5 ms·
Patches are reviewed just not in the way you are accustomed to, but it doesn't make it any less secure. The kernel is continually audited and tested, and is the
by chromedev 6y ago
Patches are reviewed just not in the way you are accustomed to, but it doesn't make it any less secure. The kernel is continually audited and tested, and is the most widely used kernel in security devices.
What you are asking for is that developers should have to prove their real-life identity and authenticate to a public SCM system and that somehow makes it more secure, when hidden exploits could as easily be sent as a PR on GitHub and merged by someone who didn't know better or who can just play dumb.
- jeffbee 6y agoI don't buy "continually audited and tested". That is a variant of the "many eyes make all bugs shallow" theory or "Linus's Law", but that hasn't proven to be the case. The Linux kernel is full of bugs and many of them hang around for years. Also the kernel testing story is a total joke. Perhaps you meant that people use the kernel and therefore it's "tested"?
- jnurmine 6y agoCalling Linux testing a "total joke" is a total joke in itself -- of course Linux is not perfect (nothing is). As for testing, there is kernelci.org, LTP, Syzbot, LKFT and so on. It's not just a bunch people in basements booting up the latest Linux and calling it testing.
- jeffbee 6y agoThe fact that syzkaller finds a new bug every 10 seconds is an indictment of Linux testing, not evidence of its quality.
- edoceo 6y agoI couldn't find anything at every 10 seconds (wouldnt that be 8k issues per day?) This reporting list has a few per day https://groups.google.com/forum/m/#!forum/syzkaller-bugs https://groups.google.com/forum/m/#!forum/syzkaller-bugs Isn't testing supposed to find bugs? And aren't fuzzers identifying issues that /might/ exist in theory but dont manifest in practice? From your assessment I'm surprised my Linux boxen don't crash every day and really surprised I had one stay online for five years - but, many things things about Linux surprise me.
- jeffbee 6y agoTesting is supposed to prevent bugs from being committed. Finding the bugs in released software after the fact is the worst possible process. The fact is that people discover and fix bugs, and then years later someone else commits the same mistake again, and nothing prevents this because the kernel has literally zero pre-commit unit tests. Here's an example (thread by the author of syzkaller). https://twitter.com/dvyukov/status/1169544165023240194 https://twitter.com/dvyukov/status/1169544165023240194
- edoceo 6y agoIt sounds like you've got a good handle on things, have you tried sending any patches?