4 ms·
you conveniently forgot to mention the fundamental difference: the upstream kernel isn't developed for free whereas our code has always been. changes the equati
by PaXTeam 9y ago
you conveniently forgot to mention the fundamental difference: the upstream kernel isn't developed for free whereas our code has always been. changes the equation quite a bit, doesn't it?
- cryptarch 9y agoWhat do you mean, the Linux kernel isn't developed for free? Many contributors aren't paid. And do you have proof that PaXTeam is not paid, if you are indeed PaXTeam?
- PaXTeam 9y ago> What do you mean, the Linux kernel isn't developed for free? Many contributors aren't paid. you're wrong, see item 6 in https://opensource.com/article/16/12/yearbook-9-lessons-25-years-linux-kernel-development https://opensource.com/article/16/12/yearbook-9-lessons-25-y... though you might want to demand that Greg prove his identity first ;). > And do you have proof that PaXTeam is not paid, if you are indeed PaXTeam? sure, come visit me in hungary and i'll take you to the local tax authorities and grant you access to my files. of course you'll have to prove your own identity first ;).
- cryptarch 9y agoYou mean that some developers are paid to implement things by companies? Fair enough, though I'd still argue it's not developed commercially because no one pays to get access to the result (they only pay to influence the result). >> sure, come visit me in hungary That'd be amusing, maybe sometime this summer? I'm kinda busy right now setting up my business :') Let me know when you're around the Benelux, we could do the key-siging song-and-dance over a coffee or beer.
- cyphar 9y agoAt most 80% of Linux contributors have jobs at software companies. That doesn't mean that all of them are paid for their kernel development, but at least 20% of contributors are definitely not paid for it. As for grsecurity, 100% of the core grsecurity team (that work at "Open Source Security") are paid for their work. I will admit that I'm not fully aware of the interactions between PaXTeam and grsecurity, but I'd be shocked to hear that nobody at PaXTeam works at a software company related to security or kernel hardening.
- PaXTeam 9y agoand the source of those numbers is...? > As for grsecurity, 100% of the core grsecurity team (that work at "Open Source Security") are paid for their work. that's 100% false. both spender and me are developing our code in our free time. what the company is for is customer support, not R&D. shocked you are? :)
- cyphar 9y ago> and the source of those numbers is...? GregKH, who you linked in a cousin comment. IIRC ~20% of code authors are not associated with a company. And if we go by your logic, then an even larger proportion are not "being paid for their kernel work". For a concrete example, I'm a maintainer of container runtimes at my current job but I have contributed code to Linux as part of my job -- does that count as "being paid" for it? In my mind, yes. In your mind, clearly not. But in GregKH's statistics I count as an employee of a company (not an independent). But since you're too lazy to look at your own link, here's the article for 4.11 (https://lwn.net/Articles/720336/ https://lwn.net/Articles/720336/). 14% of changesets and 13% of lines changed are by people not associated with a company. > that's 100% false. both spender and me are developing our code in our free time. what the company is for is customer support, not R&D. shocked you are? :) "I work in an L3 support role on $technology, but any R&D work I do on $technology is completely unrelated." It's like you're not willing to acknowledge that the only reason someone would pay a two-person team for support on a kernel technology like grsecurity+PaX is that the same team is developing it. So even if your invoices don't have "development" written on them, the only reason you'd have customers is because of the fact that you are the main R&D behind what you're supporting.
- PaXTeam 9y agocan you quote Greg back on your "At most 80% of Linux contributors have jobs at software companies" because i don't see it in there? and you can add the source for your 20% while at it. on the other hand what Greg did say is this: > The majority of developers are paid for their work[...]. that's not at all true for our case, that's all i pointed out. > I'm a maintainer of container runtimes at my current job but I have > contributed code to Linux as part of my job. if it's on company time (and thus dime) then yes, it's a paid job. > 14% of changesets and 13% of lines changed are by people not associated with a company. not really, more than half of each is 'unknown', so you can't tell one way or another. anyway, not sure what these are supposed to prove/disprove given what Greg himself said in the above quote. > It's like you're not willing to acknowledge that the only reason someone would pay a two-person > team for support on a kernel technology like grsecurity+PaX is that the same team is developing it. indeed it's not the only reason but since it's not your business (no offense meant just stating a fact), i can't comment on this further. what i did mean however is something different than the direction you veered off: our work isn't developed because it's paid for, it's a completely volunteer free time project (spender has a day job unrelated to this work, and until about a year ago i didn't have any at all in fact). that is, if you took the money out of the picture, our work would still continue to live on as it has for the previous 16 years. that is absolutely not true for upstream linux development (if it were then all these companies have been cheated out of their money they spent on developer salaries).
- admax88q 9y agoThen find someone interested in paying for its development? Security improvements to Linux are great. However a hardened linux kernel is a derived work of the kernel. It's unethical to take free software, build upon it, redistribute to customers but under contract agreements which prevent them from exercising their freedoms afforded by the license of the kernel. If you think the linux kernel is crap, you are more than welcome to write your own kernel.