1 |
> |
2 |
> Just a side note, did you ever try and patch the kernel |
3 |
> with the AC patches and grsecurity? Hidious ;-) |
4 |
> |
5 |
|
6 |
|
7 |
Just about to try. Thanks for the warning. |
8 |
|
9 |
|
10 |
> |
11 |
> As it is now, all the patches you can enable/disable during |
12 |
> 'make menuconfig', so in having them all already applied, |
13 |
> should be no hassle in my opinion. |
14 |
|
15 |
|
16 |
Good point. |
17 |
|
18 |
|
19 |
> |
20 |
> I also do not think we should include grsecurity. It is like |
21 |
> I already stated, a invasive patch, touching from FS to |
22 |
> NET/NETFILTER code. And, it being what it is, most people |
23 |
> will not run it except on a very high risc server that |
24 |
> absolutely need that extra security. For a desktop box for |
25 |
> instance, it just cause too many hassles (sound problems, |
26 |
> games like UT, etc just getting killed at start, etc). |
27 |
> |
28 |
> This in *my* opinion falls into the 'do it yourself' catagory. |
29 |
> |
30 |
|
31 |
|
32 |
I agree that it shouldn't be included by default -- I was just trying to |
33 |
think of a way to make it easier. Everytime I upgrade my sources/kernel, |
34 |
I have to first add my BeOS filesystem patch to the ebuild file. Not the |
35 |
worst thing in the world, but it would be nice to have a clean way to do it. |
36 |
|
37 |
Zach |