mirror of
https://github.com/speed47/spectre-meltdown-checker.git
synced 2026-09-12 22:03:58 +02:00
Compare commits
16
Commits
master
..
03cc4ffeb1
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
03cc4ffeb1 | ||
|
|
1ce22924f3 | ||
|
|
1db12cd347 | ||
|
|
c107f2b2ea | ||
|
|
c277a7a443 | ||
|
|
68116d87fd | ||
|
|
c060a2d2c9 | ||
|
|
fe0d3f49f4 | ||
|
|
73b67b4a80 | ||
|
|
ea6b8efd18 | ||
|
|
24d92540a7 | ||
|
|
553a9ec60f | ||
|
|
75ad60f42a | ||
|
|
931c955765 | ||
|
|
c5ef0c488a | ||
|
|
99301d1cbb |
@@ -1,41 +0,0 @@
|
||||
name: autoupdate
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
schedule:
|
||||
- cron: '42 9 * * *'
|
||||
|
||||
permissions:
|
||||
pull-requests: write
|
||||
contents: write
|
||||
|
||||
jobs:
|
||||
autoupdate:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
ref: source
|
||||
- name: Install prerequisites
|
||||
run: sudo apt-get update && sudo apt-get install -y --no-install-recommends iucode-tool sqlite3 unzip shfmt
|
||||
- name: Update microcode versions
|
||||
run: ./scripts/update_mcedb.sh
|
||||
- name: Update Intel models
|
||||
run: ./scripts/update_intel_models.sh
|
||||
- name: Check git diff
|
||||
id: diff
|
||||
run: |
|
||||
echo change="$(git diff | awk '/MCEDB/ { if(V) { print V" to "$4; exit } else { V=$4 } }')" >> "$GITHUB_OUTPUT"
|
||||
echo nbdiff="$(git diff | grep -cE -- '^\+# [AI],')" >> "$GITHUB_OUTPUT"
|
||||
git diff
|
||||
cat "$GITHUB_OUTPUT"
|
||||
- name: Create Pull Request if needed
|
||||
if: steps.diff.outputs.nbdiff != '0'
|
||||
uses: peter-evans/create-pull-request@v7
|
||||
with:
|
||||
branch: autoupdate-fwdb
|
||||
commit-message: "update: fwdb from ${{ steps.diff.outputs.change }}, ${{ steps.diff.outputs.nbdiff }} microcode changes"
|
||||
title: "[Auto] Update fwdb from ${{ steps.diff.outputs.change }}"
