[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] Design session report: Xen on Distros


  • To: George Dunlap <George.Dunlap@xxxxxxxxxx>
  • From: Jan Beulich <JBeulich@xxxxxxxx>
  • Date: Wed, 17 Jul 2019 12:37:13 +0000
  • Accept-language: en-US
  • Arc-authentication-results: i=1; mx.microsoft.com 1;spf=pass smtp.mailfrom=suse.com;dmarc=pass action=none header.from=suse.com;dkim=pass header.d=suse.com;arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=2T2Tvw1o3ECpGv75JCNAJ9Ov6rBakQcKQ5cD0U/drNY=; b=NzvVyciVAxrgCgfIri/n4mvirvHgh+V14aDeEtS6KF8If6Kzl0V5J6VFbYluJ61WSK8o/ZkiPVWzFYE/PiQRTSSUsF/Jit0B7wIcCrQ8LbmkusId0rBnhfPYDByOy77cF81sL0pZ+OTHPbPvX/QqSIbbUnqfF6RhpFqY3od2kq75aCUoOFtQ8WDgZhjwudgX3c0IRi2dRcjv5wAGR4XYMZW8Syns9fh+aCN3Ni0aFrj4xFOKEEItOMeE6ni75ZIExDbWU9NhnQOo9ZGNV5T9bjiZ+q/zOiW+OqfshQB3dUqwtWdYMOFkoLwiajkz23hL244ZAx1zGMnPwcnS3WTVKQ==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=kwmLAXYB2z1ATW84Hq/nI7dBw9NkRRnQlLVQgYPTwTYhg5BXr3aXsUypQlOpyxflLysrB/2nn2TW73XHvA/Je8ZAeK5XBF8UY1xZpP9dQ250pnnrqBXquAKlvDyEgJQe3tpjzzzeK9DwQe8EcrZdcnr3uVliVE6iJkSAWwIQKa8b2OnKwBSBQRxrWrcptn/pZHxYWLZnenhE3TFDItY/3AyYjyb2TLlE1QRxFfRzFz8ph7tJ29Iiq/+MK+al0Tm/2cqdmWHqYyKVjlxu+6m1SqbiBhBDayt/TmAG9PHCY2A0h/OHhIXMtsm1oxGYWkRqsf2wlxv9iEdJ6KSh7P11Jg==
  • Authentication-results: spf=none (sender IP is ) smtp.mailfrom=JBeulich@xxxxxxxx;
  • Cc: Andrew Cooper <Andrew.Cooper3@xxxxxxxxxx>, xen-devel <xen-devel@xxxxxxxxxxxxxxxxxxxx>, Amit Shah <amit@xxxxxxxxxxxxx>
  • Delivery-date: Wed, 17 Jul 2019 12:38:21 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>
  • Thread-index: AQHVOxdKPvpxo6u4BUiqE8VCaQqJKabLmgAAgAAWKoD///HygIAAMmeAgAHYRQCAANGKAIAARDMA
  • Thread-topic: [Xen-devel] Design session report: Xen on Distros

On 17.07.2019 12:33, George Dunlap wrote:
> 
>> On Jul 16, 2019, at 11:03 PM, Andrew Cooper
>>
>> We could trivially throw the fixes into the branch, tag it, sign it and
>> throw it out into the open, but doing that on the embargo date itself
>> would result in an official release of Xen which has had 0 testing in
>> the incumbent test system.
> 
> The point is that anyone who ships / deploys a fix on the disclosure date
> is pretty much shipping exactly that.  If it’s not good enough to sign,
> why is it good enough to deploy?

I think the security fixes themselves are good enough to deploy, perhaps
with the assumption that consumers of our pre-disclosure list have done
some testing on their own. The stable trees, however, contain more than
just security fixes, and can have regressions (most likely due to
backporting mistakes).

Jan
_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxxx
https://lists.xenproject.org/mailman/listinfo/xen-devel

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.