On Sun, 25 Jun 2017 23:47:48 -0400
Joshua Kinard <ku...@gentoo.org> wrote:

> Safe for now to just switch to gentoo-sources while retaining hardened
> toolchain?  Or would there be a few additional steps needed?  I only
> use PaX for mprotect() and the ALSR capabilities, though I suspect
> those might be in the standard sauce by now.  As such, I haven't had
> to deal with userland issues and PaX too much over the years.

A full rebuild shouldn't be neccessary after a switch to gentoo-sources
or vanilla-sources. At least, I can't think of any reason why it would,
and I haven't encountered any problems after switching on my own hosts.

Just keep in mind that vanilla-sources doesn't support the PaX xattrs
properly (AFAIR), so if you ever want to switch *back* from vanilla to
hardened, some pax markings will be missing. This shouldn't be an issue
for gentoo-sources, though.

Cheers,
Luis Ressel

Attachment: pgpNbGvSbzkd0.pgp
Description: OpenPGP digital signature

Reply via email to