Compare commits

..
Author SHA1 Message Date
christianmanivong b45444c831 Merge pull request 'fix: capture ${source:Version}, the number OSV ranges are actually stated in' (#1) from fix/capture-source-version into master 2026-09-14 04:11:34 +00:00
Christian ManivongandClaude Opus 5 e8eadb46c6 fix: capture ${source:Version}, the number OSV ranges are actually stated in
OSV states Debian ranges in *source* package versions. A source package that
ships several binaries gives each its own upstream version, and the two are
unrelated numbers: `libldb2` is `2:2.11.0+samba4.22.11+dfsg-0+deb13u1` while its
source, samba, is `2:4.22.11+dfsg-…`.

A consumer that resolves the coordinate on `source_package` — which is what this
driver's `source:Package` is for — and then compares `version` is comparing ldb's
version against samba's range. dpkg reads `2.11.0` as older than the
`2:4.17.4+dfsg-1` that fixed CVE-2022-44640, so a Debian 13 host running samba
4.22.11, five releases past the fix, was reported vulnerable on four packages at
once.

This driver cannot fix that comparison. It is the only place that can supply the
number to make it with.

Empty when dpkg considers it equal to `Version`, and empty on a dpkg that does
not know the field, so it falls back to `Version` — which is the previous
behaviour and correct everywhere except the shape above.

`maxsplit` goes from 4 to 5 with the extra field. Summary stays last, so it keeps
whatever it contains.

**The fixture was carrying four fields against a format string asking for five.**
`source_package` had been silently receiving the description, and no assertion
looked at it. It now carries what dpkg-query actually returns, including a
package whose source version is a different number from its own.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-14 06:10:41 +02:00
Christian Manivong 55635ab551 test: cover the uname -r call get_facts gained
d337398 added a fifth _send() to get_facts without extending the three
get_facts tests' side_effect lists, so each of them ran out of canned
responses and died on StopIteration. Red since 2026-08-23 — nothing gates
this repo, so it simply stayed red.

Adds the kernel release to each list and asserts running_kernel, which had
no coverage at all before.
2026-09-01 05:55:30 +02:00
2 changed files with 77 additions and 9 deletions
+20 -3
View File
@@ -835,11 +835,13 @@ class LinuxDriver(OSDriver):
def _get_packages_apt(self) -> list[PackageDict]: def _get_packages_apt(self) -> list[PackageDict]:
out = self._send( out = self._send(
"dpkg-query -W -f='${Package}\\t${Version}\\t${Installed-Size}" "dpkg-query -W -f='${Package}\\t${Version}\\t${Installed-Size}"
"\\t${source:Package}\\t${binary:Summary}\\n' 2>/dev/null" "\\t${source:Package}\\t${source:Version}\\t${binary:Summary}\\n' 2>/dev/null"
) )
packages: list[PackageDict] = [] packages: list[PackageDict] = []
for line in out.splitlines(): for line in out.splitlines():
parts = line.split("\t", 4) # Summary stays last and keeps whatever it contains: maxsplit must
# equal the number of tabs the format writes, not the field count.
parts = line.split("\t", 5)
if len(parts) < 2: if len(parts) < 2:
continue continue
name = parts[0].strip() name = parts[0].strip()
@@ -847,7 +849,21 @@ class LinuxDriver(OSDriver):
size = int(parts[2].strip()) * 1024 if len(parts) > 2 and parts[2].strip().isdigit() else 0 size = int(parts[2].strip()) * 1024 if len(parts) > 2 and parts[2].strip().isdigit() else 0
# Debian source package (e.g. openssh-server → openssh) for OSV matching. # Debian source package (e.g. openssh-server → openssh) for OSV matching.
source_package = parts[3].strip() if len(parts) > 3 and parts[3].strip() else name source_package = parts[3].strip() if len(parts) > 3 and parts[3].strip() else name
description = parts[4].strip() if len(parts) > 4 else "" # And its version, which is a different number from this package's.
#
# OSV states Debian ranges in *source* versions. A source package
# that ships several binaries gives each its own upstream version:
# libldb2 is 2:2.11.0+samba4.22.11+dfsg-… while its source, samba,
# is 2:4.22.11+dfsg-…. A consumer matching on source_package and
# comparing `version` compares two unrelated numbers — dpkg reads
# ldb's 2.11.0 as older than the 2:4.17.4+dfsg-1 that fixed
# CVE-2022-44640, and a host five releases past the fix was reported
# vulnerable on four packages at once.
#
# dpkg leaves this empty when it equals `Version`; so does an older
# dpkg that does not know the field at all.
source_version = parts[4].strip() if len(parts) > 4 and parts[4].strip() else version
description = parts[5].strip() if len(parts) > 5 else ""
packages.append({ packages.append({
"name": name, "name": name,
"version": version, "version": version,
@@ -856,6 +872,7 @@ class LinuxDriver(OSDriver):
"size": size, "size": size,
"source": "apt", "source": "apt",
"source_package": source_package, "source_package": source_package,
"source_version": source_version,
}) })
return packages return packages
+57 -6
View File
@@ -153,9 +153,22 @@ def test_parse_uptime_invalid(driver):
# --------------------------------------------------------------------------- # ---------------------------------------------------------------------------
#: What `dpkg-query` actually returns for the format this driver asks for.
#:
#: The previous fixture carried four fields against a format string asking for
#: five, so `source_package` was silently receiving the description and no
#: assertion noticed. A fixture simpler than the data cannot fail the way the
#: data does.
APT_PKG_OUTPUT = ( APT_PKG_OUTPUT = (
"openssh-server\t1:9.2p1-2+deb12u2\t512\tsecure shell server\n" "openssh-server\t1:9.2p1-2+deb12u2\t512\topenssh\t1:9.2p1-2+deb12u2"
"curl\t7.88.1-10+deb12u5\t1024\tcommand line tool for transferring data\n" "\tsecure shell server\n"
"curl\t7.88.1-10+deb12u5\t1024\tcurl\t7.88.1-10+deb12u5"
"\tcommand line tool for transferring data\n"
# The shape that matters: a binary package whose own upstream version has
# nothing to do with its source package's. ldb 2.11.0 is built from samba
# 4.22.11, and OSV states Debian ranges in source versions.
"libldb2\t2:2.11.0+samba4.22.11+dfsg-0+deb13u1\t2048\tsamba"
"\t2:4.22.11+dfsg-0+deb13u1\tLDB shared library\n"
) )
@@ -163,11 +176,45 @@ def test_get_packages_apt(driver):
driver._pkg_manager = "apt" driver._pkg_manager = "apt"
with patch.object(driver, "_send", return_value=APT_PKG_OUTPUT): with patch.object(driver, "_send", return_value=APT_PKG_OUTPUT):
pkgs = driver.get_packages() pkgs = driver.get_packages()
assert len(pkgs) == 2 assert len(pkgs) == 3
assert pkgs[0]["name"] == "openssh-server" assert pkgs[0]["name"] == "openssh-server"
assert pkgs[0]["version"] == "1:9.2p1-2+deb12u2" assert pkgs[0]["version"] == "1:9.2p1-2+deb12u2"
assert pkgs[0]["installed"] is True assert pkgs[0]["installed"] is True
assert pkgs[0]["source"] == "apt" assert pkgs[0]["source"] == "apt"
assert pkgs[0]["description"] == "secure shell server"
def test_get_packages_apt_keeps_the_source_package_and_its_version(driver):
"""OSV states Debian ranges in *source* package versions.
A consumer that matches on the source package and then compares the binary
package's version is comparing two unrelated numbers. On a Debian 13 host
that reported four Samba libraries as vulnerable to CVE-2022-44640 while
running samba 4.22.11 — five releases past the fix — because dpkg reads
ldb's own `2.11.0` as older than samba's `2:4.17.4+dfsg-1`.
The driver cannot fix the comparison, but it is the only place that can
supply the number to compare.
"""
driver._pkg_manager = "apt"
with patch.object(driver, "_send", return_value=APT_PKG_OUTPUT):
pkgs = {p["name"]: p for p in driver.get_packages()}
assert pkgs["libldb2"]["source_package"] == "samba"
assert pkgs["libldb2"]["source_version"] == "2:4.22.11+dfsg-0+deb13u1"
assert pkgs["libldb2"]["version"] == "2:2.11.0+samba4.22.11+dfsg-0+deb13u1"
assert pkgs["libldb2"]["description"] == "LDB shared library"
def test_get_packages_apt_falls_back_when_dpkg_gives_no_source(driver):
"""`source:Package` is empty for a package whose source name equals its own.
Older dpkg builds leave `source:Version` empty in that case too."""
driver._pkg_manager = "apt"
with patch.object(driver, "_send", return_value="curl\t7.88.1-10\t1024\t\t\ttool\n"):
(pkg,) = driver.get_packages()
assert pkg["source_package"] == "curl"
assert pkg["source_version"] == "7.88.1-10"
# --------------------------------------------------------------------------- # ---------------------------------------------------------------------------
@@ -639,13 +686,16 @@ def test_get_facts_baremetal_vendor_model_serial(driver):
platform = {"vendor": "Dell Inc.", "model": "PowerEdge R720", "serial": "ABC123", "is_vm": False} platform = {"vendor": "Dell Inc.", "model": "PowerEdge R720", "serial": "ABC123", "is_vm": False}
with patch.object(driver, "_collect_platform_info", return_value=platform), \ with patch.object(driver, "_collect_platform_info", return_value=platform), \
patch.object(driver, "_parse_uptime", return_value=86400), \ patch.object(driver, "_parse_uptime", return_value=86400), \
patch.object(driver, "_send", side_effect=["myhost", "myhost.example.com", "Debian GNU/Linux 12", "eth0\neth1"]): patch.object(driver, "_send", side_effect=["myhost", "myhost.example.com", "Debian GNU/Linux 12", "eth0\neth1",
"6.1.0-18-amd64"]):
facts = driver.get_facts() facts = driver.get_facts()
assert facts["vendor"] == "Dell Inc." assert facts["vendor"] == "Dell Inc."
assert facts["model"] == "PowerEdge R720" assert facts["model"] == "PowerEdge R720"
assert facts["serial_number"] == "ABC123" assert facts["serial_number"] == "ABC123"
assert facts["hostname"] == "myhost" assert facts["hostname"] == "myhost"
assert facts["uptime"] == 86400 assert facts["uptime"] == 86400
# Booted kernel, not the newest installed one — kernel CVE relevance needs it.
assert facts["running_kernel"] == "6.1.0-18-amd64"
def test_get_facts_vm_kvm(driver): def test_get_facts_vm_kvm(driver):
@@ -655,7 +705,8 @@ def test_get_facts_vm_kvm(driver):
} }
with patch.object(driver, "_collect_platform_info", return_value=platform), \ with patch.object(driver, "_collect_platform_info", return_value=platform), \
patch.object(driver, "_parse_uptime", return_value=3600), \ patch.object(driver, "_parse_uptime", return_value=3600), \
patch.object(driver, "_send", side_effect=["vmhost", "vmhost.local", "Ubuntu 22.04 LTS", "eth0"]): patch.object(driver, "_send", side_effect=["vmhost", "vmhost.local", "Ubuntu 22.04 LTS", "eth0",
"5.15.0-91-generic"]):
facts = driver.get_facts() facts = driver.get_facts()
assert facts["vendor"] == "KVM" assert facts["vendor"] == "KVM"
assert facts["model"] == "Virtual Machine" assert facts["model"] == "Virtual Machine"
@@ -666,7 +717,7 @@ def test_get_facts_fallback_vendor_when_dmi_empty(driver):
platform = {"vendor": "", "model": "", "serial": "", "is_vm": False} platform = {"vendor": "", "model": "", "serial": "", "is_vm": False}
with patch.object(driver, "_collect_platform_info", return_value=platform), \ with patch.object(driver, "_collect_platform_info", return_value=platform), \
patch.object(driver, "_parse_uptime", return_value=0), \ patch.object(driver, "_parse_uptime", return_value=0), \
patch.object(driver, "_send", side_effect=["host", "host.local", "Alpine Linux 3.19", "eth0"]): patch.object(driver, "_send", side_effect=["host", "host.local", "Alpine Linux 3.19", "eth0", "6.6.7-0-lts"]):
facts = driver.get_facts() facts = driver.get_facts()
assert facts["vendor"] == "Linux" # fallback to VENDOR class attribute assert facts["vendor"] == "Linux" # fallback to VENDOR class attribute