Is @gregkh saying #linux kernel is at the point where testing it and reporting more security bugs does not have any value anymore? I am concerned.
"We are drowning in syzkaller reports and just throwing them at us doesn't really help anyone here anymore"
https://lore.kernel.org/dri-devel/20200710103910.GD1203263@kroah.com/ …
-
-
No. Both triage and fixing are labor intensive. It's of no immediate usefulness to find new bugs when there's already a shortage of labor to fix the ones already reported. Of course it becomes useful later once there is.
1 odpowiedź 0 podanych dalej 7 polubionych -
W odpowiedzi do to @RichFelker@dvyukov i jeszcze
If new reports at least come with some of the triage work already done, they're a lot more useful.
1 odpowiedź 0 podanych dalej 3 polubione -
W odpowiedzi do to @RichFelker@dvyukov i jeszcze
It's a big deal that they come with reproducible test cases though. It's a lot better than a typical bug report in that regard. Any crash of the core kernel from userspace could be treated as a serious, priority issue if it was robust and not scaled far beyond maintainability.
1 odpowiedź 0 podanych dalej 5 polubionych -
W odpowiedzi do to @DanielMicay@RichFelker i jeszcze
Linux doesn't have a labor shortage. Rather, the proportion of people working on correctness/robustness/security is tiny. There is far too much code being added and changed. Their attitude drives away many people who try to improve these things too.
3 odpowiedzi 1 podany dalej 6 polubionych -
W odpowiedzi do to @DanielMicay@dvyukov i jeszcze
I call that a labor shortage. They don't have enough volunteer or paid people to work on the stuff that needs to be done. They have plenty paid (by third parties) to work on other things (that those third parties want done).
1 odpowiedź 1 podany dalej 9 polubionych -
W odpowiedzi do to @RichFelker@DanielMicay i jeszcze
Bingo. We have plenty of paid developers for new features wanted by those companies paying for that work. We have almost no paid developers to do bug fixing and maintenance and patch reviews.
3 odpowiedzi 8 podanych dalej 30 polubionych -
W odpowiedzi do to @gregkh@RichFelker i jeszcze
But it's always been this way, it's just that automated bug reporting tools like syzbot and the like stress the system in ways it has never been stressed as it shows the problem we have much better.
1 odpowiedź 0 podanych dalej 3 polubione
It's not the tools fault, keep them submitting and sending us stuff. It's just that fixing the issues reported is slow. Note, we have people stepping up to help with this, it just takes time to get them up to speed and we need more.
-
-
W odpowiedzi do to @gregkh@RichFelker i jeszcze
There are also some bugs that require intensive knowledge and that means it may come down to a few people to fix those and even they might take a while. Or often we end up in a long discussion about what the right strategy is. See the KCSAN fix I upstreamed ~2 weeks ago.
0 odpowiedzi 0 podanych dalej 8 polubionychDziękujemy. Twitter skorzysta z tych informacji, aby Twoja oś czasu bardziej Ci odpowiadała. CofnijCofnij
-
Wydaje się, że ładowanie zajmuje dużo czasu.
Twitter jest przeciążony lub wystąpił chwilowy problem. Spróbuj ponownie lub sprawdź status Twittera, aby uzyskać więcej informacji.