Gentoo Archives: gentoo-dev

From: Daniel Campbell <zlg@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream
Date: Fri, 23 Jun 2017 19:33:45
Message-Id: d72f8953-8843-d7a6-a48c-b1f1f2f6ec43@gentoo.org
In Reply to: [gentoo-dev] The status of grsecurity upstream and hardened-sources downstream by "Anthony G. Basile"
1 On 06/23/2017 09:28 AM, Anthony G. Basile wrote:
2 > Hi everyone,
3 >
4 > Since late April, grsecurity upstream has stop making their patches
5 > available publicly. Without going into details, the reason for their
6 > decision revolves around disputes about how their patches were being
7 > (ab)used.
8 >
9 > Since the grsecurity patch formed the main core of our hardened-sources
10 > kernel, their decision has serious repercussions for the Hardened Gentoo
11 > project. I will no longer be able to support hardened-sources and will
12 > have to eventually mask and remove it from the tree.
13 >
14 > Hardened Gentoo has two sides to it, kernel hardening (done via
15 > hardened-sources) and toolchain/executable hardening. The two are
16 > interrelated but independent enough that toolchain hardening can
17 > continue on its own. The hardened kernel, however, provided PaX
18 > protection for executables and this will be lost. We did a lot of work
19 > to properly maintain PaX markings in our package management system and
20 > there was no part of Gentoo that wasn't touched by issues stemming from
21 > PaX support.
22 >
23 > I waited two months before saying anything because the reasons were more
24 > of a political nature than some technical issue. At this point, I think
25 > its time to let the community know about the state of affairs with
26 > hardened-sources.
27 >
28 > I can no longer get into the #grsecurity/OFTC channel (nothing personal,
29 > they kicked everyone), and so I have not spoken to spengler or pipacs.
30 > I don't know if they will ever release grsecurity patches again.
31 >
32 > My plan then is as follows. I'll wait one more month and then send out
33 > a news item and later mask hardened-sources for removal. I don't
34 > recommend we remove any of the machinery from Gentoo that deals with PaX
35 > markings.
36 >
37 > I welcome feedback.
38 >
39 Thanks for taking the time to let the greater Gentoo community know.
40 It's a shame things took this turn... Is there any hope of a fork
41 emerging from the drama? Why would a security-conscious group take their
42 toys and go home? Regardless, this is a loss for Linux as a whole. I
43 hope something springs up in its place.
44
45 --
46 Daniel Campbell - Gentoo Developer
47 OpenPGP Key: 0x1EA055D6 @ hkp://keys.gnupg.net
48 fpr: AE03 9064 AE00 053C 270C 1DE4 6F7A 9091 1EA0 55D6

Attachments

File name MIME type
signature.asc application/pgp-signature