=== JanC is now known as Guest34729 | ||
=== JanC_ is now known as JanC | ||
kees | is 16.10 still expected to be a v4.8 kernel? | 19:34 |
---|---|---|
rtg | kees, yes. whats up with KASLR ? I've got your bug at the top of my list. | 19:38 |
rtg | https://bugs.launchpad.net/bugs/1573848 | 19:39 |
ubot5 | Launchpad bug 1573848 in linux (Ubuntu Yakkety) "KASLR should be enabled by default (x86)" [Medium,Triaged] | 19:39 |
kees | rtg: what would you like to know? v4.8 lands fixes to hibernation to support KASLR, so if v4.8 goes into 16.10, that bug can go away. ;) | 19:39 |
kees | (that bug has some hilarious new attachments too) | 19:39 |
rtg | kees, cool, that is easy then | 19:39 |
rtg | I noticed those this morning | 19:40 |
kees | okay, so the plan is still for v4.8? | 19:43 |
kees | I'd like to recommend two new configs: HARDENED_USERCOPY and RANDOMIZE_MEMORY | 19:43 |
kees | well, maybe three. how about SLAB_FREELIST_RANDOM too | 19:44 |
rtg | kees, I've got RANDOMIZE_MEMORY=y, but don't see HARDENED_USERCOPY yet. | 19:44 |
rtg | debian.master/config/config.common.ubuntu:CONFIG_SLAB_FREELIST_RANDOM=y | 19:45 |
kees | and, if you haven't, can you pick up Debian's patch to perf? https://lkml.org/lkml/2016/1/11/587 upstream doesn't like it, but Android and Debian ship with this as perf's attack surface is kind of huge | 19:46 |
kees | rtg: HARDENED_USERCOPY and RANDOMIZE_MEMORY got merged in the last week or so when the v4.8 merge window opened. | 19:46 |
rtg | kees, ok, my unstable repo is only at 4.8-rc1 | 19:47 |
kees | gotcha | 19:47 |
kees | these should appear when rc2 gets cut | 19:47 |
rtg | kees, as for the perf patch, please start a bug and assign me to it so it doesn't get lost. | 19:48 |
kees | okay, cool | 19:48 |
kees | rtg: opened https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1612790 | 19:57 |
ubot5 | Launchpad bug 1612790 in linux (Ubuntu) "Provide kernel.perf_event_paranoid sysctl level 3" [Undecided,New] | 19:57 |
rtg | kees, thanks | 19:57 |
Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!