LWN.net Logo

Some perspective for the timeline..

Some perspective for the timeline..

Posted Oct 17, 2006 7:15 UTC (Tue) by nhippi (subscriber, #34640)
In reply to: Write to NVIDIA by drag
Parent article: Local root exploit in NVidia driver

> The shoker is the length of time it's taken for this problem to be realy made public. The issue has been around since 2004 and it wasn't until July 2006 until a nvidia developer in their forums acknowledged it was a problem and gave it a bug report number.

I hate binary drivers as much as the next guy, but you are not being fair here.

The 2004 report was on xorg bugzilla, but it wasn't reported against nvidia drivers, instead against org/Server/General. A nvidia (propertiary) section was added later to xorg bugzilla, but nobody took the time to dig through bugzilla to search what to reassign to that category.

Nobody reported or tagged it as security issue until recently.

When it was reported to nvnews forums nvidia started promptly working on it.

It was rather a fault of bug reporting process than evidence of evilness of propiertary application development. People who report bugs are lost - they don't know where to report, how to give all information developers need and so-on. Developers hate administrative tasks such as digging and reassiging bugs in bugzilla..


(Log in to post comments)

Some perspective for the timeline..

Posted Oct 17, 2006 8:12 UTC (Tue) by nim-nim (subscriber, #34454) [Link]

>> The shoker is the length of time it's taken for this problem to be realy
>> made public. The issue has been around since 2004 and it wasn't until July
>> 2006 until a nvidia developer in their forums acknowledged it was a problem
>> and gave it a bug report number.

> I hate binary drivers as much as the next guy, but you are not being fair
> here.

> The 2004 report was on xorg bugzilla, but it wasn't reported against nvidia
> drivers, instead against org/Server/General.

And remind us again why nvidia was not reading xorg bugzilla in 2004?

... right, out-of-tree binary drivers and development team dissociated from the FOSS community

Some perspective for the timeline..

Posted Oct 26, 2006 13:46 UTC (Thu) by jond (subscriber, #37669) [Link]

The distributions only switched to X.org from XFree86 in mid-2004 (Debian's first release with X.org instead of XFree86 is due /this/ december). It is hardly suprising that Nvidia wasn't reading every bug in the X.org bugzilla before the dust had settled.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds