From: "Dr. David Alan Gilbert" <linux@treblig.org>
To: Mauro Carvalho Chehab <mchehab@redhat.com>
Cc: Eduard - Gabriel Munteanu <eduard.munteanu@linux360.ro>,
Jidong Xiao <jidong.xiao@gmail.com>,
david@lang.hm, Cong Wang <xiyou.wangcong@gmail.com>,
Kernel development list <linux-kernel@vger.kernel.org>
Subject: Re: Can we move device drivers into user-space?
Date: Sun, 26 Feb 2012 01:58:20 +0000 [thread overview]
Message-ID: <20120226015820.GB18931@gallifrey> (raw)
In-Reply-To: <4F497782.3060902@redhat.com>
* Mauro Carvalho Chehab (mchehab@redhat.com) wrote:
> Em 25-02-2012 13:10, Eduard - Gabriel Munteanu escreveu:
> > On Fri, Feb 24, 2012 at 04:21:09PM -0200, Mauro Carvalho Chehab wrote:
> >> Moving a buggy driver to userspace won't fix the bug. You're just moving
> >> it from one place to another place. Also, the code will likely require changes
> >> to work on userspace, so, the chances are that you're actually introducing more
> >> bugs.
> >
<snip>
> >> That's said, there are much more eyes inspecting the kernel sources than on any
> >> other userspace project. So, the risk of a bad code to be inserted unnoticed at
> >> the Linux kernel is degrees of magnitude lower than on an userspace driver.
> >
> > Those much more eyes have already missed important bugs in the past.
>
> Yes, nobody is perfect. But the probability that something passes on a 4000+ people
> review is lower than the probability of a bug on a piece of code where just one
> or two people are looking on it.
That there are 4000+ people reading a driver is a big assumption; for common
drivers I'd agree - one problem though is there are a lot of drivers for obscure
hardware or old/dead hardware/protocols that frankly near to nobody cares about.
Very few people read those drivers; yet sometimes they get built and distributed
and someone then finds that since no one has looked at them they're full of holes,
and given a malicious USB device for example, you can suddenly create one of these
devices that only 3 people have bothered to read the source to - 5 years ago.
(The Econet security bug recently would be an example of that).
There is a line which says that things that really aren't used
just shouldn't be built; but then there are things that are only used
by a few people, and then ones only used by a few organisations - and
it gets very difficult to say at what point you say just turn it off.
Dave
--
-----Open up your eyes, open up your mind, open up your code -------
/ Dr. David Alan Gilbert | Running GNU/Linux | Happy \
\ gro.gilbert @ treblig.org | | In Hex /
\ _________________________|_____ http://www.treblig.org |_______/
next prev parent reply other threads:[~2012-02-26 2:25 UTC|newest]
Thread overview: 68+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-02-23 4:56 Can we move device drivers into user-space? Jidong Xiao
2012-02-23 15:57 ` Cong Wang
2012-02-23 16:34 ` Jidong Xiao
2012-02-23 20:48 ` david
2012-02-23 21:01 ` Jidong Xiao
2012-02-24 18:21 ` Mauro Carvalho Chehab
2012-02-25 15:10 ` Eduard - Gabriel Munteanu
2012-02-26 0:06 ` Mauro Carvalho Chehab
2012-02-26 0:29 ` Richard Yao
2012-02-27 11:31 ` Mauro Carvalho Chehab
2012-02-26 1:58 ` Dr. David Alan Gilbert [this message]
2012-02-26 3:34 ` arts zhao
2012-02-27 11:29 ` Mauro Carvalho Chehab
2012-02-25 15:31 ` Richard Yao
2012-02-23 21:18 ` Roland Dreier
2012-02-24 15:19 ` Jidong Xiao
2012-02-24 15:38 ` Greg KH
2012-02-24 16:38 ` Jidong Xiao
2012-02-24 16:54 ` Greg KH
2012-02-24 17:06 ` Jidong Xiao
2012-02-24 17:13 ` Greg KH
2012-02-24 17:21 ` Jidong Xiao
2012-02-24 17:31 ` Greg KH
2012-02-25 2:33 ` Richard Yao
2012-02-25 4:28 ` Jidong Xiao
2012-02-24 17:10 ` Al Viro
2012-02-25 19:23 ` Jidong Xiao
2012-02-25 20:55 ` Greg KH
2012-02-25 23:43 ` Jidong Xiao
2012-02-26 17:40 ` Greg KH
2012-02-26 22:46 ` Greg KH
2012-02-27 11:17 ` Bernd Petrovitsch
2012-02-24 17:07 ` Guenter Roeck
2012-02-24 17:17 ` Greg KH
2012-02-24 17:47 ` Guenter Roeck
2012-02-24 18:34 ` Greg KH
2012-02-24 19:15 ` Henrik Rydberg
2012-02-24 19:26 ` Greg KH
2012-02-24 20:10 ` Henrik Rydberg
2012-02-24 20:16 ` Greg KH
2012-02-24 20:37 ` Henrik Rydberg
2012-02-24 20:56 ` Greg KH
2012-02-24 21:22 ` Henrik Rydberg
2012-02-24 21:30 ` Ted Ts'o
2012-02-24 22:14 ` Henrik Rydberg
2012-02-24 22:20 ` Greg KH
2012-02-24 22:49 ` Henrik Rydberg
2012-02-24 22:54 ` Greg KH
2012-02-24 23:14 ` Henrik Rydberg
2012-02-25 12:15 ` Theodore Tso
2012-02-26 9:54 ` Henrik Rydberg
2012-02-26 4:56 ` Bobby Powers
2012-02-26 10:47 ` Henrik Rydberg
2012-02-26 12:26 ` Richard Yao
2012-02-26 14:23 ` Bernd Petrovitsch
2012-02-26 15:29 ` Henrik Rydberg
[not found] ` <365b85cee33d4f1aadc31336663de21c@HUBCAS2.cs.stonybrook.edu>
2012-02-26 15:05 ` Richard Yao
2012-02-26 20:30 ` Ted Ts'o
[not found] ` <09a5cca9cffb4300843f682be529e8ca@HUBCAS2.cs.stonybrook.edu>
2012-02-26 21:25 ` Richard Yao
2012-02-26 21:35 ` Theodore Tso
[not found] ` <10de0ef9fb5d44c08669191e12343a97@HUBCAS2.cs.stonybrook.edu>
2012-02-26 22:03 ` Richard Yao
2012-02-27 11:17 ` Bernd Petrovitsch
2012-02-26 23:08 ` david
2012-02-27 0:01 ` Henrik Rydberg
2012-02-27 0:53 ` david
2012-02-27 9:07 ` Henrik Rydberg
2012-03-01 9:54 ` Thomas Gleixner
2012-02-24 15:58 ` Valdis.Kletnieks
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20120226015820.GB18931@gallifrey \
--to=linux@treblig.org \
--cc=david@lang.hm \
--cc=eduard.munteanu@linux360.ro \
--cc=jidong.xiao@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mchehab@redhat.com \
--cc=xiyou.wangcong@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox