Skip to content

Commit 34d9bcf

Browse files
committed
Fix unguarded vlt lockfile reads to prevent FIFO hangs
Replace bare tokio::fs::read_to_string and tokio::fs::read calls with guarded read_regular_to_string and read_regular_to_bytes from socket_patch_core::utils::fs. These guarded readers use O_NONBLOCK and verify files are regular before reading, preventing indefinite hangs when a FIFO or device is placed at the lockfile path. Fixes: - rollback.rs: vlt-lock.json read during hosted rollback - repair_vendor.rs: vlt-lock.json and package.json reads during repair
1 parent ff2ceb8 commit 34d9bcf

2 files changed

Lines changed: 5 additions & 4 deletions

File tree

‎crates/socket-patch-cli/src/commands/repair_vendor.rs‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,7 @@ use socket_patch_core::constants::SOCKET_DIR;
5656
use socket_patch_core::crawlers::CrawlerOptions;
5757
use socket_patch_core::manifest::schema::{PatchManifest, PatchRecord};
5858
use socket_patch_core::patch::copy_tree::remove_tree;
59-
use socket_patch_core::utils::fs::read_regular_to_string;
59+
use socket_patch_core::utils::fs::{read_regular_to_bytes, read_regular_to_string};
6060
use socket_patch_core::utils::purl::{
6161
normalize_purl, percent_decode_purl_component, strip_purl_qualifiers,
6262
};
@@ -1546,7 +1546,7 @@ pub(crate) async fn repair_vendored_artifacts_with_references(
15461546
names.extend(vendor::vlt_lock::vlt_importer_package_jsons(&common.cwd).await);
15471547
for name in names {
15481548
let p = common.cwd.join(name);
1549-
if let Ok(bytes) = tokio::fs::read(&p).await {
1549+
if let Ok(bytes) = read_regular_to_bytes(&p).await {
15501550
snap.push((p, Some(bytes)));
15511551
}
15521552
}

‎crates/socket-patch-cli/src/commands/rollback.rs‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,7 @@ use socket_patch_core::patch::rollback::{
1515
VerifyRollbackResult, VerifyRollbackStatus,
1616
};
1717
use socket_patch_core::telemetry::{track_patch_rollback_failed, track_patch_rolled_back};
18+
use socket_patch_core::utils::fs::read_regular_to_string;
1819
use socket_patch_core::utils::purl::{patch_matches, strip_purl_qualifiers};
1920
use socket_patch_core::vendor::{save_state, RevertOpts, VendorState, VendorWarning};
2021
use std::collections::{HashMap, HashSet};
@@ -1054,8 +1055,8 @@ pub(crate) async fn run_hosted_leg(
10541055
} else {
10551056
purls.to_vec()
10561057
};
1057-
let vlt_lock = tokio::fs::read_to_string(
1058-
common
1058+
let vlt_lock = read_regular_to_string(
1059+
&common
10591060
.cwd
10601061
.join(socket_patch_core::constants::npm_family::VLT_LOCK),
10611062
)

0 commit comments

Comments
 (0)