Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux
1
fork

Configure Feed

Select the types of activity you want to include in your feed.

Merge tag 'char-misc-5.4-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc

Pull Documentation/process update from Greg KH:
"Here are two small Documentation/process/embargoed-hardware-issues.rst
file updates that missed my previous char/misc pull request.

The first one adds an Intel representative for the process, and the
second one cleans up the text a bit more when it comes to how the
disclosure rules work, as it was a bit confusing to some companies"

* tag 'char-misc-5.4-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc:
Documentation/process: Clarify disclosure rules
Documentation/process: Volunteer as the ambassador for Intel

+34 -8
+34 -8
Documentation/process/embargoed-hardware-issues.rst
··· 143 143 in their role as Linux kernel developers. They will, however, agree to 144 144 adhere to this documented process and the Memorandum of Understanding. 145 145 146 + The disclosing party should provide a list of contacts for all other 147 + entities who have already been, or should be, informed about the issue. 148 + This serves several purposes: 149 + 150 + - The list of disclosed entities allows communication accross the 151 + industry, e.g. other OS vendors, HW vendors, etc. 152 + 153 + - The disclosed entities can be contacted to name experts who should 154 + participate in the mitigation development. 155 + 156 + - If an expert which is required to handle an issue is employed by an 157 + listed entity or member of an listed entity, then the response teams can 158 + request the disclosure of that expert from that entity. This ensures 159 + that the expert is also part of the entity's response team. 146 160 147 161 Disclosure 148 162 """""""""" ··· 172 158 """""""""""""""""""""" 173 159 174 160 The initial response team sets up an encrypted mailing-list or repurposes 175 - an existing one if appropriate. The disclosing party should provide a list 176 - of contacts for all other parties who have already been, or should be, 177 - informed about the issue. The response team contacts these parties so they 178 - can name experts who should be subscribed to the mailing-list. 161 + an existing one if appropriate. 179 162 180 163 Using a mailing-list is close to the normal Linux development process and 181 164 has been successfully used in developing mitigations for various hardware ··· 186 175 stable kernel versions as necessary. 187 176 188 177 The initial response team will identify further experts from the Linux 189 - kernel developer community as needed and inform the disclosing party about 190 - their participation. Bringing in experts can happen at any time of the 191 - development process and often needs to be handled in a timely manner. 178 + kernel developer community as needed. Bringing in experts can happen at any 179 + time of the development process and needs to be handled in a timely manner. 180 + 181 + If an expert is employed by or member of an entity on the disclosure list 182 + provided by the disclosing party, then participation will be requested from 183 + the relevant entity. 184 + 185 + If not, then the disclosing party will be informed about the experts 186 + participation. The experts are covered by the Memorandum of Understanding 187 + and the disclosing party is requested to acknowledge the participation. In 188 + case that the disclosing party has a compelling reason to object, then this 189 + objection has to be raised within five work days and resolved with the 190 + incident team immediately. If the disclosing party does not react within 191 + five work days this is taken as silent acknowledgement. 192 + 193 + After acknowledgement or resolution of an objection the expert is disclosed 194 + by the incident team and brought into the development process. 195 + 192 196 193 197 Coordinated release 194 198 """"""""""""""""""" ··· 242 216 ARM 243 217 AMD 244 218 IBM 245 - Intel 219 + Intel Tony Luck <tony.luck@intel.com> 246 220 Qualcomm Trilok Soni <tsoni@codeaurora.org> 247 221 248 222 Microsoft Sasha Levin <sashal@kernel.org>