Gentoo Archives: gentoo-dev

From: Tom Wijsman <TomWij@g.o>
To: gentoo-dev@l.g.o
Cc: pinkbyte@g.o
Subject: Re: [gentoo-dev] rfc: stabilization policies
Date: Wed, 21 Aug 2013 12:37:12
Message-Id: 20130821143655.04703d91@TOMWIJ-GENTOO
In Reply to: Re: [gentoo-dev] rfc: stabilization policies by Sergey Popov
1 On Wed, 21 Aug 2013 16:22:28 +0400
2 Sergey Popov <pinkbyte@g.o> wrote:
3
4 > 21.08.2013 14:29, Tom Wijsman пишет:
5 > > On Wed, 21 Aug 2013 13:42:56 +0400
6 > > You do draw assumptions, because you don't take a look; please do:
7 > >
8 > > https://bugs.gentoo.org/buglist.cgi?quicksearch=assignee%3Asecurity%40gentoo.org%20CC%3Akernel%40gentoo.org
9 > >
10 > > Sort by "Changed" such that the newest appear on top.
11 > >
12 >
13 > And how should i must knew that these bugs related to particular
14 > versions if they do not contain affected versions(i know that ALL
15 > versions may be affected in particular time, but we are talking about
16 > new stable kernel which bring fixes) and no dependant bugs in stable
17 > request? How can i, not beeing member of Gentoo Kernel Team, discover
18 > that it is security stabilization and which security bugs, registered
19 > in our bugzilla, will gone when i will upgrad to it?
20
21 Our dev 'ago' is on top of all that, but we really shouldn't rely on a
22 single person; the lack of manpower causes uncertainty here, and it is
23 because of that that we have to regard any stabilization as security.
24
25 Given the kernel volume, I think even CVE's don't cover everything...
26
27 > Honestly, we should revive Kernel Security subproject somehow, cause
28 > this mess may confuse even ordinary developers.
29
30 +1 The latest kernel related discussion(s) also make it clear there is
31 a need for more documentation on how things currently work; because
32 people that are not aware what happens upstream are making assumptions
33 that don't reflect reality, and this makes it harder to reach consensus.
34
35 With the hope of one or two people wanting to help out on genpatches
36 (although I haven't heard from them lately); I'll try to document
37 upstream's release cycle as well as how our current maintenance is
38 done as part of the move to Gentoo Wiki, together with the rest we
39 could then also clarify some kernel team policies and guidelines...
40
41 --
42 With kind regards,
43
44 Tom Wijsman (TomWij)
45 Gentoo Developer
46
47 E-mail address : TomWij@g.o
48 GPG Public Key : 6D34E57D
49 GPG Fingerprint : C165 AF18 AB4C 400B C3D2 ABF0 95B2 1FCD 6D34 E57D

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-dev] rfc: stabilization policies Ian Stakenvicius <axs@g.o>