Re: [stable] Linux 2.6.25.10

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Greg KH <greg@...>
Cc: Theodore Tso <tytso@...>, Andrew Morton <akpm@...>, Linus Torvalds <torvalds@...>, <linux-kernel@...>, <stable@...>
Date: Tuesday, July 15, 2008 - 7:09 pm

On 15 Jul 2008 at 15:39, Greg KH wrote:


read his mails and my responses, it's all in there. basically, he said
so himself that he knowingly withholds information. no matter how you spin
that, that's not full disclosure. note that i'm not advocating for using
that disclosure policy for kernel bugs, it's what *you* guys chose and
i'm just asking why you're not practicing it. you're also free to change
to something else, just don't forget to tell the world about it.


that doc says full disclosure, it doesn't say 'but withholding this
or that'. if you don't know what 'full disclosure' means then you're
welcome to ask on proper security mailing lists such as bugtraq or
dailydave or, why not, the list named after this very policy.


yes, you should include that at least. i didn't say that btw, your fellow
-stable maintainer did:

  Had I realized there was a security issue, I would highlight it in the
  announce message.  In fact, that's our standard procedure for -stable.
  (http://lkml.org/lkml/2008/6/10/328)

the 2.4 maintainer agreed with him:

  I don't like obfuscation at all WRT security issues, it does far more
  harm than good because it reduces the probability to get them picked
  and fixed by users, maintainers, distro packagers, etc...
  (http://lkml.org/lkml/2008/6/10/452)

i think you're outgunned here Greg. and no, i'm not upset (after all, i'm
the one catching you cover up security bugs, right? you're not hurting me),
but more and more of your users are.


no, that doesn't really belong there but it's a nice addition for certain
people.

Greg, instead of pretending to be surprised and upset or whatever, go
read the whole thread first.

cheers,
  PaX Team

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Linux 2.6.25.10, Greg KH, (Wed Jul 2, 11:58 pm)
Re: Linux 2.6.25.10, Bart Van Assche, (Thu Jul 3, 1:08 pm)
Re: Linux 2.6.25.10, Greg KH, (Thu Jul 3, 1:29 pm)
Re: Linux 2.6.25.10, Bart Van Assche, (Sat Jul 5, 3:54 am)
Re: Linux 2.6.25.10, Greg KH, (Tue Jul 8, 12:12 am)
Re: Linux 2.6.25.10, Greg KH, (Thu Jul 3, 2:57 pm)
Re: Linux 2.6.25.10, , (Thu Jul 3, 3:31 pm)
Re: [stable] Linux 2.6.25.10, Greg KH, (Mon Jul 14, 8:04 am)
RE: [stable] Linux 2.6.25.10, David Schwartz, (Fri Jul 18, 8:47 pm)
RE: [stable] Linux 2.6.25.10, , (Fri Jul 18, 9:01 pm)
RE: [stable] Linux 2.6.25.10, David Schwartz, (Fri Jul 18, 9:51 pm)
Re: [stable] Linux 2.6.25.10, Willy Tarreau, (Sat Jul 19, 1:41 am)
Re: [stable] Linux 2.6.25.10, , (Mon Jul 14, 10:14 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Mon Jul 14, 10:27 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 4:15 pm)
Re: [stable] Linux 2.6.25.10, Bernd Eckenfels, (Sat Jul 19, 9:13 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 7:34 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 11:31 am)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Tue Jul 15, 2:33 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 4:28 pm)
Re: [stable] Linux 2.6.25.10, Greg KH, (Tue Jul 15, 6:39 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 7:09 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 6:47 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 7:22 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 7:35 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 7:08 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 7:21 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 7:26 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 7:26 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 12:07 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 3:03 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 3:16 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 12:13 pm)
Re: [stable] Linux 2.6.25.10, Aidan Thornton, (Thu Jul 17, 5:08 pm)
Re: Linux 2.6.25.10, Greg KH, (Wed Jul 2, 11:58 pm)