On top of that, you can't use the latest kernel version until grsec is ported to it. And probably more reasons I don't know about yet. Basically, it's not one-size-fits-all solution - Ubuntu would create more problems than solutions if they just dumped it on users by default (or at least without a proper migration path with lots of deprecation time).
The vast majority of features are 'set and forget'. Most will not break userland, or have extremely low FP rates. I can think of only one or two that have a high FP rate (integer overflow plugin) that would not be enabled by default. After all, these patches tend to make it into upstream under another name in ~10 years or so.
> On top of that, you can't use the latest kernel version until grsec is ported to it.
Not really a problem unless your distro updates to the latest version the night it's released, which most will not. Grsecurity's dev patch tends to be far, far ahead of whatever Ubuntu is using.
I ran it on an Ubuntu system with virtually all features enabled with little problem.
That's exactly what I meant. It usually works the same. Apart from when it doesn't. For example arch's linux-grsec kernel requires pax changes for common KDE apps, and every separate python virtualenv. Restricted runtime CPU registers stop powertop. Something (can't remember details now) affected sysdig.
It's not critical. I used to run grsec kernel all the time on a laptop. But I can't imagine someone dropping, for example paxd support into a popular distro and expect people to deal with apps suddenly not starting.
https://github.com/hardenedlinux/grsecurity-reproducible-bui...
As exmaple of Linux Mint: https://hardenedlinux.github.io/system-security/2016/01/10/h...
https://lists.archlinux.org/pipermail/arch-general/2017-Apri...
https://www.archlinux.org/packages/community/x86_64/linux-ha...
Not a replacement but at least an alternative.
https://wiki.gentoo.org/wiki/Hardened/Grsecurity2_Quickstart...