From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp3.osuosl.org (smtp3.osuosl.org [140.211.166.136]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 739BC2144AF for ; Wed, 26 Feb 2025 13:12:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=140.211.166.136 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1740575571; cv=none; b=KBWa76qyqPoSTJ9e/f2GkLD3uQR7zm3Wtmh75NLusgF0cvdMZxOmlYy2GLmcJk7JLxQiluuYNliqy256f84HC2ZL35DFvbh6cTv4fOr06XF0ogZ9TQGt8i1K3mLdr5MEQ+41wS2PXvHfsbTW07vbH9HpMBK/U2GKhTDXHN97JXY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1740575571; c=relaxed/simple; bh=ii4VSbV76E2hzsGKsg2FfXvqfOT+Z7m0RGpMEjG9+R8=; h=Message-ID:Date:MIME-Version:To:From:Subject:Content-Type; b=qNujZuWDe79vwGLc43gLT+e6nv4DifTg9opNw+q1KXmy6QoGnG/pta3hpl5u9IrcQqgSBTqUTxdufe8P4oglkMZyj1mWG2JVj1d7HaDv3ZfZnw8ldFqbvm4nx/RiFnwnkU3ZDTXak6TjHyf+eq9IcE6U2A74zHzUtIzt/MhXLkM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=MHPCwzDc; arc=none smtp.client-ip=140.211.166.136 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="MHPCwzDc" Received: from localhost (localhost [127.0.0.1]) by smtp3.osuosl.org (Postfix) with ESMTP id 0375E60862 for ; Wed, 26 Feb 2025 13:12:50 +0000 (UTC) X-Virus-Scanned: amavis at osuosl.org X-Spam-Flag: NO X-Spam-Score: -5.79 X-Spam-Level: Received: from smtp3.osuosl.org ([127.0.0.1]) by localhost (smtp3.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP id CvqutH9jQRRQ for ; Wed, 26 Feb 2025 13:12:49 +0000 (UTC) Received-SPF: Pass (mailfrom) identity=mailfrom; client-ip=170.10.129.124; helo=us-smtp-delivery-124.mimecast.com; envelope-from=carlos@redhat.com; receiver= DMARC-Filter: OpenDMARC Filter v1.4.2 smtp3.osuosl.org 370BC60762 Authentication-Results: smtp3.osuosl.org; dmarc=pass (p=none dis=none) header.from=redhat.com DKIM-Filter: OpenDKIM Filter v2.11.0 smtp3.osuosl.org 370BC60762 Authentication-Results: smtp3.osuosl.org; dkim=pass (1024-bit key, unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=MHPCwzDc Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by smtp3.osuosl.org (Postfix) with ESMTPS id 370BC60762 for ; Wed, 26 Feb 2025 13:12:48 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1740575567; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding:autocrypt:autocrypt; bh=94gF98gP/Hdd9H4+7BU0PmhPqMKf3JlT24dCIP98jTA=; b=MHPCwzDceDzrCRG9wgtLgF6Z17lEbjVWK2z+vR7u15NHjL0D+rSwrjc+E1PZSaDzJtmdBu