* [gentoo-hardened] Regarding hardened-sources
@ 2010-03-24 19:47 Mansour Moufid
2010-03-24 19:54 ` Guillaume Castagnino
0 siblings, 1 reply; 4+ messages in thread
From: Mansour Moufid @ 2010-03-24 19:47 UTC (permalink / raw
To: gentoo-hardened
Hello,
The latest stable release of grsecurity is for 2.6.32 kernels.
Gentoo's hardened-sources have been stuck at 2.6.28-r9 for a while
now. Is there any particular reason for this?
Stability is important, but it's also fact that many (most?)
vulnerabilities in Linux are fixed silently as non-security updates in
the latest kernels. The grsecurity/PaX team has been tracking and
backporting these sorts of stealth vulnerability fixes. Therefore,
would it not make more sense for Gentoo Hardened to follow their lead?
Especially considering they will be supporting 2.6.32 on a long term
basis[1].
Thanks for your time.
[1] <http://grsecurity.net/news.php#stablechosen>
--
Mansour Moufid
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [gentoo-hardened] Regarding hardened-sources
2010-03-24 19:47 [gentoo-hardened] Regarding hardened-sources Mansour Moufid
@ 2010-03-24 19:54 ` Guillaume Castagnino
2010-03-25 1:16 ` Brian Davis
0 siblings, 1 reply; 4+ messages in thread
From: Guillaume Castagnino @ 2010-03-24 19:54 UTC (permalink / raw
To: gentoo-hardened; +Cc: Mansour Moufid
Le Mercredi 24 Mars 2010 20:47:08, Mansour Moufid a écrit :
> Hello,
>
> The latest stable release of grsecurity is for 2.6.32 kernels.
> Gentoo's hardened-sources have been stuck at 2.6.28-r9 for a while
> now. Is there any particular reason for this?
>
> Stability is important, but it's also fact that many (most?)
> vulnerabilities in Linux are fixed silently as non-security updates in
> the latest kernels. The grsecurity/PaX team has been tracking and
> backporting these sorts of stealth vulnerability fixes. Therefore,
> would it not make more sense for Gentoo Hardened to follow their lead?
> Especially considering they will be supporting 2.6.32 on a long term
> basis[1].
>
> Thanks for your time.
>
> [1] <http://grsecurity.net/news.php#stablechosen>
Try hardened-development overlay (available via layman)
http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-dev.git;a=summary
It provides a recent kernel and some toolchain patches
--
Guillaume Castagnino
casta@xwing.info / guillaume@castagnino.org
^ permalink raw reply [flat|nested] 4+ messages in thread
* RE: [gentoo-hardened] Regarding hardened-sources
2010-03-24 19:54 ` Guillaume Castagnino
@ 2010-03-25 1:16 ` Brian Davis
2010-03-25 7:44 ` Daniel Kuehn
0 siblings, 1 reply; 4+ messages in thread
From: Brian Davis @ 2010-03-25 1:16 UTC (permalink / raw
To: gentoo-hardened; +Cc: mansourmoufid
[-- Attachment #1: Type: text/plain, Size: 1696 bytes --]
I think the question still stands, however, as to why the "main-line" hardened-sources are not being updated.
> From: casta@xwing.info
> To: gentoo-hardened@lists.gentoo.org
> Subject: Re: [gentoo-hardened] Regarding hardened-sources
> Date: Wed, 24 Mar 2010 20:54:29 +0100
> CC: mansourmoufid@gmail.com
>
> Le Mercredi 24 Mars 2010 20:47:08, Mansour Moufid a écrit :
> > Hello,
> >
> > The latest stable release of grsecurity is for 2.6.32 kernels.
> > Gentoo's hardened-sources have been stuck at 2.6.28-r9 for a while
> > now. Is there any particular reason for this?
> >
> > Stability is important, but it's also fact that many (most?)
