m0dY wrote:May be this question has been already asked before but i would like to know why is the latest released stable version of the grsecurity patch is about 1 years' old ?.
it comes up every now and then
. first, there're two grsec series maintained in sync (for 2.4 and 2.6) and unless both are 'ready', we won't make a stable release for just one. as you can guess, the one holding up such a release has been 2.6 due to its development model and our lack of resources to keep up with it properly. add to this that we would not like to declare something stable while we know of outstanding bugs in it (be that in our code or in vanilla itself but manifesting under grsec only) and you can see how we ended up in the current situation.
Also if i am asked to use the latest test patch will it be stable enough for an enterprise box ? means have it gone under any sort of testing toward reliability and usability ?
i will pass on the judgement whether 2.6 itself is suitable for an enterprise box (and you know what vendor kernels are for, right? hobby projects like ours are not 'enterprise' in any sense of the word, even if we trust them more ourselves), so i assume you wanted to know whether or to what extent grsec makes the situation worse/better. as far as i know, most things work save for a few bugs in both PaX and grsec that we're tracking down but are having a hard time as they manifest only on certain configurations (read: we can't reproduce and hence debug them easily).