| Message ID | PXBPLlPuRIC3YAjeHADlAw@emlix.com (mailing list archive) |
|---|---|
| State | Changes Requested |
| Headers |
Return-Path: <libc-alpha-bounces~patchwork=sourceware.org@sourceware.org> X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id C86AE4BB1C2D for <patchwork@sourceware.org>; Fri, 21 Aug 2026 05:44:47 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org C86AE4BB1C2D Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=emlix.com header.i=@emlix.com header.a=rsa-sha256 header.s=20250930 header.b=M5/zrn8P; dkim=pass (2048-bit key) header.d=emlix.com header.i=@emlix.com header.a=rsa-sha256 header.s=20250930 header.b=M5/zrn8P X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mx1.emlix.com (mx1.emlix.com [178.63.209.131]) by sourceware.org (Postfix) with ESMTPS id 89E8F4BAE7D2 for <libc-alpha@sourceware.org>; Fri, 21 Aug 2026 05:44:01 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 89E8F4BAE7D2 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=emlix.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=emlix.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 89E8F4BAE7D2 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=178.63.209.131 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1787291041; cv=none; b=k/IaUgVKwvYDT5dmvW6GCY+hEICAQT0du2hU+Wo3EVTqKiifz4Q+ITgkAlQ9bstFbsUaPgoqX4dFEmItALvWe6sqpzBzxP1WQB2YaSuPahByQLRoYuWdANA5ybMeMFzm8QS4PsaAYE3MtBGWJnUzmF4fdDhBbopnkcvYjciQxH8= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1787291041; c=relaxed/simple; bh=B4BGHAoUdXBlCI7Zmg8XeJ/OgMyPhF8j8KmE7Tiw8O0=; h=DKIM-Signature:DKIM-Signature:From:To:Subject:Date:Message-ID: MIME-Version; b=cJV9S2IW9dsqL05dcLUbPr6aYRcyC/aUZGnwuBldv9BaJeioITY55Ys9MFLGOWHdmuptpYZ3AsOkvSvOKHJv9C9yBXXozdAhfJhsbTVs+yjUYf98cPzo6vkeRwry6ltEoCh+pT6iY7sg2MERulm8mZv+2LrqMgIuTs1AOFdpQhc= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=emlix.com header.i=@emlix.com header.a=rsa-sha256 header.s=20250930 header.b=M5/zrn8P; dkim=pass (2048-bit key) header.d=emlix.com header.i=@emlix.com header.a=rsa-sha256 header.s=20250930 header.b=M5/zrn8P DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 89E8F4BAE7D2 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=emlix.com; s=20250930; t=1787291021; bh=PyfO5/evx4jAYaXxfHXjV11lVAQJkM2dWY3P2Qs8XYM=; h=From:To:Subject:Date:In-Reply-To:References:From; b=M5/zrn8P99WgWfpcKxhpHOI4CsZA0QyBgsTXKF1IhxP9spQmxBlbi4JBIrk5sU1tE 0R8jCKmzigwZAHc4HxG8crZChP5dargOUoce/hFHdewEesoas/8DNXDqVGUagjbtNX 1QxfFCwQV/p4wY23rK+ScvG4nGh1WFynHBrIcldaMcMriGO+V+SDFidIeSTytmyeSl uPVQrAgamK1+xrQekPl65WFQat5NTxTOOachCsNG82S7hyklKk5e3szl/4gIqRh/EL NrBeEPHh8yi2hTXS+TW7d3m6EgsCxZhT5cp3XDDffvQ0zE1PU2zoCbcPnNAB3CnRT1 L83bt1GF+6c1g== Received: from mx1.emlix.com (localhost [127.0.0.1]) by mx1.emlix.com (Postfix) with ESMTP id 8F2655FB9E for <libc-alpha@sourceware.org>; Fri, 21 Aug 2026 07:43:41 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=emlix.com; s=20250930; t=1787291021; bh=PyfO5/evx4jAYaXxfHXjV11lVAQJkM2dWY3P2Qs8XYM=; h=From:To:Subject:Date:In-Reply-To:References:From; b=M5/zrn8P99WgWfpcKxhpHOI4CsZA0QyBgsTXKF1IhxP9spQmxBlbi4JBIrk5sU1tE 0R8jCKmzigwZAHc4HxG8crZChP5dargOUoce/hFHdewEesoas/8DNXDqVGUagjbtNX 1QxfFCwQV/p4wY23rK+ScvG4nGh1WFynHBrIcldaMcMriGO+V+SDFidIeSTytmyeSl uPVQrAgamK1+xrQekPl65WFQat5NTxTOOachCsNG82S7hyklKk5e3szl/4gIqRh/EL NrBeEPHh8yi2hTXS+TW7d3m6EgsCxZhT5cp3XDDffvQ0zE1PU2zoCbcPnNAB3CnRT1 L83bt1GF+6c1g== Received: from mailer.emlix.com (p5098be52.dip0.t-ipconnect.de [80.152.190.82]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1.emlix.com (Postfix) with ESMTPS id 7EC295F869 for <libc-alpha@sourceware.org>; Fri, 21 Aug 2026 07:43:41 +0200 (CEST) From: Rolf Eike Beer <eb@emlix.com> To: libc-alpha@sourceware.org Subject: [PATCH 2/4] scripts: add "scan" mode to process-advisories.sh to find more backports Date: Fri, 21 Aug 2026 07:40:41 +0200 Message-ID: <PXBPLlPuRIC3YAjeHADlAw@emlix.com> Organization: emlix GmbH In-Reply-To: <H7hLtOuJTNC3aNW98pQ7lQ@emlix.com> References: <H7hLtOuJTNC3aNW98pQ7lQ@emlix.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" X-Virus-Scanned: ClamAV using ClamSMTP X-Spam-Status: No, score=-10.8 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_BARRACUDACENTRAL, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list <libc-alpha.sourceware.org> List-Unsubscribe: <https://sourceware.org/mailman/options/libc-alpha>, <mailto:libc-alpha-request@sourceware.org?subject=unsubscribe> List-Archive: <https://sourceware.org/pipermail/libc-alpha/> List-Post: <mailto:libc-alpha@sourceware.org> List-Help: <mailto:libc-alpha-request@sourceware.org?subject=help> List-Subscribe: <https://sourceware.org/mailman/listinfo/libc-alpha>, <mailto:libc-alpha-request@sourceware.org?subject=subscribe> Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org |
| Series |
[1/4] advisories: fix typo in README
|
|
Commit Message
Rolf Eike Beer
Aug. 21, 2026, 5:40 a.m. UTC
This will look through the stable branches to find additional backports of
the fix for the given advisory.
Signed-off-by: Rolf Eike Beer <eb@emlix.com>
---
scripts/process-advisories.sh | 34 ++++++++++++++++++++++++++++++++--
1 file changed, 32 insertions(+), 2 deletions(-)
Comments
On 2026-08-21 01:40, Rolf Eike Beer wrote: > This will look through the stable branches to find additional backports of > the fix for the given advisory. That's neat, thank you for contributing this. Just some suggested changes below. > > Signed-off-by: Rolf Eike Beer <eb@emlix.com> > --- > scripts/process-advisories.sh | 34 ++++++++++++++++++++++++++++++++-- > 1 file changed, 32 insertions(+), 2 deletions(-) > > diff --git a/scripts/process-advisories.sh b/scripts/process-advisories.sh > index a520fab5e6..00a8cd9416 100755 > --- a/scripts/process-advisories.sh > +++ b/scripts/process-advisories.sh > @@ -25,7 +25,7 @@ command=$1 > > usage () { > cat >&2 <<EOF > -usage: $0 {update|news} > +usage: $0 {update|news|scan} Maybe give it a more precise name, e.g. update-backports ? > EOF > exit 1 > } > @@ -33,7 +33,7 @@ EOF > command="$1" > > case "$command" in > - update|news) > + update|news|scan) > ;; > *) > usage > @@ -69,6 +69,36 @@ advisories_update() { > done > } > > +advisories_scan() { > + advisory=$1 > + > + if [ -z $1 ]; then > + echo "Usage: $0 update GLIBC-SA-YYYY-NNNN" > + exit 1 > + fi > + > + advisory_file=advisories/$advisory > + > + FIX=$(sed -nr '/^Fix-Commit: /s/Fix-Commit: *([0-9a-fA-F]+) *\(2\.[0-9]+\).*/\1/p' $advisory_file) > + > + if [ -z "${FIX}" ]; then > + echo "No Fix-Commit found in $advisory_file" > + exit 1 > + fi There could be multiple Fix-Commit entries on the same branch, which means you likely want to search for all of those commits on older branches. Also, since backports also show up as `Fix-Commit:` with a different branch name, you might want to restrict the commits to those that exist on the master branch. > + for n in $(seq 20 44); do > + BACKPORT=($(git log ..origin/release/2.${n}/master --grep "cherry picked from commit ${FIX}" --format=%H)) > + if [ ${#BACKPORT[@]} -eq 0 ]; then > + continue > + fi > + if [ ${#BACKPORT[@]} -ne 1 ]; then > + echo "Multiple matches for backport of ${FIX} found in branch 2.${n}" > + continue This sounds like a repo inconsistency; one shouldn't have multiple matches for a cherry pick of the same commit in a branch. Maybe flag an error here? > + fi > + grep -q "^Fix-Commit: ${BACKPORT[0]} " $advisory_file || echo "Fix-Commit: ${BACKPORT[0]} ($(get_rel ${BACKPORT[0]}))" >> $advisory_file Hmm, if the process errors out in between for some reason, you may end up with a partially updated advisory file. That won't be a problem though, since the partially updated advisory file is still consistent and a subsequent run should be able to continue with it, as long as you have the check for existence of the commit on the master branch, as I suggested above. > + done > +} > + > advisories_news() { > rel=$(get_rel "HEAD") > for f in $(grep -l "^Fix-Commit: .* ($rel)$" advisories/*); do Also, I wonder if looking for the CVE id would be a better way of looking for the backports, especially if there are custom fixes on older branches. It's probably not a common problem though. Thanks, Sid
