From owner-cvs-all Fri Jan 17 15:56: 6 2003 Delivered-To: cvs-all@freebsd.org Received: by hub.freebsd.org (Postfix, from userid 931) id 84E7A37B401; Fri, 17 Jan 2003 15:56:05 -0800 (PST) Date: Fri, 17 Jan 2003 15:56:05 -0800 From: Juli Mallett To: "Bruce A. Mah" Cc: Alfred Perlstein , Gregory Sutter , Nate Lawson , Martin Blapp , cvs-all@FreeBSD.org, cvs-committers@FreeBSD.org Subject: Re: cvs commit: src/usr.sbin/mountd mountd.c src/usr.sbin/rpc.lockd lockd.c src/usr.sbin/rpc.statd statd.c src/usr.sbin/rpc.yppasswdd yppasswdd_main.c src/usr.sbin/rpcbind rpcb_svc_com Message-ID: <20030117155605.A4640@FreeBSD.org> References: <20030116185752.L98919@levais.imp.ch> <20030116185115.GQ33821@elvis.mu.org> <20030117215606.GA29071@klapaucius.zer0.org> <20030117140254.A96500@FreeBSD.org> <20030117220937.GV2964@klapaucius.zer0.org> <20030117221141.GT33821@elvis.mu.org> <200301172248.h0HMmrkC092859@intruder.bmah.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5.1i In-Reply-To: <200301172248.h0HMmrkC092859@intruder.bmah.org>; from bmah@FreeBSD.org on Fri, Jan 17, 2003 at 02:48:53PM -0800 Organisation: The FreeBSD Project X-Alternate-Addresses: , , , , X-Towel: Yes X-LiveJournal: flata, jmallett X-Negacore: Yes Sender: owner-cvs-all@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG * De: "Bruce A. Mah" [ Data: 2003-01-17 ] [ Subjecte: Re: cvs commit: src/usr.sbin/mountd mountd.c src/usr.sbin/rpc.lockd lockd.c src/usr.sbin/rpc.statd statd.c src/usr.sbin/rpc.yppasswdd yppasswdd_main.c src/usr.sbin/rpcbind rpcb_svc_ > If memory serves me right, Alfred Perlstein wrote: > > * Gregory Sutter [030117 14:09] wrote: > > > > > > Ah, right. An immediate message to developers and later forced > > > commit. Somehow I misread that the first time such that both the > > > message and the forced commit would come only after the public > > > release of security information. Sorry. > > > > > > What do you think of codifying the situation in the Committer's Guide? > > > > I think it's a great idea, when will you be done? :) > > It sounds to me like you (pl.) are advocating early disclosure of > security vulnerability information to a set of several hundred people, > at a time when generally, only a handful of people have need-to-know. > > (In case it's not clear, this idea scares me greatly.) We just need to know that there *is* a security-related aspect to what has been committed, and that we should await further info. -- Juli Mallett AIM: BSDFlata -- IRC: juli on EFnet. OpenDarwin, Mono, FreeBSD Developer. ircd-hybrid Developer, EFnet addict. FreeBSD on MIPS-Anything on FreeBSD. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe cvs-all" in the body of the message