[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] Security support for debug=y builds (Was Re: Xen Security Advisory 37 (CVE-2013-0154) - Hypervisor crash due to incorrect ASSERT (debug build only))


  • To: Andrew Cooper <Andrew.Cooper3@xxxxxxxxxx>
  • From: James Bulpin <James.Bulpin@xxxxxxxxxxxxx>
  • Date: Mon, 7 Jan 2013 12:58:40 +0000
  • Accept-language: en-US
  • Acceptlanguage: en-US
  • Cc: xen-users <xen-users@xxxxxxxxxxxxx>, "xen-devel@xxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxx>
  • Delivery-date: Mon, 07 Jan 2013 12:58:31 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xen.org>
  • Thread-index: Ac3szRgIol0R9fZDT1KRzMm+P9mpZwACUlrw
  • Thread-topic: [Xen-devel] Security support for debug=y builds (Was Re: Xen Security Advisory 37 (CVE-2013-0154) - Hypervisor crash due to incorrect ASSERT (debug build only))

On Mon, 2013-01-07 at 11:21 +0000, Andrew Cooper wrote:
> On 07/01/13 11:08, Keir Fraser wrote:
> > On 07/01/2013 10:21, "Ian Campbell"<ijc@xxxxxxx>  wrote:
> >>        * debug=y bugs are Just Bugs and not security issues. i.e. they
> >>          are discussed and fixed publicly on xen-devel and the fix is
> >>          checked in in the usual way. There is no embargo or specific
> >>          announcement. changelog may or may not refer to the security
> >>          implications if debug=y is enabled.
> > This is my preference. I consider debug builds to be developer builds, and
> > wouldn't expect to see them used in production environments. We set debug=n
> > by default in our stable branches for that reason.
> >
> >   -- Keir
>
> I second this opinion.  Production environments should not be running
> development builds.

+1 but I'd still like to see such issues backported to stable branches.

Cheers,
James


_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxx
http://lists.xen.org/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.