1 |
On Mon, May 01, 2017 at 01:28:54PM +0300, Andrew Savchenko wrote: |
2 |
> > The obvious step is indeed to stop further *current* development on |
3 |
> > hardened-sources. |
4 |
> |
5 |
> Why not support hardened-sources while corresponding vanilla |
6 |
> kernels are still supported? E.g. 4.9 is a longterm branch, so we |
7 |
> should be able to keep hardened-sources-4.9* up-to-date with |
8 |
> vanilla bugfixes. This will give a nice transition period for |
9 |
> hardened users. |
10 |
|
11 |
Transition to what exactly? |
12 |
|
13 |
There is one suggestion that mentions we would join forces with other |
14 |
projects "out there" to keep supporting the latest PaX patches. But this |
15 |
will require knowledgeable resources with enough time to do the necessary |
16 |
support on it. |
17 |
|
18 |
In my humble opinion, this is an effort which is not to be underestimated. |
19 |
Maintaining the upstream-provided patches within Gentoo is already an |
20 |
endeavour, and now we're talking about even taking on the patch content |
21 |
itself as well. |
22 |
|
23 |
If we have enough volunteers to do so, then let's do it. At least we can |
24 |
then have something for users to look forward to. If not, then the current |
25 |
long-term branch is also the latest, and the "transition period" is to allow |
26 |
users to move to a perhaps lesser kernel-hardened environment. |
27 |
|
28 |
Wkr, |
29 |
Sven Vermeulen |