Skip to content

Agent-mode npm vex hashes only the first installed copy of a package, so it attests not_affected while another nested copy of the same name@version is unpatched #516

Description

[agent] Found by the scheduled npm bug-hunt routine (ledger #302).

Summary

In agent mode, vex checks only the first installed copy of each manifest PURL (crates/socket-patch-cli/src/commands/vex.rs:556, let package_paths = collapse_to_first(copies.clone());). Hosted-basis PURLs are checked against every copy (vex_consumed::hosted_consumed_copies), but agent records are not. When an npm tree holds several nested copies of the same name@version and only some of them are patched, the verdict depends on crawl order:

  • first copy patched, another copy unpatched → not_affected (wrong);
  • first copy unpatched, another copy patched → not_applied (right, by luck).

The Deno routine found this (handover on #302). I confirmed it with plain npm, where the trigger is common: apply patches every copy present, and a later npm install of a new dependent extracts a fresh, unpatched nested copy while leaving the patched one alone.

Impact

The VEX document says not_affected while an unpatched copy of the vulnerable code is still in node_modules and gets loaded by its dependent (is-accessor-descriptor here). apply is fine: re-running it patches the new copy. Only the attestation is wrong.

Repro (real npm, Linux, main 61cfb9b)

SP=/path/to/target/release/socket-patch
mkdir npmdup && cd npmdup && echo '{"name":"npmdup","version":"1.0.0"}' > package.json
npm install kind-of@6.0.3 is-number@3.0.0      # nests kind-of@3.2.2 under is-number
# Hand-stage .socket/manifest.json + .socket/blobs with a patch for pkg:npm/kind-of@3.2.2
# that changes package/index.js (beforeHash = pristine, afterHash = pristine + a comment line),
# with one vulnerability carrying a CVE. Any free patch works too.
$SP apply --offline                            # 1 of 1 targeted patch applied
npm install is-accessor-descriptor@0.1.6       # adds is-accessor-descriptor/node_modules/kind-of@3.2.2, unpatched
$SP vex --offline -O v.json; echo $?           # exit 0, 1 statement: not_affected

State after the second install:

node_modules/is-number/node_modules/kind-of              3.2.2 patched
node_modules/is-accessor-descriptor/node_modules/kind-of 3.2.2 UNPATCHED
node_modules/kind-of                                     6.0.3 (not targeted)

vex output: Wrote OpenVEX document with 1 statement to v.json, status not_affected.

Crawl-order check on the same tree: restore the is-number copy to pristine and patch the is-accessor-descriptor copy instead, and vex omits the PURL (not_applied) and exits with "No applied patches with vulnerability metadata to attest."

Expected vs actual

  • Expected: CLI_CONTRACT.md's verification table (crates/socket-patch-cli/CLI_CONTRACT.md:390) says an agent record is verified against "the installed tree". An attestation should hold only when every installed copy the crawler finds for that PURL hashes to the patched bytes, as the hosted path already requires. Otherwise the PURL should be omitted (not_applied / hash_mismatch).
  • Actual: only the first copy is hashed, and not_affected is emitted with exit 0.

Matrix

OS npm Node main 61cfb9b v4.0.0 (with setup.manual: ["npm"])
Linux 8.19.4 22.22 reproduces not run
Linux 10.9.4 22.22 reproduces (2/2) reproduces
Linux 12.2.0 22.22 reproduces not run
macOS / Windows — — not probed (the logic isn't OS-specific) —

First bad version

This isn't a v5 regression: v4.0.0 emits the same single not_affected statement once setup.manual is set. I didn't bisect further.

Suspect code

  • crates/socket-patch-cli/src/commands/vex.rs:556: collapse_to_first(copies.clone()) feeds applied_patches_with_vendor, which hashes one path per PURL for agent records.
  • crates/socket-patch-cli/src/ecosystem_dispatch.rs:401: collapse_to_first.

The same pattern probably hits every npm-family layout that can hold several copies of one version (yarn classic and bun hoisted, Deno's hoisted linker, pnpm peer variants), but this issue covers npm only.

Related but different: #325 (bundled copies, hosted in-run --vex), #435 (pnpm global), #405 (bun isolated).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions