* Identify security-related patches
@ 2004-09-02 7:08 Frank Steiner
2004-09-02 18:48 ` Chris Wright
2004-09-02 20:22 ` Florian Weimer
0 siblings, 2 replies; 4+ messages in thread
From: Frank Steiner @ 2004-09-02 7:08 UTC (permalink / raw)
To: Kernel Mailing List
Hi,
is there an easy way to identify all security-related patches out of the
mass of patches floating around on linux.bkbits.net or the kernel bugzilla?
I'm running 2.6.8.1 and would like to keep it as stable as possible, thus,
only apply security patches. Currently I'm searching for "security" and
alike on bitkeeper, but there seems to be no consistent marking.
For instance, it would be nice if all security fixes contained a consistent
marker like "[SECURITY]" in the changeset comments (like the reiserfs xattr/acl
patch does), so that it would be easy to identify them. Or setting some kind
of flag to such patches (I've no idea what bitkeeper allows one to do...).
cu,
Frank
--
Dipl.-Inform. Frank Steiner Web: http://www.bio.ifi.lmu.de/~steiner/
Lehrstuhl f. Bioinformatik Mail: http://www.bio.ifi.lmu.de/~steiner/m/
LMU, Amalienstr. 17 Phone: +49 89 2180-4049
80333 Muenchen, Germany Fax: +49 89 2180-99-4049
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Identify security-related patches
2004-09-02 7:08 Identify security-related patches Frank Steiner
@ 2004-09-02 18:48 ` Chris Wright
2004-09-02 19:12 ` Valdis.Kletnieks
2004-09-02 20:22 ` Florian Weimer
1 sibling, 1 reply; 4+ messages in thread
From: Chris Wright @ 2004-09-02 18:48 UTC (permalink / raw)
To: Frank Steiner; +Cc: Kernel Mailing List
* Frank Steiner (fsteiner-mail@bio.ifi.lmu.de) wrote:
> is there an easy way to identify all security-related patches out of the
> mass of patches floating around on linux.bkbits.net or the kernel bugzilla?
No, there's not. It's not as simple as it seems. Your best bet is
monitoring vendor updates, as they have the same goal. Occasionaly
things get applied with a CVE candidate number (CAN-YYYY-NNNN), and
those are security relevant.
thanks,
-chris
--
Linux Security Modules http://lsm.immunix.org http://lsm.bkbits.net
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Identify security-related patches
2004-09-02 18:48 ` Chris Wright
@ 2004-09-02 19:12 ` Valdis.Kletnieks
0 siblings, 0 replies; 4+ messages in thread
From: Valdis.Kletnieks @ 2004-09-02 19:12 UTC (permalink / raw)
To: Chris Wright; +Cc: Frank Steiner, Kernel Mailing List
[-- Attachment #1: Type: text/plain, Size: 693 bytes --]
On Thu, 02 Sep 2004 11:48:07 PDT, Chris Wright said:
> * Frank Steiner (fsteiner-mail@bio.ifi.lmu.de) wrote:
> > is there an easy way to identify all security-related patches out of the
> > mass of patches floating around on linux.bkbits.net or the kernel bugzilla?
>
> No, there's not. It's not as simple as it seems. Your best bet is
> monitoring vendor updates, as they have the same goal. Occasionaly
> things get applied with a CVE candidate number (CAN-YYYY-NNNN), and
> those are security relevant.
Another point to remember is that there are probably many times that we've
fixed something because it's a bug, and only later find out that it's a bug
with security implications...
[-- Attachment #2: Type: application/pgp-signature, Size: 226 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Identify security-related patches
2004-09-02 7:08 Identify security-related patches Frank Steiner
2004-09-02 18:48 ` Chris Wright
@ 2004-09-02 20:22 ` Florian Weimer
1 sibling, 0 replies; 4+ messages in thread
From: Florian Weimer @ 2004-09-02 20:22 UTC (permalink / raw)
To: Frank Steiner; +Cc: Kernel Mailing List
* Frank Steiner:
> is there an easy way to identify all security-related patches out of the
> mass of patches floating around on linux.bkbits.net or the kernel bugzilla?
>
> I'm running 2.6.8.1 and would like to keep it as stable as possible, thus,
> only apply security patches. Currently I'm searching for "security" and
> alike on bitkeeper, but there seems to be no consistent marking.
No, there isn't. You won't see any official kernel.org advisories
that could serve as guide, either.
However, your concentration might be a bit short-sighted. Issues such
as stability (random crashes under load), data corruption (file
systems are corrupted on unmount) and performance (poor throughtput
with some USB devices) could be as important to your users as security
fixes. In this area, vendor kernels can serve as a guide, too.
Unfortunately, there is no distributed source code management system
used by all these forks, so relating all those changes appears to be
quite complicated.
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2004-09-03 3:37 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2004-09-02 7:08 Identify security-related patches Frank Steiner
2004-09-02 18:48 ` Chris Wright
2004-09-02 19:12 ` Valdis.Kletnieks
2004-09-02 20:22 ` Florian Weimer
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®