Is @gregkh saying #linux kernel is at the point where testing it and reporting more security bugs does not have any value anymore? I am concerned.
"We are drowning in syzkaller reports and just throwing them at us doesn't really help anyone here anymore"
https://lore.kernel.org/dri-devel/20200710103910.GD1203263@kroah.com/ …
-
-
But it's always been this way, it's just that automated bug reporting tools like syzbot and the like stress the system in ways it has never been stressed as it shows the problem we have much better.
-
It's not the tools fault, keep them submitting and sending us stuff. It's just that fixing the issues reported is slow. Note, we have people stepping up to help with this, it just takes time to get them up to speed and we need more.
- Pokaż odpowiedzi
Nowa rozmowa -
-
-
I don't think quality/security/testing can be improved by adding more people. We have tremendous amount of resources assigned to
#linux already, 1000x average project has. It's possible to have good quality with 1 dev on a project, and bad quality with 10000 devs. 1/n -
Consider devs don't yet write meaningful commit descriptions. If Linus says "it would be good to have meaningful commit descriptions". It can't be solved with Linus now adding descriptions to all commits. Also stuffing 10 devs to just add descriptions won't work too. 2/n
- Pokaż odpowiedzi
Nowa rozmowa -
-
-
I would do it for money!
Dziękujemy. Twitter skorzysta z tych informacji, aby Twoja oś czasu bardziej Ci odpowiadała. CofnijCofnij
-
Wydaje się, że ładowanie zajmuje dużo czasu.
Twitter jest przeciążony lub wystąpił chwilowy problem. Spróbuj ponownie lub sprawdź status Twittera, aby uzyskać więcej informacji.