On 21/08/26 02:40, Rolf Eike Beer wrote: > This will look through the stable branches to find additional backports of > the fix for the given advisory. > > Signed-off-by: Rolf Eike Beer <eb@emlix.com> Describe this new option and the workflow change on the advisories/README. > --- > scripts/process-advisories.sh | 34 ++++++++++++++++++++++++++++++++-- > 1 file changed, 32 insertions(+), 2 deletions(-) > > diff --git a/scripts/process-advisories.sh b/scripts/process-advisories.sh > index a520fab5e6..00a8cd9416 100755 > --- a/scripts/process-advisories.sh > +++ b/scripts/process-advisories.sh > @@ -25,7 +25,7 @@ command=$1 > > usage () { > cat >&2 <<EOF > -usage: $0 {update|news} > +usage: $0 {update|news|scan} > EOF > exit 1 > } > @@ -33,7 +33,7 @@ EOF > command="$1" > > case "$command" in > - update|news) > + update|news|scan) > ;; > *) > usage > @@ -69,6 +69,36 @@ advisories_update() { > done > } > > +advisories_scan() { > + advisory=$1 > + > + if [ -z $1 ]; then > + echo "Usage: $0 update GLIBC-SA-YYYY-NNNN" > + exit 1 > + fi > + > + advisory_file=advisories/$advisory > + > + FIX=$(sed -nr '/^Fix-Commit: /s/Fix-Commit: *([0-9a-fA-F]+) *\(2\.[0-9]+\).*/\1/p' $advisory_file) This breaks if an advisory has two master fix commits, FIX becomes a newline-separated list, and git treats the embedded newline as pattern OR. For instance: $ sed -nr '/^Fix-Commit: /s/Fix-Commit: *([0-9a-fA-F]+) *\(2\.[0-9]+\).*/\1/p' advisories/GLIBC-SA-2024-0006 b048a482f088e53144d26a61c390bed0210f49f2 7835b00dbce53c3c87bbbb1754a95fb5e58187aa And thus: $ ./scripts/process-advisories.sh scan GLIBC-SA-2024-0006 Multiple matches for backport of b048a482f088e53144d26a61c390bed0210f49f2 7835b00dbce53c3c87bbbb1754a95fb5e58187aa found in branch 2.31 Multiple matches for backport of b048a482f088e53144d26a61c390bed0210f49f2 7835b00dbce53c3c87bbbb1754a95fb5e58187aa found in branch 2.32 Multiple matches for backport of b048a482f088e53144d26a61c390bed0210f49f2 7835b00dbce53c3c87bbbb1754a95fb5e58187aa found in branch 2.33 Multiple matches for backport of b048a482f088e53144d26a61c390bed0210f49f2 7835b00dbce53c3c87bbbb1754a95fb5e58187aa found in branch 2.34 Multiple matches for backport of b048a482f088e53144d26a61c390bed0210f49f2 7835b00dbce53c3c87bbbb1754a95fb5e58187aa found in branch 2.35 Multiple matches for backport of b048a482f088e53144d26a61c390bed0210f49f2 7835b00dbce53c3c87bbbb1754a95fb5e58187aa found in branch 2.36 Multiple matches for backport of b048a482f088e53144d26a61c390bed0210f49f2 7835b00dbce53c3c87bbbb1754a95fb5e58187aa found in branch 2.37 Multiple matches for backport of b048a482f088e53144d26a61c390bed0210f49f2 7835b00dbce53c3c87bbbb1754a95fb5e58187aa found in branch 2.38 Multiple matches for backport of b048a482f088e53144d26a61c390bed0210f49f2 7835b00dbce53c3c87bbbb1754a95fb5e58187aa found in branch 2.39 I think you need to check each fix like: for fix in ${FIX}; do BACKPORT=($(git log ..origin/release/2.${n}/master --grep "cherry picked from commit ${fix}" --format=%H)) [...] done Also, I think we should accept both bare *and( release-annotated master commits: # Master fix commits is either not yet annotated with a release version or # annotated with a plain "(2.NN)". Backport entries carry a "(2.NN-MMM)" # subscript and must not be scanned for. FIX=$(sed -nr 's/^Fix-Commit: *([0-9a-fA-F]+) *(\(2\.