lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20180323201634.GA16350@gmail.com>
Date:   Fri, 23 Mar 2018 13:16:34 -0700
From:   Eric Biggers <ebiggers3@...il.com>
To:     Dmitry Vyukov <dvyukov@...gle.com>
Cc:     Linus Torvalds <torvalds@...ux-foundation.org>,
        LKML <linux-kernel@...r.kernel.org>,
        syzkaller <syzkaller@...glegroups.com>
Subject: Re: syzbot dashboard

On Thu, Mar 22, 2018 at 10:45:43AM +0100, 'Dmitry Vyukov' via syzkaller wrote:
> On Wed, Mar 21, 2018 at 9:32 PM, Linus Torvalds
> <torvalds@...ux-foundation.org> wrote:
> > On Wed, Mar 21, 2018 at 9:11 AM, Dmitry Vyukov <dvyukov@...gle.com> wrote:
> >>
> >> syzkaller/syzbot dashboard is now live at:
> >> https://syzkaller.appspot.com
> >
> > Ok, this may well be the thing that makes syzbot reports useful, if
> > they point to an external report instead of sending an absolutely huge
> > illegible email that nobody can read.
> 
> The dashboard was initially meant to be used only for internal
> monitoring (communication with kernel developers over emails) and I am
> too close to the project to see obvious stuff. So thanks for the
> feedback!
> 
> Do you mean to replace all attachments in syzbot emails with links to
> web dashboard content?
> I've heard opinions both ways (including "I am not clicking on any
> external links, include all content in the email"). So we need to
> decide. Provided that lots of email clients seem to inline
> attachments, rather than show them as separate files, I am leaning
> towards providing just links. Then emails can be short and tidy. Also
> will solve the problem of "I don't see original attachments in your
> forwarded email".
> 

A compromise could be to remove the raw.log from the emails, and send the config
in 'defconfig' format rather than the full config; that trims it down from 5256
lines to 925 currently.  That would get rid of most of what is bloating the size
of the emails, while still keeping the (very useful) C and syzkaller
reproducers.  Dashboard would still have everything, of course.

Eric

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