From owner-freebsd-security@FreeBSD.ORG Mon Apr 14 08:20:41 2014 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 5AA42218 for ; Mon, 14 Apr 2014 08:20:41 +0000 (UTC) Received: from mail.as41113.net (mail.as41113.net [91.208.177.22]) by mx1.freebsd.org (Postfix) with ESMTP id 1DC6111F4 for ; Mon, 14 Apr 2014 08:20:40 +0000 (UTC) Received: from [172.21.87.41] (195.98.9.212.in-addr.arpa [212.9.98.195]) (using TLSv1 with cipher ECDHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: lists@rewt.org.uk) by mail.as41113.net (Postfix) with ESMTPSA id 3g6jSd2lPnz7rBX; Mon, 14 Apr 2014 08:20:33 +0000 (UTC) Message-ID: <534B9A4D.5070404@rewt.org.uk> Date: Mon, 14 Apr 2014 09:20:29 +0100 From: Joe Holden User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.4.0 MIME-Version: 1.0 To: =?UTF-8?B?RGFnLUVybGluZyBTbcO4cmdyYXY=?= Subject: Re: Proposal References: <9eeba1ab-2ab0-4188-82aa-686c5573a5db@me.com> <8D81F198-36A7-47F4-B486-DA059910A6B4@spam.lifeforms.nl> <867g6y1kfe.fsf@nine.des.no> <86d2gqz2he.fsf@nine.des.no> <5345C98D.7030907@rewt.org.uk> <86bnw95um7.fsf@nine.des.no> In-Reply-To: <86bnw95um7.fsf@nine.des.no> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit Cc: freebsd-security@freebsd.org X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.17 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 14 Apr 2014 08:20:41 -0000 On 10/04/2014 11:47, Dag-Erling Smørgrav wrote: > Joe Holden writes: >> IME issues like this need to be patched first, tested later [...] > > If we'd done that and screwed up, you'd be on the barricades demanding > our heads. > > DES > Given the nature of the patch, and it being experimental (but still probably not as bad as leaving it unpatched) that wouldn't be the case, to be fair.