This is a horrible hack. There must be a better way to solve the problem than to introduce bizarre/subtle/brittle semantics such as this.
The disagreement seems to me to be the usual one: one group wants the problem fixed NOW (the proposed solution is good enough), the other wants it fixed CORRECTLY (the proposed solution is more offensive than the problem, or could result in other as-yet-unforeseen problems, or could prevent the implementation of a better solution).
Posted Jun 3, 2010 16:54 UTC (Thu) by spender (subscriber, #23067)
[Link]
The proposed solution has been working fine for over a decade. Any software incompatibilities were fixed years ago (i.e. Mailman) due to the feature's presence in grsecurity. But I have no interest in what the kernel developers end up doing (or more likely not doing). Every feature of grsecurity they've replicated has provided weaker security for no added compatibility benefit. So much for choosing the correct fixes.