Re: Bug#605090: Proposing amd64-hardened architecture for Debian

2014-04-23 Thread Yves-Alexis Perez
On Wed, Apr 23, 2014 at 05:02:03PM +0100, Ben Hutchings wrote: > No, I meant that you might build a single binary package that would > contain the grsec-patched source. That would encourage building custom > kernels with build-time randomisation. I understand that's not the way > you want to go.

Re: Bug#605090: Proposing amd64-hardened architecture for Debian

2014-04-23 Thread Ben Hutchings
On Wed, 2014-04-23 at 17:34 +0200, Yves-Alexis Perez wrote: > On Wed, Apr 23, 2014 at 12:45:10PM +0100, Ben Hutchings wrote: > > On Tue, 2014-04-22 at 22:41 +0200, Yves-Alexis Perez wrote: [...] > > The options I see are: > > - Provide a source package based on src:linux that includes only the > >

Re: Bug#605090: Proposing amd64-hardened architecture for Debian

2014-04-23 Thread Yves-Alexis Perez
On Wed, Apr 23, 2014 at 12:45:10PM +0100, Ben Hutchings wrote: > On Tue, 2014-04-22 at 22:41 +0200, Yves-Alexis Perez wrote: > [...] > > NOTE: I don't want to dismiss Mempo attempts, especially the > > reproducible build part, and I also think it's valuable to provide our > > users a grsec kernel a

Re: Bug#605090: Proposing amd64-hardened architecture for Debian

2014-04-23 Thread Ben Hutchings
On Tue, 2014-04-22 at 22:41 +0200, Yves-Alexis Perez wrote: [...] > NOTE: I don't want to dismiss Mempo attempts, especially the > reproducible build part, and I also think it's valuable to provide our > users a grsec kernel as part of the distribution, just that I prefered > to go the featureset w

Re: Bug#605090: Proposing amd64-hardened architecture for Debian

2014-04-22 Thread Yves-Alexis Perez
On Tue, Apr 22, 2014 at 08:30:01PM +0100, Ben Hutchings wrote: > On Mon, 2014-04-21 at 05:28 +0200, Carlos Alberto Lopez Perez wrote: > > On 17/04/14 00:23, Aaron Zauner wrote: > > > Now shipping grsec is a really good idea. I'd like to see that as well. > > > > There has been an attempt to provid