release v0.9.4: drift unblock, fragnesia range fix, infra docs
release / build (arm64) (push) Waiting to run
release / build (x86_64) (push) Waiting to run
release / build (x86_64-static / musl) (push) Waiting to run
release / build (arm64-static / musl) (push) Waiting to run
release / release (push) Blocked by required conditions

- Sync docs/CVE_METADATA.json + KEV_CROSSREF.md to match the
  hand-applied core/cve_metadata.c entries from v0.9.3. Nightly
  drift-check (red since 2026-05-25) now passes. Pintheft's CWE
  landed as CWE-787 from NVD (was NULL in the hand-applied entry).
- Fix fragnesia (CVE-2026-46300) range table. Per NVD: bug entered
  at 5.11 SKBFL_SHARED_FRAG, vulnerable through 5.15.207 / 6.1.173 /
  6.6.140 / 6.12.90 / 6.18.32 / 7.0.9, fixed at .208/.174/.141/
  .91/.33/.10. Prior table had one entry {7,0,9} — off-by-one and
  missing every other backport. Added predates-5.11 introduction gate
  + test row.
- Update tools/verify-vm/README.md to document the v0.9.x infra:
  mainline kernel pinning via kernel.ubuntu.com, per-module
  provisioner hooks, two-phase prep→reboot→verify with post-reboot
  kernel confirmation, GRUB_DEFAULT pinning.
- Add curl fallback for NVD lookups in refresh-cve-metadata.py.
  Mirrors the CISA path's existing fallback. Prevents the silent
  Python urlopen hang seen during v0.9.3 prep (55-min stuck on
  CLOSE_WAIT socket; 30s timeout never fired).
This commit is contained in:
KaraZajac
2026-05-28 13:33:28 -04:00
parent fa0228df9b
commit 4454d8148e
11 changed files with 347 additions and 113 deletions
+24 -4
View File
@@ -118,18 +118,38 @@ def fetch_kev_catalog() -> dict[str, str]:
def fetch_nvd_cwe(cve: str) -> tuple[str | None, str | None]:
"""Return (cwe_id, description) from NVD. Returns (None, None) on miss."""
"""Return (cwe_id, description) from NVD. Returns (None, None) on miss.
Same urlopen-hangs-silently pattern as the CISA fetch: NVD's HTTP/2
endpoint sometimes leaves Python sockets in CLOSE_WAIT forever even
though the 30s timeout should have fired (observed on macOS 2026-05-24,
process hung 55+ minutes). We try urlopen first, then fall back to
curl --max-time which honors the wall clock reliably."""
url = NVD_URL.format(cve=cve)
req = urllib.request.Request(url, headers={"User-Agent": "skeletonkey-cve-metadata/1"})
blob = None
try:
with urllib.request.urlopen(req, timeout=30) as r:
blob = json.loads(r.read().decode("utf-8"))
except urllib.error.HTTPError as e:
print(f"[!] NVD HTTP {e.code} for {cve}", file=sys.stderr)
return None, None
except (urllib.error.URLError, json.JSONDecodeError) as e:
print(f"[!] NVD parse error for {cve}: {e}", file=sys.stderr)
return None, None
except (urllib.error.URLError, json.JSONDecodeError, TimeoutError) as e:
print(f"[!] NVD urlopen failed for {cve} ({e}); trying curl", file=sys.stderr)
if blob is None:
import subprocess
try:
raw = subprocess.check_output(
["curl", "-fsSL", "--max-time", "20",
"-H", "User-Agent: skeletonkey-cve-metadata/1",
url],
stderr=subprocess.DEVNULL,
)
blob = json.loads(raw.decode("utf-8"))
except (subprocess.CalledProcessError, FileNotFoundError,
json.JSONDecodeError) as e:
print(f"[!] NVD curl fallback failed for {cve}: {e}", file=sys.stderr)
return None, None
vulns = blob.get("vulnerabilities") or []
if not vulns:
return None, None