CodeAnalysis icon indicating copy to clipboard operation
CodeAnalysis copied to clipboard

无法进行安全扫描

Open liweihui1 opened this issue 2 years ago • 2 comments

1.执行结果:节点端SCM任务故障 NodeError: Error[203]: fatal: unable to access 'https://github.com/TCATools/rips-scanner.git/': I/O operation timed out -2022-05-11 09:27:32,974-INFO-util.logutil: start to run task: Rips开源版, execute_processes: ['analyze', 'datahandle'] -2022-05-11 09:27:34,619-INFO-util.logutil: 加载公共编译工具的环境变量... -2022-05-11 09:27:34,719-INFO-util.logutil: Initing 1 tools, please wait a minute ...

[Tools init]: 0%| | 0/1 [00:00<?, ?it/s] [Tools init]: 100%|███████████████████████████████████████████████████| 1/1 [00:01<00:00, 1.56s/it] [Tools init]: 100%|███████████████████████████████████████████████████| 1/1 [00:01<00:00, 1.56s/it] -2022-05-11 09:27:36,281-INFO-util.logutil: Initialize tools done.(use time: 1.56s) -2022-05-11 09:27:36,283-WARNING-task.taskmgr: 不是内置工具,使用自定义工具模块(No module named 'tool.rips') -2022-05-11 09:27:36,287-INFO-task.taskmgr: task start : <class 'task.model.analyze.AnalyzeTask'> -2022-05-11 09:27:36,287-INFO-task.sourcemgr: pre_analyze start. -2022-05-11 09:27:36,287-INFO-task.sourcemgr: start __checkout_source_dir. -2022-05-11 09:27:36,288-INFO-task.sourcemgr: 常规项目,直接拉取或复用本地缓存资源. -2022-05-11 09:27:37,958-INFO-task.sourcemgr: load_source_dir done. source_dir insert env. sourcedir: /home/iotmp/CodeAnalysis-main/client/data/sourcedirs/git_n10b5zkx -2022-05-11 09:27:37,961-INFO-task.sourcemgr: pre_analyze done. -2022-05-11 09:27:37,961-INFO-util.logutil: PATH =


/sbin /bin /usr/sbin /usr/bin


-2022-05-11 09:27:37,962-INFO-util.logutil: Codemetric only scans main code (exclude test_source, auto_generate_source, third_party_source). -2022-05-11 09:27:37,963-INFO-util.logutil: Codelint only cans main code. -2022-05-11 09:27:38,008-INFO-util.codecount.codestat: task params taskdir: /home/iotmp/CodeAnalysis-main/client/data/taskdirs/task_51 -2022-05-11 09:27:38,029-INFO-util.logutil: Load from git to /home/iotmp/CodeAnalysis-main/client/../tools/rips-scanner ... -2022-05-11 09:27:38,034-INFO-util.logutil: [文件数]过滤前:211,过滤后:147 -2022-05-11 09:27:38,036-INFO-util.logutil: ['/home/iotmp/CodeAnalysis-main/client/../tools/linux-scc/scc', '--by-file', '-c', '--no-cocomo', '-f', 'json', '-o', '/home/iotmp/CodeAnalysis-main/client/data/taskdirs/task_51/scc_result_8afb17a2d0c911ecbcaffa163e3dd509.json', '/home/iotmp/CodeAnalysis-main/client/data/sourcedirs/git_n10b5zkx'] -2022-05-11 09:27:38,122-INFO-util.logutil: results written to /home/iotmp/CodeAnalysis-main/client/data/taskdirs/task_51/scc_result_8afb17a2d0c911ecbcaffa163e3dd509.json -2022-05-11 09:27:38,171-INFO-util.codecount.repoter: 上报代码行数: {'code_line_num': 8612, 'comment_line_num': 1402, 'blank_line_num': 2308, 'total_line_num': 12322, 'filtered_code_line_num': 7374, 'filtered_comment_line_num': 748, 'filtered_blank_line_num': 2272, 'filtered_total_line_num': 10394, 'filtered_lang_count': {'Markdown': {'file_num': 1, 'code_line_num': 47, 'comment_line_num': 0, 'blank_line_num': 18, 'total_line_num': 65}, 'PHP': {'file_num': 111, 'code_line_num': 7174, 'comment_line_num': 629, 'blank_line_num': 2233, 'total_line_num': 10036}, 'Plain Text': {'file_num': 2, 'code_line_num': 17, 'comment_line_num': 0, 'blank_line_num': 7, 'total_line_num': 24}, 'HTML': {'file_num': 1, 'code_line_num': 19, 'comment_line_num': 12, 'blank_line_num': 2, 'total_line_num': 33}, 'JavaScript': {'file_num': 4, 'code_line_num': 51, 'comment_line_num': 39, 'blank_line_num': 8, 'total_line_num': 98}, 'CSS': {'file_num': 28, 'code_line_num': 66, 'comment_line_num': 68, 'blank_line_num': 4, 'total_line_num': 138}}} -2022-05-11 09:27:54,005-ERROR-util.pathlib: file not exist: /home/iotmp/CodeAnalysis-main/client/../tools/rips-scanner -2022-05-11 09:28:10,747-WARNING-task.puppytask: task status code is 203 -2022-05-11 09:28:10,748-WARNING-task.puppytask: task messsage: NodeError: Error[203]: fatal: unable to access 'https://github.com/TCATools/rips-scanner.git/': I/O operation timed out -2022-05-11 09:28:10,748-INFO-task.puppytask: task result: /home/iotmp/CodeAnalysis-main/client/data/taskdirs/task_51/task_response.json

执行结果:节点端本地扫描错误 TaskError: Error[226]: 第三方工具执行异常,未生成结果文件: /home/iotmp/CodeAnalysis-main/client/../tools/codedog_0Day_checker/result.json

-2022-05-11 09:20:54,863-INFO-util.logutil: start to run task: Tool_0DayChecker, execute_processes: ['analyze', 'datahandle'] -2022-05-11 09:20:57,691-INFO-util.logutil: 加载公共编译工具的环境变量... -2022-05-11 09:20:57,897-INFO-util.logutil: Initing 1 tools, please wait a minute ...

