[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [Xen-devel] Security support for debug=y builds (Was Re: Xen Security Advisory 37 (CVE-2013-0154) - Hypervisor crash due to incorrect ASSERT (debug build only))
On 07/01/2013 12:58, "James Bulpin" <James.Bulpin@xxxxxxxxxxxxx> wrote: > On Mon, 2013-01-07 at 11:21 +0000, Andrew Cooper wrote: >> On 07/01/13 11:08, Keir Fraser wrote: >>> On 07/01/2013 10:21, "Ian Campbell"<ijc@xxxxxxx> wrote: >>>> * debug=y bugs are Just Bugs and not security issues. i.e. they >>>> are discussed and fixed publicly on xen-devel and the fix is >>>> checked in in the usual way. There is no embargo or specific >>>> announcement. changelog may or may not refer to the security >>>> implications if debug=y is enabled. >>> This is my preference. I consider debug builds to be developer builds, and >>> wouldn't expect to see them used in production environments. We set debug=n >>> by default in our stable branches for that reason. >>> >>> -- Keir >> >> I second this opinion. Production environments should not be running >> development builds. > > +1 but I'd still like to see such issues backported to stable branches. Yes, this already happens and will not change. -- Keir > Cheers, > James > > > _______________________________________________ > Xen-devel mailing list > Xen-devel@xxxxxxxxxxxxx > http://lists.xen.org/xen-devel _______________________________________________ Xen-devel mailing list Xen-devel@xxxxxxxxxxxxx http://lists.xen.org/xen-devel
|
Lists.xenproject.org is hosted with RackSpace, monitoring our |