On 15 Jul 2008 at 18:08, Linus Torvalds wrote:you didn't pay attention to me very well. i said a few times in this thread already that i did *not* care what disclosure policy you choose for the kernel security bugs, that's none of my business. what i (and many others) do care about is that you follow through that choice. as it is, you supposedly practice full disclosure, whether you know what that term means or not, it does mean something very specific for people with a security background and you most certainly do *not* practice it. *that* is what i was complaining about - inconsistency between your words and actions. i even told you that you can solve it two ways: change one or the other. that is, you can begin to practice full disclosure (or as we figured it out slowly, some form of disclosure at least as what you turned out to be doing can best be described as no disclosure or less affectionately, coverup), *or* you can declare (=let the world know) that you do *not* practice any disclosure, certainly not full disclosure at least. fair enough, that's another way to say 'i cover them up'. at least we got that out in the clear, thank you. you would have saved a lot of time if you had declared this somewhere in the kernel docs. it's still not too late and would be the prudent thing to do, there're *many* people living under the assumption that you don't actually do this. yes, perfectly clear. as i said, the disclosure policy (whether you call it that or not) is your choice. please make it public somewhere. cheers and good night, PaX Team --
| Srivatsa Vaddagiri | Re: [PATCH, RFC] reimplement flush_workqueue() |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
| debian developer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Rafael J. Wysocki | 2.6.26-rc7-git2: Reported regressions from 2.6.25 |
| Alexey Dobriyan | Re: [GIT]: Networking |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Ilpo Järvinen | Re: [bug] stuck localhost TCP connections, v2.6.26-rc3+ |
git: | |
