Re: How to fix problems with the sashiko review model
Johannes Berg <[email protected]> Wed, 22 Jul 2026 18:36:57 +0200
| Newsgroups | dev.linux.lists.ksummit,dev.linux.lists.sashiko-reviews,org.kernel.vger.linux-scsi |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 2026-07-22 at 11:55 -0400, James Bottomley wrote: > On Wed, 2026-07-22 at 11:39 -0400, Steven Rostedt wrote: > > On Wed, 22 Jul 2026 16:25:03 +0200 > > Johannes Berg <[email protected]> wrote: > >=20 > > > There's also a risk thing - if you erroneously get a report for > > > SCSI (as you did, IIUC) then you can opt out at that point and not > > > worry about it again. > > >=20 > > > If we erroneously _don't_ get a report for something that didn't > > > speak up because they're not on the list, didn't dare say anything, > > > didn't pay attention, etc. then nobody ever knows until someone > > > starts exploiting it? > >=20 > > I agree with Johannes here. It's one thing to get an annoying report > > that says "You can be compromised by your hardware" when the hardware > > is trusted. I have the same issue with boot parameters. But I rather > > opt-in than have the case that I'm the odd one out where my hardware > > is not trustworthy, but I don't know I have to take action to have it > > checked. >=20 > The thing is it's not just sashiko. Various AI driven patchers seem to > be using the prompts, which has lead to a slew of malicious hardware > fixes being sent to linux-scsi and I'm getting a bit worn out replying > to them saying that's not in our threat model. >=20 > So I figured why not fix the problem at source. I don't think anyone's saying you shouldn't (fix the problem at the source), as far as I'm concerned we're just debating the merits of opt- in vs. opt-out :) johannes