56f9e4d0dc
build / build (clang / debug) (push) Waiting to run
build / build (clang / default) (push) Waiting to run
build / build (gcc / debug) (push) Waiting to run
build / build (gcc / default) (push) Waiting to run
build / sanitizers (ASan + UBSan) (push) Waiting to run
build / clang-tidy (push) Waiting to run
build / drift-check (CISA KEV + Debian tracker) (push) Waiting to run
build / static-build (push) Waiting to run
release / build (arm64) (push) Waiting to run
release / build (x86_64) (push) Waiting to run
release / build (x86_64-static / musl) (push) Waiting to run
release / build (arm64-static / musl) (push) Waiting to run
release / release (push) Blocked by required conditions
Bumps 0.9.14 -> 0.10.0 (skeletonkey.c, README, docs/index.html) and prepends v0.10.0 release notes. Milestone: the corpus moved from detect-verified to out-of-band exploit-verified. 11 modules confirmed landing uid=0 in a VM (witnessed independently, never self-reported); four modules that falsely reported EXPLOIT_OK without ever getting root were fixed (pwnkit, ptrace_traceme, dirty_pipe, dirty_cow); a full false-EXPLOIT_OK audit was closed (every success claim now backed by a real out-of-band check). New/rewritten working exploits: ptrace_traceme, sudo_samedit, overlayfs_setuid (libfuse), dirty_pipe, dirty_cow. Plus fixes to a systemic userns uid_map bug, the kptr_restrict offset resolver, a su-over-pty hang, a readback buffer overflow, and an old-header portability issue; overlayfs upgraded to a direct uid=0 witness. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0118iUgHY44hdRtANgyCmu7y