[agent] Found by the scheduled npm bug-hunt routine (ledger #302).
Summary
In agent mode, vex checks only the first installed copy of each manifest PURL (crates/socket-patch-cli/src/commands/vex.rs:556, let package_paths = collapse_to_first(copies.clone());). Hosted-basis PURLs are checked against every copy (vex_consumed::hosted_consumed_copies), but agent records are not. When an npm tree holds several nested copies of the same name@version and only some of them are patched, the verdict depends on crawl order:
- first copy patched, another copy unpatched →
not_affected (wrong);
- first copy unpatched, another copy patched →
not_applied (right, by luck).
The Deno routine found this (handover on #302). I confirmed it with plain npm, where the trigger is common: apply patches every copy present, and a later npm install of a new dependent extracts a fresh, unpatched nested copy while leaving the patched one alone.
Impact
The VEX document says not_affected while an unpatched copy of the vulnerable code is still in node_modules and gets loaded by its dependent (is-accessor-descriptor here). apply is fine: re-running it patches the new copy. Only the attestation is wrong.
Repro (real npm, Linux, main 61cfb9b)
SP=/path/to/target/release/socket-patch
mkdir npmdup && cd npmdup && echo '{"name":"npmdup","version":"1.0.0"}' > package.json
npm install kind-of@6.0.3 is-number@3.0.0 # nests kind-of@3.2.2 under is-number
# Hand-stage .socket/manifest.json + .socket/blobs with a patch for pkg:npm/kind-of@3.2.2
# that changes package/index.js (beforeHash = pristine, afterHash = pristine + a comment line),
# with one vulnerability carrying a CVE. Any free patch works too.
$SP apply --offline # 1 of 1 targeted patch applied
npm install is-accessor-descriptor@0.1.6 # adds is-accessor-descriptor/node_modules/kind-of@3.2.2, unpatched
$SP vex --offline -O v.json; echo $? # exit 0, 1 statement: not_affected
State after the second install:
node_modules/is-number/node_modules/kind-of 3.2.2 patched
node_modules/is-accessor-descriptor/node_modules/kind-of 3.2.2 UNPATCHED
node_modules/kind-of 6.0.3 (not targeted)
vex output: Wrote OpenVEX document with 1 statement to v.json, status not_affected.
Crawl-order check on the same tree: restore the is-number copy to pristine and patch the is-accessor-descriptor copy instead, and vex omits the PURL (not_applied) and exits with "No applied patches with vulnerability metadata to attest."
Expected vs actual
- Expected: CLI_CONTRACT.md's verification table (
crates/socket-patch-cli/CLI_CONTRACT.md:390) says an agent record is verified against "the installed tree". An attestation should hold only when every installed copy the crawler finds for that PURL hashes to the patched bytes, as the hosted path already requires. Otherwise the PURL should be omitted (not_applied / hash_mismatch).
- Actual: only the first copy is hashed, and
not_affected is emitted with exit 0.
Matrix
| OS |
npm |
Node |
main 61cfb9b |
v4.0.0 (with setup.manual: ["npm"]) |
| Linux |
8.19.4 |
22.22 |
reproduces |
not run |
| Linux |
10.9.4 |
22.22 |
reproduces (2/2) |
reproduces |
| Linux |
12.2.0 |
22.22 |
reproduces |
not run |
| macOS / Windows |
— |
— |
not probed (the logic isn't OS-specific) |
— |
First bad version
This isn't a v5 regression: v4.0.0 emits the same single not_affected statement once setup.manual is set. I didn't bisect further.
Suspect code
crates/socket-patch-cli/src/commands/vex.rs:556: collapse_to_first(copies.clone()) feeds applied_patches_with_vendor, which hashes one path per PURL for agent records.
crates/socket-patch-cli/src/ecosystem_dispatch.rs:401: collapse_to_first.
The same pattern probably hits every npm-family layout that can hold several copies of one version (yarn classic and bun hoisted, Deno's hoisted linker, pnpm peer variants), but this issue covers npm only.
Related but different: #325 (bundled copies, hosted in-run --vex), #435 (pnpm global), #405 (bun isolated).
[agent] Found by the scheduled npm bug-hunt routine (ledger #302).
Summary
In agent mode,
vexchecks only the first installed copy of each manifest PURL (crates/socket-patch-cli/src/commands/vex.rs:556,let package_paths = collapse_to_first(copies.clone());). Hosted-basis PURLs are checked against every copy (vex_consumed::hosted_consumed_copies), but agent records are not. When an npm tree holds several nested copies of the samename@versionand only some of them are patched, the verdict depends on crawl order:not_affected(wrong);not_applied(right, by luck).The Deno routine found this (handover on #302). I confirmed it with plain npm, where the trigger is common:
applypatches every copy present, and a laternpm installof a new dependent extracts a fresh, unpatched nested copy while leaving the patched one alone.Impact
The VEX document says
not_affectedwhile an unpatched copy of the vulnerable code is still innode_modulesand gets loaded by its dependent (is-accessor-descriptorhere).applyis fine: re-running it patches the new copy. Only the attestation is wrong.Repro (real npm, Linux, main
61cfb9b)State after the second install:
vexoutput:Wrote OpenVEX document with 1 statement to v.json, statusnot_affected.Crawl-order check on the same tree: restore the
is-numbercopy to pristine and patch theis-accessor-descriptorcopy instead, andvexomits the PURL (not_applied) and exits with "No applied patches with vulnerability metadata to attest."Expected vs actual
crates/socket-patch-cli/CLI_CONTRACT.md:390) says an agent record is verified against "the installed tree". An attestation should hold only when every installed copy the crawler finds for that PURL hashes to the patched bytes, as the hosted path already requires. Otherwise the PURL should be omitted (not_applied/hash_mismatch).not_affectedis emitted with exit 0.Matrix
61cfb9bsetup.manual: ["npm"])First bad version
This isn't a v5 regression: v4.0.0 emits the same single
not_affectedstatement oncesetup.manualis set. I didn't bisect further.Suspect code
crates/socket-patch-cli/src/commands/vex.rs:556:collapse_to_first(copies.clone())feedsapplied_patches_with_vendor, which hashes one path per PURL for agent records.crates/socket-patch-cli/src/ecosystem_dispatch.rs:401:collapse_to_first.The same pattern probably hits every npm-family layout that can hold several copies of one version (yarn classic and bun hoisted, Deno's hoisted linker, pnpm peer variants), but this issue covers npm only.
Related but different: #325 (bundled copies, hosted in-run
--vex), #435 (pnpm global), #405 (bun isolated).