Ok, it seems reasonable to me. I'm sick of what KSPP/Linux foundation has been doing.
-
-
Some of us are sick of what grsec/spender has been doing... spender apparently bans people just for saying hi on the KSPP mailing list.
2 replies 0 retweets 2 likes -
That's not my concerns. I still think LF/CII should buy me PaX/Grsec's test patch. Spender/PaX team treated us well in past 16 yrs until..
1 reply 0 retweets 0 likes -
It makes no sense to blame other people for Spender's decision to stop sharing. That decision is his and his alone.
2 replies 0 retweets 3 likes -
Can you spell regression. In the views of some, KSPP/LF can't be trusted not to make a hash of kernel security engineering.
1 reply 0 retweets 1 like -
The vulnerability is not something that was introduced by KSPP, and I didn’t mean to imply that at all. The point is that grsecurity has better judgement about disabling dangerous features by default.
1 reply 2 retweets 2 likes -
As long as you don't care about DoS exploits and randomly crashing kernels. grsec has *terrible* judgement about those, and its default config is plagued with issues like that. They don't consider them real security problems.
2 replies 0 retweets 2 likes -
Can you elaborate what are the features in default config that you speak of?
1 reply 0 retweets 0 likes -
Replying to @slashbeast @bleidl and
SIZE_OVERFLOW for one. That compiler plugin is fundamentally broken and has endless false positives they keep missing, causing oopses or panics. At least once they actually managed to turn a false positive into a real problem with their "fix". I've been bit by S_O several times.
1 reply 0 retweets 0 likes -
Replying to @marcan42 @slashbeast and
Not sure if it's still up, but back when the patches we're public and support was via forum, every second thread was a new S_O false positive. And they missed obvious ones, like fixing an IPv4 code path without looking at the sibling IPv6 code path.
1 reply 0 retweets 0 likes
Hector Martin Retweeted Hector Martin
An S_O false positive with a broken, obviously untested and unreviewed fix is how I wound up panicking my kernel by pasting a long line of text into my terminal, also reproducible as a tweet-sized local DoS.https://twitter.com/marcan42/status/724745886794833920 …
Hector Martin added,
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.