[gentoo-hardened] Re: [gentoo-dev] New item for sys-kernel/hardened-sources removal

2017-08-16 Thread Francisco Blas Izquierdo Riera (klondike)
El 16/08/17 a las 09:40, Marek Szuba escribió: > Two tiny bits of formal nitpicking from my side: > - it's "grsecurity" (not a typo, they do use a lowercase g except when > the name appears at the beginning of a sentence), not "grsec"; > - the patches were not *distributed by* grsecurity, they

Re: [gentoo-hardened] Re: [gentoo-dev] New item for sys-kernel/hardened-sources removal

2017-08-16 Thread Robert Sharp
On 16/08/17 11:09, Francisco Blas Izquierdo Riera (klondike) wrote: El 16/08/17 a las 09:40, Marek Szuba escribió: Two tiny bits of formal nitpicking from my side: - it's "grsecurity" (not a typo, they do use a lowercase g except when the name appears at the beginning of a sentence), not

Re: [gentoo-hardened] Re: [gentoo-dev] New item for sys-kernel/hardened-sources removal

2017-08-16 Thread Francisco Blas Izquierdo Riera (klondike)
El 16/08/17 a las 15:36, Robert Sharp escribió: > On 16/08/17 11:09, Francisco Blas Izquierdo Riera (klondike) wrote: >> El 16/08/17 a las 09:40, Marek Szuba escribió: >>> Two tiny bits of formal nitpicking from my side: >>> - it's "grsecurity" (not a typo, they do use a lowercase g except when

Re: [gentoo-hardened] Re: [gentoo-dev] New item for sys-kernel/hardened-sources removal

2017-08-16 Thread Michael Orlitzky
On 08/16/2017 10:37 AM, Francisco Blas Izquierdo Riera (klondike) wrote: >>> >> Would anyone like to outline a simple process to migrate from >> hardened-sources + hardened tool-chain to gentoo-sources? >> > Unless you want to drop userspace hardening (which most likely you don't > as it is still

Re: [gentoo-hardened] Re: [gentoo-dev] New item for sys-kernel/hardened-sources removal

2017-08-16 Thread philipp . ammann
Am 16.08.2017 16:46 schrieb Michael Orlitzky: There is one thing you have to watch out for: certain vanilla kernel hardened features were subjugated to grsecurity ones and you'll probably want to enable them. For example, you probably want CONFIG_VMAP_STACK once you've switched, but it won't