On Sun, 25 Jun 2017 23:47:48 -0400 Joshua Kinard <ku...@gentoo.org> wrote:
> Safe for now to just switch to gentoo-sources while retaining hardened > toolchain? Or would there be a few additional steps needed? I only > use PaX for mprotect() and the ALSR capabilities, though I suspect > those might be in the standard sauce by now. As such, I haven't had > to deal with userland issues and PaX too much over the years. A full rebuild shouldn't be neccessary after a switch to gentoo-sources or vanilla-sources. At least, I can't think of any reason why it would, and I haven't encountered any problems after switching on my own hosts. Just keep in mind that vanilla-sources doesn't support the PaX xattrs properly (AFAIR), so if you ever want to switch *back* from vanilla to hardened, some pax markings will be missing. This shouldn't be an issue for gentoo-sources, though. Cheers, Luis Ressel
pgpNbGvSbzkd0.pgp
Description: OpenPGP digital signature