Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 15 May 2019 23:23:39 -0400
From:      Matt Garber <matt.garber@gmail.com>
To:        Bill Sorenson <instructionset@gmail.com>
Cc:        "Julian H. Stacey" <jhs@berklix.com>, Mel Pilgrim <list_freebsd@bluerosetech.com>, core@freebsd.org,  hackers@freebsd.org, stable@freebsd.org
Subject:   Re: FreeBSD flood of 8 breakage announcements in 3 mins.
Message-ID:  <CANwXMPM08L_907O6he8g9UCV4Pf3QyCLEbeVF8YPN6sFocKajQ@mail.gmail.com>
In-Reply-To: <CACcTwYn1PegBWYY9wQ_h9Nh4vV7PXu949yiSB_PkO3BpV0ZrUA@mail.gmail.com>
References:  <201905151425.x4FEPNqk065975@fire.js.berklix.net> <e8125e97-6308-5ad0-b850-6825069683d4@bluerosetech.com> <CACcTwYkr55Vxx-jk7uyhppT0LBxfKYDEzTxmhJLL-Se7EJVAew@mail.gmail.com> <CANwXMPMyi96hFx-joD-ReZGYWO_P5KcRZnBu2C2j9QfJ-g1t_A@mail.gmail.com> <CACcTwYn1PegBWYY9wQ_h9Nh4vV7PXu949yiSB_PkO3BpV0ZrUA@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, May 15, 2019 at 11:15 PM Bill Sorenson <instructionset@gmail.com>
wrote:

> > I=E2=80=99m not sure what you meant about Linux distros not categorizin=
g fixes,
> though =E2=80=94 with some notable exceptions, most of the big ones certa=
inly tag
> security fixes >separately, which is what allows `unattended-upgrades` on
> Debian/Ubuntu based systems (and `yum-cron` on RHEL) to work so nicely
> automatically as scheduled on > *only* security errata, while leaving all
> other types of updates alone for admin intervention.
>
> My comment about Linux was not in regards to any particular distro, they
> all
> have interesting policies of varying effectiveness when it comes to relea=
se
> engineering, but specifically about the Linux kernel team (Torvalds Et al=
,)
> which last I checked had a policy of specifically not handling security
> issues
> any different from any generic bug. Distros may do their own kernel relea=
se
> engineering and handling that themselves which is fine.


Understood, yep, that historical stance in the kernel itself has really
sucked and does no one any favors with =E2=80=98everything is just a bug.=
=E2=80=99
Thankfully the kernel self-protection project has made some significant
strides in that area, even if the overall security attitude of maintainers
has been slower to positive change than would be ideal.


=E2=80=94
Matt



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CANwXMPM08L_907O6he8g9UCV4Pf3QyCLEbeVF8YPN6sFocKajQ>