Gentoo Archives: gentoo-hardened

From: "Anthony G. Basile" <basile@××××××××××××××.edu>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] The state of grsecurity in gentoo
Date: Wed, 02 Sep 2015 16:13:42
Message-Id: 55E7202D.7080402@opensource.dyc.edu
1 Hi everyone,
2
3 So by now most people have heard the news that the Grsecurity/PaX team
4 are no longer going to be making their stable patches available. The
5 reason is that they are in dispute with a certain embedded systems
6 vendor and those negotiations broke down. So they decided to make their
7 stable patches only available to the sponsors. [1]
8
9 What does this mean for Gentoo? Up until now I have been maintaining
10 both the grsec upstream stable and testing patchsets in our
11 hardened-sources. Currently the upstream stable kernels are 3.2.71 and
12 3.14.51 and the testing are 4.1.6. In about one week, the 3.2.71 and
13 3.14.51 patchsets will no longer be available and I'll continue pushing
14 out the 4.1.6. Unfortunately the testing patchset is precisely as the
15 name suggests --- for testing and not production. For the embedded
16 systems company this will be the kiss of death because those patches are
17 not suitable for long term. For Gentoo it will mean that I will have to
18 be more vigilant about bugs and trying to stick with a well known kernel
19 before moving on. You can still use these kernels in production, but
20 you must be carefull about instabilities as upstream pushes out
21 experimental feature that may oops or panic. Keep older kernel images
22 around and revert if it doesn't work. Look to this list for
23 announcements about more serious issues like things that can cause data
24 loss.
25
26 I'm hoping that once this company feels the sting of what has just
27 happened, they'll come back to the table and talk with Grsec/PaX people.
28 They won't be able to ship boards with grsec anymore because its not so
29 easy to switch out a kernel on a board! If they ship a board with a
30 bug, they loose. We just reboot :)
31
32 [1] https://grsecurity.net/
33
34 --
35 Anthony G. Basile, Ph. D.
36 Chair of Information Technology
37 D'Youville College
38 Buffalo, NY 14201
39 (716) 829-8197

Replies

Subject Author
Re: [gentoo-hardened] The state of grsecurity in gentoo "Aaron W. Swenson" <titanofold@g.o>
Re: [gentoo-hardened] The state of grsecurity in gentoo "Francisco Blas Izquierdo Riera (klondike)" <klondike@g.o>
Re: [gentoo-hardened] The state of grsecurity in gentoo Marc Schiffbauer <mschiff@g.o>
Re: [gentoo-hardened] The state of grsecurity in gentoo Marc Schiffbauer <mschiff@g.o>
Re: [gentoo-hardened] The state of grsecurity in gentoo "J. Roeleveld" <joost@××××××××.org>