From: "Dr. Greg" <greg@enjellic.com>
To: Casey Schaufler <casey@schaufler-ca.com>
Cc: Paul Moore <paul@paul-moore.com>,
Linus Torvalds <torvalds@linux-foundation.org>,
Jonathan Corbet <corbet@lwn.net>,
Tetsuo Handa <penguin-kernel@i-love.sakura.ne.jp>,
LKML <linux-kernel@vger.kernel.org>,
linux-security-module@vger.kernel.org
Subject: Re: [GIT PULL] tomoyo update for v6.12
Date: Fri, 11 Oct 2024 12:06:18 -0500 [thread overview]
Message-ID: <20241011170617.GA5139@wind.enjellic.com> (raw)
In-Reply-To: <88954576-5e62-4d95-bdf4-3913ffea68c2@schaufler-ca.com>
On Tue, Oct 08, 2024 at 11:25:16AM -0700, Casey Schaufler wrote:
Good morning, I hope the week has gone well for everyone.
> On 10/8/2024 4:14 AM, Dr. Greg wrote:
> > ...
> >
> > Which we also believe justifies more attention than what it has been
> > able to receive in 20 months.
>
> You're right. You're also not alone. There are things that you can do
> that will help get the review you're looking for. Developers who attend
> to the needs and preferences of reviewers get a whole lot more attention
> than those who fuss and fume about not getting what they "deserve". My
> hopefully constructive recommendations are:
We put a significant body of code and engineering time on the table to
try and improve the Linux security ecosystem. We did this because in
certain circles the value of our approach is understood and there was
a desire to have it more generally available.
We don't believe we 'deserve' anything, review or don't review, it is
completely up to everyone involved.
Believe me when I say we are perfectly capable of supporting our
constituencies without contributing a single line of code or comment
back to the good of the Linux security commons.
Our aggravation in all of this is when statements are made regarding
serious and supposedly well understood flaws in our approach that
'everyone' agrees to be the case. Statements that are a complete and
utter crock of bullshit meant to simply gaslight the situation that
has gone down.
Hopefully our choice of lingua franca is sufficiently simple and
unsophisticated.
We would, again, encourage everyone to re-read our previous e-mail
where we outlined our concerns over the status of the review that did
occur.
We do respect reviewers, but let's engage in some sense of
intellectual honesty. This is not a situation of some poor lonely
overworked individual reviewing Linux code in their mother's basement
at night in Gulley, Minnesota while they work at the Cenex Station
during the day.
Paul has publically stated that Microsoft employees him to maintain
the Linux security system because of Microsoft's concern for the long
term health and well being of Linux. In case anyone doubts this or
missed it, here is the link:
https://lore.kernel.org/linux-security-module/20230608191304.253977-2-paul@paul-moore.com/
Unfortunately our experience seems to challenge Linus' mantra of:
"Code talks, bullshit walks".
Perhaps times have changed for Linux in this new custodial
environment.
> 1. Lead with code. Save the documentation for later.
> 2. Incremental implementation. Don't drop the whole mess on the
> reviewers at once. A patch set should be a story, with each patch
> introducing one new element.
> 3. Emphasize the similarities with existing implementations. No one
> wants to deal with novel or clever code. If it is familiar, it is
> easy to understand.
> 4. Thank your reviewers. Complaints about review latency typically
> increase it.
> 5. Do some reviews yourself. That will get in the good graces of other
> reviewers.
> 6. Be brief. The biggest single problem with reviewing TSEM has been that
> doing anything takes so long. Multiple paragraph responses to an issue
> don't help. Say it, say it once, say it in small words, and use as
> few of those as possible.
We appreciate the insight and recommendations, we will see how and
where all of this ends up getting litigated.
Given the zeal for simplicity embodied in these recommendations, we
will assume that adversaries targeting Linux from a security
perspective will also choose to limit themselves to simple and
unsophisticated means and methods of attack.
Have a good weekend.
As always,
Dr. Greg
The Quixote Project - Flailing at the Travails of Cybersecurity
https://github.com/Quixote-Project
next prev parent reply other threads:[~2024-10-11 17:06 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <0c4b443a-9c72-4800-97e8-a3816b6a9ae2@I-love.SAKURA.ne.jp>
[not found] ` <877cavdgsu.fsf@trenco.lwn.net>
2024-10-01 14:00 ` [GIT PULL] tomoyo update for v6.12 Paul Moore
2024-10-01 16:36 ` Linus Torvalds
2024-10-01 18:22 ` Paul Moore
2024-10-02 3:31 ` Tetsuo Handa
2024-10-02 14:01 ` Paul Moore
2024-10-02 23:09 ` Tetsuo Handa
2024-10-02 23:50 ` Tetsuo Handa
2024-10-03 2:45 ` John Johansen
2024-10-03 4:26 ` Tetsuo Handa
2024-10-03 5:35 ` John Johansen
2024-10-03 6:16 ` Tetsuo Handa
2024-10-03 12:59 ` Tetsuo Handa
2024-10-05 4:06 ` John Johansen
2024-10-05 3:59 ` John Johansen
2024-10-03 15:39 ` Dr. Greg
2024-10-05 4:24 ` John Johansen
2024-10-03 2:33 ` John Johansen
2024-10-02 10:38 ` Dr. Greg
2024-10-02 14:35 ` Paul Moore
2024-10-03 2:24 ` John Johansen
2024-10-08 11:14 ` Dr. Greg
2024-10-08 18:25 ` Casey Schaufler
2024-10-11 17:06 ` Dr. Greg [this message]
2024-10-11 18:01 ` Casey Schaufler
2024-10-03 2:27 ` John Johansen
2024-10-03 15:43 ` Dr. Greg
2024-10-05 4:37 ` John Johansen
2024-10-04 18:40 ` Dr. Greg
2024-10-04 18:58 ` Paul Moore
2024-10-05 2:33 ` Dr. Greg
2024-10-05 16:21 ` Paul Moore
2024-10-07 11:21 ` Dr. Greg
2024-10-07 13:28 ` Paul Moore
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20241011170617.GA5139@wind.enjellic.com \
--to=greg@enjellic.com \
--cc=casey@schaufler-ca.com \
--cc=corbet@lwn.net \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=paul@paul-moore.com \
--cc=penguin-kernel@i-love.sakura.ne.jp \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).