Received: by 2002:a05:6a10:f3d0:0:0:0:0 with SMTP id a16csp4893737pxv; Tue, 6 Jul 2021 11:43:19 -0700 (PDT) X-Google-Smtp-Source: ABdhPJzeZWTPbmMatR4GO46FSpQ4suiL0AhXNTRnfd3yO568R+ml5HpLgfVq/fN1UhmEfG9IgAQX X-Received: by 2002:a92:1948:: with SMTP id e8mr14897088ilm.77.1625596998975; Tue, 06 Jul 2021 11:43:18 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1625596998; cv=none; d=google.com; s=arc-20160816; b=MoAFdA9KNxiGjq9WZmqsDQ9yRrgVN/q52saFY1ttSYAGSjR3WL5Vft4WjXT1oBSHCH Szoqyzy+h60xUN9BmFPg8pSAXbNrGKF4abHtkjt8zsTPhPCXRdcjZ2KL61kc5bfrldxL 5KAVhSV8tXSRAEVkZNJV1bYe/aJpLpZlNwI+aFsfcxsOjiy192+As34oHfr1dvJ+m78O lJd4RoCutWYhg9p/8iROj5pHiVsxIa9pNRVYNbyDOABdlNH0XJPtYNNhP+TpzPXZP833 UQXjQUrFoEyYuqaTzahqz5G6P9ca7SBcUb/ar1IRoFFYvkx0E7eJZqMRuySjYqPAQnfX R4Sg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-disposition:mime-version :references:message-id:subject:cc:to:from:date:dkim-signature :dkim-signature; bh=R968ytTOlwNw+2WYjcHp6doapxohJ0BvC2hmSpYueUU=; b=K5XuRl2uP7v4uDCpRYR/JNFn2n8w+dmMmOAxW/M0OtgnnPukX9c5JAptrFd6eCW1/R +bQdTy1i6eis8hcaZdkH68f1WE2QERqHVkk2Ui/r8zJpoY/V5TPN09pE5aJCk/sobzQ/ 0B4obzhsSFrvZvnjP64/rZdovcroY8gBEWCncpip/6bWTdTdCoMMB67u+PlbHxjjL65+ cOC6LdbMf159PrQjna4AlzXqz9DnZh2zsh+apnNXl6G/y8m785XTcWXKnyHPrEaPzEUy MpsTnKbQ6ddexBu3eksGTknpUClv8U/PGMeS4yrKQ+EHOANLfLNkcRPpahx/B9wFpiB4 NR9g== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kroah.com header.s=fm1 header.b=EUWVdeZH; dkim=pass header.i=@messagingengine.com header.s=fm3 header.b=iKP2Uunl; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id t7si15793171jam.62.2021.07.06.11.43.06; Tue, 06 Jul 2021 11:43:18 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@kroah.com header.s=fm1 header.b=EUWVdeZH; dkim=pass header.i=@messagingengine.com header.s=fm3 header.b=iKP2Uunl; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231438AbhGFSoj (ORCPT + 99 others); Tue, 6 Jul 2021 14:44:39 -0400 Received: from wnew4-smtp.messagingengine.com ([64.147.123.18]:36525 "EHLO wnew4-smtp.messagingengine.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S230084AbhGFSoi (ORCPT ); Tue, 6 Jul 2021 14:44:38 -0400 Received: from compute2.internal (compute2.nyi.internal [10.202.2.42]) by mailnew.west.internal (Postfix) with ESMTP id D21E42B006E7; Tue, 6 Jul 2021 14:41:58 -0400 (EDT) Received: from mailfrontend2 ([10.202.2.163]) by compute2.internal (MEProxy); Tue, 06 Jul 2021 14:41:59 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kroah.com; h= date:from:to:cc:subject:message-id:references:mime-version :content-type:in-reply-to; s=fm1; bh=R968ytTOlwNw+2WYjcHp6doapxo hJ0BvC2hmSpYueUU=; b=EUWVdeZHzeCas1GdVUpvefEtK+dgpSZHLPM+ZjqZwbD XZjtNQ0pdNaWq8Iymll4qYN/q3H3VLwS1yWdN2m3DbeZV8u8xIR1a5+Y2/FjvF07 O9K1a95IAm75CE2QctM5ru4WcagKQH2Qdh4rQqv27l9Z1r4YJyjq8ZE+KIJk4D9p d1mP1uSwYGd6wYdUPQKSa44YvbgTCZ9GopKXOwGVOciBEGliTW3XkpPgJxtX11NN BY7ndhAFlol5WglJ3KrCFyqLrNrV0kro1q9okC2fY1iLnqBvDmUjWiQZ/o8Pkoaz tXnKK1Yw/754LxL1LkWbKaCChq3EOulRWVuSqiiLPUw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-proxy :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm3; bh=R968yt TOlwNw+2WYjcHp6doapxohJ0BvC2hmSpYueUU=; b=iKP2Uunlg15jYviPB8n3Iq /nn83ZoIWP4dO1dWBgLOjQOyH8iJT883cvD0J+qMvO8lvPnsMmABmFdLdhh3wxfr yEEJAXah/cr9RFTVBwWeKj9eKNS9H5NJzOSnvmd3k9MCwn3gn+m2r3jYePh1SPdM Y1XU9HTOpbtrBnAxHSVluz5dA5jIdamqxO656Zw5bGBfUBywFFckBvYJCj52E49u 8N/hn1H/s5xDwADEH4S+Q0G9/Pv7o8P23wQ6W/jDeSHw9BqZVTqiyZGhDZ6hCll9 G5k6MOwbUK0XyaexZ2o0XThZpKqJs+ZoiXrVZAR1TvRHK6/BmiJyvM61hEYM2RmQ == X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvtddrtddtgdekiecutefuodetggdotefrodftvf curfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfghnecu uegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmdenuc fjughrpeffhffvuffkfhggtggujgesthdtredttddtvdenucfhrhhomhepmfhrohgrhhdq jfgrrhhtmhgrnhcuoehgrhgvgheskhhrohgrhhdrtghomheqnecuggftrfgrthhtvghrnh eplefggeejffdtgeeutdefveevhfdtfeeufeefjefhleduuefgieegveelueejteffnecu vehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomhepghhrvghgse hkrhhorghhrdgtohhm X-ME-Proxy: Received: by mail.messagingengine.com (Postfix) with ESMTPA; Tue, 6 Jul 2021 14:41:57 -0400 (EDT) Date: Tue, 6 Jul 2021 20:41:54 +0200 From: Kroah-Hartman To: Norbert Manthey Cc: LKML , "Woodhouse, David" , "foersleo@amazon.de" , Gustavo Pimentel , "Gustavo A. R. Silva" , Kees Cook , Thomas Gleixner Subject: Re: Coverity Scan model file, license, public access Message-ID: References: <6f1cb856-fc72-cfd1-9bdd-b4dbf58c558c@amazon.de> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <6f1cb856-fc72-cfd1-9bdd-b4dbf58c558c@amazon.de> Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, Jul 06, 2021 at 08:34:16PM +0200, Norbert Manthey wrote: > With respect to sharing the results: we are allowed to upstream fixes > that we find with the tool. We contributed in that way already, e.g. [2]. Yes, that is how many companies do this and have for a long time (Canonical does this a lot). But that puts all the work on you, and you can not share the results of the tool with anyone, so you are forced to do the work to fix problems the tool reports, which feels really wrong when you are dealing with a scan of a public source tree... thanks, greg k-h