Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-26 Thread William L. Thomson Jr.
On Mon, 26 Jun 2017 16:30:41 +0900 Alice Ferrazzi wrote: > Linus Torvald on grsecurity: > https://www.spinics.net/lists/kernel/msg2540934.html Linus maybe responsible for Linux, but also things like Dirty Cow. Not sure how I feel about him and security, given that neglect. https://dirtycow.ninj

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-26 Thread Joshua Kinard
On 06/26/2017 09:15, Luis Ressel wrote: > On Sun, 25 Jun 2017 23:47:48 -0400 > Joshua Kinard wrote: > >> Safe for now to just switch to gentoo-sources while retaining hardened >> toolchain? Or would there be a few additional steps needed? I only >> use PaX for mprotect() and the ALSR capabiliti

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-26 Thread Luis Ressel
On Sun, 25 Jun 2017 23:47:48 -0400 Joshua Kinard wrote: > Safe for now to just switch to gentoo-sources while retaining hardened > toolchain? Or would there be a few additional steps needed? I only > use PaX for mprotect() and the ALSR capabilities, though I suspect > those might be in the stan

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-26 Thread Jason A. Donenfeld
On Mon, Jun 26, 2017 at 9:30 AM, Alice Ferrazzi wrote: > > Linus Torvald on grsecurity: > https://www.spinics.net/lists/kernel/msg2540934.html Spender responds: http://www.openwall.com/lists/oss-security/2017/06/24/1 Popcorn worthy thread.

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-26 Thread Alice Ferrazzi
Linus Torvald on grsecurity: https://www.spinics.net/lists/kernel/msg2540934.html -- Thanks, Alice Ferrazzi Gentoo Kernel Project Leader Mail: Alice Ferrazzi PGP: 2E4E 0856 461C 0585 1336 F496 5621 A6B2 8638 781A

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-25 Thread Joshua Kinard
On 06/23/2017 12:28, Anthony G. Basile wrote: > Hi everyone, > > Since late April, grsecurity upstream has stop making their patches > available publicly. Without going into details, the reason for their > decision revolves around disputes about how their patches were being > (ab)used. > > Since

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-24 Thread Anthony G. Basile
On 6/24/17 6:04 AM, Alexis Ballier wrote: > On Fri, 23 Jun 2017 12:28:27 -0400 > "Anthony G. Basile" wrote: > >> Hardened Gentoo has two sides to it, kernel hardening (done via >> hardened-sources) and toolchain/executable hardening. The two are >> interrelated but independent enough that toolch

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-24 Thread Alexis Ballier
On Fri, 23 Jun 2017 12:28:27 -0400 "Anthony G. Basile" wrote: > Hardened Gentoo has two sides to it, kernel hardening (done via > hardened-sources) and toolchain/executable hardening. The two are > interrelated but independent enough that toolchain hardening can > continue on its own. The harde

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-23 Thread Daniel Campbell
On 06/23/2017 09:28 AM, Anthony G. Basile wrote: > Hi everyone, > > Since late April, grsecurity upstream has stop making their patches > available publicly. Without going into details, the reason for their > decision revolves around disputes about how their patches were being > (ab)used. > > Si

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-23 Thread Vadim A. Misbakh-Soloviov
> I welcome feedback. And how about KSPP and other similar projects, that tries to continue the idea of community-friendly development based on latest release available to wide public (or, maybe some other, that was grown in parallel with PaX)? [OFFTOP] I personally very dislike Brad's behav

[gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-23 Thread Anthony G. Basile
Hi everyone, Since late April, grsecurity upstream has stop making their patches available publicly. Without going into details, the reason for their decision revolves around disputes about how their patches were being (ab)used. Since the grsecurity patch formed the main core of our hardened-sou