Gentoo Archives: gentoo-dev

From: Luis Ressel <aranea@×××××.de>
To: Joshua Kinard <kumba@g.o>
Cc: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream
Date: Mon, 26 Jun 2017 13:16:12
Message-Id: 20170626151545.433bd9c1@vega.skynet.aixah.de
In Reply to: Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream by Joshua Kinard
1 On Sun, 25 Jun 2017 23:47:48 -0400
2 Joshua Kinard <kumba@g.o> wrote:
3
4 > Safe for now to just switch to gentoo-sources while retaining hardened
5 > toolchain? Or would there be a few additional steps needed? I only
6 > use PaX for mprotect() and the ALSR capabilities, though I suspect
7 > those might be in the standard sauce by now. As such, I haven't had
8 > to deal with userland issues and PaX too much over the years.
9
10 A full rebuild shouldn't be neccessary after a switch to gentoo-sources
11 or vanilla-sources. At least, I can't think of any reason why it would,
12 and I haven't encountered any problems after switching on my own hosts.
13
14 Just keep in mind that vanilla-sources doesn't support the PaX xattrs
15 properly (AFAIR), so if you ever want to switch *back* from vanilla to
16 hardened, some pax markings will be missing. This shouldn't be an issue
17 for gentoo-sources, though.
18
19 Cheers,
20 Luis Ressel

Replies