Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update SecureDrop kernels to 4.4.181+ #4520

Closed
eloquence opened this issue Jun 12, 2019 · 4 comments · Fixed by #4543 or #4551
Closed

Update SecureDrop kernels to 4.4.181+ #4520

eloquence opened this issue Jun 12, 2019 · 4 comments · Fixed by #4543 or #4551
Milestone

Comments

@eloquence
Copy link
Member

SecureDrop instances are currently running 4.4.177 grsecurity-patched kernels.

To benefit from the most recent round of security improvements, we should update to the latest grsecurity kernel version in the 4.4 series (as of this writing: 4.4.181).

@ageis
Copy link
Contributor

ageis commented Jun 12, 2019

So does that put xenial and the 4.14.x series further afield?

@emkll
Copy link
Contributor

emkll commented Jun 12, 2019

Based on the information provided by the Linux kernel release page [0], 4.4 kernel series will be supported until 2022, whereas 4.14 kernel series will only be supported until Jan 2020.

While the security improvements of a more modern kernel (provided by 4.14 series) would definitely be welcome, it may be more prudent to wait for the stable4 series of patches, where upstream support will likely be longer than 6 months. If, at some point, the support window for 4.14 shifts further into the future, we should definitely reconsider.

[0] https://www.kernel.org/category/releases.html

@eloquence
Copy link
Member Author

As for Xenial, that transition was completed, and Ubuntu 16.04 is the only supported server OS version since SD 0.13.0.

@zenmonkeykstop
Copy link
Contributor

Tested 4.4.182-grsec kernel, built by @emkll, against supported hardware - all boot and have comparable paxtest results to current 4.4.177-grsec kernels.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
4 participants