Skip to content

Go settings written with go env -w are ignored: GOPRIVATE modules are requested from proxy.golang.org, a GOPROXY mirror is bypassed, and a GOMODCACHE cache is not found #344

Description

[agent] Found by the scheduled Go modules bug-hunt routine (ledger #317).

Summary

socket-patch reads Go settings only from the process environment. It ignores the Go environment file that go env -w writes ($GOENV, by default ~/.config/go/env, ~/Library/Application Support/go/env, %AppData%\go\env). go env -w is how Go's own docs tell users to set GOPRIVATE and GOPROXY. So when those settings live in that file:

  1. GOPRIVATE / GONOPROXY set with go env -w → the private module path goes to proxy.golang.org. vendor on a cold cache fetches https://proxy.golang.org/<private module>/@v/<ver>.zip. With the same value as an env var, it correctly refuses (matches GOPRIVATE … not fetching it, the Stop hosted Go redirects claiming unpatched deps #252 B11 fix). go itself never contacts a proxy for these modules. Keeping private module paths away from the public proxy is exactly what GOPRIVATE is for.
  2. GOPROXY set with go env -w (a corporate mirror) is bypassed. socket-patch fetches from proxy.golang.org instead. The mirror sees 0 requests while go build on the same machine fetches everything from it. In a firewalled or mirror-only network, vendoring fails (vendor_fetch_failed).
  3. GOMODCACHE / GOPATH set with go env -w → installed modules aren't found. go env GOMODCACHE and go build use the configured cache, but apply crawls $HOME/go/pkg/mod and reports The targeted manifest patch matched no installed package … 1 not found on disk (exit 1; package_not_installed in --json).

Repro (hermetic; example.com/upstream served from a local HTTP "mirror")

# fresh machine: empty cache, settings written the way the Go docs recommend
export GOENV=$T/goenv GOMODCACHE=$T/cold/modcache GOFLAGS= ; unset GOPROXY GOPRIVATE
go env -w GOPROXY=http://127.0.0.1:18702 GOSUMDB=off GOPRIVATE=example.com
socket-patch vendor --ecosystems golang --json
#  "errorCode": "vendor_fetch_failed",
#  "error": "GET https://proxy.golang.org/example.com/upstream/@v/v1.0.0.zip: HTTP 404 Not Found"
#  (the private path left the machine; the local mirror log shows 0 requests)

# control: the same values as real env vars
GOPRIVATE=example.com socket-patch vendor --ecosystems golang --json
#  "reason": "example.com/upstream matches GOPRIVATE, so go fetches it directly, never through a module proxy; not fetching it …"

# GOMODCACHE
go env -w GOMODCACHE=$T/modcache GOPROXY=file://$T/proxy; unset GOMODCACHE
go env GOMODCACHE && go build ./...                # the configured cache, build ok
socket-patch apply --offline --ecosystems golang   # "matched no installed package", exit 1

Expected vs actual

  • Expected: goproxy_base says it returns "the module proxy go itself would ask for module, or Err when go would not use a proxy for it … Falling back to a public proxy there would send a private module path off the machine". The crawler should find the cache go env GOMODCACHE names. Go resolves each variable from the environment first, then from the GOENV file, then defaults.
  • Actual: only std::env::var is consulted, so a go env -w configuration silently falls back to the defaults (proxy.golang.org, $HOME/go/pkg/mod).

Matrix (probe run https://github.com/SocketDev/socket-patch/actions/runs/36746894687, plus local)

OS go GOPRIVATE via go env -w GOMODCACHE via go env -w env-var control
Linux 1.16.15, 1.21.13, 1.24.7 (local), 1.26.3 fail (proxy.golang.org GET) fail pass
macOS 1.24.13, 1.26.3 fail fail pass
Windows 1.16.15, 1.21.13, 1.26.3 fail fail pass

The GOPROXY-mirror bypass was reproduced locally twice on Linux. The GOMODCACHE miss is the same in 4.0.0. In 4.0.0 even the env-var GOPRIVATE control leaks (fixed on main by #252).

Suspect code

  • crates/socket-patch-core/src/vendor/registry_fetch.rs:1270 goproxy_base: std::env::var for SOCKET_GOPROXY, GONOPROXY, GOPRIVATE, GOPROXY only.
  • crates/socket-patch-core/src/crawlers/go_crawler.rs:209 get_gomodcache: GOMODCACHE → GOPATH → $HOME/go from the env only. It needs the GOENV file (or a go env -json fallback when go is on PATH) between env and defaults. Note GOENV=off disables the file.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:triagedbugSomething isn't workingbughuntFound by a scheduled package-manager bug-hunt agentpm:goGo modulespriority:p2

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions