On lun., 2016-02-15 at 13:11 +0100, Florent Daigniere wrote:
> 1) It's compile-time randomization, making it useless security wise
>  (the attacker can fetch the binary from a mirror too!).

Sure, but having it enabled means it's easy for people to just rebuild the
package and have a randomized kernel. So if it doesn't break things, I prefer
having it enabled.
> 
> 2) It prevents users from rebuilding kernel modules as the
>  source packaged is distributed "cleaned".

I fail to parse this. Did you try DKMS modules with RANDKSTRUCT=n and did it
work? Because I sure didn't do anything to support external modules, so I'd be
surprised if that worked, RANDKSTRUCT or not.

Regards,
-- 
Yves-Alexis

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to