On Mon, 1 May 2017 13:58:08 +0000 Sven Vermeulen wrote:
> On Mon, May 01, 2017 at 01:28:54PM +0300, Andrew Savchenko wrote:
> > > The obvious step is indeed to stop further *current* development on
> > > hardened-sources.
> > 
> > Why not support hardened-sources while corresponding vanilla
> > kernels are still supported? E.g. 4.9 is a longterm branch, so we
> > should be able to keep hardened-sources-4.9* up-to-date with
> > vanilla bugfixes. This will give a nice transition period for
> > hardened users.
> 
> Transition to what exactly?

It doesn't really matter. Something will come up, but we need to
provide users smooth experience before then. Supporting 4.9 looks
like a good solution here.

Most likely KSPP project will come up, they are doing a good job:
bringing security features upstream fixing bugs in PaX code during
the process [1]. This is what PaX should have done long time ago,
they were even offered CII grant for this job, but refused [2].

[1] http://openwall.com/lists/kernel-hardening/2017/05/02/4
[2] 
https://lists.coreinfrastructure.org/pipermail/cii-discuss/2015-August/000003.html

Best regards,
Andrew Savchenko

Attachment: pgpwmYA_JB_Yp.pgp
Description: PGP signature

Reply via email to