[PATCH 2/4] scripts: add "scan" mode to process-advisories.sh to find more backports

Siddhesh Poyarekar siddhesh@gotplt.org
Fri Aug 21 15:20:58 GMT 2026


On 2026-08-21 01:40, Rolf Eike Beer wrote:
> This will look through the stable branches to find additional backports of
> the fix for the given advisory.

That's neat, thank you for contributing this.  Just some suggested 
changes below.

> 
> Signed-off-by: Rolf Eike Beer <eb@emlix.com>
> ---
>   scripts/process-advisories.sh | 34 ++++++++++++++++++++++++++++++++--
>   1 file changed, 32 insertions(+), 2 deletions(-)
> 
> diff --git a/scripts/process-advisories.sh b/scripts/process-advisories.sh
> index a520fab5e6..00a8cd9416 100755
> --- a/scripts/process-advisories.sh
> +++ b/scripts/process-advisories.sh
> @@ -25,7 +25,7 @@ command=$1
>   
>   usage () {
>       cat >&2 <<EOF
> -usage: $0 {update|news}
> +usage: $0 {update|news|scan}

Maybe give it a more precise name, e.g. update-backports ?

>   EOF
>       exit 1
>   }
> @@ -33,7 +33,7 @@ EOF
>   command="$1"
>   
>   case "$command" in
> -    update|news)
> +    update|news|scan)
>       ;;
>       *)
>           usage
> @@ -69,6 +69,36 @@ advisories_update() {
>       done
>   }
>   
> +advisories_scan() {
> +  advisory=$1
> +
> +  if [ -z $1 ]; then
> +    echo "Usage: $0 update GLIBC-SA-YYYY-NNNN"
> +    exit 1
> +  fi
> +
> +  advisory_file=advisories/$advisory
> +
> +  FIX=$(sed -nr '/^Fix-Commit: /s/Fix-Commit: *([0-9a-fA-F]+) *\(2\.[0-9]+\).*/\1/p' $advisory_file)
> +
> +  if [ -z "${FIX}" ]; then
> +    echo "No Fix-Commit found in $advisory_file"
> +    exit 1
> +  fi

There could be multiple Fix-Commit entries on the same branch, which 
means you likely want to search for all of those commits on older branches.

Also, since backports also show up as `Fix-Commit:` with a different 
branch name, you might want to restrict the commits to those that exist 
on the master branch.

> +  for n in $(seq 20 44); do
> +    BACKPORT=($(git log ..origin/release/2.${n}/master --grep "cherry picked from commit ${FIX}"   --format=%H))
> +    if [ ${#BACKPORT[@]} -eq 0 ]; then
> +      continue
> +    fi
> +    if [ ${#BACKPORT[@]} -ne 1 ]; then
> +      echo "Multiple matches for backport of ${FIX} found in branch 2.${n}"
> +      continue

This sounds like a repo inconsistency; one shouldn't have multiple 
matches for a cherry pick of the same commit in a branch.  Maybe flag an 
error here?

> +    fi
> +    grep -q "^Fix-Commit: ${BACKPORT[0]} " $advisory_file || echo "Fix-Commit: ${BACKPORT[0]} ($(get_rel ${BACKPORT[0]}))" >> $advisory_file

Hmm, if the process errors out in between for some reason, you may end 
up with a partially updated advisory file.  That won't be a problem 
though, since the partially updated advisory file is still consistent 
and a subsequent run should be able to continue with it, as long as you 
have the check for existence of the commit on the master branch, as I 
suggested above.

> +  done
> +}
> +
>   advisories_news() {
>     rel=$(get_rel "HEAD")
>     for f in $(grep -l "^Fix-Commit: .* ($rel)$" advisories/*); do

Also, I wonder if looking for the CVE id would be a better way of 
looking for the backports, especially if there are custom fixes on older 
branches.  It's probably not a common problem though.

Thanks,
Sid


More information about the Libc-alpha mailing list