Gentoo Archives: gentoo-dev

From: Zach Forrest <diatribe@××××.ca>
To: gentoo-dev@g.o
Subject: Re: [gentoo-dev] KUSE....
Date: Fri, 28 Dec 2001 15:51:03
Message-Id: 3C2CEA34.3090906@shaw.ca
In Reply to: Re: [gentoo-dev] KUSE.... by Martin Schlemmer
1 >
2 > Just a side note, did you ever try and patch the kernel
3 > with the AC patches and grsecurity? Hidious ;-)
4 >
5
6
7 Just about to try. Thanks for the warning.
8
9
10 >
11 > As it is now, all the patches you can enable/disable during
12 > 'make menuconfig', so in having them all already applied,
13 > should be no hassle in my opinion.
14
15
16 Good point.
17
18
19 >
20 > I also do not think we should include grsecurity. It is like
21 > I already stated, a invasive patch, touching from FS to
22 > NET/NETFILTER code. And, it being what it is, most people
23 > will not run it except on a very high risc server that
24 > absolutely need that extra security. For a desktop box for
25 > instance, it just cause too many hassles (sound problems,
26 > games like UT, etc just getting killed at start, etc).
27 >
28 > This in *my* opinion falls into the 'do it yourself' catagory.
29 >
30
31
32 I agree that it shouldn't be included by default -- I was just trying to
33 think of a way to make it easier. Everytime I upgrade my sources/kernel,
34 I have to first add my BeOS filesystem patch to the ebuild file. Not the
35 worst thing in the world, but it would be nice to have a clean way to do it.
36
37 Zach

Replies

Subject Author
Re: [gentoo-dev] KUSE.... Martin Schlemmer <azarah@g.o>