Hello Branden,

G. Branden Robinson wrote on Wed, Sep 23, 2026 at 01:21:30PM -0500:
 
> To winnow these down, select the "Enhanced" query form, then click the
> "Apply" button.

So far, your instructions work for me.

> Next, select "Private" under the "Privacy" drop-down list and click the
> "Apply" button again.

When i also change the selection dropdown to "Simple", i do get various
dropdown fileds, namely:

 * Open/Closed:
 * Status:
 * Submitter:
 * Assigned to:
 * Category:
 * Item group:
 * Severity:
 * Summary:
 * Original submission:
 * AND/OR
 * Additional constrint
 * Field name
 * modified/not modified
 * day number
 * month name
 * year number (input box, not a dropdown)
 * number to show at once (input box, not a dropdown)
 * maximum spam score (input box, not a dropdown)

I do not see any "Privacy" drop-down.

As i wrote in my private mail to you, the URI

  https://savannah.gnu.org/bugs/?group=groff&privacy[]=1

works for me - but only after first selecting "Multiple"
in the selection dropdown and clicking "Apply" once.
The Savannah is a magical place, especially around sunset!

> The oldest of these contains a lengthy comment from me on governance and
> administration issues involving tensions I perceive between security
> management and my preferred administrative philosophy of "radical
> transparency".
> 
> I welcome feedback on that as much as on the technical issues, all of
> which I feel competent to resolve one way or another.
> 
> (FORTUNE: All your hostage are belong to us.)
> 
> After the immediate difficulties have passed, I hope to bring that
> discussion to this forum.

Since it may simplify and speed up your work and improve general peace
of mind, i'll comment here right away.  Feel free to use these comments
to avoid excessive work.  No need to reply to these comments right
now, though, especially not if you want to first work on the code.

I agree with what you say in bug #68680, and i would even go further,
roughly like this:

 * I wholeheartedly agree with your concept of "radical transparency".
 * I see no need for groff to ever do embargoes - not even with respect
   to the subset of the currently private issues that i would classify
   as "related to security".  Then again, no problem if you want to
   keep a few issues private for a short time until a fix is committed,
   even in cases where i would consider privacy optional.
 * If a bug looks like a potential security risk or is known to be
   a security risk, that may influence the decision whether to
   roll an unplanned bugfix release or whether to bundle it into
   the next release that is planned anyway.  I don't think
   anything more than that is needed.
 * Whether the reporter claims what they report is a security issue is
   mostly irrelevant, and whether or not a CVE or CWE entry exists is
   entirely irrelevant.  Just use the available information together
   with your own code review and testing and use your own good judgement
   to evaluate root cause, likely or potential impact, and best fix
   of the root cause.
 * Even if there is a good reason to suspect that a bug may be
   exploitable, doing research to ascertain whether or not the bug
   is actually exploitable is usually nothing but a waste of time
   (except, of course, in certain academic, commercial, government,
   and military settings, but none of that applies to groff).
   Let's just fix the damn bug, be done with it, and move on.
 * In the most extreme cases - for example, a hypothetical bug that
   would clearly allow a remote exploit that would yields privileged
   access to webservers running groff in man.cgi contexts - cautious
   handling may be a good idea, maybe even notifying known server
   operators before commit.  A remotely exploitable DOS clearly
   would not warrant any special handling though, IMHO.
   To be clear, so far, i have seen nothing that rises anywhere
   near a threshold where i would even start considering special
   handling.
 * Avoid anything that causes additional workload, except in the
   most extreme cases, and except in such cases where you yourself
   feel more comfortable being a bit more careful than usual.
 * No need to make hard and fast rules, just use your good
   judgement, and in doubt, err towards transparency.

Yours,
  Ingo

Reply via email to