ksummit.lists.linux.dev archive mirror
 help / color / mirror / Atom feed
* [MAINTAINERS SUMMIT] Quality standards for embargoed code
@ 2023-08-15 16:58 Sasha Levin
  2023-08-15 17:18 ` Mark Brown
  2023-08-15 17:19 ` Dave Hansen
  0 siblings, 2 replies; 10+ messages in thread
From: Sasha Levin @ 2023-08-15 16:58 UTC (permalink / raw)
  To: ksummit

Hi folks,

I'd like to have a discussion about how the community handles code drops
to address embargoed security issues: my concern is that we sidestap our
regular development workflow (post patches, review, test, bots, etc...)
that gives us a good quality baseline, and end up taking largely
untested code that causes pain.

In my opinion, there's no benefit in promptly releasing kernels
containing fixes for such issues if these kernels are not usable by
(some) users.

Hardware issues are here to stay, we see an increase in embargoed
security issues, but we're still treating them as one-offs. We should
start to adapt our workflows to these, and a good starting point (IMO)
is assuring/improving the quality of what goes through the pipeline.

Some of the initial thoughts I had around these:

1. Ask (require) organizations that repeatedly go through this mechanism
to create a test environment that can demonstrate how the embargoed code
passes different build/validation tests. We should set a minimal bar to
the demonstrated quality of code that we'll "sneak" behind the backs of
community members.

2. Create a group of trusted "testers" who can test embargoed code with
different (ideally "real") workloads and environments. I think that
we're overly focused on keeping the circle of people in the know small.

3. Work with KernelCI/OpenSSF on setting up a (small) environment
similar to the public one that we could run embargoed code through.

-- 
Thanks,
Sasha

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2023-08-15 21:11 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2023-08-15 16:58 [MAINTAINERS SUMMIT] Quality standards for embargoed code Sasha Levin
2023-08-15 17:18 ` Mark Brown
2023-08-15 18:10   ` Sasha Levin
2023-08-15 18:40     ` Mark Brown
2023-08-15 17:19 ` Dave Hansen
2023-08-15 18:19   ` Sasha Levin
2023-08-15 18:34     ` Dave Hansen
2023-08-15 19:57       ` Greg KH
2023-08-15 20:47         ` Mark Brown
2023-08-15 21:11           ` Greg KH

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox