Live data from Hacker News

Passing the Baton

grsecurity.net

21–30 of 82 posts

Re: Passing the Baton

#21
post #7
post #4

Earlier quoted context omitted.

I thought the same thing. The Linux kernel has been "freely available" for a measly 26 years, and will continue to be so.

Why are the grsecurity patches not included in the Vanilla Kernel? https://unix.stackexchange.com/questions/59020/why-are-the-g...

In other words: nobody ever tried to get it into mainline. Anyone reading this right now could go and get it submitted into mainline in the chunks that Linus would accept. It would take about 6 months, though, assuming you knew what you were doing.

Re: Passing the Baton

#23
post #3

I love how grsecurity is always quick to point out how generous they have been by providing the patches for free. > We have been providing grsecurity freely for 16 years. Meanwhile the kernel upon which their work is built has been provided for free for much longer, and continues to be.

It's not just the patches they provided for, it's also innovation.

The technologies these dudes developed are used in the vast majority of OSs outthere.

Instead of posting a cynical comment here you should thank them.

Re: Passing the Baton

#24
post #3

I love how grsecurity is always quick to point out how generous they have been by providing the patches for free. > We have been providing grsecurity freely for 16 years. Meanwhile the kernel upon which their work is built has been provided for free for much longer, and continues to be.

It's not just the patches they provided for, it's also innovation. The technologies these dudes developed are used in the vast majority of OSs outthere. Instead of posting a cynical comment here you should thank them.

I mean, the grsecurity guys aren't the PAX guys.

Re: Passing the Baton

#25

Earlier quoted context omitted.

It's not just the patches they provided for, it's also innovation. The technologies these dudes developed are used in the vast majority of OSs outthere. Instead of posting a cynical comment here you should thank them.

I mean, the grsecurity guys aren't the PAX guys.

They work together.

Re: Passing the Baton

#26
post #16
post #14

Earlier quoted context omitted.

Torvalds claims [0] that he did not do enough arguing with upstream: > The apparent inability (and perhaps more importantly - total unwilling[n]ess) from the PaX team to be able to see what makes sense in a long-term general kernel and what does not, and split things up and try to push the sensible things up (and know which things are too ugly or too specialized to make sense), caused many PaX features to never be me…

PaX is developed independently from and usually shipped with grsec patches. AFAICT Spengler's not directly involved, and Torvald's comments don't reflect on them.

Every post on lwn or mailing lists by "PaXTeam" is quite obviously spender with another handle.

Re: Passing the Baton

#29

How does this work at a licensing level? GRSecurity are patches to the Linux kernel right? Can you distribute patches for a GPL licensed software without the patches themselves being GPL?

grsec has had a commercial program for a while.

The way these things tend to work is "It's GPL, but if you redistribute it publicly we terminate your subscription with no refund." (I think RHEL binaries work the same way, for instance.) The reason for companies to pay is to get reliable updates for new versions, so that they can avoid hiring a bunch of people in-house to build / forward-port things. So usually this incentive works.

Now that grsec is completely unavailable without a paid subscription, either source or binary, it'd be interesting to see if the incentive holds up, or whether someone wants to burn a subscription to get a version out to the public. I imagine that they're cautious about who they allow to sign up as a customer.

Re: Passing the Baton

#30

Earlier quoted context omitted.

We have no real evidence of that other than it's what Brad Spengler says.

Are you serious? If yes, ask PAX Team, irc email, whatever.

You mean the freemail.hu email on a page that only appeared about a year after their last release?
Post reply on HN