Live data from Hacker News

Linus: Don't bother with grsecurity. Their patches are pure garbage

spinics.net

111–120 of 172 posts

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#111
post #48

Earlier quoted context omitted.

Sure you can sell it, and under whatever terms you like. But you have to _also_ provide the full source under the GPL, not under "the GPL with additional constraints". I'm no lawyer, but I highly doubt it'll hold. And buying Linux from them could be very toxic as "GPL violation" => "termination of license" -- and I'm not sure how you go about getting a new license :)

No, under the GPL you have the right to redistribute the source. You don't have a right to receive new patches or maintain any particular subscription, that is a different consideration that you can maintain in a separate contract.

True,

But punishing people for exercising their rights, is quite similar to placing restrictions on said rights.

I'm no lawyer, but you generally can't out-smart the law :)

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#112
post #10

See Linus' follow-up http://seclists.org/oss-sec/2017/q2/596 for clarification: > They aren't split up, there has never been any effort by you to make them palatable to upstream, and when somebody else dioes try to make them palatable to upstream, you start crying about how people are taking advantage of your work (hah), and try to make them private instead. ... > It's literally less work for people to re-implement t…

And the other guy's reply: http://seclists.org/oss-sec/2017/q2/597

>You're out of touch with reality Linus. In what world would anyone sign up for your "generous" offer to be called clowns, that their patches are garbage, that they should do thousands of hours of work for free for a bunch of multi-billion dollar corporations that aren't contributing a single dime or any direct work back?

Seems a strange thing to say for a company whose revenue is completely dependent on a product, and it's source code, which they obtain for free, to modify and sell for profit.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#113
post #78

Earlier quoted context omitted.

> their toxic communications If you can't handle the truth, then every truhful communication can be "toxic" to you.

Excuse typos from phone...A quote from Randy pausch (0) last lecture(1) "And he put his arm around my shoulders and we went for a little walk and he said, Randy, it’s such a shame that people perceive you as so arrogant. Because it’s going to limit what you’re going to be able to accomplish in life. What a hell of a way to word “you’re being a jerk.” [laughter] Right? He doesn’t say you’re a jerk. He says people are…

Now imagine Randy continuing with his behaviour and you having that chat with him once every x months. After few of these, what would you tell Randy?

Imagine Randy worked for you, or under you on a project.

I've been on teams where people left quietly or loudly because of "Randies", going through the pains to change jobs.

Will you still have the same response for Randy?

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#114
post #70

Earlier quoted context omitted.

If you speak the truth like an asshole all anyone will take away from it is that you're an asshole.

Sure. But sometime, you can take away only that. but the loss will be all yours. I mean, somebody can give you a block on gold unpolished and unwrapped. Sure, you can say, "How dare you give me that gold unwrapped! There is no way I am taking it. I demand you give that wrapped up property in fancy paper and tied with a ribbon." Sure you can say that. But the loss will be all yours. You got the shit anyway and gained…

I'm not sure gold is the right analogy in this case.. I think that is holding grsecurity's work in higher esteem than is necessary. Don't forget, the code is just part of the work. Ones attitude in contributing that code is another large part of what makes the work "gold".

A better analogy might person A be handing person B back an improvement on person B's own recipe. However, the improvement is written on a piece of paper drenched in piss.

Don't forget, the entire reason grsecurity is able to exist at all is because the Linux kernel is open source and because countless of volunteers and companies have dedicated their time and energy doing exactly what grsecurity fails to do, contributing back in a manner which makes live livable for the maintainers. Each and every one of them could've decided to not bother properly splitting up patches, to not bother documenting their changes properly, and they personally wouldn't have been worse off in a lot of cases. However, because they decided to use proper communication skills (eg. not be a dick), everyone wins.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#115
post #42

Earlier quoted context omitted.

That depends on how you read section 6 of the GPL2. It states in part: > You may not impose any further restrictions on the recipients' exercise of the rights granted herein. The central right granted under the GPL is, of course, the right to modify and redistribute the source. I'm not a lawyer, and I'm certain that Grsecurity could find a number of legal arguments that what they're doing is allowed (likely starting…

It is enough for them to send the source on a written request. May be a link (working!), may be source code on a disk. Someone will have to set up an automatic snail mailer. If they do not respect that, they are explicitly violating GPL.

The point is if they punish you (such as discontinue business relationship) because you send a request to obtain the source, and exercise the rights you've been granted in the GPL, well, that's an additional restriction.

I'm no lawyer, but the spirit of the law or a contract matters. You can't avoid a speeding ticket because the wheels of your car wasn't touching the road in the photo :)

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#116

How are the Linux Foundation's funds allocated, and how much say does Linus have in it ? Most of this boils down to lack of money and attribution for grsec. Why didn't the Linux Foundation or Linus try to officially fund grsec to upstream their patches ? KSPP is still costing money. How much would it have cost to pay grsec directly instead ?

As far as I understand that is the opposite of how it works. The linux foundation was set up to receive funds from big business contributors - like Intel, Microsoft etc, who have an interest in the continuation of the linux kernel and wish to pay for jobs which didn't have a source of funding (i.e. Linus's job and other maintainer) and who wished to remain non-partisan. So these companies provide both code and money. That money isn't meant to be kicked back to profit-making companies as far as I understand.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#117
post #78

Earlier quoted context omitted.

> their toxic communications If you can't handle the truth, then every truhful communication can be "toxic" to you.

Excuse typos from phone...A quote from Randy pausch (0) last lecture(1) "And he put his arm around my shoulders and we went for a little walk and he said, Randy, it’s such a shame that people perceive you as so arrogant. Because it’s going to limit what you’re going to be able to accomplish in life. What a hell of a way to word “you’re being a jerk.” [laughter] Right? He doesn’t say you’re a jerk. He says people are…

You know, one can be a jerk when others don't actually deserve his accomplishments.

Also, jerk-circlejerk is a construct sometimes used as a protection from overly emotional people to actually get things done.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#119

Earlier quoted context omitted.

That's a pretty interesting loophole in the GPL: apparently (at least with V2), it might be fine to impose consequences for exercising your rights while technically giving them to you. It certainly violates the spirit of the GPL even if it doesn't violate the letter.

It does not impose amy restrictions on getting the code. You need to write a bot to get status updates though. Mailing list is not the code. If he starts filtering on the web server or rejecting direct source requests, he starts violating the letter of GPL 2.

I'm not sure that your claim about where the line is holds up: the GPLv2 never requires you to give your source to anyone unless you first give them binaries. That's why web sites don't have to give out their sources to everyone who visits their site if they use a GPL library for instance.

In any case, if what you say is correct, the grsecurity team are still trying to hold the threat of a more annoying experience over their users in order up prevent them from exercising their rights under the GPLv2.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#120
post #40

So, just to confirm I see this correctly: Grsecurity creates patches for issues in upstream, but their patches are too fucking big/ugly, so nobody upstream really wants to merge them, and when someone tries to fix em (take the important bits out), grsecurity complains about them using their work. Grsecurity then say they don't feel like doing a lot of work on their patches when they're not paid to do it.

Along with that Grsec then says that if while the patch is GPLv2 if you distribute them they'll never let you subscribe again to get the patch in the future.

They've turned core infrastructure enhancements into what might as well be one of Microsoft's "reference source" deals, or a EULA.
Post reply on HN