From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CEE1B15AD7 for ; Tue, 15 Aug 2023 22:17:39 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 9DC53C433C8; Tue, 15 Aug 2023 22:17:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1692137859; bh=v7rA4VRko6Q8PUn/6yx1WKGOmiBAZz/YLPNwUjwNxQU=; h=Date:From:To:cc:Subject:In-Reply-To:References:From; b=BnaFTsJdxZyOQctrjhv+ZyGoI0SPqu+ipG0dRZ9Jw5v8Zsy/k0Q+dS9uAZ84el/z7 piyz9ZmNbbbB71xY5d28oOOO4lfhwXioN1erwrn36QTzj4chhOVB55Y7KzXJfFqHB6 qxgd3+PRzmbDq5JfiPlpcWzrBpTy/ft9cdA/l9c9pAK3ZH+hDCpRc1iC88OmvhnITy 32bZWE9Xd/XfM1ObrAgVUqGlrm8MOov3mMu9NcKJ/DE2T2xgDG230kVEa3yr63qFSg 8LoR5n77D7uf+owqicF8Y8PQsbZ8Yrl4X/lQu2kIEf9QCPSUz50A0BjAgiFhN2x7nz bXhux89PkJBwQ== Date: Wed, 16 Aug 2023 00:17:36 +0200 (CEST) From: Jiri Kosina To: Greg KH cc: Steven Rostedt , Vegard Nossum , ksummit@lists.linux.dev Subject: Re: [MAINTAINERS SUMMIT] Handling of embargoed security issues -- security@korg vs. linux-distros@ In-Reply-To: <2023081540-vindicate-caterer-33c6@gregkh> Message-ID: References: <658e739b-c164-c360-d6a3-eb4fb15ae02e@oracle.com> <2023081515-lake-spotty-6a3a@gregkh> <20230815084253.7091083e@gandalf.local.home> <2023081540-vindicate-caterer-33c6@gregkh> User-Agent: Alpine 2.21 (LSU 202 2017-01-01) Precedence: bulk X-Mailing-List: ksummit@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII On Tue, 15 Aug 2023, Greg KH wrote: > Why are they not just doing what the huge majority of Linux users doing > and taking the "feed of known issues that resolve problems before they > are public knowledge" that we provide today for free to them? Because > they somehow think that knowing a specific single bugfix is more special > than all of those other bugfixes, which honestly, is just loony. If you'd like me to turn this proposal into "What can we do to make sure that most major distros are eventually basing their kernels on -stable" discussion, I'd be happy to do that, but I believe this has been discussed quite extensively already. Thanks, -- Jiri Kosina SUSE Labs