Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-26 Thread William L. Thomson Jr.
On Mon, 26 Jun 2017 16:30:41 +0900 Alice Ferrazzi wrote: > Linus Torvald on grsecurity: > https://www.spinics.net/lists/kernel/msg2540934.html Linus maybe responsible for Linux, but also things like Dirty Cow. Not sure how I feel about him and security, given that neglect. https://dirtycow.ninj

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-26 Thread Joshua Kinard
On 06/26/2017 09:15, Luis Ressel wrote: > On Sun, 25 Jun 2017 23:47:48 -0400 > Joshua Kinard wrote: > >> Safe for now to just switch to gentoo-sources while retaining hardened >> toolchain? Or would there be a few additional steps needed? I only >> use PaX for mprotect() and the ALSR capabiliti

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-26 Thread Luis Ressel
On Sun, 25 Jun 2017 23:47:48 -0400 Joshua Kinard wrote: > Safe for now to just switch to gentoo-sources while retaining hardened > toolchain? Or would there be a few additional steps needed? I only > use PaX for mprotect() and the ALSR capabilities, though I suspect > those might be in the stan

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-26 Thread Jason A. Donenfeld
On Mon, Jun 26, 2017 at 9:30 AM, Alice Ferrazzi wrote: > > Linus Torvald on grsecurity: > https://www.spinics.net/lists/kernel/msg2540934.html Spender responds: http://www.openwall.com/lists/oss-security/2017/06/24/1 Popcorn worthy thread.

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-26 Thread Alice Ferrazzi
Linus Torvald on grsecurity: https://www.spinics.net/lists/kernel/msg2540934.html -- Thanks, Alice Ferrazzi Gentoo Kernel Project Leader Mail: Alice Ferrazzi PGP: 2E4E 0856 461C 0585 1336 F496 5621 A6B2 8638 781A

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-25 Thread Joshua Kinard
On 06/23/2017 12:28, Anthony G. Basile wrote: > Hi everyone, > > Since late April, grsecurity upstream has stop making their patches > available publicly. Without going into details, the reason for their > decision revolves around disputes about how their patches were being > (ab)used. > > Since

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-24 Thread Anthony G. Basile
On 6/24/17 6:04 AM, Alexis Ballier wrote: > On Fri, 23 Jun 2017 12:28:27 -0400 > "Anthony G. Basile" wrote: > >> Hardened Gentoo has two sides to it, kernel hardening (done via >> hardened-sources) and toolchain/executable hardening. The two are >> interrelated but independent enough that toolch

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-24 Thread Alexis Ballier
On Fri, 23 Jun 2017 12:28:27 -0400 "Anthony G. Basile" wrote: > Hardened Gentoo has two sides to it, kernel hardening (done via > hardened-sources) and toolchain/executable hardening. The two are > interrelated but independent enough that toolchain hardening can > continue on its own. The harde

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-23 Thread Daniel Campbell
On 06/23/2017 09:28 AM, Anthony G. Basile wrote: > Hi everyone, > > Since late April, grsecurity upstream has stop making their patches > available publicly. Without going into details, the reason for their > decision revolves around disputes about how their patches were being > (ab)used. > > Si

Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream

2017-06-23 Thread Vadim A. Misbakh-Soloviov
> I welcome feedback. And how about KSPP and other similar projects, that tries to continue the idea of community-friendly development based on latest release available to wide public (or, maybe some other, that was grown in parallel with PaX)? [OFFTOP] I personally very dislike Brad's behav