1 |
On Sun, 30 Apr 2017 16:16:46 +0300 Alex Efros wrote: |
2 |
> Hi! |
3 |
> |
4 |
> On Sun, Apr 30, 2017 at 04:00:39PM +0300, Andrew Savchenko wrote: |
5 |
> > The only way to preserve this functionality in the long run is to |
6 |
> > port it to the mainline kernel. This will not be easy, most likely |
7 |
> > not everything will be accepted, some stuff will have to be |
8 |
> > reimplemented using another approaches, etc. |
9 |
> |
10 |
> We had 16 years to do this with help of GrSec/PaX developers. It wasn't |
11 |
> happened, and it's unlikely happens now unless some huge company decide to |
12 |
> spend a lot of resources for this. |
13 |
|
14 |
There was not enough motivation for this. Why to invest resources |
15 |
into porting if it works the way it is? Now situation is different, |
16 |
so we'll see what follows. |
17 |
|
18 |
BTW a number of features were ported to or reimplemented in the |
19 |
mainline kernel: ASLR, MAC, auditing, ptrace snooping protection. |
20 |
Probably many more, I haven't studies this in detail. |
21 |
|
22 |
Best regards, |
23 |
Andrew Savchenko |