netOrk's KB precondition vocabulary asks kernel_module and kernel_config (netOrk #268). Reading the answer is identical on every Linux host, so it lives here once:
KERNEL_FACTS_COMMAND: one read-only POSIX sh line, no privileges. It reads the release, /proc/modules, modules.builtin, modules.dep and the build configuration (/boot/config-* or /proc/config.gz). The report is framed, gzipped and base64-encoded. Nothing in it can then look like a prompt to a screen-scraping transport, and a distribution kernel's configuration (~300 kB) crosses as a fifth of that. Measured on an Ubuntu 7.0 kernel: 145 kB on the wire, 250 loaded, 306 built-in, 6 899 shipped modules, 10 284 options.
parse_kernel_facts(): a section the command could not print comes back None, never empty. Downstream, "could not read" and "read, and nothing there" lead to different verdicts.
module_name(): no path, no .ko* suffix, - folded to _, as the kernel itself does.
KernelFactsMixin uses the README's template form: get_kernel_facts() is concrete, and _run_kernel_facts_command() is the driver's hook. Drivers mix it in themselves; OSDriver does not carry it. A Windows host is an OS driver too, and hasattr(driver, "get_kernel_facts") has to stay truthful.
KernelFactsDict in models.py; version 2.1.0; README updated.
Tests: 213 pass, including one that runs the command against the test host and parses the result.
napalm-linux and napalm-proxmox PRs depend on this.
netOrk's KB precondition vocabulary asks `kernel_module` and `kernel_config` (netOrk #268). Reading the answer is identical on every Linux host, so it lives here once:
- **`KERNEL_FACTS_COMMAND`**: one read-only POSIX `sh` line, no privileges. It reads the release, `/proc/modules`, `modules.builtin`, `modules.dep` and the build configuration (`/boot/config-*` or `/proc/config.gz`). The report is framed, gzipped and base64-encoded. Nothing in it can then look like a prompt to a screen-scraping transport, and a distribution kernel's configuration (~300 kB) crosses as a fifth of that. Measured on an Ubuntu 7.0 kernel: 145 kB on the wire, 250 loaded, 306 built-in, 6 899 shipped modules, 10 284 options.
- **`parse_kernel_facts()`**: a section the command could not print comes back `None`, never empty. Downstream, "could not read" and "read, and nothing there" lead to different verdicts.
- **`module_name()`**: no path, no `.ko*` suffix, `-` folded to `_`, as the kernel itself does.
- **`KernelFactsMixin`** uses the README's template form: `get_kernel_facts()` is concrete, and `_run_kernel_facts_command()` is the driver's hook. Drivers mix it in themselves; `OSDriver` does not carry it. A Windows host is an OS driver too, and `hasattr(driver, "get_kernel_facts")` has to stay truthful.
- `KernelFactsDict` in `models.py`; version **2.1.0**; README updated.
Tests: 213 pass, including one that runs the command against the test host and parses the result.
napalm-linux and napalm-proxmox PRs depend on this.
A kernel CVE's exploitability often hangs on code that is not there: a module
neither loaded nor shipped, an option the kernel was built without. netOrk's
KB precondition vocabulary asks exactly that (kernel_module, kernel_config).
Reading it is the same on every Linux host, so the command and its parse live
here and a driver supplies only the transport:
- KERNEL_FACTS_COMMAND: one read-only POSIX sh line, no privileges. Release,
/proc/modules, modules.builtin, modules.dep and the build configuration
(/boot/config-* or /proc/config.gz). The report is framed, gzipped and
base64-encoded, so nothing in it can look like a shell prompt to a
screen-scraping transport, and ~300 kB of configuration crosses as a fifth.
- parse_kernel_facts(): a section the command could not print comes back None,
never empty -- "could not read" and "read, and nothing there" must stay apart.
- module_name(): no path, no .ko suffix, "-" folded to "_", as the kernel does.
- KernelFactsMixin, in the template form: get_kernel_facts() is concrete,
_run_kernel_facts_command() is the driver's hook. Mixed in by the drivers
that can, not by OSDriver -- a Windows host is an OS driver too, and
hasattr(driver, "get_kernel_facts") has to stay truthful.
- KernelFactsDict in models.py. Version 2.1.0.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
netOrk's KB precondition vocabulary asks
kernel_moduleandkernel_config(netOrk #268). Reading the answer is identical on every Linux host, so it lives here once:KERNEL_FACTS_COMMAND: one read-only POSIXshline, no privileges. It reads the release,/proc/modules,modules.builtin,modules.depand the build configuration (/boot/config-*or/proc/config.gz). The report is framed, gzipped and base64-encoded. Nothing in it can then look like a prompt to a screen-scraping transport, and a distribution kernel's configuration (~300 kB) crosses as a fifth of that. Measured on an Ubuntu 7.0 kernel: 145 kB on the wire, 250 loaded, 306 built-in, 6 899 shipped modules, 10 284 options.parse_kernel_facts(): a section the command could not print comes backNone, never empty. Downstream, "could not read" and "read, and nothing there" lead to different verdicts.module_name(): no path, no.ko*suffix,-folded to_, as the kernel itself does.KernelFactsMixinuses the README's template form:get_kernel_facts()is concrete, and_run_kernel_facts_command()is the driver's hook. Drivers mix it in themselves;OSDriverdoes not carry it. A Windows host is an OS driver too, andhasattr(driver, "get_kernel_facts")has to stay truthful.KernelFactsDictinmodels.py; version 2.1.0; README updated.Tests: 213 pass, including one that runs the command against the test host and parses the result.
napalm-linux and napalm-proxmox PRs depend on this.