public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: "Rodrigo Rubira Branco (BSDaemon)" <rbranco@LA.CHECKPOINT.COM>
To: Greg KH <gregkh@suse.de>
Cc: linux-kernel@vger.kernel.org, stable@kernel.org, greg@kroah.com,
	"'Justin Forbes'" <jmforbes@linuxtx.org>,
	"'Zwane Mwaikambo'" <zwane@arm.linux.org.uk>,
	"'Theodore Ts'o'" <tytso@mit.edu>,
	"'Randy Dunlap'" <rdunlap@xenotime.net>,
	"'Dave Jones'" <davej@redhat.com>,
	"'Chuck Wolber'" <chuckw@quantumlinux.com>,
	"'Chris Wedgwood'" <reviews@ml.cw.f00f.org>,
	"'Michael Krufky'" <mkrufky@linuxtv.org>,
	"'Chuck Ebbert'" <cebbert@redhat.com>,
	"'Domenico Andreoli'" <cavokz@gmail.com>,
	"'Willy Tarreau'" <w@1wt.eu>,
	torvalds@linux-foundation.org, akpm@linux-foundation.org,
	alan@lxorguk.ukuu.org.uk, "'Alan Cox'" <alan@redhat.com>,
	caglar@pardus.org.tr, casey@schaufler-ca.com,
	spender@grsecurity.net, pageexec@freemail.hu,
	rodrigo@kernelhacking.com
Subject: Re: [stable] Linux 2.6.25.10 (resume)
Date: Fri, 18 Jul 2008 11:07:45 -0300	[thread overview]
Message-ID: <4880A3B1.3050103@la.checkpoint.com> (raw)
In-Reply-To: <20080716044905.GA9033@suse.de>

[-- Attachment #1: Type: text/plain, Size: 1061 bytes --]

Greg KH escreveu:
> On Wed, Jul 16, 2008 at 01:01:24AM -0300, Rodrigo Rubira Branco wrote:
>   
>> First of all sorry for copy many people who maybe are not in the initial
>> discussion, but since I've not been copied I have no idea who are and who
>> are not in that thread ;)
>>
>> The point that many people are trying to make is that Linux has a policy
>> defined in a document (Documentation/SecurityBugs) but are not following it.
>>     
>
> {sigh}
>
> Are you sure?  What specific sentance(s) are you saying that we are not
> currently following.  And if not, can you propose a patch to the file to
> properly reflect how you seem to think we currently are working?
>
>   
Attached ;)  Please, let me know what do you think.

> getting very annoyed at people saying I am somehow doing the job I do
> for free, on my own time, incorrectly,
>
> greg k-h
>   
For free? Hum, let's forget that you work as a linux developer... we are
also trying to contribute in some way for free...


P.S:  It's obvious that my opinions are mine, not of my employer ;)




[-- Attachment #2: SecurityBugs.patch --]
[-- Type: text/plain, Size: 2497 bytes --]

--- SecurityBugs.orig	2008-07-16 23:46:09.000000000 -0300
+++ SecurityBugs	2008-07-17 14:58:32.000000000 -0300
@@ -1,7 +1,7 @@
-Linux kernel developers take security very seriously.  As such, we'd
-like to know when a security bug is found so that it can be fixed and
-disclosed as quickly as possible.  Please report security bugs to the
-Linux kernel security team.
+Linux kernel developers take security very seriously, in exactly the 
+same way we do with any other bugs.  As such, we'd like to know when 
+a security bug is found so that it can be fixed as soon as possible.
+Please report security bugs to the Linux kernel security team.
 
 1) Contact
 
@@ -14,23 +14,24 @@
 As it is with any bug, the more information provided the easier it
 will be to diagnose and fix.  Please review the procedure outlined in
 REPORTING-BUGS if you are unclear about what information is helpful.
-Any exploit code is very helpful and will not be released without
-consent from the reporter unless it has already been made public.
+Any exploit code is very helpful and will not be released.
 
 2) Disclosure
 
 The goal of the Linux kernel security team is to work with the
 bug submitter to bug resolution as well as disclosure.  We prefer
-to fully disclose the bug as soon as possible.  It is reasonable to
+to not disclose the bug, since we believe any kind of bug deserves the
+same attention and will be quickly patched.  It is reasonable to
 delay disclosure when the bug or the fix is not yet fully understood,
 the solution is not well-tested or for vendor coordination.  However, we
 expect these delays to be short, measurable in days, not weeks or months.
 A disclosure date is negotiated by the security team working with the
-bug submitter as well as vendors.  However, the kernel security team
-holds the final say when setting a disclosure date.  The timeframe for
-disclosure is from immediate (esp. if it's already publically known)
-to a few weeks.  As a basic default policy, we expect report date to
-disclosure date to be on the order of 7 days.
+bug submitter as well as vendors if the submitter wants to disclose.  
+However, the kernel security team holds the final say when setting a 
+disclosure date.  The timeframe for disclousure is from immediate (esp. if
+it's already publically known) to a few weeks.  As a basic default policy,
+we expect report date to disclosure (if the submitter requires disclosure)
+to be on the order of 7 days.
 
 3) Non-disclosure agreements
 


  reply	other threads:[~2008-07-18 15:08 UTC|newest]

Thread overview: 32+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20080701151057.930340322@mini.kroah.org>
2008-07-01 15:18 ` [patch 0/9] 2.6.25.10 -stable review Greg KH
2008-07-01 15:18   ` [patch 1/9] TTY: fix for tty operations bugs Greg KH
2008-07-01 16:01     ` Greg KH
2008-07-02  9:57       ` S.Çağlar Onur
2008-07-02  9:44         ` Alan Cox
2008-07-02 14:41         ` Greg KH
2008-07-02 15:09           ` S.Çağlar Onur
2008-07-16  4:01             ` [stable] Linux 2.6.25.10 (resume) Rodrigo Rubira Branco
2008-07-16  4:49               ` Greg KH
2008-07-18 14:07                 ` Rodrigo Rubira Branco (BSDaemon) [this message]
2008-07-18 15:20                   ` Willy Tarreau
2008-07-18 15:29                     ` Rodrigo Rubira Branco (BSDaemon)
2008-07-19  4:45                       ` david
2008-07-19 10:11                   ` Alan Cox
2008-07-22  0:48                     ` Rodrigo Rubira Branco (BSDaemon)
2008-07-23  4:27                       ` Greg KH
2008-07-23 11:54                         ` pageexec
2008-07-23 14:31                           ` Henrique de Moraes Holschuh
2008-07-23 14:53                             ` pageexec
2008-07-19 22:13                   ` Greg KH
2008-07-20 17:28                     ` Al Viro
2008-07-22  1:07                       ` Rodrigo Rubira Branco (BSDaemon)
2008-07-22  0:52                     ` Rodrigo Rubira Branco (BSDaemon)
2008-07-01 15:19   ` [patch 2/9] futexes: fix fault handling in futex_lock_pi Greg KH
2008-07-01 15:19   ` [patch 3/9] IB/mthca: Clear ICM pages before handing to FW Greg KH
2008-07-01 15:19   ` [patch 4/9] DRM: enable bus mastering on i915 at resume time Greg KH
2008-07-01 15:19   ` [patch 5/9] x86_64 ptrace: fix sys32_ptrace task_struct leak Greg KH
2008-07-01 15:19   ` [patch 6/9] sched: fix cpu hotplug Greg KH
2008-07-01 15:19   ` [patch 7/9] ptrace GET/SET FPXREGS broken Greg KH
2008-07-01 15:19   ` [patch 8/9] x86: fix cpu hotplug crash Greg KH
2008-07-01 15:19   ` [patch 9/9] x86: shift bits the right way in native_read_tscp Greg KH
2008-07-01 16:43   ` [patch 0/9] 2.6.25.10 -stable review Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4880A3B1.3050103@la.checkpoint.com \
    --to=rbranco@la.checkpoint.com \
    --cc=akpm@linux-foundation.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=alan@redhat.com \
    --cc=caglar@pardus.org.tr \
    --cc=casey@schaufler-ca.com \
    --cc=cavokz@gmail.com \
    --cc=cebbert@redhat.com \
    --cc=chuckw@quantumlinux.com \
    --cc=davej@redhat.com \
    --cc=greg@kroah.com \
    --cc=gregkh@suse.de \
    --cc=jmforbes@linuxtx.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mkrufky@linuxtv.org \
    --cc=pageexec@freemail.hu \
    --cc=rdunlap@xenotime.net \
    --cc=reviews@ml.cw.f00f.org \
    --cc=rodrigo@kernelhacking.com \
    --cc=spender@grsecurity.net \
    --cc=stable@kernel.org \
    --cc=torvalds@linux-foundation.org \
    --cc=tytso@mit.edu \
    --cc=w@1wt.eu \
    --cc=zwane@arm.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox