> Has anyone done anything like this?  Is it silly to even think that the
> hand-applied patches will apply without rejects?

I haven't tried myself, but I have read in a few spots that it can't be
done.

> Or should I be doing a strictly Xen kernel as the host kernel and if I
> want SELinux/PaX/GRSecurity, put that in a guest kernel?  But doesn't
> the guest kernel also have to be patched for xen?  In which case the
> original question of getting a kernel patched with all four still applies.

If you use a new Intel processor with VT support or an AMD processor
with Pacifica then you can run unmodified guest kernels. You could then
patch your guest kernel with SELinux/PaX/GRSecurity however you pleased.

There is possibly a performance hit involved with using the new
virtualisation features in the CPU as apposed to porting the guest OS to
run under Xen although I am not aware how much. Does anyone else know?

I would certainly like to be able to run PaX, GRSecurity and Xen together.

Cheers,

Brad
-- 
[email protected] mailing list

Reply via email to