Is @gregkh saying #linux kernel is at the point where testing it and reporting more security bugs does not have any value anymore? I am concerned.
"We are drowning in syzkaller reports and just throwing them at us doesn't really help anyone here anymore"
https://lore.kernel.org/dri-devel/20200710103910.GD1203263@kroah.com/ …
-
-
No. Both triage and fixing are labor intensive. It's of no immediate usefulness to find new bugs when there's already a shortage of labor to fix the ones already reported. Of course it becomes useful later once there is.
1 odpowiedź 0 podanych dalej 7 polubionych -
W odpowiedzi do to @RichFelker@dvyukov i jeszcze
If new reports at least come with some of the triage work already done, they're a lot more useful.
1 odpowiedź 0 podanych dalej 3 polubione -
W odpowiedzi do to @RichFelker@dvyukov i jeszcze
It's a big deal that they come with reproducible test cases though. It's a lot better than a typical bug report in that regard. Any crash of the core kernel from userspace could be treated as a serious, priority issue if it was robust and not scaled far beyond maintainability.
1 odpowiedź 0 podanych dalej 5 polubionych -
W odpowiedzi do to @DanielMicay@RichFelker i jeszcze
Linux doesn't have a labor shortage. Rather, the proportion of people working on correctness/robustness/security is tiny. There is far too much code being added and changed. Their attitude drives away many people who try to improve these things too.
3 odpowiedzi 1 podany dalej 6 polubionych -
W odpowiedzi do to @DanielMicay@dvyukov i jeszcze
I call that a labor shortage. They don't have enough volunteer or paid people to work on the stuff that needs to be done. They have plenty paid (by third parties) to work on other things (that those third parties want done).
1 odpowiedź 1 podany dalej 9 polubionych -
W odpowiedzi do to @RichFelker@DanielMicay i jeszcze
Bingo. We have plenty of paid developers for new features wanted by those companies paying for that work. We have almost no paid developers to do bug fixing and maintenance and patch reviews.
3 odpowiedzi 8 podanych dalej 30 polubionych -
W odpowiedzi do to @gregkh@RichFelker i jeszcze
I don't think quality/security/testing can be improved by adding more people. We have tremendous amount of resources assigned to
#linux already, 1000x average project has. It's possible to have good quality with 1 dev on a project, and bad quality with 10000 devs. 1/n3 odpowiedzi 2 podane dalej 6 polubionych -
Consider devs don't yet write meaningful commit descriptions. If Linus says "it would be good to have meaningful commit descriptions". It can't be solved with Linus now adding descriptions to all commits. Also stuffing 10 devs to just add descriptions won't work too. 2/n
2 odpowiedzi 1 podany dalej 4 polubione -
W odpowiedzi do to @dvyukov@RichFelker i jeszcze
Linus has said that, did so again a week or so ago. So do many many maintainers, push back on the maintainers who allow sloppy changelog text to be accepted, I know I do.
2 odpowiedzi 0 podanych dalej 4 polubione
But really, twitter is not the medium for this type of discussion. It is a fun medium for rants though, so keep it up! :)
Wydaje się, że ładowanie zajmuje dużo czasu.
Twitter jest przeciążony lub wystąpił chwilowy problem. Spróbuj ponownie lub sprawdź status Twittera, aby uzyskać więcej informacji.