You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Go settings written with go env -w are ignored: GOPRIVATE modules are requested from proxy.golang.org, a GOPROXY mirror is bypassed, and a GOMODCACHE cache is not found #344
[agent] Found by the scheduled Go modules bug-hunt routine (ledger #317).
Summary
socket-patch reads Go settings only from the process environment. It ignores the Go environment file that go env -w writes ($GOENV, by default ~/.config/go/env, ~/Library/Application Support/go/env, %AppData%\go\env). go env -w is how Go's own docs tell users to set GOPRIVATE and GOPROXY. So when those settings live in that file:
GOPRIVATE / GONOPROXY set with go env -w → the private module path goes to proxy.golang.org.vendor on a cold cache fetches https://proxy.golang.org/<private module>/@v/<ver>.zip. With the same value as an env var, it correctly refuses (matches GOPRIVATE … not fetching it, the Stop hosted Go redirects claiming unpatched deps #252 B11 fix). go itself never contacts a proxy for these modules. Keeping private module paths away from the public proxy is exactly what GOPRIVATE is for.
GOPROXY set with go env -w (a corporate mirror) is bypassed. socket-patch fetches from proxy.golang.org instead. The mirror sees 0 requests while go build on the same machine fetches everything from it. In a firewalled or mirror-only network, vendoring fails (vendor_fetch_failed).
GOMODCACHE / GOPATH set with go env -w → installed modules aren't found.go env GOMODCACHE and go build use the configured cache, but apply crawls $HOME/go/pkg/mod and reports The targeted manifest patch matched no installed package … 1 not found on disk (exit 1; package_not_installed in --json).
Repro (hermetic; example.com/upstream served from a local HTTP "mirror")
# fresh machine: empty cache, settings written the way the Go docs recommendexport GOENV=$T/goenv GOMODCACHE=$T/cold/modcache GOFLAGS= ;unset GOPROXY GOPRIVATE
go env -w GOPROXY=http://127.0.0.1:18702 GOSUMDB=off GOPRIVATE=example.com
socket-patch vendor --ecosystems golang --json
# "errorCode": "vendor_fetch_failed",# "error": "GET https://proxy.golang.org/example.com/upstream/@v/v1.0.0.zip: HTTP 404 Not Found"# (the private path left the machine; the local mirror log shows 0 requests)# control: the same values as real env vars
GOPRIVATE=example.com socket-patch vendor --ecosystems golang --json
# "reason": "example.com/upstream matches GOPRIVATE, so go fetches it directly, never through a module proxy; not fetching it …"# GOMODCACHE
go env -w GOMODCACHE=$T/modcache GOPROXY=file://$T/proxy;unset GOMODCACHE
go env GOMODCACHE && go build ./... # the configured cache, build ok
socket-patch apply --offline --ecosystems golang # "matched no installed package", exit 1
Expected vs actual
Expected:goproxy_base says it returns "the module proxy go itself would ask for module, or Err when go would not use a proxy for it … Falling back to a public proxy there would send a private module path off the machine". The crawler should find the cache go env GOMODCACHE names. Go resolves each variable from the environment first, then from the GOENV file, then defaults.
Actual: only std::env::var is consulted, so a go env -w configuration silently falls back to the defaults (proxy.golang.org, $HOME/go/pkg/mod).
The GOPROXY-mirror bypass was reproduced locally twice on Linux. The GOMODCACHE miss is the same in 4.0.0. In 4.0.0 even the env-var GOPRIVATE control leaks (fixed on main by #252).
Suspect code
crates/socket-patch-core/src/vendor/registry_fetch.rs:1270goproxy_base: std::env::var for SOCKET_GOPROXY, GONOPROXY, GOPRIVATE, GOPROXY only.
crates/socket-patch-core/src/crawlers/go_crawler.rs:209get_gomodcache: GOMODCACHE → GOPATH → $HOME/go from the env only. It needs the GOENV file (or a go env -json fallback when go is on PATH) between env and defaults. Note GOENV=off disables the file.
[agent] Found by the scheduled Go modules bug-hunt routine (ledger #317).
Summary
socket-patch reads Go settings only from the process environment. It ignores the Go environment file that
go env -wwrites ($GOENV, by default~/.config/go/env,~/Library/Application Support/go/env,%AppData%\go\env).go env -wis how Go's own docs tell users to setGOPRIVATEandGOPROXY. So when those settings live in that file:GOPRIVATE/GONOPROXYset withgo env -w→ the private module path goes toproxy.golang.org.vendoron a cold cache fetcheshttps://proxy.golang.org/<private module>/@v/<ver>.zip. With the same value as an env var, it correctly refuses (matches GOPRIVATE … not fetching it, the Stop hosted Go redirects claiming unpatched deps #252 B11 fix).goitself never contacts a proxy for these modules. Keeping private module paths away from the public proxy is exactly what GOPRIVATE is for.GOPROXYset withgo env -w(a corporate mirror) is bypassed. socket-patch fetches fromproxy.golang.orginstead. The mirror sees 0 requests whilego buildon the same machine fetches everything from it. In a firewalled or mirror-only network, vendoring fails (vendor_fetch_failed).GOMODCACHE/GOPATHset withgo env -w→ installed modules aren't found.go env GOMODCACHEandgo builduse the configured cache, butapplycrawls$HOME/go/pkg/modand reportsThe targeted manifest patch matched no installed package … 1 not found on disk(exit 1;package_not_installedin--json).Repro (hermetic; example.com/upstream served from a local HTTP "mirror")
Expected vs actual
goproxy_basesays it returns "the module proxy go itself would ask formodule, orErrwhen go would not use a proxy for it … Falling back to a public proxy there would send a private module path off the machine". The crawler should find the cachego env GOMODCACHEnames. Go resolves each variable from the environment first, then from theGOENVfile, then defaults.std::env::varis consulted, so ago env -wconfiguration silently falls back to the defaults (proxy.golang.org,$HOME/go/pkg/mod).Matrix (probe run https://github.com/SocketDev/socket-patch/actions/runs/36746894687, plus local)
go env -wgo env -wThe GOPROXY-mirror bypass was reproduced locally twice on Linux. The GOMODCACHE miss is the same in 4.0.0. In 4.0.0 even the env-var GOPRIVATE control leaks (fixed on main by #252).
Suspect code
crates/socket-patch-core/src/vendor/registry_fetch.rs:1270goproxy_base:std::env::varforSOCKET_GOPROXY,GONOPROXY,GOPRIVATE,GOPROXYonly.crates/socket-patch-core/src/crawlers/go_crawler.rs:209get_gomodcache:GOMODCACHE→GOPATH→$HOME/gofrom the env only. It needs theGOENVfile (or ago env -jsonfallback whengois on PATH) between env and defaults. NoteGOENV=offdisables the file.