On lun., 2016-02-15 at 13:11 +0100, Florent Daigniere wrote: > 1) It's compile-time randomization, making it useless security wise > (the attacker can fetch the binary from a mirror too!).
Sure, but having it enabled means it's easy for people to just rebuild the package and have a randomized kernel. So if it doesn't break things, I prefer having it enabled. > > 2) It prevents users from rebuilding kernel modules as the > source packaged is distributed "cleaned". I fail to parse this. Did you try DKMS modules with RANDKSTRUCT=n and did it work? Because I sure didn't do anything to support external modules, so I'd be surprised if that worked, RANDKSTRUCT or not. Regards, -- Yves-Alexis
signature.asc
Description: This is a digitally signed message part