|
||||
body: |
|
||||
Automated PR to update fwdb from ${{ steps.diff.outputs.change }}
|
||||
Detected ${{ steps.diff.outputs.nbdiff }} microcode changes
|
||||
@@ -1,181 +0,0 @@
|
||||
name: release
|
||||
|
||||
# Manual, path-scoped release helper for master.
|
||||
#
|
||||
# `master` is BOTH the distribution branch (users download the script here)
|
||||
# AND the default branch that hosts the scheduled CI workflows
|
||||
# (autoupdate / stale / vuln-watch). `source-build` is a build-OUTPUT branch.
|
||||
#
|
||||
# We therefore never merge source-build into master: that would drag source-build's
|
||||
# whole tree, including the *absence* of the master-only workflows.
|
||||
# Instead we copy only the assembled artifact files across, and cut GitHub
|
||||
# releases from master directly.
|
||||
#
|
||||
# Two independent manual actions to run against the `master` branch:
|
||||
#
|
||||
# 1. sync-from-source-build : open a PR against master carrying the assembled
|
||||
# files (everything on source-build EXCEPT
|
||||
# .github/). Nothing lands on master until the PR
|
||||
# is reviewed and merged.
|
||||
# 2. draft-github-release : create a DRAFT GitHub release from the script
|
||||
# currently on master, with an auto-drafted
|
||||
# changelog.
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
action:
|
||||
description: What to do
|
||||
type: choice
|
||||
required: true
|
||||
default: sync-from-source-build
|
||||
options:
|
||||
- sync-from-source-build
|
||||
- draft-github-release
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
pull-requests: write
|
||||
|
||||
concurrency:
|
||||
group: release-master
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
# ---------------------------------------------------------------------------
|
||||
# 1. Copy assembled files from source-build onto master (no .github/),
|
||||
# as a pull request.
|
||||
# ---------------------------------------------------------------------------
|
||||
sync-from-source-build:
|
||||
if: inputs.action == 'sync-from-source-build'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
ref: master
|
||||
fetch-depth: 0
|
||||
persist-credentials: true
|
||||
|
||||
- name: sync assembled files from source-build
|
||||
id: sync
|
||||
run: |
|
||||
set -eu
|
||||
git fetch --no-tags origin source-build
|
||||
|
||||
# Every top-level entry on source-build EXCEPT .github/ (master keeps
|
||||
# its own CI). Computed dynamically so any new top-level artifact is
|
||||
# picked up automatically.
|
||||
readarray -t paths < <(git ls-tree --name-only origin/source-build | grep -vxF '.github')
|
||||
echo "Syncing: ${paths[*]}"
|
||||
|
||||
# Mirror source-build exactly for those paths, removing first so that
|
||||
# deletions/renames inside doc/ etc. propagate too.
|
||||
for p in "${paths[@]}"; do rm -rf -- "$p"; done
|
||||
git checkout origin/source-build -- "${paths[@]}"
|
||||
git add --all -- "${paths[@]}"
|
||||
|
||||
if git diff --cached --quiet; then
|
||||
echo "master already up to date with source-build; nothing to sync."
|
||||
echo "changed=false" >> "$GITHUB_OUTPUT"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
{
|
||||
echo "changed=true"
|
||||
echo "version=$(grep -m1 "^VERSION=" spectre-meltdown-checker.sh | cut -d"'" -f2)"
|
||||
echo "sb=$(git rev-parse origin/source-build)"
|
||||
echo "sbdate=$(git log -1 --format=%ai origin/source-build)"
|
||||
} >> "$GITHUB_OUTPUT"
|
||||
|
||||
# Note: the repo must have "Allow GitHub Actions to create and approve
|
||||
# pull requests" enabled for this to work.
|
||||
- name: open the sync pull request
|
||||
if: steps.sync.outputs.changed == 'true'
|
||||
uses: peter-evans/create-pull-request@v7
|
||||
with:
|
||||
base: master
|
||||
branch: release/sync-from-source-build
|
||||
delete-branch: true
|
||||
committer: "github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>"
|
||||
author: "github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>"
|
||||
title: "release: sync v${{ steps.sync.outputs.version }} from source-build"
|
||||
commit-message: |
|
||||
release: sync v${{ steps.sync.outputs.version }} from source-build
|
||||
|
||||
built from source-build commit ${{ steps.sync.outputs.sb }}
|
||||
dated ${{ steps.sync.outputs.sbdate }}
|
||||
body: |
|
||||
Assembled files copied from `source-build` onto `master` (everything
|
||||
except `.github/`, which stays master-only).
|
||||
|
||||
- version: `${{ steps.sync.outputs.version }}`
|
||||
- built from source-build commit: ${{ steps.sync.outputs.sb }}
|
||||
- dated: ${{ steps.sync.outputs.sbdate }}
|
||||
|
||||
Once merged, run this workflow again with the `draft-github-release`
|
||||
action to cut the release, if required.
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# 2. Draft a GitHub release from the script currently on master.
|
||||
# ---------------------------------------------------------------------------
|
||||
draft-github-release:
|
||||
if: inputs.action == 'draft-github-release'
|
||||
runs-on: ubuntu-latest
|
||||
env:
|
||||
GH_TOKEN: ${{ github.token }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
ref: master
|
||||
fetch-depth: 0
|
||||
persist-credentials: true
|
||||
|
||||
- name: draft a release from the current master script
|
||||
run: |
|
||||
set -eu
|
||||
ver=$(grep -m1 "^VERSION=" spectre-meltdown-checker.sh | cut -d"'" -f2)
|
||||
tag="v${ver}"
|
||||
|
||||
if gh release view "$tag" >/dev/null 2>&1; then
|
||||
echo "A release for $tag already exists; refusing to recreate." >&2
|
||||
echo "Delete it first if needed." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Draft the changelog from the source-build commits assembled since the
|
||||
# previous published release. We locate the source-build commit whose
|
||||
# built VERSION equals the last release tag, then list what came after.
|
||||
git fetch --no-tags origin source-build
|
||||
last_tag=$(gh release list --exclude-drafts --limit 1 --json tagName --jq '.[0].tagName // empty')
|
||||
old_ver="${last_tag#v}"
|
||||
|
||||
base=""
|
||||
if [ -n "$old_ver" ]; then
|
||||
while read -r h; do
|
||||
v=$(git show "$h:spectre-meltdown-checker.sh" 2>/dev/null | grep -m1 "^VERSION=" | cut -d"'" -f2 || true)
|
||||
if [ "$v" = "$old_ver" ]; then base="$h"; break; fi
|
||||
done < <(git rev-list --max-count=500 origin/source-build)
|
||||
fi
|
||||
|
||||
{
|
||||
echo "## ${tag}"
|
||||
echo
|
||||
if [ -n "$base" ]; then
|
||||
git log --no-merges --format='- %s' "${base}..origin/source-build"
|
||||
else
|
||||
echo "_Could not determine the previous release point automatically — please fill in the changelog. Last 30 assembled commits below as a starting point:_"
|
||||
echo
|
||||
git log --no-merges --format='- %s' --max-count=30 origin/source-build
|
||||
fi
|
||||
} > notes.md
|
||||
|
||||
echo "----- draft notes -----"; cat notes.md; echo "-----------------------"
|
||||
|
||||
gh release create "$tag" \
|
||||
--draft \
|
||||
--target "$GITHUB_SHA" \
|
||||
--title "$tag" \
|
||||
--notes-file notes.md \
|
||||
spectre-meltdown-checker.sh
|
||||
|
||||
echo "Draft release $tag created."
|
||||
@@ -1,36 +0,0 @@
|
||||
name: 'Manage stale issues and PRs'
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: '37 7 * * *'
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
action:
|
||||
description: "dry-run"
|
||||
required: true
|
||||
default: "apply"
|
||||
type: choice
|
||||
options:
|
||||
- dryrun
|
||||
- apply
|
||||
|
||||
permissions:
|
||||
issues: write
|
||||
pull-requests: write
|
||||
|
||||
jobs:
|
||||
stale:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/stale@v10
|
||||
with:
|
||||
any-of-labels: 'needs-more-info,answered'
|
||||
labels-to-remove-when-unstale: 'needs-more-info,answered'
|
||||
days-before-stale: 30
|
||||
days-before-close: 7
|
||||
stale-issue-label: stale
|
||||
remove-stale-when-updated: true
|
||||
close-issue-reason: completed
|
||||
stale-issue-message: "If there are no further comments or activity on this issue, it'll be closed automatically in 7 days."
|
||||
close-issue-message: "Automatically closing this issue due to inactivity, don't hesitate to open a new issue if needed."
|
||||
debug-only: ${{ case(inputs.action == 'dryrun', true, false) }}
|
||||
@@ -1,190 +0,0 @@
|
||||
name: Online search for vulns
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: '42 8 * * *'
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
model:
|
||||
description: 'Claude model to use (cron runs default to Sonnet)'
|
||||
required: false
|
||||
type: choice
|
||||
default: claude-sonnet-4-6
|
||||
options:
|
||||
- claude-sonnet-4-6
|
||||
- claude-opus-4-7
|
||||
- claude-haiku-4-5-20251001
|
||||
window_hours:
|
||||
description: 'Lookback window in hours (cron runs use 25)'
|
||||
required: false
|
||||
type: string
|
||||
default: '25'
|
||||
reconsider_age_days:
|
||||
description: 'Only reconsider backlog entries last reviewed ≥ N days ago (0 = all, default 7)'
|
||||
required: false
|
||||
type: string
|
||||
default: '7'
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
actions: read # needed to list/download previous run artifacts
|
||||
id-token: write # needed by claude-code-action for OIDC auth
|
||||
|
||||
concurrency:
|
||||
group: vuln-watch
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
watch:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 20
|
||||
|
||||
steps:
