All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Theodore Tso" <tytso@mit.edu>
To: "igor.stoppa@gmail.com" <igor.stoppa@gmail.com>
Cc: Miguel Ojeda <miguel.ojeda.sandonis@gmail.com>,
	Greg KH <gregkh@linuxfoundation.org>,
	ksummit@lists.linux.dev, istoppa@nvidia.com
Subject: Re: [TECH TOPIC] Improving kernel security & integrity by generalizing ad-hoc safety mechanisms
Date: Tue, 8 Sep 2026 10:44:29 -0400	[thread overview]
Message-ID: <aqAeUSS2TZkRUVao@mit.edu> (raw)
In-Reply-To: <CAH2bzCRTnb+A=HLhFzENBgFgsyjJ91sTLyOoxPgtFjhv+Gjcow@mail.gmail.com>

On Tue, Sep 08, 2026 at 04:52:13PM -0500, igor.stoppa@gmail.com wrote:
> Presently, if a new patch introduces either a vulnerability,
> or a regression in either functionality or performance,
> it gets rejected or at least it must be fixed accordingly.
> 
> We would need the safety-qualification criteria to be added to the list of
> properties measured and preserved across releases.

So perhaps you need to start with everything out-of-tree, and when
natural changes upstream changes, you can send patches upstream to
"fix" the issue, and we can see how annoyed everyone gets.

Your claim that it's not going to be draconian, but I think you need
to demonstrate whether or not this is actually the case.  Let's see
how much cooperation you will need from the various subsystems, and
whether it's going to involve a performance tax.  (And if there is a
performance tax, how bad is it going to be.)

Hint: if there needs to be a performance tax, it should only be paid
for those systems that care about the safety certification.  Maybe for
"safety certified" systems, people will be willing to pay a 20%
performance tax.  But everyone else.... probably not.

						- Ted

  reply	other threads:[~2026-09-08 14:45 UTC|newest]

Thread overview: 35+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-07 16:53 [TECH TOPIC] Improving kernel security & integrity by generalizing ad-hoc safety mechanisms igor.stoppa
2026-09-07 19:46 ` Greg KH
2026-09-07 21:42   ` igor.stoppa
2026-09-08  3:51     ` Theodore Tso
2026-09-08 10:14       ` igor.stoppa
2026-09-08 13:55         ` Theodore Tso
2026-09-08 14:32           ` igor.stoppa
2026-09-08 19:29             ` Steven Rostedt
2026-09-08 21:13               ` igor.stoppa
2026-09-08 23:14                 ` Steven Rostedt
2026-09-08 23:48                   ` igor.stoppa
2026-09-09  7:44                     ` Gabriele Monaco
2026-09-09  9:40                       ` igor.stoppa
2026-09-09 15:22                         ` Gabriele Monaco
2026-09-09 16:07                           ` igor.stoppa
2026-09-09 16:14                             ` Steven Rostedt
2026-09-09 16:24                               ` igor.stoppa
2026-09-09 16:32                                 ` Steven Rostedt
2026-09-10 10:10                             ` Gabriele Monaco
2026-09-08  5:05     ` Greg KH
2026-09-08 11:26       ` igor.stoppa
2026-09-08 11:54         ` Greg KH
2026-09-08 12:25           ` igor.stoppa
2026-09-08 12:39             ` Greg KH
2026-09-08 12:52               ` igor.stoppa
2026-09-08 13:11             ` Miguel Ojeda
2026-09-08 13:52               ` igor.stoppa
2026-09-08 14:44                 ` Theodore Tso [this message]
2026-09-08 15:32                   ` igor.stoppa
2026-09-08 12:41         ` James Bottomley
2026-09-08 13:03           ` igor.stoppa
2026-09-08 15:40             ` Steven Rostedt
2026-09-08 16:09               ` igor.stoppa
2026-09-08 17:35                 ` Steven Rostedt
2026-09-09  1:31                   ` Theodore Tso

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aqAeUSS2TZkRUVao@mit.edu \
    --to=tytso@mit.edu \
    --cc=gregkh@linuxfoundation.org \
    --cc=igor.stoppa@gmail.com \
    --cc=istoppa@nvidia.com \
    --cc=ksummit@lists.linux.dev \
    --cc=miguel.ojeda.sandonis@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.