Posts by gregkh@social.kernel.org
(DIR) Post #B4qmaRL9gZEEqLAtwO by gregkh@social.kernel.org
1 likes, 0 repeats
Posting this link here, as I always have to dig every few years when I need it: https://cdecl.org/ a C -> English translator for those "fun" const pointer to const array issues that you have to work out every so often...
(DIR) Post #B5aRYIE3RRmKEJ93ia by gregkh@social.kernel.org
1 likes, 0 repeats
After 25+ years of kernel development, I was finally forced to touch `mm/` and it was due to a nommu "issue":https://lore.kernel.org/lkml/2026042334-acutely-unadorned-e05c@gregkh/As @axboe said the other day, we aren't expecting a box of chocolates:https://lore.kernel.org/r/2f2c91cb-f20e-44eb-8ba3-2d5b3d649642@kernel.dkbut these past weeks have made me feel like someone owes a few of us kernel developers a bunch of whisky at the very least...
(DIR) Post #B5cxXfvhPYN8J2EF3w by gregkh@social.kernel.org
1 likes, 0 repeats
As people keep guessing what/who `gkh_clanker_t1000` is: https://lore.kernel.org/r/20260424054143.087847e1617a84df8b501313@linux-foundation.org here it is after I cleaned up some of the horrid cable mess that had grown up around it.
(DIR) Post #B5oV1DWyzlyo8uvBlw by gregkh@social.kernel.org
1 likes, 0 repeats
My build system right now, as it's one of "those" mornings....
(DIR) Post #B5rP1YGzrNQUDs6GqO by gregkh@social.kernel.org
0 likes, 0 repeats
@wdormann @joshbressers @Viss I love it how people think that "coordination of vulnerabilities" is actually something that can be done these days. Think of just who uses the software in question, and who should, and should not, be on such a list to get a "early disclosure notification".As I have said for quite some time now, all early-disclosure lists are leaks, otherwise why would your government allow them to be in existence?Software, and specifically open source software, runs the world. So should the whole world be on that notification list? :)
(DIR) Post #B5rP1YmBzONbmchBT6 by gregkh@social.kernel.org
1 likes, 0 repeats
@zmanion @joshbressers @wdormann @Viss Why is linux-distros somehow "special" enough to get these types of announcements and not everyone else? How exactly would you explain that to your favorite government entity?
(DIR) Post #B5vUjSZbgpAngpOv2m by gregkh@social.kernel.org
1 likes, 0 repeats
@joshbressers I will quote this in many presentations in the future because it is so true:"The Kernel assigns lots of CVEs. They say it’s because they don’t really know how the Kernel is being used, so they err on the side of caution. Companies hate this because they have to deal with a lot of CVEs. Does the Kernel do this because it’s easier or do they have some sort of secret nefarious reason? Probably because it’s just easier and they have zero downside to disclosing and moving on. "RE: https://infosec.exchange/@joshbressers/116507930206819253
(DIR) Post #B7xHRKJmNFIVhC24zQ by gregkh@social.kernel.org
1 likes, 0 repeats
CVE issue stats for the first 6 months of the year, by vendor, sorted by quantity: 2308 "vendor": "Linux", 1752 "vendor": "Google", 1308 "vendor": "n/a", 843 "vendor": "Microsoft", 495 "vendor": "OpenClaw", 445 "vendor": "Oracle Corporation", 395 "vendor": "Adobe", 340 "vendor": "Red Hat", 310 "vendor": "Apache Software Foundation", 284 "vendor": "Apple",I gotta change my talk where I say “we are #2” as that’s not the case by far anymore. Hopefully the other vendors get their act together and start properly reporting all CVEs to the system, not just the ones that they feel like submitting…And the numbers for OpenClaw is quite impressive, nice to see someone take responsibility there :)
(DIR) Post #B7xJUSH9RaXf9XQHBo by gregkh@social.kernel.org
1 likes, 0 repeats
@samuel "CVEmaxxing", if you don't mind, I'm going to steal that for my next talk!And the Google/Microsoft codebases are for _different_ products from those vendors, not just a single codebase, so you can't really compare them that way at all. Look at the product if you wish to compare for products. For products, our numbers are way way higher because most commercial vendors do not report all CVEs, only the "high" ones.
(DIR) Post #B8zskVGNRmIk7ANqi0 by gregkh@social.kernel.org
1 likes, 0 repeats
In which I explain how I will treat LLM generated or assisted patches for the Linux kernel drivers/staging/ subsystem going forward:https://lore.kernel.org/all/2026080354-skater-urgent-31b2@gregkh/T/#u(hint, not allowed, except for security bugs that you can prove actually fix something by testing the issue on the actual hardware the driver controls.)
(DIR) Post #B9nbhYlJAxsgpfgO12 by gregkh@social.kernel.org
0 likes, 1 repeats
Some talks just write themselves, @KernelRecipes is going to be fun this year!(not that it's not fun every year, but you get the idea...)
(DIR) Post #BAEESevgjAy9ySvJjM by gregkh@social.kernel.org
1 likes, 0 repeats
I can't resist keyboards in "odd" formats...