Re: How to fix problems with the sashiko review model

Mark Brown <[email protected]> Wed, 22 Jul 2026 15:20:15 +0100
Newsgroups dev.linux.lists.ksummit,dev.linux.lists.sashiko-reviews,org.kernel.vger.linux-scsi
Message-ID <[email protected]>
--KN+SHztRLH/BVDxX
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

On Wed, Jul 22, 2026 at 04:00:15PM +0200, Johannes Berg wrote:
> On Wed, 2026-07-22 at 09:42 -0400, James Bottomley wrote:

> > Well, I noted that in my reply above.  The way I was thinking of
> > implementing it was to add a general instruction file for drivers which
> > would make hardware trusted for pretty much everything and then
> > instruct the AI to consult driver specific files for overrides to this
> > so we could add the additional threat checks to usb.md and virt.md

> I guess it's a question which way around it should be - but I'll note
> that generally for wifi customers tend to not trust the "hardware"
> because it's mostly firmware, is generally buggy and can be attacked
> over the air too...

> Personally (with that background) I'd tend to lean towards saying the
> high-performance stuff that does want/need to trust the device should
> opt out, it's harder to get that wrong. If we generally opt out as you
> describe and then forgot to include something, we might have issues.

OTOH we have a huge stack of subsystems which mostly deal with devices
that are physically part of the SoC that Linux is running on or are
soldered down on the board and for the most part do not use firmware, my
guess would be that there's more code that trusts it's hardware than
doesn't.  I don't think there's any winning here.

--KN+SHztRLH/BVDxX
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEzBAABCgAdFiEEreZoqmdXGLWf4p/qJNaLcl1Uh9AFAmpg0Z4ACgkQJNaLcl1U
h9AaQwf8CPX2XzAOvjArlnAvhUxj+H3KCuaNM40AGfLMqvlEzXlqQcN4RRLGsedL
j8j7suBTCqndoX21YQ8tV1K6672J33+YPhGiDwdWn+lf9UOrC5IUfBQ5a5kWh2UJ
QQ12Igr5ALPUzhH4G/pw3bCltRSnP+nfv7fDb34dJHS2wAYiSQTlyCqzVyiFt3ZO
72e4L5SjOqS4Lk7f6Puo+KACQSNFQJy4tLO/MTP8UoVz4MHqdtXFDLTpkTwmpcrR
M6IW12xMhkK/jqC/X19mO5QAN4cPUzexU859/H0aZkEWoMPze94hcNfvxmE4i99v
nr0NHzNzM3/XecS1UI43M6ER5hqfFw==
=SaG+
-----END PGP SIGNATURE-----

--KN+SHztRLH/BVDxX--