xen-devel.lists.xenproject.org archive mirror
 help / color / mirror / Atom feed
* tmem/XSA-15 backport?
@ 2012-09-19 15:48 Dan Magenheimer
  2012-09-19 16:00 ` Jan Beulich
  2012-09-25 10:30 ` Jan Beulich
  0 siblings, 2 replies; 5+ messages in thread
From: Dan Magenheimer @ 2012-09-19 15:48 UTC (permalink / raw)
  To: xen-devel
  Cc: Ian Campbell, Konrad Wilk, Ian Jackson, tim, Zhenzhong Duan,
	JBeulich

Once zduan's tmem restore fix is applied, all known
tmem security issues have been resolved and tested
and tmem is fully functional again in xen-unstable,
including save/restore.

I'd like to recommend that all tmem patches be backported
to 4.1-stable and 4.2-stable prior to the next
point release and preferably asap.

Auditing activities are being conducted separately under
Konrad's supervision, but it seems wise to apply known
security patches to released trees before any users/distros
update.

Comments or objections?

Thanks,
Dan

P.S. Some work remains for tmem to always work properly
with "xl create" but "xm create" works fine.

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: tmem/XSA-15 backport?
  2012-09-19 15:48 tmem/XSA-15 backport? Dan Magenheimer
@ 2012-09-19 16:00 ` Jan Beulich
  2012-09-19 17:06   ` Dan Magenheimer
  2012-09-25 10:30 ` Jan Beulich
  1 sibling, 1 reply; 5+ messages in thread
From: Jan Beulich @ 2012-09-19 16:00 UTC (permalink / raw)
  To: Dan Magenheimer
  Cc: Keir Fraser, Ian Campbell, Konrad Wilk, tim, IanJackson,
	Zhenzhong Duan, xen-devel

>>> On 19.09.12 at 17:48, Dan Magenheimer <dan.magenheimer@oracle.com> wrote:
> I'd like to recommend that all tmem patches be backported
> to 4.1-stable and 4.2-stable prior to the next
> point release and preferably asap.
> 
> Auditing activities are being conducted separately under
> Konrad's supervision, but it seems wise to apply known
> security patches to released trees before any users/distros
> update.
> 
> Comments or objections?

My recollection is that the committers more or less agreed to
consider backports only once the full audit was done, and we
were assured that no further vulnerabilities are to be
expected. But I'm certainly open to weakening that position
if others prefer going that route.

Jan

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: tmem/XSA-15 backport?
  2012-09-19 16:00 ` Jan Beulich
@ 2012-09-19 17:06   ` Dan Magenheimer
  0 siblings, 0 replies; 5+ messages in thread
From: Dan Magenheimer @ 2012-09-19 17:06 UTC (permalink / raw)
  To: Jan Beulich
  Cc: Keir Fraser, Ian Campbell, Konrad Wilk, tim, IanJackson,
	Zhenzhong Duan, xen-devel

> From: Jan Beulich [mailto:JBeulich@suse.com]
> Sent: Wednesday, September 19, 2012 10:00 AM
> To: Dan Magenheimer
> Cc: Ian Campbell; IanJackson; xen-devel@lists.xen.org; Konrad Wilk; Zhenzhong Duan; Keir Fraser;
> tim@xen.org
> Subject: Re: tmem/XSA-15 backport?
> 
> >>> On 19.09.12 at 17:48, Dan Magenheimer <dan.magenheimer@oracle.com> wrote:
> > I'd like to recommend that all tmem patches be backported
> > to 4.1-stable and 4.2-stable prior to the next
> > point release and preferably asap.
> >
> > Auditing activities are being conducted separately under
> > Konrad's supervision, but it seems wise to apply known
> > security patches to released trees before any users/distros
> > update.
> >
> > Comments or objections?
> 
> My recollection is that the committers more or less agreed to
> consider backports only once the full audit was done, and we
> were assured that no further vulnerabilities are to be
> expected. But I'm certainly open to weakening that position
> if others prefer going that route.

Yes, didn't make much sense to me :-)

I agree it may be wise to _not_ remove any published recommendations
to _not_ enable tmem until a full audit is done, but failing
to fix known issues (security or otherwise) in released trees
because there _might_ be other bugs found in the future seems
odd to me.

Other comments or objections?

Dan

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: tmem/XSA-15 backport?
  2012-09-19 15:48 tmem/XSA-15 backport? Dan Magenheimer
  2012-09-19 16:00 ` Jan Beulich
@ 2012-09-25 10:30 ` Jan Beulich
  2012-09-25 19:08   ` Dan Magenheimer
  1 sibling, 1 reply; 5+ messages in thread
From: Jan Beulich @ 2012-09-25 10:30 UTC (permalink / raw)
  To: xen-devel, Dan Magenheimer
  Cc: Zhenzhong Duan, tim, IanJackson, Ian Campbell, Konrad Wilk

>>> On 19.09.12 at 17:48, Dan Magenheimer <dan.magenheimer@oracle.com> wrote:
> Once zduan's tmem restore fix is applied, all known
> tmem security issues have been resolved and tested
> and tmem is fully functional again in xen-unstable,
> including save/restore.
> 
> I'd like to recommend that all tmem patches be backported
> to 4.1-stable and 4.2-stable prior to the next
> point release and preferably asap.

Done.

Jan

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: tmem/XSA-15 backport?
  2012-09-25 10:30 ` Jan Beulich
@ 2012-09-25 19:08   ` Dan Magenheimer
  0 siblings, 0 replies; 5+ messages in thread
From: Dan Magenheimer @ 2012-09-25 19:08 UTC (permalink / raw)
  To: Jan Beulich, xen-devel
  Cc: Zhenzhong Duan, tim, IanJackson, Ian Campbell, Konrad Wilk

> From: Jan Beulich [mailto:JBeulich@suse.com]
> Sent: Tuesday, September 25, 2012 4:30 AM
> To: xen-devel@lists.xen.org; Dan Magenheimer
> Cc: Ian Campbell; IanJackson; Konrad Wilk; Zhenzhong Duan; tim@xen.org
> Subject: Re: tmem/XSA-15 backport?
> 
> >>> On 19.09.12 at 17:48, Dan Magenheimer <dan.magenheimer@oracle.com> wrote:
> > Once zduan's tmem restore fix is applied, all known
> > tmem security issues have been resolved and tested
> > and tmem is fully functional again in xen-unstable,
> > including save/restore.
> >
> > I'd like to recommend that all tmem patches be backported
> > to 4.1-stable and 4.2-stable prior to the next
> > point release and preferably asap.
> 
> Done.

Excellent!  Thanks much!

Dan

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2012-09-25 19:08 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-09-19 15:48 tmem/XSA-15 backport? Dan Magenheimer
2012-09-19 16:00 ` Jan Beulich
2012-09-19 17:06   ` Dan Magenheimer
2012-09-25 10:30 ` Jan Beulich
2012-09-25 19:08   ` Dan Magenheimer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).