|
||||
# The scripts driving this workflow live on the `vuln-watch` branch so
|
||||
# they don't clutter master (which is what ships to production). The
|
||||
# workflow file itself MUST stay on the default branch, as GitHub only
|
||||
# honors `schedule:` triggers on the default branch.
|
||||
- name: Checkout vuln-watch branch (scripts + prompt)
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
ref: vuln-watch
|
||||
fetch-depth: 1
|
||||
persist-credentials: false
|
||||
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@v6
|
||||
with:
|
||||
python-version: '3.12'
|
||||
|
||||
- name: Install Python dependencies
|
||||
run: python -m pip install --quiet feedparser
|
||||
|
||||
# ---- Load previous state ---------------------------------------------
|
||||
# Find the most recent successful run of THIS workflow (other than the
|
||||
# current one) and pull its `vuln-watch-state` artifact. On the very
|
||||
# first run there will be none — that's fine, we start empty.
|
||||
- name: Find previous successful run id
|
||||
id: prev
|
||||
env:
|
||||
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
run: |
|
||||
set -e
|
||||
run_id=$(gh run list \
|
||||
--workflow="${{ github.workflow }}" \
|
||||
--status=success \
|
||||
--limit 1 \
|
||||
--json databaseId \
|
||||
--jq '.[0].databaseId // empty')
|
||||
echo "run_id=${run_id}" >> "$GITHUB_OUTPUT"
|
||||
if [ -n "$run_id" ]; then
|
||||
echo "Found previous successful run: $run_id"
|
||||
else
|
||||
echo "No previous successful run — starting from empty state."
|
||||
fi
|
||||
|
||||
- name: Download previous state artifact
|
||||
if: steps.prev.outputs.run_id != ''
|
||||
uses: actions/download-artifact@v8
|
||||
continue-on-error: true # tolerate retention expiry
|
||||
with:
|
||||
name: vuln-watch-state
|
||||
path: state/
|
||||
run-id: ${{ steps.prev.outputs.run_id }}
|
||||
github-token: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
# ---- Fetch + diff (token-free; runs every time) ---------------------
|
||||
# Performs conditional GETs (ETag / If-Modified-Since) against every
|
||||
# source, parses RSS/Atom/HTML, dedups against state.seen + state.aliases,
|
||||
# applies the time-window filter, and emits new_items.json.
|
||||
# Updates state.sources (HTTP cache metadata + per-source high-water
|
||||
# marks) in place so the cache survives even when Claude doesn't run.
|
||||
- name: Fetch + diff all sources
|
||||
id: diff
|
||||
env:
|
||||
SCAN_DATE: ${{ github.run_started_at }}
|
||||
# Cron runs have no `inputs` context, so the fallback kicks in.
|
||||
WINDOW_HOURS: ${{ inputs.window_hours || '25' }}
|
||||
RECONSIDER_AGE_DAYS: ${{ inputs.reconsider_age_days || '7' }}
|
||||
run: python -m scripts.vuln_watch.fetch_and_diff
|
||||
|
||||
# ---- Fetch checker code so Claude can grep it for coverage ---------
|
||||
# The orphan vuln-watch branch has none of the actual checker code,
|
||||
# so we pull the `test` branch (the dev branch where coded-but-
|
||||
# unreleased CVE checks live) into ./checker/. The prompt tells
|
||||
# Claude this is the canonical source of truth for "is CVE-X already
|
||||
# implemented?". Only fetched on days with something to classify.
|
||||
- name: Checkout checker code (test branch) for coverage grep
|
||||
if: steps.diff.outputs.new_count != '0' || steps.diff.outputs.reconsider_count != '0'
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
ref: test
|
||||
path: checker
|
||||
fetch-depth: 1
|
||||
persist-credentials: false
|
||||
|
||||
# ---- Classify new items with Claude (skipped when nothing is new) ---
|
||||
# Model selection: a manual workflow_dispatch run picks from a dropdown
|
||||
# (defaulting to Sonnet). Scheduled cron runs have no `inputs` context,
|
||||
# so the `|| 'claude-sonnet-4-6'` fallback kicks in — cron always uses
|
||||
# Sonnet to keep the daily cost floor low.
|
||||
- name: Run classifier with Claude
|
||||
id: classify
|
||||
if: steps.diff.outputs.new_count != '0' || steps.diff.outputs.reconsider_count != '0'
|
||||
uses: anthropics/claude-code-action@v1
|
||||
env:
|
||||
SCAN_DATE: ${{ github.run_started_at }}
|
||||
with:
|
||||
prompt: |
|
||||
Read the full task instructions from scripts/daily_vuln_watch_prompt.md
|
||||
and execute them end-to-end. Your input is new_items.json (already
|
||||
deduped, windowed, and pre-filtered — do NOT re-fetch sources).
|
||||
Write the three watch_${TODAY}_*.md files and classifications.json.
|
||||
Use $SCAN_DATE as the canonical timestamp.
|
||||
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
|
||||
# model + tool allowlist pass through claude_args (v1 dropped the
|
||||
# dedicated `model:` and `allowed_tools:` inputs). Job-level
|
||||
# `timeout-minutes: 20` above bounds total runtime.
|
||||
claude_args: |
|
||||
--model ${{ inputs.model || 'claude-sonnet-4-6' }}
|
||||
--allowedTools "Read,Write,Edit,Bash,Grep,Glob,WebFetch"
|
||||
|
||||
- name: Upload Claude execution log
|
||||
if: ${{ always() && steps.classify.outputs.execution_file != '' }}
|
||||
uses: actions/upload-artifact@v7
|
||||
with:
|
||||
name: claude-execution-log-${{ github.run_id }}
|
||||
path: ${{ steps.classify.outputs.execution_file }}
|
||||
retention-days: 30
|
||||
if-no-files-found: warn
|
||||
|
||||
# ---- Merge classifications back into state --------------------------
|
||||
# Also writes stub watch_*.md files if the classify step was skipped, so
|
||||
# the report artifact is consistent across runs.
|
||||
- name: Merge classifications into state
|
||||
if: always()
|
||||
env:
|
||||
SCAN_DATE: ${{ github.run_started_at }}
|
||||
run: python -m scripts.vuln_watch.merge_state
|
||||
|
||||
- name: Upload new state artifact
|
||||
if: always()
|
||||
uses: actions/upload-artifact@v7
|
||||
with:
|
||||
name: vuln-watch-state
|
||||
path: state/seen.json
|
||||
retention-days: 90
|
||||
if-no-files-found: error
|
||||
|
||||
- name: Upload daily report
|
||||
if: always()
|
||||
uses: actions/upload-artifact@v7
|
||||
with:
|
||||
name: vuln-watch-report-${{ github.run_id }}
|
||||
path: |
|
||||
watch_*.md
|
||||
current_toimplement.md
|
||||
current_tocheck.md
|
||||
new_items.json
|
||||
classifications.json
|
||||
retention-days: 90
|
||||
if-no-files-found: warn
|
||||
@@ -13,7 +13,7 @@
|
||||
#
|
||||
# Stephane Lesimple
|
||||
#
|
||||
VERSION='26.36.0730501'
|
||||
VERSION='26.36.0725325'
|
||||
|
||||
# --- Common paths and basedirs ---
|
||||
readonly VULN_SYSFS_BASE="/sys/devices/system/cpu/vulnerabilities"
|
||||
@@ -1219,7 +1219,6 @@ is_cpu_affected() {
|
||||
06-c5-02/82,0000011b
|
||||
06-c6-02/82,0000011b
|
||||
06-bd-01/80,00000125
|
||||
06-55-07/bf,05003901
|
||||
06-55-0b/bf,07002b01
|
||||
06-8f-07/87,2b000661
|
||||
06-8f-08/87,2b000661
|
||||
@@ -13135,7 +13134,7 @@ exit 0 # ok
|
||||
# with X being either I for Intel, or A for AMD
|
||||
# When the date is unknown it defaults to 20000101
|
||||
|
||||
# %%% MCEDB v351+i20260512+16e5
|
||||
# %%% MCEDB v351+i20260512+1cce
|
||||
# I,0x00000611,0xFF,0x00000B27,19961218
|
||||
# I,0x00000612,0xFF,0x000000C6,19961210
|
||||
# I,0x00000616,0xFF,0x000000C6,19961210
|
||||
|
||||
Reference in New Issue
Block a user