[Tools init]: 0%| | 0/1 [00:00<?, ?it/s] [Tools init]: 100%|███████████████████████████████████████████████████| 1/1 [00:01<00:00, 1.66s/it] [Tools init]: 100%|███████████████████████████████████████████████████| 1/1 [00:01<00:00, 1.66s/it] -2022-05-11 09:20:59,585-INFO-util.logutil: Initialize tools done.(use time: 1.69s) -2022-05-11 09:20:59,587-WARNING-task.taskmgr: 不是内置工具,使用自定义工具模块(No module named 'tool.codedog_0Day_checker') -2022-05-11 09:20:59,625-INFO-task.taskmgr: task start : <class 'task.model.analyze.AnalyzeTask'> -2022-05-11 09:20:59,625-INFO-task.sourcemgr: pre_analyze start. -2022-05-11 09:20:59,625-INFO-task.sourcemgr: start __checkout_source_dir. -2022-05-11 09:20:59,626-INFO-task.sourcemgr: 常规项目,直接拉取或复用本地缓存资源. -2022-05-11 09:21:01,518-INFO-task.sourcemgr: load_source_dir done. source_dir insert env. sourcedir: /home/iotmp/CodeAnalysis-main/client/data/sourcedirs/git_n10b5zkx -2022-05-11 09:21:01,522-INFO-task.sourcemgr: pre_analyze done. -2022-05-11 09:21:01,523-INFO-util.logutil: Codemetric only scans main code (exclude test_source, auto_generate_source, third_party_source). -2022-05-11 09:21:01,523-INFO-util.logutil: Codelint only cans main code. -2022-05-11 09:21:01,572-INFO-util.codecount.codestat: task params taskdir: /home/iotmp/CodeAnalysis-main/client/data/taskdirs/task_39 -2022-05-11 09:21:01,589-INFO-util.logutil: [文件数]过滤前:211,过滤后:147 -2022-05-11 09:21:01,590-INFO-util.logutil: ['/home/iotmp/CodeAnalysis-main/client/../tools/linux-scc/scc', '--by-file', '-c', '--no-cocomo', '-f', 'json', '-o', '/home/iotmp/CodeAnalysis-main/client/data/taskdirs/task_39/scc_result_9eae4784d0c811ec900afa163e3dd509.json', '/home/iotmp/CodeAnalysis-main/client/data/sourcedirs/git_n10b5zkx'] -2022-05-11 09:21:01,746-INFO-util.logutil: 获取需要扫描的文件 -2022-05-11 09:21:01,760-INFO-task.basic.common: /bin/sh: ./main.bin: 权限不够 -2022-05-11 09:21:01,850-INFO-util.logutil: use SubProcController run cmd: ./main.bin -2022-05-11 09:21:01,858-WARNING-task.puppytask: task status code is 226 -2022-05-11 09:21:01,859-WARNING-task.puppytask: task messsage: TaskError: Error[226]: 第三方工具执行异常,未生成结果文件: /home/iotmp/CodeAnalysis-main/client/../tools/codedog_0Day_checker/result.json -2022-05-11 09:21:01,859-INFO-task.puppytask: task result: /home/iotmp/CodeAnalysis-main/client/data/taskdirs/task_39/task_response.json -2022-05-11 09:21:01,900-INFO-util.logutil: results written to /home/iotmp/CodeAnalysis-main/client/data/taskdirs/task_39/scc_result_9eae4784d0c811ec900afa163e3dd509.json -2022-05-11 09:21:01,935-INFO-util.codecount.repoter: 上报代码行数: {'code_line_num': 8612, 'comment_line_num': 1402, 'blank_line_num': 2308, 'total_line_num': 12322, 'filtered_code_line_num': 7374, 'filtered_comment_line_num': 748, 'filtered_blank_line_num': 2272, 'filtered_total_line_num': 10394, 'filtered_lang_count': {'PHP': {'file_num': 111, 'code_line_num': 7174, 'comment_line_num': 629, 'blank_line_num': 2233, 'total_line_num': 10036}, 'HTML': {'file_num': 1, 'code_line_num': 19, 'comment_line_num': 12, 'blank_line_num': 2, 'total_line_num': 33}, 'JavaScript': {'file_num': 4, 'code_line_num': 51, 'comment_line_num': 39, 'blank_line_num': 8, 'total_line_num': 98}, 'Markdown': {'file_num': 1, 'code_line_num': 47, 'comment_line_num': 0, 'blank_line_num': 18, 'total_line_num': 65}, 'Plain Text': {'file_num': 2, 'code_line_num': 17, 'comment_line_num': 0, 'blank_line_num': 7, 'total_line_num': 24}, 'CSS': {'file_num': 28, 'code_line_num': 66, 'comment_line_num': 68, 'blank_line_num': 4, 'total_line_num': 138}}}

liweihui1 avatar May 11 '22 01:05 liweihui1

2 中 tools/codedog_0Day_checker 目录下main.bin权限不够,需给下执行权限

owlmk avatar May 11 '22 02:05 owlmk

1 中 好像是有git代理代码没有拉下来,可以试下在 管理入口 -> 工具管理 -> 找到 Rips开源版 -> 基础信息编辑 修改仓库地址为 http 或者 改为腾讯工蜂的代码库 http://git.code.tencent.com/TCA/tca-tools/rips-scanner.git 并配置相关凭证

owlmk avatar May 11 '22 02:05 owlmk