qemu-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Qemu-devel] [PATCH 1/2] CVE-2015-1779: incrementally decode websock


From: Peter Maydell
Subject: Re: [Qemu-devel] [PATCH 1/2] CVE-2015-1779: incrementally decode websocket frames
Date: Wed, 1 Apr 2015 14:41:57 +0100

On 1 April 2015 at 14:36, Gerd Hoffmann <address@hidden> wrote:
> Confirmed.  Fixes the issues I've seen in testing and looks sensible to
> me.  Comment from Daniel would be nice, especially as I know next to
> nothing about websockets, but he seems to be off into the easter
> holidays already.
>
> So, with -rc2 waiting for this (and being late already) I think I'll
> squash in the incremental fix and prepare a pull request even without
> Daniels ack ...

Yes, that seems best. Given that this is a CVE fix can you
make sure the change is called out clearly in the commit
message so it's easy for downstreams to see which version
of the fix they have applied? Might be worth including the
fixup-diff in the commit message...

thanks
-- PMM



reply via email to

[Prev in Thread] Current Thread [Next in Thread]