On Mon, 1 May 2017 13:58:08 +0000 Sven Vermeulen wrote: > On Mon, May 01, 2017 at 01:28:54PM +0300, Andrew Savchenko wrote: > > > The obvious step is indeed to stop further *current* development on > > > hardened-sources. > > > > Why not support hardened-sources while corresponding vanilla > > kernels are still supported? E.g. 4.9 is a longterm branch, so we > > should be able to keep hardened-sources-4.9* up-to-date with > > vanilla bugfixes. This will give a nice transition period for > > hardened users. > > Transition to what exactly?
It doesn't really matter. Something will come up, but we need to provide users smooth experience before then. Supporting 4.9 looks like a good solution here. Most likely KSPP project will come up, they are doing a good job: bringing security features upstream fixing bugs in PaX code during the process [1]. This is what PaX should have done long time ago, they were even offered CII grant for this job, but refused [2]. [1] http://openwall.com/lists/kernel-hardening/2017/05/02/4 [2] https://lists.coreinfrastructure.org/pipermail/cii-discuss/2015-August/000003.html Best regards, Andrew Savchenko
pgpwmYA_JB_Yp.pgp
Description: PGP signature