Review of a secure software development process for glibc.

Mark Wielaard mark@klomp.org
Sat May 10 13:51:09 GMT 2025


Hi Carlos,

On Fri, May 09, 2025 at 05:59:07PM -0400, Carlos O'Donell wrote:
> This document is glibc specific:
> https://sourceware.org/glibc/wiki/SSDLC/Policy/glibc
> 
> The specifics here are about glibc and defining what we expect from the
> infrastructure, developer end points, and our process, and how that
> creates something that is sustainably secure and what services we need
> for that process.
> 
> Some of the items in the writeup are the same as in Mark's writeup in
> "Suggested secure development policies for projects"
> https://sourceware.org/cyber-security-faq.html, but structured
> into NIST SP 800-218-based buckets and applied specifically to glibc.

At the Sourceware Open Office yesterday we were just discussing how to
add incentives for Sourceware hosted projects to adopt some of the
policies outlined in the cyber securtiy check list and how to assign
someone as a project's secure development policy champion.

The NIST SP 800-218 document might not be the ideal format for this
though. We tried that last year when Elena deconstructed the document
for us and we discussed this in the Sourceware Open Office
meetings. It contains elements you can use, but in general it isn't
really a good way for a community project to document its cyber
security practices. The Sourceware Security FAQ
https://sourceware.org/cyber-security-faq.html explains this a bit
more:

  The NIST recommendations are written for companies doing business
  with the US government and for government agencies who want to do
  their own secure development (in the cloud). They are not practical
  for describing the secure software development environment of
  upstream communities. But elements can be used as inspiration. If
  only because it shows what kind of documentation requests a project
  might get from companies working with the US government.

The idea behind the Sourceware Cyber Security project policy checklist
is that an hosted project can just concentrate on having a documented
verifiable cybersecurity policy, as recommended by these regulations
which Sourceware provides the resources for. A lot of these security
policies are already implemented by various different hosted project,
but are sometimes poorly documented. Although no project does all of
them at the moment. But they are intended so projects can learn from
each other. If you feel something is missing just let us know.

Thanks,

Mark


More information about the Libc-alpha mailing list