[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] Difference between patch in XSA and patch checked in

>>> On 24.08.17 at 12:17, <george.dunlap@xxxxxxxxxx> wrote:
> On 08/24/2017 08:29 AM, Jan Beulich wrote:
>> It is largely the adding of
>> CVE numbers and tags to the patch which has turned out easier to
>> do in a private copy of the patches (so they're ready to be applied
>> without having to wait for / pull updates to xsa.git, the more that
>> in less simple cases - which iirc XSA-218 was an example of - the
>> automatic propagation of tags into the patches at public disclosure
>> time doesn't always work [reliably]).
> Is there a "timeliness" issue for checking patches into the tree?

Well, I've been striving to commit patches pretty quickly after
advisories went public.


Xen-devel mailing list



Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.