MKxxTQaF4nL4gwj5w0dPU4YZB1pqLrTCqDoJkbzfSnsnFmt1e+44l6Nv4z/8NggzDliW/1 fxr7nj0bEjg+zJ/WaGh1VvoqOPmYGGA= Received: from mail-qv1-f72.google.com (mail-qv1-f72.google.com [209.85.219.72]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-481-cjJpqbo_N5ylpnhiEPJfGg-1; Wed, 26 Feb 2025 08:12:46 -0500 X-MC-Unique: cjJpqbo_N5ylpnhiEPJfGg-1 X-Mimecast-MFC-AGG-ID: cjJpqbo_N5ylpnhiEPJfGg_1740575565 Received: by mail-qv1-f72.google.com with SMTP id 6a1803df08f44-6e4f08c54e6so58008126d6.1 for ; Wed, 26 Feb 2025 05:12:45 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1740575565; x=1741180365; h=content-transfer-encoding:organization:autocrypt:subject:from:to :content-language:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=94gF98gP/Hdd9H4+7BU0PmhPqMKf3JlT24dCIP98jTA=; b=MvXPiKXGOukiuMoWhzFd/r5y2Z2yaRirq6NhIxRi89EjPXg+xhNOpSSWghJ4LvRDBw /7oE1bNyOSl5lti8tdLfaBjaYq+DvdzDureqMLUggtkWqlbCUv4IdzaLoQVG0nxIVQXb yVERfW1c8/x9T3pJmUEWfmovQ8MLH0utnSATYdLCJoYCZZT7udXlfePSjVMj3kd8tQlr X4wlgGEH8b4BlGRuw8flc+IFC9jcAY3VxQRvdsJHTdhfcmEVbGz3H+sHxLdN3f//mCO0 ZWbbA2JpRKhUrNtMWlTEMEqJMgjm01RVUccTw8QLv6xFMmE1y2iRDd7vblj5zuIPXB9k /ymQ== X-Gm-Message-State: AOJu0Yy8586aLoh3aKJjCtlNoj1mhJgH5yjMkP3KzgijKisXjPks6DlT 7FCwW4m+xcZSADyOW0ViQ3EQrzDT37j+rIG/RVnD88mC+Y0/KErBZMoQN7k5otfA3iZGtGpwCko 4vo+5tAh8LB1LC0PV+8WO7jMLc9sDDNMhRz6gGghoOxr92xSAwH5JBGggqtJgyFH+qJzKOVxQXg F8T0kDP+hnNFFlIRdgFPFkCwmhZHBEnMk9VY6D0vLPgrFE6PnnLQ== X-Gm-Gg: ASbGnctLHpUdaDWhIqZZ9hMPSpYe9wQM8EZRciY+Qa9LjK8AXCiSHETcNczlbRKwSXL /BklAwxcJ4wH/sTKFR2Uvmml0LTsLd5SAZUdq3ypTkPiTVptlmzHHttNMjtF8tDed1WATw1FH+t dXNWJrOInxhiMCe8/nKBC5o8AzEHVysQ0K6XtgixDvScMIjvalmYGppuuDRBCuMQ516qeoDe6iZ 377vu4oQCoG+y000t6ZM4Eku51pwDivNR/pEWzaJIZOKlWHD3ziti+GmtjMmo9JWiggZlpEluKM 1qUUWiy7SzKXUh+9 X-Received: by 2002:a05:6214:27c6:b0:6e6:684f:7f78 with SMTP id 6a1803df08f44-6e886871063mr42275376d6.3.1740575565182; Wed, 26 Feb 2025 05:12:45 -0800 (PST) X-Google-Smtp-Source: AGHT+IGenCEYgcf6E2j3e2lS4LGHL1fJTHQ3sYPM3so++v6ZNDnRBhW57IyfEGnPiaRhrdUs252N1g== X-Received: by 2002:a05:6214:27c6:b0:6e6:684f:7f78 with SMTP id 6a1803df08f44-6e886871063mr42275096d6.3.1740575564616; Wed, 26 Feb 2025 05:12:44 -0800 (PST) Received: from [192.168.0.241] ([198.48.244.52]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-6e87b087147sm21681686d6.41.2025.02.26.05.12.43 for (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 26 Feb 2025 05:12:44 -0800 (PST) Message-ID: <29ffeff2-ea80-4b61-96fc-bc75fbfd7b77@redhat.com> Date: Wed, 26 Feb 2025 08:12:43 -0500 Precedence: bulk X-Mailing-List: cti-tac@lists.linuxfoundation.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird To: cti-tac@lists.linuxfoundation.org From: Carlos O'Donell Subject: glibc status update - Week ending January 31st. Autocrypt: addr=carlos@redhat.com; keydata= xsFNBFef5BoBEACvJ15QMMZh4stKHbz0rs78XsOdxuug37dumTx6ngrDCwZ61k7nHQ+uxLuo QvLSc6YJGBEfiNFbs1hvhRFNR7xJbzRYmin7kJZZ/06fH2cgTkQhN0mRBP8KsKKT+7SvvBL7 85ZfAhArWf5m5Tl0CktZ8yoG8g9dM4SgdvdSdzZUaWBVHc6TjdAb9YEQ1/jpyfHsQp+PWLuQ ZI8nZUm+I3IBDLkbbuJVQklKzpT1b8yxVSsHCyIPFRqDDUjPL5G4WnUVy529OzfrciBvHdxG sYYDV8FX7fv6V/S3eL6qmZbObivIbLD2NbeDqw6vNpr+aehEwgwNbMVuVfH1PVHJV8Qkgxg4 PqPgQC7GbIhxxYroGbLJCQ41j25M+oqCO/XW/FUu/9x0vY5w0RsZFhlmSP5lBDcaiy3SUgp3 MSTePGuxpPlLVMePxKvabSS7EErLKlrAEmDgnUYYdPqGCefA+5N9Rn2JPfP7SoQEp2pHhEyM 6Xg9x7TJ+JNuDowQCgwussmeDt2ZUeMl3s1f6/XePfTd3l8c8Yn5Fc8reRa28dFANU6oXiZf 7/h3iQXPg81BsLMJK3aA/nyajRrNxL8dHIx7BjKX0/gxpOozlUHZHl73KhAvrBRaqLrr2tIP LkKrf3d7wdz4llg4NAGIU4ERdTTne1QAwS6x2tNa9GO9tXGPawARAQABzSpDYXJsb3MgTydE b25lbGwgKFdvcmspIDxjYXJsb3NAcmVkaGF0LmNvbT7CwZUEEwEIAD8CGwMGCwkIBwMCBhUI AgkKCwQWAgMBAh4BAheAFiEEcnNUKzmWLfeymZMUFnkrTqJTQPgFAmagDwgFCRDhXm4ACgkQ FnkrTqJTQPgLlw/+JD7l4tj8l8hAMUlszrlIT6IhKSODzjrGO+6d9Y6T9vyE2kk4Xbn+kdJf uBl+wj2+U15MsQe9Z4RwowIB3YHHXgj53M2OjqOAY/sRWXZVDfmVj03hqW8D7zFxjc0SZ9cI TI0MwrDWc+Fr3naXeo7HhgjUmULfPndxb8NHVV4Ds2DTkZoUMwB8l3dboD+nKi5GbfVBf3Q5 cBw0CPkxPl0hxD9sr5IMgWIKVLtvztMIXv2xWAavqk8pQjk0zCYd46GcA8d9pZuac24e9NbM ZzTxu6cP0sKhub1JFIadyBHtJnEV/8Auc8nXJ63QY3h0QVCJYV35gQeejEdMD94in2XTkxk0 A/xCp32bmSZv5flsmdAIv5LK4jTKLvzd6BSy/v7qlpgQ7sNaxQ/JRd+8YuBIiUVIp/kgGezD qtGZSpvPCFuG3LxsdvAu7JAzBY3sfBd2lSGOeHX/JK0nQ6s97j4HlSuXIabSOdsCI5UGSOq5 thbIqfK3ewUSUB0yGvWf7EyuZugtCZOaFGpvcT3ix9/sP1fTRlJl+bNjMcO8GwedDoy85oeg yLCEV9gejCr+NijLfPYtb1s8o0hYu13uBojFyBv+bkUI5hTQaVLacq7VglA/QLOy/3mtM2v5 4OEotiNXbKypHFKnoks/MFpP4xdwxGX5jU4MgFg80aPFGr0oZVXOwU0EV5/kGgEQAKvTJke+ QSjATmz11ALKle/SSEpUwL5QOpt3xomEATcYAamww0HADfGTKdUR+aWgOK3vqu6Sicr1zbuZ jHCs2GaIgRoqh1HKVgCmaJYjizvidHluqrox6qqc9PG0bWb0f5xGQw+X2z+bEinzv4qaep1G 1OuYgvG49OpHTgZMiJq9ncHCxkD2VEJKgMywGJ4Agdl+NWVn0T7w6J+/5QmBIE8hh4NzpYfr xzWCJ9iZ3skG4zBGB4YEacc3+oeEoybc10h6tqhQNrtIiSRJH+SUJvOiNH8oMXPLAjfFVy3d 4BOgyxJhE0UhmQIQHMJxCBw81fQD10d0dcru0rAIEldEpt2UXqOr0rOALDievMF/2BKQiOA7 PbMC3/dwuNHDlClQzdjil8O7UsIgf3IMFaIbQoUEvjlgf5cm9a94gWABcfI1xadAq9vcIB5v +9fM71xDgdELnZThTd8LByrG99ExVMcG2PZYXJllVDQDZqYA1PjD9e0yHq5whJi3BrZgwDaL 5vYZEb1EMyH+BQLO3Zw/Caj8W6mooGHgNveRQ1g9FYn3NUp7UvS22Zt/KW4pCpbgkQZefxup KO6QVNwwggV44cTQ37z5onGbNPD8+2k2mmC0OEtGBkj+VH39tRk+uLOcuXlGNSVk3xOyxni0 Nk9M0GvTvPKoah9gkvL/+AofN/31ABEBAAHCwXwEGAEIACYCGwwWIQRyc1QrOZYt97KZkxQW eStOolNA+AUCZqAPEAUJEOFedgAKCRAWeStOolNA+D38D/9WnZY9fUmPhZVwpDnhIXvlXgqX cspZJEBWNS5ArFn8CLcje7z9hzX3+86lqkEeohTmlgtTg4ctZzM+XKyWSiqHCRCR+FX5SKaa 1VveBtwvjTSVmtV1m0rNHEvUZ5x47A8NadWqYi6uOQ22FhEqUOiwJ7EHzk4w9W3gT1913XT1 vmkCn6FtQcrQvJT7pP+oA0YIVs8ADayJcqWHM+Ez7L2fpfAzBDhIS7dq2MYU8LQOQAsx1y7H 6njp5dN/OI/aN/RL6XeX1Kxl4Xe+hc+tq457fLAUnmaevUldvKThuj+5/Cd4DW25MxaqinfY m/U6pBQ4ZwQPGWA0f+GKiJcLosSRXxIuEdZAl82ht+KgT3zhV/BvQRmrD6wX3ywPkJap8h4K ibwz3r6NbHKdCX22ok58oE8NAWtmTRTKXDhh8oWOKdIYjX6jJzdb/F8rPNoEY3UiYbaNTxt5 TE9VD+yWilYO796HMXjXenCOlghy3HFmZbsQ4N+FlG6LQD7cnwm56kcrJk1IlnQXOSOd2BA2 qNbM1Ohry3B+1F4Oaee+ZKH2C5y7Kx0y3m1b5X7Wpx76H5BeUAp6dQi6nNYeqM9PglZIMvSe O4uRThl5mMDx8MXQz6M9qQ5anYwre+/TudTfCzcTpgXod1wEqi2ErJ5jNgh18DRlSQ3tbDvG O0FatDMfJw== Organization: Red Hat X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: F7_7RX0OHrYO6Ki-CrPaBGxMF4jslsgL6li6ivLNMgA_1740575565 X-Mimecast-Originator: redhat.com Content-Language: en-US Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit At the last CTI TAC meeting I decided to switch to weekly reporting on the progress I'm making going through and creating the justifying glibc policy for the CTI changes we're requesting. I'm driving this from the NIST SP 800-218 perspective which has a good framework for making these kinds of decision, and has all sorts of places to state what and why we want and need those changes. Current status looks like this: PO [In progress] 13 sections. - Started PO.1.1 "Identify and document all security requirements" PS [not started] 4 sections. PW [not started] 16 sections. RV [not started] 9 sections. Note: Sending these out backdated. -- Cheers, Carlos.