4 ms·
It's the same reason other interesting things don't get mainlined from time to time: personalities and opinions. Linus is a loudmouth and he has every right to
by DominikD 10y ago
It's the same reason other interesting things don't get mainlined from time to time: personalities and opinions. Linus is a loudmouth and he has every right to be like that. It's his playground after all. But this leads to blind spots and dogmatism in areas that ultimately hurt the project.
In case of grsecurity Linus tends to disagree with their philosophy of what leads to more secure system and what doesn't. And if Linus thinks you're wrong, then you're wrong, period. So grsecurity crowd would have to bow and compromise (which collides with their philosophy) on what stuff gets integrated, how, etc.
What's good enough according to Torvalds is not good enough according to them. But let's say they kneel. They'd have to not only cut their baby in pieces and massage it over and over again, discussing every detail of design and implementation on the list for Linus to mercifully accept it, they'd invest time pleasing him instead of doing what they care about: improving security.
So it's a lose-lose for them. And mainline doesn't seem to care about security (contrary to popular belief I guess). So yeah, there you have it.
- CrLf 10y agoYou overestimate Linus' role in the process. The process is hierarchical and by the time patches reach Linus they're already bulk by the very definition of it. What leads to better security? Having an out-of-tree patch that few people use, or include parts of it in mainline thus benefiting everyone? Eventually most, if not all, of their changes would reach mainline. Also, is it good for security to accept bulk patches touching all kinds of sensitive parts of the kernel? I'd say that the existing process is better for security in the long run. This process isn't about bowing to anyone, and thinking about patches as someone's baby doesn't help either. This happens every day with patches from companies with deep pockets and big influence and they end up going along with the program to get their stuff accepted. The result is invariably better than the original bulk patch.
- DominikD 10y agoYou're missing the crucial part: grsecurity is not a company with deep pockets. There's little to no incentive for them to spend time on doing something, somewhere they're not terribly welcome. :) Yeah, I'm exaggerating Linus' involvement. But for me there's always personality stink around projects this size. And it's obviously not different for grsecurity itself or, say, OpenBSD. But this definitely has some major upsides too. Basically what I'm trying to say is that even this over the top image of Linus-the-Destroyer should not be read as negative. Everything is shades of gray. Having said that - there's a history of clashes between prominent Linux devs and grsecurity. At this point anyone (Linus or otherwise) would be more than justified shying away from any cooperation with grsecurity. At the same time this doesn't prevent active developers with commit rights from cherry-picking changes (which happens).
- vacri 10y agoI always think it's amusing when the guy who presides over one of the largest software projects in history, with probably the largest number of contributors, is painted as 'the destroyer' or similar.
- deleted 10y ago[deleted]