Joined June 2011
659 Photos and videos
New attack surface just dropped: git.kernel.org/pub/scm/linux…

2
21
2,982
Replying to @ky1ebot

3
1
22
3,195
Hmm, quite some user copies under the mutex, some other cases seem to try to avoid that, like snd_timer_user_gstatus(), did it come up in review?
1
1
370
I don't know why I even did this, but if I could churn the world (completely compile un-tested):
1
257
To everyone (and everybot) mailing security@kernel.org with multiple public lists on CC at the same time: thank you for your service, I'll never call it mistake and believe it should be the new standard.
1
17
2,173
Doesn't matter because vulnerabilities in staging drivers aren't considered vulnerabilities now, but the way the Fixes tags are used in these two fixes are going to do wonderful things with the CNA's automation when they issue CVEs anyway: git.kernel.org/pub/scm/linux…

1
5
1,064
For each commit, the first of the fixes tags points to some irrelevant (but recent) cleanup commit which changed some whitespace or removed some commented-out code, not related at all to bug introduction.
3
625
First fix I've seen that'll probably get dropped from stable backports due to not cherry-picking clean from kmalloc_obj churn: git.kernel.org/pub/scm/linux…

1
1
9
2,111
Another: git.kernel.org/pub/scm/linux… have been several others of these I haven't posted, will stop now as I've proved the point thoroughly

1
2
483
I've probably backported ~100 security fixes now that won't get applied to upstream stable kernels because of this churn, ironic!
1
3
191
We didn't like looking at perfectly good puts so we redid the code with magic scoping rules to make the puts happen invisibly for us so that we could forget...to get: git.kernel.org/pub/scm/linux…

8
858
USERCOPY to the rescue (this is what it was designed for): lists.openwall.net/linux-har…

2
10
1,385
Brad Spengler retweeted
today's arxiv preprint - ioctl census, but linux
1
9
57
3,306
Ah whoops, 25, darnit one of these decades I'll remember 🤦‍♂️
Was going to announce the 20th anniversary of grsecurity this month, but it's been so long I didn't realize it was actually in February. 🎉🤦‍♂️
1
3
14
1,771
2 years and 2 days:
1
10
1,400
Noticed due to a merge conflict with today's 6.18 (note same fix, just different comments):
4
549