Skip to content

chore(security): bump x/net + x/sys to clear 7 govulncheck advisories - #341

Closed
lusoris wants to merge 1 commit into
masterfrom
chore/dependency-audit-2026-05-30
Closed

lusoris wants to merge 1 commit into
masterfrom
chore/dependency-audit-2026-05-30

Conversation

@lusoris

@lusoris lusoris commented May 30, 2026

Copy link
Copy Markdown
Contributor

Summary

Cross-ecosystem dependency audit (pip-audit + govulncheck) on 2026-05-30
surfaced 7 Go advisories on golang.org/x/net@v0.53.0 and
golang.org/x/sys@v0.43.0. One is symbol-reachable
(GO-2026-5026 — idna.ToASCII via vmafxnode_controller.probeHealthz);
six are module-level (x/net/html XSS / DoS / parser-correctness +
x/sys/windows integer overflow). Bumped to v0.55.0 / v0.45.0;
x/term and x/text follow via minimum-version selection.
govulncheck ./... re-run after the bump: No vulnerabilities found.

Python audit (docs/, python/, python/test/,
tools/ensemble-training-kit/ requirements + pyproject.toml for ai/,
mcp-server/vmaf-mcp/, dev-llm/, tools/vmaf-tune/,
tools/vmaf-roi-score/, tools/ensemble-training-kit/): clean across
all 10 manifests.
Container scan skipped — vmafx-dev-mcp:latest not
present locally.

Findings count by ecosystem: Python 0, Go 7 (1 reachable, 6 module-only),
Node n/a, Container deferred.

Type

  • chore — dependency bump
  • security — clears 7 advisories

Deep-dive deliverables (ADR-0108)

  • Research digest — docs/research/dependency-audit-2026-05-30.md
  • Decision matrix — no alternatives: only-one-way fix (govulncheck cites a fixed version; min-version selection forces the bundled x/sys / x/term / x/text upgrades).
  • AGENTS.md invariant note — no rebase-sensitive invariants (transitive Go dep bump; no API / dispatch / kernel touched).
  • Reproducer / smoke-test command — see below.
  • CHANGELOG fragment — changelog.d/security/dependency-audit-2026-05-30.md
  • Rebase note — entry appended to docs/rebase-notes.md ("Dependency audit 2026-05-30").

Reproducer

# Re-run the audit on master to confirm the advisories pre-existed:
git checkout master
govulncheck ./...   # expect: 1 direct + 6 module-only on x/net / x/sys

# Re-run on this PR's branch to confirm they're cleared:
git checkout chore/dependency-audit-2026-05-30
govulncheck ./...   # expect: No vulnerabilities found.

# Cross-check the Python ecosystems are still clean:
pip-audit -r docs/requirements.txt
pip-audit -r python/requirements.txt
pip-audit -r python/test/requirements.txt
pip-audit -r tools/ensemble-training-kit/requirements-frozen.txt
for d in ai mcp-server/vmaf-mcp dev-llm tools/vmaf-tune tools/vmaf-roi-score tools/ensemble-training-kit; do
  pip-audit "$d"
done

Bug-status hygiene (ADR-0165)

  • No state delta: this PR clears advisories on transitive Go dependencies, not a fork bug tracked in docs/state.md.

Netflix golden-data gate (ADR-0024)

  • I did not modify any assertAlmostEqual(...) score in the Netflix golden Python tests.
  • No backend / kernel / dispatch code touched; cross-backend numerical results unchanged.

Verification

  • go build ./... — clean.
  • go vet ./... — clean.
  • go test ./cmd/vmafx-server/... ./cmd/vmafx-controller/... — pass (the operator's envtest suite is skipped locally for lack of kubebuilder/etcd; CI runs it).
  • pre-commit run --files <touched> — pass.

Known follow-ups

… advisories

Cross-ecosystem dependency audit (pip-audit + govulncheck) on 2026-05-30
surfaced 7 Go advisories — 1 symbol-reachable (idna.ToASCII via the
operator healthz probe) and 6 module-level — on golang.org/x/net@v0.53.0
and golang.org/x/sys@v0.43.0. Bumped to v0.55.0 / v0.45.0 respectively
(x/term and x/text follow via minimum-version selection). govulncheck
re-run after the bump: clean. Python audit (4 requirements files + 6
pyproject manifests): clean. Container scan deferred — no
vmafx-dev-mcp:latest image locally.

See docs/research/dependency-audit-2026-05-30.md for the full audit
record.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@lusoris

lusoris commented May 31, 2026

Copy link
Copy Markdown
Contributor Author

Closing as part of marathon cleanup 2026-05-31 (150 PRs merged today). Content likely superseded by sibling merges. Reopen if specific finding still needs work; bigger PRs preferred going forward per session feedback.

@lusoris lusoris closed this May 31, 2026
@lusoris
lusoris deleted the chore/dependency-audit-2026-05-30 branch May 31, 2026 14:07
@lusoris
lusoris restored the chore/dependency-audit-2026-05-30 branch May 31, 2026 18:39
@lusoris lusoris reopened this May 31, 2026
@lusoris
lusoris marked this pull request as draft May 31, 2026 18:49
@lusoris

lusoris commented Jun 1, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #514 — bundled per bigger-PRs guidance.

@lusoris lusoris closed this Jun 1, 2026
lusoris added a commit that referenced this pull request Jun 2, 2026
…eQL Go) (#514)

* chore(security): bump golang.org/x/net + x/sys to clear 7 govulncheck advisories

Cross-ecosystem dependency audit (pip-audit + govulncheck) on 2026-05-30
surfaced 7 Go advisories — 1 symbol-reachable (idna.ToASCII via the
operator healthz probe) and 6 module-level — on golang.org/x/net@v0.53.0
and golang.org/x/sys@v0.43.0. Bumped to v0.55.0 / v0.45.0 respectively
(x/term and x/text follow via minimum-version selection). govulncheck
re-run after the bump: clean. Python audit (4 requirements files + 6
pyproject manifests): clean. Container scan deferred — no
vmafx-dev-mcp:latest image locally.

See docs/research/dependency-audit-2026-05-30.md for the full audit
record.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(security): resolve CodeQL config conflict, add Go CodeQL coverage (ADR-0811)

- Extend .github/codeql-config.yml paths to cover the Phase 4 Go surface
  (cmd/, pkg/, api/) and exclude gen/go (generated protobuf stubs).
- Add codeql-go job to security-scans.yml covering vmafx-controller,
  vmafx-mcp, vmafx-node, and pkg/ai/infer.go with security-and-quality
  suite; SHA-pinned to the same codeql-action v4 already in use.
- Add ADR-0811 and changelog fragment documenting the Dependabot/Renovate
  posture (Renovate osvVulnerabilityAlerts is the operative mechanism).

Source: #171 (security/codeql-go-pvr-fixes-20260529).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 2, 2026
…uite

The cmd/vmafx-operator/internal/controller envtest suite was hard-failing
in BeforeSuite with a nil-pointer deref from controlplane.(*APIServer).Stop
because the kubebuilder envtest control-plane binaries (etcd +
kube-apiserver + kubectl) were not on PATH. PRs #330, #341, and #362 all
called this out as a pre-existing failure they could not address inline.

Three-pronged fix:

1. Makefile gains a `setup-envtest` target that installs
   `sigs.k8s.io/controller-runtime/tools/setup-envtest@latest` and
   downloads the v1.31 control-plane bundle. A companion
   `setup-envtest-env` target prints the eval-friendly export line so
   developers can do `eval $(make -s setup-envtest-env)`.

2. .github/workflows/go-ci.yml installs setup-envtest and exports
   `KUBEBUILDER_ASSETS` via `$GITHUB_ENV` before `go test ./...`, so the
   operator suite runs for real in CI instead of skipping.

3. cmd/vmafx-operator/internal/controller/suite_test.go gains a
   top-of-`TestControllers` `t.Skip()` guard when `KUBEBUILDER_ASSETS`
   is unset, plus a nil-`testEnv` bailout in `AfterSuite` so the suite
   never panics on a fresh checkout where the assets are missing
   (defense in depth).

Local verification:
- `unset KUBEBUILDER_ASSETS && go test ./cmd/vmafx-operator/...` -> SKIP
  with an actionable message pointing at `make setup-envtest`.
- `eval $(make -s setup-envtest-env) && go test -v ./cmd/vmafx-operator/...`
  -> 3/3 specs pass in ~5 s.

AGENTS.md gains a new invariant #6 documenting the skip-safe envtest
pattern; rebase-notes.md, state.md, and a changelog fragment under
changelog.d/fixed/ are updated per ADR-0108 + CLAUDE.md r10/r13.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 2, 2026
…test + #446 SYCL parity round 3) (#528)

* chore(ci): audit per-file coverage overrides — tighten tiny_extractor_template.h 10 → 75

Periodic audit of `scripts/ci/coverage-check.sh`'s `PER_FILE_MIN` map
(ADR-0114). Three findings:

1. `core/src/dnn/tiny_extractor_template.h` — actual 77.4 %, override
   10 % (67.4 pp slack). Original 10 % cap was set when only one
   extractor (`feature_lpips.c`) instantiated the inline helpers; four
   extractors now do (`feature_lpips`, `fastdvdnet_pre`,
   `feature_mobilesal`, `feature_transnet_v2`). Tighten to 75 (2.4 pp
   slack, mirroring the 1.3-1.7 pp slack ADR-0114 used for the at-cap
   entries). Locks 65 pp of de-facto regression-coverage.

2. `core/src/dnn/ort_backend.c` — actual 77.8 %, override 78 % (at cap,
   currently failing on master). Keep at 78 — PR #338 in flight adds
   `vmaf_ort_output_name_at` unit test, lifting actual to 78.5 %
   without raising the bar (correct pattern per ADR-0114).

3. `core/src/dnn/dnn_api.c` — actual 78.0 %, override 78 % (at cap).
   Keep at 78 — structural ceiling rationale per ADR-0114 §Context
   unchanged.

No new override entries required. All other dnn/ files plus opt.c and
read_json_model.c clear the global 85 % critical floor
(dnn_attach_api.c 92 %, model_loader.c 87 %, onnx_scan.c 93 %,
op_allowlist.c 100 %, tensor_io.c 98 %, opt.c 100 %,
read_json_model.c 88 %).

ADR-0881 also codifies the recurring audit rule (tighten when slack
> 5 pp; keep at-cap; remove when actual ≥ global 85 % floor; audit
quarterly + before any PER_FILE_MIN edit). Audit procedure documented
in the companion research digest.

Reproducer:
  PKG_CONFIG_PATH=/path/to/onnxruntime/lib/pkgconfig \
    meson setup core/build-coverage core --buildtype=debug \
      -Db_coverage=true -Denable_cuda=false -Denable_sycl=false \
      -Denable_float=true -Denable_avx512=true -Denable_dnn=enabled \
      -Dc_args=-fprofile-update=atomic -Dcpp_args=-fprofile-update=atomic
  ninja -C core/build-coverage
  LD_LIBRARY_PATH=/path/to/onnxruntime/lib \
    meson test -C core/build-coverage --num-processes 1
  cd core && gcovr --root .. --filter 'src/.*' \
    --exclude '.*/test/.*' --exclude '.*/tests/.*' \
    --json-summary build-coverage/coverage.json build-coverage
  bash scripts/ci/coverage-check.sh core/build-coverage/coverage.json 37 85
  # Pre-audit: tiny_extractor_template.h reports "min 10%"
  # Post-audit: same file reports "min 75%" — gate enforces the new floor

Closes the ADR-0114 implicit follow-up "re-audit slack overrides on a
cadence so they don't rot".

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(ci,operator): install kubebuilder envtest binaries for operator suite

The cmd/vmafx-operator/internal/controller envtest suite was hard-failing
in BeforeSuite with a nil-pointer deref from controlplane.(*APIServer).Stop
because the kubebuilder envtest control-plane binaries (etcd +
kube-apiserver + kubectl) were not on PATH. PRs #330, #341, and #362 all
called this out as a pre-existing failure they could not address inline.

Three-pronged fix:

1. Makefile gains a `setup-envtest` target that installs
   `sigs.k8s.io/controller-runtime/tools/setup-envtest@latest` and
   downloads the v1.31 control-plane bundle. A companion
   `setup-envtest-env` target prints the eval-friendly export line so
   developers can do `eval $(make -s setup-envtest-env)`.

2. .github/workflows/go-ci.yml installs setup-envtest and exports
   `KUBEBUILDER_ASSETS` via `$GITHUB_ENV` before `go test ./...`, so the
   operator suite runs for real in CI instead of skipping.

3. cmd/vmafx-operator/internal/controller/suite_test.go gains a
   top-of-`TestControllers` `t.Skip()` guard when `KUBEBUILDER_ASSETS`
   is unset, plus a nil-`testEnv` bailout in `AfterSuite` so the suite
   never panics on a fresh checkout where the assets are missing
   (defense in depth).

Local verification:
- `unset KUBEBUILDER_ASSETS && go test ./cmd/vmafx-operator/...` -> SKIP
  with an actionable message pointing at `make setup-envtest`.
- `eval $(make -s setup-envtest-env) && go test -v ./cmd/vmafx-operator/...`
  -> 3/3 specs pass in ~5 s.

AGENTS.md gains a new invariant #6 documenting the skip-safe envtest
pattern; rebase-notes.md, state.md, and a changelog fragment under
changelog.d/fixed/ are updated per ADR-0108 + CLAUDE.md r10/r13.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* test(sycl): SYCL kernel parity coverage round 3 (5 new tests, ADR-0946)

Adds five new CPU-vs-SYCL parity tests under core/test/, extending
the SYCL parity coverage beyond rounds 1 (PR #351: integer psnr +
vif) and 2 (PR #376: integer adm / ciede / ssim / ms_ssim /
motion_v2).

New parity tests at ADR-0214 places=4 (1e-4) tolerance:

| Kernel              | New test                              | Headline score                            |
|---------------------|---------------------------------------|-------------------------------------------|
| float_psnr_sycl     | test_sycl_float_psnr_parity.c         | float_psnr                                |
| float_adm_sycl      | test_sycl_float_adm_parity.c          | VMAF_feature_adm2_score                   |
| float_vif_sycl      | test_sycl_float_vif_parity.c          | VMAF_feature_vif_scale0_score             |
| float_motion_sycl   | test_sycl_float_motion_parity.c       | VMAF_feature_motion2_score (idx 1)        |
| psnr_hvs_sycl       | test_sycl_psnr_hvs_parity.c           | psnr_hvs                                  |

Each mirrors the round-1 / round-2 pattern: 256x144 synthetic
YUV420P fixture, CPU + SYCL feature extractor, parity assertion
within ADR-0214 places=4, skip-on-no-device via
"[skip: no SYCL device]" printf.

Coverage trajectory: 50% (rounds 1+2) -> 78% (this PR).
Round-4 backlog: float_moment, speed_chroma, speed_temporal,
ssimulacra2 (need scaffold extensions for per-extractor config
dicts and ref_pic_90 fill before the same gate can be added).

Container compile-check evidence:

    docker exec vmaf-dev-mcp bash -lc '
      source /opt/intel/oneapi/setvars.sh --force >/dev/null 2>&1 && \
      cd /tmp/wt-sycl-r3 && \
      CC=icx CXX=icpx meson setup build-sycl-r3 core \
          -Denable_sycl=true -Denable_avx512=false -Db_lto=false && \
      ninja -C build-sycl-r3 \
          test/test_sycl_float_psnr_parity \
          test/test_sycl_float_adm_parity \
          test/test_sycl_float_vif_parity \
          test/test_sycl_float_motion_parity \
          test/test_sycl_psnr_hvs_parity'

All five executables compile + link clean with -Wall -Wextra under
icx/icpx. Registration sub-tests pass on this host; parity
sub-tests hit a pre-existing level_zero device-passthrough issue
(same as PR #376, not introduced by this PR).

Refs ADR-0946, ADR-0214, ADR-0868, ADR-0884.

* test(sycl): SYCL kernel parity coverage round 4 (4 new tests, ADR-0957) (#465)

Closes the SYCL kernel-coverage backlog enumerated in ADR-0946 by
adding four new CPU vs. SYCL parity tests under core/test/.

| Kernel              | New test                              | Tolerance              |
|---------------------|---------------------------------------|------------------------|
| float_moment_sycl   | test_sycl_float_moment_parity.c       | 1e-4 (ADR-0214 default)|
| speed_chroma_sycl   | test_sycl_speed_chroma_parity.c       | 1e-4 (ADR-0214 default)|
| speed_temporal_sycl | test_sycl_speed_temporal_parity.c     | 1e-4 (ADR-0214 default)|
| ssimulacra2_sycl    | test_sycl_ssimulacra2_parity.c        | 5e-3 (FEATURE_TOLERANCE)|

Each test mirrors the round-3 scaffold: 256x144 synthetic YUV420P
fixture, public vmaf_use_feature API with NULL options dict
(defaults match between CPU and SYCL for all four kernels),
parity assertion via fabs(cpu - sycl) <= TOL, skip-on-no-device
via "[skip: no SYCL device]" printf.

The SSIMULACRA2 fixture fills all three planes (the pipeline
consumes YUV -> linear-RGB -> XYB and chroma matters for the
headline score). The speed_temporal fixture submits two frames
(TEMPORAL flag means frame 0 emits 0.0) and asserts at index 1.

Discovery during round-4 implementation:
speed_chroma_sycl.cpp (752 LOC) and speed_temporal_sycl.cpp
(705 LOC) source files exist on disk but are NOT wired into
sycl_feature_sources in core/src/meson.build and their extractor
symbols are NOT declared/registered in
core/src/feature/feature_extractor.c. Both files appear complete
(no TODO/FIXME/-ENOSYS/stub markers) but ship as dormant
scaffold. Wiring them in is out of scope for a kernel-coverage
PR (it changes the production extractor surface). The two SpEED
parity tests are added in dormant form with a
"[skip: <name> not built into libvmaf]" guard that
auto-activates as a real parity gate the day a follow-up PR
wires the TUs into the build + registry.

Container compile-check evidence (CC=icx CXX=icpx,
enable_sycl=true, Intel Arc A380 visible):
- All four test executables link against libvmaf.a successfully.
- speed_chroma/temporal: pass (skip — dormant scaffold).
- float_moment / ssimulacra2: register-existence sub-test passes;
  parity sub-test hits the same pre-existing level_zero
  device-passthrough SIGSEGV that PR #446's round-3 tests hit on
  this dev container (not introduced by this PR). On a host with
  proper Intel-GPU passthrough or with no SYCL device, the tests
  pass / skip cleanly.

Coverage trajectory:
- Round 0 (pre-rounds): 2/18 (11%)
- Round 1 (#351): +2 = 4/18 (22%)
- Round 2 (#376): +5 = 9/18 (50%)
- Round 3 (#446): +5 = 14/18 (78%)
- Round 4 (this PR): +4 = 18/18 (100% of round-3 backlog;
  16 active + 2 dormant SpEED scaffolds)

Refs ADR-0957, ADR-0214, ADR-0867, ADR-0884, ADR-0946.

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>

* chore(ci): add changelog fragment for infra/CI bundle batch-1

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
@lusoris
lusoris deleted the chore/dependency-audit-2026-05-30 branch June 4, 2026 08:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant