From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mails.dpdk.org (mails.dpdk.org [217.70.189.124]) by inbox.dpdk.org (Postfix) with ESMTP id 3EF6242887; Fri, 31 Mar 2023 17:31:07 +0200 (CEST) Received: from mails.dpdk.org (localhost [127.0.0.1]) by mails.dpdk.org (Postfix) with ESMTP id 0B5F342D2C; Fri, 31 Mar 2023 17:31:06 +0200 (CEST) Received: from mail-pj1-f43.google.com (mail-pj1-f43.google.com [209.85.216.43]) by mails.dpdk.org (Postfix) with ESMTP id 43C1A42D29 for ; Fri, 31 Mar 2023 17:31:04 +0200 (CEST) Received: by mail-pj1-f43.google.com with SMTP id p3-20020a17090a74c300b0023f69bc7a68so23695892pjl.4 for ; Fri, 31 Mar 2023 08:31:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=networkplumber-org.20210112.gappssmtp.com; s=20210112; t=1680276663; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:subject:cc:to:from:date:from:to:cc:subject:date :message-id:reply-to; bh=gffUQ6CvpPWnmItRwjzBb3HJFwIihAh4XHrovWim1VE=; b=ctXhT2P+2ZJGorAY4/iqYOcvwew8+r4F9vdq/mkPG7IdP3r9wcw3R/WNp5wtL1KYOl VJiueYo9HjMaXjnLEWQ99JcMCF81kMuODV0pseQuXoeotOcEPJRNUDF2NmwKOY1gc2/p RH3n4BQaLj2JDVPjkBhOln/gSmlAEbifRqHM/8CgNm0I+qgw9Ri9H3sdT6BHyJHdN1X1 gQn+A4gEunu8tVtGHQTjUw2a+AkOZJIrhUsefclUfcAfcH7iVtXQWRUkh+11rPjhJTfK nfLbeHKU6l8vkPDrH1zgVqMxYp8MVP9R7bje84qzr9QyZeR5D1BO6DZrhCeHCHwHWXdg IREw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; t=1680276663; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:subject:cc:to:from:date:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=gffUQ6CvpPWnmItRwjzBb3HJFwIihAh4XHrovWim1VE=; b=XvyAb/WLnUi9cleo8TYuCAAPhyErBxlSD/jkkAyXsHt1UxgK47R6KRUH/f54HNwPqz vAhXDdjDNf6d16pv83jXmP3dKc534F+cd/66Vb4SJBsf5NZo83KRUbuxza8rmH4IWkjh RpXIcWTE2vf97DtVPVRnnPeWRTE8WJ8MZytM0xaV9yxfsbYiVitsds52JrdOo0a5UilK Z4fP+5UQU4vMdhaiJVikTO9VyHqevUPBKKn8U2Z67eGKnKeFKBJk5bVI5UqLYNJEPjOc E6EHepO35uSFk3oBLveCpNBy6DJum4QTO1Dj4KeebMHJY03gUKZ76rxYM89d1/OyYcRf 0TMw== X-Gm-Message-State: AO0yUKUqisMRrg8iB8r993oBpL1/2Eca0QsYf2T9sfRJ7Uu5Px/5X25b ejslbbFf3V/GnUuoAHEul9b0Lg== X-Google-Smtp-Source: AK7set9jeVxBETJKvyL+g8gMpXeNeaFQ2t+2V9/uHMXn3I/mKCcRlIDPsQTF9F/7MzAC08QRxyo5fw== X-Received: by 2002:a05:6a20:6a83:b0:d9:84d2:7aae with SMTP id bi3-20020a056a206a8300b000d984d27aaemr22860380pzb.22.1680276663383; Fri, 31 Mar 2023 08:31:03 -0700 (PDT) Received: from hermes.local (204-195-120-218.wavecable.com. [204.195.120.218]) by smtp.gmail.com with ESMTPSA id n2-20020aa79042000000b0062ddfce5cdbsm1778328pfo.45.2023.03.31.08.31.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Mar 2023 08:31:03 -0700 (PDT) Date: Fri, 31 Mar 2023 08:31:01 -0700 From: Stephen Hemminger To: Thomas Monjalon Cc: ferruh.yigit@intel.com, maxime.coquelin@redhat.com, qian.q.xu@intel.com, dev@dpdk.org, Marvin Liu , david.marchand@redhat.com, "cheng.jiang@intel.com" Subject: Re: [dpdk-dev] [PATCH] doc: clarify disclosure time slot when no response Message-ID: <20230331083101.3e572547@hermes.local> In-Reply-To: <7914272.ejJDZkT8p0@thomas> References: <20210125015736.7555-1-yong.liu@intel.com> <7914272.ejJDZkT8p0@thomas> MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-BeenThere: dev@dpdk.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: DPDK patches and discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dev-bounces@dpdk.org On Fri, 31 Mar 2023 12:38:23 +0200 Thomas Monjalon wrote: > > > > +If no confirmation mail send back to reporter in this period, thus mean security > > +team take this vulnerability as low severity. Furthermore shortest embargo **two weeks** > > +is required for it. Reporter can sumbit the bug through normal process or send > > sumbit -> submit > > > +out patch to public. > > Do we agree on the principle? > Does it require a bit of rewriting? LGTM