mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Willy Tarreau <w@1wt.eu>
To: Chris Wright <chrisw@sous-sol.org>
Cc: linux-kernel@vger.kernel.org
Subject: Re: Linux 2.6.25.6
Date: Wed, 11 Jun 2008 01:10:56 +0200	[thread overview]
Message-ID: <20080610231055.GN5609@1wt.eu> (raw)
In-Reply-To: <20080610201218.GM4018@sequoia.sous-sol.org>

On Tue, Jun 10, 2008 at 01:12:23PM -0700, Chris Wright wrote:
> * markus reichelt (ml@mareichelt.de) wrote:
> > * Henrique de Moraes Holschuh <hmh@hmh.eng.br> wrote:
> > > On Mon, 09 Jun 2008, Chris Wright wrote:
> > > > We (the -stable team) are announcing the release of the 2.6.25.6
> > > > kernel.
> > > > 
> > > > It contains a number of assorted bugfixes all over the tree.  Users are
> > > > encouraged to update.
> > > 
> > > It also contains at least one security bugfix, as some were quick
> > > to point out in not-so-kind words:
> > > 
> > > http://lwn.net/Articles/285438/
> > 
> > I agree that security bugfixes should be pointed out more clearly.
> 
> I don't think anybody is disagreeing with that.  It's not always
> obvious to bug submitters or fixers what the security implications are.
> While Brad has a good point, esp. w.r.t. the specific cpufreq bug he
> picked out having security implications, it is not true that we are
> actively hiding security bugs.  Had I realized there was a security
> issue, I would highlight it in the announce message.  In fact, that's
> our standard procedure for -stable.

I second this Chris. When I merge a fix into 2.4, I generally wait
for -stable to release it so that I can reuse the same message and
subject which already includes the reference to the vulnerability
if any.

I don't like obfuscation at all WRT security issues, it does far more
harm than good because it reduces the probability to get them picked
and fixed by users, maintainers, distro packagers, etc...

It's a shame that Brad does not post here, he could have yelled
during the review phase in order to get more explicit changelogs.
*that* would have served a useful purpose. Whining afterwards is
useless though :-/

Willy


  reply	other threads:[~2008-06-10 23:11 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-06-09 19:49 Chris Wright
2008-06-09 19:49 ` Chris Wright
2008-06-10 14:53 ` Henrique de Moraes Holschuh
2008-06-10 19:17   ` markus reichelt
2008-06-10 19:57     ` Alexey Dobriyan
2008-06-10 23:06       ` Henrique de Moraes Holschuh
2008-06-11  6:28         ` Alexey Dobriyan
2008-06-10 20:12     ` Chris Wright
2008-06-10 23:10       ` Willy Tarreau [this message]
2008-06-10 23:20         ` Henrique de Moraes Holschuh

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20080610231055.GN5609@1wt.eu \
    --to=w@1wt.eu \
    --cc=chrisw@sous-sol.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®