Earlier quoted context omitted.
Are you serious? If yes, ask PAX Team, irc email, whatever.
You mean the freemail.hu email on a page that only appeared about a year after their last release?
Passing the Baton
31–40 of 82 posts
Re: Passing the Baton
#32Earlier quoted context omitted.
Why are the grsecurity patches not included in the Vanilla Kernel? https://unix.stackexchange.com/questions/59020/why-are-the-g...
In other words: nobody ever tried to get it into mainline. Anyone reading this right now could go and get it submitted into mainline in the chunks that Linus would accept. It would take about 6 months, though, assuming you knew what you were doing.
https://www.linux.com/news/google-developer-kees-cook-detail...
He's been working on this for a very long time.
Re: Passing the Baton
#33Re: Passing the Baton
#34How does this work at a licensing level? GRSecurity are patches to the Linux kernel right? Can you distribute patches for a GPL licensed software without the patches themselves being GPL?
grsec has had a commercial program for a while. The way these things tend to work is "It's GPL, but if you redistribute it publicly we terminate your subscription with no refund." (I think RHEL binaries work the same way, for instance.) The reason for companies to pay is to get reliable updates for new versions, so that they can avoid hiring a bunch of people in-house to build / forward-port things. So usually this i…
Re: Passing the Baton
#35Re: Passing the Baton
#36Earlier quoted context omitted.
Of course you can. https://01.org/linuxgraphics/gfx-docs/drm/admin-guide/tainte... Edit: --- Good point about the distinction between adding modules modifying existing source. It is an interesting question, actually and I haven't been able to find an authoritative answer on the subject. A patch is a description of changes that would be made to a work, if they were made. Does it trigger the licence before it is applie…
That's not the same thing at all. The 'P' taint flag exists because upstream kernel maintainers aren't interested in dealing with bug reports where the bug may have been caused by proprietary code loaded by end users, which often can't be examined or copied even for the purpose of discussing the bug. Total waste of time, so the flag makes those cases obvious to anyone reading the bug report. The user can be told upfr…
Is this true? I would think that as long as your "new" code is sufficiently distinct from the stuff you're replacing, you'd be fine distributing a non-GPL patch (at least if it's e.g. purely positional to elide context related issues). The result of applying the patch would not be distributable, but I'd think the patch itself would be fine.
Re: Passing the Baton
#37I suspect this will just shift focus to the Kernel Self Protection Project[1]. It may end up being the best thing that could have happened for kernel security in the end. [1] https://kernsec.org/wiki/index.php/Kernel_Self_Protection_Pr...
Re: Passing the Baton
#38Earlier quoted context omitted.
Don't do what exactly?
Push your conspiracy teories.
Also, pedantically, this wouldn't be a 'conspiracy theory', since all I'm suggesting is that one guy is being disingenuous on the internet.
Re: Passing the Baton
#39I love how grsecurity is always quick to point out how generous they have been by providing the patches for free. > We have been providing grsecurity freely for 16 years. Meanwhile the kernel upon which their work is built has been provided for free for much longer, and continues to be.
Re: Passing the Baton
#40Earlier quoted context omitted.
PaX is developed independently from and usually shipped with grsec patches. AFAICT Spengler's not directly involved, and Torvald's comments don't reflect on them.
Every post on lwn or mailing lists by "PaXTeam" is quite obviously spender with another handle.