Re: Technical repercussions of grsecurity removal
Alex Efros <[email protected]> Tue, 2 May 2017 23:41:34 +0300
| Newsgroups | gmane.linux.gentoo.hardened |
|---|---|
| Organization | http://powerman.name/ |
| Message-ID | <[email protected]> |
Hi! On Tue, May 02, 2017 at 09:58:18PM +0200, Daniel Cegiełka wrote: > This means that any future solution will not be compatible with current > PaX support. It doesn't means that. That may happens, or not - if someone will bother about compatibility, for example. I also think it makes sense to keep paxmarking in ebuilds, for now. If not for technical reasons, then just to avoid adding more damage. GrSec/PaX is not going anywhere, at least not immediately, there are a lot of systems which still use hardened-sources and may continue using current versions for long enough time - and they'll need that paxmarking for current and new versions of ebuilds. Plus there is a non-zero chance next solution will replace GrSec/PaX in more or less compatible way. And thus until it became clear next solution doesn't require similar paxmarking at same places or supporting paxmarking in existing ebuilds will require any noticeable effort - there is no good reason to destroy something what just works now. > Again: years of work and PaX support ends in the trash. Yeah, we already know you feel it this way. Any reason to repeat this again and again? How this will improve anything? -- WBR, Alex.