Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Wed, 2 Sep 2020 14:16:05 +0200
From: Solar Designer <solar@...nwall.com>
To: "Tobin C. Harding" <me@...in.cc>
Cc: Tycho Andersen <tycho@...ho.ws>, Kees Cook <keescook@...omium.org>,
	kernel-hardening@...ts.openwall.com,
	Mrinal Pandey <mrinalmni@...il.com>,
	Tycho Andersen <tycho@...ho.pizza>
Subject: Re: [PATCH] scripts: Add intended executable mode and SPDX license

On Tue, Sep 01, 2020 at 02:24:50PM +1000, Tobin C. Harding wrote:
> On Mon, Aug 31, 2020 at 06:15:19PM -0600, Tycho Andersen wrote:
> > On Thu, Aug 27, 2020 at 11:02:00AM -0700, Kees Cook wrote:
> > > On Thu, Aug 27, 2020 at 03:06:53PM +0200, Solar Designer wrote:
> > > > How about we remove kernel-hardening from the MAINTAINERS entries it's
> > > > currently in? -
> > > > 
> > > > GCC PLUGINS
> > > > M:      Kees Cook <keescook@...omium.org>
> > > > R:      Emese Revfy <re.emese@...il.com>
> > > > L:      kernel-hardening@...ts.openwall.com
> > > > S:      Maintained
> > > > F:      Documentation/kbuild/gcc-plugins.rst
> > > > F:      scripts/Makefile.gcc-plugins
> > > > F:      scripts/gcc-plugin.sh
> > > > F:      scripts/gcc-plugins/
> > > > 
> > > > LEAKING_ADDRESSES
> > > > M:      Tobin C. Harding <me@...in.cc>
> > > > M:      Tycho Andersen <tycho@...ho.ws>
> > > > L:      kernel-hardening@...ts.openwall.com
> > > > S:      Maintained
> > > > T:      git git://git.kernel.org/pub/scm/linux/kernel/git/tobin/leaks.git
> > > > F:      scripts/leaking_addresses.pl
> > > > 
> > > > Alternatively, would this be acceptable? -
> > > > 
> > > > L:      kernel-hardening@...ts.openwall.com (only for messages focused on core functionality, not for maintenance detail)
> > > > 
> > > > I think the latter would be best, if allowed.
> > > > 
> > > > Kees, please comment (so that we'd hopefully not need that next time),
> > > > and if you agree please make a change to MAINTAINERS.
> > > 
> > > A comment isn't going to really help fix this (much of the CCing is done
> > > by scripts, etc).

Understood.  Maybe some other agreed-upon syntax would help - a new tag
letter in place of "L" and/or e-mail address obfuscation or an https URL
for further information instead of a direct posting address - but I
guess this is only worth introducing if we're not unique with this wish.

> > > I've tended to prefer more emails than missing discussions, and I think
> > > it's not unreasonable to have the list mentioned in MAINTAINERS for
> > > those things. It does, of course, mean that "maintenance" patches get
> > > directed there too, as you say.
> > > 
> > > If it's really something you'd like to avoid, I can drop those
> > > references. My instinct is to leave it as-is, but the strength of my
> > > opinion is pretty small. Let me know what you prefer...

Thank you for your comments, Kees.

It's not a matter of my preference, but of what works best for getting
more actual work done.  Unfortunately, we have to make our subjective
guesses on this.  FYI, when we dropped the [kernel-hardening] prefix on
Subjects this appears to have resulted in some people unsubscribing.
I agree we had to do that anyway because of CC'ing other lists, which
is customary in Linux kernel development.  Before that change, we had a
slow but steady growth in the number of subscribers.  When we made that
change, the numbers of people joining and leaving became about the same,
so we're staying at 600 to 650 subscribed addresses for a long time now.
These numbers are fine by themselves; it's more relevant who is on the
list, not how many.  I think we might have "forced" some capable people
to unsubscribe, but like I explained we kind of had to.  Now I think
we're doing the same with these maintenance-only threads, and I think we
don't have to.  This is why I think we should preferably either somehow
limit the requested CC's to messages focused on core functionality, or
if we can't then drop the list references from MAINTAINERS.  We should
also not discuss this for very long, as this discussion itself hurts
actual work in a similar way.

> > One thing about leaking_addresses.pl is that I'm not sure anyone is
> > actively using it at this point. I told Tobin I'd help review stuff,
> > but I don't even have a GPG key with enough signatures to send PRs.
> > I'm slowly working on figuring that out, but in the meantime I wonder
> > if we couldn't move it into some self test somehow, so that at least
> > nobody adds new leaks? Does that seem worth doing?
> > 
> > It would then probably go away as a separate perl script and live
> > under selftests, which could mean we could drop the reference to the
> > list. But that's me making it someone else's problem then, kind of :)
> > 
> > Also, I'm switching my e-mail address to tycho@...ho.pizza, so future
> > replies will be from there.
> 
> I don't mind if the reference to kernel-hardening is removed, if in
> the event that someone sends a patch that needs input from the kernel
> hardening community we can always mail the list.

Thank you for your comments as well, Tycho and Tobin.

Alexander

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.