| This reads like a bunch of baloney to obscure the real problem. The only relevant part you need to see: >Due to a bug in the Content Validator, one of the two Template Instances passed validation despite containing problematic content data. Problematic content? Yeah, this is telling exactly nothing. Their mitigation is "ummm we'll test more and maybe not roll the updates to everyone at once", without any direct explanation on how that would prevent this from happening again. Conspicuously absent: — fixing whatever produced "problematic content" — fixing whatever made it possible for "problematic content" to cause "ungraceful" crashes — rewriting code so that the Validator and Interpreter would use the same code path to catch such issues in test — allowing the sysadmins to roll back updates before the OS boots — diversifying the test environment to include actual client machine configurations running actual releases as they would be received by clients This is a nothing sandwich, not an incident review. |
It's far from perfect (both in terms of the lack of defenses to crashloop in the sensor and in what it said about their previous practices) but calling it a nothing sandwich is a bit hyperbolic.