Re: [stable] Linux 2.6.25.10

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Linus Torvalds <torvalds@...>
Cc: Greg KH <greg@...>, Andrew Morton <akpm@...>, <linux-kernel@...>, <stable@...>
Date: Tuesday, July 15, 2008 - 9:23 pm

On 15 Jul 2008 at 18:08, Linus Torvalds wrote:


you didn't pay attention to me very well. i said a few times in this
thread already that i did *not* care what disclosure policy you choose
for the kernel security bugs, that's none of my business. what i (and
many others) do care about is that you follow through that choice.

as it is, you supposedly practice full disclosure, whether you know what
that term means or not, it does mean something very specific for people
with a security background and you most certainly do *not* practice it.

*that* is what i was complaining about - inconsistency between your words
and actions. i even told you that you can solve it two ways: change one
or the other. that is, you can begin to practice full disclosure (or as
we figured it out slowly, some form of disclosure at least as what you
turned out to be doing can best be described as no disclosure or less
affectionately, coverup), *or* you can declare (=let the world know) that
you do *not* practice any disclosure, certainly not full disclosure at
least.


fair enough, that's another way to say 'i cover them up'. at least we got
that out in the clear, thank you. you would have saved a lot of time if you
had declared this somewhere in the kernel docs. it's still not too late and
would be the prudent thing to do, there're *many* people living under the
assumption that you don't actually do this.


yes, perfectly clear. as i said, the disclosure policy (whether you call it
that or not) is your choice. please make it public somewhere.

cheers and good night,
  PaX Team

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 4:18 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 4:23 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 4:42 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 5:18 pm)
Re: [stable] Linux 2.6.25.10, Rafael C. de Almeida, (Thu Jul 17, 3:19 am)
Re: [stable] Linux 2.6.25.10, , (Thu Jul 17, 3:59 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 5:26 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 6:08 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 7:28 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 8:04 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 8:24 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 8:56 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 9:08 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 9:23 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 8:00 pm)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Tue Jul 15, 9:08 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 9:53 pm)
Re: [stable] Linux 2.6.25.10, Casey Schaufler, (Tue Jul 15, 11:27 pm)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 5:33 am)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Wed Jul 16, 9:21 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 11:16 am)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Wed Jul 16, 12:13 am)
Re: [stable] Linux 2.6.25.10, Casey Schaufler, (Wed Jul 16, 1:26 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Wed Jul 16, 12:21 am)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Wed Jul 16, 1:02 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Wed Jul 16, 1:13 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 10:02 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 10:36 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Wed Jul 16, 12:07 am)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Wed Jul 16, 12:16 am)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 9:30 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 8:16 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 8:38 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 8:51 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 9:10 pm)
Re: [stable] Linux 2.6.25.10, Greg KH, (Tue Jul 15, 11:13 pm)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 5:01 am)
Re: [stable] Linux 2.6.25.10, Greg KH, (Wed Jul 16, 10:43 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 11:43 am)
Re: [stable] Linux 2.6.25.10, Greg KH, (Wed Jul 16, 12:29 pm)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 1:25 pm)
Re: [stable] Linux 2.6.25.10, Mike Galbraith, (Wed Jul 16, 11:43 pm)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Wed Jul 16, 2:08 pm)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 3:09 pm)
Re: [stable] Linux 2.6.25.10, Gabor Gombas, (Wed Jul 16, 5:35 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 6:04 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 9:41 pm)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 5:49 am)
Re: [stable] Linux 2.6.25.10, David Miller, (Wed Jul 16, 6:08 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 6:23 am)
Re: [stable] Linux 2.6.25.10, David Miller, (Wed Jul 16, 6:31 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 6:51 am)
Re: [stable] Linux 2.6.25.10, David Miller, (Wed Jul 16, 7:04 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 7:52 am)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 10:24 pm)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Tue Jul 15, 11:11 pm)