Linux Test Project
 help / color / mirror / Atom feed
From: Andrea Cervesato via ltp <ltp@lists.linux.it>
To: "Petr Vorel" <pvorel@suse.cz>
Cc: Linux Test Project <ltp@lists.linux.it>
Subject: Re: [LTP] [PATCH v6] cve: reproducer for cve-2026-64600
Date: Mon, 10 Aug 2026 11:24:48 +0000	[thread overview]
Message-ID: <6a79b501.18b7d65e.302874.4926@mx.google.com> (raw)
In-Reply-To: <20260810111521.GB918586@pevik>

Hi Petr,

> > > > +			.min_kver = "4.16",
> > > It got introduced in 4.11. Is there a reason for testing from 4.16?
> > > Or is it just the copy paste error?
> 
> > 1e369b0e199bb ("xfs: remove experimental tag for reflinks") was merged
> > in 4.16
> 
> Well, 1e369b0e199bb just remove warning from dmesg that reflinks are
> experimental. Why to hide from users that kernels from 4.11 to 4.15 are
> vulnerable? Also, Darrick marked his fix as vulnerable from 4.11 (Commit has
> "Cc: stable@vger.kernel.org # v4.11" [1]), blog publish 4.11 [2], but LTP test
> says "Test requires 4.16" => potential user of 4.11 will think "ok I'm safe".
> IMHO perfect example of hiding kernel bug, specially due the fact that oldest
> fixed kernel is v5.15.212, which backported upstream fix 2f4acd0fcd86 as
> dc11be133efc, it was not backported to still supported LTS 5.10.x (EOL 31 Dec
> 2026) because it has conflicts.

We can use 4.11 then

> [5] https://lore.kernel.org/ltp/20260401094946.GA126168@pevik/

you will have hard time updating all tests then :) from what i see, we have
just a bunch of tests using the short SHA. Anyway, I had more than a few
reviews in the past asking to keep it short, so if we want to use the long one
in order to avoid hash collisions, we also need to officially ask for it.

I will update thepatch and merge, thanks 

--
Andrea Cervesato
SUSE QE Automation Engineer Linux
andrea.cervesato@suse.com

-- 
Mailing list info: https://lists.linux.it/listinfo/ltp

  reply	other threads:[~2026-08-10 11:25 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-06  9:45 [LTP] [PATCH v6] cve: reproducer for cve-2026-64600 Andrea Cervesato
2026-08-06 10:41 ` [LTP] " linuxtestproject.agent
2026-08-07  7:35 ` [LTP] [PATCH v6] " pvorel
2026-08-07  7:51   ` Andrea Cervesato via ltp
2026-08-10 11:15     ` Petr Vorel
2026-08-10 11:24       ` Andrea Cervesato via ltp [this message]
2026-08-10 11:28 ` Andrea Cervesato via ltp

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6a79b501.18b7d65e.302874.4926@mx.google.com \
    --to=ltp@lists.linux.it \
    --cc=andrea.cervesato@suse.com \
    --cc=pvorel@suse.cz \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox