Gentoo Archives: gentoo-kernel

From: Greg KH <gregkh@g.o>
To: gentoo-kernel@l.g.o
Subject: Re: [gentoo-kernel] Gentoo Kernel Security Policy (DRAFT)
Date: Thu, 16 Mar 2006 00:43:57
Message-Id: 20060316004318.GA15855@kroah.com
In Reply to: [gentoo-kernel] Gentoo Kernel Security Policy (DRAFT) by John Mylchreest
1 On Wed, Mar 15, 2006 at 11:31:01PM +0000, John Mylchreest wrote:
2 > 3. Genpatches-Base Support
3 >
4 > For as long as there is a kernel package in the tree using genpatches,
5 > the corresponding genpatches-base will be maintained from a security
6 > point of view. Announcements for each update follow the normal
7 > procedure, however there is a caveat. Kernel sources which use
8 > genpatches should not lapse more than 2 minor releases from upstream.
9 > IE: kernel sources should not fall behind 2.6.14 if the most recent
10 > upstream release is 2.6.16. In the extreme case where this is not
11 > technically possible, this will require it being addressed on a
12 > case-by-case basis, and a sectag penalty of 10 applied if appropriate.
13
14 Wow, we are commiting to support 2 kernel versions back? Since when?
15 That's going to be a major effort that no one has signed up to do (even
16 kernel.org doesn't offer that...) Do we _really_ want to say we are
17 going to do this?
18
19 If so, we're already behind with all of the recent 2.6.15 security fixes
20 not being backported to 2.6.14 :)
21
22 thanks,
23
24 greg k-h
25 --
26 gentoo-kernel@g.o mailing list

Replies

Subject Author
Re: [gentoo-kernel] Gentoo Kernel Security Policy (DRAFT) Tim Yamin <plasmaroo@g.o>