kernel-hardening.lists.openwall.com archive mirror
 help / color / mirror / Atom feed
From: Brad Spengler <spender@grsecurity.net>
To: Daniel Micay <danielmicay@gmail.com>
Cc: Kernel Hardening <kernel-hardening@lists.openwall.com>,
	pageexec@freemail.hu
Subject: Re: [kernel-hardening] Stop the plagiarism
Date: Sun, 4 Jun 2017 08:49:00 -0400	[thread overview]
Message-ID: <20170604124900.GA7153@grsecurity.net> (raw)
In-Reply-To: <CA+DvKQ+1BRVgWRcg_anBdf-8cV4=mgu8J9Kf1xVcbZBVePHSsw@mail.gmail.com>

[-- Attachment #1: Type: text/plain, Size: 2743 bytes --]

> comparable to where it came from. If they independently write the
> features without using your code as a reference (KSTACKOVERFLOW vs.
> VMAP_STACK

This is demonstrably false given Andy's own public statements:
https://lwn.net/Articles/692208/

> ARM memory domain PAN emulation

As posted in the other message, I emailed directly with the person
solely credited for ideas for that work, detailing everything
exactly and linking to the blog post about it.  I leave it up to
others to decide if they think it's at all likely if during discussions
of the topic, it never came in the head of that person that they had
discussed this very exact same thing a few years prior, while coming
up with the same solution.

> an issue with it. You weren't truly interested in being paid to
> upstream it yourself either, only to develop code downstream in a
> massive out-of-tree patch set.

Where's the evidence?  The PaX Team gave permission for anyone to publish
any private contracts and financial terms of real offers made.  Where are
they?  I don't recall if you and I ever had a real discussion about
upstreaming where I laid out the (what should be obvious) concerns --
namely that given that we have limited time, any paid upstreaming work,
being largely a waste of time and non-technical in nature, would need to
also ensure the continuity of the actual technical grsecurity work
and allow us to expand our pool of available hours.  Otherwise there's no
possibility for stable funding to continue any work and no time to do it,
which is exactly the short-sighted thinking I had mentioned to Kees since
the very beginning of the KSPP.  It's pointless to rehash it at this point
since again as mentioned, there is no evidence whatsoever that the
companies funding KSPP ever made any real offers to fund the work.  That
decision was made long ago, and we're simply continuing our work and doing
what needs to be done to ensure it continues.  As a reminder, upstreaming
doesn't solve all problems, and grsecurity would need to continue to exist
regardless of any upstreaming efforts.  You need look no further at the
100 or so KSPP emails about a single-line TIOCSTI change that not one
user has complained about in years.

> available patch. Sending me a legal threat over that tweet was
> ridiculous especially considering that the post linked to by that

You missed a step in there in your public portrayal of private messages
(it's not the first time, but I don't expect much else from someone
who needs to cultivate an image to fool the public into assisting him
with code his business depends on to sell).  Instead of replying to
or acknowledging my initial simple mail, you went on IRC to joke about
it publicly with other people.

-Brad

[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 836 bytes --]

  parent reply	other threads:[~2017-06-04 12:49 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-06-03 11:30 [kernel-hardening] Stop the plagiarism Brad Spengler
2017-06-03 13:53 ` Daniel Micay
2017-06-03 14:21   ` Brad Spengler
2017-06-03 15:55     ` Daniel Micay
2017-06-04  3:28       ` Brad Spengler
2017-06-04 14:15         ` Daniel Micay
2017-06-05  0:12           ` Brad Spengler
2017-06-05  1:21             ` Daniel Micay
2017-06-05  1:44               ` Daniel Micay
2017-06-04 12:49       ` Brad Spengler [this message]
2017-06-04 13:48         ` Hector Martin
2017-06-04 14:44           ` Brad Spengler
2017-06-04 16:59             ` Hector Martin
2017-06-03 15:08 ` Lionel Debroux
2017-06-03 15:16 ` Matt Brown
2017-06-03 17:32 ` Rik van Riel
2017-06-04  7:16 ` Kees Cook
2017-06-04 11:43   ` Brad Spengler
2017-06-06  0:29     ` Kees Cook
2017-06-06 13:05     ` [kernel-hardening] " Jonathan Corbet
2017-06-05 17:43   ` [kernel-hardening] " Pavel Labushev

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20170604124900.GA7153@grsecurity.net \
    --to=spender@grsecurity.net \
    --cc=danielmicay@gmail.com \
    --cc=kernel-hardening@lists.openwall.com \
    --cc=pageexec@freemail.hu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).