github / github/codeql

codeql pack publish fails with confusing SocketException when token lacks permission

Aperta
#14,104 6 commenti 0 reazioni 0 assegnatari Vedi su GitHub
CodeQL packaging enhancement good first issue
Lingua principale
CodeQL
Stelle
10.1k
Fork
2.1k
Merge medio
2g 15h
PR unite (30g)
141

Descrizione

When publishing a codeql pack using `codeql pack publish` and the GitHub token lacks the `write:packages` scope, the following error will be shown:

```
Aug 30, 2023 8:15:17 AM org.apache.http.impl.execchain.RetryExec execute
INFO: I/O exception (java.net.SocketException) caught when processing request to {s}->https://ghcr.io:443: An established connection was aborted by the software in your host machine
Aug 30, 2023 8:15:17 AM org.apache.http.impl.execchain.RetryExec execute
INFO: Retrying request to {s}->https://ghcr.io:443
Aug 30, 2023 8:15:17 AM org.apache.http.impl.execchain.RetryExec execute
INFO: I/O exception (java.net.SocketException) caught when processing request to {s}->https://ghcr.io:443: An established connection was aborted by the software in your host machine
Aug 30, 2023 8:15:17 AM org.apache.http.impl.execchain.RetryExec execute
INFO: Retrying request to {s}->https://ghcr.io:443
Aug 30, 2023 8:15:18 AM org.apache.http.impl.execchain.RetryExec execute
INFO: I/O exception (java.net.SocketException) caught when processing request to {s}->https://ghcr.io:443: An established connection was aborted by the software in your host machine
Aug 30, 2023 8:15:18 AM org.apache.http.impl.execchain.RetryExec execute
INFO: Retrying request to {s}->https://ghcr.io:443
A fatal error occurred: Could not upload blob asurion/asurion-java-queries@0.1.0.
```

The error `An established connection was aborted by software in your host machine` makes it seem as though a firewall or antivirus tool blocked the publish. Instead, the shown error message should mention that access was denied.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Reproduce `codeql pack publish` with a token lacking the `write:packages` scope and compare the displayed SocketException with the requested access-denied behavior. Trace the publish command's upload error handling; done means the failure identifies insufficient package permission rather than suggesting a local firewall problem.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
github
Ambito
devtools, security
Tipo di issue
Bug
Difficoltà
3/5
Tempo stimato
1-2 giorni
Stato di attività
Tranquilla
Chiarezza
Abbastanza chiara
Idoneità per principianti
42/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.