From: Petr Vorel <pvorel@suse.cz>
To: Andrea Cervesato <andrea.cervesato@suse.com>
Cc: Linux Test Project <ltp@lists.linux.it>
Subject: Re: [LTP] [PATCH v6] cve: reproducer for cve-2026-64600
Date: Tue, 11 Aug 2026 07:41:39 +0200 [thread overview]
Message-ID: <20260811054139.GB1613289@pevik> (raw)
In-Reply-To: <6a79b501.18b7d65e.302874.4926@mx.google.com>
Hi Andrea,
> Hi Petr,
> > > > > + .min_kver = "4.16",
> > > > It got introduced in 4.11. Is there a reason for testing from 4.16?
> > > > Or is it just the copy paste error?
> > > 1e369b0e199bb ("xfs: remove experimental tag for reflinks") was merged
> > > in 4.16
> > Well, 1e369b0e199bb just remove warning from dmesg that reflinks are
> > experimental. Why to hide from users that kernels from 4.11 to 4.15 are
> > vulnerable? Also, Darrick marked his fix as vulnerable from 4.11 (Commit has
> > "Cc: stable@vger.kernel.org # v4.11" [1]), blog publish 4.11 [2], but LTP test
> > says "Test requires 4.16" => potential user of 4.11 will think "ok I'm safe".
> > IMHO perfect example of hiding kernel bug, specially due the fact that oldest
> > fixed kernel is v5.15.212, which backported upstream fix 2f4acd0fcd86 as
> > dc11be133efc, it was not backported to still supported LTS 5.10.x (EOL 31 Dec
> > 2026) because it has conflicts.
> We can use 4.11 then
Thank you!
> > [5] https://lore.kernel.org/ltp/20260401094946.GA126168@pevik/
> you will have hard time updating all tests then :) from what i see, we have
> just a bunch of tests using the short SHA. Anyway, I had more than a few
> reviews in the past asking to keep it short, so if we want to use the long one
> in order to avoid hash collisions, we also need to officially ask for it.
I'll just after some time rerun the script to update them in a single batch
(script is part of the commit message, anybody can run it).
I also updated the examples in the docs. I wonder if it should be more
documented.
> I will update thepatch and merge, thanks
Thank you!
Kind regards,
Petr
--
Mailing list info: https://lists.linux.it/listinfo/ltp
next prev parent reply other threads:[~2026-08-11 5:42 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-06 9:45 [LTP] [PATCH v6] cve: reproducer for cve-2026-64600 Andrea Cervesato
2026-08-06 10:41 ` [LTP] " linuxtestproject.agent
2026-08-07 7:35 ` [LTP] [PATCH v6] " pvorel
2026-08-07 7:51 ` Andrea Cervesato via ltp
2026-08-10 11:15 ` Petr Vorel
2026-08-10 11:24 ` Andrea Cervesato via ltp
2026-08-11 5:41 ` Petr Vorel [this message]
2026-08-10 11:28 ` Andrea Cervesato via ltp
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260811054139.GB1613289@pevik \
--to=pvorel@suse.cz \
--cc=andrea.cervesato@suse.com \
--cc=ltp@lists.linux.it \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.