Re: [arch-general] Changing compilation flags

2017-07-01 Thread Alexander Harrigan
On On Sat, Jul 1, 2017 at 09:54 AM, arch-general wrote: > >On 2016-10-24 05:56, Allan McRae wrote: > >*> 1) building gcc to enable PIE by default > *> > >I am in the middle of rebuilding gcc with --enable-default-pie. When it > >finishes, I will start a todo for r

Re: [arch-general] End of official PaX and grsecurity support in Arch Linux

2017-05-01 Thread Alexander Harrigan
It looks Gentoo's Hardened Kernel Project oficially started. https://wiki.gentoo.org/wiki/Hardened/Hardened_Kernel_Project \-- Sent using MsgSafe.io's Free Plan Private, encrypted, online communication For everyone. https://www.msgsafe.io

Re: [arch-general] [Questions] Questions from past project and ideas fomr -dev-public that get silence.

2017-04-30 Thread Alexander Harrigan
I think the problem is lack of information about statuses of various projects. Users can't disticnt between something that is being worked on slowly because of lack of time of dev or technical difficulties and something totally forgotten. I think it would be helpful if features/isues discussed here

Re: [arch-general] End of official PaX and grsecurity support in Arch Linux

2017-04-29 Thread Alexander Harrigan
using grsec kernel myself until something like linux-hardened be avalaible. On On Sat, Apr 29, 2017 at 07:20 PM, Daniel Micay via arch-general <arch- gene...@archlinux.org> wrote: > On Sat, 2017-04-29 at 17:03 +, Alexander Harrigan wrote: > > I found someone from opensuse starte

Re: [arch-general] End of official PaX and grsecurity support in Arch Linux

2017-04-29 Thread Alexander Harrigan
I found someone from opensuse started to maintain grsec patches for 4.9 kernel series [1]. Maybe it will be possible to add linux-lts-grsec package to AUR based on Daniel's PKGBUILD and config with RANDSTRUCT enabled linked to new upstream source. [1] https://github.com/kdave/grsecurity-patches/tr

Re: [arch-general] End of official PaX and grsecurity support in Arch Linux

2017-04-27 Thread Alexander Harrigan
It would be great if you can provide linux-hardened kernel with everything what KSPP has enabled by default. Even in AUR so you won't have to rebuild it constantly and random stack option would have more sense. Two questions: 1\. Do you think maintaining 4.9 lts grsec kernel would be doable until