[19562] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Fixes for some issues found using Coverity

daemon@ATHENA.MIT.EDU (Greg Hudson)
Mon Mar 20 13:12:46 2017

To: "Kittel, Martin" <martin.kittel@sap.com>,
        "krbdev@mit.edu" <krbdev@mit.edu>
From: Greg Hudson <ghudson@mit.edu>
Message-ID: <de4e80d6-ceb2-b6e2-898f-fd8d2e525e3e@mit.edu>
Date: Mon, 20 Mar 2017 13:12:36 -0400
MIME-Version: 1.0
In-Reply-To: <23f1e43d7f284d7bb2278be66dfa9e51@sap.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On 03/20/2017 01:03 PM, Kittel, Martin wrote:
> we ship krb5 as part of some of our products and as part of our QA we run Coverity scans on all components, including krb5.
> As part of these scans a number of issues were found that we think need or might need fixing. I am wondering now how to best feed back those fixes into the mainline
> I have prepared a first bunch of git commits against the current HEAD from https://github.com/krb5/krb5 and tried to group them according to the Coverity findings. However I don't know whether I can feed these into krb5-bugs directly. What is the preferred way to post such patches?

For any issue which might have a realistic security impact, please send
mail to krbcore-security@mit.edu.  (It's likely that most Coverity
defects with a security impact have been fixed already, but there's a
chance that not all have.)  You can PGP-encrypt mail to krbcore-security
using the key listed at https://web.mit.edu/kerberos/contact.html if
you're set up to do that.

For other changes, please create a github pull request.  See
https://k5wiki.kerberos.org/wiki/Contributing_code for more information.
 Don't get too bogged down in the details; we can always fix those up if
necessary.
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post