Hi,
i don't use yet ACL system but i have few feature request :
1 - i saw that we can globally disable ACLs, but i really like the feature provided by LIDS which allow us to have a free shell, and only one, free of ACLs system, where we can do all that we want.
It could be usefull for instance when i am connected by SSH on my server to be able to disabled ACLs temporarly to install and build binaries without disable the global security.
2- documentation request : i perfectly understand that all your time is dedicated to work and improvement of grsecurity, but more documentation and howto would be greatly appreciated. For instance, it's hard to know what options we will have in the kernel until we are in, a global description would be nice (a summary).
I'm dedicated to my security, i use and configure in depth some advanced feature of my linux server, but the fact that i lack of documentation about grsecurity blocks me at some points, for instance about ACL, i'm unable to use them and try to use per application learning mode without blocking all my system. I know grsecurity is a best to have, a must, better by far than other security product that i saw, but i think that few users give up (that i was close to do!) because of not finding answers on official documentation (i don't know so good grsecurity to do them myself).
So i think that more documention will help to the spread of grsecurity, and to configure it!
(more doc about cvs would be great too, not toward cvs itself (man is good for) but to retrieve a ".patch" file for instance...)
3 - I think it could be good to choose password algorithm cipher, that we could configured regarding our state and local laws, i know that you can't force people to use some strong key like 2048 bits also, regardless of the cipher.
4 - for production use : a special option at building time of kernel allowing to secure it disabling the possibility for gradm to manage it, i mean ACLs are loaded at start and no program at all can disabled the protection
(had to reboot on normal grsecurity kernel to manage ACL).
Of course if the grsecurity password is totally unbreakable and 100% secure, this option is useless
5 - last : keep it the good work !! the most important request
regards,
gkweb.