Gentoo Archives: gentoo-kernel

From: Strake <strake888@×××××.com>
To: gentoo-kernel@l.g.o
Subject: Re: [gentoo-kernel] More manpower needed for Gentoo Kernel Security project
Date: Mon, 21 May 2007 13:27:14
Message-Id: ab87a3bf0705210625t13f2bc60k3e813208664175ff@mail.gmail.com
In Reply to: [gentoo-kernel] More manpower needed for Gentoo Kernel Security project by Daniel Drake
1 I can help
2
3 On 5/20/07, Daniel Drake <dsd@g.o > wrote:
4 >
5 > Anyone interested in contributing the Gentoo kernel security project?
6 >
7 > Basic roles here are to handle vulnerabilities (both minor and major) in
8 > the kernel. The issues come in from databases such as cve.mitre.org,
9 > usually with patches, and you have to coordinate those patches flowing
10 > into the portage tree.
11 >
12 > The usual process is to have a bug on the Gentoo bugzilla per security
13 > report. Initially you get me to include the patch in genpatches, then
14 > you CC maintainers of all other affected kernels and pester them until
15 > they have fixed their kernel, either by including the newer genpatches
16 > or by adding the patch individually.
17 >
18 > This isn't a terribly interesting task, but is important and we're
19 > behind on issue tracking here. The thing that will make it interesting
20 > is that after getting a grasp of how the system works, we are looking
21 > for someone to develop software to help us track the security bugs and
22 > help communicate that info to users (who typically want to know when a
23 > new kernel fixes a security issue, so that they can upgrade). This
24 > software would probably be web-based.
25 >
26 > Anyone interested?
27 >
28 > http://www.gentoo.org/proj/en/security/kernel.xml
29 >
30 > Thanks,
31 > Daniel
32 > --
33 > gentoo-kernel@g.o mailing list
34 >
35 >
36
37
38 --
39 Registered Linux User #392061
40 counter.li.org
41 --------
42 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0
43 --------
44 Roses are Red
45 Violets are Blue
46 In Soviet Russia
47 Poem Writes YOU!