[Ksummit-discuss] [MAINTAINERS SUMMIT] Handling of embargoed security issues

Jiri Kosina jikos at kernel.org
Fri Sep 7 13:30:32 UTC 2018


On Thu, 6 Sep 2018, Eduardo Valentin wrote:

> Should we add maybe a point here to discuss which kernels are to be 
> considered for patching in these cases? All the stable branches? Only 
> mainline? Obviously, either extreme cases can hurt people. Patching 
> older kernels requires insane amount of work and patching only mainline 
> leaves distros on limbo.

That'd be mostly question for the stable guys I guess. I am not sure how 
often did they in the past have to say "sorry, the backport is horribly 
complex, so we are not backporting the fix and we're keeping the bug 
unfixed".

Greg, is this something that actually has been happening for real in the 
past? Or would that absolutely break the expectations that stable tree 
consumers have?

Thanks,

-- 
Jiri Kosina
SUSE Labs



More information about the Ksummit-discuss mailing list