From: John Richard Moser <nigelenki@comcast.net>
To: Brandon Hale <brandon@smarterits.com>
Cc: Arjan van de Ven <arjan@infradead.org>,
ubuntu-hardened@lists.ubuntu.com, linux-kernel@vger.kernel.org
Subject: Re: [ubuntu-hardened] Re: Collecting NX information
Date: Mon, 28 Mar 2005 17:17:47 -0500 [thread overview]
Message-ID: <4248828B.20708@comcast.net> (raw)
In-Reply-To: <1112043246.10117.5.camel@localhost.localdomain>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Brandon Hale wrote:
>>>actually Linus was really against adding non-related things to this
>>>flag. And I think he is right...
>>>
>
>
> Makes sense to me.
>
>
[...]
>
> IMO you have this backwards, John. Rather than having the majority (ES,
> mainline NX stuff) respect your less popular branch, it would make sense
> to have PaX work as well as possible with PT_GNU_STACK, and politely
> request that any missing functionality be duplicated in ES. PT_GNU_STACK
> is the most widely available header, and we should leverage that
> ubiquity as much as possible. Marking our binaries with PT_PAX_FLAGS
> and then begging everyone else to support our way of doing things will
> never work.
>
You need to consider that in the end I'd need PT_GNU_STACK to do
everything PaX wants, and to make PF_X a tristate (On, Off, Neutral)
which mapped to PF_PAGEEXEC in PaX. In other words, I'd have to
overhaul and most likely *break* everything else that relied on
PT_GNU_STACK, instead of passively adding logic for PT_PAX_FLAGS and
letting everyone else catch up at their leisure.
I'd rather not break anything and force everyone to upgrade *now*; but
instead add PT_PAX_FLAGS functionality for mainline/ES, let it lay there
for a year or so as people start moving over and accepting it, let the
kernel devs decide when it's time to depricate PT_GNU_STACK, and see it
naturally decay away once it's actually no longer needed. The point is
to not break anything, yet to still make things easier for those
projects and distributions like Hardened Ubuntu.
> ---
> Brandon Hale
- --
All content of all messages exchanged herein are left in the
Public Domain, unless otherwise explicitly stated.
Creative brains are a valuable, limited resource. They shouldn't be
wasted on re-inventing the wheel when there are so many fascinating
new problems waiting out there.
-- Eric Steven Raymond
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFCSIKKhDd4aOud5P8RAkqEAJwNhFvfDc63qyPrBvMxs6naG1xuAQCfZKHn
upzqNI5/XzYVCmDKGM6q8ZY=
=YZkT
-----END PGP SIGNATURE-----
next prev parent reply other threads:[~2005-03-28 22:17 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-03-28 18:21 Collecting NX information John Richard Moser
2005-03-28 18:37 ` Arjan van de Ven
2005-03-28 18:50 ` John Richard Moser
2005-03-28 18:55 ` Arjan van de Ven
2005-03-28 19:14 ` John Richard Moser
2005-03-28 20:54 ` [ubuntu-hardened] " Brandon Hale
2005-03-28 22:17 ` John Richard Moser [this message]
2005-03-29 7:16 ` Arjan van de Ven
2005-03-29 7:53 ` John Richard Moser
2005-03-29 8:09 ` Arjan van de Ven
[not found] ` <424911FF.1080702@comcast.net>
2005-03-29 8:46 ` Arjan van de Ven
[not found] ` <42499C40.5030202@comcast.net>
[not found] ` <1112121756.6282.88.camel@laptopd505.fenrus.org>
[not found] ` <4249A78A.1040407@comcast.net>
2005-03-29 19:34 ` Arjan van de Ven
2005-03-29 20:41 ` John Richard Moser
2005-03-29 8:45 ` John Richard Moser
2005-03-29 8:15 ` John Richard Moser
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4248828B.20708@comcast.net \
--to=nigelenki@comcast.net \
--cc=arjan@infradead.org \
--cc=brandon@smarterits.com \
--cc=linux-kernel@vger.kernel.org \
--cc=ubuntu-hardened@lists.ubuntu.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox