1 msgIt's time for the BIG one!
2 msgRE: [SECURITY] [DSA 1139-1] New ruby1.6 package...
1 msgRE: Prima esperienza giovane pompinare qui.
1 msgPatrik Nordkvist is on vacation.
1 msgRe: [SECURITY] [DSA 1135-1] New libtunepimp pac...

Out of tree kernel images / Lustre image
\ Goswin von Brederlow (1 Aug 2006)
. \ Goswin von Brederlow (1 Aug 2006)
. . \ dann frazier (1 Aug 2006)
. . . \ Goswin von Brederlow (2 Aug 2006)
. . \ Bastian Blank (2 Aug 2006)
. . . \ dann frazier (2 Aug 2006)
. . . . \ Alastair McKinstry (3 Aug 2006)
. . . . \ Sven Luther (3 Aug 2006)
. . . . \ Goswin von Brederlow (4 Aug 2006)

1 msgRe: [DSA 1132-1] New apache2 packages fix buffe...
1 msgHynix case... Time
1 msgRe: seeynVljIAGRA
1 msgRe: [SECURITY] [DSA 1129-1] New osiris packages...
18 msg'su -' and 'su' - what is the real difference?
1 msgDominic McDonald has left Australian Geographic
1 msgRe: [SECURITY] [DSA 1125-2] New drupal packages...
1 msgRe: [SECURITY] [DSA 1111-2] New Linux kernel 2....
1 msgintent having somewhat swell
1 msgSmall correction re [DSA 1111-2] (AUSCERT#20065...
2 msgdebian testing Packages.bz2 md5 sum mismatch
3 msgdrupal security fix bronkens drupal website (wa...
2 msgRe: [SECURITY] [DSA 1123-1] New libdumb package...
1 msgflap copy:At
Subject:Re: Out of tree kernel images / Lustre image
Group:Debian-security
From:Goswin von Brederlow
Date:4 Aug 2006


 
dann frazier <dannf> writes:

> On Wed, Aug 02, 2006 at 11:06:23AM +0000, Bastian Blank wrote:
>> If you want to be correct, you can't use linux-source. So the security
>> team have to support another kernel source.
>
> A kernel-patch package that applies on top of the kernel team's
> linux-source is the approach I'd suggest. But to reiterate, if
> something in a kernel update causes the patch to no longer apply, I
> would want to have a reliable contact (hopefully 2 people) whom we can
> call upon for assistance.

A Build-Depends on the linux-source or linux-tree will be
there. Lustre already comes as patch set to the kernel so there is 0
reason to fork/copy the linux source.

I believe security updates should also be less of a problem than
actual kernel updates. They don't tend to mess around with the
VFS/etx3 code overly much. But as I mentioned, now we are two people
needing this for work so there should always be someone available.

I guess we can build an image and see how well this works out till
etch+1 comes out. I'm not sure if I want this in etch/stable. Having
it in unstbale for the time being would be fine with me.

MfG
Goswin


--
To UNSUBSCRIBE, email to debian-security-REQUEST
with a subject of "unsubscribe". Trouble? Contact listmaster



© 2004-2008 readlist.com