Re: Year 2038 time set problem
On Mar 4, 2018 3:21 PM, Ruben Safir <ruben@mrbrklyn.com> wrote:
On 03/04/2018 01:31 PM, valdis.kletnieks@vt.edu wrote:
Note that saying "The CPU isn't vulnerable to Meltdown/Spectre, therefor the 4.1 kernel is OK" is *incredibly* wrong.
For the record, since 4.1 came out, there's been at *least* a dozen security issues in the Linux kernel that have been a *lot* scarier for security professionals than the Meltdown/Spectre issue. That only got any news coverage because it was an actual hardware design flaw that was believed to be difficult to easily fix with software changes...
By this standard, it is necessary to update the kernel and reboot nearly every week. Is that right?
You can kexec into the newer kernel to avoid rebooting if you absolutely must but yeah the best practice is to keep your system up to date and that requires some disruption of service. There's also kernel live patching which would allow you to patch the kernel without rebooting but I don't know how well supported that option is.
-- So many immigrant groups have swept through our town that Brooklyn, like Atlantis, reaches mythological proportions in the mind of the world - RI Safir 1998 http://www.mrbrklyn.com
DRM is THEFT - We are the STAKEHOLDERS - RI Safir 2002 http://www.nylxs.com - Leadership Development in Free Software http://www2.mrbrklyn.com/resources - Unpublished Archive http://www.coinhangout.com - coins! http://www.brooklyn-living.com
Being so tracked is for FARM ANIMALS and and extermination camps, but incompatible with living as a free human being. -RI Safir 2013
_______________________________________________ Kernelnewbies mailing list Kernelnewbies@kernelnewbies.org https://lists.kernelnewbies.org/mailman/listinfo/kernelnewbies
Regards, Alex
On Sun, 04 Mar 2018 20:47:15 +0000, Alex Arvelaez said:
You can kexec into the newer kernel to avoid rebooting if you absolutely must but yeah the best practice is to keep your system up to date and that requires some disruption of service.
If you can't afford the disruption of service a reboot causes, you *really* need to be deploying HA or load-balancer solutions. Because if you can't afford a reboot's worth of 15-20 minutes of downtime, you *really* can't afford the 6-8 hours you're probably going to be down if a chip soldered onto the motherboard/backplane fries. (All of $DAYJOB's important systems are behind HA or load-balancers, as well as HA-capable storage. Let's just say that some vendors make it easier than others to set up 8+2 RAID6 across 10 separate shelves of storage, and designing mutli-petabyte solutions without single points of failure is harder than it looks :)
On 03/04/2018 05:24 PM, valdis.kletnieks@vt.edu wrote:
If you can't afford the disruption of service a reboot causes, you *really* need to be deploying HA or load-balancer solutions.
Because if you can't afford a reboot's worth of 15-20 minutes of downtime, you *really* can't afford the 6-8 hours you're probably going to be down if a chip soldered onto the motherboard/backplane fries.
(All of $DAYJOB's important systems are behind HA or load-balancers, as well as HA-capable storage. Let's just say that some vendors make it easier than others to set up 8+2 RAID6 across 10 separate shelves of storage, and designing mutli-petabyte solutions without single points of failure is harder than it looks :)
These questions always lead into these philosophical discussions as to how I should run my boxes and theoretical flights of opinionated rubbish that I am not interested in. I got the answer to the question I needed and it is very sobering. I am not setting up a high availability cluster in my house, thank you. And fwiw, I've run systems for 6-8 years without rebooting on pc hardware. My little fanless fit/pc service running an intel atom had at one time run 5 years without rebooting. I only had a system fry once while it was up an running since the late 1990's until today, and in that case it was wild power surge and the hardware was up and running in 20 minutes with a swap out of the hard drive. The linux kernel is integrated into dozens of devices which never see the light of day for kernel upgrades from PPOE routers, IOT devices, cellphones, VOIP boxes, electrocardiograms, menu displays for McDonalds, signal boxes on train systems, etc etc etc. What has been described is a huge security problem and your solution is a non-starter and doesn't help the broader problem. -- So many immigrant groups have swept through our town that Brooklyn, like Atlantis, reaches mythological proportions in the mind of the world - RI Safir 1998 http://www.mrbrklyn.com DRM is THEFT - We are the STAKEHOLDERS - RI Safir 2002 http://www.nylxs.com - Leadership Development in Free Software http://www2.mrbrklyn.com/resources - Unpublished Archive http://www.coinhangout.com - coins! http://www.brooklyn-living.com Being so tracked is for FARM ANIMALS and and extermination camps, but incompatible with living as a free human being. -RI Safir 2013
On Sun, 04 Mar 2018 21:21:13 -0500, Ruben Safir said:
I am not setting up a high availability cluster in my house, thank you. And fwiw, I've run systems for 6-8 years without rebooting on pc hardware. My little fanless fit/pc service running an intel atom had at one time run 5 years without rebooting. I only had a system fry once while it was up an running since the late 1990's until today, and in that case it was wild power surge and the hardware was up and running in 20 minutes with a swap out of the hard drive.
The fact that you've kept a system going for 8 years without a reboot isn't proof that actually doing so is a good idea security wise.
The linux kernel is integrated into dozens of devices which never see the light of day for kernel upgrades from PPOE routers, IOT devices, cellphones, VOIP boxes, electrocardiograms, menu displays for McDonalds, signal boxes on train systems, etc etc etc.
The big problem *there* isn't that a reboot is often required. The problem is that the vendors won't ship a patched system to reboot *into*.
What has been described is a huge security problem and your solution is a non-starter and doesn't help the broader problem.
I repeat what I said - if you can't afford a reboot because it's mission critical, you can't afford to *not* be doing HA or load balancing or something. The Internet of Pwned Things problem is with systems where a reboot *is* feasible (are you going to notice if your light bulb reboots at 3AM when it's off anyhow?), but vendors have no ecomonic incentive to provide fixes after they've got your money (unless they can monetize you post-purchase - and most people won't pay for a support contract, so the vendor's only realistic choice is monetizing your data..) And that's a totally orthogonal issue.
On 03/04/2018 11:15 PM, valdis.kletnieks@vt.edu wrote:
I repeat what I said - if you can't afford a reboot because it's mission critical, you can't afford to *not* be doing HA or load balancing or something.
I know, that is the thing about talking to guys like you. It is a personality type. Its worst that talking to a rock. You just repeat the same insane advice over and over. Complete tunnel vision. You don't even have a clue as to how to deal with this problem. Truthfully, you don't know what the problem even is. Don't pretend to understand what I can and can not afford. Your not picking security policy for Google. What your failing to address, because you are so blinded to your own frame of reference, is that your solution leaves out well over 90% of the devices connected to the internet, some of those devices connected to things like nuclear power plants. Others are just VOIP appliances. This conversation is now over, at least for me. Repeating the same bad advice is not contributing to anyone, and especially not I. -- So many immigrant groups have swept through our town that Brooklyn, like Atlantis, reaches mythological proportions in the mind of the world - RI Safir 1998 http://www.mrbrklyn.com DRM is THEFT - We are the STAKEHOLDERS - RI Safir 2002 http://www.nylxs.com - Leadership Development in Free Software http://www2.mrbrklyn.com/resources - Unpublished Archive http://www.coinhangout.com - coins! http://www.brooklyn-living.com Being so tracked is for FARM ANIMALS and and extermination camps, but incompatible with living as a free human being. -RI Safir 2013
On Sun, 04 Mar 2018 23:50:32 -0500, Ruben Safir said:
Don't pretend to understand what I can and can not afford. Your not picking security policy for Google. What your failing to address, because you are so blinded to your own frame of reference, is that your solution leaves out well over 90% of the devices connected to the internet, some of those devices connected to things like nuclear power plants. Others are just VOIP appliances.
Give an example of a system - *ANY* system - where you *can't* afford the time down for a reboot, but the downtime for a hardware failure *is* acceptable. If you connect something to a nuclear power plant and can't afford a reboot time, what is your plan if the device fails entirely? If you can't stand your VOIP box being down at 3AM when there's no calls in progress, what do you intend to use for voice service if you're down because a DIMM failed? Don't confuse "the downtime for a reboot pisses me off personally" with "if we take downtime at all, it's A Serious Problem". If it's the former, then you have to learn that reboots are like changing the oil in your car - refusing to do periodic maintenance will bite you eventually. If it's the latter, and you *aren't* already doing things like HA to deal with hardware failures, *you are being negligent*. And yes, we're talking in "court of law" mode here for some things - if you knew that downtime would cause damages (either physical or monetary) and you didn't do anything about it, you better have a *really* hefty insurance policy covering negligence on your part. And if you *are* doing stuff to deal with hardware failures, *then a reboot is a non-issue*. (And by the way - as I've mentioned, managing reboots is the *easy* part of updating an Internet of Pwned Things device. The hard part is getting the vendor to produce an update in the first place...)
On 03/05/2018 03:50 AM, valdis.kletnieks@vt.edu wrote:
Give an example of a system - *ANY* system - where you *can't* afford the time down for a reboot, but the downtime for a hardware failure *is* acceptable.
You are right. No you move on to another target.. where you can show you are right -- So many immigrant groups have swept through our town that Brooklyn, like Atlantis, reaches mythological proportions in the mind of the world - RI Safir 1998 http://www.mrbrklyn.com DRM is THEFT - We are the STAKEHOLDERS - RI Safir 2002 http://www.nylxs.com - Leadership Development in Free Software http://www2.mrbrklyn.com/resources - Unpublished Archive http://www.coinhangout.com - coins! http://www.brooklyn-living.com Being so tracked is for FARM ANIMALS and and extermination camps, but incompatible with living as a free human being. -RI Safir 2013
On 03/05/2018 03:50 AM, valdis.kletnieks@vt.edu wrote:
Give an example of a system - *ANY* system - where you *can't* afford the time down for a reboot, but the downtime for a hardware failure *is* acceptable.
this is a black hole of a conversation. I see no benefit to it at this point. Your not even reading what I wrote. -- So many immigrant groups have swept through our town that Brooklyn, like Atlantis, reaches mythological proportions in the mind of the world - RI Safir 1998 http://www.mrbrklyn.com DRM is THEFT - We are the STAKEHOLDERS - RI Safir 2002 http://www.nylxs.com - Leadership Development in Free Software http://www2.mrbrklyn.com/resources - Unpublished Archive http://www.coinhangout.com - coins! http://www.brooklyn-living.com Being so tracked is for FARM ANIMALS and and extermination camps, but incompatible with living as a free human being. -RI Safir 2013
On 03/05/2018 03:50 AM, valdis.kletnieks@vt.edu wrote:
If it's the former, then you have to learn that reboots are like changing the oil in your car
yeah, BTW, my car doesn't need its oil changed any longer. It hasn't needed to be done before 100,000 miles since the mid-1980s. I only WISH that the kernel development used automobile industry standards for reliability and security. -- So many immigrant groups have swept through our town that Brooklyn, like Atlantis, reaches mythological proportions in the mind of the world - RI Safir 1998 http://www.mrbrklyn.com DRM is THEFT - We are the STAKEHOLDERS - RI Safir 2002 http://www.nylxs.com - Leadership Development in Free Software http://www2.mrbrklyn.com/resources - Unpublished Archive http://www.coinhangout.com - coins! http://www.brooklyn-living.com Being so tracked is for FARM ANIMALS and and extermination camps, but incompatible with living as a free human being. -RI Safir 2013
On 03/05/2018 07:34 AM, Ruben Safir wrote:
On 03/05/2018 03:50 AM, valdis.kletnieks@vt.edu wrote:
If it's the former, then you have to learn that reboots are like changing the oil in your car yeah, BTW, my car doesn't need its oil changed any longer. It hasn't needed to be done before 100,000 miles since the mid-1980s. I only WISH that the kernel development used automobile industry standards for reliability and security.
I'll bite. Is this a mazda rotary? They quit using those some time ago, right?
On 03/04/2018 11:15 PM, valdis.kletnieks@vt.edu wrote:
I only had a system fry once while it was up an running since the late 1990's until today, and in that case it was wild power surge and the hardware was up and running in 20 minutes with a swap out of the hard drive. The fact that you've kept a system going for 8 years without a reboot isn't proof that actually doing so is a good idea security wise.
I made that point with regard to the silly notion that somehow the hardware would just magically fry periodically. On the scale I'm working at, hardware failure over decades is rare. Whether it is reasonable to expect to be able to use a kernel securely for 8 years is a problem I leave for the experts. -- So many immigrant groups have swept through our town that Brooklyn, like Atlantis, reaches mythological proportions in the mind of the world - RI Safir 1998 http://www.mrbrklyn.com DRM is THEFT - We are the STAKEHOLDERS - RI Safir 2002 http://www.nylxs.com - Leadership Development in Free Software http://www2.mrbrklyn.com/resources - Unpublished Archive http://www.coinhangout.com - coins! http://www.brooklyn-living.com Being so tracked is for FARM ANIMALS and and extermination camps, but incompatible with living as a free human being. -RI Safir 2013
On 03/04/2018 11:15 PM, valdis.kletnieks@vt.edu wrote:
The big problem *there* isn't that a reboot is often required.
Yes, it is a problem. If you have 25 thousand signal switches that depend on, and build a wifi network for signally and telemetry, you aren't going to be able to put all those devices behind a cluster, and you sure as hell aren't going to reboot them all every week. These things need to be all but bulletproof on installation. That is the way that the world works outside of a server farm closet. ... just as an example -- So many immigrant groups have swept through our town that Brooklyn, like Atlantis, reaches mythological proportions in the mind of the world - RI Safir 1998 http://www.mrbrklyn.com DRM is THEFT - We are the STAKEHOLDERS - RI Safir 2002 http://www.nylxs.com - Leadership Development in Free Software http://www2.mrbrklyn.com/resources - Unpublished Archive http://www.coinhangout.com - coins! http://www.brooklyn-living.com Being so tracked is for FARM ANIMALS and and extermination camps, but incompatible with living as a free human being. -RI Safir 2013
participants (4)
-
Alex Arvelaez -
Darin Avery -
Ruben Safir -
valdis.kletnieks@vt.edu