All of lore.kernel.org
 help / color / mirror / Atom feed
* [RFC 0/1] security-process: update with mailing list details
@ 2020-11-24 14:22 P J P
  2020-11-24 14:22 ` [RFC 1/1] security-process: update process information P J P
  0 siblings, 1 reply; 6+ messages in thread
From: P J P @ 2020-11-24 14:22 UTC (permalink / raw)
  To: Stefan Hajnoczi
  Cc: peter.maydell, Stefano Stabellini, Petr Matousek, Prasad J Pandit,
	Konrad Rzeszutek Wilk, secalert, Michael Roth,
	Michael S . Tsirkin, QEMU Developers, Darren Kenny,
	Daniel P . Berrangé

From: Prasad J Pandit <pjp@fedoraproject.org>

Hello,

* After upstream discussions and considering various options like
  LaunchPad bugs, GitLab issues etc.

  -> https://lists.nongnu.org/archive/html/qemu-devel/2020-09/msg04266.html
  -> https://lists.nongnu.org/archive/html/qemu-devel/2020-10/msg00059.html

  We are about to introduce a 'qemu-security' mailing list to receive and
  triage upstream QEMU security issues.

* Intention is to allow more community participation in handling and
  triaging of the QEMU security issues.

* This change relieves current set of individual contacts from the
  responsibility of handling upstream QEMU issues. Of course they are
  welcome to the new 'qemu-security' mailing list.

* To simplify the encrypted communication process, we keep only a single
  contact of <secalert@redhat.com> from our previous list of contacts.

  This way reporters need not look for and manage GPG keys of multiple
  contacts.

* This patch updates the QEMU security-process web page with these
  details.

I'd appreciate if you have any inputs and/or suggestions for this change.

Thank you.
--
Prasad J Pandit (1):
  security-process: update process information

 contribute/security-process.md | 105 +++++++++++++++++----------------
 1 file changed, 55 insertions(+), 50 deletions(-)

--
2.28.0



^ permalink raw reply	[flat|nested] 6+ messages in thread
* Re: [RFC 1/1] security-process: update process information
@ 2020-11-24 16:26 Red Hat Product Security
  0 siblings, 0 replies; 6+ messages in thread
From: Red Hat Product Security @ 2020-11-24 16:26 UTC (permalink / raw)
  To: stefanha, michael.roth, peter.maydell, darren.kenny, konrad.wilk,
	pjp, berrange, sstabellini, ppandit, mst, pmatouse, qemu-devel


[-- Attachment #1.1: Type: text/plain, Size: 3578 bytes --]

Hello!

INC1531976 ([RFC 1/1] security-process: update process information) has been updated.

Opened for: Prasad Pandit
Followers: stefanha@gmail.com, peter.maydell@linaro.org, sstabellini@kernel.org, Petr Matousek, pjp@fedoraproject.org, konrad.wilk@oracle.com, michael.roth@amd.com, mst@redhat.com, qemu-devel@nongnu.org, darren.kenny@oracle.com, Daniel Berrange

A Guest updated your request with the following comments:

Reply from: darren.kenny@oracle.com
 Hi Prasad,
 Thanks for writing this up.
 I have some comments below on the response steps.
 On Tuesday, 2020-11-24 at 19:52:38 +0530, P J P wrote:
> From: Prasad J Pandit 
>
> We are about to introduce a qemu-security mailing list to report
> and triage QEMU security issues.
>
> Update the QEMU security process web page with new mailing list
> and triage details.
>
> Signed-off-by: Prasad J Pandit 
> ---
> contribute/security-process.md | 105 +++++++++++++++++----------------
> 1 file changed, 55 insertions(+), 50 deletions(-)
>
> diff --git a/contribute/security-process.md b/contribute/security-process.md
> index 1239967..a03092c 100644
> --- a/contribute/security-process.md
> +++ b/contribute/security-process.md
 ...
 > +## How we respond:
> +
> +* Steps to triage:
> + - Examine and validate the issue details to confirm whether the
> + issue is genuine and can be misused for malicious purposes.
> + - Determine its worst case impact and severity(Low/M/I/Critical)
> + - Negotiate embargo timeline (if required)
> + - Request a CVE and open an upstream bug
> + - Create an upstream fix patch
> +
> +* Above security lists are operated by select analysts, maintainers and/or
> + representatives from downstream communities.
> +
> +* List members follow a **responsible disclosure** policy. Any non-public
> + information you share about security issues, is kept confidential within the
> + respective affiliated companies. Such information shall not be passed on to
> + any third parties, including Xen Security Project, without your prior
> + permission.
> +
> +* We aim to triage security issues within maximum of 60 days.
 I always understood triage to be the initial steps in assessing a bug:
 - determining if it is a security bug, in this case
 - then deciding on the severity of it
 I would not expect triage to include seeing it through to the point
where there is a fix as in the steps above and as such that definition
of triage should probably have a shorter time frame.
 At this point, if it is not a security bug, then it should just be
logged as any other bug in Qemu, which goes on to qemu-devel then.
 But, if it is a security bug - then that is when the next steps would be
taken, to (not necessarily in this order):
 - negotiate an embargo (should the predefined 60 days be insufficient)
  - don't know if you need to mention that this would include downstream
 in this too, since they will be the ones most likely to need the
 time to distribute a fix
 - request a CVE
 - create a fix for upstream
  - distros can work on bringing that back into downstream as needed,
 within the embargo period
 I do feel that it is worth separating the 2 phases of triage and beyond,
but of course that is only my thoughts on it, I'm sure others will have
theirs.
 Thanks,
 Darren.

How can I track and update my request?

To respond, reply to this email. You may also create a new email and include the request number (INC1531976) in the subject.

Thank you,
Product Security

Ref:MSG36787539

[-- Attachment #1.2: Type: text/html, Size: 5159 bytes --]

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2020-11-25 14:45 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2020-11-24 14:22 [RFC 0/1] security-process: update with mailing list details P J P
2020-11-24 14:22 ` [RFC 1/1] security-process: update process information P J P
2020-11-24 16:23   ` Darren Kenny
2020-11-25 12:48     ` P J P
2020-11-25 14:44       ` Darren Kenny
  -- strict thread matches above, loose matches on Subject: below --
2020-11-24 16:26 Red Hat Product Security

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.