git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: What's cooking in git.git (May 2023, #04; Thu, 11)

From
Felipe Contreras <felipe.contreras@gmail.com>
Date
May 12, 2023, 03:46 UTC
Message-ID
<CAMP44s0N7tLmpEbScVDDc=M2NG=vx+SoMLu4Vc_vRcS7dvLOgQ@mail.gmail.com>
In-Reply-To
<ZF2tDgngoBHZojLf@nand.local>
On Thu, May 11, 2023 at 10:05 PM Taylor Blau <me@ttaylorr.com> wrote:
> On Thu, May 11, 2023 at 08:36:36PM -0500, Felipe Contreras wrote:
> > Junio C Hamano wrote:
Show 19 quoted lines
> > > * ds/merge-tree-use-config (2023-05-10) 1 commit
> > >   (merged to 'next' on 2023-05-11 at e0dab53028)
> > >  + merge-tree: load default git config
> > >
> > >  Allow git forges to disable replace-refs feature while running "git
> > >  merge-tree".
> > >
> > >  Will merge to 'master'.
> > >  source: <pull.1530.git.1683745654800.gitgitgadget@gmail.com>
> >
> > Why was this series merged after only 11 minutes of review window? Are patches
> > from GitHub favored over all others?
>
> Certainly not.
>
> The reason that this was merged quickly is because both of the first two
> reviewers had already seen the patch and reviewed it earlier on the
> git-security list. The patch that Stolee sent was urgent enough to merit
> a quick merge.
There's a quick review, and there is zero review.
Even Derrick Stolee wanted more time for the public list to review the patch.

If the eyeballs of the public list are not wanted after a security review, then why bother sending it here? Just merge it directly from git-security.

I don't think that's desirable though. I share the opinion of Linus Torvalds that security fixes are not special: they are just another fix. Therefore they should go through the same process as any other patch, because just like any other patch, they can introduce regressions, and benefit from more eyeballs.

If "given enough eyeballs, all bugs are shallow", I fail to see why we would want less eyeballs for security fixes. I for one found two issues with the patch, my first comment was a bit more than an hour later, and it's already merged.

I don't think that's ideal.
Cheers.
-- 
Felipe Contreras
Previous: Taylor BlauNext: Patrick Steinhardt
Message 4 of 9 in “What's cooking in git.git (May 2023, #04; Thu, 11)”
  1. Junio C HamanoMay 12, 2023
  2. Felipe ContrerasMay 12, 2023
  3. Taylor BlauMay 12, 2023
  4. Felipe ContrerasMay 12, 2023
  5. Patrick SteinhardtMay 12, 2023
  6. Junio C HamanoMay 12, 2023
  7. tl/push-branches-is-an-alias-for-all (Was: Re: What's cooking in git.git (May 2023, #04; Thu, 11))Elijah Newren, May 12, 2023
  8. Junio C HamanoMay 12, 2023
  9. brian m. carlsonMay 12, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.