| *** sskartheekadivi <sskartheekadivi!~sskarthee@user/sskartheekadivi> has quit IRC (Read error: Connection reset by peer) | 03:51 | |
| *** sskartheekadivi <sskartheekadivi!~sskarthee@user/sskartheekadivi> has joined #cip | 03:52 | |
| *** monstr <monstr!~monstr@nat-108f.starnet.cz> has joined #cip | 05:52 | |
| *** monstr <monstr!~monstr@nat-108f.starnet.cz> has quit IRC (Ping timeout: 248 seconds) | 06:03 | |
| *** sskartheekadivi <sskartheekadivi!~sskarthee@user/sskartheekadivi> has quit IRC (Read error: Connection reset by peer) | 06:12 | |
| *** sskartheekadivi <sskartheekadivi!~sskarthee@user/sskartheekadivi> has joined #cip | 06:13 | |
| *** sskartheekadivi <sskartheekadivi!~sskarthee@user/sskartheekadivi> has quit IRC (Read error: Connection reset by peer) | 08:28 | |
| *** sskartheekadivi <sskartheekadivi!~sskarthee@user/sskartheekadivi> has joined #cip | 08:28 | |
| *** monstr <monstr!~monstr@nat-108f.starnet.cz> has joined #cip | 09:04 | |
| *** monstr <monstr!~monstr@nat-108f.starnet.cz> has quit IRC (Ping timeout: 248 seconds) | 09:31 | |
| *** prabhakalad <prabhakalad!~prabhakar@97e54365.skybroadband.com> has quit IRC (Read error: Connection reset by peer) | 10:52 | |
| *** prabhakalad <prabhakalad!~prabhakar@97e54365.skybroadband.com> has joined #cip | 11:04 | |
| *** ctani <ctani!~ctani@86.121.79.65> has joined #cip | 11:53 | |
| *** jki <jki!~jki@62.156.206.16> has joined #cip | 11:54 | |
| *** masami <masami!~masami@FL1-111-168-44-134.tky.mesh.ad.jp> has joined #cip | 11:58 | |
| jki | hi all | 12:00 |
|---|---|---|
| uli_ | hello | 12:00 |
| pave1 | Hi! | 12:00 |
| masami | hi | 12:00 |
| iwamatsu | hello | 12:00 |
| jki | #startmeeting CIP IRC weekly meeting | 12:00 |
| collab-meetbot | Meeting started Thu Apr 30 12:00:48 2026 UTC and is due to finish in 60 minutes. The chair is jki. Information about MeetBot at http://wiki.debian.org/MeetBot. | 12:00 |
| collab-meetbot | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 12:00 |
| collab-meetbot | The meeting name has been set to 'cip_irc_weekly_meeting' | 12:00 |
| *** collab-meetbot changes topic to " (Meeting topic: CIP IRC weekly meeting)" | 12:00 | |
| jki | #topic AI review | 12:00 |
| *** collab-meetbot changes topic to "AI review (Meeting topic: CIP IRC weekly meeting)" | 12:00 | |
| jki | again: none | 12:01 |
| jki | 5 | 12:01 |
| jki | 4 | 12:01 |
| jki | 3 | 12:01 |
| jki | 2 | 12:01 |
| jki | 1 | 12:01 |
| jki | #topic Kernel maintenance updates | 12:01 |
| *** collab-meetbot changes topic to "Kernel maintenance updates (Meeting topic: CIP IRC weekly meeting)" | 12:01 | |
| uli_ | i pushed 4.4 | 12:01 |
| masami | This week reported 163 new CVEs and 60 updated CVEs. | 12:01 |
| iwamatsu | I was unable to work on the review this week. | 12:02 |
| pave1 | I did some reviews: 6.12.84, .83 and .82 | 12:02 |
| masami | fyi: I have confirmed that the Copy Fail PoC works with versions 4.19.325-cip130-st14 and 5.10.252-cip71. | 12:03 |
| masami | I haven't tested with 6.1 yet. | 12:03 |
| pave1 | Local root. World is not ending, but this one has high publicity... | 12:04 |
| jki | which PoC exactly? | 12:04 |
| pave1 | ...and a name :-) | 12:04 |
| pave1 | CVE-2026-31431. | 12:04 |
| masami | https://copy.fail/#exploit this one. | 12:04 |
| jki | yes, it's more on the visibility side | 12:04 |
| jki | older systems used to have less local exploit vectors then todays systems have | 12:05 |
| jki | so, were is upstream with backporting? | 12:05 |
| jki | I lost overview | 12:05 |
| jki | and what are we doing right now? | 12:05 |
| pave1 | I tried backporting, and it turned out not to be trivial. | 12:06 |
| jki | and LTS has the fix in... ? | 12:06 |
| pave1 | This may help: | 12:07 |
| pave1 | https://lore.kernel.org/stable/2026043003-skier-sprint-7b88@gregkh/T/#t | 12:07 |
| jki | so, down to 5.10 should come via LTS for us | 12:07 |
| jki | only 4.19 then our business, right? | 12:07 |
| pave1 | Yes. | 12:08 |
| jki | BTW, Debian is waiting as well: https://security-tracker.debian.org/tracker/CVE-2026-31431 | 12:08 |
| arisut | just disable it | 12:08 |
| jki | do we have it enabled in our configs? | 12:08 |
| arisut | https://paste.gentoo.zip/tnMM73Xk | 12:08 |
| pave1 | I believe so. At least that's what review scripts were telling me. | 12:09 |
| jki | can it be .config-wise disabled as well without breaking too much? | 12:09 |
| arisut | need to disable authencesn | 12:10 |
| iwamatsu | AF_ALG? | 12:10 |
| pave1 | CONFIG_CRYPTO_AUTHENC. I have not known about it before the exploit :-) | 12:10 |
| *** sskartheekadivi <sskartheekadivi!~sskarthee@user/sskartheekadivi> has quit IRC (Read error: Connection reset by peer) | 12:11 | |
| *** sskartheekadivi <sskartheekadivi!~sskarthee@user/sskartheekadivi> has joined #cip | 12:11 | |
| jki | use cases? | 12:11 |
| iwamatsu | CONFIG_CRYPTO_AUTHENC is enabled on cip-kernel-configs | 12:11 |
| jki | quite a few "select" in the kernel... | 12:11 |
| pave1 | Kconfig help says: Authenc: Combined mode wrapper for IPsec. This is required for IPSec ESP (XFRM_ESP). | 12:11 |
| jki | IPsec - was already suspecting this | 12:12 |
| jki | I bet we have users who would shout out, "I need it", even if not all | 12:13 |
| jki | CONFIG_MAC802154 selects it as well | 12:13 |
| pave1 | We still should teach our users not to enable things they don't need, but that's long term project. | 12:13 |
| jki | sure - they will learn eventually ;) | 12:14 |
| pave1 | Or their customers will :-) | 12:14 |
| arisut | patches are already in in the latest kernels https://kernel.org/ | 12:14 |
| pave1 | I don't believe it is worth press release "run and disable CRYPTO_AUTHENC because sky is falling" | 12:14 |
| pave1 | ...before by the time they disable the config, better solution will be already available. | 12:15 |
| jki | nope, but some posting on the mailing list would be good | 12:15 |
| jki | we could communicate the workaround(s) now and ask for demand of faster fixes | 12:15 |
| jki | while waiting for 5.10 to settle and developing/testing 4.19 fix | 12:15 |
| jki | once the fixes are in our tree, we can communicate again and only then decide whether to release earlier | 12:16 |
| pave1 | So... 6.12.85 is out, mostly crypto changes. I believe that's related. | 12:16 |
| jki | several releases are due mid of May | 12:16 |
| jki | anyway, I think communicating is key unless we already consider this super-critical | 12:17 |
| jki | which does not seem to be the case | 12:17 |
| pave1 | 5.10.254 is out, too. | 12:17 |
| pave1 | Well, I did "Copy fail" -- Fun CVE -- CVE-2026-31431" post :-) | 12:17 |
| jki | yes, but also share more more structured overview | 12:18 |
| jki | for workarounds and for our patching status | 12:18 |
| jki | 5.10.254 is fixed, newer ones then as well | 12:18 |
| pave1 | I don't believe it is super-critical, but I believe simply doing the -cip releases is the easiest way to go forward. | 12:18 |
| uli_ | ftr, 5.10.253 is large, so 4.19 is not going to be an early release this time | 12:19 |
| uli_ | if it's supposed to be quick i'd have to leave 253 patches and do one based on 254 only instead | 12:19 |
| jki | we could pull the fix early into 4.19 and do the rest later | 12:19 |
| pave1 | uli: That would be the way to do it. I don't believe .254 changes depend on anything in .253. | 12:20 |
| iwamatsu | +1 | 12:20 |
| uli_ | i think so, too | 12:20 |
| jki | if we do earlier releases for the other CIP kernels, 4.19 should be treated similar | 12:20 |
| jki | unless there are technical complications | 12:20 |
| jki | so, who will look into the 4.19 backport? | 12:21 |
| pave1 | I believe we can do -cip releases fairly easily. -cip-rt may be more tricky. | 12:21 |
| arisut | 6.12 backports: https://lore.kernel.org/stable/20260430060702.110091-1-ebiggers@kernel.org/ | 12:21 |
| arisut | 6.1 backports: https://lore.kernel.org/stable/20260430062731.140497-1-ebiggers@kernel.org/ | 12:21 |
| jki | -rt could be handled like 4.19: no baseline updates | 12:21 |
| uli_ | jki: i will, i guess. it's in the pipeline anyway | 12:21 |
| jki | uli_; thanks! | 12:22 |
| jki | then we agree to give this fix prio in our queues and try to update all CIP kernels? | 12:23 |
| pave1 | jki: In emergency, that probably can be done, but ... just trying to do the regular way would be preffered option. | 12:23 |
| uli_ | +1 | 12:23 |
| pave1 | I think that's best. I can simply go 6.12-cip, 6.1-cip, 5.10-cip and then figure out what to do with -rt. | 12:23 |
| iwamatsu | +1 | 12:24 |
| jki | great | 12:24 |
| jki | hope this does not ruin anyone's long weekend | 12:25 |
| jki | (where there is one) | 12:25 |
| pave1 | Should I write some kind of "Copy fail is bad, disable CONFIG_foo especially on -rt, expect out of schedule kernels"? | 12:25 |
| pave1 | email? | 12:25 |
| jki | +1 - thanks! | 12:26 |
| jki | more on this? or other maintenance topics? | 12:26 |
| jki | 5 | 12:27 |
| jki | 4 | 12:27 |
| jki | 3 | 12:27 |
| jki | 2 | 12:27 |
| jki | 1 | 12:27 |
| jki | #topic Kernel release status | 12:27 |
| *** collab-meetbot changes topic to "Kernel release status (Meeting topic: CIP IRC weekly meeting)" | 12:27 | |
| jki | all green | 12:27 |
| jki | rest we just discussed | 12:27 |
| jki | 5 | 12:27 |
| jki | 4 | 12:27 |
| jki | 3 | 12:27 |
| jki | 2 | 12:27 |
| jki | 1 | 12:27 |
| jki | #topic Kernel testing | 12:28 |
| *** collab-meetbot changes topic to "Kernel testing (Meeting topic: CIP IRC weekly meeting)" | 12:28 | |
| arisut | nothing from me | 12:28 |
| pave1 | 7.0.3 is out; if we are testing it somewhere, tell me url :-) | 12:29 |
| jki | anything else on testing? | 12:30 |
| arisut | pave1, I'm currently fixing gentoo sources vulnerabilities | 12:30 |
| arisut | for 7.0,3 testing I think you could look KernelCI as usual | 12:31 |
| pave1 | ok, I'll ask again next week :-) | 12:31 |
| pave1 | I'd like https://gitlab.com/cip-project/cip-testing/linux-stable-rc-ci/-/tree/linux-7.0.y | 12:31 |
| iwamatsu | We don't have it, so we need to create it... | 12:33 |
| jki | so, $someone will do it once there is time ;) | 12:36 |
| jki | anything else? | 12:36 |
| arisut | most of the recent kernel added commit a664bf3d603d | 12:36 |
| arisut | t reverts the 2017 algif_aead in-place optimization, so page-cache pages can no longer end up in the writable destination scatterlist. Most major distributions are shipping the fix now. | 12:37 |
| jki | yes, this is what we discussed before, I think | 12:37 |
| pave1 | Yep. That's the "copy fail" fix. Optimalization was bogus, anyway, so I don't expect performance regressions. | 12:37 |
| arisut | looks now added on all new kernels | 12:38 |
| jki | down to 5.10, see above | 12:38 |
| arisut | yes | 12:38 |
| jki | so, anything else on /testing/? ;) | 12:39 |
| arisut | you can use the patch I linked for above for disabling authencesn.o on older kernels | 12:39 |
| jki | why? we have the reverts | 12:40 |
| pave1 | Lets discuss that at aob session or after the meeting. | 12:40 |
| jki | then let's move to aob - unless there is more on testing... | 12:40 |
| jki | 5 | 12:40 |
| jki | 4 | 12:40 |
| jki | 3 | 12:40 |
| jki | 2 | 12:40 |
| jki | 1 | 12:40 |
| jki | #topic AOB | 12:40 |
| *** collab-meetbot changes topic to "AOB (Meeting topic: CIP IRC weekly meeting)" | 12:40 | |
| jki | thanks for the first config extension feedback! | 12:41 |
| pave1 | arisut: Yes, that can be done, but that's quite a hack, and proper solution is as easy. | 12:41 |
| arisut | pave1, ok | 12:41 |
| pave1 | jki: Sorry for taking time. That pc104 stuff scares me a bit (I thought it must have been a mistake) -- that's old hardware, but we should be able to do it. | 12:42 |
| arisut | can you add also me in copy on the email/patch with the solution | 12:42 |
| jki | pavel: if you see any noteworthy effort increase as well, let me know | 12:43 |
| jki | there are more questions/wishes coming, I'm moderating them first | 12:43 |
| pave1 | arisut: We'll just update to latest stable kernels. There were released in last few hours, and they fix just this. | 12:43 |
| pave1 | jki: ok, but I don't expect much effort increase. It was just strange. | 12:44 |
| arisut | pave1, what about older cip kernels ? | 12:44 |
| pave1 | arisut: Down to 5.10, we have -stable fixes. For 4.19, we backport fixes from stable. 4.4 is not affected. | 12:44 |
| arisut | yes, I was meaning the 4.19 backport | 12:45 |
| *** sskartheekadivi <sskartheekadivi!~sskarthee@user/sskartheekadivi> has quit IRC (Read error: Connection reset by peer) | 12:46 | |
| *** sskartheekadivi <sskartheekadivi!~sskarthee@user/sskartheekadivi> has joined #cip | 12:46 | |
| jki | other topics? | 12:48 |
| pave1 | uli will be doing that. We hope 5.10 patches will simply apply. If not, we try to fit them | 12:48 |
| pave1 | as usual, if that's impossible, we can probably just disable that, too. | 12:48 |
| *** prabhakalad <prabhakalad!~prabhakar@97e54365.skybroadband.com> has quit IRC (Ping timeout: 246 seconds) | 12:49 | |
| *** prabhakalad <prabhakalad!~prabhakar@97e54365.skybroadband.com> has joined #cip | 12:50 | |
| jki | so... | 12:50 |
| arisut | jki, not from me I'm going back to pushing gentoo sources | 12:50 |
| jki | then let's close | 12:51 |
| jki | 5 | 12:51 |
| jki | 4 | 12:51 |
| jki | 3 | 12:51 |
| jki | 2 | 12:51 |
| jki | 1 | 12:51 |
| jki | #endmeeting | 12:51 |
| collab-meetbot | Meeting ended Thu Apr 30 12:51:28 2026 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 12:51 |
| collab-meetbot | Minutes: http://ircbot.wl.linuxfoundation.org/meetings/cip/2026/04/cip.2026-04-30-12.00.html | 12:51 |
| collab-meetbot | Minutes (text): http://ircbot.wl.linuxfoundation.org/meetings/cip/2026/04/cip.2026-04-30-12.00.txt | 12:51 |
| collab-meetbot | Log: http://ircbot.wl.linuxfoundation.org/meetings/cip/2026/04/cip.2026-04-30-12.00.log.html | 12:51 |
| *** collab-meetbot changes topic to "Civil Infrastructure Platform Project. CIP mailing list at https://lists.cip-project.org/g/cip-dev | CIP kernel meeting every Thursday at 13:00 UTC | Find the meeting logs at https://ircbot.wl.linuxfoundation.org/meetings/cip/ and chat logs at https://ircbot.wl.linuxfoundation.org/logs/%23cip/" | 12:51 | |
| jki | thanks! | 12:51 |
| pave1 | Thank you! | 12:51 |
| uli_ | thanks | 12:51 |
| masami | thank you | 12:51 |
| iwamatsu | Thank you | 12:51 |
| *** masami <masami!~masami@FL1-111-168-44-134.tky.mesh.ad.jp> has quit IRC (Quit: Leaving) | 12:51 | |
| arisut | tnx | 12:52 |
| *** jki <jki!~jki@62.156.206.16> has quit IRC (Quit: Leaving) | 12:53 | |
| *** prabhakalad <prabhakalad!~prabhakar@97e54365.skybroadband.com> has quit IRC (Ping timeout: 245 seconds) | 12:54 | |
| *** prabhakalad <prabhakalad!~prabhakar@97e54365.skybroadband.com> has joined #cip | 12:57 | |
| *** prabhakalad <prabhakalad!~prabhakar@97e54365.skybroadband.com> has quit IRC (Client Quit) | 12:58 | |
| *** prabhakalad <prabhakalad!~prabhakar@97e54365.skybroadband.com> has joined #cip | 12:58 | |
| *** ctani <ctani!~ctani@86.121.79.65> has quit IRC (Quit: Client closed) | 13:31 | |
| *** sskartheekadivi <sskartheekadivi!~sskarthee@user/sskartheekadivi> has quit IRC (Ping timeout: 265 seconds) | 14:16 | |
| *** sskartheekadivi <sskartheekadivi!~sskarthee@user/sskartheekadivi> has joined #cip | 14:36 | |
| *** arisut <arisut!~none@gentoo/developer/alicef> has quit IRC (Quit: install gentoo) | 15:01 | |
| *** arisut <arisut!~none@gentoo/developer/alicef> has joined #cip | 15:04 | |
| *** ChanServ sets mode: +o arisut | 15:04 | |
| *** sskartheekadivi <sskartheekadivi!~sskarthee@user/sskartheekadivi> has quit IRC (Read error: Connection reset by peer) | 16:28 | |
| *** sskartheekadivi <sskartheekadivi!~sskarthee@user/sskartheekadivi> has joined #cip | 16:31 | |
| *** monstr <monstr!~monstr@nat-108f.starnet.cz> has joined #cip | 16:57 | |
| *** monstr <monstr!~monstr@nat-108f.starnet.cz> has quit IRC (Ping timeout: 248 seconds) | 17:02 | |
| *** sskartheekadivi <sskartheekadivi!~sskarthee@user/sskartheekadivi> has quit IRC (Ping timeout: 245 seconds) | 21:27 | |
| *** sskartheekadivi <sskartheekadivi!~sskarthee@user/sskartheekadivi> has joined #cip | 21:33 | |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!