All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Daniel P. Berrangé" <berrange@redhat.com>
To: Thomas Huth <thuth@redhat.com>
Cc: qemu-devel@nongnu.org, "Michael S. Tsirkin" <mst@redhat.com>,
	Paolo Bonzini <pbonzini@redhat.com>
Subject: Re: [qemu-web PATCH] security: rework guideline about issue URL / CVE references
Date: Fri, 19 Jun 2026 09:41:44 +0100	[thread overview]
Message-ID: <ajUAyOd7mYaeiAlD@redhat.com> (raw)
In-Reply-To: <ff565264-cabf-45d7-81e2-a35a23c79638@redhat.com>

On Fri, Jun 19, 2026 at 10:27:33AM +0200, Thomas Huth wrote:
> On 19/06/2026 10.22, Daniel P. Berrangé wrote:
> > Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
> > ---
> > 
> > This incorporates the feedback that Michael provided on the
> > just merged security process changes.
> > 
> >   contribute/security-process.md | 23 ++++++++++++++++-------
> >   1 file changed, 16 insertions(+), 7 deletions(-)
> > 
> > diff --git a/contribute/security-process.md b/contribute/security-process.md
> > index c091fa1..146e9cd 100644
> > --- a/contribute/security-process.md
> > +++ b/contribute/security-process.md
> > @@ -92,19 +92,28 @@ be scrubbed before disclosure.
> >    * The maintainer(s) will develop and/or review patch(es)
> >      for the issue privately, optionally attaching work in
> > -   progress fixes to the GitLab issues. All patches must
> > -   include the issue URL in the commit message(s). The
> > -   **"Workflow::In Progress"** label should be assigned when
> > +   progress fixes to the GitLab issues. The
> > +   **"Workflow::In Progress"** label can be assigned when
> >      a maintainer starts working on a fix.
> >    * When a CVE is allocated, it must be recorded as a comment on
> >      the GitLab issue, and the **"CVE::Required"** label replaced by
> >      the **"CVE::Assigned"** label.
> > - * The maintainer(s) will update the commit message(s) to include
> > -   the assigned CVE and issue URL. If multiple commits are required
> > -   to fix an issue the CVE must be included in the final commit in
> > -   the series, and may optionally be included in all prior commits.
> > + * The maintainer(s) will update the commit message(s) before
> > +   sending a pull request to include the assigned CVE and issue
> > +   URL in the following format:
> > +
> > +     ```
> > +     Fixes: CVE-1980-12345
> 
> So far we used "Fixes:" to indicate the commit ID of the patch that
> contained the bug. So maybe it's better to use something like "CVE:"
> instead?

We've used it alot for CVEs too:

  $ git log | grep 'Fixes: CVE'  | wc -l
  116


> > +     Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/75
> 
> Maybe best to use a number here that does not exist, e.g. "42".

Oh yes, good idea.

> 
>  Thomas
> 
> 
> > +     Reviewed-by: Not Me <notme@elsewhere.com>
> > +     Signed-off-by: Some One <someone@somewhere.com>
> > +     ```
> > +
> > +   If multiple commits are required to fix an issue the CVE must
> > +   be included in the final commit in the series, and may optionally
> > +   be included in all prior commits.
> >    * When the maintainer(s) are satisfied that the patch(es) are
> >      suitable to propose for merge, they must be submitted to
> 

With regards,
Daniel
-- 
|: https://berrange.com       ~~        https://hachyderm.io/@berrange :|
|: https://libvirt.org          ~~          https://entangle-photo.org :|
|: https://pixelfed.art/berrange   ~~    https://fstop138.berrange.com :|



  reply	other threads:[~2026-06-19  8:42 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-19  8:22 [qemu-web PATCH] security: rework guideline about issue URL / CVE references Daniel P. Berrangé
2026-06-19  8:27 ` Thomas Huth
2026-06-19  8:41   ` Daniel P. Berrangé [this message]
2026-06-19  8:45     ` Thomas Huth
2026-06-19  8:27 ` Michael S. Tsirkin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ajUAyOd7mYaeiAlD@redhat.com \
    --to=berrange@redhat.com \
    --cc=mst@redhat.com \
    --cc=pbonzini@redhat.com \
    --cc=qemu-devel@nongnu.org \
    --cc=thuth@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.