Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
14 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
test(hosted): accept the new CVE-2022-21831 activestorage patch in GE…
…M_UUIDS

Production extended pkg:gem/activestorage@6.0.3 with a second advisory's
patch on 2026-08-19T21:19Z (GHSA-w749-p3v6-hccq / CVE-2022-21831, uuid
6c4141c5-1535-4fd2-9db1-b5f8e4834bdb) and the server-ranked hosted
selection now wires it, failing the pinned any-of assert exactly as
designed. The new patch was live-verified before extending the pin: the
served .gem matches the /info checksum, carries the Socket patch header
in image_processing_transformer.rb, and every other file is
byte-identical to stock rubygems 6.0.3. Both advisories' uuids stay in
the set (the batch API still publishes both).

Verified live: preflight_required_patches_are_published +
gem_bundler_hosted_install_proof green against production.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
  • Loading branch information
mikolalysenko and claude committed Aug 20, 2026
commit f842a21e8b5f8bdd539c74ce1c7ecbfbe3589231
15 changes: 13 additions & 2 deletions crates/socket-patch-cli/tests/e2e_hosted_production.rs
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@
//! | npm | `pkg:npm/minimist@1.2.2` | `80630680-4da6-45f9-bba8-b888e0ffd58c` | GHSA-xvch-5gv4-984h (CVE-2021-44906) |
//! | PyPI | `pkg:pypi/urllib3@1.26.18` | *any of three* (see [`PYPI_UUIDS`]) | GHSA-gm62-xv2j-4w53 &co |
//! | Cargo | `pkg:cargo/traitobject@0.1.1` | `cf2e6f58-d9fa-4096-9151-c34afa717f89` | GHSA-pp8r-vv2j-9j5v |
//! | gem | `pkg:gem/activestorage@6.0.3` | *any of* [`GEM_UUIDS`] (one today) | GHSA-m42x-37p3-fv5w (CVE-2020-8162) |
//! | gem | `pkg:gem/activestorage@6.0.3` | *any of* [`GEM_UUIDS`] (two today) | GHSA-m42x-37p3-fv5w (CVE-2020-8162), GHSA-w749-p3v6-hccq (CVE-2022-21831) |
//!
//! `docs/testing/hosted-production-e2e.md` explains how these were chosen and
//! how to re-pick one if it is ever withdrawn.
Expand Down Expand Up @@ -144,7 +144,18 @@ const GEM_VERSION: &str = "6.0.3";
/// Gemfile, asserts it is one of these, and content-verifies against that
/// exact patch's `/patch/view` manifest. When production publishes another
/// acceptable 6.0.3 patch, verify it and append its UUID here.
const GEM_UUIDS: &[&str] = &["15e960b5-f432-4b6c-b8aa-534a2b419323"];
const GEM_UUIDS: &[&str] = &[
// GHSA-m42x-37p3-fv5w / CVE-2020-8162 (s3_service.rb), from the
// 2026-08-18 catalog republish.
"15e960b5-f432-4b6c-b8aa-534a2b419323",
// GHSA-w749-p3v6-hccq / CVE-2022-21831 (image_processing_transformer.rb),
// published 2026-08-19T21:19Z when production re-extended 6.0.3 with the
// second advisory; the server-ranked selection now wires this one.
// Content live-verified 2026-08-20: served .gem matches the /info
// checksum, carries the Socket patch header in the transformer, and every
// other file is byte-identical to stock rubygems 6.0.3.
"6c4141c5-1535-4fd2-9db1-b5f8e4834bdb",
];

/// Header the patch service injects into patched npm / PyPI source files.
const PATCH_MARKER: &str = "Socket Community Patch";
Expand Down
2 changes: 1 addition & 1 deletion docs/testing/hosted-production-e2e.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ from the child environment.
| npm | `pkg:npm/minimist@1.2.2` | `80630680-4da6-45f9-bba8-b888e0ffd58c` | GHSA-xvch-5gv4-984h / CVE-2021-44906 | all five npm-family legs |
| PyPI | `pkg:pypi/urllib3@1.26.18` | `de58c8b8-796c-4b6d-8a48-539b5563db76`, `26242e35-f867-4da8-8789-f0d2ea49e0f1`, `e828efa5-5c6d-43f3-9909-03f5ac232b98` | GHSA-38jv-5279-wg99, GHSA-2xpw-w6gg-jr37, GHSA-gm62-xv2j-4w53 | requirements.txt, uv.lock |
| Cargo | `pkg:cargo/traitobject@0.1.1` | `cf2e6f58-d9fa-4096-9151-c34afa717f89` | GHSA-pp8r-vv2j-9j5v | cargo sparse-registry leg |
| RubyGems | `pkg:gem/activestorage@6.0.3` | `15e960b5-f432-4b6c-b8aa-534a2b419323` | GHSA-m42x-37p3-fv5w / CVE-2020-8162 | bundler leg |
| RubyGems | `pkg:gem/activestorage@6.0.3` | any of `15e960b5-f432-4b6c-b8aa-534a2b419323` (GHSA-m42x-37p3-fv5w / CVE-2020-8162), `6c4141c5-1535-4fd2-9db1-b5f8e4834bdb` (GHSA-w749-p3v6-hccq / CVE-2022-21831, published 2026-08-19) | see UUID column | bundler leg |

urllib3 1.26.18 carries **three** distinct free patches, one per advisory. Which
one the resolver returns is a server-side ordering detail, so the suite accepts
Expand Down
Loading