Re: [Xen-devel] Xen Project Security Process Whitepaper v1 is ready for community review

2018-07-02 Thread Lars Kurth
> On 28 Jun 2018, at 02:57, Lars Kurth wrote: > > > On 27/06/2018, 22:47, "Steven Haigh" wrote: > >On Wednesday, 27 June 2018 7:19:58 PM AEST Jan Beulich wrote: > On 27.06.18 at 06:05, wrote: >>> Right now, we're at a stage where we could probably justify a new release >>> of 4.6,

Re: [Xen-devel] Xen Project Security Process Whitepaper v1 is ready for community review

2018-06-27 Thread Lars Kurth
On 27/06/2018, 22:47, "Steven Haigh" wrote: On Wednesday, 27 June 2018 7:19:58 PM AEST Jan Beulich wrote: > >>> On 27.06.18 at 06:05, wrote: > > Right now, we're at a stage where we could probably justify a new release > > of 4.6, 4.7, 4.8, 4.9, and 4.10 due to the depth of XS

Re: [Xen-devel] Xen Project Security Process Whitepaper v1 is ready for community review

2018-06-27 Thread Steven Haigh
On Wednesday, 27 June 2018 7:19:58 PM AEST Jan Beulich wrote: > >>> On 27.06.18 at 06:05, wrote: > > Right now, we're at a stage where we could probably justify a new release > > of 4.6, 4.7, 4.8, 4.9, and 4.10 due to the depth of XSAs contained within > > that can't be patched on top of the relea

Re: [Xen-devel] Xen Project Security Process Whitepaper v1 is ready for community review

2018-06-27 Thread Jan Beulich
>>> On 27.06.18 at 06:05, wrote: > Right now, we're at a stage where we could probably justify a new release of > 4.6, 4.7, 4.8, 4.9, and 4.10 due to the depth of XSAs contained within that > can't be patched on top of the release archive. 4.7.6 and 4.8.4 are imminent anyway, and 4.9.3 is due i

Re: [Xen-devel] Xen Project Security Process Whitepaper v1 is ready for community review

2018-06-26 Thread Steven Haigh
On Tuesday, 5 June 2018 8:34:28 PM AEST George Dunlap wrote: > On Mon, Jun 4, 2018 at 3:55 PM, Lars Kurth wrote: > > 2.2.3 B. Git baseline of patches > > This created quite a bit of discussion and we did learn a few things: > > * From the thread, having to cherry pick a small (around 5-6) patches

Re: [Xen-devel] Xen Project Security Process Whitepaper v1 is ready for community review

2018-06-05 Thread Jan Beulich
>>> On 05.06.18 at 14:07, wrote: > On Tue, Jun 05, 2018 at 05:44:48AM -0600, Jan Beulich wrote: >> >>> On 05.06.18 at 13:03, wrote: >> > On Tue, Jun 05, 2018 at 11:34:28AM +0100, George Dunlap wrote: >> >> Suppose we did this: >> >> 1. When we predisclose an issue, freeze the stable branches unti

Re: [Xen-devel] Xen Project Security Process Whitepaper v1 is ready for community review

2018-06-05 Thread Marek Marczykowski
On Tue, Jun 05, 2018 at 05:44:48AM -0600, Jan Beulich wrote: > >>> On 05.06.18 at 13:03, wrote: > > On Tue, Jun 05, 2018 at 11:34:28AM +0100, George Dunlap wrote: > >> On Mon, Jun 4, 2018 at 3:55 PM, Lars Kurth wrote: > >> > >> > 2.2.3 B. Git baseline of patches > >> > This created quite a bit o

Re: [Xen-devel] Xen Project Security Process Whitepaper v1 is ready for community review

2018-06-05 Thread Jan Beulich
>>> On 05.06.18 at 13:03, wrote: > On Tue, Jun 05, 2018 at 11:34:28AM +0100, George Dunlap wrote: >> On Mon, Jun 4, 2018 at 3:55 PM, Lars Kurth wrote: >> >> > 2.2.3 B. Git baseline of patches >> > This created quite a bit of discussion and we did learn a few things: >> > * From the thread, havin

Re: [Xen-devel] Xen Project Security Process Whitepaper v1 is ready for community review

2018-06-05 Thread Marek Marczykowski
On Tue, Jun 05, 2018 at 11:34:28AM +0100, George Dunlap wrote: > On Mon, Jun 4, 2018 at 3:55 PM, Lars Kurth wrote: > > > 2.2.3 B. Git baseline of patches > > This created quite a bit of discussion and we did learn a few things: > > * From the thread, having to cherry pick a small (around 5-6) pat

Re: [Xen-devel] Xen Project Security Process Whitepaper v1 is ready for community review

2018-06-05 Thread George Dunlap
On Mon, Jun 4, 2018 at 3:55 PM, Lars Kurth wrote: > 2.2.3 B. Git baseline of patches > This created quite a bit of discussion and we did learn a few things: > * From the thread, having to cherry pick a small (around 5-6) patches have to > be cherry-picked for XSAs to apply to tarballs this appea

Re: [Xen-devel] Xen Project Security Process Whitepaper v1 is ready for community review

2018-06-04 Thread Lars Kurth
Hi all, I tried to summarize this thread (also see https://lists.xenproject.org/archives/html/xen-devel/2018-05/threads.html#01127), CC'ing everyone that contributed or requested to be on the thread. I also moved comments into https://docs.google.com/document/d/1FbGV4ZZB9OU8SI4b9ntnM-l6NaQLND