Theodore Tso wrote:That's fallacious. Assuming that you have good programmers, and you do, it's of very low cost the act of identifying what *is likely to be* a security bug. In most cases, they are easy to spot. And, hey, we are not asking for an absurd amount of care. You must not pay $200 /hour for someone to review your software. All I, personally, ask for is that the basic attention is given. With this simple act, I'm sure you would cover the majority of the bugs. So, only those willing to pay have the right of respect? Because, you see, this is rather a matter of respect with those who choose to use your solution. And, no, the "free will" argument does not qualify herein. My mother is not aware of your absurd acts. > 2.6.18 in Fall 2006, and their next snapshot will be sometime two I don't follow what you have just said. What is the problem with "versioning" and the strictness of its relation to bugs, security or not? I think, CVE registration or the alike would be too much for what I call "act of decency". A single parenthesis note on the bug itself would be of great help and of small effort. --t --
| Andrew Morton | Re: -mm merge plans for 2.6.23 -- sys_fallocate |
| david | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Linus Torvalds | Linux 2.6.27-rc5 |
| David Miller | Re: [PATCH] net: Fix the prototype of call_netdevice_notifiers |
git: | |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| David Miller | Re: [GIT]: Networking |
| Jarek Poplawski | [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
