All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Michael S. Tsirkin" <mst@redhat.com>
To: "Daniel P. Berrangé" <berrange@redhat.com>
Cc: qemu-devel@nongnu.org,
	"Pierrick Bouvier" <pierrick.bouvier@oss.qualcomm.com>,
	"Alex Bennée" <alex.bennee@linaro.org>,
	"Mauro Matteo Cascella" <mcascell@redhat.com>,
	"Paolo Bonzini" <pbonzini@redhat.com>,
	"Thomas Huth" <thuth@redhat.com>
Subject: Re: [qemu-web RFC 2/3] contribute: add automate tool disclosure to bug reporting
Date: Wed, 10 Jun 2026 06:29:19 -0400	[thread overview]
Message-ID: <20260610062841-mutt-send-email-mst@kernel.org> (raw)
In-Reply-To: <20260604165048.457860-3-berrange@redhat.com>

On Thu, Jun 04, 2026 at 05:50:47PM +0100, Daniel P. Berrangé wrote:
> A while back we added a requirement to declare the use of any
> automated tooling used in discover of security issues, and set
> a rule that the reporter must perform triage before submission
> rather than blindly reporting issues. This applies equally
> well to normal issue reporting, so copy it over from the
> security process guidance.
> 
> Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>


Acked-by: Michael S. Tsirkin <mst@redhat.com>

Maybe .gitlab/issue_templates/bug.md should be updated then?

> ---
>  contribute/report-a-bug.md | 7 +++++++
>  1 file changed, 7 insertions(+)
> 
> diff --git a/contribute/report-a-bug.md b/contribute/report-a-bug.md
> index 6071837..fd3bc6b 100644
> --- a/contribute/report-a-bug.md
> +++ b/contribute/report-a-bug.md
> @@ -20,6 +20,13 @@ on GitLab, taking into account the following guidance.
>    to the vendor's own bug tracker instead, or reproduced with
>    an upstream QEMU build prior to submission.
>  
> +* If any automated tools (AI/LLM based, traditional static
> +  analysis, or fuzzers) were used to discover the issue, the
> +  reporter is required to declare this at the start of the
> +  bug report. Users of such tools are required to perform
> +  triage of their output to validate all findings and reproducer
> +  scenarios prior to submitting a bug report.
> +
>  * Reproduce the problem directly with a QEMU command-line. Avoid
>    frontends and management stacks, to ensure that the bug is in
>    QEMU itself and not in a frontend and make it easier for
> -- 
> 2.54.0



  parent reply	other threads:[~2026-06-10 10:29 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-04 16:50 [qemu-web RFC 0/3] switch to GitLab confidential issues for security disclosure Daniel P. Berrangé
2026-06-04 16:50 ` [qemu-web RFC 1/3] contribute: reformat/restructure bug report guidance Daniel P. Berrangé
2026-06-08 13:13   ` Peter Maydell
2026-06-04 16:50 ` [qemu-web RFC 2/3] contribute: add automate tool disclosure to bug reporting Daniel P. Berrangé
2026-06-08 13:16   ` Peter Maydell
2026-06-10 10:29   ` Michael S. Tsirkin [this message]
2026-06-04 16:50 ` [qemu-web RFC 3/3] contribute: switch security process to gitlab confidential issues Daniel P. Berrangé
2026-06-08 13:39   ` Peter Maydell
2026-06-10 10:22     ` Michael S. Tsirkin
2026-06-10  8:14   ` Thomas Huth
2026-06-10 10:18   ` Michael S. Tsirkin
2026-06-10 11:02     ` Daniel P. Berrangé
2026-06-10 11:06       ` Michael S. Tsirkin
2026-06-10 11:10         ` Daniel P. Berrangé
2026-06-10 11:20           ` Michael S. Tsirkin
2026-06-08 16:10 ` [qemu-web RFC 0/3] switch to GitLab confidential issues for security disclosure Mauro Matteo Cascella
2026-06-10 10:28 ` Michael S. Tsirkin
2026-06-10 11:07   ` Daniel P. Berrangé

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260610062841-mutt-send-email-mst@kernel.org \
    --to=mst@redhat.com \
    --cc=alex.bennee@linaro.org \
    --cc=berrange@redhat.com \
    --cc=mcascell@redhat.com \
    --cc=pbonzini@redhat.com \
    --cc=pierrick.bouvier@oss.qualcomm.com \
    --cc=qemu-devel@nongnu.org \
    --cc=thuth@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.