Christian Brauner 🦊🐺
The real tragedy about the ptrace bug is that @jann@infosec.exchange pointed to the exact exploit primitive in a 2020 patch series where he implemented the architecturally sound fix: keep the mm alive until the task is reaped.
But it neither got reviewed nor merged. Let's try and change that:
https://lore.kernel.org/20201016024019.1882062-1-jannh@google.com/
After a brief discussion I initiated #systemd updated their stability guarantees to be aligned with the #kernel:
"The kernel has a "don't break userspace" policy [1] which is very easy
to understand and like (even if the details are complicated). [...]
To improve public perception, and to align the docs with practice, let's
make a general promise to keep stability [...]"
It's been that way implicitly for a while and now it's communicated clearly as well.
https://github.com/systemd/systemd/commit/f4dd927e5cc47a88fa427a6e1ce210b1f2350978
My role in upstream maintenance for the Linux Kernel will continue as it always has. The same goes for @pid_eins@mastodon.social involvement in systemd. We take our upstream responsibility very seriously and always have.
Today I'm super excited to announce Amutable, our new company together with @pid_eins@mastodon.social and @blixtra@hachyderm.io.
I couldn't be happier to have @cyphar@mastodon.social, @daandemeyer@mastodon.social, @zbyszek@fosstodon.org, @pothos@fosstodon.org, @michaelvogt@mastodon.social,
@rodrigo_rata@mastodon.social, @davidstrauss@mastodon.social as part of our team.
I've known them for a very long time and I'm very happy they are on board for the ride.
I can't wait to show everyone what we're building.
Made with ❤️ in Berlin.
https://amutable.com/blog/introducing-amutable
#amutable #linux #systemd #⊼mutable #integrity
RE: @daandemeyer@mastodon.social
I love that me ranting to @pid_eins@mastodon.social about "I don't want to mount unprivileged images in the kernel so my idea is to do it in userspace relying on the new mount API through a daemon in systemd please come to LSFMM with me" turned out exactly as envisioned. And all in less than two years.
I do enjoy using some of the AI coding tools but judging by some of the patchsets on the kernel mailing list it is clear that without strong focus on code quality this will significantly degrade architectural thought and code design. I mean, spaghetti galore...
I took it one step further and implemented both CLONE_AUTOREAP (now for non-pidfd as well) and CLONE_PIDFD_AUTOKILL (requires no new privileges for the child now):
https://patch.msgid.link/20260223-work-pidfs-autoreap-v4-0-e393c08c09d1@kernel.org
I can confidently say that I sent another completely batshit series that will probably end up with Linus revoking any pr rights because I clearly lost it. But it was kinda tempting to see whether I could move all kthreads into nullfs and separate PID 1 from kthread filesystem state:
https://patch.msgid.link/20260303-work-kthread-nullfs-v1-0-87e559b94375@kernel.org
Also, usermodehelpers must cease to be a thing and so do userspace filesystem operations from kthread context.
@daandemeyer@mastodon.social has been working on #barrage a concurrent async test framework for Python:
https://github.com/amutable-systems/barrage
He's got great plans for it. :)
Some tooling changes for @monsieuricon@social.kernel.org
https://lore.kernel.org/all/20260306-master-v1-0-5a4b9cbe11d7@kernel.org
epoll, not for the faint of heart:
Interested in a UAF that is just too cursed to be real?
https://lore.kernel.org/20260224-mittlerweile-besessen-2738831ae7f6@brauner
So I've just been looking at the sponsorship page for LSFMM and you all need to go out and steal some of that AI funding money for one of the conferences that makes the compute for all the fanciness possible! Like right now, please.
I love that ksmbd does I/O from kthread context. What can possibly go wrong.
Hey #Linux #Kernel people. Last year we had the first #Kernel Devroom at #FOSDEM. And we're running the #Kernel Devroom for #FOSDEM in 2024 as well!
#FOSDEM 2024 is taking place over the weekend of the 3 & 4 February in Brussels, Belgium!
It is a wonderful event that's very close to my and a lot of people's hearts!
Join @rppt@mastodon.social, Daniel Borkmann, and @stgraber@hachyderm.io, and myself and make this another great #FOSDEM!
We're very excited for your submissions!
https://lists.fosdem.org/pipermail/fosdem/2023q4/003536.html
The first and largest round of invites for the (V)FS track has been sent:
https://lore.kernel.org/all/20260225-aufeinander-kummervoll-1953a06beae9@brauner/
This includes everyone who would need a VISA. The next round will be smaller.
We just accepted the eBPF & Networking track for #LinuxPlumbers 2023. 🥳🎉
https://lpc.events/blog/current/index.php/2023/04/24/networking-and-bpf-track/
I totally forgot: We created a fediverse account for #LinuxPlumbers! Go and follow @linuxplumbersconf@mastodon.social everyone! :)
#LinuxPlumbers will take place November 13 - 15 in Richmond, VA.
@alwayscurious Yeah, I think we could reasonably add CLONE_PIDFD_AUTOKILL_TREE or something. @jann