Live data from Hacker News

Linus: Don't bother with grsecurity. Their patches are pure garbage

spinics.net

101–110 of 172 posts

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#101
post #90

Earlier quoted context omitted.

> their toxic communications If you can't handle the truth, then every truhful communication can be "toxic" to you.

There is not factual statement argument in that mail, so it can hardly be "the truth". Except the truth about Linus emotions (strongly negative). It is an emotional outburst, not learning material.

The comment I was replying was about the general "toxic communication" from these people..Not about this specific mail...

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#102

Earlier quoted context omitted.

And the other guy's reply: http://seclists.org/oss-sec/2017/q2/597

Seems like a waste of time for him to hold up that side of the argument. Even if he's 100% correct, what's he going to achieve? The changes aren't going into the kernel until they get past Linus, and for that to happen the patches need to meet the same standards as every other patch. It's not like he's going to lower the bar for one company.

Same goes for Linus though. The "best" he can achieve is maybe stopping people from getting patches from grsecurity, which isn't a very productive use of his time either. Relations between these two camps have been poisoned long ago, unless someone with a budget decides it's worth paying grsecurity to help patch the mainline kernel I don't expect any change, and even then I wouldn't be surprised if that project fails.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#103
post #59

Reading one of the follow-up e-mail http://seclists.org/oss-sec/2017/q2/586 Wouldn't it be nice if you didn't demand free work of us in our free time? seems an odd line, but is there some context for the non-Linux person on what is going on?

Don't count on this recount to be correct but as far I've followed it: 200x? - grsecurity patchset is introduced and fixes a lot of bug-classes (!) and introduces lot's of security improvements to the kernel that are ground breaking and find their way in other systems like *BSD / Windows 200x-201x - code and trademarks of grsecurity get ripped from embbedded vendors - Linux foundations does nothing because they don't…

"2016-2017: - Linux foundation founds KSPP and works on integrating basically PaX/grsecurity into mainline - does not even ask grsecurity or PaX if they want to get paid for helping but they are flamed at and bothered with inquiries from devs - according to grsecurity most of KSPP work is copy&paste the grsecurity code without deeper understanding"

I don't follow this stuff closely, but I believe that the KSPP was started by Kees Cook because other approaches had failed: grsecurity/PaXTeam had been unwilling to cooperate to get their patches upstream for a long time, so the only way to move things forwards for everybody was to re-implement the functionality without PaXTeam.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#104
post #63
post #9

Earlier quoted context omitted.

I kind of find Linus refreshing, although I'm not sure that would survive working directly with him. I think you're begging the question though: surely compatibility/ABI stability/performance trumps extreme security (for some values of 'extreme') for people and in cases where that is true. I happen to agree with you and Linus on this (baring a known exploit of an unpatched security bug), but that heirarchy is nowhere…

I've always found it weird that de Raadt is admired for being abrasive, and Torvalds is pilloried. I've always wondered, if the grsec people are such believers of 'security above all else', why they just don't work with OpenBSD instead.

>I've always found it weird that de Raadt is admired for being abrasive, and Torvalds is pilloried.

It's because most of the people who get upset about Linus, have never heard of Theo. The ones who have, tend to think he's worse.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#105
post #40

So, just to confirm I see this correctly: Grsecurity creates patches for issues in upstream, but their patches are too fucking big/ugly, so nobody upstream really wants to merge them, and when someone tries to fix em (take the important bits out), grsecurity complains about them using their work. Grsecurity then say they don't feel like doing a lot of work on their patches when they're not paid to do it.

[deleted]

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#106
post #2

Strong words. Usually when Linus ways in so strongly on a topic he's pretty certain of his take on it-it'll be interesting to see if there's further discussion on both ends.

>How could they know that calling people clowns and their work garbage wasn't payment enough?

>With no technical content coming from your end, there's no need to discuss anything further -- don't waste your time because I won't reply.

I don't think there will be any further discussion.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#107

Earlier quoted context omitted.

And the other guy's reply: http://seclists.org/oss-sec/2017/q2/597

Note: this is a lot tamer than a lot of the stuff I've seen him post in lwn.net comments. I have a lot of respect for their work. It's just a shame that their toxic communications will make the good things they do so much less likely to be widely adopted.

> It's just a shame that their toxic communications will make the good things they do so much less likely to be widely adopted.

You are talking as if they wanted it to be upstreamed in the first place, which isn't quite obvious from this email.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#108
post #63
post #9

Earlier quoted context omitted.

I kind of find Linus refreshing, although I'm not sure that would survive working directly with him. I think you're begging the question though: surely compatibility/ABI stability/performance trumps extreme security (for some values of 'extreme') for people and in cases where that is true. I happen to agree with you and Linus on this (baring a known exploit of an unpatched security bug), but that heirarchy is nowhere…

I've always found it weird that de Raadt is admired for being abrasive, and Torvalds is pilloried. I've always wondered, if the grsec people are such believers of 'security above all else', why they just don't work with OpenBSD instead.

I've always found it weird that de Raadt is admired for being abrasive, and Torvalds is pilloried.

Theo isn't universally loved. There was the time he was "pilloried" by none other than Linus himself, who said "the OpenBSD crowd is a bunch of masturbating monkeys".

The Internet is forever.

https://lkml.org/lkml/2008/7/15/296

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#109
How are the Linux Foundation's funds allocated, and how much say does Linus have in it ? Most of this boils down to lack of money and attribution for grsec. Why didn't the Linux Foundation or Linus try to officially fund grsec to upstream their patches ? KSPP is still costing money. How much would it have cost to pay grsec directly instead ?

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#110
After reading the entire exchange between Torvalds and Spengler I must say Torvalds was thoroughly trounced. It was like watching a child argue with an adult. Spengler provided facts, justification, reasoning and proof while Torvalds acted like a child and called him names and his work garbage. If you're going to call someone out then at least have the decency to properly address their reply instead of completely ignoring what they said and just saying what you want to say.
Post reply on HN