>
You can't really ship all of the grsec, because some compile time settings break userspace apps. Other options disable things you want on laptops, like power management registers. Basically your need to opt-in to grsec and you need to know what to configure afterwards. Or enable only selected few features and not get the whole protection.
The vast majority of features are 'set and forget'. Most will not break userland, or have extremely low FP rates. I can think of only one or two that have a high FP rate (integer overflow plugin) that would not be enabled by default. After all, these patches tend to make it into upstream under another name in ~10 years or so.
> On top of that, you can't use the latest kernel version until grsec is ported to it.
Not really a problem unless your distro updates to the latest version the night it's released, which most will not. Grsecurity's dev patch tends to be far, far ahead of whatever Ubuntu is using.
I ran it on an Ubuntu system with virtually all features enabled with little problem.