawler.rs.venvat L1214-L1215,`` is guarded byis_file()and only has a TOCTOU window, so it isn't part of this issue.Impact
A checked-out repository (or a PR in CI) can wedge every
socket-patch scanon it with one FIFO. The other crawlers were fixed for this bug class in #111. Size: three call sites.Proposed change
Replace the three reads with
read_regular_to_string(async) andread_regular_to_string_sync(in the blocking-poolscan_crate_source). Keep today's "unreadable means skip" behavior. Nothing else is deleted; the shared readers already exist.Size and scope
crawlers/nuget_crawler.rs,crawlers/cargo_crawler.rs: about 10 production lines plus tests. Out of scope: the Maven POM reads atmaven_crawler.rsL498 and L813, which read the machine repository, not the project tree. Follow-up: an architecture test that bans bareread_to_stringincrawlers/outside#[cfg(test)].Acceptance criteria
obj/project.assets.json(NuGet) and atvendor/<crate>/Cargo.toml(Cargocrawl_allandfind_by_purls) returns within 1 s, and the crawl skips the entry.cargo test -p socket-patch-core --lib crawlersand the crawler oracle suites stay green.Dependencies
None. Independent of the E05 cache-scoping work.