Posts by thesamesam@social.treehouse.systems
(DIR) Post #B5teaiEogqDWtNDxlA by thesamesam@social.treehouse.systems
1 likes, 0 repeats
@pinskia @mgorny I've felt for a while that the GCC approach is quite reasonable because it's not so old that people forget big changes in a release. And remember, in GCC (and in basically every project but the kernel), the backports are either done by the person who made the change, or at least they are asked.In the kernel, it is basically automated git cherry-pick. If it applies cleanly, in it goes. Doesn't mean it does the right thing. If not, good luck.
(DIR) Post #B5vPUOQuIl3mjaKOPI by thesamesam@social.treehouse.systems
0 likes, 0 repeats
@mgorny Compare Solar Designer's attempt to find a compromise at https://www.openwall.com/lists/oss-security/2026/05/01/2 with the response at https://www.openwall.com/lists/oss-security/2026/05/01/3I don't think I can keep commenting on this, because it's driving me mad. I've already tried to be very restrained in what I say.
(DIR) Post #B5vtMQWpcjOnXeDUUC by thesamesam@social.treehouse.systems
0 likes, 0 repeats
@tomasv @AndresFreundTec @mgorny This doesn't apply if the reporter has provided what seems to be a genuinely serious vulnerability or if they've provided a PoC, though. I'm not asking for in-depth analysis of every vague possible bug that people report.
(DIR) Post #B5vtMQy7zFEWuIzI24 by thesamesam@social.treehouse.systems
0 likes, 0 repeats
@vbabka @tomasv @AndresFreundTec @mgorny Their report from the tool in their disclosure said LPE and such, so I think so, but I'm not sure they've actually confirmed what they gave to the kernel security team. I'll look around and update if I find some confirmation.
(DIR) Post #B5vtMRBFCTj1Yz7lTc by thesamesam@social.treehouse.systems
0 likes, 0 repeats
@vbabka @tomasv @AndresFreundTec @mgorny Asked now on oss-security: https://www.openwall.com/lists/oss-security/2026/05/03/13
(DIR) Post #B5vtMRNeSLeMBSvfoe by thesamesam@social.treehouse.systems
1 likes, 0 repeats
@vbabka @tomasv @AndresFreundTec @mgorny ... yes, @grsecurity pointed out the CEO has stated they included a full exploit. Beyond words.
(DIR) Post #B5xK3j1xV8O1LL2iYq by thesamesam@social.treehouse.systems
1 likes, 0 repeats
Why are Xen security issues allowed to retain their security marking in commit messages, like in https://cdn.kernel.org/pub/linux/kernel/v7.x/ChangeLog-7.0.3 ?
(DIR) Post #B62BSePBuJHORNWHk8 by thesamesam@social.treehouse.systems
1 likes, 0 repeats
@bluca nails it on LWN [0]:I wonder if there's anybody honestly taking seriously the stream of absolute garbage that comes out of the kernel CNA anymore these days?If so, it seems to me it's high time to stop and just ignore them, and get professionals who actually understand what they are doing to analyze these reports, and provide actual, sensible triagingThe status quo might be good for OWNING THE FREELOADING COMPANIES, it's not so good for anybody else.[0] https://lwn.net/Articles/1070698/
(DIR) Post #B6C4uwPNoEdYHnkezQ by thesamesam@social.treehouse.systems
1 likes, 0 repeats
@dalias Completely agreed and I'm a little surprised more people don't care about this.I did propose a patch to at least allow emulating it a bit better per-repo but there wasn't interest upstream: https://lore.kernel.org/git/20240311213928.1872437-1-sam@gentoo.org/I think the copy detection is kind of a hack and it means people often don't realise this is missing, which I'd argue is worse.
(DIR) Post #B6CTKYBess7Zat4nPU by thesamesam@social.treehouse.systems
1 likes, 0 repeats
@pinskia I think regardless of how one feels about it, I don't think it's really some perfect beginner language like people push it as..It gets treated like it is some universal language everyone can obviously write.
(DIR) Post #B6ICHHpGj1Vji4DmD2 by thesamesam@social.treehouse.systems
1 likes, 0 repeats
@pwithnall inline patch pasted PTSD
(DIR) Post #B6J3DO42stWnTC9tjc by thesamesam@social.treehouse.systems
1 likes, 0 repeats
At what point do @mgorny and I have to start working in shifts for kernel sec issues?
(DIR) Post #B6J41HFgUDe0oyOMnA by thesamesam@social.treehouse.systems
1 likes, 0 repeats
@cadey @mgorny The last 2 weeks, we've been patching every day or every other day.
(DIR) Post #B6QTycdySBIbDErqUK by thesamesam@social.treehouse.systems
1 likes, 0 repeats
@andersonc0d3 I found learning about static-pie illustrative as well.
(DIR) Post #B6q0WfTexQeUh94Nns by thesamesam@social.treehouse.systems
0 likes, 0 repeats
@icing @samueloph @ariadne https://github.com/RsyncProject/rsync/pull/864 was made by Claude ;)But you'll also see tridge carefully reviewed that.
(DIR) Post #B6q0iIsOoTqa4fBoxs by thesamesam@social.treehouse.systems
0 likes, 0 repeats
@ariadne @icing @samueloph I'm pointing out that appealing to the rsync maintainer in Debian may not go as one expects.The review part was to say at least tridge isn't a zombie as some have said (though not here).
(DIR) Post #B6qZt73QbY5KzQEp0a by thesamesam@social.treehouse.systems
0 likes, 0 repeats
wrt openrsync: the repo at https://github.com/kristapsdz/openrsync doesn't have any tests, but Apple's does as https://github.com/apple-oss-distributions/rsync/tree/708962b7b1ec0fa6af1cca68d0639099ddac1c8d/tests/openrsyncThe README.md in there implies the tests were imported from a BSD?
(DIR) Post #B6qZt7HFm98zgIhrYe by thesamesam@social.treehouse.systems
0 likes, 0 repeats
Klara Systems has https://github.com/KlaraSystems/openrsync/tree/a548ebb10646d593fa21aa7b2dffe810163a8ab1/tests where they mention merging w/ another repo..
(DIR) Post #B6qZt7Tf214KImVltg by thesamesam@social.treehouse.systems
1 likes, 0 repeats
Ah, they're imported from https://github.com/openbsd/src/tree/545ae0a97078ba9469aa24234bb840fa4a517dd2/regress/usr.bin/rsyncI obviously don't look at OpenBSD enough..
(DIR) Post #B8wXsYqzIhJX3Ud4am by thesamesam@social.treehouse.systems
0 likes, 0 repeats
@ariadne Thank you for handling these things, I know doing a load of followups sucks.(Doesn't help that it's not obvious what the behaviour was supposed to be here either.)