From: Greg KH <greg@kroah.com>
To: James Bottomley <James.Bottomley@HansenPartnership.com>
Cc: Mauro Carvalho Chehab <mchehab+samsung@kernel.org>,
ksummit-discuss@lists.linuxfoundation.org
Subject: Re: [Ksummit-discuss] [MAINTAINERS SUMMIT] Handling of embargoed security issues
Date: Sun, 9 Sep 2018 14:51:30 +0200 [thread overview]
Message-ID: <20180909125130.GA16474@kroah.com> (raw)
In-Reply-To: <1536422066.22308.3.camel@HansenPartnership.com>
On Sat, Sep 08, 2018 at 08:54:26AM -0700, James Bottomley wrote:
> On Sat, 2018-09-08 at 17:32 +0200, Greg KH wrote:
> > On Sat, Sep 08, 2018 at 08:00:29AM -0700, James Bottomley wrote:
> > > On Sat, 2018-09-08 at 13:34 +0200, Greg KH wrote:
> > > > On Sat, Sep 08, 2018 at 08:21:41AM -0300, Mauro Carvalho Chehab
> > > > wrote:
> > > > > IMHO, the best would be to have a formal/legal way to handle
> > > > > it.
> > > >
> > > > No, sorry, some of us are not allowed legally to sign NDAs for
> > > > stuff like this.
> > >
> > > As a blanket statement this simply isn't true.
> >
> > Um, I said "some of us". Some of us can, some of us can not. That's
> > a blanket statement that has to be true :)
>
> OK, let me make it more specific: there exists no individual
> contributing to open source in a leadership capacity for whom a
> signable NDA cannot be crafted.
"can be crafted eventually" :)
There are language issues, corporate issues, and lots and lots of other
issues involved here, you know this. Look at Mauro's situation for one
example.
Anyway, if the main goal here is to somehow have the LF provide some
sort of situation where we can invoke the old "3-way" NDA process to
handle security issues, then fine, let's propose that and see if the LF
wishes to do this.
But remember, this is only needed for the "crazy" issues, like Meltdown.
What we put together add-hoc for L1TF worked well, and what we do every
week in handling security issues sent to security@k.org works very well
also. So well that no one really realizes what we do there :)
So again, if this is something that people strongly feel the LF should
handle, let the TAB know and they will be glad to work on it.
thanks,
greg k-h
next prev parent reply other threads:[~2018-09-09 12:51 UTC|newest]
Thread overview: 54+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-09-06 19:18 Jiri Kosina
2018-09-06 20:56 ` Linus Torvalds
2018-09-06 21:14 ` Jiri Kosina
2018-09-06 22:51 ` Eduardo Valentin
2018-09-07 9:17 ` Jani Nikula
2018-09-07 14:43 ` David Woodhouse
2018-09-06 22:55 ` Eduardo Valentin
2018-09-07 8:21 ` Geert Uytterhoeven
2018-09-10 23:26 ` Eduardo Valentin
2018-09-11 8:45 ` Greg KH
2018-09-11 17:10 ` Dave Hansen
2018-09-11 18:28 ` Greg KH
2018-09-11 18:44 ` Thomas Gleixner
2018-09-07 13:30 ` Jiri Kosina
2018-09-09 12:55 ` Greg KH
2018-09-09 19:48 ` Jiri Kosina
2018-09-10 4:04 ` Eduardo Valentin
2018-09-12 7:03 ` Greg KH
2018-09-10 4:12 ` Eduardo Valentin
2018-09-10 11:10 ` Mark Brown
2018-09-12 4:22 ` Balbir Singh
2018-09-08 4:21 ` Andy Lutomirski
2018-09-08 8:56 ` Thomas Gleixner
2018-09-08 11:21 ` Mauro Carvalho Chehab
2018-09-08 11:34 ` Greg KH
2018-09-08 14:20 ` Andy Lutomirski
2018-09-08 15:29 ` Greg KH
2018-09-08 15:00 ` James Bottomley
2018-09-08 15:32 ` Greg KH
2018-09-08 15:54 ` James Bottomley
2018-09-08 19:49 ` Linus Torvalds
2018-09-08 21:24 ` James Bottomley
2018-09-08 22:33 ` Andy Lutomirski
2018-09-09 12:18 ` Mauro Carvalho Chehab
2018-09-10 22:59 ` Dave Hansen
2018-09-11 8:48 ` Greg KH
2018-09-09 12:51 ` Greg KH [this message]
2018-09-09 14:20 ` Linus Torvalds
2018-09-09 14:38 ` James Bottomley
2018-09-09 14:51 ` Andy Lutomirski
2018-09-09 17:20 ` Theodore Y. Ts'o
2018-09-09 17:48 ` David Woodhouse
2018-09-09 18:17 ` Andy Lutomirski
2018-09-09 18:56 ` Theodore Y. Ts'o
2018-09-09 19:19 ` Andy Lutomirski
2018-09-09 20:20 ` Jiri Kosina
2018-09-09 21:36 ` James Bottomley
2018-09-10 9:25 ` Thomas Gleixner
2018-09-10 14:40 ` James Bottomley
2018-09-11 8:20 ` Jiri Kosina
2018-09-11 9:03 ` Thomas Gleixner
2018-09-09 19:41 ` Jiri Kosina
2018-09-08 19:26 ` Jiri Kosina
2018-09-08 19:47 ` James Bottomley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20180909125130.GA16474@kroah.com \
--to=greg@kroah.com \
--cc=James.Bottomley@HansenPartnership.com \
--cc=ksummit-discuss@lists.linuxfoundation.org \
--cc=mchehab+samsung@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox