Re: Research help needed

Andreas Haumer (andreas@xss.co.at)
Sat, 26 Jun 1999 14:01:32 +0200


Hi!

Lou Grinzo wrote:
>
> I'm currently working on a writing project that will discuss, among
> other things, the Linux kernel developers' reputation for fixing
> reported bugs very quickly.
>
> Trying to nail down examples is a little harder than I expected.
> I would like to cite several concrete, verifiable examples, along the
> lines of, "on Feb. 10, 1999 a security bug was found in component
> X, and a fix was coded, tested, and made available on the Internet
> within 24 hours."
>

Here are some examples from my own experience. Feel free to use
them in your project.

1.) Memory leak in bridging code Linux-2.0.36pre
One of my customers machines rebooted every other day due to
a memory leak in the Linux bridging & IP-alias code. I did some
research on this issue (including a quite impressive memory usage
statistic over 2 days and memory leak debugging with tools from
the kernel mailing list) and reported it on September 21, 1998, at
about midnight MET to linux-kernel. Two hours later (at about
02:30am MET!) I got a first answer from Alan Cox, and on September
23rd, 1998 Alan finally released a new kernel which cured the problem.
My customers machine is up and running since then...

2.) AMD K6 bugs
There were several bugs in the AMD K6 CPU. One of them I found myself
during stress-testing Linux-2.0.36 with the tool "crashme". I reported
this to linux-kernel on about May 26, 1998. In the following weeks
there was a quite interesting discussion on linux-kernel, and finally
we found a specific piece of assembler code (a few instructions)
which instantly crashed the AMD K6 CPU.
We reported this to AMD, but never got an answer... :-(
Though there is no "bug-fix" for Linux-2.0 for this specific CPU
problem, Linux-2.2 seems to be immune due to different memory
handling.

These 2 examples are 100% verifiable, you should find the whole
discussion for both examples at any linux-kernel archive.

There were several other occasions where I got instant support
from linux-kernel, but I don't have the facts right now, so they
probably won't count in your project.

Hope that helps

- andreas

-- 
 Andreas Haumer         | email: andreas@xss.co.at | PGP key available
 *x Software + Systeme  | phone: +43.1.6060114-0   | on request.
 Karmarschgasse 51/2/20 |        +43.664.3004449   |   
 A-1100 Vienna, Austria |   fax: +43.1.6060114-71  | AH327-RIPE

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/