[Ksummit-discuss] [MAINTAINERS SUMMIT] Handling of embargoed security issues

Jiri Kosina jikos at kernel.org
Sat Sep 8 19:26:55 UTC 2018


On Sat, 8 Sep 2018, James Bottomley wrote:

> I think we might benefit from a discussion of whether we could have
> handled Meltdown/Spectre better in an NDA framework ... 

Well, at the end of the day, we actually did handle it in the NDA 
framework (otherwise the end result wrt. stable and distros really 
wouldn't look like it did by the release date), but everything else 
(timing, information sharing, feedback channels to the "owners", ...) 
didn't really work all that well.

--
Jiri Kosina
SUSE Labs



More information about the Ksummit-discuss mailing list