[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [Xen-devel] Security support for debug=y builds (Was Re: Xen Security Advisory 37 (CVE-2013-0154) - Hypervisor crash due to incorrect ASSERT (debug build only))
>>> On 07.01.13 at 11:21, Ian Campbell <ijc@xxxxxxx> wrote: > Options which I can think of are: > > * debug=y bugs are Just Bugs and not security issues. i.e. they > are discussed and fixed publicly on xen-devel and the fix is > checked in in the usual way. There is no embargo or specific > announcement. changelog may or may not refer to the security > implications if debug=y is enabled. +1 > * debug=y bugs are security issues regardless, they are treated > like any other security issue, i.e. following the process[0]. -1 > * debug=y bugs are somewhere in the middle. (perhaps no embargo, > less formal announcement etc etc) +/-0 Jan _______________________________________________ Xen-devel mailing list Xen-devel@xxxxxxxxxxxxx http://lists.xen.org/xen-devel
|
Lists.xenproject.org is hosted with RackSpace, monitoring our |