[0-9]+\))? *$/\1/p' $advisory_file) > + > + if [ -z "${FIX}" ]; then > + echo "No Fix-Commit found in $advisory_file" > + exit 1 > + fi > + > + for n in $(seq 20 44); do This would require to update this file on each release. We can assume that release branch will always follow the release/2*./master pattern and query the available one as: branches=$(git for-each-ref --format='%(refname:short)' \ 'refs/remotes/origin/release/2.*/master') And iterate as: for branch in ${branches}; do > + BACKPORT=($(git log ..origin/release/2.${n}/master --grep "cherry picked from commit ${FIX}" --format=%H)) The return might be empty depending on current tree status, I think it would be better to specify the script should always scan master (where the fix always land first): BACKPORT=($(git log origin/master..${branch} --grep "cherry picked from commit ${fix}" --format=%H)) > + if [ ${#BACKPORT[@]} -eq 0 ]; then > + continue > + fi > + if [ ${#BACKPORT[@]} -ne 1 ]; then > + echo "Multiple matches for backport of ${FIX} found in branch 2.${n}" > + continue > + fi > + grep -q "^Fix-Commit: ${BACKPORT[0]} " $advisory_file || echo "Fix-Commit: ${BACKPORT[0]} ($(get_rel ${BACKPORT[0]}))" >> $advisory_file The extra space after the pattern only matches lines where something follows the hash. And Advisory files contain Fix-Commit lines in two shapes: * Fix-Commit: 2ae9446c... (2.38-74) — the post-update shape and it has the expected space. * Fix-Commit: 2ae9446c... - there is no trailing space to match, so grep reports "not found". We need to handle both cases: grep -qE "^Fix-Commit: ${BACKPORT[0]}( |\$)" $advisory_file || echo "Fix-Commit: ${BACKPORT[0]} ($(get_rel ${BACKPORT[0]}))" >> $advisory_file > + done > +} > + > advisories_news() { > rel=$(get_rel "HEAD") > for f in $(grep -l "^Fix-Commit: .* ($rel)$" advisories/*); do
* Rolf Eike Beer: > This will look through the stable branches to find additional backports of > the fix for the given advisory. Is time to convert this script to Python? Thanks, Florian
On Freitag, 21. August 2026 07:40:41 Mitteleuropäische Sommerzeit Rolf Eike Beer wrote: > This will look through the stable branches to find additional backports of > the fix for the given advisory. Thank you all for your review. What is the way forward, should I try to address the comments in this shell script or will it be converted to Python? Regards, Eike
diff --git a/scripts/process-advisories.sh b/scripts/process-advisories.sh index a520fab5e6..00a8cd9416 100755 --- a/scripts/process-advisories.sh +++ b/scripts/process-advisories.sh @@ -25,7 +25,7 @@ command=$1 usage () { cat >&2 <<EOF -usage: $0 {update|news} +usage: $0 {update|news|scan} EOF exit 1 } @@ -33,7 +33,7 @@ EOF command="$1" case "$command" in - update|news) + update|news|scan) ;; *) usage @@ -69,6 +69,36 @@ advisories_update() { done } +advisories_scan() { + advisory=$1 + + if [ -z $1 ]; then + echo "Usage: $0 update GLIBC-SA-YYYY-NNNN" + exit 1 + fi + + advisory_file=advisories/$advisory + + FIX=$(sed -nr '/^Fix-Commit: /s/Fix-Commit: *([0-9a-fA-F]+) *\(2\.[0-9]+\).*/\1/p' $advisory_file) + + if [ -z "${FIX}" ]; then + echo "No Fix-Commit found in $advisory_file" + exit 1 + fi + + for n in $(seq 20 44); do + BACKPORT=($(git log ..origin/release/2.${n}/master --grep "cherry picked from commit ${FIX}" --format=%H)) + if [ ${#BACKPORT[@]} -eq 0 ]; then + continue + fi + if [ ${#BACKPORT[@]} -ne 1 ]; then + echo "Multiple matches for backport of ${FIX} found in branch 2.${n}" + continue + fi + grep -q "^Fix-Commit: ${BACKPORT[0]} " $advisory_file || echo "Fix-Commit: ${BACKPORT[0]} ($(get_rel ${BACKPORT[0]}))" >> $advisory_file + done +} + advisories_news() { rel=$(get_rel "HEAD") for f in $(grep -l "^Fix-Commit: .* ($rel)$" advisories/*); do