> > vulnerabilities in Linux are fixed silently as non-security updates in
> > the latest kernels. The grsecurity/PaX team has been tracking and
> > backporting these sorts of stealth vulnerability fixes. Therefore,
> > would it not make more sense for Gentoo Hardened to follow their lead?
> > Especially considering they will be supporting 2.6.32 on a long term
> > basis[1].
> >
> > Thanks for your time.
> >
> > [1] <http://grsecurity.net/news.php#stablechosen>
>
> Try hardened-development overlay (available via layman)
> http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-dev.git;a=summary
>
> It provides a recent kernel and some toolchain patches
>
>
>
> --
> Guillaume Castagnino
> casta@xwing.info / guillaume@castagnino.org
>
_________________________________________________________________
The New Busy is not the old busy. Search, chat and e-mail from your inbox.
http://www.windowslive.com/campaign/thenewbusy?ocid=PID27925::T:WLMTAGL:ON:WL:en-US:WM_HMP:032010_3
[-- Attachment #2: Type: text/html, Size: 2118 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [gentoo-hardened] Regarding hardened-sources
2010-03-25 1:16 ` Brian Davis
@ 2010-03-25 7:44 ` Daniel Kuehn
0 siblings, 0 replies; 4+ messages in thread
From: Daniel Kuehn @ 2010-03-25 7:44 UTC (permalink / raw
To: gentoo-hardened; +Cc: mansourmoufid
[-- Attachment #1: Type: text/plain, Size: 2136 bytes --]
On Thu, Mar 25, 2010 at 2:16 AM, Brian Davis <bridavis@live.com> wrote:
> I think the question still stands, however, as to why the "main-line"
> hardened-sources are not being updated.
>
> > From: casta@xwing.info
> > To: gentoo-hardened@lists.gentoo.org
> > Subject: Re: [gentoo-hardened] Regarding hardened-sources
> > Date: Wed, 24 Mar 2010 20:54:29 +0100
> > CC: mansourmoufid@gmail.com
>
> >
> > Le Mercredi 24 Mars 2010 20:47:08, Mansour Moufid a écrit :
> > > Hello,
> > >
> > > The latest stable release of grsecurity is for 2.6.32 kernels.
> > > Gentoo's hardened-sources have been stuck at 2.6.28-r9 for a while
> > > now. Is there any particular reason for this?
> > >
> > > Stability is important, but it's also fact that many (most?)
> > > vulnerabilities in Linux are fixed silently as non-security updates in
> > > the latest kernels. The grsecurity/PaX team has been tracking and
> > > backporting these sorts of stealth vulnerability fixes. Therefore,
> > > would it not make more sense for Gentoo Hardened to follow their lead?
> > > Especially considering they will be supporting 2.6.32 on a long term
> > > basis[1].
> > >
> > > Thanks for your time.
> > >
> > > [1] <http://grsecurity.net/news.php#stablechosen>
> >
> > Try hardened-development overlay (available via layman)
> > http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-dev.git;a=summary
> >
> > It provides a recent kernel and some toolchain patches
> >
> >
> >
> > --
> > Guillaume Castagnino
> > casta@xwing.info / guillaume@castagnino.org
> >
>
> ------------------------------
> The New Busy is not the old busy. Search, chat and e-mail from your inbox. Get
> started.<http://www.windowslive.com/campaign/thenewbusy?ocid=PID27925::T:WLMTAGL:ON:WL:en-US:WM_HMP:032010_3>
>
From what I recall from the discussions on Irc there has been several issues
with .32 and .31 was skipped entirely in favour for .32 but the update to
the main-tree should be coming soon according to Anarchy and gang (Was a
while since I spoke to Anarchy tho, but they are doing their best)
Kind Regards
/Daniel
[-- Attachment #2: Type: text/html, Size: 3170 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2010-03-25 8:03 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-03-24 19:47 [gentoo-hardened] Regarding hardened-sources Mansour Moufid
2010-03-24 19:54 ` Guillaume Castagnino
2010-03-25 1:16 ` Brian Davis
2010-03-25 7:44 ` Daniel Kuehn
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox