E.g. https://packages.gentoo.org/packages/sys-kernel/hardened-sou...
E.g. https://packages.gentoo.org/packages/sys-kernel/hardened-sou...
I can tell you how to make a perfectly secure computer, grind it down and launch it into the sun.
Part of the rest of the kernel communities complaints about many of these changes is that they aren't sufficiently pragmatic for widescale use or long term maintenance.
"Grsecurity stable patch downloads are available to customers only."
edit: that's for grsec only, not PaX + grsec.
https://wiki.gentoo.org/wiki/Handbook:X86/Portage/Branches#T...
The most recent stable hardened-sources is 4.4.8-r1 which is ~6 months old.
https://wiki.gentoo.org/wiki/Kernel/Overview#vanilla-sources
The last unmasked release is 4.4.8-r1 which is six months behind.
(Edit in reply to below: That basically just means 'we dont want to babysit people can't compile a kernel or recover an unbootable machine'. It has nothing to do with the currency or utility of PaX or Gentoo. You obviously do not have experience in this area.)
"Users that do not know how Gentoo works and how to solve problems, we recommend to stick with the stable and tested branch."
https://wiki.gentoo.org/wiki/Handbook:X86/Portage/Branches#T...
In reply (because of reply functionality, instead of stealthy edits), you should know I run an unmasked ck-sources kernel because rice (and BFS/BFQ).
If you really want an unstable Gentoo install, go with the x32 profile.