All of lore.kernel.org
 help / color / mirror / Atom feed
* "Hardened" tree on kernel.org?
@ 2018-08-31 17:44 Konstantin Ryabitsev
  2018-09-10 12:24 ` Yves-Alexis Perez
  0 siblings, 1 reply; 3+ messages in thread
From: Konstantin Ryabitsev @ 2018-08-31 17:44 UTC (permalink / raw)
  To: kernel-hardening

[-- Attachment #1: Type: text/plain, Size: 1376 bytes --]

Hi, all:

There's a lot of excellent work being done on this list and as part of 
KSPP that enjoys limited exposure due to long and arduous upstreaming 
process. I am wondering if some of the proposed changes would see wider 
testing if there was a curated semi-official "hardened" tree hosted on 
kernel.org that would carry kernel hardening patches proposed for 
inclusion into mainline. There is at least one project that does 
something like this:

https://git.kernel.org/pub/scm/linux/kernel/git/rt/linux-stable-rt.git

though there's the distinction that, to my knowledge, RT is not intended 
to be upstreamed.

I think wider testing and adoption would be easier if there was a place 
for folks to download a "hardened Linux tarball" -- with the 
understanding that it would include features that may or may not 
eventually make it into mainline. I know it's a lot of work, and I'm 
certainly not volunteering for it (I don't have the right set of skills 
for this), but I believe there is a demand for such resource among 
security enthusiasts and security-minded distros.

In a sense, this would shadow Greg's work -- taking the latest stable 
tree and porting a hardening patchset on top of it. Maybe one of the LTS 
trees, too?

Do you think this would be a worthwhile thing, or would that distract 
from overall mainlining goals?

-K

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2018-09-10 16:03 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2018-08-31 17:44 "Hardened" tree on kernel.org? Konstantin Ryabitsev
2018-09-10 12:24 ` Yves-Alexis Perez
2018-09-10 16:03   ` Kees Cook

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.