From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (qmail 11971 invoked from network); 18 Sep 2004 06:11:21 +0000 Received: from smtp.gentoo.org (156.56.111.197) by lists.gentoo.org with AES256-SHA encrypted SMTP; 18 Sep 2004 06:11:21 +0000 Received: from lists.gentoo.org ([156.56.111.196] helo=parrot.gentoo.org) by smtp.gentoo.org with esmtp (Exim 4.41) id 1C8YRP-0005k1-QV for arch-gentoo-dev@lists.gentoo.org; Sat, 18 Sep 2004 06:11:23 +0000 Received: (qmail 19570 invoked by uid 89); 18 Sep 2004 06:11:10 +0000 Mailing-List: contact gentoo-dev-help@gentoo.org; run by ezmlm Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-dev@gentoo.org Received: (qmail 11237 invoked from network); 18 Sep 2004 06:11:09 +0000 From: Ned Ludd Reply-To: solar@gentoo.org To: gentoo-hardened@lists.gentoo.org Cc: gentoo-dev@lists.gentoo.org, ps.m@gmx.net, pageexec@freemail.hu Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="=-8wC2pS+ydCz6detguEsx" Organization: Gentoo (hardened,security,infrastructure,embedded,toolchain) Developer Message-Id: <1095487827.11248.284.camel@simple> Mime-Version: 1.0 X-Mailer: Ximian Evolution 1.4.6 Date: Sat, 18 Sep 2004 02:10:27 -0400 Subject: [gentoo-dev] Considering dropping the hardened toolchain X-Archives-Salt: a97b811f-899a-442a-a574-3edd5ed20a94 X-Archives-Hash: 687f87dd5816616eb7954ec930981010 --=-8wC2pS+ydCz6detguEsx Content-Type: text/plain Content-Transfer-Encoding: quoted-printable I really never wanted to send a mail like this but I don't know what else to do. ;/ Due to low positive feedback and user input I'm considering dropping the hardened toolchain and retiring from non commercial proactive security efforts. ie pulling the patches developed that brings you pie/ssp/relro/now/etc.. Doing otherwise I feel would leave you limping along, which I feel would be a disservice to everybody. This motivation stems from bugs that are going unresolved or being improperly fixed and or filtered. I'm not getting the help I/we need from my own team or the user community. This is becoming an overwhelming/stressful job for one person to handle alone on with a user-base this large. If you wish to see the hardened toolchain continue YOU need to step up in the next few weeks and offer help (ie we need 2-3 really good people). Mail me off list for more details if your interested in helping. A fair to strong understanding is needed of entire toolchain process. Desired is somebody(s) that preferably also understands ELF and multi arch assembly that wishes to see the solution developed to it's fullest as per the goals outlined in the PaX documentation. --=20 Ned Ludd Gentoo (hardened,security,infrastructure,embedded,toolchain) Developer --=-8wC2pS+ydCz6detguEsx Content-Type: application/pgp-signature; name=signature.asc Content-Description: This is a digitally signed message part -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQBBS9FT94CCfB4KcwwRArAgAKDDHLo91FjMH8TOqdvedqYPCbcVCQCgpCZ8 4mHRgDtdg6eIXWizQMClW2k= =tnH4 -----END PGP SIGNATURE----- --=-8wC2pS+ydCz6detguEsx--