Repository navigation
Go settings written with go env -w are ignored: GOPRIVATE modules are requested from proxy.golang.org, a GOPROXY mirror is bypassed, and a GOMODCACHE cache is not found #344
Description
Activity
- addedbugSomething isn't workingSomething isn't workingbughuntFound by a scheduled package-manager bug-hunt agentFound by a scheduled package-manager bug-hunt agentpm:goGo modulesGo modules
on Sep 30, 2026 mikolalysenko commented
on Sep 30, 2026 CollaboratorAuthorMore actions[agent] Triaged:
priority:p2(Go modules). Not a duplicate, and no open or merged PR fixes it. Confirmed on mainf6b7fb9:goproxy_base(vendor/registry_fetch.rs) andget_gomodcache(crawlers/go_crawler.rs) readstd::env::varonly. All three symptoms (GOPRIVATE, GOPROXY and GOMODCACHE) come from one missing piece, a Go-env resolver (env →$GOENVfile unlessGOENV=off→ defaults) used by both call sites, so they belong in one fix. This is a different cause from #343.
Generated by Claude Code
mikolalysenko commented
on Oct 1, 2026 CollaboratorAuthorMore actions[agent] New information: this also breaks global mode, silently. On main
2463257(Linux, go 1.24.7, non-root), I rango env -w GOMODCACHE=$R/custom-cacheand thengo mod download example.com/upstream@v1.0.0.go env GOMODCACHEpoints at the custom cache, and the module is there.socket-patch scan -g --json --ecosystems golang→ exit 0,"status": "success",scannedPackages: 0. A module with a patch is reported as nothing to patch, with no warning.socket-patch get -g pkg:golang/example.com/upstream@v1.0.0→ exit 1, "matched no installed package" (loud, at least).
GoCrawler::get_gomodcache(crates/socket-patch-core/src/crawlers/go_crawler.rs:209) reads only theGOMODCACHE/GOPATH/HOMEenv vars and never the GOENV file, so the report-only global scan misses the user's real cache.
Generated by Claude Code
- addedv5-blockerMust resolve before v5: public interface/migration or ordinary patch-install-undo failure.Must resolve before v5: public interface/migration or ordinary patch-install-undo failure.compatibilityPublic CLI/JSON, saved state, upgrades, or package-manager compatibility.Public CLI/JSON, saved state, upgrades, or package-manager compatibility.and removed
on Oct 8, 2026 mikolalysenko commented
on Oct 9, 2026 CollaboratorAuthorMore actionsv5 release blocker (P1). Honor the Go configuration users set with go env -w; a normal scan must not bypass their proxy/private-module settings.
This follows the maintainer's release scope: one normally completing CLI instance, prioritizing valid-lockfile patch/install behavior, compatibility, and actionable CLI UX.
mikolalysenko commented
on Oct 9, 2026 CollaboratorAuthorMore actions[agent] Claiming for v5 blocker burn-down (shared root cause: Go settings resolved only from process env, never from the GOENV file). Branch: agent/v5-go-env-file. Claim-ID: 2026-10-09T16:41:32Z-3cf085
[agent] Found by the scheduled Go modules bug-hunt routine (ledger #317).
Summary
socket-patch reads Go settings only from the process environment. It ignores the Go environment file that
go env -wwrites ($GOENV, by default~/.config/go/env,~/Library/Application Support/go/env,%AppData%\go\env).go env -wis how Go's own docs tell users to setGOPRIVATEandGOPROXY. So when those settings live in that file:GOPRIVATE/GONOPROXYset withgo env -w→ the private module path goes toproxy.golang.org.vendoron a cold cache fetcheshttps://proxy.golang.org/<private module>/@v/<ver>.zip. With the same value as an env var, it correctly refuses (matches GOPRIVATE … not fetching it, the Stop hosted Go redirects claiming unpatched deps #252 B11 fix).goitself never contacts a proxy for these modules. Keeping private module paths away from the public proxy is exactly what GOPRIVATE is for.GOPROXYset withgo env -w(a corporate mirror) is bypassed. socket-patch fetches fromproxy.golang.orginstead. The mirror sees 0 requests whilego buildon the same machine fetches everything from it. In a firewalled or mirror-only network, vendoring fails (vendor_fetch_failed).GOMODCACHE/GOPATHset withgo env -w→ installed modules aren't found.go env GOMODCACHEandgo builduse the configured cache, butapplycrawls$HOME/go/pkg/modand reportsThe targeted manifest patch matched no installed package … 1 not found on disk(exit 1;package_not_installedin--json).Repro (hermetic; example.com/upstream served from a local HTTP "mirror")
Expected vs actual
goproxy_basesays it returns "the module proxy go itself would ask formodule, orErrwhen go would not use a proxy for it … Falling back to a public proxy there would send a private module path off the machine". The crawler should find the cachego env GOMODCACHEnames. Go resolves each variable from the environment first, then from theGOENVfile, then defaults.std::env::varis consulted, so ago env -wconfiguration silently falls back to the defaults (proxy.golang.org,$HOME/go/pkg/mod).Matrix (probe run https://github.com/SocketDev/socket-patch/actions/runs/36746894687, plus local)
go env -wgo env -wThe GOPROXY-mirror bypass was reproduced locally twice on Linux. The GOMODCACHE miss is the same in 4.0.0. In 4.0.0 even the env-var GOPRIVATE control leaks (fixed on main by #252).
Suspect code
crates/socket-patch-core/src/vendor/registry_fetch.rs:1270goproxy_base:std::env::varforSOCKET_GOPROXY,GONOPROXY,GOPRIVATE,GOPROXYonly.crates/socket-patch-core/src/crawlers/go_crawler.rs:209get_gomodcache:GOMODCACHE→GOPATH→$HOME/gofrom the env only. It needs theGOENVfile (or ago env -jsonfallback whengois on PATH) between env and defaults. NoteGOENV=offdisables the file.Backlog review — 2026-10-08
Priority: P2 → P1. Ignoring persisted GOPRIVATE can disclose private module names to a public proxy; also bypasses configured infrastructure.